Cyber-Physical System Mode Switching Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems are vulnerable to cyber-attacks, particularly mode switching attacks, which can disrupt operations and cause catastrophic damage, as existing methods fail to detect such attacks automatically and accurately at the domain layer where sensors, controllers, and actuators are located.

Innovation Solution

A cyber-physical system with monitoring nodes generating current monitoring node values, a features extraction computer platform generating feature vectors, and a system mode estimation computer platform using a probabilistic graphical model to compare estimated and reported system modes, generating a system mode status indication to override the current mode if necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing monitoring methods are used in IT and OT layers, then basic cyber-attack detection is provided, but attacks can still penetrate to the domain layer causing catastrophic damage

Engineering Contradiction:
Improveprotection against cyber-attacksVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the cyber-physical system into three distinct protection layers: IT layer (information technology), OT layer (operation technology), and domain layer (physical sensors, actuators, and controllers). By segmenting the system architecture and applying specialized monitoring at each layer, the patent achieves comprehensive attack detection without requiring complete system redesign. The domain layer monitoring specifically addresses the gap in existing protections by focusing on physical layer anomalies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary monitoring system at the domain layer that acts as a mediator between the OT control systems and the physical processes. This intermediary continuously monitors sensor readings, actuator commands, and controller outputs for anomalies indicative of attacks, providing an additional protection layer without directly modifying the core control systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multiple simultaneous attacks occur at the domain layer, then system performance is severely degraded, but existing failure diagnostic technologies cannot detect these stealthy attacks

Engineering Contradiction:
Improveattack detection accuracyVSAvoidstealthy attack detection
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms that continuously compare expected system behavior (based on control commands and process models) with actual sensor readings. When discrepancies exceed thresholds, the system triggers alerts and can automatically respond to mitigate attacks. This closed-loop feedback enables detection of subtle, coordinated attacks that deviate from normal operational patterns.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent transitions from traditional single-layer monitoring to multi-dimensional monitoring across IT, OT, and domain layers. By adding the domain layer dimension with its specific monitoring metrics (sensor-actuator-controller correlations), the system can detect attacks that remain invisible to conventional IT/OT-focused monitoring approaches.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Extent of automation

If mode switching attacks are not detected, then catastrophic damage occurs, but automatic detection methods are not available

Engineering Contradiction:
Improveattack detection automationVSAvoidsystem safety
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent enables the system to self-monitor and self-diagnose for mode switching attacks through automated analysis of domain layer data. The monitoring system automatically detects inconsistencies between controller mode commands and actual process behavior, triggering automated responses without requiring external intervention. This self-service capability provides continuous protection while maintaining system safety.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11170314B2Detection and protection against mode switching attacks in cyber-physical systems
Publication Date: 2021.11.09 GE INFRASTRUCTURE TECH LLC
  • US11170314B2 patent drawing
  • US11170314B2 patent drawing
  • US11170314B2 patent drawing

AI summary

A cyber-physical system may have a plurality of monitoring nodes each generating a series of current monitoring node values over time that represent current operation of the cyber-physical system. According to some embodiments, a features extraction computer platform may receive the series of current monitoring node values over time and generate current feature vectors based on the series of current monitoring mode values. A system mode estimation computer platform may provide the current feature vectors to a probabilistic graphical model to generate an estimated system mode. The system mode estimation computer platform may then compare the estimated system mode with a currently reported system mode output by the cyber-physical system and generate a system mode status indication based on a result of said comparison. According to some embodiments, the system mode status indication can be used to override the currently reported system mode of the cyber-physical system.