The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.
The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.
Patent No.:
Date of Patent:
Sep. 08, 2026
Filed:
Mar. 30, 2021
National Technology & Engineering Solutions of Sandia, Llc, Albuquerque, NM (US);
Shamina Hossain-Mckenzie, Albuquerque, NM (US);
Christian Birk Jones, Albuquerque, NM (US);
Adrian R. Chavez, Davis, CA (US);
Adam Summers, Albuquerque, NM (US);
Nicholas Jacobs, Saint Louis Park, MN (US);
Jay Tillay Johnson, Albuquerque, NM (US);
James Obert, Kuna, ID (US);
Brian J. Wright, Albuquerque, NM (US);
National Technology & Engineering Solutions of Sandia, LLC, Albuquerque, NM (US);
Abstract
A proactive intrusion detection and mitigation system (PIDMS) and method based upon both physical system data and cyber data is disclosed. The physical system data corresponds to one or more aspects of a device that can be measured. These aspects of the device may be controlled, either directly or indirectly, by cyber commands sent over a network. The cyber data corresponds not only to the cyber commands, but virtually any aspect of the cyber command. The PIDMS monitors both the physical system data and the cyber data for anomalies, including anomalies that can only be detected through the combination of physical system and cyber data, i.e., cyber-physical anomalies, as well as monitoring peer-to-peer communication between PIDMSs. These anomalies are detected using signature-based and behavioral-based approaches. Upon detecting an anomaly, the PIDMS undertakes preventative or mitigative action to counter the detected anomaly.