Safety Instrumented System Cyber-Attack Defense via Zone Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional integrated industrial systems are vulnerable to cyber-attacks, which can compromise the safety instrumented system by breaching security measures in individual zones, potentially leading to loss of control and safety risks.
Innovation Solution
An integrated industrial system with a safety instrumented system in one zone and a host system in another, equipped with detectors to identify cyber-attacks and a defense mechanism to restrict communication between zones based on detection results, ensuring the safety instrumented system's integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security countermeasures are applied to each zone individually, then the system can maintain normal communication operations in each zone, but the safety instrumented system becomes vulnerable to cyber-attacks that breach individual zone defenses
Solution Approach 1:
A network defense device is introduced as an intermediary between the distributed control system and the safety instrumented system. This mediator monitors network traffic and blocks malicious communications targeting the safety instrumented system, preventing cyber-attacks from reaching it while allowing legitimate control communications to pass through.
Solution Approach 2:
The system is divided into distinct security zones with different protection levels. The safety instrumented system is isolated in a dedicated zone with restricted network access, while the distributed control system operates in a separate zone. This segmentation prevents attacks from propagating across the entire network and allows targeted security measures for each zone.
2Object-affected harmful factors
If the safety instrumented system is isolated from the host system, then it is protected from cyber-attacks, but it loses the ability to communicate with the host system when needed
Solution Approach 1:
The network defense device serves as a controlled intermediary that enables communication between the safety instrumented system and the host system through the distributed control system. It allows legitimate control commands and status information to pass through while blocking malicious traffic, thus maintaining both security and operational communication needs.
Solution Approach 2:
Different communication requirements are addressed with different security policies. Critical real-time control communications between the distributed control system and safety instrumented system are allowed with high priority, while non-critical communications with the host system are subject to stricter security filtering. This local quality approach ensures operational needs are met while maintaining security.
3Reliability
If the safety instrumented system communicates with the distributed control system, then it can perform safety functions, but it becomes indirectly connected to the host system and vulnerable to attacks
Solution Approach 1:
The network defense device is positioned as a mediator between the distributed control system and the safety instrumented system. It monitors and filters all communications passing through the distributed control system toward the safety instrumented system, blocking any malicious traffic that may have originated from the host system or external networks while allowing legitimate safety-related communications to pass through.
Data Source
AI summary
An integrated industrial system includes a safety instrumented system which is installed in a first zone, a host system which is connected to the safety instrumented system through a network, the host system being installed in a second zone which is different from the first zone, a detector which is installed in each of the first zone and the second zone, the detector being configured to detect a cyber-attack from outside to a self-zone, and a defender configured to perform a countermeasure of restricting a communication between the first zone and the second zone or of restricting a communication in the first zone or the second zone, based on a detection result of the detector.


