Risk Manager System Deployment Assurance for Industrial Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face increasing cyber-security concerns due to unaddressed vulnerabilities in networked devices from various vendors, making it difficult to quickly determine potential risks and ensure monitoring does not disrupt operations or safety.

Innovation Solution

A risk manager system identifies vulnerable devices, evaluates system resource usage, and provides recommendations on whether to proceed with monitoring, ensuring that monitoring does not jeopardize system safety or production by checking for hardware, software, and security prerequisites.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If monitoring is implemented on vulnerable devices, then security risks are detected, but system safety and production may be jeopardized due to resource constraints

Engineering Contradiction:
Improvesystem safetyVSAvoidcyber-security risks
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system performs preliminary deployment assurance checks before monitoring is activated. These checks evaluate resource usage, hardware capabilities, software prerequisites, and security configurations in advance to ensure that monitoring will not compromise system safety or production while still detecting security risks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary assessment layer between the monitoring function and the industrial control system. This intermediary evaluates multiple factors (resource usage, hardware, software, security) and provides a risk score that determines whether monitoring should proceed, thus mediating between security detection needs and system safety concerns.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive monitoring is deployed across all vulnerable devices, then security coverage is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies different monitoring approaches and assessment criteria to different devices based on their specific characteristics. Instead of a uniform monitoring deployment, each device is evaluated individually for resource usage, hardware capabilities, software prerequisites, and security configurations, allowing tailored monitoring strategies that reduce overall system complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes multiple parameters simultaneously including resource usage thresholds, hardware requirements, software version prerequisites, and security configuration settings. By adjusting these parameters based on device-specific conditions, the system achieves comprehensive security coverage without uniformly increasing complexity across all devices.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If monitoring resources are allocated to vulnerable devices, then security detection capability is enhanced, but available system resources are consumed

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem resource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs a limited set of critical checks (resource usage, hardware, software, security) rather than exhaustive monitoring of all possible parameters. This partial action approach provides sufficient security detection capability while consuming minimal system resources, avoiding the need to monitor every aspect of each device.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The deployment assurance checks are designed to evaluate and manage their own resource requirements. By assessing resource usage as part of the deployment process, the system ensures that security detection activities are self-regulating and do not excessively consume system resources that could impact safety or production.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10181038B2Deployment assurance checks for monitoring industrial control systems
Publication Date: 2019.01.15 HONEYWELL INTERNATIONAL INC
  • US10181038B2 patent drawing
  • US10181038B2 patent drawing
  • US10181038B2 patent drawing

AI summary

This disclosure provides an apparatus and method for deployment assurance checks for monitoring industrial control systems and other systems. A method includes identifying, by a risk manager system, a plurality of connected devices that are vulnerable to cyber-security risks. The method includes determining devices to be monitored from the plurality of connected devices. The method includes evaluating system resource usage, by the risk manager system, on each device to be monitored. The method includes providing recommendations to a user as to whether or not the user should proceed with the monitoring, based on the evaluation.