System for securing a cyber-physical method
The invention relates to an industrial system comprising machines, systems for controlling machines connected by a first communication network, and a gateway intended to connect the first communication network to a second communication network. The gateway comprises a memory and comprises a processor configured to copy to the memory first data transmitted over the second communication network and relating to the operation of the machines.
1. An industrial system comprising machines, controllers for controlling machines connected by a first communication network and a gateway connecting the first communication network to a second communication network, the gateway comprising a memory and comprising a processor configured to:
copy to the memory first data transmitted to the second communication network and relating to the operation of the machines,
perform authentication of a user of a station connected to the second communication network, and
in response to a successful authentication, allow the station to read data stored in the memory of the gateway or to write data to the memory of the gateway without giving the station direct access to the machines,
the industrial system further comprising an analyser, configured to:
collect values of variables relating to the operation of the machines,
determine, for at least some of the variables, ranges of values from at least one first operational model of the machines,
detect at least one anomaly, if the value of at least one variable is outside of the range of values of said variable, said anomaly having a likelihood,
detect, from the at least one anomaly, at least one undesirable event, to which is allocated an impact on the industrial system, said impact having a severity,
determine, for each impact allocated to each of the at least one undesirable event, a likelihood, from a combination of likelihoods of the at least one anomaly detected,
provide, for each impact and the severity-likelihood combination thereof, a numerical value, and
determine an overall risk level of the industrial system from the numerical values obtained of the impacts of the at least one undesirable event detected.
2. The industrial system according to claim 1 , wherein the first data are provided by the controllers.
3. The industrial system according to claim 1 , wherein the processor is configured to write in the memory second data provided by the station connected to the second communication network.
4. The industrial system according to claim 3 , wherein the processor is configured to transmit to at least one of the controllers the second data written in the memory.
5. The industrial system according to claim 3 , wherein the authentication of the user of said station comprises implementing two distinct identification methods.
6. The industrial system according to claim 1 , comprising at least one network sensor configured to make a copy of third data circulating over the first communication network and connected to the analyser.
7. The industrial system according to claim 6 , wherein the analyser is configured to receive the third data, in order to classify the third data according to at least first and second categories, and in order to determine at least the first operational model from the third data of the first category and a second operational model from the third data of the second category.