Protected OS for Industrial Control System Cybersecurity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face challenges in cybersecurity due to obsolete equipment and software, lack of IT security updates, and inadequate security measures, leading to vulnerabilities from malicious actions and unintentional mistakes, which can disrupt technological processes and compromise data integrity.

Innovation Solution

Implementing a protected Operating System (OS) on control subjects of industrial technological systems, which includes analyzing log files for suspicious actions, intercepting network packets, and regulating access to USB ports, all while operating in a hypervisor mode to enhance cybersecurity and prevent malicious interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a protected Operating System is implemented to detect and prevent suspicious actions, then cybersecurity is improved, but system complexity increases

Engineering Contradiction:
ImprovecybersecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into distinct functional modules: a protected Operating System layer that provides security functions, a hypervisor mode for isolation, log file analysis components, network packet interception mechanisms, and USB port access regulation. This segmentation allows each component to perform its security function independently while maintaining overall system manageability despite the increased complexity.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If log file analysis and network packet interception are implemented to detect suspicious actions, then detection capability is improved, but processing time increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The protected Operating System performs preliminary actions by continuously monitoring and analyzing log files and intercepting network packets in real-time before suspicious actions can execute. Security policies are pre-configured and automatically applied, allowing the system to detect and respond to threats without significant processing delays during actual security events.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If USB port access is regulated to prevent malicious actions, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements feedback mechanisms where USB port access requests are automatically evaluated against configured security policies. The protected Operating System monitors access attempts, analyzes them for suspicious patterns, and dynamically adjusts access permissions based on the assessment. This automated feedback loop maintains security while reducing manual intervention requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11971996B2Increasing the cybersecurity of a control subject of a technological system by using a protected operating system
Publication Date: 2024.04.30 AO KASPERSKY LAB
  • US11971996B2 patent drawing
  • US11971996B2 patent drawing
  • US11971996B2 patent drawing

AI summary

The present disclosure provides systems and methods for increasing the cybersecurity of a control subject of an industrial technological system. In an exemplary aspect, the method comprises installing a protected Operating System (OS) on a control subject of the industrial technological system, receiving, by the protected OS, a plurality of log files from the control subject, analyzing, by the protected OS, the plurality of log files to determine if a suspicious action has been applied to the control subject, wherein the control subject is configured to apply a controlling action to the object of control, intercepting, by the protected OS, network packets transmitted by an application launched in a guest OS to the control subject, and preventing, by the protected OS, an interaction between the application and the control subject, in response to determining that the suspicious action has been applied to the control subject.