Network asset characterization, classification, grouping and control
Abstract
Techniques applicable to a network orchestration and security platform for a network, such as an industrial control system (ICS) network, are disclosed. Such techniques include, for example, methods to characterize and classify networked industrial devices based upon conversation patterns, generate security zones for ICS networked assets based upon conversation characteristics and patterns, to identify and record ICS networked devices in a non-intrusive way, to create secure conduits between security zones for ICS networked devices with no impact to endpoint hose devices, and systems therefor.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method comprising:
initiating an operational connection of a source in a first security zone to a destination in a second security zone; sending a message in the clear from the source to a security zone egress port of the first security zone; sending the message via a secure conduit from the security zone egress port to a security zone ingress port of the second security zone; sending the message in the clear from the security zone ingress port to the destination; and when the operational connection is re-activated, validating a fingerprint generated for the source to ensure the source is authorized.
2 . The method of claim 1 , wherein the first security zone and the second security zone represent a logical grouping of trust of assets in which communications received by an asset from assets within the same security zone are trusted and communications received by an asset from assets outside the same security zone are untrusted.
3 . The method of claim 1 , comprising sending the message via the secure conduit through one or more switches of an industrial control system (ICS) network.
4 . The method of claim 1 , comprising generating the fingerprint for the source.
5 . The method of claim 1 , wherein sending the message in the clear means sending the message without encryption.
6 . The method of claim 1 , wherein sending the message in the clear means sending the message without tunneling.
7 . The method of claim 1 , comprising identifying the operational connection as a new active connection.
8 . The method of claim 1 , comprising each time the active connection is re-activated, validating the fingerprint generated for the source to ensure the source is authorized.
9 . A system comprising:
an industrial control system (ICS) network; a first security zone coupled to the ICS network; a second security zone coupled to the ICS network; a network orchestration and security platform coupled to the ICS network for generating a fingerprint to ensure a source in the first security zone is authorized to send to a destination in the second security zone; wherein, in operation:
the network orchestration and security platform initiates an operational connection from the source to the destination;
the source sends a message in the clear to a security zone egress port of the first security zone;
the security zone egress port sends the message via a secure conduit to a security zone ingress port of the second security zone;
the security zone ingress port sends the message in the clear to the destination;
wherein, when the operational connection is re-activated, the destination validates the fingerprint.
10 . The system of claim 9 , wherein the first security zone and the second security zone represent a logical grouping of trust of assets in which communications received by an asset from assets within the same security zone are trusted and communications received by an asset from assets outside the same security zone are untrusted.
11 . The system of claim 9 , wherein the message is sent via the secure conduit through one or more switches of the ICS network.
12 . The system of claim 9 , wherein sending the message in the clear means sending the message without encryption.
13 . The system of claim 9 , wherein sending the message in the clear means sending the message without tunneling.
14 . The system of claim 9 , wherein the network orchestration and security platform identifies the operational connection as a new active connection.
15 . The system of claim 9 , wherein each time the active connection is re-activated, the destination validates the fingerprint to ensure the source is authorized.
16 . A system comprising:
a means for initiating an operational connection of a source in a first security zone to a destination in a second security zone; a means for sending a message in the clear from the source to a security zone egress port of the first security zone; a means for sending the message via a secure conduit from the security zone egress port to a security zone ingress port of the second security zone; a means for sending the message in the clear from the security zone ingress port to the destination; a means for, when the operational connection is re-activated, validating a fingerprint generated for the source to ensure the source is authorized.
17 . The system of claim 16 , wherein the first security zone and the second security zone represent a logical grouping of trust of assets in which communications received by an asset from assets within the same security zone are trusted and communications received by an asset from assets outside the same security zone are untrusted.
18 . The system of claim 16 , comprising a means for sending the message via the secure conduit through one or more switches of an industrial control system (ICS) network.
19 . The system of claim 16 , comprising a means for generating the fingerprint for the source.
20 . The system of claim 16 , comprising a means for, each time the active connection is re-activated, validating the fingerprint generated for the source to ensure the source is authorized.Join the waitlist — get patent alerts
Track US2021194932A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.