Threat Detection Model Tuning for Industrial Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial asset control systems connected to the Internet are vulnerable to cyber-attacks, which can disrupt operations and cause catastrophic damage, as existing threat detection methods like FDIA are limited in addressing multiple simultaneous faults and false alerts, and do not adequately protect against cyber threats.

Innovation Solution

A threat detection model creation system that generates normal and threatened feature vectors, calculates decision boundaries, evaluates performance metrics, and tunes algorithm parameters to automatically detect and alert on cyber threats, using advanced feature-based methods and machine learning techniques to differentiate between normal and abnormal system behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional FDIA approaches are used for threat detection, then the system can detect single sensor faults, but it cannot address multiple simultaneous faults or cyber threats and produces false alerts

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidfalse alert rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the threat detection problem into multiple independent decision boundaries, each trained on specific feature vectors from monitoring nodes. This segmentation allows the system to handle multiple simultaneous faults by evaluating each boundary independently, thereby improving reliability without increasing false alerts from aggregated complex models.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms the detection problem from traditional sensor space to a higher-dimensional feature vector space. By calculating decision boundaries in this elevated dimensionality, the system can better separate normal operation from cyber threats, improving detection accuracy while reducing false positives through more precise classification.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If manual threat detection system creation is performed, then the system can be customized, but it requires substantial time and expertise to evaluate multiple monitoring nodes and tune performance metrics

Engineering Contradiction:
Improvedetection system accuracyVSAvoidsystem creation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service through automated algorithms that independently evaluate multiple monitoring nodes, calculate optimal decision boundaries, and tune performance metrics without requiring manual intervention. The system automatically processes feature vectors from various nodes and configures detection parameters, dramatically reducing creation time while maintaining high reliability through systematic optimization.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs parameter changes by automatically adjusting algorithm parameters and decision boundary thresholds based on performance metrics. This automated parameter tuning allows the system to optimize detection accuracy across multiple monitoring nodes without manual configuration, reducing creation time while ensuring reliable detection through data-driven parameter selection.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If comprehensive monitoring of multiple node types is performed, then the system can detect various threats, but it increases system complexity and difficulty in evaluating performance metrics

Engineering Contradiction:
Improvethreat detection coverageVSAvoidsystem configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a unified threat detection framework that processes feature vectors from multiple types of monitoring nodes (IT, OT, and physical domain) through a common decision boundary evaluation mechanism. This universal approach enables comprehensive threat detection across diverse nodes while simplifying system configuration, as the same automated processes handle all node types regardless of their specific functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10204226B2Feature and boundary tuning for threat detection in industrial asset control system
Publication Date: 2019.02.12 GE INFRASTRUCTURE TECH LLC
  • US10204226B2 patent drawing
  • US10204226B2 patent drawing
  • US10204226B2 patent drawing

AI summary

According to some embodiments, a threat detection model creation computer may receive a series of normal monitoring node values (representing normal operation of the industrial asset control system) and generate a set of normal feature vectors. The threat detection model creation computer may also receive a series of threatened monitoring node values (representing a threatened operation of the industrial asset control system) and generate a set of threatened feature vectors. At least one potential decision boundary for a threat detection model may be calculated based on the set of normal feature vectors, the set of threatened feature vectors, and an initial algorithm parameter. A performance of the at least one potential decision boundary may be evaluated based on a performance metric. The initial algorithm parameter may then be tuned based on a result of the evaluation, and the at least one potential decision boundary may be re-calculated.