Cyber-Physical Attack Detection via Synchronized Measurement Vectors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Contemporary cyber security systems struggle to detect cyber threats effectively, particularly replay attacks, as they may not appear unusual and require excessive resources, lacking dynamic threat modeling and integration in enterprise architectures.

Innovation Solution

The development of cyber security systems that use machine-learning classifiers and deep unsupervised learning to identify malicious sensor measurements by processing real-time data from cyber-physical systems, such as power grids, without prior knowledge of physical relationships, and can detect attacks in real-time with low latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If anomaly detection methods are used to detect cyber threats, then the system can identify unusual patterns, but replay attacks may go undetected because they do not appear peculiar or abnormal

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddetection reliability against replay attacks
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary actions by embedding unique identifiers and timestamps in sensor measurements before transmission. This preliminary marking allows the security system to later detect replay attacks by checking whether these identifiers and timestamps are valid and not from past executions, thereby solving the problem of replay attacks going undetected by anomaly detection alone.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security layer that sits between the sensor measurements and the anomaly detection system. This intermediary layer validates measurements using physical laws and predefined criteria before they reach the anomaly detection system, preventing replay attacks from being misclassified as normal behavior.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical law detections are used to monitor system parameters, then the system can detect threats based on physical relationships, but parameters are not always known and detection may still be missed

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security framework that can work with or without knowledge of specific physical relationships. The system uses a combination of anomaly detection, physical law validation, and predefined criteria checking that can adapt to different types of cyber-physical systems regardless of whether the specific physical parameters are known, thereby providing reliable detection without requiring complex system-specific knowledge.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the approach from relying on specific physical parameters to using broader validation criteria including timestamps, unique identifiers, and statistical anomalies. This parameter transformation allows the system to detect threats without needing detailed knowledge of the underlying physical relationships, reducing complexity while maintaining reliability.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If contemporary cyber security systems implement anomaly detection and physical law monitoring, then they can detect some threats, but they require excessive resources and lack dynamic threat modeling

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by implementing a layered security approach where not all measurements undergo full validation. Instead, the system uses a combination of lightweight anomaly detection for all measurements and more resource-intensive physical law validation only when anomalies are detected or for critical measurements, thereby reducing overall resource consumption while maintaining detection reliability.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary filtering and validation actions at the sensor level before data reaches the central security system. By pre-marking measurements with identifiers and timestamps, and performing initial validity checks at the source, the system reduces the computational burden on the central system while maintaining comprehensive threat detection capability.

Inventive Principle:
Principle #10Preliminary action

4Speed

If cyber security systems are designed to detect threats in real-time, then they can respond quickly to attacks, but they are difficult to integrate in enterprise architectures

Engineering Contradiction:
Improveresponse speedVSAvoidintegration flexibility
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The patent designs a universal security framework that can be integrated into various enterprise architectures through standardized interfaces and protocols. The system uses common data formats and can work with different types of sensors and systems, allowing quick deployment and real-time threat detection without requiring custom integration work for each enterprise architecture, thereby achieving both speed and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10929529B2Cyber physical attack detection
Publication Date: 2021.02.23 UT BATTELLE LLC
  • US10929529B2 patent drawing
  • US10929529B2 patent drawing
  • US10929529B2 patent drawing

AI summary

A cyber-security threat detection system and method stores physical data measurements from a cyber-physical system and extracts synchronized measurement vectors synchronized to one or more timing pulses. The system and method synthesize data integrity attacks in response to the physical data measurements and applies alternating parameterized linear and non-linear operations in response to the synthesized data integrity attacks. The synthesis renders optimized model parameters used to detect multiple cyber-attacks.