IP Library › Granted Patent US 11,568,056
Granted Patent B2
US 11,568,056 · App. 16/590,793 · Granted Jan 31, 2023

Methods and apparatuses for vulnerability detection and maintenance prediction in industrial control systems using hash data analytics

Inventors: Ganesh Gadhe (Phoenix, AZ); Eric Knapp (Boston, MA); Virgil Mehalek (Dover, NH); Doug Swain (Dover, NH)
Assignee: Honeywell International Inc.
G06F21/577G05B19/0425G06F16/9014G06F16/953
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,568,056
App. No.
16/590,793
Granted
Jan 31, 2023
Kind
B2
Abstract

Method, apparatus and computer program product for detecting vulnerability and predicting maintenance in an industrial control system are described herein.

Claims (38)

1. A method for detecting vulnerability in an industrial control system, comprising:

receiving a hash query in response to a portable storage device being communicatively coupled to a secure media exchange node, wherein the hash query comprises a file hash generated at the secure media exchange node based at least in part on one or more industrial control files stored on the portable storage device and associated with at least one of one or more ICS computing components in an industrial control system (ICS);

querying an ICS computing component hash information database based on the hash query to generate one or more ICS computing component information items associated with at least one of the one or more ICS computing components by comparing the hash query with one or more hashes stored in the ICS computing component hash information database;

generating a vulnerability analysis regarding the industrial control system based on the one or more ICS computing component information items; and

outputting the vulnerability analysis to a secure media exchange vulnerability portal associated with the secure media exchange node.

2. The method of claim 1 , wherein the ICS computing component hash information database is configured to store at least one or more security threat hashes representing one or more security threats associated with one or more industrial control files, and wherein the method further comprises:

upon determining that the file hash in the hash query matches at least one of the one or more security threat hashes, generating one or more threat indicators representing the one or more security threats in the ICS system based on the one or more ICS computing component information items.

3. The method of claim 2 , wherein the one or more security threats are each associated with one of the one or more ICS computing components.

4. The method of claim 2 , wherein the one or more security threats are one or more of: one or more known security vulnerabilities, one or more viruses, or one or more trojans.

5. The method of claim 1 , wherein the ICS computing component hash information database is configured to store one or more hashes associated with one or more industrial control files, and wherein the method further comprises:

determining one or more predictive indicators associated with at least one of the one or more ICS computing components; and

generating the vulnerability analysis based on the one or more predictive indicators.

6. The method of claim 5 , wherein the one or more predictive indicators include one or more of: a version number associated with at least one of the one or more industrial control files, an updated timestamp associated with at least one of the one or more industrial control files, or an outdated file flag representing that one or more files associated with at least one of the one or more industrial control files is not in the one or more industrial control files.

7. The method of claim 1 , wherein the secure media exchange vulnerability portal is a web-based portal installed on the secure media exchange node.

8. The method of claim 1 , wherein the secure media exchange vulnerability portal is associated with the ICS computing component hash information database.

9. The method of claim 1 , wherein the one or more ICS computing components do not have access to the world wide web while the ICS is in operation.

10. The method of claim 1 , further comprising,

querying the ICS computing component hash information database based on the hash query to identify at least one component of the one or more ICS computing components; and

storing the identified component in an ICS computing components model associated with the ICS.

11. An apparatus configured to programmatically detect vulnerability in an industrial control system, the apparatus comprising at least a processor, and a memory associated with the processor having computer coded instructions therein, with the computer coded instructions configured to, when executed by the processor, cause the apparatus to:

receive a hash query in response to a portable storage device being communicatively coupled to a secure media exchange node, wherein the hash query comprises a file hash generated at the secure media exchange node based at least in part on one or more industrial control files stored on the portable storage device and associated with at least one of one or more ICS computing components in an industrial control system (ICS);

query an ICS computing component hash information database based on the hash query to generate one or more ICS computing component information items associated with at least one of the one or more ICS computing components by comparing the hash query with one or more hashes stored in the ICS computing component hash information database;

generate a vulnerability analysis regarding the industrial control system based on the one or more ICS computing component information items; and

output the vulnerability analysis to a secure media exchange vulnerability portal associated with the secure media exchange node.

12. The apparatus of claim 11 , wherein the ICS computing component hash information database is configured to store at least one or more security threat hashes representing one or more security threats associated with one or more industrial control files, and wherein the computer coded instructions are further configured to, when executed by the processor, cause the apparatus to:

upon determining that the file hash in the hash query matches at least one of the one or more security threat hashes, generate one or more threat indicators representing the one or more security threats in the ICS system based on the one or more ICS computing component information items.

13. The apparatus of claim 12 , wherein the one or more security threats are each associated with one of the one or more ICS computing components.

14. The apparatus of claim 12 , wherein the one or more security threats are one or more of: one or more known security vulnerabilities, one or more viruses, or one or more trojans.

15. The apparatus of claim 11 , wherein the ICS computing component hash information database is configured to store one or more hashes associated with one or more industrial control files, and wherein the computer coded instructions are further configured to, when executed by the processor, cause the apparatus to:

determine one or more predictive indicators associated with at least one of the one or more ICS computing components; and

generate the vulnerability analysis based on the one or more predictive indicators.

16. The apparatus of claim 15 , wherein the one or more predictive indicators include one or more of: a version number associated with at least one of the one or more industrial control files, an update timestamp associated with at least one of the one or more industrial control files, or an outdated file flag representing that one or more files associated with at least one of the one or more industrial control files is not in the one or more industrial control files.

17. The apparatus of claim 11 , wherein the secure media exchange vulnerability portal is a web-based portal installed on the secure media exchange node.

18. The apparatus of claim 11 , wherein the secure media exchange vulnerability portal is associated with the ICS computing component hash information database.

19. The apparatus of claim 11 , wherein the one or more ICS computing components do not have access to the world wide web while the ICS is in operation.

20. The apparatus of claim 11 , wherein the computer coded instructions are further configured to, when executed by the processor, cause the apparatus to:

query the ICS computing component hash information database based on the hash query to identify at least one component of the one or more ICS computing components; and

store the identified component in an ICS computing components model associated with the ICS.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2020
From: GADHE, GANESH; KNAPP, ERIC; MEHALEK, VIRGIL; SWAIN, DOUG
To: HONEYWELL INTERNATIONAL INC.
Reel/Frame 052307/0891 →
Continuity (1)
Related Publication 20210103663A1 · Apr 8, 2021