IP Library Granted Patent US 10,261,489
Granted Patent B2
US 10,261,489 · App. 14/686,878 · Granted Apr 16, 2019

Detection of mis-configuration and hostile attacks in industrial control networks using active querying

Inventor: Mille Gandelsman (Haifa, IL)
Assignee: INDEGY LTD.
G05B19/058G05B19/4185G06F21/51G06F21/572G05B2219/13197G05B2219/24159G05B2219/31203G05B2219/31362G05B2219/31436Y02P90/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,261,489
App. No.
14/686,878
Granted
Apr 16, 2019
Kind
B2
Abstract

A method includes requesting a controller, which controls one or more field devices in an industrial control network, to report code currently used by the controller for controlling the field devices. The code reported by the controller is compared with a stored baseline version of the code, and a notification is issued upon detecting a discrepancy between the code reported by the controller and the baseline version.

Claims (23)

1. A method, comprising:

in a management appliance that is connected to an industrial control network in which a controller controls one or more field devices, running in parallel a passive monitoring process and an active querying process,

wherein the passive monitoring process comprises (i) continuously intercepting traffic exchanged over the industrial control network, (ii) checking whether the intercepted traffic comprises a code-update transaction that is sent to the controller and based on which the controller updates a code currently used for controlling the field devices, (iii) if the traffic comprises the code-update transaction, checking whether the code-update transaction is legitimate, and (iv) if the code-update transaction is legitimate, using the code-update transaction to update an up-to-date trustworthy baseline version of the code stored in the management appliance,

and wherein the active querying process comprises (i) requesting the controller to report the code currently used by the controller for controlling the field devices, and (ii) comparing the code reported by the controller with the baseline version of the code; and

interacting between the passive monitoring process and the active querying process, including issuing a notification (i) if the active querying process detects a discrepancy between the code reported by the controller and the baseline version that is being continuously updated by the passive monitoring process, or (ii) if the passive monitoring process detects that the code-update transaction is illegitimate.

2. The method according to claim 1 , wherein the code comprises at least one code type selected from a group of types consisting of firmware, application logic and configuration parameters of the controller.

3. The method according to claim 1 , wherein comparing the reported code to the baseline version comprises comparing a first digest of the reported code with a second digest of the baseline version.

4. The method according to claim 1 , wherein requesting the controller to report the code comprises emulating an engineering protocol used for configuring the controller.

5. A management appliance connected to an industrial control network in which a controller controls one or more field devices, the management appliance comprising:

a memory; and

a processor, which is configured to:

run in parallel a passive monitoring process and an active querying process,

wherein the passive monitoring process (i) continuously intercepts traffic exchanged over the industrial control network, (ii) checks whether the intercepted traffic comprises a code-update transaction that is sent to the controller and based on which the controller updates a code currently used for controlling the field devices, (iii) if the traffic comprises the code-update transaction, checks whether the code-update transaction is legitimate, and (iv) if the code-update transaction is legitimate, uses the code-update transaction to update an up-to-date trustworthy baseline version of the code stored in the management appliance,

and wherein the active querying process (i) requests the controller to report the code currently used by the controller for controlling the field devices, and (ii) compares the code reported by the controller with the baseline version of the code; and

interact between the passive monitoring process and the active querying process, including issuing a notification (i) if the active querying process detects a discrepancy between the code reported by the controller and the baseline version that is being continuously updated by the passive monitoring process, or (ii) if the passive monitoring process detects that the code-update transaction is illegitimate.

6. The management appliance according to claim 5 , wherein the code comprises at least one code type selected from a group of types consisting of firmware, application logic and configuration parameters of the controller.

7. The management appliance according to claim 5 , wherein the processor is configured to compare the reported code to the baseline version by comparing a first digest of the reported code with a second digest of the baseline version.

8. The management appliance according to claim 5 , wherein the processor is configured to request the controller to report the code by emulating an engineering protocol used for configuring the controller.

9. A computer software product, the product comprising a tangible non-transitory computer-readable medium in which program instructions are stored, which instructions, when read by a processor in a management appliance connected to an industrial control network in which a controller controls one or more field devices, cause the processor to:

run in parallel a passive monitoring process and an active querying process,

wherein the passive monitoring process (i) continuously intercepts traffic exchanged over the industrial control network, (ii) checks whether the intercepted traffic comprises a code-update transaction that is sent to the controller and based on which the controller updates a code currently used for controlling the field devices, (iii) if the traffic comprises the code-update transaction, checks whether the code-update transaction is legitimate, and (iv) if the code-update transaction is legitimate, uses the code-update transaction to update an up-to-date trustworthy baseline version of the code stored in the management appliance,

and wherein the active querying process (i) requests the controller to report the code currently used by the controller for controlling the field devices, and (ii) compares the code reported by the controller with the baseline version of the code; and

interact between the passive monitoring process and the active querying process, including issuing a notification (i) if the active querying process detects a discrepancy between the code reported by the controller and the baseline version that is being continuously updated by the passive monitoring process, or (ii) if the passive monitoring process detects that the code-update transaction is illegitimate.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Jul 8, 2021
From: TENABLE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 056807/0546 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2020
From: INDEGY LTD.
To: TENABLE, INC.
Reel/Frame 052351/0519 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2015
From: GANDELSMAN, MILLE
To: INDEGY LTD.
Reel/Frame 035411/0321 →
Continuity (1)
Related Publication 20160306337A1 · Oct 20, 2016
Cited By (2)
US 12,536,536 US 12,548,021