IP Library › Granted Patent US 12,603,910
Granted Patent B2
US 12,603,910 · App. 17/987,487 · Granted Apr 14, 2026

Cybersecurity risk assessment and mitigation for industrial control systems

Inventor: Tarun Gupta (Bangalore, IN)
Assignee: HONEYWELL INTERNATIONAL INC.
H04L63/1433H04L63/1416G05B19/0428G05B19/41835G06F21/55
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,910
App. No.
17/987,487
Granted
Apr 14, 2026
Kind
B2
Abstract

Various embodiments described herein relate to cybersecurity risk assessment and mitigation for industrial control systems. In an embodiment, a request to perform a cybersecurity assessment of a set of industrial assets is received. Additionally, the set of industrial assets are correlated to industrial asset data associated with the set of industrial assets and a first industrial asset feature set is compared to a cybersecurity rules set to determine a cybersecurity threat level indicator for respective industrial assets from the set of industrial assets. In response to the cybersecurity threat level indicator satisfying a defined criterion, one or more cybersecurity countermeasure actions for the respective industrial assets are then determined based on a comparison between a second industrial asset feature set and a predefined industrial asset feature set for a set of predefined industrial assets associated with one or more predefined cybersecurity countermeasures.

Claims (63)

1 . A system, comprising:

one or more processors;

a memory; and

one or more programs stored in the memory, the one or more programs comprising instructions configured to:

generate a knowledge graph that defines at least a portion of a network topology for an industrial control system, wherein the knowledge graph defines nodes associated with the set of industrial assets of the industrial control system and links associated with network connections of the industrial control system;

monitor network traffic broadcasted to a set of industrial assets of the industrial control system to generate industrial asset data associated with the set of industrial assets;

in response to a detection of a change in the industrial control system based on the network traffic, scan the knowledge graph to determine modeled network topology information for the industrial control system;

determine a set of asset descriptors respectively describing an industrial asset from the set of industrial assets based on the modeled network topology information;

correlate, based on the set of asset descriptors, respective industrial assets from the set of industrial assets to respective portions of the industrial asset data associated with the set of industrial assets;

compare a first industrial asset feature set from the industrial asset data to a cybersecurity rules set stored in an asset risk assessment signature repository to determine a cybersecurity threat level indicator for the respective industrial assets from the set of industrial assets;

in response to a determination that that the cybersecurity threat level indicator for the respective industrial assets satisfies a defined criterion, determine one or more cybersecurity countermeasure actions for the respective industrial assets based on a comparison between a second industrial asset feature set from the industrial asset data and a predefined industrial asset feature set for a set of predefined industrial assets associated with one or more predefined cybersecurity countermeasures; and

cause performance of the one or more cybersecurity countermeasure actions associated with the industrial control system.

2 . The system of claim 1 , the one or more programs further comprising instructions configured to:

scan the knowledge graph in response to an action initiated via a processing unit associated with the set of industrial assets.

3 . The system of claim 1 , the one or more programs further comprising instructions configured to:

determine the set of asset descriptors based on textual analysis of data provided via an electronic interface of a computing device.

4 . The system of claim 1 , the one or more programs further comprising instructions configured to:

provide the first industrial asset feature set to a machine learning model configured to determine the cybersecurity threat level indicator based on the cybersecurity rules set.

5 . The system of claim 1 , the one or more programs further comprising instructions configured to:

provide a threat level mapping of a network topology associated with the industrial control system based on the one or more cybersecurity countermeasure actions.

6 . The system of claim 1 , the one or more programs further comprising instructions configured to:

provide asset information for a new industrial asset to replace one or more industrial assets in the industrial control system in response to the determination that the cybersecurity threat level indicator for the respective industrial assets satisfies the defined criterion.

7 . The system of claim 1 , the one or more programs further comprising instructions configured to:

generate an alert for an electronic interface of a computing device in response to the determination that the cybersecurity threat level indicator for the respective industrial assets satisfies the defined criterion.

8 . The system of claim 1 , the one or more programs further comprising instructions configured to:

generate a ranking of cybersecurity countermeasure actions in response to the determination that the cybersecurity threat level indicator for the respective industrial assets satisfies the defined criterion.

9 . The system of claim 1 , the one or more programs further comprising instructions configured to:

determine the one or more cybersecurity countermeasure actions for the respective industrial assets responsive to a comparison between (i) the cybersecurity threat level indicator for the respective industrial assets and (ii) a predefined cybersecurity threat indicator associated with a particular type of cybersecurity threat level.

10 . A computer-implemented method, comprising:

generating a knowledge graph that defines at least a portion of a network topology for an industrial control system, wherein the knowledge graph defines nodes associated with the set of industrial assets of the industrial control system and links associated with network connections of the industrial control system;

monitoring network traffic broadcasted to a set of industrial assets of the industrial control system to generate industrial asset data associated with the set of industrial assets;

in response to a detection of a change in the industrial control system based on the network traffic, scanning the knowledge graph to determine modeled network topology information for the industrial control system;

determining a set of asset descriptors respectively describing an industrial asset from the set of industrial assets based on the modeled network topology information;

correlating, based on the set of asset descriptors, respective industrial assets from the set of industrial assets to respective portions of the industrial asset data associated with the set of industrial assets;

comparing a first industrial asset feature set from the industrial asset data to a cybersecurity rules set stored in an asset risk assessment signature repository to determine a cybersecurity threat level indicator for the respective industrial assets from the set of industrial assets;

in response to a determination that that the cybersecurity threat level indicator for the respective industrial assets satisfies a defined criterion, determining one or more cybersecurity countermeasure actions for the respective industrial assets based on a comparison between a second industrial asset feature set from the industrial asset data and a predefined industrial asset feature set for a set of predefined industrial assets associated with one or more predefined cybersecurity countermeasures; and

causing performance of the one or more cybersecurity countermeasure actions associated with the industrial control system.

11 . The computer-implemented method of claim 10 , wherein the scanning the knowledge graph comprises scanning the knowledge graph in response to an action initiated via a processing unit associated with the set of industrial assets.

12 . The computer-implemented method of claim 10 , further comprising:

determining the set of asset descriptors based on textual analysis of data provided via an electronic interface of a computing device.

13 . The computer-implemented method of claim 10 , further comprising:

providing the first industrial asset feature set to a machine learning model configured to determine the cybersecurity threat level indicator based on the cybersecurity rules set.

14 . The computer-implemented method of claim 10 , further comprising:

providing a threat level mapping of a network topology associated with the industrial control system based on the one or more cybersecurity countermeasure actions.

15 . The computer-implemented method of claim 10 , further comprising:

providing asset information for a new industrial asset to replace one or more industrial assets in the industrial control system in response to the determination that the cybersecurity threat level indicator for the respective industrial assets satisfies the defined criterion.

16 . The computer-implemented method of claim 10 , further comprising:

generating an alert for an electronic interface of a computing device in response to the determination that the cybersecurity threat level indicator for the respective industrial assets satisfies the defined criterion.

17 . The computer-implemented method of claim 10 , further comprising:

determining the one or more cybersecurity countermeasure actions for the respective industrial assets responsive to a comparison between (i) the cybersecurity threat level indicator for the respective industrial assets and (ii) a predefined cybersecurity threat indicator associated with a particular type of cybersecurity threat level.

18 . A computer program product comprising at least one computer-readable storage medium having program instructions embodied thereon, the program instructions executable by a processor to cause the processor to:

generate a knowledge graph that defines at least a portion of a network topology for an industrial control system, wherein the knowledge graph defines nodes associated with the set of industrial assets of the industrial control system and links associated with network connections of the industrial control system;

monitor network traffic broadcasted to a set of industrial assets of the industrial control system to generate industrial asset data associated with the set of industrial assets;

in response to a detection of a change in the industrial control system based on the network traffic, scan the knowledge graph to determine modeled network topology information for the industrial control system;

determine a set of asset descriptors respectively describing an industrial asset from the set of industrial assets based on the modeled network topology information;

correlate, based on the set of asset descriptors, respective industrial assets from the set of industrial assets to respective portions of the industrial asset data associated with the set of industrial assets;

compare a first industrial asset feature set from the industrial asset data to a cybersecurity rules set stored in an asset risk assessment signature repository to determine a cybersecurity threat level indicator for the respective industrial assets from the set of industrial assets;

in response to a determination that that the cybersecurity threat level indicator for the respective industrial assets satisfies a defined criterion, determine one or more cybersecurity countermeasure actions for the respective industrial assets based on a comparison between a second industrial asset feature set from the industrial asset data and a predefined industrial asset feature set for a set of predefined industrial assets associated with one or more predefined cybersecurity countermeasures; and

cause performance of the one or more cybersecurity countermeasure actions associated with the industrial control system.

19 . The computer program product of claim 18 , the program instructions further executable by the processor to cause the processor to:

determine the one or more cybersecurity countermeasure actions for the respective industrial assets responsive to a comparison between (i) the cybersecurity threat level indicator for the respective industrial assets and (ii) a predefined cybersecurity threat indicator associated with a particular type of cybersecurity threat level.

20 . The computer program product of claim 18 , the program instructions further executable by the processor to cause the processor to:

scan the knowledge graph in response to an action initiated via a processing unit associated with the set of industrial assets.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2022
From: GUPTA, TARUN
To: HONEYWELL INTERNATIONAL INC.
Reel/Frame 061780/0672 →
Continuity (1)
Related Publication 20240163304A1 · May 16, 2024
References Cited (6)
US 10176320B1 · McMurdie · 2019 [cited by examiner]
US 20130031037A1 · Brandt · 2013 [cited by examiner]
US 20130104236A1 · Ray · 2013 [cited by examiner]
US 20140137257A1 · Martinez · 2014 [cited by examiner]
US 20140337086A1 · Asenjo · 2014 [cited by examiner]
US 20170228589A1 · Parapurath · 2017 [cited by examiner]