Abstract:
A method for automatically improving security of a network system (10) comprises: collecting security relevant information (30') from network devices (14) of the network system (10), the security relevant information (30') including security settings (32) and operational information (34) of the network devices (14); analyzing the security relevant information (30') for determining weak security settings (32') of a network device (14), the weak security settings (32') being not necessary for a regular operation of the network system (10); determining hardened security settings (32'') for the network device (14) based on the weak security settings (32'), the hardened security settings (32'') restricting a possible operation of the network device (14) but allow a regular operation of the network system (10); and applying the hardened security settings (32'') to the network device (14).
Abstract:
The invention relates to a method and system for detecting and mitigating cabling issues with devices connected in industrial redundant networks. An agent runs on each device and generates information about traffic received at the corresponding device. The agent running on a node generates indicators of traffic received at each port, and error rates for traffic at each port. The agent running on a switch generates information about switch misconfiguration by collecting device identifiers for each port of the switch. The agents send the information to a network manager, which determines switch misconfigurations and wrong cabling from the received information. The network manager also mitigates cabling issues by sending a signal to the affected device(s) or sending a communication to mitigate the issue.
Abstract:
The present invention provides a method for message authentication, in particular in case of low of transmission or storage capacities. The present invention further provides corresponding devices for generating or sending authenticated messages and for receiving or retrieving authenticated messages as well as a system comprising such devices. In an embodiment, the method may comprise (a) preparing a data block having an uncompressed length; (b) compressing the data block so that the data block has a compressed length smaller than the uncompressed length; (c) determining an available length from at least the compressed length and a maximum length of a data frame; (d) calculating a message authentication code, MAC, from at least the data block, having a MAC length not greater than the available length; and (e) creating the data frame, comprising the data block and the MAC.
Abstract:
A method 100 for automatically providing a time signal to containers in an operating system level virtualization or to virtual machines, the method comprising: - creating 102 a pool of clocks; - executing 104 one or more containers in an operating system level virtualization or one or more virtual machines running on an executing hardware device; - allocating 106 one or more clocks of the pool of clocks to client containers in the one or more containers or to client virtual machines of the one or more virtual machines, thereby obtaining allocated clocks allocated to the client containers or the client virtual machines; wherein each of the allocated clocks provides a time signal in a time domain to at least one of the client containers or to at least one of the client virtual machines.
Abstract:
The present invention discloses a method of transmitting time-critical messages in an OSI layer 2 network tunnel from an IED in a first substation to an IED in a second substation over a WAN, wherein each of the first and second substation comprises an edge IED and is associated with a substation LAN, wherein each of the time-critical messages comprises message parameters. The method comprises the steps of: a) creating a translation table comprising corresponding values of the message parameters, between the LANs and the WAN, b) defining a virtual IED model in the second substation using the translated values of the message parameters, to impersonate the IED of the first substation, c) translating the message parameters according to the translation table, d) forwarding the time-critical messages from the IED in the first substation to the WAN, and e) receiving the time-critical messages by the IED of the second substation from the WAN.
Abstract:
A method for providing a training dataset for training and/or testing a machine learning model (20) for predicting timing and/or resource requirements of an unknown application (52) running on an electronic device is provided. The method comprising: providing a training module configured for showing a behaviour as a predetermined electronic device; obtaining a plurality of representative applications (26), which are known and configured to run on the electronic device; running the plurality of representative applications (26) on the training module; recording at least one value of at least one performance metric for each of the representative applications (26) when running on the training module; extracting at least one feature from the representative applications (26); and associating the extracted features, the corresponding recorded values of the performance metric and the corresponding performance metrics in the training dataset; and providing the dataset for training and/or testing the machine learning model (20).
Abstract:
A control arrangement (22) for controlling an electronic device (26), is provided. The control arrangement (22) comprises: an inner controller (30) being coupled to the electronic device (26) and being configured for generating at least one control signal for controlling the electronic device (26) depending on at least one instruction signal from an outer controller (50); and a smart controller (32) coupled to the inner controller (30) and being configured for providing at least one substitute instruction signal for controlling the electronic device (26) to the inner controller (30) if an abnormality related to a signal traffic between the inner controller (30) and the outer controller (50) is detected.
Abstract:
A technique for a control method (100) and a control system in a substation is provided. The control system comprises a substation feeder (30), an intelligent electronic device, IED, (36), a merging unit (34), and BUS network (38a, 38b) connecting the IED (36) and the merging unit (34). The control method comprises providing (10) measurement signals by the substation feeder (30) to the merging unit (34); transmitting (12), by the merging unit (34), measurement data based on the measurement signals of the substation feeder to the IED (36) via the BUS network (38a, 38b); identifying (14), by the IED (36), a fault condition based on the measurement data, the fault condition being indicative of a potentially forthcoming fault; transmitting (16), by the IED (36), a conditional control command to the merging unit (34) via the BUS network (38a, 38b), the conditional control command comprising a control measure and a condition for executing the control measure; determining (18), by the merging unit, whether the condition of the conditional control command is met, and if so initiating (20), by the merging unit, the control measure of the substation feeder circuit.