Virtual IACS Malware Impact Assessment for DoS Vulnerability Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation and control systems face challenges in assessing and mitigating the impact of malicious software, which can cause denial of service and disrupt critical infrastructure, as existing methods are costly and ineffective in simulating unique industrial network behaviors.

Innovation Solution

A method and system for assessing the impact of malicious software on industrial automation and control systems by generating a configuration on a testing device, simulating interactions, and determining the degree of performance degradation, allowing for early identification of vulnerabilities and potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional methods are used to assess malicious software impact on industrial systems, then comprehensive security evaluation can be achieved, but the cost is high and the methods are ineffective in simulating unique industrial network behaviors

Engineering Contradiction:
Improvesecurity evaluation effectivenessVSAvoidassessment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates virtual copies of industrial control systems, network devices, and software components to form a simulated test environment. These virtual replicas allow malicious software assessment without requiring physical industrial systems, thereby reducing costs while maintaining evaluation effectiveness. The virtual environment accurately mimics industrial network behaviors and device interactions.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary virtualization layer between the assessment process and actual industrial systems. This intermediary environment acts as a mediator that enables comprehensive security evaluation while isolating real industrial systems from direct testing, thus reducing costs and risks associated with traditional assessment methods.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If virtualization technology is used to simulate industrial network behaviors, then assessment effectiveness is improved, but system complexity increases

Engineering Contradiction:
Improveassessment effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the virtualized assessment system to perform multiple functions within a unified platform: simulating various industrial network behaviors, deploying test malware, monitoring system responses, and generating assessment reports. This multi-functionality reduces overall system complexity compared to having separate specialized systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines multiple assessment capabilities and virtualized components into an integrated testing environment. By merging network simulation, malware execution, and impact analysis functions into a single cohesive system, the patent manages complexity while maintaining high assessment effectiveness.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If comprehensive testing of malicious software is performed, then vulnerability identification is improved, but testing time and resources increase

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidtesting time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary setup of the virtualized test environment, pre-configuring industrial network simulations, device virtualizations, and assessment protocols before actual malicious software testing begins. This preliminary action reduces the time required during the actual comprehensive testing phase while maintaining high vulnerability identification accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous monitoring and assessment throughout the malicious software testing process, allowing real-time detection of vulnerabilities and system impacts. This continuous action enables comprehensive testing without significant time loss, as the system continuously gathers and analyzes data throughout the test execution.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11599443B2System and method for assessing an impact of malicious software causing a denial of service of components of industrial automation and control systems
Publication Date: 2023.03.07 AO KASPERSKY LAB
  • US11599443B2 patent drawing
  • US11599443B2 patent drawing
  • US11599443B2 patent drawing

AI summary

Disclosed herein are systems and methods for assessing an impact of malicious software causing a denial of service of components of industrial automation and control systems (IACS). In one aspect, an exemplary method comprises, generating a configuration of the IACS on a testing device based on specifications, obtaining a set of investigated software, where the set includes at least one sample of one malicious software, testing the generated configuration using the received set of investigated software, identifying occurrences of denials of service of the components of the testing device which are used to simulate the generated configuration, determining an impact of the malicious software on the generated configuration, and a degree of degradation of a performance of the generated configuration of IACS, and pronouncing a verdict as to a danger of the malicious software for the generated configuration of IACS based on the determined impact of the malicious software.