Cyber Threat Detection in Electric Power Grids Using Feature Vectors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electric power grids connected to the Internet are vulnerable to cyber-attacks, which can disrupt operations and cause catastrophic damage, as existing protection methods like FDIA systems are limited in detecting malicious threats and do not address multiple faults simultaneously.

Innovation Solution

A system that uses heterogeneous data source nodes to generate feature vectors, which are compared to decision boundaries created offline using normal and abnormal data sets, to automatically detect and alert on cyber threats in real-time, enabling accurate and automatic protection against malicious intent.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional FDIA approaches are used to analyze sensor data, then single sensor faults can be detected, but multiple simultaneous malicious faults cannot be detected and the system remains vulnerable to cyber-attacks

Engineering Contradiction:
Improvedetection accuracyVSAvoidcapability to detect multiple simultaneous faults
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the power grid into multiple zones and creates separate decision boundaries for each zone. Each zone's data source nodes are independently analyzed against their specific decision boundaries, allowing the system to detect multiple simultaneous faults across different zones without mutual interference

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transforms raw sensor data into feature vectors that represent the state of data source nodes in a multi-dimensional space. Decision boundaries are established in this feature space rather than in the original sensor space, enabling more effective separation and detection of multiple simultaneous abnormal states that would be difficult to distinguish in the original dimension

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If more data source nodes are monitored to improve detection coverage, then system security improves, but system complexity and computational burden increase

Engineering Contradiction:
Improvesystem securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the most relevant features from raw sensor data to create compact feature vectors. By selecting and extracting key characteristics rather than processing all raw data, the system maintains high detection accuracy while reducing computational complexity and making the system more manageable

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the parameter representation from raw sensor values to normalized feature vectors that highlight abnormal conditions. This parameter transformation simplifies the detection process by converting complex multi-parameter sensor readings into standardized features that can be efficiently compared against decision boundaries

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10452845B2Generic framework to detect cyber threats in electric power grid
Publication Date: 2019.10.22 GE DIGITAL HLDG LLC
  • US10452845B2 patent drawing
  • US10452845B2 patent drawing
  • US10452845B2 patent drawing

AI summary

According to some embodiments, a plurality of heterogeneous data source nodes may each generate a series of current data source node values over time that represent a current operation of an electric power grid. A real-time threat detection computer, coupled to the plurality of heterogeneous data source nodes, may receive the series of current data source node values and generate a set of current feature vectors. The threat detection computer may then access an abnormal state detection model having at least one decision boundary created offline using at least one of normal and abnormal feature vectors. The abnormal state detection model may be executed, and a threat alert signal may be transmitted if appropriate based on the set of current feature vectors and the at least one decision boundary.