Trusted Cyber-Attack Detection for Power System Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Networked electrical power system (NEPS) devices face challenges due to limited computing resources, communication bandwidth, and unique physical and operational conditions, which hinder effective cyber-attack detection and mitigation, especially when requiring retrofits or upgrades.
Innovation Solution
Incorporating a trusted cyber-attack detection (TCAD) component with pre-trained logic that combines physical and computational state inputs to determine an attack metric, using a neural network to predict and respond to cyber-attacks by disconnecting the NEPS device from electrical and communication networks when compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional cyber-attack detection techniques are applied to NEPS devices, then detection capability is improved, but device complexity and resource requirements increase beyond available computing resources
Solution Approach 1:
The system segments the cyber-attack detection function into a dedicated TCAD component that operates independently from the main control logic. This component receives specific inputs (physical parameters, computational state, execution time, alarm events) and processes them separately, reducing the burden on the overall device computing resources while maintaining detection capability.
Solution Approach 2:
The patent introduces an intermediary TCAD component that acts as a mediator between the NEPS device operations and cyber-attack detection. This component aggregates multiple input parameters and processes them through pre-trained logic, shielding the main device from the computational complexity of attack detection while still achieving reliable detection.
2Measurement precision
If comprehensive cyber-attack detection monitoring is implemented, then detection accuracy is improved, but communication bandwidth consumption increases
Solution Approach 1:
The system merges multiple monitoring functions into a single TCAD component that simultaneously processes physical parameters, computational state, execution time, and alarm events. By combining these inputs and processing them through unified pre-trained logic, the system achieves comprehensive detection accuracy while consolidating communication requirements into a single efficient processing stream.
3Reliability
If cyber-attack detection and response systems are added to existing NEPS devices, then security is improved, but hardware and software upgrade requirements increase
Solution Approach 1:
The TCAD component is designed with universal input interfaces that can accept various types of data (physical parameters from sensors, computational state from the controller, execution time metrics, and alarm events). This multi-functional design allows the same component to be applied across different NEPS device types and configurations, simplifying retrofitting efforts.
Solution Approach 2:
The system utilizes existing device resources and parameters for cyber-attack detection without requiring extensive external additions. The TCAD component leverages already-available data streams (physical parameters, computational state, execution time) and existing alarm mechanisms, allowing the device to essentially detect attacks using its own operational data with minimal external modifications.
Data Source
AI summary
Apparatuses, methods, systems, and techniques for detecting and effecting countermeasures against cyber-attacks on networked electrical power system (NEPS) devices include a trusted cyber-attack detection (TCAD) component including pre-trained cyber-attack detection logic which receives a first input indicating a physical parameter of a NEPS device and a second input indicating a computational state of a computer system of the NEPS device, determines an attack metric in response to the plurality of inputs. The attack metric can indicate whether the NEPS device is in the process of being attacked or whether the NEPS device has been successfully attacked and has been compromised.


