Search NASA⌕ Search

DOE OSTI · 2222234

Systems and methods for global cyber-attack or fault detection model

Abstract

An industrial asset may have monitoring nodes that generate current monitoring node values representing a current operation of the industrial asset. An abnormality detection computer may detect when a monitoring node is currently being attacked or experiencing a fault based on a current feature vector, calculated in accordance with current monitoring node values, and a detection model that includes a decision boundary. A model updater (e.g., a continuous learning model updater) may determine an update time-frame (e.g., short-term, mid-term, long-term, etc.) associated with the system based on trigger occurrence detection (e.g., associated with a time-based trigger, a performance-based trigger, an event-based trigger, etc.). The model updater may then update the detection model in accordance with the determined update time-frame (and, in some embodiments, continuous learning).

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Xu, Rui, Yan, Weizhong, Abbaszadeh, Masoud, Nielsen, Matthew Christian. 2023-08-29. Systems and methods for global cyber-attack or fault detection model. https://www.osti.gov/biblio/2222234

Cite the original work for its findings. Save a collection to share your selection of sources.