Cyber-Physical Anomaly Detection Using Physics-Based Error Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cyber-physical control systems lack effective anomaly detection mechanisms that integrate both cyber and physical state data, leading to vulnerabilities in detecting malicious attacks, especially those that conform to normal behavior patterns, and are often plagued by false positives and the need for complex, error-prone physical state models.

Innovation Solution

A method and apparatus for anomaly detection in cyber-physical systems that acquire physical features defining relationships between physical attributes, determine physical state error metrics, and integrate these with cyber state metrics using membership functions to detect anomalous behavior, thereby enhancing security without requiring complex physical state models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cyber-based anomaly detection means are used, then detection of cyber behavior anomalies is possible, but attackers can exploit these means by conforming cyber attacks to certain network traffic patterns

Engineering Contradiction:
Improveanomaly detection reliabilityVSAvoidattack effectiveness
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent combines cyber-based anomaly detection with physics-based anomaly detection into an integrated system. The cyber component monitors network traffic patterns while the physics component monitors physical process variables and their relationships. By merging these two detection mechanisms, the system achieves more reliable anomaly detection that cannot be easily circumvented by attackers conforming to network traffic patterns, since the physics-based detection independently verifies actual physical system behavior.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces physics-based relationships as an intermediary layer between cyber data and anomaly detection. Instead of relying solely on cyber behavior analysis, the system uses physical laws and relationships (e.g., thermodynamic relationships, fluid dynamics equations) as mediators to verify whether observed cyber and physical data are consistent with actual physical system behavior, thereby preventing attacks that mimic normal network traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical state models are developed for anomaly detection, then physical process monitoring is possible, but extensive engineering efforts are required and the models are not scalable

Engineering Contradiction:
Improvephysical process monitoring capabilityVSAvoidmodel development complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and utilizes only the essential physics-based relationships needed for anomaly detection rather than developing complete, comprehensive physical state models. By taking out only the critical relationships (e.g., key thermodynamic relationships, fundamental conservation laws) that are necessary for detecting anomalies, the system achieves effective physical process monitoring without the extensive engineering efforts and complexity of full physical state modeling. This selective extraction makes the approach scalable to different systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent develops physics-based relationship frameworks that are universal and can be applied across different physical processes and systems. Rather than creating custom models for each specific system, the system uses general physics principles (thermodynamics, fluid dynamics, heat transfer) that can be adapted to various industrial processes, making the approach scalable and reducing engineering efforts for deployment in different contexts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If physical state models are developed for anomaly detection, then physical process monitoring is possible, but integration with cyber-based anomaly detection means is not suitable

Engineering Contradiction:
Improvephysical anomaly detection capabilityVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges physics-based anomaly detection with cyber-based anomaly detection into a unified, integrated system. The architecture combines cyber data processing (network traffic analysis) with physics-based data processing (physical relationship verification) in a coordinated manner, enabling seamless integration that leverages the strengths of both approaches while maintaining manageable system complexity through modular design and standardized interfaces.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If conventional security perimeter protections are implemented, then defense against inadvertent access is possible, but defense against cyberattacks conforming to normal behavior patterns is insufficient

Engineering Contradiction:
Improvesecurity perimeter protectionVSAvoidadvanced cyberattack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where the integrated cyber-physical anomaly detection system continuously monitors system behavior, compares observed data against both cyber baselines and physics-based expectations, and adjusts detection parameters and alerting thresholds dynamically. This feedback loop enables the system to adapt to evolving attack patterns while maintaining robust security perimeter protection, detecting advanced cyberattacks that conform to normal behavior by identifying inconsistencies between cyber data and physical system responses.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11874930B2Anomaly detection for cyber-physical systems
Publication Date: 2024.01.16 BATTELLE ENERGY ALLIANCE LLC
  • US11874930B2 patent drawing
  • US11874930B2 patent drawing
  • US11874930B2 patent drawing

AI summary

An anomaly detector is configured to construct cyber and/or physical features comprising information configured to characterize the cyber and/or physical state of a cyber-physical system. The physical features may be based on physical and/or physics-based relationships between a plurality of physical state attributes. A health of the cyber-physical system may be based on an error between estimates of one or more of the physical state attributes and measurements of the one or more physical state attributes. The relationships may be incorporated into machine learning membership functions used to classify cyber and/or physical behavior of the system.