Firewall with Application Packet Classifier
    2.
    发明申请
    Firewall with Application Packet Classifier 审中-公开
    防火墙与应用程序包分类器

    公开(公告)号:US20160149861A1

    公开(公告)日:2016-05-26

    申请号:US14554621

    申请日:2014-11-26

    IPC分类号: H04L29/06

    摘要: An improved system for establishing rules in a firewall for an industrial network is disclosed. Rules are established at an application level, identifying, for example, actions to occur between two devices. The action may be, for example, read data table or get attribute, and each action may require multiple message packets to be transmitted between the two devices in order to complete. A network device executing the firewall is configured to receive message packets from a sending device and to inspect the message packets to determine which action the sending device is requesting to perform. If the action corresponds to a rule in the database, the network device manages communications between the two devices until all message packets have been transmitted. Thus, a single action, or application, may be defined in the rules database to permit multiple data packets to be communicated between the devices.

    摘要翻译: 公开了一种用于在工业网络的防火墙中建立规则的改进的系统。 在应用程序级别建立规则,识别例如两个设备之间发生的动作。 该动作可以是例如读取数据表或获取属性,并且每个动作可能需要在两个设备之间传送多个消息分组以便完成。 执行防火墙的网络设备被配置为从发送设备接收消息分组,并且检查消息分组以确定发送设备请求执行哪个动作。 如果该动作对应于数据库中的规则,则网络设备管理两个设备之间的通信,直到所有消息分组已被发送。 因此,可以在规则数据库中定义单个动作或应用程序,以允许在设备之间传送多个数据包。

    Centralized security event generation policy

    公开(公告)号:US12052137B2

    公开(公告)日:2024-07-30

    申请号:US18149292

    申请日:2023-01-03

    IPC分类号: H04L41/0816 H04L9/40

    摘要: A model-based industrial security policy configuration system implements a plant-wide industrial asset security policy in accordance with security policy definitions provided by a user. The configuration system models the collection of industrial assets for which diverse security policies are to be implemented. An interface allows the user to define zone-specific security configuration and event management policies for a plant environment at a high-level based on a security model that groups the industrial assets into security zones. Based on the model and these policy definitions, the system generates asset-level security setting instructions configured to set appropriate device settings on one or more of the industrial assets to implement the security event management policies, and deploys these instructions to the appropriate assets in order to implement the defined policies.

    Centralized security event generation policy

    公开(公告)号:US11575571B2

    公开(公告)日:2023-02-07

    申请号:US16870075

    申请日:2020-05-08

    IPC分类号: H04L41/0816 H04L9/40

    摘要: A model-based industrial security policy configuration system implements a plant-wide industrial asset security policy in accordance with security policy definitions provided by a user. The configuration system models the collection of industrial assets for which diverse security policies are to be implemented. An interface allows the user to define zone-specific security configuration and event management policies for a plant environment at a high-level based on a security model that groups the industrial assets into security zones. Based on the model and these policy definitions, the system generates asset-level security setting instructions configured to set appropriate device settings on one or more of the industrial assets to implement the security event management policies, and deploys these instructions to the appropriate assets in order to implement the defined policies.

    Agile control model system and method
    7.
    发明授权
    Agile control model system and method 有权
    敏捷控制模型系统和方法

    公开(公告)号:US09389606B2

    公开(公告)日:2016-07-12

    申请号:US13662258

    申请日:2012-10-26

    IPC分类号: G05B19/418 G05B19/05

    摘要: A control and monitoring system is provided that includes an automation controller. The system includes a distributed model stored on the automation controller. Changes to the distributed model are provided via delta scripts that define only the changes to the model. Further, the control and monitoring system 24 includes distributed execution engines that execute commands based upon trigger events determined in the system. a plurality of automation control components networked together and with the automation controller, wherein the plurality of automation control components are capable of load balancing among the plurality of automation control components in response to performance demands of the control and monitoring system. These features of the control and monitoring system enable load balancing, data and processing redundancy, and collaborative design within the control and monitoring system.

    摘要翻译: 提供了包括自动化控制器的控制和监控系统。 该系统包括存储在自动化控制器上的分布式模型。 通过增量脚本提供对分布式模型的更改,该脚本仅定义模型的更改。 此外,控制和监视系统24包括基于在系统中确定的触发事件执行命令的分布式执行引擎。 多个自动化控制组件联网在一起并与自动化控制器组合,其中多个自动化控制组件能够响应于控制和监视系统的性能要求在多个自动化控制组件之间进行负载平衡。 控制和监控系统的这些功能使得负载平衡,数据和处理冗余以及控制和监控系统内的协同设计成为可能。

    USER SECURITY CREDENTIALS AS AN ELEMENT OF FUNCTIONAL SAFETY

    公开(公告)号:US20210385190A1

    公开(公告)日:2021-12-09

    申请号:US16894076

    申请日:2020-06-05

    IPC分类号: H04L29/06 G05B19/418

    摘要: An industrial safety architecture integrates employee identity and enterprise-level security policy into plant-floor functional safety systems, allowing control and safety systems on the plant floor to regulate safe interactions with hazardous controlled machinery based on user identity or role. The architecture leverages existing employee identity and security policy data maintained on the corporate level of an industrial enterprise to manage identity- and/or role-based control and safety on the plant level. Safety authority systems at both the corporate level and the plant level of the industrial enterprise obtain employee and security policy data from corporate-level systems and provides this data in as SIL-rated manner to industrial control and safety systems on the plant floor, where the identity and security policy information is used by functional safety systems to control access to industrial systems as a function of user identity, role, certifications, or other qualifications.

    CENTRALIZED SECURITY EVENT GENERATION POLICY

    公开(公告)号:US20210351980A1

    公开(公告)日:2021-11-11

    申请号:US16870075

    申请日:2020-05-08

    IPC分类号: H04L12/24 H04L29/06

    摘要: A model-based industrial security policy configuration system implements a plant-wide industrial asset security policy in accordance with security policy definitions provided by a user. The configuration system models the collection of industrial assets for which diverse security policies are to be implemented. An interface allows the user to define zone-specific security configuration and event management policies for a plant environment at a high-level based on a security model that groups the industrial assets into security zones. Based on the model and these policy definitions, the system generates asset-level security setting instructions configured to set appropriate device settings on one or more of the industrial assets to implement the security event management policies, and deploys these instructions to the appropriate assets in order to implement the defined policies.