Monitoring Node Threat Localization in Industrial Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems connected to the Internet are vulnerable to cyber threats that can disrupt operations and cause catastrophic damage, as existing methods like FDIA are limited in detecting and localizing threats across IT and OT layers, and may fail to distinguish between original threats and their propagated effects.

Innovation Solution

A system that receives real-time monitoring node signal inputs, generates feature vectors, compares them with decision boundaries to separate normal and abnormal states, and automatically transmits threat alerts, enabling accurate localization of threats within the industrial asset control system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If FDIA approaches are used to analyze sensor data for threat detection, then sensor node monitoring is improved, but the system cannot distinguish between original threats and propagated effects, making threat localization impossible

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidthreat localization capability
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system segments the industrial control system into multiple monitoring nodes (sensor nodes, controller nodes, actuator nodes) and creates separate decision boundaries for each node type. This segmentation allows the system to analyze abnormal behavior propagation patterns across different node types, enabling identification of the original threat source versus propagated effects.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a temporal dimension to threat analysis by examining the sequence and propagation of abnormal behaviors across nodes over time. By analyzing how abnormalities propagate through the system in time, the system can distinguish between original threats (first occurrence) and propagated effects (subsequent occurrences), enabling threat localization.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If traditional IT and OT protection layers are implemented, then basic cyber threat protection is provided, but threats can still penetrate through these layers and reach the physical domain

Engineering Contradiction:
Improvecyber threat protectionVSAvoidphysical domain vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system introduces a new intermediary layer between IT/OT networks and the physical domain consisting of multiple monitoring nodes (sensor nodes, controller nodes, actuator nodes) with decision boundaries. This intermediary layer continuously monitors for abnormal behaviors and can detect threats before they cause physical damage, providing an additional protection mechanism that complements traditional IT and OT security layers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive monitoring of all control system nodes is implemented, then threat detection coverage is improved, but system complexity and computational requirements increase

Engineering Contradiction:
Improvethreat detection coverageVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses a universal monitoring framework that applies the same decision boundary methodology across all node types (sensor nodes, controller nodes, actuator nodes). This universal approach provides comprehensive threat detection coverage while avoiding the complexity of implementing separate specialized systems for each node type, as the same abnormal behavior detection logic is applied universally across the entire control system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11005863B2Threat detection and localization for monitoring nodes of an industrial asset control system
Publication Date: 2021.05.11 GE INFRASTRUCTURE TECH LLC
  • US11005863B2 patent drawing
  • US11005863B2 patent drawing
  • US11005863B2 patent drawing

AI summary

In some embodiments, a plurality of real-time monitoring node signal inputs receive streams of monitoring node signal values over time that represent a current operation of the industrial asset control system. A threat detection computer platform, coupled to the plurality of real-time monitoring node signal inputs, may receive the streams of monitoring node signal values and, for each stream of monitoring node signal values, generate a current monitoring node feature vector. The threat detection computer platform may then compare each generated current monitoring node feature vector with a corresponding decision boundary for that monitoring node, the decision boundary separating a normal state from an abnormal state for that monitoring node, and localize an origin of a threat to a particular monitoring node. The threat detection computer platform may then automatically transmit a threat alert signal based on results of said comparisons along with an indication of the particular monitoring node.