IP Library › Granted Patent US 11,924,227
Granted Patent B2
US 11,924,227 · App. 17/259,010 · Granted Mar 5, 2024

Hybrid unsupervised machine learning framework for industrial control system intrusion detection

Inventors: Jiaxing Pi (Weehawken, NJ); Dong Wei (Edison, NJ); Leandro Pfleger de Aguiar (Robbinsville, NJ); Honggang Wang (Edison, NJ); Saman Zonouz (Edison, NJ)
Assignees: SIEMENS AKTIENGESELLSCHAFT; Rutgers University
H04L63/1416H04L63/1425H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,924,227
App. No.
17/259,010
Granted
Mar 5, 2024
Kind
B2
Abstract

A system for monitoring an industrial system for cyberattacks includes an industrial control system including a plurality of actuators, a plurality of sensors each arranged to measure one of a plurality of operating parameters, and an edge device and a computer including a data storage device having stored thereon a program that includes each of a time-series database including expected operating ranges for each operating parameter, a clustering-based database that includes clusters of operating parameters having similarities, and a correlation database that includes pairs of operating parameters that show a correlation. An alarm system is operable to initiate an alarm in response to current operating data including a measurement from one of the plurality of sensors falling outside of an expected range, a change in the expected clustering of one of the plurality of sensors based on the current operating data from each of the plurality of sensors, and a variation in the current operating data between two of the plurality of sensors that falls outside of an expected correlation of the two of the plurality of sensors.

Claims (27)

1. A method of protecting an industrial system from cyberattacks, the method comprising:

collecting initial operating data from a plurality of sensors each positioned within the industrial system and operable to monitor an operating parameter of the industrial system;

analyzing the initial operating data to develop a program that includes a time-series database including expected operating ranges for each operating parameter, a clustering-based database that includes clusters of operating parameters having similarities, and a correlation database that includes pairs of operating parameters that show a correlation in their initial operating data;

operating the program including the time-series database, the clustering-based database, and the correlation database in a computer, the program operable to receive current operating data and to analyze that operating data in view of each of the time-series database, the clustering-based database, and the correlation database; and

triggering an alarm in response to the analysis of the current operating data indicating at least one of an operating parameter outside of an expected range, a change in the expected clustering, and a variation in a correlation.

2. The method of claim 1 , wherein the industrial system includes a plurality of edge devices each arranged to collect data from a portion of the plurality of sensors, each edge device operable to communicate with the program to deliver the current operating data from its respective portion of the plurality of sensors.

3. The method of claim 2 , wherein each edge device includes the time-series database and each edge device operates to analyze the current operating data received by that edge device to determine if any measured operating parameter is outside of an expected range.

4. The method of claim 3 , wherein each edge device includes the correlation database and each edge device operates to analyze the current operating data received by that edge device to determine if any pair of measured operating data deviates from the known correlations in the correlation database.

5. The method of claim 4 , wherein each edge device includes the clustering-based database and each edge device operates to analyze the current operating data received by that edge device to determine if any of the measured data deviates from the known clusters in the clustering-based database.

6. The method of claim 1 , wherein triggering the alarm includes indicating the most deviated operating parameter and a time frame for the deviation in response to the detection of the operating parameter outside of the expected range.

7. The method of claim 1 , wherein triggering the alarm includes indicating the most deviated operating parameters in response to the detection of the change in the expected clustering.

8. The method of claim 1 , wherein triggering the alarm includes indicating the most deviated operating parameter pairs in response to the detection of the variation in the correlation.

9. The method of claim 1 , wherein the initial operating data is known to be free of any data effected by a cyberattack.

10. The method of claim 1 , further comprising a correlation database for the storage of detected security events.

11. The method of claim 10 , further comprising correlating the security events in the correlation database with and detected alarms to determine if a detected anomaly is related to a security attack rather than to a process control anomaly.

12. A non-transitory computer readable medium encoded with processor executable instructions that when executed by at least one processor, cause the at least one processor to carry out a method for protecting an industrial system from cyberattacks according to claim 1 .

13. A system for monitoring an industrial system for cyberattacks, the system comprising:

an industrial control system including a plurality of actuators, a plurality of sensors each arranged to measure one of a plurality of operating parameters, and an edge device;

a computer including a data storage device having stored thereon a program that includes each of a time-series database including expected operating ranges for each operating parameter, a clustering-based database that includes clusters of operating parameters having similarities, and a correlation database that includes pairs of operating parameters that show a correlation; and

an alarm system operable to initiate an alarm in response to current operating data including a measurement from one of the plurality of sensors falling outside of an expected range, a change in the expected clustering of one of the plurality of sensors based on the current operating data from each of the plurality of sensors, and a variation in the current operating data between two of the plurality of sensors that falls outside of an expected correlation of the two of the plurality of sensors.

14. The system of claim 13 , wherein the data storage device includes initial operating data collected by the plurality of sensors and wherein the computer analyzes the initial operating data to populate the time-series database, the clustering-based database, and the correlation database.

15. The system of claim 14 , wherein the initial operating data is known to be free of any data effected by a cyberattack.

16. The system of claim 13 , wherein the edge device is one of a plurality of edge devices, and wherein each edge device is arranged to collect data from a portion of the plurality of sensors, each edge device operable to communicate with the computer to deliver the current operating data from its respective portion of the plurality of sensors.

17. The system of claim 16 , wherein each edge device includes the time-series database and each edge device operates to analyze the current operating data received by that edge device to determine if any measured operating parameter is outside of an expected range.

18. The system of claim 17 , wherein each edge device includes the correlation database and each edge device operates to analyze the current operating data received by that edge device to determine if any pair of measured operating data deviates from the known correlations in the correlation database.

19. The system of claim 18 , wherein each edge device includes the clustering-based database and each edge device operates to analyze the current operating data received by that edge device to determine if any of the measured data deviates from the known clusters in the clustering-based database.

20. The system of claim 13 , wherein the alarm includes an indication of the most deviated operating parameter and a time frame for the deviation in response to the detection of the operating parameter outside of the expected range.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2021
From: ZONOUZ, SAMAN
To: RUTGERS, THE STATE UNIVERSITY OF NEW JERSEY
Reel/Frame 054922/0302 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2021
From: WANG, HONGGANG
To: RUTGERS, THE STATE UNIVERSITY OF NEW JERSEY
Reel/Frame 054922/0467 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2021
From: PI, JIAXING; WEI, DONG; PFLEGER DE AGUIAR, LEANDRO
To: SIEMENS CORPORATION
Reel/Frame 054900/0956 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2021
From: SIEMENS CORPORATION
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 054901/0047 →
Continuity (2)
Provisional Application 62695873 · Jul 10, 2018
Related Publication 20210306356A1 · Sep 30, 2021
Cited By (2)
US 12,241,563 US 12,748,417