Cluster-Based Decision Boundaries for Industrial Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial asset control systems connected to the Internet are vulnerable to cyber-attacks, with existing threat detection methods like FDIA being inadequate for detecting multiple simultaneous faults and cyber threats, especially when dealing with diverse monitoring nodes and operational states.

Innovation Solution

A threat detection model creation computer generates cluster-based decision boundaries using monitoring node values to differentiate between normal and threatened operations, automatically determining potential boundaries and transmitting threat alerts based on real-time data analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional FDIA approaches are used to analyze sensor data, then single sensor faults can be detected, but multiple simultaneous faults and cyber threats cannot be detected

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidability to handle multiple faults and different operational states
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the monitoring data into multiple clusters representing different operational states. Each cluster has its own decision boundary, allowing the system to handle multiple simultaneous faults by identifying which cluster the current data belongs to, thereby resolving the limitation of traditional FDIA that can only detect single faults.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic decision boundaries that adapt to different operational states. Instead of using fixed thresholds, the system dynamically adjusts decision boundaries based on the identified operational state (cluster), enabling versatile detection across varying operating conditions and multiple fault scenarios.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If decision boundaries are created for each operational state, then accurate threat detection can be achieved, but system complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidnumber of decision boundaries and clusters
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies partial action by creating decision boundaries only for the most critical operational states or by using a limited number of representative clusters. This approach maintains adequate detection accuracy while avoiding the complexity of creating boundaries for every possible operational condition, thus resolving the trade-off between precision and complexity.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If multiple monitoring nodes are evaluated simultaneously, then comprehensive threat detection is achieved, but detection difficulty increases

Engineering Contradiction:
Improvecomprehensive threat detectionVSAvoidcomplexity of analyzing multiple monitoring nodes
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent merges data from multiple monitoring nodes into a unified feature vector that represents the overall system state. By combining multiple data sources into a single clustered representation, the system achieves comprehensive threat detection while simplifying the analysis process, as the clustering algorithm handles the complexity of integrating multiple nodes automatically.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10805324B2Cluster-based decision boundaries for threat detection in industrial asset control system
Publication Date: 2020.10.13 GE INFRASTRUCTURE TECH LLC
  • US10805324B2 patent drawing
  • US10805324B2 patent drawing
  • US10805324B2 patent drawing

AI summary

A threat detection model creation computer may receive a series of monitoring node values (representing normal and/or threatened operation of the industrial asset control system) and generate a set of normal feature vectors. The threat detection model creation computer may identify a first cluster and a second cluster in the set of feature vectors. The threat detection model creation computer may then automatically determine a plurality of cluster-based decision boundaries for a threat detection model. A first potential cluster-based decision boundary for the threat detection model may be automatically calculated based on the first cluster in the set of feature vectors. Similarly, the threat detection model creation computer may also automatically calculate a second potential cluster-based decision boundary for the threat detection model based on the second cluster in the set of feature vectors.