Side-Channel State Recognition for Cyber-Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems for cyber-physical systems, such as vehicles, rely on supervised learning methods that require large amounts of labeled data and multiple examples of normal and abnormal behavior to detect intrusions, and are ineffective in automatically identifying distinct states from noisy side-channel signals.

Innovation Solution

A system that uses unsupervised recognition of recurring signal patterns by acquiring and processing side-channel signals to identify system states, generating and updating templates, and triggering actions when discrepancies are detected, allowing for real-time detection of cyber-attacks without pre-existing examples.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If supervised learning methods are used for cyber-attack detection, then detection accuracy can be improved with sufficient training data, but the system requires large amounts of labeled data and pre-existing examples of normal and abnormal behavior

Engineering Contradiction:
Improvedetection accuracyVSAvoidamount of training data
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system performs self-service by automatically identifying distinct states and generating labels from unlabeled side-channel data without requiring pre-existing labeled examples. The unsupervised learning algorithm autonomously clusters signal patterns and assigns state labels, eliminating the need for manual data annotation and pre-collected training sets.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent inverts the conventional supervised learning approach by using unsupervised learning to first identify states from unlabeled data, then using those identified states for detection. Instead of requiring labeled data to train a classifier, the system lets the data structure reveal the states automatically, then uses those states for anomaly detection.

Inventive Principle:
Principle #13The other way round (Inversion)

2Measurement precision

If multiple pre-existing examples of normal and abnormal behavior are required for detection, then classification accuracy improves, but the system cannot automatically identify distinct states from noisy signals

Engineering Contradiction:
Improveclassification accuracyVSAvoidautomatic state identification
Core Design Contradiction:
Measurement precisionVSExtent of automation

Solution Approach 1:

The system performs self-service by automatically identifying distinct states and generating labels from unlabeled side-channel data without requiring pre-existing labeled examples. The unsupervised learning algorithm autonomously clusters signal patterns and assigns state labels, eliminating the need for manual data annotation and pre-collected training sets.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameter of labeled vs. unlabeled data from its conventional state to the opposite, enabling the system to work with unlabeled side-channel data. By transforming the data through unsupervised clustering, the system converts unlabeled noisy signals into labeled state sequences that can be used for detection.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If side-channel samples are extracted for specific states, then detection precision improves, but the states must first be identified or labeled by a person

Engineering Contradiction:
Improvedetection precisionVSAvoidmanual state labeling
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system performs self-service by automatically identifying distinct states and generating labels from unlabeled side-channel data without requiring pre-existing labeled examples. The unsupervised learning algorithm autonomously clusters signal patterns and assigns state labels, eliminating the need for manual data annotation and pre-collected training sets.

Inventive Principle:
Principle #25Self-service

4Extent of automation

If existing unsupervised learning methods are used to capture distinct states, then automatic state identification is achieved, but large amounts of unlabeled data are required for training

Engineering Contradiction:
Improveautomatic state identificationVSAvoidamount of unlabeled data
Core Design Contradiction:
Extent of automationVSQuantity of substance

Solution Approach 1:

The patent applies partial action by using a minimal amount of data to initialize the template library, then using that library to process and label the full data stream. Instead of requiring all data to be processed at once for training, the system uses a small initial subset to create templates, then efficiently labels the remainder using those templates.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3841504B1System and method for cyber attack detection based on rapid unsupervised recognition of recurring signal patterns
Publication Date: 2023.12.06 HRL LAB
  • EP3841504B1 patent drawingFigure 1
  • EP3841504B1 patent drawingFigure 2
  • EP3841504B1 patent drawingFigure 3

AI summary

A system for cyber-attack detection within cyber-physical systems (such as a vehicle). The system operates by obtaining a time- varying analog side-channel signal from components with the cyber-physical system and converting the time-varying analog side- channel signal to a digital side-channel signal. A time-series of system states are then identified based on the digital side-channel signal. The time-series of system states are compared with software states as generated by the cyber-physical system components, such that when the software states are unmatched with the time-series of system states, a side-channel is designated as having a security breach. In such an event, the cyber- physical system is then caused to implement an action based on the side-channel security breach.