Cluster-Based Decision Boundaries for Industrial Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial asset control systems connected to the Internet are vulnerable to cyber-attacks, with existing threat detection methods like FDIA being inadequate for detecting multiple simultaneous faults and cyber threats, especially when dealing with diverse monitoring nodes and operational states.
Innovation Solution
A threat detection model creation computer generates cluster-based decision boundaries using monitoring node values to differentiate between normal and threatened operations, automatically determining potential boundaries and transmitting threat alerts based on real-time data analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional FDIA approaches are used to analyze sensor data, then single sensor faults can be detected, but multiple simultaneous faults and cyber threats cannot be detected
Solution Approach 1:
The patent segments the monitoring data into multiple clusters representing different operational states. Each cluster has its own decision boundary, allowing the system to handle multiple simultaneous faults by identifying which cluster the current data belongs to, thereby resolving the limitation of traditional FDIA that can only detect single faults.
Solution Approach 2:
The patent implements dynamic decision boundaries that adapt to different operational states. Instead of using fixed thresholds, the system dynamically adjusts decision boundaries based on the identified operational state (cluster), enabling versatile detection across varying operating conditions and multiple fault scenarios.
2Measurement precision
If decision boundaries are created for each operational state, then accurate threat detection can be achieved, but system complexity increases
Solution Approach 1:
The patent applies partial action by creating decision boundaries only for the most critical operational states or by using a limited number of representative clusters. This approach maintains adequate detection accuracy while avoiding the complexity of creating boundaries for every possible operational condition, thus resolving the trade-off between precision and complexity.
3Reliability
If multiple monitoring nodes are evaluated simultaneously, then comprehensive threat detection is achieved, but detection difficulty increases
Solution Approach 1:
The patent merges data from multiple monitoring nodes into a unified feature vector that represents the overall system state. By combining multiple data sources into a single clustered representation, the system achieves comprehensive threat detection while simplifying the analysis process, as the clustering algorithm handles the complexity of integrating multiple nodes automatically.
Data Source
AI summary
A threat detection model creation computer may receive a series of monitoring node values (representing normal and/or threatened operation of the industrial asset control system) and generate a set of normal feature vectors. The threat detection model creation computer may identify a first cluster and a second cluster in the set of feature vectors. The threat detection model creation computer may then automatically determine a plurality of cluster-based decision boundaries for a threat detection model. A first potential cluster-based decision boundary for the threat detection model may be automatically calculated based on the first cluster in the set of feature vectors. Similarly, the threat detection model creation computer may also automatically calculate a second potential cluster-based decision boundary for the threat detection model based on the second cluster in the set of feature vectors.


