Threat detection and localization for monitoring nodes of an industrial asset control system

US2017359366A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2017359366-A1
Application numberUS-201615179034-A
CountryUS
Kind codeA1
Filing dateJun 10, 2016
Priority dateJun 10, 2016
Publication dateDec 14, 2017
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In some embodiments, a plurality of real-time monitoring node signal inputs receive streams of monitoring node signal values over time that represent a current operation of the industrial asset control system. A threat detection computer platform, coupled to the plurality of real-time monitoring node signal inputs, may receive the streams of monitoring node signal values and, for each stream of monitoring node signal values, generate a current monitoring node feature vector. The threat detection computer platform may then compare each generated current monitoring node feature vector with a corresponding decision boundary for that monitoring node, the decision boundary separating a normal state from an abnormal state for that monitoring node, and localize an origin of a threat to a particular monitoring node. The threat detection computer platform may then automatically transmit a threat alert signal based on results of said comparisons along with an indication of the particular monitoring node.

First claim

Opening claim text (preview).

1 . A system to protect an industrial asset control system, comprising: a plurality of real-time monitoring node signal inputs to receive streams of monitoring node signal values over time that represent a current operation of the industrial asset control system; and a threat detection computer platform, coupled to the plurality of real-time monitoring node signal inputs, to: (i) receive the streams of monitoring node signal values and, for each stream of monitoring node signal values, generate a current monitoring node feature vector, (ii) compare each generated current monitoring node feature vector with a corresponding decision boundary for that monitoring node, the decision boundary separating a normal state from an abnormal state for that monitoring node, (iii) localize an origin of a threat to a particular monitoring node; and (iv) automatically transmit a threat alert signal based on results of said comparisons along with an indication of the particular monitoring node. 2 . The system of claim 1 , wherein at least one of the monitoring nodes is associated with at least one of: sensor data, an auxiliary equipment input signal, a control intermediary parameter, and a control logic value. 3 . The system of claim 1 , wherein at least one monitoring node is associated with a plurality of decision boundaries and said comparison is performed in connection with each of those boundaries. 4 . The system of claim 1 , wherein at least one decision boundary was generated in accordance with a feature-based learning algorithm and at least one of: (i) a high fidelity model, and (ii) normal operation of the industrial asset control system. 5 . The system of claim 1 , wherein the alert notification is performed using a cloud-based system. 6 . The system of claim 5 , wherein said localizing is performed in accordance with a time at which a decision boundary associated with one monitoring node was crossed as compared to a time at which a decision boundary associated with another monitoring node was crossed. 7 . The system of claim 1 , wherein at least one of the current monitoring node feature vectors is associated with at least one of: principal components, statistical features, deep learning features, frequency domain features, time series analysis features, logical features, geographic or position based locations, and interaction features. 8 . The system of claim 1 , wherein a threat detection model associated with at least one decision boundary is dynamically adapted based on at least one of: a transient condition, a steady state model of the industrial asset control system, and data sets obtained while operating the system as in self-learning systems from incoming data stream. 9 . The system of claim 1 , wherein the threat is associated with at least one of: an actuator attack, a controller attack, a monitoring node attack, a plant state attack, spoofing, financial damage, unit availability, a unit trip, a loss of unit life, and asset damage requiring at least one new part. 10 . The system of claim 1 , further comprising: a normal space data source storing, for each of the plurality of monitoring nodes, a series of normal monitoring node values over time that represent normal operation of the industrial asset control system; a threatened space data source storing, for each of the plurality of monitoring nodes, a series of threatened monitoring node values over time that represent a threatened operation of the industrial asset control system; and a threat detection model creation computer, coupled to the normal space data source and the threatened space data source, to: receive the series normal monitoring node values and generate the set of normal feature vectors, receive the series of threatened monitoring node values and generate the set of threatened feature vectors, and automatically calculate and output at least one decision boundary for a threat detection model based on the set of normal feature vectors and the set of threatened feature vectors. 11 . The system of claim 10 , wherein at least one of the series of normal monitoring node values and the series of threatened monitoring node values are associated with a high fidelity equipment model. 12 . The system of claim 10 , wherein at least one decision boundary exists in a multi-dimensional space and is associated with at least one of: a dynamic model, design of experiment data, machine learning techniques, a support vector machine, a full factorial process, Taguchi screening, a central composite methodology, a Box-Behnken methodology, real-world operating conditions, a full-factorial design, a screening design, and a central composite design. 13 . The system of claim 10 , wherein the threat detection model is associated with decision boundaries and at least one of: feature mapping, and feature parameters. 14 . The system of claim 10 , wherein at least one of the normal and threatened monitoring node values are obtained by running design of experiments on an industrial control system associated with at least one of: a power turbine, a jet engine, a locomotive, and an autonomous vehicle. 15 . A computerized method to protect an industrial asset control system, comprising: receiving, by a threat detection computer platform, a plurality of real-time streams of monitoring node signal values over time that represent a current operation of the industrial asset control system; generating, by the threat detection computer platform, a current monitoring node feature vector for each stream of monitoring node signal values; comparing, by the threat detection computer platform, each generated current monitoring node feature vector with a corresponding non-linear, multi-dimensional decision boundary for that monitoring node, the decision boundary separating a normal state from an abnormal state for that monitoring node; localize an origin of a threat to a particular monitoring node; and automatically transmitting a threat alert signal based on results of said comparisons along with an indication of the particular monitoring node. 16 . The method of claim 15 , wherein at least one of the monitoring nodes is associated with at least one of: sensor data, an auxiliary equipment input signal, a control intermediary parameter, and a control logic value. 17 . The method of claim 15 , wherein at least one monitoring node is associated with a plurality of multi-dimensional decision boundaries, said comparison is performed in connection with each of those boundaries, and at least one decision boundary was generated in accordance with a feature-based learning algorithm and at least one of: (i) a high fidelity model, and (ii) normal operation of the industrial asset control system. 18 . The method of claim 15 , wherein said localizing is performed in accordance with a time at which a decision boundary associated with one monitoring node was crossed as compared to a time at which a decision boundary associated with another monitoring node was crossed. 19 . A non-transient, computer-readable medium storing instructions to be executed by a processor to perform a method of protecting an asset control system, the method comprising: receiving, by a threat detection computer platform, real-time streams of monitoring node signal values over time that represent a current operation of the asset control system; generating, by the threat detection computer platform, a current monitoring node feature vector for each stream of monitoring node signal values; comparing, by the threat detectio

Assignees

Inventors

Classifications

  • Vulnerability analysis · CPC title

  • in which an application is distributed across nodes in the network (software deployment G06F8/60; multiprogramming arrangements G06F9/46) · CPC title

  • H04W4/38Primary

    for collecting sensor information · CPC title

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • model based detection method, e.g. first-principles knowledge model · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2017359366A1 cover?
In some embodiments, a plurality of real-time monitoring node signal inputs receive streams of monitoring node signal values over time that represent a current operation of the industrial asset control system. A threat detection computer platform, coupled to the plurality of real-time monitoring node signal inputs, may receive the streams of monitoring node signal values and, for each stream of…
Who is the assignee on this patent?
Gen Electric
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Dec 14 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).