Hierarchical Abnormality Localization for Cyber-Physical Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current industrial control systems are vulnerable to cyber-attacks that can disrupt operations and cause catastrophic damage, as existing methods fail to detect abnormalities at the domain layer where sensors, controllers, and actuators are located, and existing protection schemes are passive and inadequate against mass spoofing or replay attacks.
Innovation Solution
A hierarchical abnormality localization computer platform that generates feature vectors and decision boundaries to automatically detect and localize abnormalities in a cyber-physical system, using a multi-level hierarchy to determine abnormality status and isolate issues to specific monitoring nodes, enabling accurate and automatic protection against cyber-attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passive monitoring data collection methods are used, then the system can operate with simple architecture, but the system fails to detect mass spoofing attacks and replay attacks
Solution Approach 1:
The patent segments the monitoring system into multiple active monitoring nodes distributed across the cyber-physical system. Each node independently collects and analyzes data from specific subsystems, enabling comprehensive coverage without requiring a single complex centralized system. This segmentation allows detection of spoofing and replay attacks while maintaining manageable node-level complexity.
Solution Approach 2:
The patent introduces watermarking signals as intermediaries injected into control inputs. These watermarks serve as detectable markers that allow the system to distinguish legitimate control commands from spoofed ones. The watermarking mechanism acts as a mediator between the controller and actuators, enabling reliable detection without fundamentally redesigning the entire control architecture.
2Reliability
If a single monitoring node is used, then the system architecture is simple, but subtle stealthy attacks are not readily detectable
Solution Approach 1:
The patent divides the monitoring function across multiple distributed nodes, each responsible for specific subsystems or process areas. This segmentation enables cross-validation of measurements and detection of subtle anomalies that would be invisible to a single node. The segmented architecture maintains operational simplicity at each node while achieving high detection accuracy collectively.
Solution Approach 2:
The patent combines data from multiple monitoring nodes through a centralized analysis platform that aggregates measurements, compares against expected behavior, and identifies coordinated attacks. This merging of distributed node data enables detection of subtle stealthy attacks that affect multiple subsystems, achieving high detection accuracy without requiring each individual node to be overly complex.
3Reliability
If existing failure and diagnostics technologies are used, then the system can identify faults, but the technologies do not adequately address cyber-attacks when substantial numbers of monitoring nodes need to be analyzed
Solution Approach 1:
The patent extracts and analyzes specific attack characteristics from the data collected by multiple monitoring nodes. By isolating patterns unique to cyber-attacks (such as coordinated deviations across nodes, impossible physical behaviors, or inconsistencies with control commands), the system can differentiate attacks from genuine faults even when analyzing substantial numbers of nodes. This extraction approach maintains manageable complexity by focusing on discriminative features rather than analyzing all node data equally.
Solution Approach 2:
The patent performs preliminary watermarking and data validation at each monitoring node before central aggregation. This preliminary action filters and pre-processes data to remove obvious anomalies and reduce the burden on centralized analysis. By conducting initial screening at the node level, the system achieves reliable fault-attack differentiation across multiple nodes without overwhelming computational complexity.
Data Source
AI summary
A cyber-physical system may have monitoring nodes that generate a series of current monitoring node values over time that represent current operation of the system. A hierarchical abnormality localization computer platform accesses a multi-level hierarchy of elements, and elements in a first level of the hierarchy are associated with elements in at least one lower level of the hierarchy and at least some elements may be associated with monitoring nodes. The computer platform may then determine, based on feature vectors and a decision boundary, an abnormality status for a first element in the highest level of the hierarchy. If the abnormality status indicates an abnormality, the computer platform may determine an abnormality status for elements, associated with the first element, in at least one level of the hierarchy lower than the level of the first element. These determinations may be repeated until an abnormality is localized to a monitoring node.


