Risk Manager System for Near-Real-Time Cybersecurity Export
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial process control and automation systems face challenges in quickly determining and addressing cyber-security risks across a mix of equipment from different vendors, which can disrupt operations or cause unsafe conditions due to unaddressed security vulnerabilities, and existing monitoring systems may impact safety and production.
Innovation Solution
A risk manager system that monitors connected devices for cyber-security risks, detects vulnerabilities, and sends near-real-time risk data to external systems, allowing for filtered or unfiltered data streams based on user-configured options, ensuring timely notification and mitigation of risks without compromising system safety or production.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If monitoring systems are implemented to detect cyber-security risks in industrial control systems, then security vulnerability detection capability is improved, but system complexity and potential impact on safety and production increase
Solution Approach 1:
The monitoring system is divided into separate functional modules: a risk manager system that monitors for vulnerabilities, a detector component that identifies specific security risks, and an exporter that sends notifications to external systems. This segmentation allows each module to perform its function independently, reducing overall system complexity while maintaining comprehensive security monitoring capability.
Solution Approach 2:
The patent introduces an intermediary risk manager system that sits between the industrial control devices and external security systems. This intermediary collects security risk data from multiple devices, processes and filters the information, and then exports only relevant risk notifications to external systems, thereby simplifying the overall architecture while improving detection capability.
2Reliability
If comprehensive monitoring of all connected devices is performed, then security risk detection coverage is improved, but data processing time and resource consumption increase
Solution Approach 1:
The system extracts and exports only the essential security risk information to external systems, separating critical vulnerability data from the comprehensive monitoring data. This extraction approach maintains full monitoring coverage while reducing processing time by focusing only on the most important security risk notifications.
Solution Approach 2:
The risk manager performs comprehensive monitoring of all devices but applies selective export actions based on configured filtering options. Only risk data that meets specific criteria (such as high-severity vulnerabilities or devices matching certain profiles) are exported to external systems, reducing processing overhead while maintaining thorough monitoring coverage.
3Ease of operation
If filtered data streams are sent to external systems, then notification relevance is improved, but information completeness may be reduced
Solution Approach 1:
The filtering options are dynamically configurable based on user needs and specific security contexts. The system can adjust which data streams are filtered and how, allowing users to balance between notification relevance and information completeness depending on the operational situation. This dynamic approach enables the same system to serve different information needs without loss of underlying data integrity.
Data Source
AI summary
This disclosure provides an apparatus and method for near-real-time export of cyber-security risk information, including but not limited to in industrial control systems and other systems. A method includes monitoring, by a risk manager system, a plurality of connected devices that are vulnerable to cyber-security risks. The method includes detecting a cyber-security risk to one or more of the devices being monitored. The method includes identifying an external system to be notified of the detected cyber-security risk. The method includes sending cyber-security risk data to the external system according to the detected cyber-security risk and at least one filtering option.


