Cyber-attack Detection and Neutralization in Industrial Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information technology and operational technology protection mechanisms are inadequate in preventing cyber-attacks on industrial control systems, as they fail to automatically detect and neutralize cyber threats, leading to potential system downtime and disruption.
Innovation Solution
A threat detection and neutralization system that transforms incoming signals from assets into feature values, detects abnormal patterns based on a predetermined normalcy boundary, and generates neutralized signals to mask the effects of cyber-attacks, utilizing a Boundary and Performance Constrained Resilient Estimator (BPRE) to estimate true operational states and maintain system normalcy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional information technology and operational technology protection mechanisms are used, then system security is maintained to some extent, but the system cannot automatically detect and neutralize cyber threats in real-time
Solution Approach 1:
The system implements self-service by automatically detecting cyber threats and neutralizing them without human intervention. The BPRE algorithm autonomously analyzes sensor signals, identifies attack patterns, and generates neutralized signals to counteract threats, enabling the control system to defend itself like an immune system.
Solution Approach 2:
The system employs feedback mechanisms by continuously monitoring sensor signals from the physical asset, comparing them against learned normal patterns, and automatically adjusting the control signals to neutralize detected threats. The system uses the output feedback to refine its detection capabilities and maintain system normalcy.
2Adaptability or versatility
If more software is made available through the cloud, then business value and functionality are enhanced, but the system becomes more vulnerable to cyber-attacks
Solution Approach 1:
The system introduces an intermediary layer between the cloud-based control software and the physical asset. This intermediary continuously analyzes sensor signals and control signals to detect and neutralize cyber threats, acting as a protective buffer that allows cloud connectivity while blocking malicious attacks before they reach the physical system.
Solution Approach 2:
The system converts the harmful effect of cyber-attacks into a benefit by using the attack signals themselves as input for detection. The BPRE algorithm learns from both normal and attacked signals, and when an attack is detected, it generates neutralized signals that use the attack information to counteract and neutralize the threat, turning the harmful input into a protective mechanism.
3Productivity
If a successful cyber-attack occurs on similar software installations, then a large number of systems can be compromised, but detection and response time is delayed
Solution Approach 1:
The system performs preliminary action by continuously learning and establishing a baseline of normal operational patterns before attacks occur. The BPRE algorithm pre-processes sensor signals and maintains a model of normal system behavior, enabling it to immediately detect deviations caused by cyber-attacks without waiting for post-attack analysis.
Solution Approach 2:
The system ensures continuity of useful action by operating continuously in real-time, constantly analyzing sensor signals and control signals without interruption. This continuous monitoring and neutralization process ensures that cyber threats are detected and counteracted immediately, maintaining uninterrupted operation of the physical asset.
Data Source
AI summary
The example embodiments are directed to a system and method for neutralizing abnormal signals in a cyber-physical system. In one example, the method includes receiving input signals comprising time series data associated with an asset and transforming the input signals into feature values in a feature space, detecting one or more abnormal feature values in the feature space based on a predetermined normalcy boundary associated with the asset, and determining an estimated true value for each abnormal feature value, and performing an inverse transform of each estimated true value to generate neutralized signals comprising time series data and outputting the neutralized signals.


