Adaptive Thresholding for Cyber-Physical Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for protecting cyber-physical systems from cyber-attacks are inadequate, as they often result in false positives and negatives due to static decision boundaries that are not adaptive to real-time operational variations, and stealthy attacks can go undetected, posing risks to critical infrastructure like power turbines and autonomous vehicles.
Innovation Solution
A system with real-time monitoring nodes and a threat detection platform that computes anomaly scores and compares them to an adaptive threshold, allowing for accurate classification of anomalies and detection of cyber-attacks, using adaptive thresholding systems that adjust based on operational modes and conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If static decision boundaries are used for attack detection, then the system is simpler to implement, but false positives and false negatives increase due to inability to adapt to real-time operational variations
Solution Approach 1:
The patent applies dynamics by transforming static decision boundaries into dynamic adaptive thresholds that evolve with operational conditions. The system continuously updates thresholds based on real-time monitoring of system behavior, allowing the detection mechanism to adapt to changing operational modes while maintaining a relatively simple underlying structure.
Solution Approach 2:
The patent changes the parameter of the decision boundary from fixed to variable by introducing adaptive thresholds that adjust their values based on operational context. This allows the same detection structure to perform reliably across different operational scenarios without increasing structural complexity.
2Reliability
If adaptive thresholding is implemented to reduce false positives/negatives, then detection accuracy improves, but system complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-establishing the framework for adaptive thresholds during system design and initialization. The adaptation rules and computational mechanisms are prepared in advance, allowing the system to adapt to real-time conditions without requiring complex runtime decision-making structures.
3Reliability
If multiple monitoring nodes are used to detect subtle attacks, then detection capability improves, but the difficulty of detecting and measuring attacks increases due to coordination and analysis complexity
Solution Approach 1:
The patent applies segmentation by dividing the attack detection task into node-specific anomaly scores that are computed independently at each monitoring node. This segmentation allows the system to handle multiple nodes without overwhelming complexity, as each node contributes its local assessment to the overall detection framework.
Solution Approach 2:
The patent merges the anomaly scores from multiple segmented monitoring nodes into a unified decision framework. By combining local assessments through the adaptive thresholding mechanism, the system achieves improved detection of subtle attacks while managing the complexity of multi-node coordination.
Data Source
AI summary
According to some embodiments, a system, method, and non-transitory computer readable medium are provided comprising a plurality of real-time monitoring nodes to receive streams of monitoring node signal values over time that represent a current operation of the cyber physical system; and a threat detection computer platform, coupled to the plurality of real-time monitoring nodes, to: receive the monitoring node signal values; compute an anomaly score; compare the anomaly score with an adaptive threshold; and detect that one of a particular monitoring node and a system is outside a decision boundary based on the comparison, and classify that particular monitoring node or system as anomalous. Numerous other aspects are provided.


