Physical System Attack Detection Using Signal Noise Fingerprints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems and other critical physical systems are vulnerable to malicious attacks, such as injection, transform, and replay attacks, which can disrupt operations and compromise data authenticity, posing risks to real-time emergency decision-making.

Innovation Solution

A computer system and method for detecting attacks on physical systems by receiving signals, de-noising them to extract a smooth portion, obtaining a noise portion, classifying the noise, determining expected states, and comparing them to detected states to identify potential attacks, using a database of fingerprints and regression models for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional detection methods are used in industrial control systems, then operational problems and malfunctions can be detected, but the systems remain vulnerable to malicious attacks such as injection, transform, and replay attacks that compromise data authenticity

Engineering Contradiction:
Improvedata authenticityVSAvoidmalicious attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary de-noising and classification of noise portions before detecting attacks. By preprocessing signals to extract smooth portions and classify noise characteristics in advance, the system establishes a baseline of normal operation that enables later detection of malicious transformations and injections without being fooled by replayed or transformed attack signals

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system compares detected states against expected states derived from classified noise portions and creates feedback loops for continuous monitoring. This feedback mechanism allows the system to identify deviations caused by malicious attacks by constantly comparing actual system behavior against predicted behavior based on noise classification and signal de-noising results

Inventive Principle:
Principle #23Feedback

2Measurement precision

If signal processing is applied to detect attacks, then data authenticity can be verified, but false alarms may occur reducing detection accuracy

Engineering Contradiction:
Improveattack detection accuracyVSAvoidfalse alarm rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system transforms the signal from its original form through de-noising operations that extract smooth portions while preserving essential characteristics. By changing the parameter representation of the signal (from raw noisy data to de-noised smooth portions with classified noise components), the system improves detection precision while maintaining reliability through parameter transformation rather than simple thresholding

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies different processing techniques to different portions of the signal - de-noising is applied to extract smooth portions while separate noise classification is applied to the noise components. This local quality approach allows the system to treat signal and noise differently, improving detection accuracy by focusing on the smooth portions while using noise classification to identify anomalies without triggering false alarms

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11190530B2Method and system for detecting attacks on monitored physical systems
Publication Date: 2021.11.30 APERIO SYST 2020 LTD
  • US11190530B2 patent drawing
  • US11190530B2 patent drawing
  • US11190530B2 patent drawing

AI summary

A computer system and computer implemented method of detecting attacks on physical systems are disclosed. The system may include one or more databases and one or more controller configured to execute instructions. The instructions may include the following method steps: receiving at least one signal related to a monitored physical system; de-noising the at least one signal to extract a smooth portion of the signal; detecting one or more states of the monitored physical system by analyzing the smooth portion of the signal; obtaining a noise portion of the signal by subtracting the de-noised smooth portion from the at least one signal; classifying the noise portion; determining expected states of the system based on the classified noise portion; comparing the expected states to the detected one or more states; and detecting an attack on the monitored physical system based on the comparison.