Network security risk assessment method for unmanned aerial vehicle system
An AI-driven network security assessment method for UAVs addresses vulnerabilities and attacks by implementing real-time threat detection and dynamic defense strategies, enhancing flight stability and security.
Patent Information
- Application Number
- CN202510750183.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-15
AI Technical Summary
The existing technology cannot conduct systematic network security assessments on drone systems, resulting in security vulnerabilities not being discovered in time, frequent attacks occur, system reliability declines, and existing methods are difficult to achieve real-time monitoring and dynamic adjustment risk assessment.
AI algorithms are used for real-time analysis, combined with dynamic evaluation and automated defense strategies, and through static code analysis, threat intelligence collection, AI real-time analysis and dynamic defense strategy adjustment, a closed-loop system is built to realize real-time risk assessment and dynamic defense of the drone system.
Effectively respond to the threat environment of rapidly changing drone systems during flight, improve system security and reliability, reduce attack possibilities, and ensure the continuity and stability of drone missions.
Smart Images

Figure CN120321656A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of UAV network security, and particularly relates to a network security risk assessment method for UAV systems. Background Art
[0002] In 2024, State Grid Aksu Power Supply Company had a total of 44 UAVs, mainly used for power transmission line inspection work. However, the current network security assessment methods owned by the company cannot systematically evaluate UAVs. In the actual application of UAV systems, the lack of a network security risk assessment method has led to the following problems:
[0003] 1. Security vulnerabilities are not discovered in time: Due to the lack of a systematic network security assessment method, potential security vulnerabilities in UAV systems (such as communication protocol vulnerabilities, data tampering risks, malware intrusion, etc.) cannot be discovered and repaired in time, increasing the risk of system attacks.
[0004] 2. Frequent attack incidents: The wide application of UAV systems in the power field makes them high-value targets for cyberattacks. Due to the lack of effective risk assessment, attackers can use system weaknesses to carry out malicious behaviors such as data theft and system control right seizure, resulting in serious security incidents. In actual penetration, it is found that breaking into the UAV system website will control all UAVs, leak inspection videos, tasks, and sensitive data, leading to serious consequences.
[0005] 3. System reliability decreases: Network security problems may cause the UAV system to operate unstably, such as being interfered with and having connection interruptions during the inspection process, affecting its reliability and security in actual applications.
[0006] In response to the above problems, the network security risk assessment methods in the prior art have poor real-time performance. UAV systems may face different security threats at any time during flight. Existing methods usually rely on offline analysis and are difficult to achieve real-time monitoring and dynamic adjustment of risk assessment results:
[0007] In summary, in view of the current situation of UAV use in our Aksu Power Supply Company, we have proposed "a network security risk assessment method for UAV systems" to ensure effective risk assessment in a rapidly changing threat environment during UAV flight and meet the on-site use requirements. Summary of the Invention
[0008] The present invention aims at the technical deficiencies of the prior art and provides a network security risk assessment method for an unmanned aerial vehicle (UAV) system. By using real-time analysis of AI algorithms, combined with dynamic assessment and automated defense strategies, it can perform real-time monitoring and dynamically adjust the risk assessment results to ensure effective risk assessment in a rapidly changing threat environment during UAV flight and meet the usage requirements.
[0009] The present invention provides the following technical solutions: A network security risk assessment method for an unmanned aerial vehicle system, comprising the following steps:
[0010] Step 1, using a static code analysis tool to scan the source code of the security-critical components of the UAV system to identify all potential attack points;
[0011] Step 2, collecting the system status, network data, and sensor information of the UAV, obtaining threat intelligence, and using an AI algorithm to analyze the data in real time to identify abnormal behaviors;
[0012] Step 3, quantifying the security threats of the current abnormal behaviors and evaluating the attack possibility and potential impact;
[0013] Step 4, dynamically adjusting the defense strategy according to the risk assessment results;
[0014] Step 5, recording all security events and response situations to form an attack traceability analysis, and regularly updating the AI model to enhance the recognition ability of new attacks.
[0015] Further,
[0016] In the said Step 1, the security-critical components include UAV hardware components, software systems, and network connection points. The UAV hardware components include a flight control system, a navigation module, a communication module, sensors, and a battery. The software system includes an operating system, a flight control algorithm, a wireless communication protocol, and mission software. The network connection point is any one of 5G / 4G, WiFi, Bluetooth, satellite communication, and RF signals;
[0017] The attack points include network attacks, communication attacks, physical attacks, and software attacks;
[0018] When the static code analysis tool scans the source code of the security-critical components, by analyzing the data flow, checking the declaration, assignment, and usage of variables in the program, potential vulnerabilities are identified. The vulnerabilities are marked as potential attack points and a report is generated according to the identified problems, including the description of the problem, the code location, and repair suggestions.
[0019] Further,
[0020] In step 2, the network data includes communication data, communication protocols, and encryption status, and the sensor information includes GPS, inertial measurement unit (IMU), and battery status.
[0021] The system status of the UAV includes flight attitude and navigation information data, which is collected through the communication interface of the flight control system. The ground control software Mission Planner of the UAV is connected to the communication interface to collect real-time flight control data in real time.
[0022] Use the Wireshark network protocol analysis tool to collect the network data between the UAV and the UAV control system, identify potential network attacks, and use the Sniffer tool to collect and analyze the communication protocols and encryption status in the network data.
[0023] Furthermore,
[0024] The AI analysis and identification steps in step 2 are as follows:
[0025] S1: Perform preprocessing on the collected data information, including cleaning, denoising, standardization, and dimensionality reduction.
[0026] S2: Extract key features from the data preprocessed in step S1, set the normal range threshold, and mark as abnormal if it exceeds the threshold.
[0027] S3: Train and evaluate the AI model using the key features extracted in step S2.
[0028] S3-1: Divide the key feature data extracted in step S2 into a training set and a test set, with 80% for the training set and 20% for the test set.
[0029] S3-2: Input the training set data into the AI model, perform forward propagation through the neural network, and calculate the predicted output value of the model. The expression used is:
[0030] ,
[0031] ,
[0032] ,
[0033] ,
[0034] where x is the input data, is the weight matrix from the input layer to the hidden layer, is the bias term,
[0035]
[0036] is the result of the linear transformation, and f is the activation function. is the output of the hidden layer. The final predicted value;
[0037] S3-3: Calculate the error between the predicted output and the true label using the loss function. The expression used is: L = -[y log(y^) + (1 - y) log(1 - y^)], where y ∈ {0, 1} is the true
[0038] label, and y^ ∈ (0, 1) is the predicted value;
[0039] S3-4: Calculate the gradients of the weights and biases through the output of the loss function. The expression for the gradient of the weights is: ;
[0040] The formula for the gradient of the bias is: ;
[0041] where z = w x + b, y^ = f(z), L = Loss(y, y^), f(z) is the derivative of the activation function, z is the weighted input, x is the input feature vector, w is the weight parameter, and b is the bias parameter;
[0042] S3-5: The gradient descent optimization algorithm updates the parameters of the network according to the gradient. The expression used is: ;
[0043] ; where is the learning rate, which controls the step size of each update, is the partial derivative of the loss function with respect to the weight (i.e., the gradient), and l is the loss function;
[0044] S3-6: Repeat the steps of S3-2 to S3-5 until the model reaches the predetermined number of training epochs;
[0045] S3-7: Input the input data x in the test set into the model trained and evaluated in step S3-6 to generate the corresponding predicted value y^;
[0046] S3-8: Calculate the evaluation metrics based on the predicted result y^ and the true label y, and determine whether the AI model has been trained well according to the evaluation metrics. If not, repeat steps S3-1 to S3-6;
[0047] S4: Input the real-time data of the drone into the AI model trained and evaluated in S3, and use the unsupervised learning method to detect outliers and output the abnormal data. The expression used is:
[0048] ;
[0049] Where h(x) is the average path length of the data point x, T is the number of decision trees, and if h(x) is much smaller than that of normal data, then x may be an outlier;
[0050] S5: Match the abnormal data with the known attack paths and the behavioral characteristics of the attacker, use the association rule learning method to find the relevance between behaviors, determine the nature of the abnormal behavior, and judge the attack type;
[0051] S6: Judge whether the attack is persistent or sudden. If the abnormal behavior continuously appears in the past N time windows, it may be a persistent attack, and the expression used is: ;
[0052] Where represents the moving average calculated at time point t, N represents the size of the moving window, represents the data value at time point i, t represents the current moment, that is, the current time point of the moving window, and t−N + 1 represents the Nth time point before the current moment, which is used to define the starting position of the window.
[0053] Furthermore,
[0054] The evaluation metrics in S3 - 8 include accuracy, precision, and recall, and their expressions are respectively:
[0055] , where TP is true positive, TN is true negative, FP is false positive, FN is false negative, and the closer the accuracy is to 1, the higher the accuracy;
[0056] , the higher the precision, the better, and the ideal value is 1;
[0057] , the higher the recall, the better, and the ideal value is 1.
[0058] Furthermore,
[0059] Step 3 includes the following steps:
[0060] Step 3 - 1: Use the binomial distribution to evaluate the probability of abnormal behavior being transformed into an attack event;
[0061] The expression is: ;
[0062] Where P(X = k) is the probability of exactly k successes occurring in n experiments, is the combination number, representing the number of ways to choose k successes from n experiments;
[0063] Step 3-2: Based on the attack type determined in Step S5 and the attack probability calculated in Step 3-1, construct a risk matrix to evaluate the attack possibility, and classify abnormal behaviors into different levels according to the attack probability and impact degree.
[0064] Step 3-3: Evaluate the possible impacts on the UAV system, operators, and the enterprise according to the attack type and behavior.
[0065] Step 3-4: Combine the attack probability and potential impact, and use a weighted average model to calculate the final security risk score. The expression used is: Risk Score = Likelihood × Impact Severity, where Likelihood is the probability of the attack event calculated according to S301, and Impact Severity is a quantified value evaluated according to the magnitude of the potential impact.
[0066] , where is the weight of each impact category, is the quantified value of each impact category.
[0067] Furthermore,
[0068] In the above-mentioned Step 3-1, The calculation expression of the combination number is:
[0069] ;
[0070] where n is the total number of experiments, representing the number of samples evaluated or the number of detections performed over a period of time, k is the number of successes, representing the number of abnormal behaviors transformed into attack events, and p is the probability of an attack occurring in a single experiment.
[0071] Furthermore,
[0072] The above-mentioned Step 4 includes the following steps:
[0073] Step 4-1: Understand the current security state of the UAV system, and determine whether it is necessary to adjust the defense strategy. If the threat is low, choose to maintain the existing strategy or make minor adjustments. If there are high-risk threats, they need to be addressed first.
[0074] Step 4-2: Set defense goals according to the identified high-risk attack types. The defense goals include: improving the recognition ability for specific attacks, enhancing the protection of key data and control signals, and accelerating the response time to attack events.
[0075] Step 4-3: Strengthen the detection of high-risk attacks. For network attacks, enhance intrusion detection systems and traffic analysis. For malware attacks, increase virus scanning and sandbox technologies. For attacks on control systems, enhance encryption and access control mechanisms, increase the depth of defense, strengthen the authentication mechanism for critical system components to prevent unauthorized access, isolate different modules in the network to avoid the spread of attacks, and strengthen data encryption for communication between systems to prevent man-in-the-middle attacks;
[0076] Step 4-4: After the policy adjustment, continuously monitor the system status and threat intelligence, automatically update the rules according to the new threat patterns, and automatically adjust the defense measures through the AI model.
[0077] Furthermore,
[0078] In step 4-4, the AI model uses a reinforcement learning model to learn. By trying different defense strategies and obtaining feedback, it automatically adjusts and updates according to the feedback;
[0079] The expression used in its reinforcement learning model is:
[0080] Q(s,a)=Q(s,a)+α[r+γa′maxQ(s′,a′)−Q(s,a)];
[0081] Where Q(s,a) is the expected return of executing action a in state S, α is the learning rate, which determines the step size of learning and updating, r is the immediate reward, γ is the discount factor, used to evaluate the long-term return, and a is the action that may be taken subsequently.
[0082] Furthermore,
[0083] In step 5, a dependency graph is used to construct the attack path and analyze the possible action routes of the attacker. The expression used is: G=(V,E), where V represents system components and E represents the dependency relationships or data flows between components;
[0084] A sliding window is used to detect and analyze the occurrence time of attack events and identify the attack chain pattern. The expression used is: , where P(A∣B) represents the probability that attack A occurs after event B occurs, and P(B∣A) represents the probability that event B is caused by attack A. By using historical attack data, calculate the probability distribution of different attack chains to predict the next attack.
[0085] Compared with the prior art, the beneficial effects of the present invention are:
[0086] This evaluation method constructs a closed-loop system covering "attack surface discovery - threat identification - risk assessment - strategy adjustment - model evolution" through a four-layer architecture of static code analysis, real-time threat perception, dynamic risk quantification, and automated defense. Its core advantage lies in the deep integration of AI-driven real-time analysis capabilities and dynamic defense strategies, enabling effective response to the rapidly changing threat environment faced by the UAV system during flight, such as GPS spoofing, communication link hijacking, sensor data tampering, etc., meeting the high real-time and high-reliability security requirements, while ensuring the continuity of UAV missions and significantly reducing security risks;
[0087] 1. Improve the security of UAV system inspections: Through systematic risk assessment and vulnerability repair, the overall security of the UAV system is significantly improved, reducing the likelihood of being attacked;
[0088] 2. Enhance the reliability of the UAV system: Solving network security problems makes the UAV system operate more stably, reducing failures and accidents caused by security issues, and effectively improving the stability of the UAV during power transmission inspection operations. Brief Description of the Drawings
[0089] Figure 1 It is a flowchart of a network security risk assessment method for UAV systems proposed by the present invention. Detailed Implementation Modes
[0090] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0091] As Figure 1 shown, it shows the detailed implementation mode of the present invention:
[0092] A network security risk assessment method for UAV systems, which forms a complete set of UAV network security risk assessment and response systems through links such as static code analysis, threat intelligence collection, AI real-time analysis, dynamic assessment, and automated defense strategy adjustment.
[0093] A network security risk assessment method for UAV systems disclosed by the present invention includes the following steps:
[0094] Step 1, use a static code analysis tool to scan the source code of the security-critical components of the UAV system to identify all potential attack points;
[0095] Step 2, collect the system status, network data, and sensor information of the UAV to obtain threat intelligence, and use AI algorithms to analyze the data in real time to identify abnormal behaviors;
[0096] Step 3, quantify the security threats of the current abnormal behavior, and evaluate the attack possibility and potential impact;
[0097] Step 4, dynamically adjust the defense strategy according to the risk assessment results;
[0098] Step 5, record all security events and response situations, form an attack traceability analysis, regularly update the AI model, and enhance the recognition ability of new attacks.
[0099] Furthermore,
[0100] In the said Step 1, the security critical components include the UAV hardware components, software systems, and network connection points. The UAV hardware components include a flight control system, a navigation module, a communication module, sensors, and a battery. The software systems include an operating system, flight control algorithms, wireless communication protocols, and mission software. The network connection point is any one of 5G / 4G, WiFi, Bluetooth, satellite communication, and RF signals;
[0101] The attack points include network attacks, communication attacks, physical attacks, and software attacks;
[0102] When the static code analysis tool scans the source code of the security critical components, by analyzing the data flow, it checks the declaration, assignment, and usage of variables in the program, identifies potential vulnerabilities. The vulnerabilities are marked as potential attack points and a report is generated according to the identified problems, including the description of the problem, the code location, and repair suggestions.
[0103] Through static code analysis, software vulnerabilities in the UAV security critical components can be systematically identified, and a defense-in-depth system can be constructed in combination with hardware / network protection measures (such as encrypted communication, secure boot).
[0104] Furthermore,
[0105] In the said Step 2, the network data includes communication data, communication protocols, and encryption status, and the sensor information includes GPS, inertial measurement unit IMU, and battery status;
[0106] The system status of the UAV includes flight attitude and navigation information data, which is collected through the communication interface of the flight control system. The ground control software Mission Planner of the UAV is connected to the communication interface to collect real-time flight control data in real time;
[0107] Use the Wireshark network protocol analysis tool to collect the network data between the UAV and the UAV control system, identify potential network attacks, and use the Sniffer tool to collect and analyze the communication protocols and encryption status in the network data.
[0108] By monitoring network data, sensor information, and system status in real time and combining in-depth analysis with Wireshark / Sniffer tools, attack behaviors in the UAV communication link can be effectively detected.
[0109] Furthermore,
[0110] The AI analysis and recognition steps in Step 2 are as follows:
[0111] S1. Preprocess the collected data information by cleaning, denoising, normalizing, and dimensionality reduction;
[0112] S2. Extract key features from the preprocessed data in Step S1, set the normal range threshold, and mark as abnormal if it exceeds the threshold;
[0113] S3. Train and evaluate the AI model using the key features extracted in Step S2;
[0114] S3-1: Divide the key feature data extracted in Step S2 into a training set and a test set, with 80% for the training set and 20% for the test set;
[0115] S3-2: Input the training set data into the AI model, perform forward propagation through the neural network, and calculate the predicted output value of the model. The expression used is:
[0116] ,
[0117] ,
[0118] ,
[0119] ,
[0120] where x is the input data, is the weight matrix from the input layer to the hidden layer, is the bias term,
[0121] is the result of the linear transformation, f is the activation function, is the output of the hidden layer, the final predicted value;
[0122] S3-3: Calculate the error between the predicted output and the true label using the loss function. The expression used is: L = −[y log(y^)+(1−y) log(1−y^)], where y ∈ {0,1} is the true
[0123] label, and y^ ∈ (0,1) is the predicted value;
[0124] S3-4: Calculate the gradients of the weights and biases through the output of the loss function. The expression used for the gradient of the weights is: ;
[0125] The formula used for the gradient of the bias is: ;
[0126] where z = w x + b, ŷ = f(z), L = Loss(y, ŷ), f(z) is the derivative of the activation function, z is the weighted input, x is the input feature vector, w is the weight parameter, and b is the bias parameter;
[0127] S3-5: The gradient descent optimization algorithm updates the parameters of the network according to the gradient. The expression it uses is: ;
[0128] ; where is the learning rate, which controls the step size of each update, is the partial derivative of the loss function with respect to the weights (i.e., the gradient), and l is the loss function;
[0129] S3-6: Repeat the steps of S3-2 to S3-5 until the model reaches the predetermined number of training epochs;
[0130] S3-7, Input the input data x in the test set into the model trained in S3-6 to generate the corresponding predicted value ŷ;
[0131] S3-8, Calculate the evaluation metrics based on the predicted result ŷ and the true label y. Determine whether the AI model has been trained well according to the evaluation metrics. If it has not been trained well, repeat the steps of S3-1 to S3-6;
[0132] S4, Input the real-time data of the drone into the AI model trained and evaluated in S3, use the unsupervised learning method to detect the outliers, and output the abnormal data. The expression it uses is:
[0133] ;
[0134] where h(x) is the average path length of the data point x, T is the number of decision trees. If h(x) is much smaller than the normal data, then x may be an outlier;
[0135] S5: Match the abnormal data with the known attack paths and the behavioral characteristics of the attacker, use the association rule learning method to find the correlations between behaviors, determine the nature of the abnormal behavior, and judge the attack type;
[0136] S6: Determine whether the attack is continuous or sudden. If the abnormal behavior continuously appears in the past N time windows, it may be a continuous attack. The expression used is: ;
[0137] where represents the moving average calculated at time point t, N represents the size of the moving window, represents the data value at time point i, t represents the current moment, that is, the current time point of the moving window, and t−N + 1 represents the Nth time point before the current moment, which is used to define the starting position of the window.
[0138] Through the above process, the AI model can achieve a full-link analysis of the UAV system from data preprocessing to attack type recognition.
[0139] Furthermore,
[0140] The evaluation metrics in S3-8 include accuracy, precision, and recall. Their expressions are respectively:
[0141] where TP is true positive, TN is true negative, FP is false positive, and FN is false negative. The closer the accuracy is to 1, the higher the accuracy;
[0142] , the higher the precision, the better, and the ideal value is 1;
[0143] , the higher the recall, the better, and the ideal value is 1.
[0144] In the evaluation, the closer the accuracy is to 1, the higher the accuracy. If the precision is low, it means that the model has more false positive examples, which may lead to unnecessary misjudgments; a low recall indicates that the model misses many positive class samples.
[0145] Furthermore,
[0146] Step 3 includes the following steps:
[0147] Step 3-1: Use the binomial distribution to evaluate the probability of abnormal behavior transforming into an attack event;
[0148] The expression is: ;
[0149] where P(X = k) is the probability of exactly k successes occurring in n experiments, is the combination number, representing the number of ways to choose k successes from n experiments;
[0150] Step 3-2: Based on the attack type determined in Step S5 and the attack probability calculated in Step 3-1, construct a risk matrix to evaluate the attack possibility, and classify the abnormal behaviors into different levels according to the attack probability and impact degree.
[0151] Step 3-3: Evaluate the possible impacts on the UAV system, operators, and the enterprise according to the attack type and behavior.
[0152] Step 3-4: Combine the attack probability and potential impact, and use a weighted average model to calculate the final security risk score. The expression used is: Risk Score = Likelihood × Impact Severity, where Likelihood is the probability of the attack event calculated according to S301, and Impact Severity is the quantified value evaluated according to the size of the potential impact.
[0153] , where is the weight of each impact category, is the quantified value of each impact category.
[0154] Both its weight and the quantified value of each impact category are reasonably evaluated based on the domain experts' experience and knowledge of the system and attack methods; the judgment criteria for the quantified value of each impact category are: 1-3 points represent low impact (small range or negligible impact), 4-6 points represent medium impact (certain degree of loss or threat, and measures may need to be taken), and 7-10 points represent high impact (major loss or harm, which needs to be prioritized).
[0155] Suppose we analyze the impact of a certain attack event, and its impact is divided into the following categories:
[0156] System damage: Seriously damage the flight control system of the UAV, with a weight of 0.4 and a quantification of 7 points (high impact);
[0157] Data leakage: Leakage of UAV sensor data, with a weight of 0.3 and a quantification of 6 points (medium impact);
[0158] Financial loss: The enterprise needs to pay repair costs and compensate customers, with a weight of 0.2 and a quantification of 8 points (high impact);
[0159] Personal safety: No personnel are injured, with a weight of 0.1 and a quantification of 2 points (low impact);
[0160] Impact Severity = (0.4×7) + (0.3×6) + (0.2×8) + (0.1×2) = 6.2. Therefore, the Impact Severity of the attack event is 6.2, indicating a medium-high level of impact.
[0161] Its risk matrix is shown in Table 1:
[0162] Table 1:
[0163]
[0164] Furthermore,
[0165] In step 3-1, The calculation expression for the combination number is:
[0166] ;
[0167] where n is the total number of experiments, representing the number of samples evaluated or the number of detections conducted over a period of time, k is the number of successes, representing the number of abnormal behaviors transformed into attack events, and p is the probability of an attack occurring in a single experiment.
[0168] Furthermore,
[0169] Step 4 includes the following steps:
[0170] Step 4-1: Understand the current security status of the UAV system, determine whether it is necessary to adjust the defense strategy. If the threat is low, choose to maintain the existing strategy or make minor adjustments. If there are high-risk threats, they need to be addressed first;
[0171] Step 4-2: Set defense goals based on the identified high-risk attack types. The defense goals include: improving the recognition ability for specific attacks, enhancing the protection of critical data and control signals, and accelerating the response time to attack events;
[0172] Step 4-3: Strengthen the detection of high-risk attacks. For network attacks, enhance the intrusion detection system and traffic analysis. For malware attacks, increase virus scanning and sandbox technology. For attacks on the control system, enhance encryption and access control mechanisms, increase the depth of defense, strengthen the authentication mechanism for critical components of the system to prevent unauthorized access, isolate different modules in the network to avoid the spread of attacks, and strengthen the data encryption of inter-system communication to prevent man-in-the-middle attacks;
[0173] Step 4-4: After the strategy is adjusted, continuously monitor the system status and threat intelligence, automatically update the rules according to the new threat patterns, and automatically adjust the defense measures through the AI model.
[0174] Through the above process, the drone system can be upgraded from passive defense to active adaptation.
[0175] Furthermore,
[0176] In step 4-4, the AI model uses a reinforcement learning model to learn. By trying different defense strategies and obtaining feedback, it automatically adjusts and updates according to the feedback.
[0177] The expression used by its reinforcement learning model is:
[0178] Q(s,a)=Q(s,a)+α[r+γa′maxQ(s′,a′)−Q(s,a)];
[0179] Where Q(s,a) is the expected return of executing action a in state S, α is the learning rate, which determines the step size of learning and updating, r is the immediate reward, γ is the discount factor, used to evaluate the long-term return, and a is the action that may be taken subsequently.
[0180] Introducing a reinforcement learning (RL) model in the drone security defense scenario, and optimizing the defense strategy through dynamic trial and error and feedback can significantly improve the autonomy of the system in dealing with unknown threats.
[0181] Through the Q-Learning reinforcement learning model, the drone security defense system can achieve the following advantages:
[0182] 1. Autonomous adaptation: It can cope with unknown threats (such as new GPS spoofing variants) without manual intervention;
[0183] 2. Long-term optimization: Balance immediate defense and system sustainability through the discount factor;
[0184] 3. Dynamic balance: Automatically find the optimal solution between security requirements and system performance (such as sacrificing some performance for security when under high threats).
[0185] Furthermore,
[0186] In step 5, a dependency graph is used to construct the attack path and analyze the possible action routes of the attacker. The expression it uses is: G=(V,E), where V represents the system components and E represents the dependency relationship or data flow between the components;
[0187] A sliding window is used to detect and analyze the occurrence time of attack events and identify the attack chain pattern. The expression it uses is: , where P(A∣B) represents the probability that attack A occurs after event B occurs, P(B∣A) represents the probability that event B is caused by attack A, and the probability distribution of different attack chains is calculated through historical attack data to predict the next attack.
[0188] Through dependency graph and sliding window probability analysis, the UAV security defense system can achieve the following:
[0189] Visualization of attack paths: Identify potential breakthrough points of attackers (such as GPS components);
[0190] Prediction of threat evolution: Based on historical data and real-time events, anticipate the next attack in advance (such as communication hijacking);
[0191] Precise defense response: Dynamically adjust defense strategies for high-probability attack chains (such as enabling dual-mode positioning).
[0192] The practical application of this method in the power grid solves the problem of the lack of power grid network security risk assessment methods from four major aspects: system modeling and threat identification, vulnerability scanning and risk assessment, attack simulation and penetration testing, and continuous assessment and improvement. It solves the problems of existing security vulnerabilities not being discovered in time, frequent attack incidents, and decreased system reliability, and produces the following beneficial effects:
[0193] 1. System modeling and threat identification: Conduct comprehensive modeling of the hardware, software, communication protocols, etc. of the UAV system to identify potential attack surfaces, and can analyze the network security situation in real time during UAV power transmission line inspections. Use threat modeling tools to analyze possible attack paths and threat scenarios, and can effectively block them.
[0194] 2. Vulnerability scanning and risk assessment: Use automated tools to scan for vulnerabilities in the firmware, communication protocols, UAV clusters, etc. of the UAV system. Combine qualitative and quantitative methods (such as CVSS scores, risk matrices) to evaluate the severity and impact scope of vulnerabilities.
[0195] 3. Attack simulation and penetration testing: Simulate network attacks against the UAV system (such as GPS spoofing, data injection, DoS attacks, etc.) in a controlled environment to verify the system's anti-attack ability. Discover actual security weaknesses through penetration testing.
[0196] 4. Continuous assessment and improvement: Establish a continuous assessment mechanism to regularly conduct network security risk assessments on the UAV system to ensure that its security is dynamically adjusted with changes in the threat environment. Continuously optimize security policies and measures through a feedback mechanism.
[0197] Beneficial effects after application:
[0198] 1. Improve the security of UAV system inspections: Through systematic risk assessment and vulnerability repair, the overall security of the UAV system is significantly improved, reducing the possibility of being attacked.
[0199] 2. Improve the reliability of the UAV system: Solving network security problems makes the UAV system operate more stably, reduces failures and accidents caused by security problems, and effectively improves the stability of UAVs in power transmission inspection operations.
[0200] 3. Reduce economic losses: By preventing and responding to network security threats, the company has avoided economic losses caused by attack incidents.
[0201] 4. Promote technological innovation: The introduction of network security risk assessment methods has promoted innovation in the security technology of UAV systems, providing new impetus for the development of the power industry.
[0202] The preferred embodiments of the present invention have been described in detail above in conjunction with the accompanying drawings. However, the present invention is not limited to the above embodiments. Within the scope of knowledge possessed by those of ordinary skill in the art, various changes can be made without departing from the gist of the present invention. These changes involve related technologies well-known to those skilled in the art, and all of these fall within the protection scope of the patent of the present invention.
[0203] Many other changes and modifications can be made without departing from the concept and scope of the present invention. It should be understood that the present invention is not limited to specific embodiments, and the scope of the present invention is defined by the appended claims.
Claims
1. A network security risk assessment method for a drone system, characterized in that It includes the following steps: Step 1: Use a static code analysis tool to scan the source code of the safety-critical components of the UAV system to identify all potential attack points; Step 2: Collect the system status, network data, and sensor information of the UAV, obtain threat intelligence, and use an AI algorithm to analyze the data in real time to identify abnormal behaviors; Step 3: Quantify the security threats of the current abnormal behaviors and evaluate the attack possibility and potential impact; Step 4: Dynamically adjust the defense strategy according to the risk assessment results; Step 5: Record all security events and response situations to form an attack traceability analysis, regularly update the AI model, and enhance the recognition ability of new attacks.
2. The network security risk assessment method for a drone system according to claim 1, wherein In the said Step 1, the safety-critical components include UAV hardware components, software systems, and network connection points. The UAV hardware components include a flight control system, a navigation module, a communication module, sensors, and a battery. The software system includes an operating system, a flight control algorithm, a wireless communication protocol, and mission software. The network connection point is any one of 5G / 4G, WiFi, Bluetooth, satellite communication, and RF signals; The attack points include network attacks, communication attacks, physical attacks, and software attacks; When the static code analysis tool scans the source code of the safety-critical components, it analyzes the data flow, checks the declaration, assignment, and usage of variables in the program, identifies potential vulnerabilities, marks the vulnerabilities as potential attack points, and generates a report according to the identified problems, including the description of the problem, the code location, and repair suggestions.
3. The network security risk assessment method for a drone system according to claim 2, wherein In the said Step 2, the network data includes communication data, communication protocols, and encryption status. The sensor information includes GPS, inertial measurement unit (IMU), and battery status; The system status of the UAV includes flight attitude and navigation information data, which is collected through the communication interface of the flight control system. The ground control software Mission Planner of the UAV is connected to the communication interface to collect real-time flight control data in real time; Use the Wireshark network protocol analysis tool to collect the network data between the UAV and the UAV control system to identify potential network attacks, and use the Sniffer tool to collect and analyze the communication protocols and encryption status in the network data.
4. A network security risk assessment method for a drone system according to claims 1-3, characterized in that, The AI analysis and identification steps in the said Step 2 are as follows: S1: Perform preprocessing such as cleaning, denoising, standardization, and dimensionality reduction on the collected data information; S2: Extract key features from the data preprocessed in the said Step S1, set the normal range threshold, and mark it as abnormal if it exceeds the threshold; S3: Train and evaluate the AI model through the key features extracted in the said Step S2; S3-1: Divide the key feature data extracted in the said Step S2 into a training set and a test set, with 80% for the training set and 20% for the test set; S3-2: Input the training set data into the AI model, perform forward propagation through the neural network, and calculate the predicted output value of the model. The expression used is: , , , , where x is the input data, is the weight matrix from the input layer to the hidden layer, is the bias term, is the result of the linear transformation, f is the activation function, is the output of the hidden layer, the final predicted value; S3-3: Calculate the error between the predicted output and the true label using a loss function, and the expression used is: L = -[y log(y^) + (1 - y) log(1 - y^)], where y ∈ {0, 1} is the true Label, y^∈(0,1) is the predicted value; S3-4: Calculate the gradients of the weights and biases based on the output of the loss function. The expression for the gradient of the weights is: ; The formula for using the gradient of the deviation is: ; where z = w x + b, ŷ = f(z), L = Loss(y, ŷ), f(z) is the derivative of the activation function, z is the weighted input, x is the input feature vector, w is the weight parameter, and b is the bias parameter; S3-5: The gradient descent optimization algorithm updates the parameters of the network according to the gradient, and the expression it uses is: ; ; where is the learning rate, which controls the step size of each update, is the partial derivative of the loss function with respect to the weights (i.e., the gradient), and l is the loss function; S3-6: Repeat the steps of S3-2 to S3-5 until the model reaches the predetermined number of training rounds; S3-7. Input the input data x in the test set into the model trained in step S3-6 to generate the corresponding predicted value ŷ; S3-8. According to the predicted result ŷ and the true label y, calculate the evaluation metrics, and determine whether the AI model has been trained well based on the evaluation metrics. If it has not been trained well, repeat steps S3-1 to S3-6; S4. Input the real-time data of the drone into the AI model trained and evaluated in S3, and use the unsupervised learning method to detect outliers and output the abnormal data. The expression used is: ; where h(x) is the average path length of the data point x, T is the number of decision trees. If h(x) is much smaller than the normal data, then x may be an outlier; S5: Match the abnormal data with the known attack paths and the behavioral characteristics of the attacker, use the association rule learning method to find the correlations between behaviors, determine the nature of the abnormal behavior, and judge the attack type; S6: Determine whether the attack is persistent or sudden. If the abnormal behavior continuously appears in the past N time windows, it may be a persistent attack, and the expression used is: ; wherein represents the moving average calculated at time point t, N represents the size of the moving window, represents the data value at time point i, t represents the current time, that is, the current time point of the moving window, and t−N + 1 represents the Nth time point before the current time, which is used to define the starting position of the window.
5. The network security risk assessment method for a drone system according to claim 4, wherein The evaluation metrics in S3-8 include accuracy, precision, and recall, and their expressions are respectively: , where TP is true positive, TN is true negative, FP is false positive, and FN is false negative. The accuracy rate is close to 1, indicating a higher accuracy rate; , the higher the precision, the better, and the ideal value is 1; , the higher its recall rate, the better, and the ideal value is 1.
6. The network security risk assessment method for a drone system according to claim 5, characterized in that, Step 3 includes the following steps: Step 3-1. Use the binomial distribution to evaluate the probability of abnormal behavior transforming into an attack event; The expression is: ; where P(X = k) is the probability of exactly k successes in n trials, is the binomial coefficient, representing the number of ways to choose k successes out of n trials; Step 3-2. According to the attack type judged in step S5 and the attack probability calculated in step 3-1, construct a risk matrix to evaluate the attack possibility, and divide the abnormal behaviors into different levels according to the attack probability and impact degree; Step 3-3. Evaluate the possible impacts on the drone system, operators, and the enterprise according to the attack type and behavior; Step 3-4. Combine the attack probability and potential impact, and use a weighted average model to calculate the final security risk score. The expression used is: Risk Score = Likelihood × Impact Severity, where Likelihood is the probability of the attack event calculated according to S301, and Impact Severity is the quantified value evaluated according to the size of the potential impact; , where is the weight for each impact category, is the quantification value for each impact category.
7. The network security risk assessment method for a drone system according to claim 6, wherein, In the said step 3-1, The calculation expression of the combination number is: ; where n is the total number of experiments, representing the number of samples evaluated or the number of detections performed over a period of time, k is the number of successes, representing the number of times abnormal behavior transforms into an attack event, and p is the probability of an attack occurring in a single experiment.
8. A method for network security risk assessment for a drone system according to claim 7, characterized in that, Step 4 includes the following steps: Step 4-1. Understand the current security state of the drone system, and judge whether it is necessary to adjust the defense strategy. If the threat is low, choose to maintain the existing strategy or make minor adjustments. If there is a high-risk threat, it needs to be addressed first; Step 4-2. According to the identified high-risk attack type, set the defense goals, and the defense goals include: improving the recognition ability of specific attacks, enhancing the protection of key data and control signals, and accelerating the response time to attack events; Step 4-3: Strengthen the detection of high-risk attacks. For network attacks, enhance the intrusion detection system and traffic analysis. For malware attacks, increase virus scanning and sandbox technology. For attacks on control systems, enhance encryption and access control mechanisms, increase the depth of defense, strengthen the authentication mechanism for critical components of the system to prevent unauthorized access, isolate different modules in the network to avoid the spread of attacks, and strengthen data encryption for communication between systems to prevent man-in-the-middle attacks; Step 4-4: After the policy adjustment, continuously monitor the system status and threat intelligence, automatically update the rules according to the new threat patterns, and automatically adjust the defense measures through the AI model.
9. The network security risk assessment method for a drone system according to claim 8, wherein In the said Step 4-4, the AI model uses a reinforcement learning model for learning. By trying different defense strategies and obtaining feedback, it automatically adjusts and updates according to the feedback; The expression used by its reinforcement learning model is: ; where Q(s,a) is the expected return of executing action a in state S, α is the learning rate, which determines the step size of learning and update, r is the immediate reward, γ is the discount factor, which is used to evaluate the long-term return, and a is the possible subsequent action.
10. A network security risk assessment method for a drone system according to claim 1 or 9, characterized in that, In the said Step 5, a dependency graph is used to construct the attack path and analyze the possible action routes of the attacker. The expression used is: G=(V,E), where V represents the system components and E represents the dependency relationship or data flow between the components; The occurrence time of attack events is detected and analyzed using a sliding window to identify the attack chain pattern. The expression used is: , where P(A|B) represents the probability of attack A occurring after event B occurs, and P(B|A) represents the probability of event B being caused by attack A. Based on historical attack data, the probability distribution of different attack chains is calculated to predict the next attack.
Citation Information
Cited By
Website AI intelligent risk assessment real-time avoiding system and avoiding method thereof
CN120512308A
Service-oriented unmanned equipment intelligent behavior conceptual model construction method
CN120953891A
Unmanned aerial vehicle management and control system and method based on intelligent agent
CN121037850A
An unmanned aerial vehicle management and control system and method based on an agent
CN121037850B
Decision-making method, device and equipment for turntable tracking unmanned aerial vehicle, and storage medium
CN121115891A