Causal Attribution via Kolmogorov Complexity for Cyber-Physical Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems are vulnerable to cyber-attacks that can disrupt operations and cause catastrophic damage, with existing protection methods failing to detect stealthy attacks and analyze causal relationships between variables effectively.

Innovation Solution

A system and method that determine the optimal number of bins in data distributions to create models, allowing for the calculation of descriptive sizes and causal directions between variables, thereby identifying causal relationships and detecting cyber-attacks in real-time with reduced computational complexity and improved accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If machine learning models are used to predict attacks, then attack detection capability is improved, but the ability to analyze causal relationships between variables is insufficient

Engineering Contradiction:
Improveattack detection capabilityVSAvoidcausal relationship analysis
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces causal inference as an intermediary mechanism between data collection and attack detection. By analyzing causal relationships between variables using algorithms like PC-algorithm and FCI-algorithm, the system can identify meaningful connections while filtering out spurious correlations, thereby improving both detection reliability and causal analysis capability simultaneously

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional correlation-based machine learning approaches with causal inference mechanisms. This substitution enables the system to not only predict attacks but also understand the underlying causal structures, allowing for more robust detection that accounts for temporal and causal dependencies between variables

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If conventional causal techniques are used to determine causality, then causal relationship identification is achieved, but computational complexity increases significantly

Engineering Contradiction:
Improvecausal relationship identificationVSAvoidcomputational complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by pre-processing data to identify and remove redundant variables, and by pre-computing causal structures from historical data. This preparation reduces the computational burden during real-time causal analysis, making the system feasible for deployment in resource-constrained environments

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by selectively analyzing only the most relevant variable pairs and causal structures, rather than exhaustively evaluating all possible relationships. This approach maintains causal analysis accuracy while significantly reducing computational complexity through targeted analysis of high-priority relationships

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If real-time detection is implemented, then response time to cyber-attacks is improved, but computational resources required increase

Engineering Contradiction:
Improvedetection response timeVSAvoidcomputational resources
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic adaptation by adjusting the level of causal analysis depth and the number of variables monitored based on system state and threat level. During normal operation, the system performs lighter computational tasks, while automatically increasing computational intensity when anomalies are detected, thereby maintaining real-time response without excessive resource consumption

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-service by automatically learning and adapting to normal system behavior patterns, allowing it to detect deviations with minimal computational overhead. The causal models continuously refine themselves using background data, reducing the need for intensive real-time computational analysis while maintaining high detection speed

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20230136071A1System and method for cyber causal attribution via kolmogorov complexity
Publication Date: 2023.05.04 GE INFRASTRUCTURE TECH LLC
  • US20230136071A1 patent drawing
  • US20230136071A1 patent drawing
  • US20230136071A1 patent drawing

AI summary

Some embodiments provide a system and method comprising a memory and a processor to cause the system to: receive a first and second data distribution for a first and second variable, respectively; determine a first and second data optimum number of bins for the first and second data distribution, respectively; create a first and second model for the first and second data distribution using the first and second data optimum number of bins, respectively; apply the first model to the second data distribution to calculate a smallest descriptive size of the second data distribution given the first model; apply the second model to the first data distribution to calculate a smallest descriptive size of the first data distribution given the second model; and determine a causal direction between the first variable and the second variable based on the application of the first and second model. Numerous other aspects are provided.