Comprehensive cyberdefense technology
An AI-based cybersecurity system for ICS and DER integrates network and intrusion detection with rule-based and AI-driven countermeasures, addressing the limitations of existing solutions by enhancing threat detection and mitigation with reduced false alarms and improved alignment with operator procedures.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- SIEMENS CORP
- Filing Date
- 2023-08-21
- Publication Date
- 2026-06-04
AI Technical Summary
Existing cybersecurity solutions for Industrial Control Systems (ICS) and energy delivery systems with distributed energy resources (DER) lack comprehensive cyber defense capabilities, often resulting in frequent false alarms, failure to detect relevant threats, and inadequate automated countermeasures due to reliance on predefined rules and black-box machine learning models that abstract away critical semantics.
An AI-based system integrating multiple layers of cybersecurity analytics, including network-based, compromised controller, and intrusion detection modules, with rule-based and AI-driven countermeasures, to provide comprehensive detection and mitigation capabilities, leveraging explainable models and knowledge graphs for threat analysis and automated response.
The system effectively detects and mitigates cyberattacks with reduced false alarms, enhances threat detection accuracy, and ensures automated countermeasures align with operator procedures, providing a robust defense-in-depth approach.
Smart Images

Figure US2023030687_04062026_PF_FP_ABST
Abstract
Description
202217313COMPREHENSIVE CYBERDEFENSE TECHNOLOGYTECHNICAL FIELD
[0001] This application relates to cybersecurity. More particularly, this application relates to applying an Al-based solution addressing autonomous cyberattack detection and countermeasures for controllers operating in an operational technology environment.BACKGROUND
[0002] Controllers in Industrial Control Systems (ICS) with embedded intelligence receive instruction signals from supervisory level systems through a computer-based network which is susceptible to cyberattacks. Similarly, energy delivery systems utilizing distributed energy resources (DER) (e.g., renewable energy sources, microgrids, etc.) have controllable components (e.g., smart inverters) that are vulnerable to cyberattack. Solutions exist for detection of cyberattacks which are usually adaptations of existing Information Technology (IT) tools that analyze computer network communication adapted to Operational Technology (OT) environments and protocols. While such tools can provide an important level of protection, none of them provides comprehensive cyber defense capabilities. Idiosyncrasies of the power system are not taken into consideration and issues such as frequent false alarms or inability to detect relevant OT specific threats reduce their effectiveness. Considering automated countermeasures for mitigation of the effects of cyberattacks, very few solutions currently exist. They usually rely on manually hard coded rules (predefined) for performing this task, therefore only threats directly foreseen by the human expert are considered.
[0003] Intrusion detection solutions leverage abstract and generic models of critical infrastructure cyber-physical behavior and detect model trajectory discrepancies at runtime. Several efforts use formal cyber-physical modeling approaches to verify the controller semantics202217313 before executing safety-critical control programs. Offline verification approaches often suffer from the state space (execution path) explosion problem as complexity scales. Other research endeavors utilize machine learning to capture the dynamic, non-linear behavior of complex cyber-physical systems and detect abnormalities. However, they treat the cyber-physical dynamics as a black-box, i.e., the associated deep learning models aim to capture the input-to-output relationships of the entire cyber-physical platform. Such black-box and unexplainable nature of the models abstracts away intermediate semantics that could be useful for root-cause analysis.SUMMARY
[0004] System and method provide Al-based autonomous cyberattack detection and multilevel countermeasures that are Al-based and rule-based for protection of controllers in an OT environment. In an aspect, a system includes at least one Al-based cyberattack detection module configured to generate threat detection information, having one or more of (1) a network based attack detection and localization module comprising analytics for network communication and for power system measurements; (2) a compromised controller detection module comprising a lightweight machine learning-based approximate computing model that replicates functionalities of controller logic and configured to distinguish whether a monitored controller is misbehaving or veering off path, and to report detected misbehavior as a potential cyberattack; or (3) an advanced intrusion detection module comprising NLP and semantic algorithms that extract entities, relationships and context from collected threat detection information. The advanced intrusion detection module is configured to construct a cybersecurity knowledge graph based on the entities and the relationships, and generate Al-based models that analyze the knowledge graph to detect anomalies and identify patterns that indicate potential intrusions. A semi-automatic rule engine is configured to automatically explore data, find patterns in the data, and generate detection rules202217313 capable of successful atack mitigation. A rule-based countermeasure module is configured to, in response to the threat detection information, convert the detection rules into action rules that are executable using an automation controller that acts in various configurable ways in the system based on the threat detection information; and trigger a rule-based countermeasure signal to a power system controller in response to a detected cyberatack. An Al-based countermeasure module with trained reinforcement learning algorithms is configured to trigger an Al-based countermeasure signal to a power system controller in response to threat detection information.BRIEF DESCRIPTION OF THE DRAWINGS
[0005] Non-limiting and non-exhaustive embodiments of the present disclosure are described with reference to the following FIGURES, wherein like reference numerals refer to like elements throughout the drawings unless otherwise specified.
[0006] FIG. 1 illustrates a framework example for Al-based cyberattack detection and countermeasures in an OT environment in accordance with embodiments of this disclosure.
[0007] FIG. 2 an example of a computing environment within which embodiments of the disclosure may be implemented.DETAILED DESCRIPTION
[0008] Methods and systems are disclosed for automated cyberattack prevention and mitigation for protection of controllers in an operational technology (OT) environment, such as for energy delivery systems with Distributed Energy Resources (DER) (e.g., photovoltaic (PV) and energy storage systems (ESS)), Industrial Control Systems in industrial automation facilities, and the like. Unlike conventional IT-based approaches that rely on predefined rules, the proposed approaches disclosed herein incorporate Al-based solutions for both cyberattack detection and for202217313 countermeasures in a comprehensive defense-in-depth approach. The proposed solution includes multiple layers of cybersecurity analytics integrating an ensemble of dissimilar cyberattack detection and identification methods / tools and two levels of automated countermeasures, introducing significant improvements compared to currently available cyberattack detection and automated mitigation solutions, and creating an effective defense- in-depth approach. The proposed solution provides three categories of cyberattack detectors creating comprehensive capabilities which include the integration of information from the computer network communication with that from power system measurements: (i) network-based attack detectors, (ii) compromised controller detectors, and (iii) intrusion detectors. A first level of automatic mitigation corresponds to a rulebased system which automates countermeasures in an explainable and predictable way that complies with standard operator procedures. A semi-automatic rule generation tool facilitates management of the information obtained from the large variety of cyberattack detectors. A second level of automated mitigation includes an artificial intelligence (Al)-based system which applies mitigations defined in a data-driven fashion, which can be applied as a complementary mitigation or as a fallback plan in case the capabilities of the first level are exceeded. With such methods and systems, a system network is enabled to autonomously recognize a cyberattack, attempt to prevent it, and autonomously isolate and eradicate it with, ideally, no interruption of service.
[0009] FIG. 1 illustrates a framework example for Al-based cyberattack detection and countermeasures in an OT environment in accordance with embodiments of this disclosure. As shown in FIG. 1, the framework 100 includes an ensemble of dissimilar complementary solutions which includes one or more conventional intrusion detection modules 124 (e.g., commercial-off- the-shelf (COTS) intrusion detection software tools), but also integrates one or more types of artificial intelligence (Al)-based solutions. Al based algorithms are implemented in network-202217313 based atack detection and localization module 121, compromised controller detection and localization module 122, and advanced intrusion detection module 123. These features include aspects of OT systems and take into consideration specific characteristics and data from operation of power systems. By integrating this set of dissimilar complementary tools, a comprehensive coverage in terms of detection of the possible approaches of an adversary can be obtained, yielding a reliable awareness about any threats affecting the system. Also, as traditional tools 124 are part of the solution and additional functionality is incorporated in a modular fashion, the concept provides means for assessing the benefits provided by each of the new functions compared to a well-defined baseline and also means for customizing the solution for different applications and priorities in the future.
[0010] With respect to network based atack detection and localization module 121, one example of such atacks is false data injection (FDI) attacks. Module 121 integrates two forms of analytics submodules that take as inputs two different sources of information: submodule 121a for computer network communication and submodule 121b for power system measurements. For analytics by submodule 121a related to computer network communication, algorithms based on adaptations of natural language processing (NLP) solutions are employed to read computer network communications and create embeddings that represent time windows of network communication information (e.g., words or multi-word terms). The software tool Word2Vec can be useful to assist with this functionality. These algorithms are employed to potentially identify multiple states of normal operation and detect anomalies corresponding to each of those states by comparison of a current state to the multiple states of normal operation. Analytics by submodule 121b related to power system measurements are based on anomaly detection methods that employ autoencoder neural networks. Multiple submodules 121a can be used for analytics of computer202217313 network communications being associated to different assets so that besides detection, the localization of the attack can also be performed.
[0011] Network based attack detection module 121 has been successfully embedded into an industrial controller and tested based on a HIL testbed with a realistic real-time simulation model and real-world cyberattacks affecting Industrial Control System (ICS) protocols or communications. Test results indicated not only the effectiveness of the proposed method in terms of detecting cyberattacks, but also concerning differentiation between cyberattacks and other types of anomalies affecting the power grid and the communication network.
[0012] In an embodiment, network based attack detection module 121 extends the methodology in terms of targeting other types of network-based attacks (e.g., inhibiting response function), in order to make the solution comprehensive in terms of this category of cyberattack. Module 121 may also use Al or machine learning (ML) methods that make the method more easily reusable and adaptable considering different operating conditions, such as various topologies or contingencies which are rare or inexistent in historical data. In an aspect, network based attack detection module 121 applies ML based methods such as graph neural networks or few shot learning.
[0013] Compromised controller detection module 122 is configured to address substantive threats against embedded autonomous critical infrastructure controllers, with no sufficient solution in sight for detecting and defending against data-oriented attacks and syntax-oriented attacks. Data-oriented attacks exploit the critical infrastructure attack surfaces, comprising external sensors readings and actuation commands. Sensor / actuation spoofing attacks could lead to unsafe controller misbehaviors and catastrophic failures in critical infrastructure, since the adversaries effectively gain control over the controller software execution. Syntax-oriented attacks originate202217313 from a software vulnerability and enable attackers to subvert the program’s logic by hijacking its control flow. Traditional code injection attacks and code reuse attacks (e.g., return-oriented programming (ROP)) pose the threats of arbitrary code execution by redirecting control flow and reusing existing code segments to accomplish a malicious purpose.
[0014] In an embodiment, compromised controller detection module 122 is configured to distinguish whether a monitored controller is misbehaving or veering off path, and to report detected misbehavior as a potential cyberattack. Module 122 includes algorithms that apply a novel data-driven and explainable approach for runtime monitoring and response for controller execution security using a lightweight ML-based approximate computing model 122a (e.g., configured as a deep neural network (DNN)-based approximate computing model), which is implemented as a surrogate model. Module 122 is configured to detect data-oriented exploits against the controller software that includes external physical attacks (e.g., sensor / signal spoofing attacks) and internal control parameter manipulations (e.g., deciding control variables in essential control logic) that may lead to failure (e.g., blackout). Module 122 protects the critical infrastructure controller against attacks on communication channels, sensor readings, and internal dynamic memory operations by running surrogate model 122a that replicates functionalities of controller logic. During the controller operation, the surrogate model 122a runs in parallel to the controller’s complex software execution, comparing the expected values for controller variables (including the outputs) calculated by the approximate model with those by the original full-blown controller. Any deviation above a predefined threshold between the outputs of the controller and surrogate indicates an anomaly as a potential malicious misbehavior.
[0015] Advanced intrusion detection module 123 provides a technical solution to address the inherent limitations of existing intrusion detection systems that undermine their effectiveness in202217313 combating advanced cyber threats. These limitations are due to reliance on static signatures and predefined rules, which do not provide a contextual understanding of the network environment. Furthermore, existing systems have limited visibility into the relationships between entities involved in cyber threats. They identify isolated events or indicators and neglect the broader contextual landscape, making it challenging to detect complex attack patterns or identify the root cause of an intrusion. As a solution, advance intrusion detection module 123 extracts semantic relationships between entities in the cybersecurity data sources with automatic creation of a cybersecurity knowledge graph. This enables contextualization, enriching cybersecurity-relevant observations, and provides information which will be leveraged by Al models for enhanced attack detection.
[0016] Module 123 collects data from various sources, such as threat intelligence feeds, security logs and alerts (e.g., from a Nozomi service), vulnerability databases, network topology, and asset information. Module 123 preprocesses and analyzes the collected data using NLP and semantic algorithms to extract entities, relationships, and context. In an embodiment, submodule 123a constructs a cybersecurity knowledge graph once the entities and their relationships are identified. The knowledge graph represents the entities as nodes and the relationships as edges, creating a structured representation of the cybersecurity domain. This knowledge graph can be continually updated and expanded as new data becomes available. The knowledge graph provides contextual information by linking entities with their relevant attributes and relationships. For instance, it can connect an IP address with associated domains, network protocols, user accounts, and past security incidents. This contextual awareness allows for a deeper understanding of the relationships and dependencies between entities, facilitating more accurate threat detection.202217313
[0017] In an embodiment, module 123 includes submodule 123b configured to generate AI- based models that analyze the knowledge graph to detect anomalies and identify patterns that indicate potential intrusions. The Al-based models can detect deviations from normal behavior more effectively by considering semantic relationships and contextual information. This approach improves the detection of advanced attacks that exhibit subtle or evolving patterns.
[0018] In an embodiment, framework 100 includes multi-level countermeasures. For example, a primary level 151 may be defined by rule-based countermeasure module 102 and semi-automatic rule engine 112, complemented by a secondary level 152 defined by Al-based countermeasure module 101. For example, the secondary level 152 is activated only when the primary level 151 countermeasures fail to fully mitigate the cyberattack. Alternatively, rule-based countermeasure module 102 and Al -based countermeasure module 101 may work in cooperation as a single level of countermeasure protection in response to detected cyberattacks. As another alternative, a multilevel approach may be embodied with rule-based countermeasure module 102 of level 151 providing secondary countermeasures to Al-based countermeasure module 101 of level 152 being activated as a primary protection level.
[0019] Rule-based countermeasure module 102 incorporates pre-defined actions specified by the operator so that it works in a predictable way that complies with operator procedures. Possible mitigation actions considered are both the IT side and the OT side. For example, as an IT mitigation, the OT can implement a change in firewall rules or change the network topology. On the OT side for instance, an industrial controller can operate to change state of an industrial device that has been compromised (e.g., deenergize), a circuit breaker can isolate a compromised branch of the power and control network, or a PLC can change a control rule for a compromised subsystem. A tool for semi-automatic rule generation is incorporated in this level so that the202217313 complexity yielded by the integration of multiple detectors can be managed and the coverage of all possible relevant cases is maximized.
[0020] Semi-automatic rule generation engine 112 provides means for an operator or domain expert to better understand and explore events occurring in the power system and associations among them. Attacks targeting cyber-physical systems may originate in IT but they focus on OT domain, especially when the goal of the adversary is to disrupt system operation. Most successful attacks tend to have both spatial and temporal dimensions where attackers use multiple simple vulnerabilities and weaponizations to pivot in the system and compromise their targets. The attackers also adapt to existing detection and prevention systems. Thus, it is paramount to know the intent and current attack evolution as well as the best countermeasures to block the attacks. Semi-automated rule generation engine 112 aims to help operators to explore data, find patterns in the data and generate rules capable of successful attack mitigation.
[0021] A set of statistical and knowledge discovery tools are implemented to extract meaningful patterns from the data which associate two or more events in the system. An event may originate from multiple sources ranging from captured logs and network traffic to alerts produced by intrusion detection systems and other modules from the cyberattack detection layer. Events contain attributes describing their spatial and temporal nature such as start time, duration, origin, class indicators, etc. In an embodiment, one or more suitable frameworks are implemented to express such events and reason about their dependencies and causal relationships, such as timeinterval temporal patterns, subgraph pattern mining, and linear temporal logic.
[0022] The solution may alternate between automated and user-driven exploration strategies. Users are able to drill-down and include additional information based on domain expertise. Generative Al methods can be employed at later stages to aid the users in creating the rules by202217313 automated completion and extended context analysis. Meaningful patterns yielded by the process are converted into rules for monitoring and detection purposes. These detection rules have a general form of “temporal pattern indicates attack event”. Where suitable, the detection rules are incorporated into the Detection Layer solutions to enhance detection capabilities.
[0023] Rule based countermeasure module 102 is configured to convert the detection rules into action rules of the form “temporal pattern triggers action” that are executable using an automation controller (e.g., Siemens SIBERprotect) that acts in various configurable ways in the system based on threat detection information. Such rules are evaluated by extensive testing and scenario-based complex attack simulation. The most critical attacks affecting each pattern are identified by a framework configured to take into consideration the possible counter measures during an optimization analysis so that mitigation options can be identified and included as part of the rules. In an embodiment, such a framework is implemented with augmented digital twin simulations that incorporate computer network topology, devices, and possible adversary actions. Attack criticality is assessed in terms of impact in operational performance by means of a defined key performance indicator (KPI). An attack cost-budget mechanism is employed to define adjustable constraints to the adversary actions. The framework tracks cyber states that describe the progression of attack scenarios, consisting of a sequence of adversary actions, in a way that enables the use of optimization / search methods for identification of the most critical possibilities. For example, a Monte-Carlo Tree Search (MCTS) can be employed based on the system topology.
[0024] The rules can be validated and vetted by domain experts to ensure their adequacy. Any rules that are difficult to validate or that have representations with exceeding complexity may still be used as inputs to the Al-based countermeasure module 101. To aid domain experts in the action202217313 rule selection, a Neuro-Symbolic Computing approach is employed that allows the users to express the rule-action relationships as structured and interpretable programs.
[0025] Al-based countermeasure module 101 employs existing controllers in the systems that are deemed to be intact and not impacted by the cyberattack (i.e., the detection measures have determined with a degree of certainty which elements are compromised and which elements are not compromised) to counteract consequences of cyberattacks in an OT environment to avoid consequences that could disrupt operations in an ICS or DER network.
[0026] In an aspect, framework 100 may be applied for DER protection, where Al-based countermeasure module 101 applies reinforcement-learning (RL) based algorithms to protect DER smart inverters by adjusting settings of non-compromised DER devices in response to detected deleterious power quality conditions. If a portion of DER smart inverter control functions (e.g., smart inverter Volt-VAR and Volt-Watt controllers) have had their settings maliciously adjusted to create large oscillations or deleterious power quality conditions, the algorithms adjust the settings of non-compromised DER devices to ameliorate the attack in real time.
[0027] In an aspect for DER protection, a library provides a link between power system simulators and a reinforcement learning (RL) library. The library is leveraged to train reinforcement learning (RL) algorithms for DER cyber defense, and for electric power distribution grids on quasi-static time scales. The library is configured as a unified API that can interface different power system simulators (e.g., OpenDSS), while on the RL side, the library uses the RL library in order to deploy large scale experiments on a server, machine cluster or on a cloud.
[0028] In an aspect for DER protection, the library also includes rule-based control devices (e.g., tap-changing transformers), in addition to RL-based controllers, and can easily be extended to support the integration of other more complicated DER (e.g., electric vehicle charging and202217313 batery storage systems). The library provides a foundation for the rapid development of learningbased control algorithms for heterogeneous classes of DER in electric power distribution grids. The library contributes to this task by extending to incorporate a tool for optimizing attacks with the purpose of testing mitigation solutions. This tool is enhanced and adapted to generate optimized atack scenarios for RL training, ensuring the Al-based solution can properly deal with the worstcase conditions.
[0029] In an embodiment, the detection modules 121, 122, 123 and 124 continuously monitor the system, and detection buffer 111 stores any cyberatack detections for retrieval by countermeasure modules 101, 102. Each detection may be stored with a timestamp, location information, and / or affected power system component as reported by the respective detection module 121, 122, 123, 124.
[0030] Semi-automatic rule engine 112 is incorporated such that complexity yielded by the integration of multiple detectors can be managed and the coverage of all possible relevant cases is maximized. Rule based countermeasure module 102 is programmed with pre-defined actions specified by the operator, enabling countermeasure actions that are predictable and in compliance with operator procedures. One or more mitigation signals are generated by rule-based countermeasure module 102 and delivered to one or more controllers in the power system that activate the mitigation on the affected components. Feedback is provided to the rule-based countermeasure module 102 regarding the status of the mitigation. In response to an unsuccessful mitigation to a detected cyberattack, rule based countermeasure module 102 notifies Al-based countermeasure module 101 to engage. Based on information from detection status module 111, Al-based countermeasure module 101 responds with an automated and optimized countermeasure202217313 instruction to a controller in the power system as a secondary level of mitigation for the detected cyberattack.
[0031] In terms of detection, the disclosed framework includes an ensemble of dissimilar complementary solutions. Significant improvements are realized in terms of cyberattack detection and mitigation compared to the current available solutions which are adapted from IT applications, creating a comprehensive defense-in-depth approach.
[0032] Besides the novel aspects included in detection, the advances proposed in the mitigation aspect present even more significant enhancements compared to currently available solutions, with the two level approach including semi-automatic rule-generation and Al-based countermeasures. All those are new aspects which should considerably enhance automated mitigation capabilities.
[0033] FIG. 2 shows an example of a computer environment within which embodiments of the disclosure may be implemented. A computing device 210 includes a processor 215 and memory 211 (e.g., a non-transitory computer readable media) on which is stored various computer applications, modules or executable programs. In an embodiment, memory 211 includes one or more of the following modules: Al based countermeasure module 101, rule-based countermeasure module 102, Al-based detection modules 121, 122, 123, conventional intrusion detection module 124.
[0034] As shown in FIG. 2, as an alternative computer implementation of Al based countermeasure module 101, rule- based countermeasure module 102, Al-based detection modules 121, 122, 123, conventional intrusion detection module 124, one or more of such modules may be deployed as cloud-based or web-based operations in modules 241, 242, or as a divided operation shared by local modules 101, 102, 121-124, and web-based modules 241, 242.202217313
[0035] A network 260, such as a local area network (LAN), wide area network (WAN), or an internet based network, connects training data 251 to Al-based modules 101, 121, 122, 123 of computing device 210 and to Al-based modules 241, 242.
[0036] User interface module 214 provides an interface between modules 101, 102, 121-124 and user interface 230 devices, such as display device 231 and user input device 232. GUI engine 213 drives the display of an interactive user interface on display device 231, allowing a user to receive visualizations of analysis results and assisting user entry of learning objectives and domain constraints for modules 101, 102, 121-124, 241, 242.
[0037] Computer readable medium instructions for carrying out operations of the present disclosure may be assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state-setting data, or either source code or object code written in any combination of one or more programming languages, including an object oriented programming language such as Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The computer readable program instructions may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGA), or programmable logic arrays (PLA) may execute the computer readable program instructions by utilizing state202217313 information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present disclosure.
[0038] Aspects of the present disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, may be implemented by computer readable medium instructions.
[0039] The program modules, applications, computer-executable instructions, code, or the like depicted in FIG. 2 as being stored in the system memory 211 are merely illustrative and not exhaustive and that processing described as being supported by any particular module may alternatively be distributed across multiple modules or performed by a different module. In addition, various program module(s), script(s), plug-in(s), Application Programming Interface(s) (API(s)), or any other suitable computer-executable code hosted locally on the computer system 210, remote network devices storing modules 241, 242 and / or hosted on other computing device(s) accessible via one or more of the network(s) 260, may be provided to support functionality provided by the program modules, applications, or computer-executable code and / or additional or alternate functionality. Further, functionality may be modularized differently such that processing described as being supported collectively by the collection of program modules depicted in FIG. 2 may be performed by a fewer or greater number of modules, or functionality described as being supported by any particular module may be supported, at least in part, by another module. In addition, program modules that support the functionality described herein may form part of one or more applications executable across any number of systems or devices in accordance with any202217313 suitable computing model such as, for example, a client-server model, a peer-to-peer model, and so forth. In addition, any of the functionality described as being supported by any of the program modules depicted in FIG. 2 may be implemented, at least partially, in hardware and / or firmware across any number of devices.
[0040] It should further be appreciated that the computer system 210 may include alternate and / or additional hardware, software, or firmware components beyond those described or depicted without departing from the scope of the disclosure. More particularly, it should be appreciated that software, firmware, or hardware components depicted as forming part of the computer system 210 are merely illustrative and that some components may not be present or additional components may be provided in various embodiments. While various illustrative program modules have been depicted and described as software modules stored in system memory 211, it should be appreciated that functionality described as being supported by the program modules may be enabled by any combination of hardware, software, and / or firmware. It should further be appreciated that each of the above-mentioned modules may, in various embodiments, represent a logical partitioning of supported functionality. This logical partitioning is depicted for ease of explanation of the functionality and may not be representative of the structure of software, hardware, and / or firmware for implementing the functionality. Accordingly, it should be appreciated that functionality described as being provided by a particular module may, in various embodiments, be provided at least in part by one or more other modules. Further, one or more depicted modules may not be present in certain embodiments, while in other embodiments, additional modules not depicted may be present and may support at least a portion of the described functionality and / or additional functionality. Moreover, while certain modules may be depicted and described as sub-modules of202217313 another module, in certain embodiments, such modules may be provided as independent modules or as sub-modules of other modules.
[0041] Although specific embodiments of the disclosure have been described, one of ordinary skill in the art will recognize that numerous other modifications and alternative embodiments are within the scope of the disclosure. For example, any of the functionality and / or processing capabilities described with respect to a particular device or component may be performed by any other device or component. Further, while various illustrative implementations and architectures have been described in accordance with embodiments of the disclosure, one of ordinary skill in the art will appreciate that numerous other modifications to the illustrative implementations and architectures described herein are also within the scope of this disclosure. In addition, it should be appreciated that any operation, element, component, data, or the like described herein as being based on another operation, element, component, data, or the like can be additionally based on one or more other operations, elements, components, data, or the like. Accordingly, the phrase “based on,” or variants thereof, should be interpreted as “based at least in part on.”
[0042] The flowchart and block diagrams in the Figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagrams may represent a module, segment, or portion of instructions, which comprises one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions noted in the block may occur out of the order noted in the Figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of202217313 the block diagrams and / or flowchart illustration, and combinations of blocks in the block diagrams and / or flowchart illustration, can be implemented by special purpose hardware-based systems that perform the specified functions or acts or carry out combinations of special purpose hardware and computer instructions.
Claims
202217313CLAIMSWhat is claimed is:
1. A computer based system of cyberattack detection and intervention for a network operating in an operational technology environment, comprising: a processor; and a non-transitory memory having stored thereon modules executed by the processor, the modules comprising: at least one Al-based cyberattack detection module, configured to generate threat detection information, comprising one or more of; a network based attack detection and localization module comprising analytics for network communication and for power system measurements; a compromised controller detection module comprising a lightweight machine learning-based approximate computing model that replicates functionalities of controller logic and configured to distinguish whether a monitored controller is misbehaving or veering off path, and to report detected misbehavior as a potential cyberattack; or an advanced intrusion detection module comprising NLP and semantic algorithms that extract entities, relationships and context from collected threat detection information, the advanced intrusion detection module configured to: construct a cybersecurity knowledge graph based on the entities and the relationships; and generate Al-based models that analyze the knowledge graph to detect anomalies and identify patterns that indicate potential intrusions; a semi-automatic rule engine configured to automatically explore data, find patterns in the data, and generate detection rules capable of successful attack mitigation; a rule-based countermeasure module configured to, in response to the threat detection information:202217313 convert the detection rules into action rules that are executable using an automation controller that acts in various configurable ways in the system based on the threat detection information; and trigger a rule-based countermeasure signal to a power system controller in response to a detected cyberattack; and an Al-based countermeasure module with trained reinforcement learning algorithms configured to trigger an Al-based countermeasure signal to a power system controller in response to threat detection information.
2. The system of claim 1, wherein the system is configured to operate as a multi-level countermeasure approach, with the rule based countermeasure module and the semi-automatic rule generation module providing primary protection, and the Al-based countermeasure module activated as a secondary level countermeasure that is employed only when the rule-based countermeasure module fails to fully mitigate the attack.
3. The system of claim 1, wherein the system is configured to operate as a multi-level countermeasure approach, with the Al -based countermeasure providing primary level countermeasure protection, and module rule based countermeasure module and the semiautomatic rule generation module activated as a secondary level countermeasure that is employed only when the Al-based countermeasure module fails to fully mitigate the attack.
4. The system of claim 1, wherein the lightweight machine learning-based approximate computing model is configured as a deep neural network (DNN).
5. The system of claim 1, wherein the network based attack detection and localization module comprises: a submodule configured with algorithms based on adaptations of natural language processing (NLP) solutions employed to read network communications and create embeddings that represent time windows of network communication information, wherein the algorithms identify multiple states of normal operation and detect anomalies corresponding to each of those states by comparison of a current state to the multiple states of normal operation.2022173136. The system of claim 1, wherein the network based attack detection and localization module comprises: a submodule configured to perform analytics based on anomaly detection methods that employ autoencoder neural networks.
7. The system of claim 1, wherein the compromised controller detection module is further configured to detect data-oriented exploits against the controller software that includes external physical attacks and internal control parameter that may lead to failure.
8. The system of claim 1, wherein the system is applied for distributed energy resources (DER) protection, the Al -based countermeasure module being further configured to apply reinforcement-learning (RL) based algorithms to protect DER smart inverters by adjusting settings of non-compromised DER devices in response to detected deleterious power quality conditions.
9. A computer-implemented method of cyberattack detection and intervention for a network operating in an operational technology environment, comprising: generating threat detection information using one or more of: performing a network based attack detection and localization using analytics for network communication and for power system measurements; performing a compromised controller detection using a lightweight machine learning-based approximate computing model that replicates functionalities of controller logic and that distinguishes whether a monitored controller is misbehaving or veering off path, and reports detected misbehavior as a potential cyberattack; or performing an advanced intrusion detection using NLP and semantic algorithms that extract entities, relationships and context from collected threat detection information, comprising: constructing a cybersecurity knowledge graph based on the entities and the relationships; and202217313 generating Al -based models that analyze the knowledge graph to detect anomalies and identify patterns that indicate potential intrusions; automatically exploring data, finding patterns in the data, and generating detection rules capable of successful attack mitigation; applying rule-based countermeasures in response to the threat detection information that: convert the detection rules into action rules that are executable using an automation controller that acts in various configurable ways in the system based on the threat detection information; and trigger a rule-based countermeasure signal to a power system controller in response to a detected cyberattack; and applying Al -based countermeasures with trained reinforcement learning algorithms configured to trigger an Al-based countermeasure signal to a power system controller in response to the threat detection information.
10. The method of claim 9, wherein: applying rule-based countermeasures and applying Al-based countermeasures is performed as a multi-level countermeasure approach, with the rule based countermeasures and providing primary protection, and the Al-based countermeasures activated as a secondary level countermeasure that is employed only when the rule-based countermeasures fail to fully mitigate the attack.
11. The method of claim 9, wherein: applying rule-based countermeasures and applying Al-based countermeasures is performed as a multi-level countermeasure approach, with the Al-based countermeasures providing primary protection, and the rule based countermeasures activated as a secondary level countermeasure that is employed only when the Al-based countermeasures fail to fully mitigate the attack.20221731312. The method of claim 9, wherein the performing network based attack detection and localization comprises: applying algorithms based on adaptations of natural language processing (NLP) solutions employed to read network communications and create embeddings that represent time windows of network communication information, wherein the algorithms identify multiple states of normal operation and detect anomalies corresponding to each of those states by comparison of a current state to the multiple states of normal operation.
13. The method of claim 9, wherein the performing network based attack detection and localization comprises: performing analytics based on anomaly detection methods that employ autoencoder neural networks.
14. The method of claim 9, wherein the performing compromised controller detection comprises: detecting data-oriented exploits against the controller software that includes external physical attacks and internal control parameter that may lead to failure.
15. The method of claim 9, wherein the method is applied for distributed energy resources (DER) protection, wherein the applying Al-based countermeasure comprises: applying reinforcement-learning (RL) based algorithms to protect DER smart inverters by adjusting settings of non-compromised DER devices in response to detected deleterious power quality conditions.