首页> 外国专利> SECURITY ZONES IN INDUSTRIAL CONTROL SYSTEMS

SECURITY ZONES IN INDUSTRIAL CONTROL SYSTEMS

机译:工业控制系统中的安全区域

摘要

The present invention is concerned with security zoning or clustering, i.e. the task of defining a set of non-overlapping security zones and assigning each node or resource of an Industrial Automation and Control System (IACS)to exactly one zone. The invention is based on deterministic, engineered information about network nodes of the IACS as retrieved from an IACS system description file or equivalent representation of the system configuration. The invention suggests an automated,structured and repeatable approach for segmenting the network of an IACS to better provide cyber security functionalities in an IACS installation, to decrease the risk for unintentional errors and to provide traceable documentation on the network segregation. The invention allows for more thorough zoning than that performed manually by engineers, especially when dealing with complex network topologies, and reduces the time that engineers need to spend in designing an optimal solution that meets all the security zoning requirements and rules.
机译:本发明涉及安全分区或聚类,即定义一组不重叠的安全区域并将工业自动化和控制系统(IACS)的每个节点或资源分配给一个区域的任务。本发明基于从IACS系统描述文件或系统配置的等效表示中检索到的关于IACS的网络节点的确定的工程信息。本发明提出了一种自动,结构化和可重复的方法,用于对IACS的网络进行分段,以更好地在IACS安装中提供网络安全功能,以减少意外错误的风险并提供有关网络隔离的可追溯文档。本发明允许比工程师手动执行的分区更彻底的分区,尤其是在处理复杂的网络拓扑时,并减少了工程师在设计满足所有安全分区要求和规则的最佳解决方案上花费的时间。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号