Stealthy Attack Detection in Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems for cyber-physical systems are inadequate as they do not consider process semantics, leading to difficulties in detecting subtle anomalies and stealthy attacks that can cause significant physical damage.

Innovation Solution

A data-driven approach that uses time series of raw data and singular spectrum analysis to detect anomalies by identifying deviations from normal behavior, without requiring prior knowledge of system dynamics or using machine learning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional intrusion detection systems are used, then the system can detect obvious attacks, but it fails to detect subtle anomalies and stealthy attacks due to not considering process semantics

Engineering Contradiction:
Improveanomaly detection precisionVSAvoiddetection reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent transforms the detection approach by changing from traditional security parameters to process-level parameters. It uses process variables and their temporal relationships to detect anomalies, thereby improving both detection precision and reliability by considering the semantic meaning of process behavior rather than just raw data patterns

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces process semantics as an intermediary layer between raw sensor data and anomaly detection. By modeling normal process behavior and comparing actual behavior against this model, the system achieves more reliable detection of subtle attacks that would otherwise go unnoticed

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If Linear Dynamical State-Space models are built for process-level detection, then anomaly detection capability improves, but the system requires massive human effort and complete detailed models that are not always available

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidmodel building complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces complex, difficult-to-build LDS models with simpler statistical models that can be constructed from available data. These lighter models achieve comparable detection capability without requiring complete detailed process models or massive human effort in the preliminary stage

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent changes the modeling approach from deterministic LDS models to statistical models that work with available data. This parameter change in modeling philosophy reduces complexity while maintaining detection effectiveness by focusing on statistical deviations rather than complete process modeling

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If prediction-based methods are used to detect anomalies, then future behavior can be anticipated, but the methods fail when changes in time series are subtle and noise-reduced information is needed

Engineering Contradiction:
Improvedetection timingVSAvoidsubtle change detection precision
Core Design Contradiction:
Loss of timeVSMeasurement precision

Solution Approach 1:

The patent extracts noise-reduced information from time series data by analyzing temporal relationships and patterns. It separates signal from noise by focusing on structured temporal dependencies, enabling detection of subtle changes that would be obscured in raw data

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary analysis to establish what normal behavior looks like by examining historical data patterns. This preliminary characterization of normality enables the system to detect deviations more effectively, addressing the timing aspect by preparing detection thresholds based on learned temporal patterns

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12282542B2Departure-based process-level detection of stealthy attacks on control systems
Publication Date: 2025.04.22 CLAVISTER TECHNOLOGIES AB
  • US12282542B2 patent drawing
  • US12282542B2 patent drawing
  • US12282542B2 patent drawing

AI summary

Method and device for extracting noise-reduced signal information from a time series of sensor measurements during normal process operation and then actively checking whether present realizations of the process are departing from historical normal behavior. To extract signal information, the solution borrows ideas from singular spectrum analysis a non-parametric exploratory analysis tool for time series that is particularly suitable for separating the deterministic part of a dynamical system behavior from the chaotic part, purely from noisy time series of measurements.