Two-dimensionality detection method for industrial control system attacks

US11657150B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11657150-B2
Application numberUS-202217887027-A
CountryUS
Kind codeB2
Filing dateAug 12, 2022
Priority dateSep 9, 2021
Publication dateMay 23, 2023
Grant dateMay 23, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A two-dimensionality detection method for industrial control system attacks: collecting data; transmitting the data to a PLC and an embedded attack detection system; uploading, by the PLC, received data to an SCADA system; transmitting, by the SCADA system, the data to the embedded attack detection system after classifying and counting the data; before starting detection, directly reading, by the embedded attack detection system, the data measured by sensors; refining data association relationships and probability distribution characteristics of the sensors of normal operation to complete storage of health data model; after starting detection, in first dimensionality, comparing the data collected directly by the sensors with statistical data of the SCADA system to judge the attacked condition of the SCADA system, and in second dimensionality, comparing the characteristics of the data collected directly by the sensors and counted online with the health data model to judge the attacked condition of the sensors.

First claim

Opening claim text (preview).

The invention claimed is: 1. A two-dimensionality detection method for industrial control system attacks, specifically comprising the following steps: S 1 , collecting data from underlying sensors of an industrial control system in real time by an industrial control sensor network; transmitting the data to an industrial control system including a programmable logic controller (PLC) and an independent embedded attack detection system, wherein an embedded processor in the embedded attack detection system does not allow a host computer to update the embedded processor and a download port is not allowed to be connected online; uploading, PLC, the received sensor data to a supervisory control and data acquisition (SCADA) system, and meanwhile, receiving, by the embedded attack detection system, downlink data after statistics of the SCADA system through network cables; S 2 , under the condition of no attack, refining, by the embedded attack detection system, independent data distribution characteristics of normal operation of each sensor in the industrial control system by reading the data collected by the sensors; the independent data distribution characteristics comprising types of probability distribution near a mean value point, estimated error covariance, and function relationships between variables abstracted based on internal physical relationships of the industrial control system; and storing a refined feature pattern in the embedded processor of stand-alone operation, recorded as a system health data model; and S 3 , an attack detection method of the industrial control system comprises two-dimensionality; first dimensionality: comparing the data collected directly by the sensors with statistical data of the SCADA system to detect an attacked condition of the SCADA system, recorded as a first level attack alert; a detection mode is: comparing system control variable data downstream from the SCADA system at the same timestamp with the sensor data directly read by the embedded attack detection system; if a difference exceeds a maximum quantization error range for data transmission, considering that the SCADA system has malicious intrusion; second dimensionality: comparing a statistical pattern of the data collected directly by the sensors with the health data model to judge the attacked condition of the sensors, recorded as a second level attack alert; wherein the statistical pattern of the data collected directly by the sensors comprises the types of probability distribution, covariance sizes and the function relationships between the variables; a detection mode is: on the premise of not triggering the first level attack alert, firstly counting whether the function relationships between the mean values of variables of the sensors is within an allowable error range of health model function relationships; if beyond the range, considering that sensor drivers have malicious tampering; next, counting types of probability density distribution of the data of each sensor, and covariances, and comparing with the health data model; if a difference is beyond a confidence interval, considering that the sensor drivers have malicious tampering.

Assignees

Inventors

Classifications

  • Preprocessing measurements, e.g. data collection rate adjustment; Standardization of measurements; Time series or signal analysis, e.g. frequency analysis or wavelets; Trustworthiness of measurements; Indexes therefor; Measurements using easily measured parameters to estimate parameters difficult to measure; Virtual sensor creation; De-noising; Sensor fusion; Unconventional preprocessing inherently present in specific fault detection methods like PCA-based methods · CPC title

  • by registering files or documents with a third party · CPC title

  • Real time diagnostics · CPC title

  • Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title

  • Total factory control, e.g. smart factories, flexible manufacturing systems [FMS] or integrated manufacturing systems [IMS] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11657150B2 cover?
A two-dimensionality detection method for industrial control system attacks: collecting data; transmitting the data to a PLC and an embedded attack detection system; uploading, by the PLC, received data to an SCADA system; transmitting, by the SCADA system, the data to the embedded attack detection system after classifying and counting the data; before starting detection, directly reading, by t…
Who is the assignee on this patent?
Univ Dalian Tech
What technology area does this patent fall under?
Primary CPC classification G05B23/0221. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue May 23 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).