SYSTEM AND METHOD FOR DETERMINING ANOMALY SOURCE IN CYBER-PHYSICAL SYSTEM HAVING CERTAIN CHARACTERISTICS Russian patent published in 2020 - IPC G06F21/50 G06N20/00 

Abstract RU 2724075 C1

FIELD: computer equipment.

SUBSTANCE: invention relates to computer engineering. Disclosed is a computer-implemented method of teaching a prediction model of values of features of a cyber-physical system (CPS) and calculating an error threshold for determining anomalies in CPS, wherein: a) using the training apparatus, obtaining an initial sample containing the values of the CPS criteria for the historical period of observing the CPS, wherein the anomaly fraction does not exceed a given value, wherein the CPS characteristics are numerical characteristics of the control subjects; b) using a training apparatus based on the initial sample and taking into account the characteristics of the CPS, a training sample is formed, including values of at least one of the said CPS characteristics, for the observation period, which is contained in the historical observation period; c) using the training apparatus, constructing a model for predicting the values of the CPS attributes at each moment in the prediction window based on the values of said CPS attributes at each time point of the input window, wherein the input window and the prediction window are time intervals contained within the observation period, and, besides, said input window and prediction window are selected depending on the CPS characteristics, and the distance between the input window and the prediction window is equal to the prediction horizon, which is selected depending on the CPS characteristics; d) using the training apparatus, the prediction model is trained on the training sample data; e) using the trained prediction model using the calculation means, performing the CPS characteristics values prediction at each observation time instant; e) using the calculation means, determining the overall prediction error obtained using the constructed prediction model at each time point of the observation period; g) using the training apparatus, calculating a common error threshold depending on the CPS characteristics such that exceeding the calculated threshold with a common prediction error means an anomaly in the CPS.

EFFECT: technical result is providing training model prediction values of features of cyber-physical system (CPS) and calculation of error threshold to determine abnormality in CPS.

24 cl, 21 dwg

Similar patents RU2724075C1

Title Year Author Number
SYSTEM AND METHOD OF GENERATING DATA FOR MONITORING CYBER-PHYSICAL SYSTEM FOR PURPOSE OF EARLY DETECTION OF ANOMALIES IN GRAPHICAL USER INTERFACE 2018
  • Lavrentev Andrej Borisovich
  • Vorontsov Artem Mikhajlovich
  • Filonov Pavel Vladimirovich
  • Shalyga Dmitrij Konstantinovich
  • Shkulev Vyacheslav Igorevich
  • Demidov Nikolaj Nikolaevich
  • Ivanov Dmitrij Aleksandrovich
RU2724716C1
METHOD OF DETERMINING ANOMALY SOURCES IN A CYBER-PHYSICAL SYSTEM 2020
  • Lavrentev Andrej Borisovich
  • Vorontsov Artem Mikhajlovich
  • Filonov Pavel Vladimirovich
  • Shalyga Dmitrij Konstantinovich
  • Shkulev Vyacheslav Igorevich
  • Demidov Nikolaj Nikolaevich
  • Ivanov Dmitrij Aleksandrovich
RU2749252C1
METHOD FOR DIAGNOSING AND MONITORING ANOMALIES IN A CYBER-PHYSICAL SYSTEM 2021
  • Lavrentev Andrei Borisovich
  • Shkulev Viacheslav Igorevich
  • Travov Aleksandr Viktorovich
  • Vorontsov Artem Mikhailovich
  • Nechiporuk Artem Mikhailovich
  • Mamaev Maksim Aleksandrovich
  • Ivanov Dmitrii Aleksandrovich
  • Demidov Nikolai Nikolaevich
RU2784981C1
METHOD FOR DETERMINING AN ANOMALY IN A CYBER-PHYSICAL SYSTEM 2022
  • Lavrentev Andrei Borisovich
  • Mamaev Maksim Aleksandrovich
  • Vorontsov Artem Mikhailovich
  • Nechiporuk Artem Mikhailovich
  • Travov Aleksandr Viktorovich
  • Shkulev Viacheslav Igorevich
  • Ivanov Dmitrii Aleksandrovich
  • Demidov Nikolai Nikolaevich
RU2790331C1
SYSTEM AND METHOD FOR DETECTING ANOMALIES IN A CYBER-PHYSICAL SYSTEM 2022
  • Lavrentev Andrei Borisovich
  • Vorontsov Artem Mikhailovich
  • Nechiporuk Artem Mikhailovich
  • Shkulev Viacheslav Igorevich
  • Travov Aleksandr Viktorovich
  • Ivanov Dmitrii Aleksandrovich
  • Demidov Nikolai Nikolaevich
  • Mamaev Maksim Aleksandrovich
RU2800740C1
SYSTEM AND METHOD FOR PROTECTING USER DEVICES 2020
  • Shchetinin Evgenij Igorevich
  • Tikhomirov Anton Vladimirovich
RU2770146C2
SYSTEM AND METHOD FOR DETERMINING PROCESS ASSOCIATED WITH MALWARE ENCRYPTING COMPUTER SYSTEM FILES 2020
  • Lopatin Evgenij Igorevich
  • Kondratev Dmitrij Andreevich
RU2770570C2
SYSTEM AND METHOD FOR REVEALING THE STRUCTURE OF PATTERNS AND ANOMALIES IN THE STREAM OF EVENTS COMING FROM A CYBER-PHYSICAL SYSTEM OR AN INFORMATION SYSTEM 2022
  • Lavrentev Andrei Borisovich
  • Ivanov Dmitrii Aleksandrovich
  • Travov Aleksandr Viktorovich
  • Mamaev Maksim Aleksandrovich
  • Shkulev Viacheslav Igorevich
  • Demidov Nikolai Nikolaevich
RU2793549C1
SYSTEM AND METHOD OF CORRELATING EVENTS FOR DETECTING INFORMATION SECURITY INCIDENT 2019
  • Lyukshin Ivan Stanislavovich
  • Kiryukhin Andrej Aleksandrovich
  • Lukiyan Dmitrij Sergeevich
  • Filonov Pavel Vladimirovich
RU2739864C1
METHOD AND COMPUTER SYSTEM FOR CONTROL OF DRILLING OF THE WELLS 2019
  • Antipova Kseniya Aleksandrovna
  • Koroteev Dmitrij Anatolevich
  • Klyuchnikov Nikita Andreevich
RU2723805C1

RU 2 724 075 C1

Authors

Lavrentev Andrej Borisovich

Vorontsov Artem Mikhajlovich

Filonov Pavel Vladimirovich

Shalyga Dmitrij Konstantinovich

Shkulev Vyacheslav Igorevich

Demidov Nikolaj Nikolaevich

Ivanov Dmitrij Aleksandrovich

Dates

2020-06-19Published

2018-12-28Filed