Fleet-Wide Threat Detection for Industrial Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems connected to the Internet are vulnerable to cyber-attacks, which can disrupt operations and cause catastrophic damage, and existing fault detection and isolation methods are inadequate for detecting multiple simultaneous faults or malicious threats across a fleet of industrial assets.

Innovation Solution

A system that calculates a fleet-wide operation feature vector from information received from multiple industrial assets, compares it with a decision boundary to detect abnormal operations, and automatically transmits responses, such as threat alerts or adjustments, to protect a fleet of industrial assets from cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If FDIA approaches are used to analyze sensor data for threat detection, then single sensor faults can be detected, but multiple simultaneous faults and malicious threats cannot be detected

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddetection scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines data from multiple monitoring nodes (sensors, actuators, control logic) into a unified analysis framework. By merging these diverse data sources and applying joint probability calculations, the system can detect multiple simultaneous faults and malicious threats that single-node FDIA approaches miss.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal threat detection framework that handles multiple types of threats (single faults, multiple simultaneous faults, malicious cyber threats) through a single integrated system. The Bayesian network and decision boundary approach provide multi-functional detection capabilities across different threat types and monitoring node configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple industrial assets are monitored simultaneously to detect fleet-wide threats, then comprehensive protection is achieved, but system complexity and computational burden increase

Engineering Contradiction:
Improvefleet-wide protectionVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the fleet-wide monitoring system into individual asset-level monitoring nodes, each performing local data collection and preliminary analysis. This segmentation allows distributed processing that reduces central computational burden while maintaining comprehensive fleet-wide detection capability through coordinated analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from analyzing individual monitoring node data to a fleet-wide dimension by calculating joint probability distributions across multiple assets. This dimensional expansion enables detection of coordinated attacks and fleet-wide threats while using efficient statistical methods to manage computational complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If real-time analysis of all monitoring node data is performed for each industrial asset, then immediate threat detection is achieved, but processing time and computational resources increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary calculations of probability distributions and decision boundaries during system setup and normal operation phases. By pre-computing these reference values and storing them, the system avoids performing complex full-scale analyses during real-time threat detection, significantly reducing processing time while maintaining detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where detection results from previous time steps inform current analysis. The system uses historical data and previous threat assessments to update current probability calculations, reducing the computational burden of real-time analysis while maintaining high detection precision through adaptive learning.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10476902B2Threat detection for a fleet of industrial assets
Publication Date: 2019.11.12 GE INFRASTRUCTURE TECH LLC
  • US10476902B2 patent drawing
  • US10476902B2 patent drawing
  • US10476902B2 patent drawing

AI summary

A system to protect a fleet of industrial assets may include a communication port to exchange information with a plurality of remote industrial assets. An industrial fleet protection system may receive information from the plurality of remote industrial assets or a cloud-based security platform and calculate, based on information received from multiple industrial assets, a current fleet-wide operation feature vector. The industrial fleet protection system may then compare the current fleet-wide operation feature vector with a fleet-wide decision boundary (e.g., separating normal from abnormal operation of the industrial fleet). The system may then automatically transmit a response (e.g., a cyber-attack threat alert or an adjustment to a decision boundary of an industrial asset) when a result of the comparison indicates abnormal operation of the industrial fleet.