Intelligent Grid Malicious Attack Detection via CEP Bus
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intelligent utility grid systems face residual security risks that are not adequately addressed by traditional SCADA, enterprise IT, and physical security controls, particularly in detecting and characterizing malicious attacks beyond typical risks.
Innovation Solution
A method and system that utilize a Complex Event Processor (CEP) bus and a Security Information and Event Management (SIEM) system to process non-IT data, applying rules to associate undesired events with IT-related activity and determine the probability of malicious activity, thereby characterizing risks and alerting appropriate authorities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional SCADA, enterprise IT, and physical security controls are used, then basic security protection is provided, but residual security risks remain undetected
Solution Approach 1:
The patent introduces a Complex Event Processor (CEP) bus as an intermediary layer between traditional security controls and threat detection. This CEP bus collects, correlates, and analyzes events from multiple sources including SCADA systems, IT networks, and physical security systems, enabling the detection of residual risks that individual systems cannot detect alone. The CEP acts as a mediator that integrates data across system boundaries to identify patterns indicating malicious activity.
2Measurement precision
If non-IT data sources are integrated for enhanced detection, then malicious activity characterization improves, but system complexity increases
Solution Approach 1:
The patent creates a universal event processing architecture that handles multiple data types (IT logs, SCADA telemetry, physical security alerts, weather data, geographic information) through a single CEP bus framework. This multi-functional system uses standardized event schemas and correlation rules that can process diverse data sources uniformly, reducing the complexity that would otherwise arise from handling each data type separately. The system achieves versatility without proportionally increasing complexity by reusing the same processing infrastructure across different data sources.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
A system for characterizing malicious activity in an intelligent utility grid system includes a system storage in which to store a database including a plurality of rules. A collector is operable to collect and store in the system storage information-technology (IT) data including IT-related activity from the intelligent grid system. A complex event processing (CEP) bus is operable to receive non-IT data including location-specific event data from a plurality of electronic sources, the CEP bus further operable to disregard the non-IT data failing to meet a predetermined level of relevance to one of a plurality of risk-related events. A processor is operable to apply the plurality of rules to the relevant non-IT data to: associate an undesired event with reference to the IT-related activity; and determine a probability that the undesired event is indicative of malicious activity. The processor further applies a risk characterization to the undesired event based on the probability and the IT-related activity.