Cyber-attack Detection and Neutralization in Industrial Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information technology and operational technology protection mechanisms are inadequate in preventing cyber-attacks on industrial control systems, as they fail to automatically detect and neutralize cyber threats, leading to potential system downtime and disruption.

Innovation Solution

A threat detection and neutralization system that transforms incoming signals from assets into feature values, detects abnormal patterns based on a predetermined normalcy boundary, and generates neutralized signals to mask the effects of cyber-attacks, utilizing a Boundary and Performance Constrained Resilient Estimator (BPRE) to estimate true operational states and maintain system normalcy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional information technology and operational technology protection mechanisms are used, then system security is maintained to some extent, but the system cannot automatically detect and neutralize cyber threats in real-time

Engineering Contradiction:
Improvesystem securityVSAvoidautomatic threat detection and neutralization
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system implements self-service by automatically detecting cyber threats and neutralizing them without human intervention. The BPRE algorithm autonomously analyzes sensor signals, identifies attack patterns, and generates neutralized signals to counteract threats, enabling the control system to defend itself like an immune system.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system employs feedback mechanisms by continuously monitoring sensor signals from the physical asset, comparing them against learned normal patterns, and automatically adjusting the control signals to neutralize detected threats. The system uses the output feedback to refine its detection capabilities and maintain system normalcy.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If more software is made available through the cloud, then business value and functionality are enhanced, but the system becomes more vulnerable to cyber-attacks

Engineering Contradiction:
Improvebusiness valueVSAvoidcyber vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system introduces an intermediary layer between the cloud-based control software and the physical asset. This intermediary continuously analyzes sensor signals and control signals to detect and neutralize cyber threats, acting as a protective buffer that allows cloud connectivity while blocking malicious attacks before they reach the physical system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system converts the harmful effect of cyber-attacks into a benefit by using the attack signals themselves as input for detection. The BPRE algorithm learns from both normal and attacked signals, and when an attack is detected, it generates neutralized signals that use the attack information to counteract and neutralize the threat, turning the harmful input into a protective mechanism.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Productivity

If a successful cyber-attack occurs on similar software installations, then a large number of systems can be compromised, but detection and response time is delayed

Engineering Contradiction:
Improvesystem operation continuityVSAvoiddetection and response time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary action by continuously learning and establishing a baseline of normal operational patterns before attacks occur. The BPRE algorithm pre-processes sensor signals and maintains a model of normal system behavior, enabling it to immediately detect deviations caused by cyber-attacks without waiting for post-attack analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system ensures continuity of useful action by operating continuously in real-time, constantly analyzing sensor signals and control signals without interruption. This continuous monitoring and neutralization process ensures that cyber threats are detected and counteracted immediately, maintaining uninterrupted operation of the physical asset.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10771495B2Cyber-attack detection and neutralization
Publication Date: 2020.09.08 GE INFRASTRUCTURE TECH LLC
  • US10771495B2 patent drawing
  • US10771495B2 patent drawing
  • US10771495B2 patent drawing

AI summary

The example embodiments are directed to a system and method for neutralizing abnormal signals in a cyber-physical system. In one example, the method includes receiving input signals comprising time series data associated with an asset and transforming the input signals into feature values in a feature space, detecting one or more abnormal feature values in the feature space based on a predetermined normalcy boundary associated with the asset, and determining an estimated true value for each abnormal feature value, and performing an inverse transform of each estimated true value to generate neutralized signals comprising time series data and outputting the neutralized signals.