Virtual Sensor Cyber Attack Compensation in Industrial Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems connected to the Internet are vulnerable to cyber-attacks, which can disrupt operations and cause catastrophic damage, as existing methods fail to detect stealthy attacks at the domain layer where sensors and actuators are located, especially when multiple attacks occur simultaneously.

Innovation Solution

Implementing a system with multiple monitoring nodes that generate monitoring node values, a threat detection computer to identify attacked nodes, and a virtual sensor that estimates and replaces node values from attacked nodes with virtual node values based on information from healthy nodes, using a virtual sensor creation platform and adaptive protection units to automatically replace data in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual sensors are used to replace attacked monitoring node data, then system reliability is improved during cyber-attacks, but device complexity increases due to additional virtual sensor creation platform and processing mechanisms

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtual sensor as an intermediary component that mediates between the attacked monitoring node and the control system. The virtual sensor receives data from healthy monitoring nodes, processes it through the virtual sensor creation platform, and generates replacement values that mimic the expected output of the attacked node. This intermediary approach maintains system reliability by providing clean data while isolating the complexity of attack detection and data reconstruction from the core control system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtual sensor creates a computational copy or model of the attacked monitoring node's expected behavior. By using the virtual sensor creation platform to generate replacement data based on patterns from healthy nodes, the system replicates the functional output of the compromised node without physically replacing it. This copying mechanism preserves system reliability while managing complexity through software-based solutions rather than hardware redundancy.

Inventive Principle:
Principle #26Copying

2Measurement precision

If multiple monitoring nodes are used to detect and compensate for attacks, then measurement precision is improved for identifying attacked nodes, but device complexity increases due to additional monitoring infrastructure

Engineering Contradiction:
Improveattack detection precisionVSAvoidmonitoring infrastructure complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges the functions of multiple monitoring nodes into a coordinated detection and response system. The virtual sensor creation platform combines data from multiple healthy monitoring nodes to collectively identify and compensate for attacks on any single node. This merging approach improves measurement precision by leveraging multiple data sources while managing complexity through centralized processing logic that treats the monitoring nodes as an integrated system rather than separate components.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms where the virtual sensor continuously monitors the consistency between actual monitoring node outputs and expected values derived from other nodes. When discrepancies indicate an attack, the feedback loop triggers automatic replacement of compromised data. This feedback-driven approach enhances detection precision while managing complexity through automated response protocols that reduce the need for manual intervention and complex decision-making infrastructure.

Inventive Principle:
Principle #23Feedback

3Productivity

If automatic replacement of attacked node data with virtual sensor values is implemented, then productivity is maintained during cyber-attacks, but loss of information increases due to substitution of original sensor data

Engineering Contradiction:
Improvesystem operation continuityVSAvoidoriginal sensor data integrity
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The virtual sensor creation platform performs preliminary actions by continuously establishing the relationship between monitoring nodes and their expected data patterns during normal operation. This pre-computation of node relationships and behavior models enables the system to rapidly generate accurate replacement data when attacks occur, maintaining productivity without significant delay. The preliminary establishment of these models minimizes information loss by ensuring replacement values are based on pre-analyzed, high-quality data from healthy nodes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent substitutes the physical sensor data collection mechanism with a computational model-based approach. Instead of relying solely on physical sensors to provide data, the system uses virtual sensors that compute replacement values based on mathematical models and relationships derived from healthy monitoring nodes. This substitution maintains productivity by providing continuous data flow while managing information loss through computational verification and cross-validation against multiple data sources, ensuring replacement values reflect true system state rather than attack-corrupted data.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10826922B2Using virtual sensors to accommodate industrial asset control systems during cyber attacks
Publication Date: 2020.11.03 GE INFRASTRUCTURE TECH LLC
  • US10826922B2 patent drawing
  • US10826922B2 patent drawing
  • US10826922B2 patent drawing

AI summary

In some embodiments, an industrial asset may be associated with a plurality of monitoring nodes, each monitoring node generating a series of monitoring node values over time that represent operation of the industrial asset. A threat detection computer may determine that an attacked monitoring node is currently being attacked. Responsive to this determination, a virtual sensor coupled to the plurality of monitoring nodes may estimate a series of virtual node values for the attacked monitoring node(s) based on information received from monitoring nodes that are not currently being attacked. The virtual sensor may then replace the series of monitoring node values from the attacked monitoring node(s) with the virtual node values. Note that in some embodiments, virtual node values may be estimated for a particular node even before it is determined that the node is currently being attacked.