CPS Invariant Monitoring for Multi-Stage Cyber Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber physical systems (CPS) are vulnerable to cyber attacks due to their interconnected communications infrastructure, which can lead to compromised sensor and actuator data, causing undesirable system responses such as system shutdown or device damage, and existing detection mechanisms are inadequate for detecting multi-stage attacks.

Innovation Solution

A method involving the derivation and configuration of invariants based on system design or operational data to detect anomalies in CPS, where these invariants are executed on computing devices to monitor and identify cyber attacks by matching retrieved measurements against predefined conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If CPS is connected to external networks for communication, then system functionality and data exchange are improved, but vulnerability to cyber attacks increases

Engineering Contradiction:
Improvecommunication capabilityVSAvoidcyber attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary detection mechanism that sits between the CPS communication infrastructure and external networks. This intermediary monitors and analyzes data packets, sensor readings, and control commands to detect anomalies indicating cyber attacks. The intermediary acts as a buffer that allows communication functionality while filtering out malicious inputs before they can compromise the physical process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary detection actions by establishing invariant-based monitoring rules before cyber attacks occur. These pre-configured detection mechanisms continuously evaluate system state against expected behavioral invariants, enabling early detection of attack patterns. The system prepares detection capabilities in advance rather than reacting after compromise occurs.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If traditional detection mechanisms are used, then implementation simplicity is maintained, but detection capability against multi-stage attacks is insufficient

Engineering Contradiction:
Improvedetection mechanism simplicityVSAvoidattack detection effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the CPS into multiple stages, each with its own PLC and set of sensors/actuators. The detection mechanism is similarly segmented, with each stage having localized invariant-based monitoring. This segmentation allows the system to detect attacks at individual stages while maintaining overall system-wide detection coverage. The modular approach preserves operational simplicity while enhancing detection reliability against multi-stage attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal detection framework based on invariants that can be applied across all stages and types of CPS. The invariant-based monitoring mechanism serves multiple functions: detecting sensor spoofing, actuator manipulation, PLC compromise, and inter-stage attack propagation. This multi-functional approach maintains operational simplicity through a unified detection language while achieving comprehensive attack detection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If invariant-based monitoring is implemented across all stages, then attack detection coverage is improved, but system complexity increases

Engineering Contradiction:
Improveattack detection coverageVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by deriving and implementing invariants specific to each stage's physical process and control logic. Each PLC stage has customized invariants tailored to its local sensors, actuators, and process dynamics. This localized approach ensures comprehensive detection coverage for stage-specific attacks while avoiding the complexity of a single monolithic detection system. The local invariants are computationally efficient and easy to implement at each distributed PLC.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10911482B2Method of detecting cyber attacks on a cyber physical system which includes at least one computing device coupled to at least one sensor and/or actuator for controlling a physical process
Publication Date: 2021.02.02 SINGAPORE UNIVERSITY OF TECHNOLOGY AND DESIGN
  • US10911482B2 patent drawing
  • US10911482B2 patent drawing
  • US10911482B2 patent drawing

AI summary

A method of detecting cyber attacks on a cyber physical system is disclosed, and the system includes at least one computing device coupled to at least one sensor and/or actuator for controlling a physical process. The method comprises: deriving at least one invariant for the computing device, based on a system design of the system or computer code configured to control the system in relation to the physical process or data collected from the system during testing or operation of the system, the invariant defining a set of conditions that enable determination from the sensor and/or actuator regarding process anomalies of the physical process being controlled; configuring the invariant as corresponding computer code; and executing the invariant as the computer code on the computing device to monitor the physical process via the sensor and/or actuator and detect the process anomalies for detecting the cyber attacks.