Patent · US9367683B2 · B2 · US
Cyber security
- (11) Publication number
- US9367683B2
- (21) Application number
- 14/211,909
- (22) Filing date
- 2014-03-14
- (30) Priority date
- 2013-03-15
- (43) Publication date
- 2016-06-14
- (45) Date of grant
- 2016-06-14
- (52) CPC
- G06F Electric digital data processing: 21/55, 21/52, 21/552, 21/577, 2221/034
- G06N Computing arrangements based on specific computational models: 20/00, 7/01
- Y04S Systems integrating technologies related to power network operation, communication or information technologies for improving the electrical power generation, transmission, distribution, management or usage, i.e. smart grids: 40/20
- (73) Assignee
- KOLACINSKI RICHARD M; ANGELINE BARRY D; LOPARO KENNETH A; CYBERRICADE INC
- (54) Title
- Cyber security
- (57) Abstract
Systems and methods that use probabilistic grammatical inference and statistical data analysis techniques to characterize the behavior of systems in terms of a low dimensional set of summary variables and, on the basis of these models, detect anomalous behaviors are disclosed. The disclosed information-theoretic system and method exploit the properties of information to deduce a structure for information flow and management. The properties of information can provide a fundamental basis for the decomposition of systems and hence a structure for the transmission and combination of observations at the desired levels of resolution (e.g., component, subsystem, system).
- Full text
- View on Google Patents
Claims (13)
- A computer implemented method for detecting cyber physical system behavior, comprising: utilizing one or more processors and associated memory storing one or more programs for execution by the one or more processors, the one or more programs including instructions for: receiving data from a plurality of sensors associated with the cyber physical system; constructing a metrization of the data utilizing a data structuring; determining at least one ensemble and at least one summary variable from the metrized data, wherein the determining includes a symbolic encoding of the metrized data and inferring an automata model utilizing a probabilistic grammatical inference that comprises an ε-Machine Reconstruction statistical machine learning technique that includes describing a system trajectory as a string of symbols and describing system dynamics in terms of shift dynamics of the associated symbol string, wherein the ε-Machine Reconstruction statistical machine learning technique includes at least one of: (a) discovering common subtrees of a string parse tree via a nonparametric Bayesian clustering method including a Dirichlet Process or a Beta Process; or (b) a diffusion map technique; applying a thermodynamic formalism to the at least one summary variable to classify a plurality of system behaviors; identifying the plurality of system behaviors based at least in part on the classified plurality of system behaviors; obtaining, by the one or more processors, a baseline of the system behavior associated with the classified plurality of system behaviors; detecting an anomalous condition based on a deviation of the plurality of system behaviors from the baseline; and generating an output indicating the identified plurality of system behaviors or the anomalous condition.
- The method for detecting cyber physical system behavior of claim 1, including identifying cycles in strings of symbols utilizing pumping lemmas.
- The method for detecting cyber physical system behavior of claim 1, wherein the at least one ensemble is determined empirically.
- The method for detecting cyber physical system behavior of claim 1, wherein applying a thermodynamic formalism includes applying thermodynamic techniques to the sensor data.
- The method for detecting cyber physical system behavior of claim 1, wherein the data structuring includes a manifold learning technique comprising at least one of a Diffusion Mapping, a bijective mapping or a spectral graph analysis.
- The method for detecting cyber physical system behavior of claim 1, wherein the at least one summary variable is determined by forming a derivative of a natural variable.
- The method for detecting cyber physical system behavior of claim 1, wherein receiving data includes receiving time series data from a plurality of sensors monitoring a cyber-physical system.
- The method for detecting cyber physical system behavior of claim 7, wherein the cyber-physical system is an electrical power grid system.
- The method for detecting cyber physical system behavior of claim 1, wherein detecting an anomalous condition includes at least one of predicting or detecting the presence of an Improvised Explosive Device.
- A system for detecting cyber physical system behavior, comprising: a processor and memory coupled to the processor, the processor executes the following executable components: a data collection component that receives encoded information from a plurality of sensors associated with the cyber physical system; a data assimilation component for decoding the encoded information by applying a manifold learning technique to the information to identify system features including at least one summary variable, wherein the data assimilation component applies a thermodynamic formalism to the at least one summary variable to obtain an indication of system behavior, wherein the data assimilation component utilizes a spectral graph analysis process that includes integrating data across at least one of a continuous physical domain or a discrete physical domains and at least one of a computational cyber domain or a transactional cyber domain, wherein the spectral graph analysis process comprises a Diffusion Mapping technique; and an operational component for receiving the indication of system behavior and for detecting an anomalous system behavior.
- The system for detecting cyber physical system behavior of claim 10, wherein the encoded information includes at least one of continuous, discrete or transactional cyber physical system dynamics.
- The system for detecting cyber physical system behavior of claim 10, wherein the operational component provides an output indicating the anomalous system behavior.
- The system for detecting cyber physical system behavior of claim 10, wherein the data assimilation component utilizes a bijective mapping technique.
Citations (12)
- US2010042563A1
- US2011089323A1
- US2011288692A1
- US2012022700A1
- US2012065783A1
- US2012072983A1
- US2012131674A1
- US2012284790A1
- US2013305357A1
- US2013312092A1
- US8091093B2
- WO2012154260A2
Record as JSON
{
"publication_number": "US9367683B2",
"country": "US",
"kind": "B2",
"title": "Cyber security",
"abstract": "Systems and methods that use probabilistic grammatical inference and statistical data analysis techniques to characterize the behavior of systems in terms of a low dimensional set of summary variables and, on the basis of these models, detect anomalous behaviors are disclosed. The disclosed information-theoretic system and method exploit the properties of information to deduce a structure for information flow and management. The properties of information can provide a fundamental basis for the decomposition of systems and hence a structure for the transmission and combination of observations at the desired levels of resolution (e.g., component, subsystem, system).",
"claims": [
"1. A computer implemented method for detecting cyber physical system behavior, comprising: utilizing one or more processors and associated memory storing one or more programs for execution by the one or more processors, the one or more programs including instructions for: receiving data from a plurality of sensors associated with the cyber physical system; constructing a metrization of the data utilizing a data structuring; determining at least one ensemble and at least one summary variable from the metrized data, wherein the determining includes a symbolic encoding of the metrized data and inferring an automata model utilizing a probabilistic grammatical inference that comprises an ε-Machine Reconstruction statistical machine learning technique that includes describing a system trajectory as a string of symbols and describing system dynamics in terms of shift dynamics of the associated symbol string, wherein the ε-Machine Reconstruction statistical machine learning technique includes at least one of: (a) discovering common subtrees of a string parse tree via a nonparametric Bayesian clustering method including a Dirichlet Process or a Beta Process; or (b) a diffusion map technique; applying a thermodynamic formalism to the at least one summary variable to classify a plurality of system behaviors; identifying the plurality of system behaviors based at least in part on the classified plurality of system behaviors; obtaining, by the one or more processors, a baseline of the system behavior associated with the classified plurality of system behaviors; detecting an anomalous condition based on a deviation of the plurality of system behaviors from the baseline; and generating an output indicating the identified plurality of system behaviors or the anomalous condition.",
"2. The method for detecting cyber physical system behavior of claim 1, including identifying cycles in strings of symbols utilizing pumping lemmas.",
"3. The method for detecting cyber physical system behavior of claim 1, wherein the at least one ensemble is determined empirically.",
"4. The method for detecting cyber physical system behavior of claim 1, wherein applying a thermodynamic formalism includes applying thermodynamic techniques to the sensor data.",
"5. The method for detecting cyber physical system behavior of claim 1, wherein the data structuring includes a manifold learning technique comprising at least one of a Diffusion Mapping, a bijective mapping or a spectral graph analysis.",
"6. The method for detecting cyber physical system behavior of claim 1, wherein the at least one summary variable is determined by forming a derivative of a natural variable.",
"7. The method for detecting cyber physical system behavior of claim 1, wherein receiving data includes receiving time series data from a plurality of sensors monitoring a cyber-physical system.",
"8. The method for detecting cyber physical system behavior of claim 7, wherein the cyber-physical system is an electrical power grid system.",
"9. The method for detecting cyber physical system behavior of claim 1, wherein detecting an anomalous condition includes at least one of predicting or detecting the presence of an Improvised Explosive Device.",
"10. A system for detecting cyber physical system behavior, comprising: a processor and memory coupled to the processor, the processor executes the following executable components: a data collection component that receives encoded information from a plurality of sensors associated with the cyber physical system; a data assimilation component for decoding the encoded information by applying a manifold learning technique to the information to identify system features including at least one summary variable, wherein the data assimilation component applies a thermodynamic formalism to the at least one summary variable to obtain an indication of system behavior, wherein the data assimilation component utilizes a spectral graph analysis process that includes integrating data across at least one of a continuous physical domain or a discrete physical domains and at least one of a computational cyber domain or a transactional cyber domain, wherein the spectral graph analysis process comprises a Diffusion Mapping technique; and an operational component for receiving the indication of system behavior and for detecting an anomalous system behavior.",
"11. The system for detecting cyber physical system behavior of claim 10, wherein the encoded information includes at least one of continuous, discrete or transactional cyber physical system dynamics.",
"12. The system for detecting cyber physical system behavior of claim 10, wherein the operational component provides an output indicating the anomalous system behavior.",
"13. The system for detecting cyber physical system behavior of claim 10, wherein the data assimilation component utilizes a bijective mapping technique."
],
"cpc": [
"G06F 21/55",
"G06F 21/52",
"G06F 21/552",
"G06F 21/577",
"G06F 2221/034",
"G06N 20/00",
"G06N 7/01",
"Y04S 40/20"
],
"assignees": [
"KOLACINSKI RICHARD M",
"ANGELINE BARRY D",
"LOPARO KENNETH A",
"CYBERRICADE INC"
],
"filing_date": "2014-03-14",
"publication_date": "2016-06-14",
"grant_date": "2016-06-14",
"priority_date": "2013-03-15",
"application_number": "US-201414211909-A",
"family_id": "51537655",
"citations": [
"US2010042563A1",
"US2011089323A1",
"US2011288692A1",
"US2012022700A1",
"US2012065783A1",
"US2012072983A1",
"US2012131674A1",
"US2012284790A1",
"US2013305357A1",
"US2013312092A1",
"US8091093B2",
"WO2012154260A2"
]
}
Record 1,966 of 5,000 in Patents full text (MLC-0201). Request the full dataset.