Security Notification Subsystem for Industrial Device Risk Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial process control and automation systems face challenges in quickly identifying and addressing cyber-security vulnerabilities due to the complexity of managing multiple devices from various vendors, leading to potential disruptions and unsafe conditions, as operators often lack a comprehensive understanding of the equipment and potential sources of risk.

Innovation Solution

A notification subsystem that discovers devices, groups them into security zones, generates risk values, and automatically notifies users when thresholds are exceeded, utilizing a data collection component, rules engine, and risk management database to prioritize and alert potential security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple devices from various vendors are managed in industrial control systems, then system functionality and versatility are improved, but device complexity and difficulty of security management increase

Engineering Contradiction:
Improvesystem functionalityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the industrial control system into multiple security zones based on risk levels. Devices are grouped into different zones (e.g., high-risk, medium-risk, low-risk) allowing differentiated security management strategies for each zone, thus reducing overall management complexity while maintaining versatility

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an automated notification subsystem as an intermediary between device discovery and security management. This subsystem automatically discovers devices, assesses their security risks, generates notifications, and routes them to appropriate users, eliminating the need for operators to manually manage each device's security posture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If operators manually monitor security vulnerabilities in multiple devices, then security awareness is improved, but time consumption and operational efficiency deteriorate

Engineering Contradiction:
Improvesecurity awarenessVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service security monitoring where the notification subsystem automatically performs device discovery, risk assessment, and notification generation without requiring operator intervention. The system serves itself by autonomously identifying and reporting security vulnerabilities

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback mechanism where the notification subsystem continuously monitors devices, generates risk assessments, and provides automated notifications to users. This creates a closed-loop feedback system that maintains security awareness without consuming operator time

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive security monitoring is implemented across all devices, then security coverage is improved, but notification volume and information overload increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidinformation overload
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies local quality by providing differentiated notification content based on security zone and risk level. High-risk zones receive detailed, immediate notifications while low-risk zones receive summarized or less frequent notifications, ensuring appropriate information density for each context without overwhelming users

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10075474B2Notification subsystem for generating consolidated, filtered, and relevant security risk-based notifications
Publication Date: 2018.09.11 HONEYWELL INTERNATIONAL INC
  • US10075474B2 patent drawing
  • US10075474B2 patent drawing
  • US10075474B2 patent drawing

AI summary

This disclosure provides a notification subsystem for generating consolidated, filtered, and relevant security risk-based notifications. A method includes discovering multiple devices in a computing system. The method includes grouping the multiple devices into multiple security zones. The method includes generating a risk value identifying at least one cyber-security risk of the devices for one of the security zones. The method includes comparing the risk value to a threshold. The method includes automatically generating a notification for one or more users when the risk value violates the threshold.