SCADA Network Cybersecurity Assessment and Response System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SCADA systems are vulnerable to cyberattacks due to their interconnected nature, with Level 1 and 2 nodes being particularly susceptible, posing safety hazards and requiring technologies to assess and enhance cybersecurity effectively.

Innovation Solution

A method and system that assess cybersecurity threats by monitoring network information, determining threat scores based on data packet traffic, node connections, and operational parameters, and controlling network responses to data packets based on access control scores, while also prompting maintenance actions to reduce vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SCADA systems use interconnected nodes for communication and control, then system functionality and data transmission are improved, but vulnerability to cyberattacks increases

Engineering Contradiction:
Improvesystem functionalityVSAvoidcyberattack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the SCADA network into multiple zones and implements zone-based access control policies. Each zone can be independently secured with specific threat scores and access control levels, limiting the propagation of cyberattacks while maintaining interconnectivity for system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security system that monitors network traffic between nodes and applies access control policies. This intermediary layer evaluates threat scores and mediates data transmission, protecting interconnected nodes from direct cyberattacks while preserving communication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive network monitoring and threat assessment are implemented, then cybersecurity detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system changes parameters by assigning numerical threat scores to nodes and access control levels to data packets. This quantification simplifies complex threat assessment into comparable metrics, enabling precise threat detection while maintaining manageable system complexity through standardized parameter evaluation.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The security system performs self-service by automatically monitoring network traffic, calculating threat scores, and applying access control policies without requiring constant human intervention. This automation reduces operational complexity while maintaining high threat detection precision through continuous automated assessment.

Inventive Principle:
Principle #25Self-service

3Reliability

If real-time access control decisions are made based on threat scores, then cybersecurity response effectiveness is improved, but processing time and computational load increase

Engineering Contradiction:
Improvesecurity response effectivenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-calculating base threat scores for nodes and pre-establishing access control policies before cyberattacks occur. This preparation enables rapid real-time decisions during actual security events, improving response effectiveness while minimizing processing time during critical moments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where threat scores and access control decisions are continuously updated based on real-time network monitoring. This feedback loop improves security response effectiveness by adapting to evolving threats while optimizing processing time through iterative refinement of threat assessments.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240380769A1Methods and systems for assessing and enhancing cybersecurity of a network
Publication Date: 2024.11.14 WILLOWGLEN SYST INC
  • US20240380769A1 patent drawing
  • US20240380769A1 patent drawing
  • US20240380769A1 patent drawing

AI summary

A method and related system are provided for assessment of cybersecurity of a network, by determining cybersecurity threat scores on a node-by-node basis, based on network information associated with the node, acquired by network monitoring. Another method and related system are provided for control of a response of a network to a data packet addressed from a first node to a second node in the network depending on the node locations, and/or cybersecurity threat scores of the nodes. Another method and related system are provided for maintaining a network to reduce cybersecurity risks by monitoring network components for cybersecurity vulnerabilities, generating and transmitting a first notification to a first node to take a corrective maintenance action to address the vulnerabilities within a time period, and escalating the notification to a second node of the network if the corrective action is not taken within the time period.