Cyber Attack Localization in Industrial Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial asset control systems connected to the Internet are vulnerable to cyber-attacks, which can disrupt operations and cause catastrophic damage, as existing fault detection and isolation methods are limited in addressing multiple simultaneous faults and distinguishing between independent and dependent attacks.

Innovation Solution

A threat detection computer platform that generates feature vectors from real-time monitoring node signal values, compares them with decision boundaries to classify attacks as independent or dependent, and automatically determines the nature of the threat, using dynamic models and machine learning techniques to provide accurate and timely protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional FDIA approaches are used to detect faults, then single sensor faults can be detected, but multiple simultaneous faults and cyber-attacks cannot be accurately detected or distinguished

Engineering Contradiction:
Improveattack detection accuracyVSAvoidcapability to detect multiple simultaneous attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the attack detection problem into multiple independent decision boundaries, each tailored to a specific monitoring node and attack type. By creating specialized detectors for different nodes (sensors, actuators, controllers) and attack scenarios, the system achieves both high precision for individual attack detection and the versatility to handle multiple simultaneous attacks through parallel monitoring of multiple decision boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension to fault detection by moving beyond traditional residual analysis to a feature-space approach. By transforming monitoring node data into feature vectors and creating decision boundaries in this extended feature space, the system gains the ability to distinguish between multiple simultaneous attacks and normal variations, resolving the contradiction between detection precision and multi-attack versatility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If automated attack classification is implemented, then independent and dependent attacks can be distinguished, but system complexity increases

Engineering Contradiction:
Improveattack classification informationVSAvoidattack analysis system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing decision boundaries and attack classification rules during system setup. The causal dependency relationships between monitoring nodes are pre-analyzed and encoded into the detection algorithm. This allows the system to automatically classify attacks as independent or dependent in real-time without requiring complex runtime analysis, thus preserving attack classification information while managing system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses feedback mechanisms where the detection results from multiple monitoring nodes are continuously analyzed to determine attack independence or dependence. The classification outcome feeds back into the monitoring process, allowing the system to adapt its detection strategy based on the identified attack type, thereby maintaining information completeness without proportionally increasing complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10417415B2Automated attack localization and detection
Publication Date: 2019.09.17 GE INFRASTRUCTURE TECH LLC
  • US10417415B2 patent drawing
  • US10417415B2 patent drawing
  • US10417415B2 patent drawing

AI summary

According to some embodiments, a threat detection computer platform may receive a plurality of real-time monitoring node signal values over time that represent a current operation of the industrial asset. For each stream of monitoring node signal values, the platform may generate a current monitoring node feature vector. The feature vector may also be estimated using a dynamic model output with that monitoring node signal values. The platform may then compare the feature vector with a corresponding decision boundary for that monitoring node, the decision boundary separating a normal state from an abnormal state for that monitoring node. The platform may detect that a particular monitoring node has passed the corresponding decision boundary and classify that particular monitoring node as being under attack. The platform may then automatically determine if the attack on that particular monitoring node is an independent attack or a dependent attack.