Hierarchical Abnormality Localization for Cyber-Physical Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current industrial control systems are vulnerable to cyber-attacks that can disrupt operations and cause catastrophic damage, as existing methods fail to detect abnormalities at the domain layer where sensors, controllers, and actuators are located, and existing protection schemes are passive and inadequate against mass spoofing or replay attacks.

Innovation Solution

A hierarchical abnormality localization computer platform that generates feature vectors and decision boundaries to automatically detect and localize abnormalities in a cyber-physical system, using a multi-level hierarchy to determine abnormality status and isolate issues to specific monitoring nodes, enabling accurate and automatic protection against cyber-attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passive monitoring data collection methods are used, then the system can operate with simple architecture, but the system fails to detect mass spoofing attacks and replay attacks

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the monitoring system into multiple active monitoring nodes distributed across the cyber-physical system. Each node independently collects and analyzes data from specific subsystems, enabling comprehensive coverage without requiring a single complex centralized system. This segmentation allows detection of spoofing and replay attacks while maintaining manageable node-level complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces watermarking signals as intermediaries injected into control inputs. These watermarks serve as detectable markers that allow the system to distinguish legitimate control commands from spoofed ones. The watermarking mechanism acts as a mediator between the controller and actuators, enabling reliable detection without fundamentally redesigning the entire control architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a single monitoring node is used, then the system architecture is simple, but subtle stealthy attacks are not readily detectable

Engineering Contradiction:
Improveattack detection accuracyVSAvoidnumber of monitoring nodes
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the monitoring function across multiple distributed nodes, each responsible for specific subsystems or process areas. This segmentation enables cross-validation of measurements and detection of subtle anomalies that would be invisible to a single node. The segmented architecture maintains operational simplicity at each node while achieving high detection accuracy collectively.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines data from multiple monitoring nodes through a centralized analysis platform that aggregates measurements, compares against expected behavior, and identifies coordinated attacks. This merging of distributed node data enables detection of subtle stealthy attacks that affect multiple subsystems, achieving high detection accuracy without requiring each individual node to be overly complex.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If existing failure and diagnostics technologies are used, then the system can identify faults, but the technologies do not adequately address cyber-attacks when substantial numbers of monitoring nodes need to be analyzed

Engineering Contradiction:
Improvefault and attack differentiationVSAvoidanalysis of multiple monitoring nodes
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and analyzes specific attack characteristics from the data collected by multiple monitoring nodes. By isolating patterns unique to cyber-attacks (such as coordinated deviations across nodes, impossible physical behaviors, or inconsistencies with control commands), the system can differentiate attacks from genuine faults even when analyzing substantial numbers of nodes. This extraction approach maintains manageable complexity by focusing on discriminative features rather than analyzing all node data equally.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary watermarking and data validation at each monitoring node before central aggregation. This preliminary action filters and pre-processes data to remove obvious anomalies and reduce the burden on centralized analysis. By conducting initial screening at the node level, the system achieves reliable fault-attack differentiation across multiple nodes without overwhelming computational complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11503045B2Scalable hierarchical abnormality localization in cyber-physical systems
Publication Date: 2022.11.15 GE INFRASTRUCTURE TECH LLC
  • US11503045B2 patent drawing
  • US11503045B2 patent drawing
  • US11503045B2 patent drawing

AI summary

A cyber-physical system may have monitoring nodes that generate a series of current monitoring node values over time that represent current operation of the system. A hierarchical abnormality localization computer platform accesses a multi-level hierarchy of elements, and elements in a first level of the hierarchy are associated with elements in at least one lower level of the hierarchy and at least some elements may be associated with monitoring nodes. The computer platform may then determine, based on feature vectors and a decision boundary, an abnormality status for a first element in the highest level of the hierarchy. If the abnormality status indicates an abnormality, the computer platform may determine an abnormality status for elements, associated with the first element, in at least one level of the hierarchy lower than the level of the first element. These determinations may be repeated until an abnormality is localized to a monitoring node.