Industrial Security Zone Segmentation for Risk Data Collection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial process control and automation systems face increasing cybersecurity concerns due to unaddressed security vulnerabilities, making it difficult to quickly determine potential sources of risk and disrupt operations or cause unsafe conditions.
Innovation Solution
An infrastructure monitoring tool, utilizing a risk manager system that discovers and groups devices into security zones, collects and categorizes risk data using System Center Operations Manager (SCOM) software, and calculates risk values based on stored information, providing alerts and events associated with unique identifier values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive security monitoring is implemented across all devices, then security coverage is improved, but system complexity increases
Solution Approach 1:
The patent segments the industrial control system into multiple security zones (OT zones, IT zones, DMZ) and monitors each zone separately through dedicated collectors. This segmentation allows comprehensive security monitoring while reducing overall system complexity by organizing monitoring functions into manageable zones with specific monitoring responsibilities.
Solution Approach 2:
The patent introduces a centralized risk manager system that acts as an intermediary between individual security monitoring components and the overall security architecture. The risk manager collects data from multiple collectors, standardizes the data formats, and provides unified risk assessment, thereby simplifying the architecture while maintaining comprehensive coverage.
2Measurement precision
If detailed risk data collection is performed, then risk assessment accuracy is improved, but data processing time increases
Solution Approach 1:
The patent performs preliminary data collection and categorization at the security zone level before final risk assessment. Collectors gather and pre-categorize data locally, and the risk manager pre-processes this data into standardized formats. This preliminary action reduces the time required for final risk assessment while maintaining detailed and accurate risk data collection.
Solution Approach 2:
The patent implements local data collection and processing at each security zone level, where each zone's collector handles data specific to that zone's devices and protocols. This local quality approach allows detailed data collection tailored to each zone's specific requirements while reducing the processing burden on the central risk manager, thereby decreasing overall processing time.
3Quantity of substance
If multiple data types are collected from diverse devices, then information completeness is improved, but data standardization difficulty increases
Solution Approach 1:
The patent creates a universal data collection framework where the risk manager system can collect multiple data types (configuration data, operational data, security data) from diverse devices across different security zones. The standardized data formats and unified risk assessment methodology provide multi-functionality, allowing the same system to handle various device types and data formats without increasing standardization difficulty.
Solution Approach 2:
The patent employs parameter changes in data collection by adapting collection parameters to match the specific protocols and data formats of different device types within each security zone. The system modifies collection parameters dynamically based on device type, zone location, and data requirements, enabling comprehensive data collection while maintaining standardization through consistent parameter transformation at the risk manager level.
Data Source
AI summary
This disclosure provides an infrastructure monitoring tool, and related systems and methods, for collecting industrial process control and automation system risk data, and other data. A method includes discovering multiple devices in a computing system by a risk manager system. The method includes grouping the multiple devices into multiple security zones by the risk manager system. The method includes, for each security zone, causing one or more devices in that security zone to provide information to the risk manager system identifying alerts and events associated with the one or more devices. The method includes storing the information, by the risk manager system, in association with unique identifier values, the unique identifier values identifying different types of information.


