Patent · US9910982B2 · B2 · US
Large-scale, time-sensitive secure distributed control systems and methods
- (11) Publication number
- US9910982B2
- (21) Application number
- 14/889,840
- (22) Filing date
- 2014-05-21
- (30) Priority date
- 2013-05-25
- (43) Publication date
- 2018-03-06
- (45) Date of grant
- 2018-03-06
- (51) IPC
- G06F 21/55; H04L 29/06; H04L 12/26
- (52) CPC
- (73) Assignee
- North Carolina State University
- (72) Inventors
- Mo-Yuen Chow; Wente ZENG
- (54) Title
- Large-scale, time-sensitive secure distributed control systems and methods
- (57) Abstract
Large-scale, time-sensitive secure distributed control systems and methods are disclosed. According to an aspect, a method includes detecting an anomaly at a module among a plurality of modules in a network. The method also includes adjusting a reputation level of the module associated with the detected anomaly. Further, the method includes controlling interaction of the module associated with the detected anomaly within the network based on the adjusted reputation level.
- Full text
- View on Google Patents
Claims (20)
- A method comprising: determining, by a processor, a consensus computation weight at a plurality of modules in a computer network; detecting, by the processor, an anomaly at a module among the plurality of modules in the computer network; decreasing, by the processor, the consensus computation weight of the module associated with the detected anomaly to reduce a malicious effect to a second module among the plurality of modules with the computer network; adjusting, by the processor, a reputation level of the module associated with the decreased consensus computation weight of the module associated with the detected anomaly in parallel with the plurality of modules in the computer network; determining, by the processor, that the computer network would remain connected upon isolating the module associated with the detected anomaly; isolating, by the processor, the module associated with the detected anomaly in the computer network based on the adjusted reputation level of the module associated with the detected anomaly; and controlling interaction of the module associated with the detected anomaly within the network based on the adjusted reputation level.
- The method of claim 1, wherein detecting an anomaly comprises: determining states of the modules; and comparing the states of the modules to determine anomaly behavior of one of the modules.
- The method of claim 1, wherein detecting an anomaly comprises detecting behaviors among the modules that are indicative of one of a cyber attack and a malicious operation among neighboring modules.
- The method of claim 1, further comprising receiving information about availability of one of communication links and information flows with one or more neighboring modules, and wherein detecting an anomaly comprises detecting the anomaly based on the one of the communication links and information flows.
- The method of claim 1, wherein controlling interaction of the module comprises isolating the module from the network based on the reputation level.
- The method of claim 1, further comprising restoring the consensus computation weight of the module when the anomaly is not detected.
- The method of claim 1, further comprising determining whether the reputation level of the module associated with the detected anomaly is below a predetermined level, and wherein controlling interaction of the module comprises rejecting information from the module in response to determining that the reputation level is below the predetermined level.
- A system comprising: at least a processor and memory configured to: determine a consensus computation weight at a plurality of modules in a computer network; detect an anomaly at a module among the plurality of modules in the computer network; decrease the consensus computation weight of the module associated with the detected anomaly to reduce a malicious effect to a second module among the plurality of modules within the computer network; adjust a reputation level of the module associated with the decreased consensus computation weight of the module associated with the detected anomaly in parallel with the plurality of modules in the computer network; determine that the computer network would remain connected upon isolating the module associated with the detected anomaly; isolate the module associated with the detected anomaly in the computer network based on the adjusted reputation level of the module associated with the detected anomaly; and control interaction of the module associated with the detected anomaly within the network based on the adjusted reputation level.
- The system of claim 8, wherein the at least a processor and memory are configured to: determine states of the modules; and compare the states of the modules to determine anomaly behavior of one of the modules.
- The system of claim 8, wherein the at least a processor and memory are configured to detect behaviors among the modules that are indicative of one of a cyber attack and a malicious operation among neighboring modules.
- The system of claim 8, wherein the at least a processor and memory are configured to: receive information about availability of one of communication links and information flows with one or more neighboring modules; and detect the anomaly based on the one of the communication links and information flows.
- The system of claim 8, wherein the at least a processor and memory are configured to isolate the module from the network based on the reputation level.
- The system of claim 8, wherein the at least a processor and memory are configured to restore the consensus computation weight of the module when the anomaly is not detected.
- The system of claim 8, wherein the at least a processor and memory are configured to: determine whether the reputation level of the module associated with the detected anomaly is below a predetermined level; and reject information from the module in response to determining that the reputation level is below the predetermined level.
- A computer program product comprising a non-transitory computer readable storage medium having program instructions embodied therewith, the program instructions readable by a computing device to cause the computing device to: determine, by the computing device, a consensus computation weight at a plurality of modules in a computer network; detect, by the computing device, an anomaly at a module among the plurality of modules in the computer network; decrease, by the computing device, the consensus computation weight of the module associated with the detected anomaly to a malicious effect to a second module among the plurality of modules with the computer network; adjust, by the computing device, a reputation level of the module associated with the decreased consensus computation weight of the module associated with the detected anomaly in parallel with the plurality of modules in the computer network; determine, by the computing device, that the computer network would remain connected upon isolating the module associated with the detected anomaly; isolate, by the computing device, the module associated with the detected anomaly in the computer network based on the adjusted reputation level of the module associated with the detected anomaly; and control, by the computing device, interaction of the module associated with the detected anomaly within the network based on the adjusted reputation level.
- The computer program product of claim 15, wherein the program instructions are readable by the computing device to cause the computing device to: determine, by the computing device, states of the modules; and compare, by the computing device, the states of the modules to determine anomaly behavior of one of the modules.
- The computer program product of claim 15, wherein the program instructions are readable by the computing device to cause the computing device to detect behaviors among the modules that are indicative of one of a cyber attack and a malicious operation among neighboring modules.
- The computer program product of claim 15, wherein the program instructions are readable by the computing device to cause the computing device to: receive information about availability of one of communication links and information flows with one or more neighboring modules; and detect the anomaly based on the one of the communication links and information flows.
- The computer program product of claim 15, wherein the program instructions are readable by the computing device to cause the computing device to isolate the module from the network based on the reputation level.
- The computer program product of claim 15, wherein the program instructions are readable by the computing device to cause the computing device to: determine whether the reputation level of the module associated with the detected anomaly is below a predetermined level; and reject information from the module in response to determining that the reputation level is below the predetermined level.
Description
The present subject matter relates to large-scale, time-sensitive secure distributed control systems and methods.
Distributed Networked Control Systems (D-NCS) have been at the core of national critical infrastructures and industrial control systems for many decades (e.g., electrical power systems and transportation systems). While most D-NCS have been safe in the past, a few confirmed cases of cyber attacks have occurred. The recent presence of the infamous industrial control system malwares “Stuxnet” and “Flame” have brought significant attention to making industrial control systems safe from such malicious cyber attacks. Many D-NCS applications are time-sensitive, data-sensitive, and safety-critical. The potential consequences of compromising D-NCS can be devastating to public health and safety, national security, and the economy. Therefore, it is important to implement D-NCS with secure controls that make reliable, safe, and flexible performance possible.
D-NCS are increasingly more vulnerable to cyber attacks with the rapid advancements and uses of networking, embedded systems, wireless communication technologies, and novel control strategies. In particular, more and more distributed control algorithms are being used in D-NCS because of their flexibility, robustness, computation, and communication features. These algorithms, however, increase the vulnerability of D-NCS to malicious cyber attacks. In the absence of a centralized supervisory node that monitors the activities of the nodes in the network, distributed control strategies are prone to cyber attacks and component failures.
Citations (7)
- US20030149888A1
- US20040133640A1
- US20050262237A1
- KR20070109527A
- US20090044265A1
- US20110179164A1
- US20120209411A1
Record as JSON
{
"publication_number": "US9910982B2",
"country": "US",
"kind": "B2",
"title": "Large-scale, time-sensitive secure distributed control systems and methods",
"abstract": "Large-scale, time-sensitive secure distributed control systems and methods are disclosed. According to an aspect, a method includes detecting an anomaly at a module among a plurality of modules in a network. The method also includes adjusting a reputation level of the module associated with the detected anomaly. Further, the method includes controlling interaction of the module associated with the detected anomaly within the network based on the adjusted reputation level.",
"claims": [
"1. A method comprising: determining, by a processor, a consensus computation weight at a plurality of modules in a computer network; detecting, by the processor, an anomaly at a module among the plurality of modules in the computer network; decreasing, by the processor, the consensus computation weight of the module associated with the detected anomaly to reduce a malicious effect to a second module among the plurality of modules with the computer network; adjusting, by the processor, a reputation level of the module associated with the decreased consensus computation weight of the module associated with the detected anomaly in parallel with the plurality of modules in the computer network; determining, by the processor, that the computer network would remain connected upon isolating the module associated with the detected anomaly; isolating, by the processor, the module associated with the detected anomaly in the computer network based on the adjusted reputation level of the module associated with the detected anomaly; and controlling interaction of the module associated with the detected anomaly within the network based on the adjusted reputation level.",
"2. The method of claim 1, wherein detecting an anomaly comprises: determining states of the modules; and comparing the states of the modules to determine anomaly behavior of one of the modules.",
"3. The method of claim 1, wherein detecting an anomaly comprises detecting behaviors among the modules that are indicative of one of a cyber attack and a malicious operation among neighboring modules.",
"4. The method of claim 1, further comprising receiving information about availability of one of communication links and information flows with one or more neighboring modules, and wherein detecting an anomaly comprises detecting the anomaly based on the one of the communication links and information flows.",
"5. The method of claim 1, wherein controlling interaction of the module comprises isolating the module from the network based on the reputation level.",
"6. The method of claim 1, further comprising restoring the consensus computation weight of the module when the anomaly is not detected.",
"7. The method of claim 1, further comprising determining whether the reputation level of the module associated with the detected anomaly is below a predetermined level, and wherein controlling interaction of the module comprises rejecting information from the module in response to determining that the reputation level is below the predetermined level.",
"8. A system comprising: at least a processor and memory configured to: determine a consensus computation weight at a plurality of modules in a computer network; detect an anomaly at a module among the plurality of modules in the computer network; decrease the consensus computation weight of the module associated with the detected anomaly to reduce a malicious effect to a second module among the plurality of modules within the computer network; adjust a reputation level of the module associated with the decreased consensus computation weight of the module associated with the detected anomaly in parallel with the plurality of modules in the computer network; determine that the computer network would remain connected upon isolating the module associated with the detected anomaly; isolate the module associated with the detected anomaly in the computer network based on the adjusted reputation level of the module associated with the detected anomaly; and control interaction of the module associated with the detected anomaly within the network based on the adjusted reputation level.",
"9. The system of claim 8, wherein the at least a processor and memory are configured to: determine states of the modules; and compare the states of the modules to determine anomaly behavior of one of the modules.",
"10. The system of claim 8, wherein the at least a processor and memory are configured to detect behaviors among the modules that are indicative of one of a cyber attack and a malicious operation among neighboring modules.",
"11. The system of claim 8, wherein the at least a processor and memory are configured to: receive information about availability of one of communication links and information flows with one or more neighboring modules; and detect the anomaly based on the one of the communication links and information flows.",
"12. The system of claim 8, wherein the at least a processor and memory are configured to isolate the module from the network based on the reputation level.",
"13. The system of claim 8, wherein the at least a processor and memory are configured to restore the consensus computation weight of the module when the anomaly is not detected.",
"14. The system of claim 8, wherein the at least a processor and memory are configured to: determine whether the reputation level of the module associated with the detected anomaly is below a predetermined level; and reject information from the module in response to determining that the reputation level is below the predetermined level.",
"15. A computer program product comprising a non-transitory computer readable storage medium having program instructions embodied therewith, the program instructions readable by a computing device to cause the computing device to: determine, by the computing device, a consensus computation weight at a plurality of modules in a computer network; detect, by the computing device, an anomaly at a module among the plurality of modules in the computer network; decrease, by the computing device, the consensus computation weight of the module associated with the detected anomaly to a malicious effect to a second module among the plurality of modules with the computer network; adjust, by the computing device, a reputation level of the module associated with the decreased consensus computation weight of the module associated with the detected anomaly in parallel with the plurality of modules in the computer network; determine, by the computing device, that the computer network would remain connected upon isolating the module associated with the detected anomaly; isolate, by the computing device, the module associated with the detected anomaly in the computer network based on the adjusted reputation level of the module associated with the detected anomaly; and control, by the computing device, interaction of the module associated with the detected anomaly within the network based on the adjusted reputation level.",
"16. The computer program product of claim 15, wherein the program instructions are readable by the computing device to cause the computing device to: determine, by the computing device, states of the modules; and compare, by the computing device, the states of the modules to determine anomaly behavior of one of the modules.",
"17. The computer program product of claim 15, wherein the program instructions are readable by the computing device to cause the computing device to detect behaviors among the modules that are indicative of one of a cyber attack and a malicious operation among neighboring modules.",
"18. The computer program product of claim 15, wherein the program instructions are readable by the computing device to cause the computing device to: receive information about availability of one of communication links and information flows with one or more neighboring modules; and detect the anomaly based on the one of the communication links and information flows.",
"19. The computer program product of claim 15, wherein the program instructions are readable by the computing device to cause the computing device to isolate the module from the network based on the reputation level.",
"20. The computer program product of claim 15, wherein the program instructions are readable by the computing device to cause the computing device to: determine whether the reputation level of the module associated with the detected anomaly is below a predetermined level; and reject information from the module in response to determining that the reputation level is below the predetermined level."
],
"description_excerpt": "The present subject matter relates to large-scale, time-sensitive secure distributed control systems and methods.\n\nDistributed Networked Control Systems (D-NCS) have been at the core of national critical infrastructures and industrial control systems for many decades (e.g., electrical power systems and transportation systems). While most D-NCS have been safe in the past, a few confirmed cases of cyber attacks have occurred. The recent presence of the infamous industrial control system malwares “Stuxnet” and “Flame” have brought significant attention to making industrial control systems safe from such malicious cyber attacks. Many D-NCS applications are time-sensitive, data-sensitive, and safety-critical. The potential consequences of compromising D-NCS can be devastating to public health and safety, national security, and the economy. Therefore, it is important to implement D-NCS with secure controls that make reliable, safe, and flexible performance possible.\n\nD-NCS are increasingly more vulnerable to cyber attacks with the rapid advancements and uses of networking, embedded systems, wireless communication technologies, and novel control strategies. In particular, more and more distributed control algorithms are being used in D-NCS because of their flexibility, robustness, computation, and communication features. These algorithms, however, increase the vulnerability of D-NCS to malicious cyber attacks. In the absence of a centralized supervisory node that monitors the activities of the nodes in the network, distributed control strategies are prone to cyber attacks and component failures.",
"cpc": [
"G06F 21/552",
"G06F 2221/034",
"H04L 43/00",
"H04L 63/1425",
"H04L 67/104",
"H04L 67/1057",
"H04L 67/12"
],
"ipc": [
"G06F 21/55",
"H04L 29/06",
"H04L 12/26"
],
"assignees": [
"North Carolina State University"
],
"inventors": [
"Mo-Yuen Chow",
"Wente ZENG"
],
"filing_date": "2014-05-21",
"publication_date": "2018-03-06",
"grant_date": "2018-03-06",
"priority_date": "2013-05-25",
"application_number": "US-201414889840-A",
"family_id": "51989322",
"cited_by_count": 4,
"citations": [
"US20030149888A1",
"US20040133640A1",
"US20050262237A1",
"KR20070109527A",
"US20090044265A1",
"US20110179164A1",
"US20120209411A1"
]
}
Record 3,547 of 8,000 in Patents full text (MLC-0201). Request the full dataset.