Factory Process Signal Monitoring for Malware Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Factory processes and automated systems are vulnerable to malware attacks that can cause subtle yet severe disruptions, evading existing IT security measures and leading to equipment damage and yield diminishment by altering control parameters and providing false feedback.

Innovation Solution

A deep learning processor is trained to correlate input operating instructions with output control signals and measured control values, detecting anomalies and providing indications of anomalous activity to prevent damage by identifying deviations from expected ranges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IT security measures are used to protect factory control systems, then basic security is provided, but subtle malware attacks that alter control parameters can evade detection and cause severe disruptions

Engineering Contradiction:
Improvedetection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A deep learning processor is introduced as an intermediary component between the controller and the process equipment. This processor receives copies of control signals and operating instructions, analyzes them for anomalies using trained machine learning models, and generates alerts when deviations are detected. The intermediary approach enables sophisticated anomaly detection without directly modifying the existing control system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The deep learning processor is pre-trained using historical control signal data and operating instructions to learn normal system behavior patterns before deployment. This preliminary training enables the system to detect subtle anomalies and deviations that traditional real-time monitoring would miss, allowing the system to anticipate and alert on potential malware attacks before they cause significant damage.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If control parameters are monitored in real-time to detect malware attacks, then detection capability is improved, but false feedback from malware can still evade traditional monitoring and lead to equipment damage

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidequipment damage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system implements a feedback mechanism where the deep learning processor continuously receives control signals and operating instructions, compares them against learned normal behavior patterns, and generates alerts when anomalies are detected. This feedback loop enables real-time detection of malware-induced deviations in control parameters, allowing operators to take corrective action before equipment damage occurs.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Traditional mechanical or rule-based monitoring systems are replaced with an intelligent deep learning processor that uses machine learning algorithms to detect anomalies. This substitution enables the system to identify subtle patterns and deviations that would be impossible for traditional monitoring to detect, significantly improving the ability to catch malware attacks that attempt to evade conventional security measures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If deep learning processors are deployed to detect subtle anomalies in control signals, then detection precision is improved, but system resource consumption and processing complexity increase

Engineering Contradiction:
Improvecontrol signal analysis precisionVSAvoidprocessor energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The monitoring system is segmented into distinct functional components: signal collection modules that gather control signals and operating instructions, a deep learning processor that performs anomaly detection, and alert generation modules that notify operators. This segmentation allows the computationally intensive deep learning analysis to be performed separately from the real-time control system, reducing the energy burden on the control devices themselves while maintaining high detection precision.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11953863B2Dynamic monitoring and securing of factory processes, equipment and automated systems
Publication Date: 2024.04.09 NANOTRONICS IMAGING INC
  • US11953863B2 patent drawing
  • US11953863B2 patent drawing
  • US11953863B2 patent drawing

AI summary

A training set that includes at least two data types corresponding to operations and control of a manufacturing process is obtained. A deep learning processor is trained to predict expected characteristics of output control signals that correspond with one or more corresponding input operating instructions. A first input operating instruction is received from a first signal splitter. A first output control signal is received from a second signal splitter. The deep learning processor correlates the first input operating instruction and the first output control signal. Based on the correlating, the deep learning processor determines that the first output control signal is not within a range of expected values based on the first input operating instruction. Responsive to the determining, an indication of an anomalous activity is provided as a result of detection of the anomalous activity in the manufacturing process.