Adaptive Cyber-Attack Detection Model for Industrial Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems connected to the Internet are vulnerable to cyber-attacks, particularly stealthy attacks that occur at the domain layer, which current methods fail to detect automatically, especially when multiple attacks occur simultaneously, and existing fault detection technologies are not designed to handle such scenarios effectively.

Innovation Solution

A system with multiple monitoring nodes that generate monitoring node values over time, an abnormality detection computer using a current feature vector and detection model with a decision boundary to detect attacks or faults, and a model updater that determines an update time-frame for the detection model based on trigger occurrence detection, enabling continuous learning and updating.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multiple monitoring nodes are used to detect attacks, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the monitoring function into multiple independent monitoring nodes, each responsible for specific parameters or assets. This segmentation enables distributed detection that improves accuracy through multiple perspectives while maintaining manageable complexity at each node level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines data from multiple monitoring nodes through a centralized analysis system that integrates their outputs. This merging approach consolidates the detection capabilities of individual nodes to achieve superior overall detection accuracy while managing complexity through unified processing.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If the detection model is continuously updated to adapt to dynamic environments, then detection reliability improves, but computational resources and time increase

Engineering Contradiction:
Improvedetection model reliabilityVSAvoidmodel update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic updates of the detection model at scheduled intervals rather than continuous updates. This periodic approach maintains detection reliability by regularly refreshing the model with new data while controlling computational resource consumption and update time through structured, interval-based refresh cycles.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent incorporates feedback mechanisms where detection results and system performance data are fed back into the model updating process. This feedback loop enables the model to adapt to changing environments and improve reliability by learning from actual operational data, while managing update frequency based on detected changes or performance thresholds.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If the detection model adapts to dynamic system conditions, then adaptability improves, but measurement precision may deteriorate due to concept drift

Engineering Contradiction:
Improvemodel adaptability to dynamic conditionsVSAvoiddetection precision
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system implements a dynamic detection model that can adapt its parameters and structure based on changing system conditions. This dynamic approach enables the model to maintain precision across different operational states by adjusting to concept drift while preserving its ability to accurately detect attacks in evolving environments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs parameter changes in the detection model to adapt to dynamic conditions. By modifying model parameters based on observed system behavior changes, the model maintains detection precision despite concept drift, allowing it to adapt to new normal operating conditions while preserving its attack detection capability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11740618B2Systems and methods for global cyber-attack or fault detection model
Publication Date: 2023.08.29 GE INFRASTRUCTURE TECH LLC
  • US11740618B2 patent drawing
  • US11740618B2 patent drawing
  • US11740618B2 patent drawing

AI summary

An industrial asset may have monitoring nodes that generate current monitoring node values representing a current operation of the industrial asset. An abnormality detection computer may detect when a monitoring node is currently being attacked or experiencing a fault based on a current feature vector, calculated in accordance with current monitoring node values, and a detection model that includes a decision boundary. A model updater (e.g., a continuous learning model updater) may determine an update time-frame (e.g., short-term, mid-term, long-term, etc.) associated with the system based on trigger occurrence detection (e.g., associated with a time-based trigger, a performance-based trigger, an event-based trigger, etc.). The model updater may then update the detection model in accordance with the determined update time-frame (and, in some embodiments, continuous learning).