CYBER SECURITY
First Claim
1. A computer implemented method for detecting cyber physical system behavior, comprising:
- utilizing one or more processors and associated memory storing one or more programs for execution by the one or more processors, the one or more programs including instructions for;
receiving data from a plurality of sensors associated with the system;
constructing a metrization of the data utilizing a data structuring;
determining at least one ensemble and at least one summary variable from the metrized data;
applying a thermodynamic formalism to the at least one summary variable to classify a plurality of system behaviors;
identifying the system behaviors based at least in part on the classified behaviors;
obtaining a baseline of the system associated with the classified behaviors;
detecting an anomalous condition based on a deviation of the system behaviors from the baseline; and
providing an output indicating the identified system behaviors or the anomalous condition.
2 Assignments
0 Petitions
Accused Products
Abstract
Systems and methods that use probabilistic grammatical inference and statistical data analysis techniques to characterize the behavior of systems in terms of a low dimensional set of summary variables and, on the basis of these models, detect anomalous behaviors are disclosed. The disclosed information-theoretic system and method exploit the properties of information to deduce a structure for information flow and management. The properties of information can provide a fundamental basis for the decomposition of systems and hence a structure for the transmission and combination of observations at the desired levels of resolution (e.g., component, subsystem, system).
23 Citations
20 Claims
-
1. A computer implemented method for detecting cyber physical system behavior, comprising:
-
utilizing one or more processors and associated memory storing one or more programs for execution by the one or more processors, the one or more programs including instructions for; receiving data from a plurality of sensors associated with the system; constructing a metrization of the data utilizing a data structuring; determining at least one ensemble and at least one summary variable from the metrized data; applying a thermodynamic formalism to the at least one summary variable to classify a plurality of system behaviors; identifying the system behaviors based at least in part on the classified behaviors; obtaining a baseline of the system associated with the classified behaviors; detecting an anomalous condition based on a deviation of the system behaviors from the baseline; and providing an output indicating the identified system behaviors or the anomalous condition. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12)
-
-
13. A system for detecting cyber physical system behavior, comprising:
-
a data collection component that receives encoded information from a plurality of sensors associated with the cyber physical system; a data assimilation component for decoding the encoded information by applying a manifold learning technique to the information to identify system features including at least one summary variable, wherein the data assimilation component applies a thermodynamic formalism to the at least one summary variable to obtain an indication of system behavior; and an operational component for receiving the indication of system behavior and for detecting an anomalous system behavior. - View Dependent Claims (14, 15, 16, 17, 18)
-
-
19. A computer implemented method of defining a model for detecting electrical power grid behavior, comprising:
-
utilizing one or more processors and associated memory storing one or more programs for execution by the one or more processors, the one or more programs including instructions for; accessing a data set comprising information regarding a characteristic of the electric power grid; metrizing a subset of the data set; processing the metrized subset of the data to provide at least one natural variable and at least one thermodynamic variable; and constructing a model for processing the information regarding a characteristic of the power grid based at least in part on the natural variable and the thermodynamic variable. - View Dependent Claims (20)
-
Specification