Dynamic normalization of monitoring node data for threat detection in industrial asset control system

US10678912B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10678912-B2
Application numberUS-201615351809-A
CountryUS
Kind codeB2
Filing dateNov 15, 2016
Priority dateNov 15, 2016
Publication dateJun 9, 2020
Grant dateJun 9, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Operation of an industrial asset control system may be simulated or monitored under various operating conditions to generate a set of operating results. Subsets of the operating results may be used to calculate a normalization function for each of a plurality of operating conditions. Streams of monitoring node signal values over time may be received that represent a current operation of the industrial asset control system. A threat detection platform may then dynamically calculate normalized monitoring node signal values based at least in part on a normalization function in an operating mode database. For each stream of normalized monitoring node signal values, a current monitoring node feature vector may be generated and compared with a corresponding decision boundary for that monitoring node, the decision boundary separating normal and abnormal states for that monitoring node. A threat alert signal may then be automatically transmitted based on results of those comparisons.

First claim

Opening claim text (preview).

The invention claimed is: 1. A system to protect an industrial asset control system, comprising: a high fidelity model to simulate operation of the industrial asset control system under various operating conditions to generate a set of operating results; a normalization platform coupled to the high fidelity model to calculate a normalization function for each of a plurality of operating conditions, wherein normalization is performed as follows: S normalized = S nominal - S original S _ ⁢ nominal where S nominal is a spatio-temporal average for normal operating conditions, S nominal represents a time series signal for nominal operating conditions, and S orignal represents time series data requiring normalization; an operating mode database to store the normalization function; a plurality of real-time monitoring node signal inputs to receive streams of monitoring node signal values over time that represent a current operation of the industrial asset control system, wherein at least one monitoring node is associated with at least one of: an auxiliary equipment input signal, a control intermediary parameter, and a control logic value; and a threat detection computer platform, coupled to the plurality of real-time monitoring node signal inputs and the operating mode database, including: a computer processor, and a computer memory, coupled to the computer processor, storing instructions that, when executed by the processor cause the threat detection computer platform to: (i) receive the streams of monitoring node signal values, (ii) dynamically calculate normalized monitoring node signal values based at least in part on a normalization function in the operating mode database, (iii) for each stream of normalized monitoring node signal values, generate a current monitoring node feature vector, (iv) compare each generated current monitoring node feature vector with a corresponding decision boundary for that monitoring node, the decision boundary separating a normal state from an abnormal state for that monitoring node, and (v) automatically transmit a threat alert signal based on results of said comparisons. 2. The system of claim 1 , wherein current monitoring node feature vectors are associated with dynamic temporal normalization. 3. The system of claim 1 , wherein current monitoring node feature vectors are associated with dynamic spatial normalization. 4. The system of claim 1 , wherein the industrial asset control system is associated with a gas turbine and the operating conditions are associated with at least one of: (i) gas turbine loads, and (ii) gas turbine temperatures. 5. The system of claim 4 , wherein the operating conditions are further associated with at least one of: (i) an operating mode, (ii) an external condition, (iii) a system degradation factor, (iv) fuel input, (v) a turbine inlet temperature, (vi) a turbine inlet pressure, (vii) a turbine power, (viii) a turbine speed, (ix) compressor discharge pressure, (x) compressor discharge temperature, (xi) fuel flow, and (xii) turbine exhaust temperature. 6. The system of claim 1 , wherein the industrial asset control system is associated with a computer network and the operating conditions are associated with information packet transmission characteristics. 7. The system of claim 1 , wherein the normalized output S normalized is expressed as a weighted linear combination of basis functions as follows: S = S 0 + ∑ j = 1 N ⁢ w j ⁢ Ψ j where S 0 is an average sensor output with threats, w j is the j th weight, and Ψ j is the j th basis vector. 8. The system of claim 1 , wherein at least one monitoring node is associated with a plurality of decision boundaries and said comparison is performed in connection with each of those boundaries. 9. The system of claim 1 , wherein the threat alert signal transmission is performed using at least one of: (i) a cloud-based system, (ii) an edge-based system, (iii) a wireless system, (iv) a wired system, (v) a secured network, and (vi) a communication system. 10. The system of claim 1 , wherein the threat is associated with at least one of: an actuator attack, a controller attack, a monitoring node attack, a plant state attack, spoofing, financial damage, unit availability, a unit trip, a loss of unit life, and asset damage requiring at least one new part. 11. A computerized method to protect an industrial asset control system, comprising: simulating, by a high fidelity model, operation of the industrial asset control system under various operating conditions to generate a set of operating results; calculating, by a normalization platform, a normalization function for each of a plurality of operating conditions, wherein normalization is performed as follows: S normalized = S nominal - S original S _ ⁢ nominal where S nominal is a spatio-temporal average for normal operating conditions, S nominal represents a time series signal for nominal operating conditions, and S original represents time series data requiring normalization; receiving, via a plurality of real-time monitoring node signal inputs, streams of monitoring node signal values over time that represent a current operation of the industrial asset control system, wherein at least one monitoring node is associated with at least one of: an auxiliary equipment input signal, a control intermediary parameter, and a control logic value; dynamically calculating, by a threat detection computer platform, normalized monitoring node signal values based at least in part on a normalization function; for each stream of normalized monitoring node signal values, generating, by the threat detection computer platform, a current monitoring node feature vector associated with at least one of: (i) dynamic temporal normalization, and (ii)

Assignees

Inventors

Classifications

  • G06F21/554Primary

    involving event detection and direct action · CPC title

  • by means of a monitoring system capable of detecting and responding to faults · CPC title

  • for detecting or protecting against malicious traffic · CPC title

  • Security, surveillance applications · CPC title

  • specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10678912B2 cover?
Operation of an industrial asset control system may be simulated or monitored under various operating conditions to generate a set of operating results. Subsets of the operating results may be used to calculate a normalization function for each of a plurality of operating conditions. Streams of monitoring node signal values over time may be received that represent a current operation of the ind…
Who is the assignee on this patent?
Gen Electric
What technology area does this patent fall under?
Primary CPC classification G06F21/554. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jun 09 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 10 related publications on this page (citations in our corpus or others sharing the same primary CPC).