Apparatus and method for assigning cyber-security risk consequences in industrial process control environments

US9800604B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9800604-B2
Application numberUS-201514705379-A
CountryUS
Kind codeB2
Filing dateMay 6, 2015
Priority dateMay 6, 2015
Publication dateOct 24, 2017
Grant dateOct 24, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method includes identifying multiple devices or groups of devices in an industrial process control and automation system. The method also includes, for each device or group of devices, (i) obtaining impact values identifying potential effects of a failure or compromise of the device or group of devices due to one or more cyber-security risks and (ii) identifying a consequence value using the impact values. Multiple impact values associated with different categories of potential effects are obtained, and the consequence value identifies an overall effect of the failure or compromise of the device or group of devices.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: identifying multiple devices or groups of devices in an industrial process control and automation system; for each device or group of devices: obtaining impact values identifying potential effects of a failure or compromise of the device or group of devices due to one or more cyber-security risks, wherein multiple impact values associated with different categories of potential effects are obtained; and identifying a consequence value using the impact values, the consequence value identifying an overall effect of the failure or compromise of the device or group of devices; and using the consequence value for a first of the devices or groups of devices to modify the consequence value for a second of the devices or groups of devices based on a process control connection between the first and second devices or groups of devices. 2. The method of claim 1 , wherein the different categories of potential effects comprise: a category associated with impacts to health or safety of individuals or to an environment associated with the control and automation system; a category associated with a production process performed or managed by the control and automation system; and a category associated with an organization operating the control and automation system. 3. The method of claim 2 , wherein each impact value comprises an identification of one of: no impact, a minor impact, a moderate impact, a high impact, and a critical impact. 4. The method of claim 1 , wherein identifying the consequence value for one device or group of devices comprises: assigning a numerical value to each of the impact values obtained for the device or group of devices; and identifying a largest of the numerical values associated with the device or group of devices. 5. A method comprising: identifying multiple devices or groups of devices in an industrial process control and automation system; and for each device or group of devices: obtaining impact values identifying potential effects of a failure or compromise of the device or group of devices due to one or more cyber-security risks, wherein multiple impact values associated with different categories of potential effects are obtained; identifying a consequence value using the impact values, the consequence value identifying an overall effect of the failure or compromise of the device or group of devices; and calculating one or more risk scores associated with the device or group of devices, each risk score associated with at least one of the one or more cyber-security risks and calculated using the consequence value for the device or group of devices. 6. The method of claim 1 , further comprising: generating a graphical user interface identifying details of at least one of the one or more cyber-security risks, the details identifying at least one of the potential effects associated with at least one of the devices or groups of devices. 7. The method of claim 1 , wherein obtaining the impact values comprises: presenting a graphical user interface comprising a list of the devices or groups of devices and inputs for each device or group of devices, the inputs configured to receive the impact values in the different categories. 8. The method of claim 5 , further comprising: using the consequence value for a first of the devices or groups of devices to modify the consequence value for a second of the devices or groups of devices based on a process control connection between the first and second devices or groups of devices. 9. An apparatus comprising: at least one processing device configured to: identify multiple devices or groups of devices in an industrial process control and automation system; for each device or group of devices: obtain impact values identifying potential effects of a failure or compromise of the device or group of devices due to one or more cyber-security risks, wherein multiple impact values associated with different categories of potential effects are obtained; and identify a consequence value using the impact values, the consequence value identifying an overall effect of the failure or compromise of the device or group of devices; and use the consequence value for a first of the devices or groups of devices to modify the consequence value for a second of the devices or groups of devices based on a process control connection between the first and second devices or groups of devices. 10. The apparatus of claim 9 , wherein the different categories of potential effects comprise: a category associated with impacts to health or safety of individuals or to an environment associated with the control and automation system; a category associated with a production process performed or managed by the control and automation system; and a category associated with an organization operating the control and automation system. 11. The apparatus of claim 10 , wherein each impact value comprises an identification of one of: no impact, a minor impact, a moderate impact, a high impact, and a critical impact. 12. The apparatus of claim 9 , wherein, to identify the consequence value for one device or group of devices, the at least one processing device is configured to: assign a numerical value to each of the impact values obtained for the device or group of devices; and identify a largest of the numerical values associated with the device or group of devices. 13. The apparatus of claim 9 , wherein the at least one processing device is further configured to: generate a graphical user interface identifying details of at least one of the one or more cyber-security risks, the details identifying at least one of the potential effects associated with at least one of the devices or groups of devices. 14. The apparatus of claim 9 , wherein, to obtain the impact values, the at least one processing device is configured to: present a graphical user interface comprising a list of the devices or groups of devices and inputs for each device or group of devices, the inputs configured to receive the impact values in the different categories. 15. An apparatus comprising: at least one processing device configured to: identify multiple devices or groups of devices in an industrial process control and automation system; and for each device or group of devices: obtain impact values identifying potential effects of a failure or compromise of the device or group of devices due to one or more cyber-security risks, wherein multiple impact values associated with different categories of potential effects are obtained; identify a consequence value using the impact values, the consequence value identifying an overall effect of the failure or compromise of the device or group of devices; and calculate one or more risk scores associated with the device or group of devices, each risk score associated with at least one of the one or more cyber-security risks and calculated using the consequence value for the device or group of devices. 16. A non-transitory computer readable medium embodying computer readable program code that when executed causes at least one processing device to: identify multiple devices or groups of devices in an industrial process control and automation system; and for each device or group of devices: obtain impact values identifying potential effects of a failure or compromise of the device or group of devices due to one or more cyber-security risks, wherein multiple impact values associated with different categories of potential effects are obtained; identify a consequence value using

Assignees

Inventors

Classifications

  • Vulnerability analysis · CPC title

  • Selection of displayed objects or displayed text elements (G06F3/0482 takes precedence) · CPC title

  • Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title

  • using icons (graphical or visual programming using iconic symbols G06F8/34) · CPC title

  • Assessing vulnerabilities and evaluating computer system security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9800604B2 cover?
A method includes identifying multiple devices or groups of devices in an industrial process control and automation system. The method also includes, for each device or group of devices, (i) obtaining impact values identifying potential effects of a failure or compromise of the device or group of devices due to one or more cyber-security risks and (ii) identifying a consequence value using the …
Who is the assignee on this patent?
Honeywell Int Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 24 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 11 related publications on this page (citations in our corpus or others sharing the same primary CPC).