Cooperative Anomaly Detection Across Multiple Control Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems lack cooperative anomaly detection across multiple systems, limiting their ability to accurately identify and respond to anomalies in a networked environment.
Innovation Solution
A networked anomaly detection system comprising multiple analysis devices that acquire and analyze events from control systems, with a first device determining whether to indicate events to a second device for correlation analysis, enabling detection of anomalies that may not be apparent in a single system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If multiple control systems operate independently with individual anomaly detection, then each system can maintain simple monitoring logic, but the overall anomaly detection accuracy across the networked system is limited
Solution Approach 1:
The patent merges multiple independent anomaly detection systems into a cooperative networked system. Analysis devices from different control systems share event information and collaborate to detect anomalies, combining their individual detection capabilities to achieve higher overall accuracy while maintaining relatively simple individual device architectures.
Solution Approach 2:
The patent introduces an event sharing mechanism as an intermediary that enables communication between analysis devices. This mediator allows devices to exchange event information without requiring direct complex interconnections, facilitating cooperative anomaly detection while keeping individual device complexity manageable.
2Adaptability or versatility
If control systems are connected through external networks with generic protocols, then multiple systems can cooperate and share information, but the risk of undetected anomalies spreading across systems increases
Solution Approach 1:
The patent implements feedback mechanisms where analysis devices continuously monitor and share event information across the network. When anomalies are detected or suspected, the system provides feedback through event sharing to other analysis devices, enabling them to adjust their monitoring and detection strategies accordingly, thus preventing anomaly propagation.
Solution Approach 2:
The patent enables preliminary anomaly detection by allowing analysis devices to share event information before anomalies fully propagate across the network. By detecting potential anomalies early through cooperative monitoring and sharing preliminary detection results, the system can take preventive actions to stop anomaly spread.
3Reliability
If individual control systems perform comprehensive anomaly monitoring, then each system can detect anomalies within its own boundaries, but correlated anomalies across multiple systems cannot be identified
Solution Approach 1:
The patent merges the monitoring perspectives of multiple control systems by enabling analysis devices to share event information. This combination allows the system to identify correlated anomalies that span across multiple systems, which would be invisible to any single independent monitoring system, thereby improving overall detection reliability.
Solution Approach 2:
The patent creates a universal event sharing framework that enables analysis devices to perform multiple functions: individual anomaly detection, event sharing, and correlated anomaly identification. This multi-functional approach allows the system to maintain individual system reliability while also detecting cross-system patterns.
Data Source
AI summary
An anomaly detection system for detecting an anomaly in a plurality of control systems comprises a plurality of analysis devices that are associated with the respective control systems and that acquire an event occurring in an associated control system and analyze the event to determine whether there is an anomaly. A first analysis device among the plurality of analysis devices determines whether an event occurring in the associated control system is to be indicated to a second analysis device among the plurality of analysis devices, and the second analysis device determines that there is an anomaly on condition that the event indicated by the first analysis device has correlation with an event indicated by an analysis device other than the first analysis device.


