Cyber-physical system defense via sensor disagreement clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber-physical systems face increased vulnerability due to remote access and reliance on automated control systems, with traditional perimeter security struggling to detect and counter well-formed, coordinated multi-vector attacks, leading to costly defense efforts and potential system compromise.

Innovation Solution

Implementing a robust defense system that utilizes multiple redundant sensors to analyze disagreements and apply statistical models to identify potential attacks, including cluster analysis and decision tree logic to determine compromised sensors, thereby providing ongoing defense beyond perimeter security mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional perimeter security mechanisms are used, then system security is maintained at basic level, but the system cannot detect well-formed coordinated multi-vector attacks

Engineering Contradiction:
Improvedetection capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security system into multiple independent sensor units that monitor different aspects of system behavior. Each sensor independently evaluates specific parameters and generates alerts, rather than relying on a single complex perimeter security mechanism. This segmentation enables detection of multi-vector attacks through coordinated analysis of multiple independent observations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements sensors with multi-functional capabilities that can detect various types of attacks (intrusion, denial of service, malware) using unified statistical analysis methods. The same sensor infrastructure and analytical framework handle diverse threat types, making the system universally applicable to different attack scenarios without requiring separate specialized mechanisms for each threat type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If multiple redundant sensors are deployed, then detection accuracy improves, but system complexity and cost increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidsensor system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines multiple sensor data streams and integrates their observations through statistical analysis to achieve superior detection accuracy. Rather than managing complex independent sensor systems, the methodology merges sensor outputs into unified statistical models that automatically correlate observations across sensors, reducing operational complexity while improving precision.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent transforms sensor observations into statistical parameters and uses parameter-based analysis to detect attacks. By converting raw sensor data into standardized statistical metrics (means, variances, correlation coefficients), the system simplifies the processing of multi-sensor inputs and enables precise attack detection through parameter thresholding and anomaly detection.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If perimeter defense is strengthened, then external access is blocked, but automated control systems remain vulnerable to internal attacks

Engineering Contradiction:
Improveexternal attack resistanceVSAvoidinternal system security
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements continuous feedback loops where sensors monitor system behavior, statistical analysis evaluates observed patterns, and alerts are generated when anomalies detected. This feedback mechanism enables real-time detection of both external and internal attacks by continuously comparing actual system behavior against expected operational patterns, providing ongoing security verification beyond static perimeter defenses.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables the control system to self-monitor and self-detect attacks through integrated sensors and statistical analysis. The system automatically evaluates its own operational parameters, identifies anomalies indicating attacks, and generates alerts without requiring external security intervention. This self-service capability provides continuous internal security verification independent of perimeter defense effectiveness.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9942262B1Cyber-physical system defense
Publication Date: 2018.04.10 UNIV OF VIRGINIA PATENT FOUND
  • US9942262B1 patent drawing
  • US9942262B1 patent drawing
  • US9942262B1 patent drawing

AI summary

System and techniques for cyber-physical system defense are described herein. Sensor disagreements between a plurality of sensors over time can be sampled. Cluster analysis on the sampled sensor disagreements can be performed. A deviation indication can be provided in response to the cluster analysis resulting in disagreement density beyond a threshold.