IP Library › Granted Patent US 12,549,519
Granted Patent B2
US 12,549,519 · App. 18/592,723 · Granted Feb 10, 2026

Security system, device, and method for protecting control systems

Inventors: Rick A. Jones (Charlottesville, VA); Edward C. Suhler (Earlysville, VA); Daniel D. Park (Charlottesville, VA); John Mark Baggett (Deer Park, TX); Gary W. Huband (Crozet, VA); Paul D. Robertson (Shenandoah, VA); Austin C. Suhler (Earlysville, VA); Casey Silver (Forest, VA)
Assignee: ServiceNow, Inc.
H04L63/0245G06N20/00H04L41/06H04L63/308H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,519
App. No.
18/592,723
Filed
Mar 1, 2024
Granted
Feb 10, 2026
Kind
B2
Art Unit
2498
USPC
726/11
Abstract

A protection system, method, and a security device can protect an operational technology (OT) system having connected hardware equipment, including at least an interface that can receive a control communication and an industrial control device (ICD) for controlling at least one industrial device. They feature tasks/steps that receive control communication from the communication interface, determine whether the received control communication contains an undesirable control command, and either pass or block the received control communication to the ICD depending on whether the received control communication contains an undesirable control command. The security device can be disposed between a source of communication in an OT network and the ICD for protection.

Claims (64)

1 . A method of protecting an operational technology (OT) system having connected hardware equipment, including at least a communication interface configured to receive a control communication, the method comprising:

receiving a maintenance request for lowering a security state of the OT system from the communication interface;

determining whether the received maintenance request is valid;

blocking the maintenance request when the received maintenance request is determined to be invalid;

lowering the security state of the OT system when the received maintenance request is determined to be valid;

receiving the control communication for the OT system from the communication interface;

determining whether the received control communication contains an undesirable control command;

blocking the received control communication to the OT system when the received control communication is determined to contain the undesirable control command; and

passing the received control communication to the OT system when the received control communication is determined not to contain the undesirable control command.

2 . The method according to claim 1 , further comprising storing, in a storage device, forensic data for the OT system.

3 . The method according to claim 1 , further comprising storing, in a storage device, forensic data when the received maintenance request is determined to be invalid or when the received control communication is determined to contain an undesirable control command.

4 . The method according to claim 1 ,

wherein the OT system further includes at least one human machine interface (HMI), and

wherein the method further comprises sending an alarm to the HMI when the received maintenance request is determined to be invalid or when the received control communication is determined to contain an undesirable control command.

5 . The method according to claim 1 , further comprising:

validating the received maintenance request,

wherein determining the received maintenance request is valid is based on at least one of a predefined maintenance schedule, authorization provided by a system administrator, or authentication information of a maintenance provider.

6 . The method according to claim 1 , further comprising:

analyzing the received control communication,

wherein determining the received control communication contains an undesirable control command is based on at least one of whether the control communication is received from a validated network source or content of the control communication.

7 . The method according to claim 1 ,

wherein the OT system includes a security device that intercepts communication between the OT system and the communication interface, and

wherein the security device includes a memory and a processor configured to implement instructions stored in the memory to execute the method.

8 . The method according to claim 1 , further comprising authenticating communication between the OT system and the communication interface.

9 . The method according to claim 1 , further comprising learning a system model that encodes normal behavior patterns of system processes operating in the OT system and the hardware equipment in the OT system,

wherein determining the received control communication contains an undesirable command includes identifying an anomalous system behavior or deviation in system state that indicates a potential cyber incident or a general system failure based on the learned system model.

10 . The method according to claim 9 , wherein learning the system model uses artificial intelligence (AI) hosted algorithms for learning the normal behavior patterns for detecting inconsistent system state information.

11 . A protection system for an operational technology (OT) system, the protection system comprising:

a communication interface that communicates with a source that provides control communication; and

a security device that controls communication between the OT system and the communication interface,

wherein the security device includes a memory configured to store instructions and a processor configured to execute the instructions stored in the memory to perform a set of operations:

receiving a maintenance request for lowering a security state of the OT system from the communication interface;

a first determining task of determining whether the received maintenance request is valid;

blocking the maintenance request when the received maintenance request is determined to be invalid;

lowering the security state of the OT system when the received maintenance request is determined to be valid;

receiving the control communication for the OT system from the communication interface;

determining whether the received control communication contains an undesirable control command;

blocking the received control communication to the OT system when the received control communication is determined to contain the undesirable control command; and

passing the received control communication to the OT system when the received control communication is determined not to contain the undesirable control command.

12 . The protection system according to claim 11 , wherein the set of operations further comprises storing, in a storage device, forensic data for the OT system.

13 . The protection system according to claim 11 , wherein the set of operations further comprises storing, in a storage device, forensic data when the received maintenance request is determined to be invalid or when the received control communication is determined to contain an undesirable control command.

14 . The protection system according to claim 11 ,

wherein the OT system further includes at least one human machine interface (HMI); and

wherein the set of operations further comprises sending an alarm to the HMI when the received maintenance request is determined to be invalid or when the received control communication is determined to contain an undesirable control command.

15 . The protection system according to claim 11 ,

wherein the set of operations further comprises validating the received maintenance request, and

wherein determining the received maintenance request is valid is based on at least one of a predefined maintenance schedule, authorization provided by a system administrator, or authentication information of a maintenance provider.

16 . The protection system according to claim 11 ,

wherein the set of operations further comprises analyzing the received control communication, and

wherein determining the received control communication contains an undesirable control command is based on at least one of whether the control communication is received from a validated network source or the content of the control communication.

17 . The protection system according to claim 11 , wherein the set of operations further comprises authenticating communication between the OT system and the communication interface.

18 . The protection system according to claim 11 ,

wherein the set of operations further comprises learning a system model that encodes normal behavior patterns of system processes operating in the OT system and the hardware equipment in the OT system, and

wherein determining the received control communication contains an undesirable command includes identifying an anomalous system behavior or a deviation in system state that indicates a potential cyber incident or a general system failure based on the learned system model.

19 . The protection system according to claim 18 , wherein learning the system model uses artificial intelligence (AI) hosted algorithms for learning the normal behavior patterns detecting inconsistent system state information.

20 . A non-transitory computer readable storage medium comprising instructions for protecting an operational technology (OT) system having connected hardware equipment, including at least a communication interface configured to receive a control communication, that, when executed, cause at least one processor to perform a set of operations comprising:

receiving a maintenance request for lowering a security state of the OT system from the communication interface;

determining whether the received maintenance request is valid;

blocking the maintenance request when the received maintenance request is determined to be invalid;

lowering the security state of the OT system when the received maintenance request is determined to be valid;

receiving the control communication for the OT system from the communication interface;

determining whether the received control communication contains an undesirable control command;

blocking the received control communication to the OT system when the received control communication is determined to contain the undesirable control command; and

passing the received control communication to the OT system when the received control communication is determined not to contain the undesirable control command.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2025
From: MISSION SECURE, INC.
To: SERVICENOW, INC.
Reel/Frame 070460/0898 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2024
From: JONES, RICK A.; SUHLER, EDWARD C.; PARK, DANIEL D.; BAGGETT, JOHN MARK; HUBAND, GARY W.; ROBERTSON, PAUL D.; SUHLER, AUSTIN C.; SILVER, CASEY
To: MISSION SECURE, INC.
Reel/Frame 066613/0929 →
Continuity (6)
Continuation In Part 18483806 · Oct 10, 2023
Continuation 17475674 · Sep 15, 2021
Continuation 16702944 · Dec 4, 2019
Continuation In Part 15414441 · Jan 24, 2017
Provisional Application 62412143 · Oct 24, 2016
Related Publication 20240430232A1 · Dec 26, 2024
References Cited (48)
US 5566326A · Hirsch · 1996 [cited by examiner]
US 6289457B1 · Bishop · 2001 [cited by examiner]
US 8782771B2 · Chen · 2014 [cited by applicant]
US 9613512B2 · Williams · 2017 [cited by applicant]
US 9973527B2 · Bhargav-Spantzel · 2018 [cited by examiner]
US 10049564B2 · Tegeder · 2018 [cited by applicant]
US 10205733B1 · Park · 2019 [cited by applicant]
US 10530749B1 · Park · 2020 [cited by applicant]
US 11153277B2 · Park · 2021 [cited by applicant]
US 20050206514A1 · Zanovitch · 2005 [cited by examiner]
US 20090299542A1 · Nuqui · 2009 [cited by applicant]
US 20110039237A1 · Skare · 2011 [cited by examiner]
US 20110086280A1 · Roustaei · 2011 [cited by examiner]
US 20110154438A1 · Price · 2011 [cited by examiner]
US 20110314538A1 · Huang · 2011 [cited by examiner]
US 20120266209A1 · Gooding · 2012 [cited by applicant]
US 20120323381A1 · Yadav · 2012 [cited by applicant]
US 20140109182A1 · Smith · 2014 [cited by applicant]
US 20140157400A1 · Kwon · 2014 [cited by examiner]
US 20140337086A1 · Asenjo · 2014 [cited by applicant]
US 20140344896A1 · Pak · 2014 [cited by examiner]
US 20150005968A1 · Dorough · 2015 [cited by applicant]
US 20150074820A1 · Toda · 2015 [cited by applicant]
US 20150161155A1 · Pletcher · 2015 [cited by applicant]
US 20150277406A1 · Maturana · 2015 [cited by applicant]
US 20150281278A1 · Gooding · 2015 [cited by applicant]
US 20150281453A1 · Maturana · 2015 [cited by applicant]
US 20150287318A1 · Nair · 2015 [cited by applicant]
US 20150350914A1 · Baxley · 2015 [cited by applicant]
US 20160127931A1 · Baxley · 2016 [cited by applicant]
US 20160149861A1 · Batke · 2016 [cited by applicant]
US 20160182309A1 · Maturana · 2016 [cited by applicant]
US 20160210832A1 · Williams · 2016 [cited by applicant]
US 20160330225A1 · Kroyzer · 2016 [cited by applicant]
US 20160359873A1 · Chand · 2016 [cited by examiner]
US 20170025040A1 · Maturana · 2017 [cited by applicant]
US 20170052524A1 · Kunz · 2017 [cited by applicant]
US 20190349426A1 · Smith · 2019 [cited by applicant]
US 20200106743A1 · Park · 2020 [cited by applicant]
US 20220006781A1 · Park · 2022 [cited by applicant]
US 20220187847A1 · Cella · 2022 [cited by applicant]
US 20230186201A1 · Cella · 2023 [cited by applicant]
Office Action issued in U.S. Appl. No. 15/414,441 mailed Apr. 4, 2019. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 15/414,441 mailed Aug. 22, 2019. [cited by applicant]
Office Action issued in U.S. Appl. No. 16/702,944 mailed Apr. 1, 2021. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 16/702,944 mailed Jun. 15, 2021. [cited by applicant]
Office Action issued in U.S. Appl. No. 17/475,674 mailed Jan. 6, 2023. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 17/475,674 mailed Jul. 6, 2023. [cited by applicant]