Policy Undo in Operational Technology Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Implementing new security policies in operational technology (OT) networks often results in unintended side effects, leading to downtime or outages, as existing technologies lack effective methods to manage and revert policies quickly.
Innovation Solution
OT devices are equipped with a policy undo capability, allowing them to revert to a previously known stable state by storing an active policy and a backup policy in memory, enabling administrators to quickly switch between them via a command, either through a physical input device or the OT network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If new security policies are implemented in OT networks, then security posture is improved, but system stability deteriorates due to unintended side effects causing downtime or outages
Solution Approach 1:
The system performs preliminary actions by automatically backing up the active policy before applying a new policy. This preliminary backup creation enables rapid recovery if the new policy causes instability, resolving the contradiction by preparing a safety mechanism in advance that allows security updates without compromising long-term system stability.
Solution Approach 2:
The system provides beforehand cushioning by maintaining policy backups as a protective buffer against unintended side effects. When a new policy is applied, the backup serves as a cushion that can be deployed immediately if stability issues arise, allowing security improvements while protecting against potential system failures.
2Reliability
If policy updates are applied frequently to improve security, then security effectiveness is improved, but downtime increases due to inability to quickly revert to stable states
Solution Approach 1:
The system performs preliminary actions by automatically creating policy backups before applying updates. This preliminary backup mechanism enables frequent security updates without significant downtime, as recovery can be executed immediately by switching to the pre-prepared backup policy if issues occur.
Solution Approach 2:
The system implements skipping by enabling rapid policy switching through automated rollback capabilities. When a new policy causes problems, the system can quickly skip back to the previous stable policy state, minimizing downtime and allowing frequent security updates to be tested and deployed efficiently.
3Device complexity
If manual policy management processes are used, then system complexity is reduced, but response time deteriorates due to lack of automated policy switching capabilities
Solution Approach 1:
The system implements self-service by automatically creating policy backups and enabling automated rollback without requiring complex manual intervention. The OT device autonomously manages policy versions and can switch between policies based on predefined triggers, maintaining low complexity while achieving rapid response times for policy management.
Solution Approach 2:
The system uses an intermediary approach by implementing an automated policy management layer that mediates between policy updates and system operation. This intermediary mechanism handles the complexity of policy versioning and switching automatically, providing fast response times without requiring complex manual processes.
Data Source
AI summary
An OT device includes a memory and a processor. The memory stores a first policy, a second policy, and program instructions. The first policy includes a first set of settings associated with the operation of the OT device. The second policy includes a second set of settings associated with the operation of the OT device. The program instructions, when executed by the processor, cause the processor to receive first data associated with a first event, identify a first action in response to the first event based on the first policy, perform the identified first action, receive a command to enforce the second policy and stop enforcing the first policy, receive second data associated with a second event, identify a second action in response to the second event based on the second policy, and perform the identified second action.


