Cyber-Physical System Vulnerability Assessment via Graph Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches to preventing sabotage of cyber-physical systems are inadequate as they focus on software hacking and ignore downstream effects, and lack coordination among different human entities and vendors, resulting in an incomplete picture of vulnerabilities.

Innovation Solution

A method that uses dynamical model data to generate vulnerability metrics for links between nodes in a graph representing cyber-physical systems, identifying and ranking vulnerable links and nodes based on these metrics to facilitate mitigation analysis and reduce vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional approaches focus on software hacking prevention, then software security is improved, but downstream effects and system-wide vulnerabilities are not detected

Engineering Contradiction:
Improvesoftware securityVSAvoidsystem-wide vulnerability picture
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system segments the cyber-physical system into discrete nodes and links, analyzing vulnerability at each component level while maintaining system-wide context. This allows detailed software security analysis at individual nodes while aggregating results to provide a complete system-wide vulnerability picture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines multiple analysis perspectives (software hacking, downstream effects, system destabilization) into a unified vulnerability assessment framework. By merging these previously separate concerns into a single graph-based model, the system provides comprehensive security analysis without losing any dimension of vulnerability.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If vulnerability analysis is performed manually by human experts, then detailed assessment is possible, but the process is time-consuming and incomplete

Engineering Contradiction:
Improvevulnerability assessment detailVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs automated vulnerability analysis using graph-based models and computational algorithms. The computer system independently calculates vulnerability metrics, identifies critical links, and generates assessments without requiring manual human analysis, thereby providing detailed results rapidly and efficiently.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual human expert analysis with automated computational mechanisms. Graph theory algorithms and vulnerability metric calculations substitute for human reasoning processes, enabling rapid, consistent, and comprehensive vulnerability assessment across the entire system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If comprehensive vulnerability assessment of all links is performed, then complete security picture is achieved, but computational complexity increases

Engineering Contradiction:
Improvevulnerability detection completenessVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system calculates vulnerability metrics locally at each link in the graph rather than performing global analysis of the entire system at once. By computing vulnerability measures for individual links between nodes and then aggregating these local assessments, the system achieves comprehensive coverage while managing computational complexity through divide-and-conquer.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent transforms the vulnerability assessment problem by changing parameters from traditional security metrics to graph-theoretic measures (link vulnerability, node vulnerability, critical link identification). This parameter transformation enables efficient computational algorithms that scale better with system size while maintaining assessment completeness.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10581893B2Modeling of attacks on cyber-physical systems
Publication Date: 2020.03.03 BRIGHAM YOUNG UNIV
  • US10581893B2 patent drawing
  • US10581893B2 patent drawing
  • US10581893B2 patent drawing

AI summary

Techniques of preventing sabotage attacks in cyber-physical systems involve automatically identifying links between nodes of a graph representing cyber-physical systems as vulnerable to sabotage attacks according to a vulnerability metric for each link. The vulnerability metric used depends on the particular sabotage attack used to determine the vulnerable links. Once a computer configured to design cyber-physical systems based on vulnerability to sabotage attacks receives data representing the graph, the computer enumerates the possible links between nodes of the graph along which a sabotage attack may be performed. For each of those links, the computer computes the vulnerability metric. The computer then ranks the links according to respective values of the vulnerability metric. Based on the ranking, a designer may then perform a mitigation analysis that results in changes to the graph to reduce the vulnerability at each node accessible to a malicious actor.