SYSTEMS AND METHODS FOR CONTROLLING AN INDUSTRIAL ASSET IN THE PRESENCE OF A CYBER ATTACK

    公开(公告)号:US20230126087A1

    公开(公告)日:2023-04-27

    申请号:US17509159

    申请日:2021-10-25

    Abstract: Systems and methods are provided for the control of an industrial asset, such as a power generating asset. Accordingly, an interceptor module receives a state-change instruction from a state module that directs a change from a first state condition to a second state condition. The first and second state conditions direct modes of operation of at least one sub module of the controller of the industrial asset. The interceptor module then correlates the state-change instruction to a state-change classification. Based on the state-change classification, the interceptor module identifies an indication of a mode-switching attack. In response to the identification of the mode-switching attack, at least one mitigation response is implemented.

    DYNAMIC, RESILIENT SENSING SYSTEM FOR AUTOMATIC CYBER-ATTACK NEUTRALIZATION

    公开(公告)号:US20210120031A1

    公开(公告)日:2021-04-22

    申请号:US16654319

    申请日:2019-10-16

    Abstract: An industrial asset may have monitoring nodes that generate current monitoring node values. An abnormality detection computer may determine that an abnormal monitoring node is currently being attacked or experiencing fault. A dynamic, resilient estimator constructs, using normal monitoring node values, a latent feature space (of lower dimensionality as compared to a temporal space) associated with latent features. The system also constructs, using normal monitoring node values, functions to project values into the latent feature space. Responsive to an indication that a node is currently being attacked or experiencing fault, the system may compute optimal values of the latent features to minimize a reconstruction error of the nodes not currently being attacked or experiencing a fault. The optimal values may then be projected back into the temporal space to provide estimated values and the current monitoring node values from the abnormal monitoring node are replaced with the estimated values.

    SYSTEMS AND METHODS FOR CONTROLLING DISTRIBUTED POWER SYSTEMS USING DOWN-SAMPLING

    公开(公告)号:US20210091565A1

    公开(公告)日:2021-03-25

    申请号:US16577791

    申请日:2019-09-20

    Abstract: A method for controlling a distributed power system is provided, the power system including an aggregator communicatively coupled to a plurality of nodes. The method includes receiving, at the aggregator, a specified aggregated power level, and at each of a plurality of sample times recurring at a regular interval, receiving, at the aggregator from each of the nodes, a condensed dataset, calculating, at the aggregator, a global value based on the specified aggregated power level, the condensed datasets, and a control prediction horizon, transmitting the global value to each of the nodes, solving, at each of the plurality of nodes, a local optimization problem based on the received global value and a local model prediction horizon for that node that is longer than the control prediction horizon, and controlling, at each of the plurality of nodes, a load based on the solved local optimization problem.

    Multi-mode boundary selection for threat detection in industrial asset control system

    公开(公告)号:US10397257B2

    公开(公告)日:2019-08-27

    申请号:US15371723

    申请日:2016-12-07

    Abstract: According to some embodiments, streams of monitoring node signal values may be received over time that represent a current operation of an industrial asset control system. A current operating mode of the industrial asset control system may be received and used to determine a current operating mode group from a set of potential operating mode groups. For each stream of monitoring node signal values, a current monitoring node feature vector may be determined. Based on the current operating mode group, an appropriate decision boundary may be selected for each monitoring node, the appropriate decision boundary separating a normal state from an abnormal state for that monitoring node in the current operating mode. Each generated current monitoring node feature vector may be compared with the selected corresponding appropriate decision boundary, and a threat alert signal may be automatically transmitted based on results of said comparisons.

    Systems and methods for global cyber-attack or fault detection model

    公开(公告)号:US11740618B2

    公开(公告)日:2023-08-29

    申请号:US17239054

    申请日:2021-04-23

    CPC classification number: G05B23/024 G05B23/027 G05B23/0221 G06N3/045 G06N3/08

    Abstract: An industrial asset may have monitoring nodes that generate current monitoring node values representing a current operation of the industrial asset. An abnormality detection computer may detect when a monitoring node is currently being attacked or experiencing a fault based on a current feature vector, calculated in accordance with current monitoring node values, and a detection model that includes a decision boundary. A model updater (e.g., a continuous learning model updater) may determine an update time-frame (e.g., short-term, mid-term, long-term, etc.) associated with the system based on trigger occurrence detection (e.g., associated with a time-based trigger, a performance-based trigger, an event-based trigger, etc.). The model updater may then update the detection model in accordance with the determined update time-frame (and, in some embodiments, continuous learning).

    Anomaly forecasting and early warning generation

    公开(公告)号:US11475124B2

    公开(公告)日:2022-10-18

    申请号:US15594779

    申请日:2017-05-15

    Abstract: The example embodiments are directed to a system and method for forecasting anomalies in feature detection. In one example, the method includes storing feature behavior information of at least one monitoring node of an asset, including a normalcy boundary identifying normal feature behavior and abnormal feature behavior for the at least one monitoring node in feature space, receiving input signals from the at least one monitoring node of the asset and transforming the input signals into feature values in the feature space, wherein the feature values are located within the normalcy boundary, forecasting that a future feature value corresponding to a future input signal from the at least one monitoring node is going to be positioned outside the normalcy boundary based on the feature values within the normalcy boundary, and outputting information concerning the forecasted future feature value being outside the normalcy boundary for display.

    Dynamic, resilient virtual sensing system and shadow controller for cyber-attack neutralization

    公开(公告)号:US11468164B2

    公开(公告)日:2022-10-11

    申请号:US16710051

    申请日:2019-12-11

    Abstract: An industrial asset may have monitoring nodes (e.g., sensor or actuator nodes) that generate current monitoring node values. An abnormality detection and localization computer may receive the series of current monitoring node values and output an indication of at least one abnormal monitoring node that is currently being attacked or experiencing a fault. An actor-critic platform may tune a dynamic, resilient state estimator for a sensor node and output tuning parameters for a controller that improve operation of the industrial asset during the current attack or fault. The actor-critic platform may include, for example, a dynamic, resilient state estimator, an actor model, and a critic model. According to some embodiments, a value function of the critic model is updated for each action of the actor model and each action of the actor model is evaluated by the critic model to update a policy of the actor-critic platform.

    Detection and protection against mode switching attacks in cyber-physical systems

    公开(公告)号:US11170314B2

    公开(公告)日:2021-11-09

    申请号:US16166417

    申请日:2018-10-22

    Abstract: A cyber-physical system may have a plurality of monitoring nodes each generating a series of current monitoring node values over time that represent current operation of the cyber-physical system. According to some embodiments, a features extraction computer platform may receive the series of current monitoring node values over time and generate current feature vectors based on the series of current monitoring mode values. A system mode estimation computer platform may provide the current feature vectors to a probabilistic graphical model to generate an estimated system mode. The system mode estimation computer platform may then compare the estimated system mode with a currently reported system mode output by the cyber-physical system and generate a system mode status indication based on a result of said comparison. According to some embodiments, the system mode status indication can be used to override the currently reported system mode of the cyber-physical system.

Patent Agency Ranking