DOE Patents title logo U.S. Department of Energy
Office of Scientific and Technical Information

Title: Integrated behavior-based infrastructure command validation

Abstract

A cybersecurity infrastructure command validation system is provided herein for validating asset commands issued within an infrastructure network. The cybersecurity infrastructure command validation system can be integrated into an infrastructure network to monitor and validate infrastructure asset commands in real-time or while the infrastructure network is active. The cybersecurity infrastructure command validation system can receive or intercept commands issued by asset controllers. The cybersecurity infrastructure command validation system can validate the commands based on a command validation model. The command validation model can represent normal operating behavior of the infrastructure network. The cybersecurity infrastructure command validation system can provide valid commands to the intended infrastructure asset, or can reject invalid commands. The cybersecurity infrastructure command validation system can store validation results for use in updating the command validation model. The cybersecurity infrastructure command validation system can flag or otherwise warn the infrastructure network or administrators of invalid commands.

Inventors:
; ; ; ; ; ;
Issue Date:
Research Org.:
Pacific Northwest National Laboratory (PNNL), Richland, WA (United States)
Sponsoring Org.:
USDOE
OSTI Identifier:
2221990
Patent Number(s):
11706192
Application Number:
16/655,071
Assignee:
Battelle Memorial Institute (Richland, WA)
DOE Contract Number:  
AC05-76RL01830
Resource Type:
Patent
Resource Relation:
Patent File Date: 10/16/2019
Country of Publication:
United States
Language:
English

Citation Formats

Akyol, Bora A., Haack, Jereme N., Carroll, Thomas E., Monson, Kyle E., McKenzie, Penny L., Thornhill, Keith W., and Mylrea, Michael E. Integrated behavior-based infrastructure command validation. United States: N. p., 2023. Web.
Akyol, Bora A., Haack, Jereme N., Carroll, Thomas E., Monson, Kyle E., McKenzie, Penny L., Thornhill, Keith W., & Mylrea, Michael E. Integrated behavior-based infrastructure command validation. United States.
Akyol, Bora A., Haack, Jereme N., Carroll, Thomas E., Monson, Kyle E., McKenzie, Penny L., Thornhill, Keith W., and Mylrea, Michael E. Tue . "Integrated behavior-based infrastructure command validation". United States. https://www.osti.gov/servlets/purl/2221990.
@article{osti_2221990,
title = {Integrated behavior-based infrastructure command validation},
author = {Akyol, Bora A. and Haack, Jereme N. and Carroll, Thomas E. and Monson, Kyle E. and McKenzie, Penny L. and Thornhill, Keith W. and Mylrea, Michael E.},
abstractNote = {A cybersecurity infrastructure command validation system is provided herein for validating asset commands issued within an infrastructure network. The cybersecurity infrastructure command validation system can be integrated into an infrastructure network to monitor and validate infrastructure asset commands in real-time or while the infrastructure network is active. The cybersecurity infrastructure command validation system can receive or intercept commands issued by asset controllers. The cybersecurity infrastructure command validation system can validate the commands based on a command validation model. The command validation model can represent normal operating behavior of the infrastructure network. The cybersecurity infrastructure command validation system can provide valid commands to the intended infrastructure asset, or can reject invalid commands. The cybersecurity infrastructure command validation system can store validation results for use in updating the command validation model. The cybersecurity infrastructure command validation system can flag or otherwise warn the infrastructure network or administrators of invalid commands.},
doi = {},
journal = {},
number = ,
volume = ,
place = {United States},
year = {2023},
month = {7}
}

Works referenced in this record:

Intelligent sensor and controller framework for the power grid
patent, March 2018


Distributed micro-grid controller
patent-application, February 2016


Integration of network admission control functions in network access devices
patent, June 2015


Extracting Dependences between Network Assets Using Deep Learning
patent-application, May 2016


Intelligent sensor and controller framework for the power grid
patent, April 2019


Compliance-as-Code for Cybersecurity Automation in Hybrid Cloud
conference, July 2022


Method and system for managing power grid data
patent, November 2015


SecWater
conference, April 2017


Dynamic Distributed Power Grid Control System
patent-application, February 2012


Intelligent sensor and controller framework for the power grid
patent, July 2015


Securing virtual machine orchestration with blockchains
conference, October 2017


Well valve control system
patent, January 1987