SYSTEM AND METHOD FOR DETERMINING ANOMALY SOURCE IN CYBER-PHYSICAL SYSTEM HAVING CERTAIN CHARACTERISTICS Russian patent published in 2020 - IPC G06F21/50 G06N20/00 

Abstract RU 2724075 C1

FIELD: computer equipment.

SUBSTANCE: invention relates to computer engineering. Disclosed is a computer-implemented method of teaching a prediction model of values of features of a cyber-physical system (CPS) and calculating an error threshold for determining anomalies in CPS, wherein: a) using the training apparatus, obtaining an initial sample containing the values of the CPS criteria for the historical period of observing the CPS, wherein the anomaly fraction does not exceed a given value, wherein the CPS characteristics are numerical characteristics of the control subjects; b) using a training apparatus based on the initial sample and taking into account the characteristics of the CPS, a training sample is formed, including values of at least one of the said CPS characteristics, for the observation period, which is contained in the historical observation period; c) using the training apparatus, constructing a model for predicting the values of the CPS attributes at each moment in the prediction window based on the values of said CPS attributes at each time point of the input window, wherein the input window and the prediction window are time intervals contained within the observation period, and, besides, said input window and prediction window are selected depending on the CPS characteristics, and the distance between the input window and the prediction window is equal to the prediction horizon, which is selected depending on the CPS characteristics; d) using the training apparatus, the prediction model is trained on the training sample data; e) using the trained prediction model using the calculation means, performing the CPS characteristics values prediction at each observation time instant; e) using the calculation means, determining the overall prediction error obtained using the constructed prediction model at each time point of the observation period; g) using the training apparatus, calculating a common error threshold depending on the CPS characteristics such that exceeding the calculated threshold with a common prediction error means an anomaly in the CPS.

EFFECT: technical result is providing training model prediction values of features of cyber-physical system (CPS) and calculation of error threshold to determine abnormality in CPS.

24 cl, 21 dwg

Similar patents RU2724075C1

Title Year Author Number
SYSTEM AND METHOD OF GENERATING DATA FOR MONITORING CYBER-PHYSICAL SYSTEM FOR PURPOSE OF EARLY DETECTION OF ANOMALIES IN GRAPHICAL USER INTERFACE 2018
  • Lavrentev Andrej Borisovich
  • Vorontsov Artem Mikhajlovich
  • Filonov Pavel Vladimirovich
  • Shalyga Dmitrij Konstantinovich
  • Shkulev Vyacheslav Igorevich
  • Demidov Nikolaj Nikolaevich
  • Ivanov Dmitrij Aleksandrovich
RU2724716C1
METHOD OF DETERMINING ANOMALY SOURCES IN A CYBER-PHYSICAL SYSTEM 2020
  • Lavrentev Andrej Borisovich
  • Vorontsov Artem Mikhajlovich
  • Filonov Pavel Vladimirovich
  • Shalyga Dmitrij Konstantinovich
  • Shkulev Vyacheslav Igorevich
  • Demidov Nikolaj Nikolaevich
  • Ivanov Dmitrij Aleksandrovich
RU2749252C1
METHOD FOR DIAGNOSING AND MONITORING ANOMALIES IN A CYBER-PHYSICAL SYSTEM 2021
  • Lavrentev Andrei Borisovich
  • Shkulev Viacheslav Igorevich
  • Travov Aleksandr Viktorovich
  • Vorontsov Artem Mikhailovich
  • Nechiporuk Artem Mikhailovich
  • Mamaev Maksim Aleksandrovich
  • Ivanov Dmitrii Aleksandrovich
  • Demidov Nikolai Nikolaevich
RU2784981C1
METHOD FOR DETERMINING AN ANOMALY IN A CYBER-PHYSICAL SYSTEM 2022
  • Lavrentev Andrei Borisovich
  • Mamaev Maksim Aleksandrovich
  • Vorontsov Artem Mikhailovich
  • Nechiporuk Artem Mikhailovich
  • Travov Aleksandr Viktorovich
  • Shkulev Viacheslav Igorevich
  • Ivanov Dmitrii Aleksandrovich
  • Demidov Nikolai Nikolaevich
RU2790331C1
SYSTEM AND METHOD FOR DETECTING ANOMALIES IN A CYBER-PHYSICAL SYSTEM 2022
  • Lavrentev Andrei Borisovich
  • Vorontsov Artem Mikhailovich
  • Nechiporuk Artem Mikhailovich
  • Shkulev Viacheslav Igorevich
  • Travov Aleksandr Viktorovich
  • Ivanov Dmitrii Aleksandrovich
  • Demidov Nikolai Nikolaevich
  • Mamaev Maksim Aleksandrovich
RU2800740C1
METHOD OF DETECTING ANOMALIES IN CYBER-PHYSICAL SYSTEM IN REAL TIME 2023
  • Mamaev Maksim Aleksandrovich
  • Travov Aleksandr Viktorovich
  • Lavrentev Andrei Borisovich
RU2824318C1
METHOD FOR ADAPTIVE CONTROL OF SYSTEM FOR ENSURING INFORMATION SECURITY OF CORPORATE COMMUNICATION NETWORK 2023
  • Dobryshin Mikhail Mikhailovich
  • Belov Andrei Sergeevich
  • Tsibulia Aleksei Nikolaevich
  • Anisimov Vladimir Georgievich
  • Gromov Iurii Iurevich
RU2823575C1
SYSTEM AND METHOD FOR PROTECTING USER DEVICES 2020
  • Shchetinin Evgenij Igorevich
  • Tikhomirov Anton Vladimirovich
RU2770146C2
METHOD OF REDUCING STREAM OF OBSERVATIONS OF PARAMETERS OF CYBERPHYSICAL SYSTEM COMING IN REAL TIME TO EQUAL-INTERVAL TIME GRID 2023
  • Mamaev Maksim Aleksandrovich
  • Travov Aleksandr Viktorovich
  • Lavrentev Andrei Borisovich
RU2825558C1
SYSTEM AND METHOD FOR DETERMINING PROCESS ASSOCIATED WITH MALWARE ENCRYPTING COMPUTER SYSTEM FILES 2020
  • Lopatin Evgenij Igorevich
  • Kondratev Dmitrij Andreevich
RU2770570C2

RU 2 724 075 C1

Authors

Lavrentev Andrej Borisovich

Vorontsov Artem Mikhajlovich

Filonov Pavel Vladimirovich

Shalyga Dmitrij Konstantinovich

Shkulev Vyacheslav Igorevich

Demidov Nikolaj Nikolaevich

Ivanov Dmitrij Aleksandrovich

Dates

2020-06-19Published

2018-12-28Filed