Physics-Based Verification for Utility Cyber-Physical Attack Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Utilities systems, such as power generation and water treatment plants, are vulnerable to cyber-physical attacks that compromise communication links and control systems, leading to system shutdowns and component damage, as existing defense solutions are inadequate in detecting and mitigating such attacks, especially zero-day attacks.

Innovation Solution

A defense system comprising sensors, controller devices, and verification devices that monitor physical processes based on predefined invariants, allowing for anomaly detection and remedial action, independent of traditional network-centric defenses, to regulate and defend against cyber-physical attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network-centric defense systems are used to protect utilities systems, then network security is improved, but the system remains vulnerable to cyber-physical attacks that compromise communication links and control systems

Engineering Contradiction:
Improvenetwork securityVSAvoidcyber-physical attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces verification devices as intermediaries between sensors/actuators and the control system. These verification devices monitor physical processes directly and verify sensor readings and actuator commands against predefined invariants, acting as a mediator that detects cyber-physical attacks before they can compromise the control system, thus resolving the vulnerability to attacks that bypass traditional network defenses

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the control system into multiple independent components: sensors, verification devices, controller devices, and actuators. Each segment operates semi-independently with the verification devices providing a layer of security that is separate from the traditional network-centric defense architecture, allowing detection and mitigation of attacks without complete system compromise

Inventive Principle:
Principle #1Segmentation

2Difficulty of detecting and measuring

If verification devices monitor physical processes based on predefined invariants, then anomaly detection capability is improved, but device complexity increases

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidverification system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining invariants that represent normal physical process behavior before deployment. These invariants are established beforehand based on physical laws and expected operational parameters, allowing verification devices to detect anomalies by comparing real-time measurements against pre-established criteria, thereby improving detection capability while managing complexity through pre-computation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification devices perform self-service by autonomously monitoring physical processes and comparing sensor readings against predefined invariants without requiring constant human intervention or complex centralized analysis. Each verification device independently detects anomalies and can trigger remedial actions, reducing the complexity of centralized monitoring systems

Inventive Principle:
Principle #25Self-service

3Reliability

If the defense system uses orthogonal verification mechanisms independent of attacker models, then detection effectiveness against zero-day attacks is improved, but system complexity and computational requirements increase

Engineering Contradiction:
Improvedetection effectivenessVSAvoidverification mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional cyber-centric defense mechanisms with physics-based verification mechanisms. Instead of relying on network security protocols and attacker model assumptions, the system uses physical invariants derived from fundamental physical laws to verify system behavior. This substitution makes the defense effective against zero-day attacks while managing complexity through the use of well-established physical principles

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If actuators are controlled by verification devices to remedy anomalies, then system safety is improved, but control precision may be affected

Engineering Contradiction:
Improvesystem safetyVSAvoidcontrol precision
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The verification devices apply preliminary anti-action by detecting anomalies and triggering remedial control actions through actuators before the cyber-physical attack can cause significant harm. By acting preemptively to counteract detected deviations from normal behavior, the system maintains safety while minimizing the impact on control precision through timely corrections

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11431733B2Defense system and method against cyber-physical attacks
Publication Date: 2022.08.30 SINGAPORE UNIVERSITY OF TECHNOLOGY AND DESIGN
  • US11431733B2 patent drawing
  • US11431733B2 patent drawing
  • US11431733B2 patent drawing

AI summary

The present disclosure generally relates to a system and method for defending a utilities system against cyber-physical attacks associated with anomalies in a physical process operative in the utilities system. The defense system comprises: a set of sensors for collecting physical data associated with the physical process; a set of controller devices for monitoring process states of the physical process based on the physical data from the sensors; a set of verification devices for monitoring the physical process based on the physical data from the sensors, the physical data enabling the verification devices to detect the anomalies based on a set of invariants predefined for the physical process; and a set of actuators controllable by the controller devices or verification devices to remedy the anomalies and regulate the physical process, thereby defending the utilities system against the cyber-physical attacks.