IP Library › Granted Patent US 10,331,429
Granted Patent B2
US 10,331,429 · App. 15/237,872 · Granted Jun 25, 2019

Patch management for industrial control systems

Inventors: Leandro Pfleger de Aguiar (Robbinsville, NJ); Alberto Avritzer (Mountainside, NJ)
Assignee: SIEMENS AKTIENGESELLSCHAFT
G06F8/65G06F21/577G06N7/005G06Q10/06G06Q10/20H04L63/1433G05B19/4185G06F2221/033Y02P90/86
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,331,429
App. No.
15/237,872
Granted
Jun 25, 2019
Kind
B2
Abstract

For patch management of an industrial control system, predicted temporal evolution of risk due to vulnerability is provided to industrial control system operators to help schedule patching. A Markov chain representing the temporal evolution uses asset (e.g., industrial control system component) specific information to determine risk over time. This risk information may be used to prioritize and/or schedule patching. The operator is provided more information to help manage patching of the industrial control system, allowing better balancing of risk with manufacturing burden.

Claims (18)

1. A method for patch management of an industrial control system, the industrial control system operably connected to a plurality of assets, the method comprising:

determining criticality rankings for each of the plurality of assets;

acquiring a vulnerability information for each of the plurality of assets, the combination of the asset and its associated vulnerability information defining a pair;

modeling a temporal evolution of the vulnerability information for each pair with a Markov chain, each temporal evolution including at least three states for the vulnerability and predicted times of transition between the states;

acquiring a patch for at least one of the pairs;

determining a current state and a time to transition to a subsequent state for each of the pairs;

determining a risk level for each of the pairs, the risk level based on the current state and the criticality rankings for the pair; and

comparing the risk level for each pair to a threshold risk level and the predicted time to transition to the subsequent state to define a time period during which patches must be installed, wherein acquiring comprises acquiring Common Vulnerability Scoring System information as the vulnerability information, and wherein modeling comprises modeling the temporal evolution of an exploit code maturity of the Common Vulnerability Scoring System information, the at least three states being proof-of-concept, functional, and high of the exploit code maturity.

2. The method of claim 1 wherein acquiring comprises acquiring the vulnerability information for a programmable logic controller, a remote terminal unit, a supervisory control and acquisition system, or a human-machine interface system for a manufacturing process.

3. The method of claim 1 wherein acquiring further comprises acquiring a time from disclosure of the vulnerability and information about exploitation of the vulnerability.

4. The method of claim 1 wherein transmitting comprises transmitting the first state as a current state and the first predicted time as a time to reach a threshold risk of exploitation of the vulnerability.

5. The method of claim 1 wherein transmitting comprise transmitting probabilities for the at least three states and probabilities for the predicted times.

6. The method of claim 1 wherein determining comprises calculating an aging rate of the vulnerability and an aging probability from an average time to disclosure, and calculating a risk score distribution across the at least three states as a cost of the Markov chain.

7. The method of claim 1 wherein transmitting further comprises transmitting a schedule to install the patch on the industrial control system based on the first predicted time.

8. The method of claim 1 wherein determining comprises determining as a function of asset exposure, asset criticality, or both of the industrial control system.

9. The method of claim 1 wherein acquiring further comprises acquiring a patch installation rate, wherein modeling comprises modeling as a function of the patch installation rate, and wherein transmitting further comprises transmitting a predicted time in a highest risk of the at least three states before the patch is applied.

10. The method of claim 1 wherein transmitting comprises transmitting the first state and the first predicted time in a visual representation of the Markov chain.

11. The method of claim 1 wherein determining comprises determining for a current time and further comprising repeating the determining for a user selected time.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2016
From: SIEMENS CORPORATION
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 039972/0835 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2016
From: AVRITZER, ALBERTO; PFLEGER DE AGUIAR, LEANDRO
To: SIEMENS CORPORATION
Reel/Frame 039817/0357 →
Continuity (2)
Provisional Application 62214236 · Sep 4, 2015
Related Publication 20180136921A1 · May 17, 2018
Cited By (2)
US 12,294,509 US 12,556,465