Feature Extraction Models for Industrial Cyber-Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems connected to the Internet are vulnerable to cyber-attacks that can disrupt operations and cause catastrophic damage, with existing methods failing to detect such attacks automatically and accurately, especially when multiple attacks occur simultaneously.

Innovation Solution

A system that uses heterogeneous monitoring nodes to generate feature vectors through a multi-modal, multi-disciplinary framework, performing feature dimensionality reduction and data-driven machine learning to derive digital models and calculate decision boundaries for automatic detection of abnormal states, thereby protecting industrial assets from cyber-attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multiple monitoring nodes are used to detect cyber-attacks, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the monitoring function across multiple heterogeneous monitoring nodes distributed throughout the industrial control system. Each node independently monitors specific parameters and generates monitoring node values, which are then processed by the offline model creation computer. This segmentation allows the system to achieve high detection accuracy through distributed observation while managing complexity by assigning specialized monitoring functions to individual nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an offline model creation computer as an intermediary that processes data from multiple monitoring nodes and generates decision boundaries. This intermediary component consolidates the complex processing requirements, transforming raw monitoring data into actionable detection rules that can be applied in real-time without overwhelming the distributed monitoring nodes or requiring complex coordination between them.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If feature extraction and dimensionality reduction are performed, then computational efficiency improves, but information loss may occur

Engineering Contradiction:
Improveprocessing speedVSAvoidfeature information loss
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system extracts only the most relevant features from the raw monitoring node values through a feature extraction process. The offline model creation computer identifies and extracts salient features that are most indicative of cyber-attacks, discarding redundant information. This extraction process is followed by dimensionality reduction that further selects the most critical features, ensuring computational efficiency while preserving the essential information needed for accurate attack detection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms the original monitoring node values into different parameter representations through feature extraction and dimensionality reduction. By changing the parameter space from raw sensor values to extracted features and then to a reduced set of critical features, the system achieves computational efficiency while maintaining detection accuracy. The transformation is designed to preserve the discriminative information necessary for distinguishing normal operations from cyber-attacks.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If domain level features are generated from sensor measurements and digital models, then detection accuracy improves, but computational complexity increases

Engineering Contradiction:
Improveabnormal state detection accuracyVSAvoidmodeling complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-computing domain level features and decision boundaries offline using historical monitoring data and digital models. The offline model creation computer generates these features and establishes detection thresholds during periods when the system is not under attack, storing them for rapid application during real-time monitoring. This preliminary computation reduces the complexity of real-time detection while maintaining high accuracy, as the computationally intensive modeling work is done in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service by having the system automatically generate domain level features and update decision boundaries using the monitoring data it collects. The offline model creation computer continuously refines the detection model by learning from historical data, reducing the need for manual model configuration and updating. This self-service approach manages modeling complexity by automating the feature generation and model refinement processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12099571B2Feature extractions to model large-scale complex control systems
Publication Date: 2024.09.24 GE INFRASTRUCTURE TECH LLC
  • US12099571B2 patent drawing
  • US12099571B2 patent drawing
  • US12099571B2 patent drawing

AI summary

Heterogeneous monitoring nodes may each generate a series of monitoring node values over time associated with operation of an industrial asset. An offline abnormal state detection model creation computer may receive the series of monitoring node values and perform a feature extraction process using a multi-modal, multi-disciplinary framework to generate an initial set of feature vectors. Then feature dimensionality reduction is performed to generate a selected feature vector subset. The model creation computer may derive digital models through a data-driven machine learning modeling method, based on input/output variables identified by domain experts or by learning from the data. The system may then automatically generate domain level features based on a difference between sensor measurements and digital model output. A decision boundary may then be automatically calculated and output for an abnormal state detection model based on the selected feature vector subset and the plurality of derived generated domain level features.