Cyber-Attack Detection at Sample Speed for Industrial Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial asset control systems connected to the Internet are vulnerable to cyber-attacks, which can disrupt operations and cause catastrophic damage, as existing fault detection and isolation methods are inadequate in detecting multiple simultaneous threats in real-time.

Innovation Solution

A threat detection model using deep learning processes monitoring node values to compute feature vectors and automatically calculate decision boundaries, distinguishing between normal and abnormal operations, enabling rapid and accurate detection of cyber-attacks across multiple monitoring nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional FDIA approaches are used to analyze sensor data, then single sensor faults can be detected, but multiple simultaneous cyber-attacks cannot be detected and detection speed is insufficient for real-time protection

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the industrial control system into multiple monitoring nodes, each independently monitored by the deep learning model. This allows the system to detect multiple simultaneous attacks across different nodes without requiring a single overly complex detection mechanism, resolving the contradiction between comprehensive detection capability and system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces deep learning models as an intermediary layer between sensor data collection and fault detection. This intermediary automatically processes and analyzes data from multiple monitoring nodes, enabling detection of complex multi-node cyber-attacks while keeping the overall system architecture manageable and not excessively complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If deep learning models are used to process monitoring data, then detection accuracy improves, but processing time increases making real-time detection difficult

Engineering Contradiction:
Improvedetection precisionVSAvoiddetection delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary action by training the deep learning model offline with normal and abnormal operation data before deployment. This pre-training establishes the model's detection capabilities in advance, allowing it to rapidly classify new monitoring data in real-time without requiring complex online computation, thus achieving both high precision and fast response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by focusing the deep learning model's processing on critical features and patterns relevant to cyber-attack detection rather than analyzing all possible data dimensions. This selective processing maintains high detection precision while reducing computational overhead and processing time for real-time operation.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If monitoring nodes are increased to detect attacks across multiple components, then detection coverage improves, but data processing complexity and computational load increase

Engineering Contradiction:
Improvedetection coverageVSAvoiddata processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal deep learning model that can process and analyze data from multiple different types of monitoring nodes (sensors, actuators, controllers) using the same architecture and algorithms. This multi-functional approach allows comprehensive coverage across diverse system components while maintaining consistent processing methods, thereby reducing overall data processing complexity despite increased monitoring scope.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10594712B2Systems and methods for cyber-attack detection at sample speed
Publication Date: 2020.03.17 GE INFRASTRUCTURE TECH LLC
  • US10594712B2 patent drawing
  • US10594712B2 patent drawing
  • US10594712B2 patent drawing

AI summary

A threat detection model creation computer receives normal monitoring node values and abnormal monitoring node values. At least some received monitoring node values may be processed with a deep learning model to determine parameters of the deep learning model (e.g., a weight matrix and affine terms). The parameters of the deep learning model and received monitoring node values may then be used to compute feature vectors. The feature vectors may be spatial along a plurality of monitoring nodes. At least one decision boundary for a threat detection model may be automatically calculated based on the computed feature vectors, and the system may output the decision boundary separating a normal state from an abnormal state for that monitoring node. The decision boundary may also be obtained by combining feature vectors from multiple nodes. The decision boundary may then be used to detect normal and abnormal operation of an industrial asset.