Risk Manager System for Near-Real-Time Cybersecurity Export

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial process control and automation systems face challenges in quickly determining and addressing cyber-security risks across a mix of equipment from different vendors, which can disrupt operations or cause unsafe conditions due to unaddressed security vulnerabilities, and existing monitoring systems may impact safety and production.

Innovation Solution

A risk manager system that monitors connected devices for cyber-security risks, detects vulnerabilities, and sends near-real-time risk data to external systems, allowing for filtered or unfiltered data streams based on user-configured options, ensuring timely notification and mitigation of risks without compromising system safety or production.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If monitoring systems are implemented to detect cyber-security risks in industrial control systems, then security vulnerability detection capability is improved, but system complexity and potential impact on safety and production increase

Engineering Contradiction:
Improvesecurity vulnerability detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring system is divided into separate functional modules: a risk manager system that monitors for vulnerabilities, a detector component that identifies specific security risks, and an exporter that sends notifications to external systems. This segmentation allows each module to perform its function independently, reducing overall system complexity while maintaining comprehensive security monitoring capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary risk manager system that sits between the industrial control devices and external security systems. This intermediary collects security risk data from multiple devices, processes and filters the information, and then exports only relevant risk notifications to external systems, thereby simplifying the overall architecture while improving detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive monitoring of all connected devices is performed, then security risk detection coverage is improved, but data processing time and resource consumption increase

Engineering Contradiction:
Improvesecurity risk detection coverageVSAvoiddata processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system extracts and exports only the essential security risk information to external systems, separating critical vulnerability data from the comprehensive monitoring data. This extraction approach maintains full monitoring coverage while reducing processing time by focusing only on the most important security risk notifications.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The risk manager performs comprehensive monitoring of all devices but applies selective export actions based on configured filtering options. Only risk data that meets specific criteria (such as high-severity vulnerabilities or devices matching certain profiles) are exported to external systems, reducing processing overhead while maintaining thorough monitoring coverage.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If filtered data streams are sent to external systems, then notification relevance is improved, but information completeness may be reduced

Engineering Contradiction:
Improvenotification relevanceVSAvoidinformation completeness
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The filtering options are dynamically configurable based on user needs and specific security contexts. The system can adjust which data streams are filtered and how, allowing users to balance between notification relevance and information completeness depending on the operational situation. This dynamic approach enables the same system to serve different information needs without loss of underlying data integrity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10135855B2Near-real-time export of cyber-security risk information
Publication Date: 2018.11.20 HONEYWELL INTERNATIONAL INC
  • US10135855B2 patent drawing
  • US10135855B2 patent drawing
  • US10135855B2 patent drawing

AI summary

This disclosure provides an apparatus and method for near-real-time export of cyber-security risk information, including but not limited to in industrial control systems and other systems. A method includes monitoring, by a risk manager system, a plurality of connected devices that are vulnerable to cyber-security risks. The method includes detecting a cyber-security risk to one or more of the devices being monitored. The method includes identifying an external system to be notified of the detected cyber-security risk. The method includes sending cyber-security risk data to the external system according to the detected cyber-security risk and at least one filtering option.