IP Library Granted Patent US 12,470,594
Granted Patent B1
US 12,470,594 · App. 18/588,646 · Granted Nov 11, 2025

Systems and methods for blocking, detecting and responding to cyber attacks in physically controlled distributed systems

Inventors: Jay T. Johnson (Albuquerque, NM); Christian B. Jones (Albuquerque, NM); Adrian R. Chavez (Davis, CA); Shamina S. Hossain-McKenzie (Albuquerque, NM)
Assignee: National Technology & Engineering Solutions of Sandia, LLC
H04L63/1458H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,594
App. No.
18/588,646
Granted
Nov 11, 2025
Kind
B1
Abstract

Systems and methods that provide Security Orchestration, Automation, and Response (SOAR) technologies that equip cyber-defenders with new capabilities to autonomously respond to network and host-based system alerts, threat hunting results, and cyber intelligence data streams. Systems and methods provide a novel SOAR approach for networked systems where such networked systems include PCDS systems such as DERs. System may ingest data from multiple Intrusion Detection Systems (IDSs) to quickly block attacks and revert PCDS systems to known good states via a collection of IDS technologies including Bump-in-the-Wire (BITW) devices which incorporate physical and cyber data to detect abnormal and potential malicious behaviors.

Claims (22)

1 . A Security Orchestration, Automation, and Response (SOAR) system for a plurality of physically controlled distributed system (PCDS), including:

a plurality of distributed Intrusion Detection Systems (IDS) in communication with the plurality of PCDS collecting cyber-physical data directed to or generated by the plurality of PCDS;

one of or a combination of at least one of plurality of distributed IDS and a SOAR system analyzing the collected cyber-physical data;

one of or a combination of the at least one of plurality of distributed IDS and the SOAR system employing at least one of a plurality of playbooks to detect one of a signature-based attack, a behavior-based attack, and a physical configuration attack on at least one of the plurality of PCDS based on the analyzed collected cyber-physical data; and

one of the SOAR system or a combination of the at least one of plurality of distributed IDS and the SOAR system responding to the attack on the at least one of the plurality of PCDS by employing at least one of a plurality of playbooks.

2 . The SOAR system of claim 1 , further including the SOAR system reverting the affected one of the plurality of PCDS to a previous known good state of operation.

3 . The SOAR system of claim 1 , wherein one of plurality of distributed IDS is a Bump-in-the-Wire (BITW) system in communication with one of the plurality of PCDS and collects cyber-physical data directed to or generated by the one of the plurality of PCDS.

4 . The SOAR system of claim 1 , wherein the at least one of the plurality of attack playbooks is employed to detect a signature-based attack.

5 . The SOAR system of claim 4 , wherein the signature-based attack playbook detects one of identify packet manipulation and Address Resolution Protocol (ARP) spoofing.

6 . The SOAR system of claim 1 , wherein the at least one of the plurality of attack playbooks is employed to detect a behavior-based attack.

7 . The SOAR system of claim 6 , wherein the behavior-based attack playbook detects of one identifies adversary reconnaissance and denial-of-service attempts.

8 . The SOAR system of claim 1 , wherein the at least one of the plurality of attack playbooks detects a physical configuration attack.

9 . The SOAR system of claim 8 , further including the SOAR system reverting the affected at least one of the plurality of PCDS to a previous known good state of operation when one of the plurality of attack playbooks detects a physical configuration attack.

10 . The SOAR system of claim 1 , wherein one of the plurality of attack playbooks is employed to detect a signature-based attack, a second one of the plurality of attack playbooks is employed to detect a behavior-based attack, and a third one of the plurality of attack playbooks is employed to detect a physical configuration attack.

11 . The SOAR system of claim 10 , wherein the plurality of attack playbooks is employed to detect adversary reconnaissance, denial-of-service attacks, malicious Modbus commands, brute force logins, and machine-in-the-middle attacks.

12 . The SOAR system of claim 10 , wherein the plurality of PCDS are distributed energy resources (DER).

13 . The SOAR system of claim 12 , wherein each of the plurality of distributed Intrusion Detection Systems (IDS) is in communication with a particular one the plurality of DER and collects cyber-physical data directed to or generated by the particular DER.

14 . The SOAR system of claim 13 , wherein each of the plurality of distributed Intrusion Detection Systems (IDS) is a Bump-in-the-Wire (BITW) system.

15 . The SOAR system of claim 11 , wherein the plurality of distributed Intrusion Detection Systems (IDS) collects network traffic via various sniffers including Snort and Zeek.

16 . The SOAR system of claim 15 , wherein the plurality of distributed Intrusion Detection Systems (IDS) further conducts traffic analysis.

17 . The SOAR system of claim 15 , wherein the plurality of distributed Intrusion Detection Systems (IDS) further performs deep packet inspections.

18 . The SOAR system of claim 16 , wherein the plurality of distributed Intrusion Detection Systems (IDS) further creates signatures based on the traffic.

Assignments (3)
CONFIRMATORY LICENSE Recorded Dec 12, 2025
From: NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA, LLC
To: NNSA
Reel/Frame 073204/0119 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2024
From: JOHNSON, JAY T.; JONES, CHRISTIAN B.; CHAVEZ, ADRIAN R.; HOSSAIN-MCKENZIE, SHAMINA S.
To: NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA, LLC
Reel/Frame 067880/0404 →
CONFIRMATORY LICENSE Recorded Mar 26, 2024
From: NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA, LLC
To: US DEPARTMENT OF ENERGY
Reel/Frame 066903/0786 →
Continuity (1)
Provisional Application 63448748 · Feb 28, 2023
References Cited (22)
US 12107869B1 · Kannan · 2024 [cited by examiner]
US 12120146B1 · Shakhzadyan · 2024 [cited by examiner]
US 12126643B1 · Skarphedinsson · 2024 [cited by examiner]
US 12309185B1 · Skarphedinsson · 2025 [cited by examiner]
US 12309188B1 · Al Ghazo · 2025 [cited by examiner]
US 12323449B1 · Graves · 2025 [cited by examiner]
US 12348545B1 · Parikh · 2025 [cited by examiner]
US 20210297427A1 · Narula · 2021 [cited by examiner]
US 20230021214A1 · Lehmer · 2023 [cited by examiner]
US 20230319071A1 · Durbin · 2023 [cited by examiner]
US 20230379353A1 · Fichter · 2023 [cited by examiner]
US 20240031395A1 · Kiss · 2024 [cited by examiner]
US 20240411898A1 · Lin · 2024 [cited by examiner]
US 20240422178A1 · Hariri · 2024 [cited by examiner]
US 20250007945A1 · Rieger · 2025 [cited by examiner]
US 20250086280A1 · Murphy · 2025 [cited by examiner]
US 20250088520A1 · Gerow · 2025 [cited by examiner]
US 20250150467A1 · Birsan · 2025 [cited by examiner]
US 20250156303A1 · Stevens · 2025 [cited by examiner]
US 20250175456A1 · Crabtree · 2025 [cited by examiner]
US 20250181749A1 · Thompson · 2025 [cited by examiner]
US 20250190185A1 · Hanson · 2025 [cited by examiner]