Causal Attribution via Kolmogorov Complexity for Cyber-Physical Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems are vulnerable to cyber-attacks that can disrupt operations and cause catastrophic damage, with existing protection methods failing to detect stealthy attacks and analyze causal relationships between variables effectively.
Innovation Solution
A system and method that determine the optimal number of bins in data distributions to create models, allowing for the calculation of descriptive sizes and causal directions between variables, thereby identifying causal relationships and detecting cyber-attacks in real-time with reduced computational complexity and improved accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If machine learning models are used to predict attacks, then attack detection capability is improved, but the ability to analyze causal relationships between variables is insufficient
Solution Approach 1:
The patent introduces causal inference as an intermediary mechanism between data collection and attack detection. By analyzing causal relationships between variables using algorithms like PC-algorithm and FCI-algorithm, the system can identify meaningful connections while filtering out spurious correlations, thereby improving both detection reliability and causal analysis capability simultaneously
Solution Approach 2:
The patent replaces traditional correlation-based machine learning approaches with causal inference mechanisms. This substitution enables the system to not only predict attacks but also understand the underlying causal structures, allowing for more robust detection that accounts for temporal and causal dependencies between variables
2Loss of information
If conventional causal techniques are used to determine causality, then causal relationship identification is achieved, but computational complexity increases significantly
Solution Approach 1:
The patent performs preliminary actions by pre-processing data to identify and remove redundant variables, and by pre-computing causal structures from historical data. This preparation reduces the computational burden during real-time causal analysis, making the system feasible for deployment in resource-constrained environments
Solution Approach 2:
The patent applies partial action by selectively analyzing only the most relevant variable pairs and causal structures, rather than exhaustively evaluating all possible relationships. This approach maintains causal analysis accuracy while significantly reducing computational complexity through targeted analysis of high-priority relationships
3Speed
If real-time detection is implemented, then response time to cyber-attacks is improved, but computational resources required increase
Solution Approach 1:
The patent implements dynamic adaptation by adjusting the level of causal analysis depth and the number of variables monitored based on system state and threat level. During normal operation, the system performs lighter computational tasks, while automatically increasing computational intensity when anomalies are detected, thereby maintaining real-time response without excessive resource consumption
Solution Approach 2:
The system performs self-service by automatically learning and adapting to normal system behavior patterns, allowing it to detect deviations with minimal computational overhead. The causal models continuously refine themselves using background data, reducing the need for intensive real-time computational analysis while maintaining high detection speed
Data Source
AI summary
Some embodiments provide a system and method comprising a memory and a processor to cause the system to: receive a first and second data distribution for a first and second variable, respectively; determine a first and second data optimum number of bins for the first and second data distribution, respectively; create a first and second model for the first and second data distribution using the first and second data optimum number of bins, respectively; apply the first model to the second data distribution to calculate a smallest descriptive size of the second data distribution given the first model; apply the second model to the first data distribution to calculate a smallest descriptive size of the first data distribution given the second model; and determine a causal direction between the first variable and the second variable based on the application of the first and second model. Numerous other aspects are provided.


