Cybersecurity Algorithms for SCADA Device Identification and Attack Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity solutions for SCADA systems and ICS lack comprehensive methods to identify vulnerabilities across all stages of the risk management process, particularly in legacy systems with inadequate documentation and complex network topologies.

Innovation Solution

A hybrid approach combining communication-pattern recognition and passive fingerprinting techniques to identify control hierarchy levels and device models, along with an automated attack-graph generator and visualizer to assess global vulnerabilities and identify critical attack paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SCADA systems/ICS are connected to the internet/cloud to improve supervisory and control processes, then information sharing and operational flexibility are enhanced, but vulnerability to cyberattacks and security risks increase

Engineering Contradiction:
Improveinformation sharing capabilityVSAvoidcybersecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security system that sits between the SCADA/ICS system and the internet/cloud network. This intermediary layer includes security appliances, firewalls, and monitoring tools that filter and control traffic flow, allowing legitimate information sharing while blocking malicious cyberattacks. The intermediary architecture enables the system to benefit from cloud connectivity without directly exposing the control system to internet threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If passive fingerprinting is used to identify devices in legacy SCADA systems, then device identification accuracy is improved, but the ability to handle inadequate documentation and complex network topologies deteriorates

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidnetwork topology complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the device identification process into multiple independent modules: network traffic capture, packet analysis, fingerprint extraction, device database matching, and identification result generation. Each module handles a specific aspect of the identification process, making the overall system more manageable despite complex network topologies. The segmentation allows the system to process different types of network traffic and device protocols independently, improving accuracy while maintaining complexity management.

Inventive Principle:
Principle #1Segmentation

3Reliability

If comprehensive vulnerability assessment methods are implemented across all risk management stages, then cybersecurity coverage is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvecybersecurity coverageVSAvoidassessment system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring security policies, vulnerability databases, and assessment criteria before deployment. The system includes pre-loaded databases of known vulnerabilities, device fingerprints, and security protocols that are prepared in advance. This preliminary preparation reduces the complexity of real-time vulnerability assessment, as the system only needs to match observed traffic against pre-established criteria rather than creating assessment frameworks during operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12309188B1Cybersecurity algorithms and tools for supervisory control and data acquisition and industrial control systems
Publication Date: 2025.05.20 IOWA STATE UNIV RES FOUND INC
  • US12309188B1 patent drawing
  • US12309188B1 patent drawing
  • US12309188B1 patent drawing

AI summary

A hybrid approach involving the mix of communication patterns and passive fingerprinting is used to identify unknown device types, manufacturers, and models of devices of digital control systems. ANDVI implementation maps the identified devices to their known vulnerabilities. According to one example, to identify how interdependence among existing atomic vulnerabilities may be exploited by an adversary to stitch together an attack that can compromise the system, model-checking based A2G2V is employed. According to another example, an A2G2V algorithm uses existing model-checking tools, an architecture description tool, and code to generate an attack-graph that enumerates the set of all possible sequences in which atomic-level vulnerabilities can be exploited to compromise system security. In yet another example, identification of label-cuts within an attack-graph automatically identifies a set of critical-attacks that, when blocked, renders the system secure. A linear complexity approximation utilizing SCCs helps identify the minimum label-cut representing a critical-attacks set.