Industrial Sensor Baselines for Correlated Cyber-Physical Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial operations face challenges in securing and ensuring safety due to the increasing complexity of data traffic and sensor information, making it difficult to detect abnormal conditions that could lead to security breaches or equipment damage.
Innovation Solution
The method involves receiving sensor information from multiple sensors, monitoring data traffic, and deriving a baseline signature representing normal operating conditions. By comparing additional sensor information with the baseline signature, abnormal operating and data traffic conditions are identified, and if correlated, a security alert is sent.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If sensor information is used for functionality of industrial operation components, then operational functionality is improved, but security detection capability deteriorates due to data complexity
Solution Approach 1:
The patent segments the monitoring system into two distinct pathways: one for operational functionality using sensor information, and another for security detection using data traffic analysis. This segmentation allows the system to maintain operational efficiency while separately detecting security threats without being overwhelmed by the complexity of operational data.
Solution Approach 2:
The patent introduces data traffic as an intermediary layer for security monitoring. Instead of directly analyzing complex sensor information for security threats, the system monitors data traffic patterns that mediate between the sensor information and security detection, simplifying the detection process while maintaining effectiveness.
2Reliability
If data traffic monitoring is added to detect abnormal conditions, then security detection capability is improved, but device complexity increases
Solution Approach 1:
The patent makes the data traffic monitoring system multi-functional by using it for both operational data transmission and security detection purposes. This universality allows the system to improve security detection capability without adding separate dedicated security hardware, thereby limiting the increase in device complexity.
Solution Approach 2:
The system performs self-service security monitoring by analyzing its own data traffic patterns. The industrial operation system monitors itself for abnormal conditions through data traffic analysis, eliminating the need for external complex security infrastructure and reducing overall device complexity.
3Measurement precision
If baseline signature is derived from sensor information, then abnormal condition identification is improved, but loss of time occurs during baseline derivation
Solution Approach 1:
The patent performs preliminary action by establishing the baseline signature during normal operational periods before security threats occur. This preliminary baseline derivation allows the system to quickly compare subsequent data against the pre-established baseline, improving abnormal condition identification while minimizing time loss during actual security events.
Solution Approach 2:
The baseline signature derivation is performed continuously during normal operations rather than as a separate batch process. This continuous derivation maintains operational functionality while progressively building the baseline, eliminating dedicated derivation time and ensuring the system is always ready for anomaly detection.
Data Source
AI summary
A method for security and safety of an industrial operation includes receiving sensor information from a plurality of sensors of an industrial operation. Sensor information from at least a portion of the plurality sensors is used for functionality of a plurality of components of the industrial operation. The method includes monitoring data traffic of the industrial operation, and deriving a baseline signature from the sensor information. The baseline signature encompasses a range of normal operating conditions. The method includes identifying an abnormal operating condition of the industrial operation based on a comparison between additional sensor information from the plurality of sensors and the baseline signature and identifying an abnormal data traffic condition. The method includes determining that the abnormal operating condition correlates to the abnormal data traffic condition, and sending a security alert in response to determining that the abnormal operating condition correlates to the abnormal data traffic condition.


