Adaptive Thresholding for Cyber-Physical Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for protecting cyber-physical systems from cyber-attacks are inadequate, as they often result in false positives and negatives due to static decision boundaries that are not adaptive to real-time operational variations, and stealthy attacks can go undetected, posing risks to critical infrastructure like power turbines and autonomous vehicles.

Innovation Solution

A system with real-time monitoring nodes and a threat detection platform that computes anomaly scores and compares them to an adaptive threshold, allowing for accurate classification of anomalies and detection of cyber-attacks, using adaptive thresholding systems that adjust based on operational modes and conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If static decision boundaries are used for attack detection, then the system is simpler to implement, but false positives and false negatives increase due to inability to adapt to real-time operational variations

Engineering Contradiction:
Improvedecision boundary structureVSAvoidattack detection accuracy
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies dynamics by transforming static decision boundaries into dynamic adaptive thresholds that evolve with operational conditions. The system continuously updates thresholds based on real-time monitoring of system behavior, allowing the detection mechanism to adapt to changing operational modes while maintaining a relatively simple underlying structure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of the decision boundary from fixed to variable by introducing adaptive thresholds that adjust their values based on operational context. This allows the same detection structure to perform reliably across different operational scenarios without increasing structural complexity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If adaptive thresholding is implemented to reduce false positives/negatives, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidthreshold adaptation mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing the framework for adaptive thresholds during system design and initialization. The adaptation rules and computational mechanisms are prepared in advance, allowing the system to adapt to real-time conditions without requiring complex runtime decision-making structures.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple monitoring nodes are used to detect subtle attacks, then detection capability improves, but the difficulty of detecting and measuring attacks increases due to coordination and analysis complexity

Engineering Contradiction:
Improvestealthy attack detectionVSAvoidattack localization complexity
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies segmentation by dividing the attack detection task into node-specific anomaly scores that are computed independently at each monitoring node. This segmentation allows the system to handle multiple nodes without overwhelming complexity, as each node contributes its local assessment to the overall detection framework.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges the anomaly scores from multiple segmented monitoring nodes into a unified decision framework. By combining local assessments through the adaptive thresholding mechanism, the system achieves improved detection of subtle attacks while managing the complexity of multi-node coordination.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11916940B2Attack detection and localization with adaptive thresholding
Publication Date: 2024.02.27 GE INFRASTRUCTURE TECH LLC
  • US11916940B2 patent drawing
  • US11916940B2 patent drawing
  • US11916940B2 patent drawing

AI summary

According to some embodiments, a system, method, and non-transitory computer readable medium are provided comprising a plurality of real-time monitoring nodes to receive streams of monitoring node signal values over time that represent a current operation of the cyber physical system; and a threat detection computer platform, coupled to the plurality of real-time monitoring nodes, to: receive the monitoring node signal values; compute an anomaly score; compare the anomaly score with an adaptive threshold; and detect that one of a particular monitoring node and a system is outside a decision boundary based on the comparison, and classify that particular monitoring node or system as anomalous. Numerous other aspects are provided.