Embedded Anomaly Detector for Cyber-Physical Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber-physical systems (CPS) such as control systems on vehicles, ships, and industrial plants are vulnerable to cyberattacks, with existing security measures failing to effectively detect and prevent both known and novel attack patterns, particularly in scenarios where attackers breach existing defense layers.

Innovation Solution

An embedded anomalies detector (HEAD) is integrated into CPS devices to monitor data input, output, and memory for anomalies, using customized detection algorithms with minimal computational footprint, capable of detecting known and novel attacks by recognizing patterns and deviations from normal behavior, and reporting security events to secure access servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security measures (firewalls, access control, encryption) are implemented, then basic security protection is provided, but they fail to detect novel attack patterns and require significant computational resources

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical security measures (firewalls, access control lists, encryption protocols) with an embedded anomaly detector that uses statistical pattern recognition and machine learning algorithms to automatically detect both known and novel cyberattacks, reducing the need for complex manual security configurations

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The embedded anomaly detector continuously learns from normal system behavior patterns and automatically adapts to detect deviations, enabling the security system to self-improve its detection capabilities without requiring external intervention or complex manual updates for each new threat

Inventive Principle:
Principle #25Self-service

2Measurement precision

If comprehensive monitoring of all data input, output, and memory is performed, then anomaly detection accuracy is improved, but processing overhead and computational resources increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidcomputational energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts and monitors only the most critical data elements and behavioral patterns that are most indicative of cyberattacks, rather than processing all possible data, thereby maintaining high detection accuracy while minimizing computational overhead and energy consumption on resource-constrained embedded devices

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs monitoring at selective critical points in the data flow and uses efficient statistical algorithms that provide sufficient detection accuracy without requiring exhaustive analysis of every single data point, achieving a practical balance between accuracy and computational efficiency

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If parallel monitoring is implemented alongside data processing, then real-time anomaly detection is achieved, but system processing speed may be reduced

Engineering Contradiction:
Improvereal-time detection capabilityVSAvoiddata processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the monitoring function into separate embedded anomaly detection modules that operate independently from the main data processing pipeline, allowing parallel execution without interfering with the primary control system's performance while maintaining real-time detection capabilities

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11886578B2Systems and methods for embedded anomalies detector for cyber-physical systems
Publication Date: 2024.01.30 HONEYWELL INTERNATIONAL INC
  • US11886578B2 patent drawing
  • US11886578B2 patent drawing
  • US11886578B2 patent drawing

AI summary

Disclosed are methods, systems, and non-transitory computer-readable medium for detecting data anomalies on a device. The method may include determining data patterns for data input to the device, data output from the device, and/or data stored in a memory of the device; monitoring the data input, data output, and the data stored in the memory at least based on the determined data patterns in parallel with processing of the data input, data output, and/or the data stored in the memory; and detecting whether an anomaly exists in the data input, data output, and/or the data stored in the memory of the device based on the monitoring.