Behavior-Based Command Validation for Legacy Grid Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The energy industry and electrical grid face significant threats from cyberattacks that can compromise control systems, with existing cybersecurity measures being insufficient to prevent unauthorized access and protect legacy systems without significant upgrades or replacements.

Innovation Solution

A cybersecurity infrastructure command validation system that uses machine learning to build and validate command models based on infrastructure data, intercepting and analyzing commands to prevent malicious or erroneous instructions from being executed, thereby ensuring the integrity and security of control systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current inspection techniques are used to validate commands, then the system is simple to operate, but the system is vulnerable to cyberattacks and unauthorized access

Engineering Contradiction:
Improvesecurity against cyberattacksVSAvoidcommand validation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary validation of commands against the command validation model before execution. The command validation model is generated in advance based on historical command data and system state data, enabling proactive detection of malicious commands before they can compromise the control system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The command validation model acts as an intermediary layer between the command source and the controlled infrastructure assets. It mediates command validation by analyzing commands against learned patterns of legitimate system behavior, blocking malicious commands while allowing legitimate ones to pass through to the assets.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If legacy systems are protected with traditional cybersecurity measures, then the systems remain operational, but significant cost is required for upgrades or replacements

Engineering Contradiction:
Improveprotection of legacy systemsVSAvoidcost of system upgrades
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system creates a virtual model (command validation model) of the legacy control system's legitimate behavior based on historical data. This digital copy enables validation of commands without requiring physical modifications or replacements of the legacy hardware systems, preserving them while adding security through software-based validation.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces physical hardware upgrades or replacements with a software-based command validation system. Instead of modifying or replacing legacy control system hardware, the solution uses machine learning models to validate commands, substituting mechanical/engineering solutions with information-processing approaches.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If comprehensive command validation is implemented, then the security against malicious commands is improved, but the processing time for command validation increases

Engineering Contradiction:
Improvedetection of malicious commandsVSAvoidcommand validation processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The command validation model is pre-trained using historical command data and system state data before deployment. This preliminary training phase enables the model to quickly validate new commands by comparing them against established patterns of legitimate behavior, reducing real-time validation processing time while maintaining comprehensive security checks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11706192B2Integrated behavior-based infrastructure command validation
Publication Date: 2023.07.18 BATTELLE MEMORIAL INST
  • US11706192B2 patent drawing
  • US11706192B2 patent drawing
  • US11706192B2 patent drawing

AI summary

A cybersecurity infrastructure command validation system is provided herein for validating asset commands issued within an infrastructure network. The cybersecurity infrastructure command validation system can be integrated into an infrastructure network to monitor and validate infrastructure asset commands in real-time or while the infrastructure network is active. The cybersecurity infrastructure command validation system can receive or intercept commands issued by asset controllers. The cybersecurity infrastructure command validation system can validate the commands based on a command validation model. The command validation model can represent normal operating behavior of the infrastructure network. The cybersecurity infrastructure command validation system can provide valid commands to the intended infrastructure asset, or can reject invalid commands. The cybersecurity infrastructure command validation system can store validation results for use in updating the command validation model. The cybersecurity infrastructure command validation system can flag or otherwise warn the infrastructure network or administrators of invalid commands.