Data-Driven Dynamic Model for Industrial Cyber-Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems connected to the Internet are vulnerable to cyber-attacks, particularly stealthy attacks that occur at the domain layer, which current methods fail to detect automatically, especially when high-fidelity physics models are not available for older assets or those from various manufacturers.

Innovation Solution

A system that uses monitoring nodes to collect normal and synthetic attack data, constructing a data-driven dynamic system model to create a threat detection model, enabling automatic detection of cyber-attacks by distinguishing between normal and abnormal operations without relying on high-fidelity physics models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If high-fidelity physics models are used to detect cyber-attacks, then detection accuracy is improved, but model availability deteriorates for older assets and multi-manufacturer equipment

Engineering Contradiction:
Improveattack detection accuracyVSAvoidmodel availability across different assets
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent creates a virtual copy (digital twin) of the physical industrial asset that replicates its dynamic behavior. This virtual model is trained using historical operational data from multiple sources including sensors, logs, and manuals, enabling attack detection without requiring access to the actual physical asset or proprietary physics models from original manufacturers.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces traditional physics-based mechanical models with a data-driven virtual model that learns system behavior from operational data. This substitution eliminates dependency on manufacturer-specific physics models while maintaining the ability to detect anomalies and cyber-attacks through pattern recognition in the virtual environment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional failure diagnostic technologies are used, then system protection is provided, but detection of stealthy cyber-attacks deteriorates

Engineering Contradiction:
Improvesystem protection capabilityVSAvoidstealthy attack detectability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements continuous feedback loops where the virtual model constantly compares expected system behavior against actual sensor data. When discrepancies indicate potential cyber-attacks, the system generates alerts and can trigger corrective actions. This real-time feedback mechanism enables detection of subtle, stealthy attacks that traditional diagnostic tools miss.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary training of the virtual model using extensive historical data and simulated attack scenarios before deployment. This preliminary action prepares the system to recognize attack patterns in advance, enabling it to detect stealthy cyber-attacks before they cause significant damage, rather than reacting only after traditional failure diagnostics are triggered.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If multiple monitoring nodes are used to detect attacks, then detection coverage is improved, but system complexity and false positives increase

Engineering Contradiction:
Improveattack detection coverageVSAvoidmonitoring system structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges data from multiple monitoring nodes and sensors into a unified virtual model that processes all inputs collectively. Instead of analyzing each sensor independently, the virtual twin integrates multiple data streams to form a comprehensive view of system state, reducing false positives while maintaining wide detection coverage through holistic pattern recognition.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10671060B2Data-driven model construction for industrial asset decision boundary classification
Publication Date: 2020.06.02 GE INFRASTRUCTURE TECH LLC
  • US10671060B2 patent drawing
  • US10671060B2 patent drawing
  • US10671060B2 patent drawing

AI summary

In some embodiments, a system model construction platform may receive, from a system node data store, system node data associated with an industrial asset. The system model construction platform may automatically construct a data-driven, dynamic system model for the industrial asset based on the received system node data. A synthetic attack platform may then inject at least one synthetic attack into the data-driven, dynamic system model to create, for each of a plurality of monitoring nodes, a series of synthetic attack monitoring node values over time that represent simulated attacked operation of the industrial asset. The synthetic attack platform may store, in a synthetic attack space data source, the series of synthetic attack monitoring node values over time that represent simulated attacked operation of the industrial asset. This information may then be used, for example, along with normal operational data to construct a threat detection model for the industrial asset.