Intelligent Grid Malicious Attack Detection via CEP Bus

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intelligent utility grid systems face residual security risks that are not adequately addressed by traditional SCADA, enterprise IT, and physical security controls, particularly in detecting and characterizing malicious attacks beyond typical risks.

Innovation Solution

A method and system that utilize a Complex Event Processor (CEP) bus and a Security Information and Event Management (SIEM) system to process non-IT data, applying rules to associate undesired events with IT-related activity and determine the probability of malicious activity, thereby characterizing risks and alerting appropriate authorities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional SCADA, enterprise IT, and physical security controls are used, then basic security protection is provided, but residual security risks remain undetected

Engineering Contradiction:
Improvesecurity protectionVSAvoidundetected malicious activity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a Complex Event Processor (CEP) bus as an intermediary layer between traditional security controls and threat detection. This CEP bus collects, correlates, and analyzes events from multiple sources including SCADA systems, IT networks, and physical security systems, enabling the detection of residual risks that individual systems cannot detect alone. The CEP acts as a mediator that integrates data across system boundaries to identify patterns indicating malicious activity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If non-IT data sources are integrated for enhanced detection, then malicious activity characterization improves, but system complexity increases

Engineering Contradiction:
Improvemalicious activity detection accuracyVSAvoiddata processing system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal event processing architecture that handles multiple data types (IT logs, SCADA telemetry, physical security alerts, weather data, geographic information) through a single CEP bus framework. This multi-functional system uses standardized event schemas and correlation rules that can process diverse data sources uniformly, reducing the complexity that would otherwise arise from handling each data type separately. The system achieves versatility without proportionally increasing complexity by reusing the same processing infrastructure across different data sources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2572278B1Malicious attack detection and analysis
Publication Date: 2018.03.07 ACCENTURE GLOBAL SERVICES LTD
  • EP2572278B1 patent drawingFigure 1A
  • EP2572278B1 patent drawingFigure 1B
  • EP2572278B1 patent drawingFigure 1C

AI summary

A system for characterizing malicious activity in an intelligent utility grid system includes a system storage in which to store a database including a plurality of rules. A collector is operable to collect and store in the system storage information-technology (IT) data including IT-related activity from the intelligent grid system. A complex event processing (CEP) bus is operable to receive non-IT data including location-specific event data from a plurality of electronic sources, the CEP bus further operable to disregard the non-IT data failing to meet a predetermined level of relevance to one of a plurality of risk-related events. A processor is operable to apply the plurality of rules to the relevant non-IT data to: associate an undesired event with reference to the IT-related activity; and determine a probability that the undesired event is indicative of malicious activity. The processor further applies a risk characterization to the undesired event based on the probability and the IT-related activity.