US 11,818,098 B2
Security system, device, and method for protecting control systems
Daniel D. Park, Charlottesville, VA (US); John Mark Baggett, Deer Park, TX (US); Edward C. Suhler, Earlysville, VA (US); Rick A. Jones, Charlottesville, VA (US); Gary W. Huband, Crozet, VA (US); Paul D. Robertson, Shenandoah, VA (US); Austin C. Suhler, Earlysville, VA (US); and Casey Silver, Forest, VA (US)
Assigned to MISSION SECURE, INC., Charlottesville, VA (US)
Filed by MISSION SECURE, INC., Charlottesville, VA (US)
Filed on Sep. 15, 2021, as Appl. No. 17/475,674.
Application 17/475,674 is a continuation of application No. 16/702,944, filed on Dec. 4, 2019, granted, now 11,153,277.
Application 16/702,944 is a continuation in part of application No. 15/414,441, filed on Jan. 24, 2017, granted, now 10,530,749, issued on Jan. 7, 2020.
Claims priority of provisional application 62/412,143, filed on Oct. 24, 2016.
Prior Publication US 2022/0006781 A1, Jan. 6, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01); H04L 41/06 (2022.01); H04L 67/12 (2022.01); G06N 20/00 (2019.01)
CPC H04L 63/0245 (2013.01) [G06N 20/00 (2019.01); H04L 41/06 (2013.01); H04L 63/308 (2013.01); H04L 67/12 (2013.01)] 7 Claims
OG exemplary drawing
 
1. A method of providing configuration assurance for an operational technology (OT) system having connected hardware equipment, including at least a communication interface connected to a control system for the OT system and configured to provide configuration information specifying one or more parameters of the control system for the OT system, the method comprising:
a first receiving step of receiving configuration information from the communication interface;
a second receiving step of receiving reference configuration information from a reference source;
a determining step of determining whether the received configuration information contains an undesirable configuration for at least one parameter of the one or more parameters based at least on a comparison of the received configuration information with the reference configuration information;
a storing step of storing the received configuration information as acceptable in a case where the determining step does not determine that the received configuration information contains an undesirable configuration for at least one parameter of the one or more parameters; and
a notifying step of notifying a user that the received configuration information is undesirable in a case where the determining step determines that the received configuration information contains an undesirable configuration for at least one parameter of the one or more parameters,
wherein the control system includes a processor configured to provide control commands for the connected hardware equipment, and
wherein the configuration information includes information associated with a normal operative state or behavior of the control system for the OT system.