CPS Invariant Monitoring for Multi-Stage Cyber Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cyber physical systems (CPS) are vulnerable to cyber attacks due to their interconnected communications infrastructure, which can lead to compromised sensor and actuator data, causing undesirable system responses such as system shutdown or device damage, and existing detection mechanisms are inadequate for detecting multi-stage attacks.
Innovation Solution
A method involving the derivation and configuration of invariants based on system design or operational data to detect anomalies in CPS, where these invariants are executed on computing devices to monitor and identify cyber attacks by matching retrieved measurements against predefined conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If CPS is connected to external networks for communication, then system functionality and data exchange are improved, but vulnerability to cyber attacks increases
Solution Approach 1:
The patent introduces an intermediary detection mechanism that sits between the CPS communication infrastructure and external networks. This intermediary monitors and analyzes data packets, sensor readings, and control commands to detect anomalies indicating cyber attacks. The intermediary acts as a buffer that allows communication functionality while filtering out malicious inputs before they can compromise the physical process.
Solution Approach 2:
The patent implements preliminary detection actions by establishing invariant-based monitoring rules before cyber attacks occur. These pre-configured detection mechanisms continuously evaluate system state against expected behavioral invariants, enabling early detection of attack patterns. The system prepares detection capabilities in advance rather than reacting after compromise occurs.
2Ease of operation
If traditional detection mechanisms are used, then implementation simplicity is maintained, but detection capability against multi-stage attacks is insufficient
Solution Approach 1:
The patent segments the CPS into multiple stages, each with its own PLC and set of sensors/actuators. The detection mechanism is similarly segmented, with each stage having localized invariant-based monitoring. This segmentation allows the system to detect attacks at individual stages while maintaining overall system-wide detection coverage. The modular approach preserves operational simplicity while enhancing detection reliability against multi-stage attacks.
Solution Approach 2:
The patent creates a universal detection framework based on invariants that can be applied across all stages and types of CPS. The invariant-based monitoring mechanism serves multiple functions: detecting sensor spoofing, actuator manipulation, PLC compromise, and inter-stage attack propagation. This multi-functional approach maintains operational simplicity through a unified detection language while achieving comprehensive attack detection.
3Reliability
If invariant-based monitoring is implemented across all stages, then attack detection coverage is improved, but system complexity increases
Solution Approach 1:
The patent applies local quality by deriving and implementing invariants specific to each stage's physical process and control logic. Each PLC stage has customized invariants tailored to its local sensors, actuators, and process dynamics. This localized approach ensures comprehensive detection coverage for stage-specific attacks while avoiding the complexity of a single monolithic detection system. The local invariants are computationally efficient and easy to implement at each distributed PLC.
Data Source
AI summary
A method of detecting cyber attacks on a cyber physical system is disclosed, and the system includes at least one computing device coupled to at least one sensor and/or actuator for controlling a physical process. The method comprises: deriving at least one invariant for the computing device, based on a system design of the system or computer code configured to control the system in relation to the physical process or data collected from the system during testing or operation of the system, the invariant defining a set of conditions that enable determination from the sensor and/or actuator regarding process anomalies of the physical process being controlled; configuring the invariant as corresponding computer code; and executing the invariant as the computer code on the computing device to monitor the physical process via the sensor and/or actuator and detect the process anomalies for detecting the cyber attacks.


