Cyber-Physical Anomaly Detection via Parameter Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anomaly detection systems in cyber-physical systems often face challenges in scalability and accuracy due to the need for integrating multiple anomaly detection modules, which can be costly and complex, especially when dealing with failures in control and measuring devices and the complexity of combining information from various modules.

Innovation Solution

A method and system for detecting anomalies in cyber-physical systems by operating multiple anomaly detection modules, where data is pre-processed and then analyzed using selected anomaly detectors, with results combined to identify and characterize combined anomalies, improving scalability and accuracy through data fusion and post-processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple anomaly detection modules are integrated to improve detection accuracy, then the reliability of anomaly detection is improved, but the device complexity and cost increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the anomaly detection task by dividing parameters into different subsets and assigning different anomaly detection algorithms to different subsets. This allows multiple detection modules to work in parallel with reduced complexity each, while collectively achieving high detection accuracy through their coordinated results.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system merges results from multiple anomaly detection algorithms by combining their outputs through a unified interface. This integration allows the system to leverage the strengths of different detection methods while presenting a consolidated anomaly detection capability to users.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multiple anomaly detection modules are deployed to cover various deviations, then the reliability improves, but the ease of operation deteriorates due to the need for data fusion

Engineering Contradiction:
Improveanomaly detection coverageVSAvoidoperation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements a universal anomaly detection interface that can accommodate multiple different detection algorithms through a single unified entry point. This multi-functional interface automatically handles data fusion and result integration, allowing users to benefit from multiple detection methods without needing to manually manage the complexity of combining their outputs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If comprehensive data from APCS telemetry is used to monitor all technological processes, then the measurement precision improves, but the use of energy and computational resources increases

Engineering Contradiction:
Improvemonitoring completenessVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system segments the comprehensive APCS telemetry data into different parameter subsets and processes each subset with appropriate detection algorithms. This segmentation allows the system to maintain complete monitoring coverage while distributing computational load efficiently across multiple specialized processing streams rather than one monolithic processor.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different levels of detection scrutiny to different parameter subsets based on their importance and characteristics. Not all parameters receive identical processing intensity - critical parameters may receive more rigorous analysis while less critical ones receive streamlined processing, optimizing the balance between detection precision and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240086267A1System and method for detecting anomalies in a cyber-physical system
Publication Date: 2024.03.14 AO KASPERSKY LAB
  • US20240086267A1 patent drawing
  • US20240086267A1 patent drawing
  • US20240086267A1 patent drawing

AI summary

Disclosed herein are systems and methods for detecting anomalies in a cyber-physical system. In one aspect, an exemplary method comprises, for a list of parameters of the CPS, collecting data containing values of the parameters of the CPS, generating at least two subsets of parameters of the CPS from the collected data, selecting at least two anomaly detectors from a list of anomaly detectors and selecting at least one corresponding subset of the parameters of the CPS for each selected anomaly detector, pre-processing each subset of the parameters of the CPS and transmitting an output of the pre-processing to the corresponding anomaly detector, for each pre-processed subset, detecting anomalies in the data using the corresponding respective anomaly detector, and detecting a combined anomaly in the CPS by combining and processing results obtained from the selected at least two anomaly detectors.