Anomaly detection for cyber-physical systems

US11874930B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11874930-B2
Application numberUS-202017027463-A
CountryUS
Kind codeB2
Filing dateSep 21, 2020
Priority dateSep 19, 2019
Publication dateJan 16, 2024
Grant dateJan 16, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An anomaly detector is configured to construct cyber and/or physical features comprising information configured to characterize the cyber and/or physical state of a cyber-physical system. The physical features may be based on physical and/or physics-based relationships between a plurality of physical state attributes. A health of the cyber-physical system may be based on an error between estimates of one or more of the physical state attributes and measurements of the one or more physical state attributes. The relationships may be incorporated into machine learning membership functions used to classify cyber and/or physical behavior of the system.

First claim

Opening claim text (preview).

We claim: 1. A method for anomaly detection in a cyber-physical system (CPS), the method comprising: deriving a physics-based correlation from a configuration of one or more physical components of the CPS, the physics-based correlation defining a mathematical relationship between a plurality of physical attributes of the CPS, the plurality of physical attributes comprising a first physical attribute and a second physical attribute; acquiring measurements of respective physical attributes of the plurality of physical attributes from the CPS, the measurements associated with a capture time; applying the mathematical relationship defined between the plurality of physical attributes to determine an estimated value for the first physical attribute at the capture time based, at least in part, on a measurement of the second physical attribute associated with the capture time; determining a physical state (PS) error metric for the capture time, the PS error metric configured to quantify deviation of the acquired measurements associated with the capture time from the mathematical relationship defined between the plurality of physical attributes by the physics-based correlation, wherein the PS error metric is based, at least in part, on an error between a measurement of the first physical attribute associated with the capture time and the estimated value of the first physical attribute determined for the capture time; and detecting anomalous behavior of the CPS based, at least in part, on the PS error metric. 2. The method of claim 1 , wherein the physics-based correlation is further configured to define a constraint of a first physical attribute of the plurality of physical attributes, and wherein the PS error metric is based, at least in part, on a degree to which the measurement of the first physical attribute conforms with the constraint. 3. The method of claim 1 , further comprising receiving measurements of one or more physical attributes of the plurality of physical attributes from a sensor device coupled to a physical process of the CPS. 4. The method of claim 3 , wherein: the estimated value for the first physical attribute at the capture time is based, at least in part, on a measurement of a third physical attribute acquired at the capture time. 5. The method of claim 1 , further comprising: determining an estimate of the second physical attribute of the plurality of physical attributes based, at least in part, on the mathematical relationship defined between the plurality of physical attributes by the physics-based correlation and the measurement of the first physical attribute; wherein the PS error metric is based, at least in part, on a difference between the estimate of the first physical attribute and the measurement of the first physical attribute and a difference between the estimate of the second physical attribute and a measurement of the second physical attribute. 6. The method of claim 1 , further comprising: determining an error threshold for the physics-based correlation, the error threshold based on a deviation between training measurements of the plurality of physical attributes, the training measurements configured to characterize nominal operation of the CPS; and detecting the anomalous behavior of the CPS responsive to the PS error metric exceeding the error threshold. 7. The method of claim 1 , further comprising: deriving a first membership function from one or more fuzzy sets, the one or more fuzzy sets corresponding to nominal operation of the CPS and comprising training measurements of the plurality of physical attributes, wherein the first membership function is configured to model a PS error distribution, the PS error distribution corresponding to differences between the training measurements of the plurality of physical attributes and the mathematical relationship defined between the plurality of physical attributes by the physics- based correlation; acquiring measurements of the plurality of physical attributes; and utilizing the first membership function to determine the PS error metric, the PS error metric configured to quantify a degree to which the acquired measurements of the physical attributes conform to the PS error distribution of the first membership function. 8. The method of claim 7 , wherein the one or more fuzzy sets further comprise training measurements of a cyber feature, the training measurements of the cyber feature corresponding to nominal operation of an electronic communication network of the CPS, the method further comprising: deriving a second membership function from the training measurements of the cyber feature; utilizing the second membership function to determine a cyber state (CS) error metric, the CS error metric configured to quantify a degree to which acquired measurements of the cyber feature correspond to the second membership function; and detecting the anomalous behavior of the CPS based, at least in part, on the PS error metric and the CS error metric. 9. An apparatus for monitoring a CPS, the apparatus comprising: a processor; and an anomaly detector configured for operation on the processor, the anomaly detector further configured to: derive a physics-based correlation from a configuration of one or more physical components of the CPS, the physics-based correlation defining a mathematical relationship between a plurality of physical attributes of the CPS, the plurality of physical attributes comprising a first physical attribute and a second physical attribute; acquire measurements of respective physical attributes of the plurality of physical attributes from the CPS, the measurements associated with a capture time; apply the mathematical relationship defined between the plurality of physical attributes to determine an estimated value for the first physical attribute at the capture time based, at least in part, on a measurement of the second physical attribute associated with the capture time; determine a first affinity metric for the capture time, the first affinity metric configured to quantify a degree to which the acquired measurements associated with the capture time conform to the mathematical relationship defined between the plurality of physical attributes by the physics-based correlation, wherein the first affinity metric is based, at least in part, on an error between a measurement of the first physical attribute associated with the capture time and the estimated value of the first physical attribute determined for the capture time; and detect anomalous behavior of the CPS based, at least in part, on a health metric determined for the CPS, the health metric based, at least in part, on the first affinity metric and a second affinity metric, the second affinity metric configured to quantify a degree to which a cyber feature conforms with nominal behavior of an electronic communication network of the CPS. 10. The apparatus of claim 9 , wherein the physics-based correlation is further configured to define a constraint of the first physical attribute, and wherein the first affinity metric is based, at least in part, on a degree to which the measurement of the first physical attribute conforms with the constraint. 11. The apparatus of claim 9 , wherein the anomaly detector is communicatively coupled to a sensor device through the electronic communication network of the CPS. 12. The apparatus of claim 9 , wherein: the estimated value for the first physical attribute at the capture time is based, at least in part, on a measurement of a third physical attribute acquired at the capture time. 13. The apparatus of claim 1 , wherein: the anomaly detector is further con

Assignees

Inventors

Classifications

  • G06F21/577Primary

    Assessing vulnerabilities and evaluating computer system security · CPC title

  • by exceeding limits · CPC title

  • Performance evaluation by tracing or monitoring · CPC title

  • to assure secure computing or processing of information · CPC title

  • Error or fault detection not based on redundancy (power supply failures G06F1/30; network fault management H04L41/06) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11874930B2 cover?
An anomaly detector is configured to construct cyber and/or physical features comprising information configured to characterize the cyber and/or physical state of a cyber-physical system. The physical features may be based on physical and/or physics-based relationships between a plurality of physical state attributes. A health of the cyber-physical system may be based on an error between estima…
Who is the assignee on this patent?
Battelle Energy Alliance Llc
What technology area does this patent fall under?
Primary CPC classification G06F21/577. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jan 16 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).