Smart Network Switching for Industrial Control Traffic Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional technologies for protecting industrial control systems from cyber-attacks are difficult to scale and manage, especially in larger systems, and often assume endpoints are secure, which is a flawed assumption, limiting their effectiveness in preventing unauthorized access and attacks.
Innovation Solution
A smart network switching system utilizing software-defined networking that monitors and controls industrial control system traffic at the application layer, enabling real-time creation and modification of rules, out-of-band monitoring and control, and scalable management of endpoints to prevent unauthorized access and attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional monitoring technologies are used, then basic traffic monitoring is achieved, but scalability and remote management capability are poor
Solution Approach 1:
The patent introduces a software-defined networking (SDN) controller as an intermediary between the network switches and the monitoring system. This controller abstracts the complex switching operations and provides centralized management, enabling scalable deployment across large networks while maintaining comprehensive security monitoring. The SDN architecture separates the control plane from the data plane, allowing complex security policies to be managed remotely without complicating the underlying network infrastructure.
2Device complexity
If endpoint security assumptions are made, then system complexity is reduced, but security effectiveness deteriorates due to compromised endpoints
Solution Approach 1:
The patent places an intermediary monitoring system at the network layer between endpoints and their destinations. This intermediary can inspect, filter, and control traffic without requiring trust in the endpoint systems. By operating at the network level rather than relying on endpoint security, the system maintains simplicity while achieving robust security that is independent of endpoint integrity.
3Reliability
If bump-in-the-wire devices are deployed for equipment protection, then individual equipment security is improved, but scalability to larger systems is poor
Solution Approach 1:
The patent implements a universal network switch architecture that can serve multiple functions simultaneously: data forwarding, security monitoring, access control, and traffic management. This multi-functional switch replaces the need for multiple specialized devices like bump-in-the-wire protectors, providing comprehensive equipment security while enabling scalable deployment across entire networks through a single standardized platform.
4Reliability
If span port monitoring is used, then traffic monitoring capability is achieved, but remote management and control capability are limited
Solution Approach 1:
The patent replaces the mechanical/physical approach of span port configuration with software-defined networking control. Instead of manually configuring span ports on physical switches, the system uses an SDN controller to programmatically manage traffic monitoring and access control policies. This substitution enables remote management and dynamic policy changes without physical access to the switches, while maintaining comprehensive traffic monitoring capability.
Data Source
AI summary
A method of monitoring and controlling network traffic within an industrial control system including receiving one or more data packets at a smart network switching system operating software-defined networking, analyzing the one or more data packets at a protocol level within a control plane of the software-defined networking, based on the analysis, determining whether the one or more data packets are authorized data packets, and forwarding a data packet of the one or more data packets to a destination device within a data plane of the software-defined networking upon determining that the data packet is an authorized data packet. The method further includes providing information related to the analysis of the one or more data packets to an out-of-band monitoring and control system for display to a user, and receiving a response communication from the out-of-band monitoring and control system indicating whether the one or more data packets are authorized data packets.


