Threat Detection Platform for Industrial Asset Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial asset control systems connected to the Internet are vulnerable to cyber-attacks, which can disrupt operations and cause catastrophic damage, as existing methods like FDIA only analyze sensor data and do not effectively address multiple simultaneous faults or malicious attacks.

Innovation Solution

A threat detection platform that monitors industrial asset control systems under various operating conditions, calculates normalization functions, generates feature vectors, and compares them to decision boundaries to automatically detect and alert on cyber threats, using a combination of normalization and feature-based learning techniques to differentiate between normal and abnormal states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional FDIA approaches are used to analyze sensor data, then single sensor faults can be detected, but multiple simultaneous cyber-attacks cannot be effectively identified

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcapability to handle multiple simultaneous faults
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the monitoring approach by creating separate decision boundaries for different monitoring nodes (sensors, actuators, controllers) rather than using a unified FDIA approach. Each node has its own feature vector and decision boundary, allowing independent analysis of multiple nodes simultaneously. This segmentation enables the system to detect and localize multiple simultaneous cyber-attacks on different system components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from traditional single-dimensional sensor fault analysis to multi-dimensional monitoring by incorporating data from multiple monitoring nodes (sensors, actuators, controllers) across different system layers. The feature vectors are constructed in multi-dimensional space, and decision boundaries are established in this extended dimensionality, enabling detection of complex multi-node cyber-attacks that traditional FDIA cannot identify.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If control systems are connected to the Internet for operational flexibility, then system adaptability improves, but vulnerability to cyber-attacks increases

Engineering Contradiction:
Improveoperational flexibilityVSAvoidcyber-threat vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system introduces an intermediary threat detection layer between the Internet-connected control system and external networks. This intermediary continuously monitors data streams from multiple monitoring nodes, compares them against learned decision boundaries, and identifies cyber-attacks before they can cause catastrophic damage. The intermediary acts as a protective barrier that maintains operational flexibility while mitigating cyber-threat vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback monitoring where data streams from monitoring nodes are constantly analyzed against decision boundaries. When deviations indicating cyber-attacks are detected, the system provides feedback through threat alert signals that can trigger protective responses. This feedback mechanism enables real-time detection and response to cyber-threats, maintaining system security while allowing Internet connectivity for operational flexibility.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If dynamic normalization is applied to monitoring node data, then threat detection accuracy improves, but computational complexity increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system dynamically changes normalization parameters based on operating conditions. Different normalization functions are applied depending on the specific monitoring node, data type, and operational context. This parameter adaptation allows the system to maintain high threat detection accuracy across varying operating conditions while managing computational complexity by selecting appropriate normalization strategies for each scenario rather than applying a single complex method universally.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10678912B2Dynamic normalization of monitoring node data for threat detection in industrial asset control system
Publication Date: 2020.06.09 GE INFRASTRUCTURE TECH LLC
  • US10678912B2 patent drawing
  • US10678912B2 patent drawing
  • US10678912B2 patent drawing

AI summary

Operation of an industrial asset control system may be simulated or monitored under various operating conditions to generate a set of operating results. Subsets of the operating results may be used to calculate a normalization function for each of a plurality of operating conditions. Streams of monitoring node signal values over time may be received that represent a current operation of the industrial asset control system. A threat detection platform may then dynamically calculate normalized monitoring node signal values based at least in part on a normalization function in an operating mode database. For each stream of normalized monitoring node signal values, a current monitoring node feature vector may be generated and compared with a corresponding decision boundary for that monitoring node, the decision boundary separating normal and abnormal states for that monitoring node. A threat alert signal may then be automatically transmitted based on results of those comparisons.