Virtual Sensor Reconfiguration for Industrial Cyber-Attack Neutralization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems connected to the Internet are vulnerable to cyber-attacks, which can disrupt operations and cause catastrophic damage, with existing methods failing to detect stealthy attacks at the domain layer where sensors and actuators are located, especially when multiple attacks occur simultaneously.

Innovation Solution

An autonomous, resilient estimator continuously learns and updates virtual sensor models to detect and neutralize cyber-attacks by replacing abnormal monitoring node values with virtual node values, using information from normal nodes and determined threat levels, allowing the system to maintain functionality without redundant components or major changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cyber-attack detection methods are used in IT and OT layers, then some attacks can be detected, but stealthy attacks at the domain layer can still penetrate and cause damage

Engineering Contradiction:
Improveattack detection capabilityVSAvoidstealthy attack penetration
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a new domain layer for attack detection that operates alongside the traditional IT and OT layers. This domain layer uses virtual sensing technology to create a parallel detection mechanism that can identify stealthy attacks by comparing virtual sensor readings with actual sensor data, effectively adding a dimensional layer of security without disrupting existing detection architectures.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent employs virtual sensors as intermediary elements that mediate between physical sensors and the control system. These virtual sensors generate estimated measurements that serve as a reference for detecting attacks on actual sensors, acting as a buffer that prevents direct penetration of stealthy attacks into the control system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multiple monitoring nodes are used to detect attacks, then detection accuracy improves, but system complexity and cost increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidmonitoring node quantity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates virtual copies of sensors through virtual sensing technology. These virtual sensors are mathematical models that replicate the behavior of physical sensors without requiring additional physical hardware. By using virtual sensor copies, the system achieves enhanced detection accuracy through multiple monitoring perspectives while avoiding the complexity and cost of deploying additional physical monitoring nodes.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms the detection approach by changing from physical sensor deployment to virtual sensor parameter configuration. Instead of adding more physical monitoring nodes, the system modifies detection parameters by configuring virtual sensor models with different measurement characteristics, achieving diverse monitoring coverage through parameter variation rather than hardware multiplication.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If the system shuts down during detected attacks, then safety is ensured, but productivity and asset functionality are lost

Engineering Contradiction:
Improvesafety protectionVSAvoidasset functionality
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent extracts the attacked sensor data from the control loop by identifying and isolating compromised sensors through virtual sensing comparison. Once attacked sensors are identified, their data is removed from control calculations while virtual sensor estimates continue to provide safe operating parameters, allowing the system to maintain functionality without the harmful influence of attacked data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent prepares virtual sensor models in advance that can provide estimated measurements for all possible sensor failures or attacks. This beforehand cushioning ensures that when an attack occurs, the system already has pre-configured alternative data sources ready to immediately replace attacked sensor readings, maintaining safety and continuity without shutdown.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

4Reliability

If redundant components are added to protect against attacks, then system reliability improves, but cost and complexity increase

Engineering Contradiction:
Improvesystem protection capabilityVSAvoidredundant components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses virtual sensor copies as software-based redundancy instead of physical hardware redundancy. These virtual copies are mathematical models that can be instantiated without additional physical components, providing the same protective function as redundant physical sensors would, but without the associated cost and complexity of duplicate hardware installations.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11487598B2Adaptive, self-tuning virtual sensing system for cyber-attack neutralization
Publication Date: 2022.11.01 GE INFRASTRUCTURE TECH LLC
  • US11487598B2 patent drawing
  • US11487598B2 patent drawing
  • US11487598B2 patent drawing

AI summary

An industrial asset may have a plurality of monitoring nodes, each monitoring node generating a series of monitoring node values over time representing current operation of the industrial asset. An abnormality detection computer may determine that an abnormal monitoring node is currently being attacked or experiencing a fault. An autonomous, resilient estimator may continuously execute an adaptive learning process to create or update virtual sensor models for that monitoring node. Responsive to an indication that a monitoring node is currently being attacked or experiencing a fault, a level of neutralization may be automatically determined. The autonomous, resilient estimator may then be dynamically reconfigured to estimate a series of virtual node values based on information from normal monitoring nodes, appropriate virtual sensor models, and the determined level of neutralization. The series of monitoring node values from the abnormal monitoring node or nodes may then be replaced with the virtual node values.