Fleet-Wide Threat Detection for Industrial Assets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems connected to the Internet are vulnerable to cyber-attacks, which can disrupt operations and cause catastrophic damage, and existing fault detection and isolation methods are inadequate for detecting multiple simultaneous faults or malicious threats across a fleet of industrial assets.
Innovation Solution
A system that calculates a fleet-wide operation feature vector from information received from multiple industrial assets, compares it with a decision boundary to detect abnormal operations, and automatically transmits responses, such as threat alerts or adjustments, to protect a fleet of industrial assets from cyber threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If FDIA approaches are used to analyze sensor data for threat detection, then single sensor faults can be detected, but multiple simultaneous faults and malicious threats cannot be detected
Solution Approach 1:
The patent combines data from multiple monitoring nodes (sensors, actuators, control logic) into a unified analysis framework. By merging these diverse data sources and applying joint probability calculations, the system can detect multiple simultaneous faults and malicious threats that single-node FDIA approaches miss.
Solution Approach 2:
The patent creates a universal threat detection framework that handles multiple types of threats (single faults, multiple simultaneous faults, malicious cyber threats) through a single integrated system. The Bayesian network and decision boundary approach provide multi-functional detection capabilities across different threat types and monitoring node configurations.
2Reliability
If multiple industrial assets are monitored simultaneously to detect fleet-wide threats, then comprehensive protection is achieved, but system complexity and computational burden increase
Solution Approach 1:
The patent segments the fleet-wide monitoring system into individual asset-level monitoring nodes, each performing local data collection and preliminary analysis. This segmentation allows distributed processing that reduces central computational burden while maintaining comprehensive fleet-wide detection capability through coordinated analysis.
Solution Approach 2:
The patent transitions from analyzing individual monitoring node data to a fleet-wide dimension by calculating joint probability distributions across multiple assets. This dimensional expansion enables detection of coordinated attacks and fleet-wide threats while using efficient statistical methods to manage computational complexity.
3Measurement precision
If real-time analysis of all monitoring node data is performed for each industrial asset, then immediate threat detection is achieved, but processing time and computational resources increase
Solution Approach 1:
The patent performs preliminary calculations of probability distributions and decision boundaries during system setup and normal operation phases. By pre-computing these reference values and storing them, the system avoids performing complex full-scale analyses during real-time threat detection, significantly reducing processing time while maintaining detection accuracy.
Solution Approach 2:
The patent implements feedback mechanisms where detection results from previous time steps inform current analysis. The system uses historical data and previous threat assessments to update current probability calculations, reducing the computational burden of real-time analysis while maintaining high detection precision through adaptive learning.
Data Source
AI summary
A system to protect a fleet of industrial assets may include a communication port to exchange information with a plurality of remote industrial assets. An industrial fleet protection system may receive information from the plurality of remote industrial assets or a cloud-based security platform and calculate, based on information received from multiple industrial assets, a current fleet-wide operation feature vector. The industrial fleet protection system may then compare the current fleet-wide operation feature vector with a fleet-wide decision boundary (e.g., separating normal from abnormal operation of the industrial fleet). The system may then automatically transmit a response (e.g., a cyber-attack threat alert or an adjustment to a decision boundary of an industrial asset) when a result of the comparison indicates abnormal operation of the industrial fleet.


