Network security device and method for aircraft network
By inserting network modules into the avionics network and dynamically changing the network mapping to mask the actual mapping, the problem of unauthorized passenger access to the avionics network is solved, and network security is improved.
Patent Information
- Application Number
- CN202010527614.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-06-14
- Filing Date
- 2020-06-11
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2040-06-11
AI Technical Summary
Existing technologies are insufficient to effectively prevent passengers from gaining unauthorized access to avionics networks through external access points, especially during the reconnaissance phase, which involves network mapping and information gathering activities.
By inserting a network module between the external access node and the avionics bus, artificial network mappings are generated and dynamically changed to mask the actual network mappings and present false mappings to interrupt the reconnaissance phase.
It effectively prevents unauthorized passenger access to avionics networks, prevents network reconnaissance and potential attacks, and improves network security.
Smart Images

Figure CN112087757B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to systems and methods for network security. More specifically, the disclosed examples relate to disrupting the reconnaissance phase of a network attack. Background Art
[0002] The demand for network connectivity (e.g., internet access) for passengers on aircraft and other transportation vehicles continues to grow. As passenger connectivity increases, it becomes increasingly important for network security systems to be able to prevent malicious network activity. For example, improved systems and methods are needed to prevent reconnaissance via external access points provided to passengers. Summary of the Invention
[0003] The present disclosure provides systems, devices, and methods related to mapping of obfuscated computer networks. In some examples, a method for mapping an obfuscated avionics network may include: operably coupling a network module between an external access node and an avionics bus of the avionics network, wherein all communications between the external access node and the avionics bus pass through the network module. The method may further include: generating a first network map that identifies network addresses of a first set of components on at least a first portion of the avionics bus; loading the first network map onto the network module; and making the first network map accessible to the external access node. The method may further include: generating at least a second network map that identifies network addresses of a second set of components on at least a second portion of the avionics network, the second network map being different from the first network map; and loading the second network map onto the network module. The method may further include changing the network map accessible to the external access node from the first network map to the second network map.
[0004] In some examples, a network module can be operably coupled to an avionics network and configured to be operably interposed between an avionics bus of the avionics network and an external access node, with all communications between the external access node and the avionics bus traversing the network module. The module can be configured to generate a first network map that identifies network addresses of a first set of components on at least a first portion of the avionics network and make the first network map accessible to the external access node. The module can be configured to generate a second network map that identifies network addresses of a second set of components on at least a second portion of the avionics network, the second network map being different from the first network map. The module can be configured to change the network map accessible to the external access node from the first network map to the second network map.
[0005] In some examples, a system for obfuscating a network mapping of an avionics network of an aircraft may include: a first container including a first network mapping identifying network addresses of network components of at least a first portion of the avionics network; and a second container including a second network mapping identifying network addresses of network components of at least a second portion of the avionics network, the second network mapping being different from the first network mapping. The system may further include a switching device configured to insert the first container between an avionics bus of the avionics network and an external access node, and, in response to at least a first criterion, replace the first container with a second container and insert the second container between the avionics bus and the external access node to change the network mapping accessible to the external access node from the first network mapping to the second network mapping.
[0006] The features, functions, and advantages can be achieved independently in various examples of the present disclosure or may be combined in yet other examples, further details of which can be seen with reference to the following description and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0007] Figure 1 is a flow chart depicting the steps of an illustrative aircraft manufacturing and maintenance method.
[0008] Figure 2 is a schematic diagram of an illustrative aircraft.
[0009] Figure 3 is a schematic diagram of an illustrative data processing system.
[0010] Figure 4 is a schematic diagram of an illustrative distributed data processing system.
[0011] Figure 5 is a schematic diagram of an illustrative aircraft network system including a fuzzy module according to aspects of the present disclosure.
[0012] Figure 6 yes Figure 5 Schematic diagram of the fuzzy module.
[0013] Figure 7 It shows Figure 5 Schematic diagram of the operation of the fuzzy module.
[0014] Figure 8 is a flow chart depicting the steps of an illustrative method of mapping a fuzzy computer network according to the present teachings. DETAILED DESCRIPTION
[0015] The method for mapping of fuzzy computer networks and various aspects and examples of related devices are described below and shown in the accompanying drawings. Unless otherwise stated, the network module and / or its various components according to this teaching can, but are not required to be included in at least one of the structure, components, functions and / or variations described, illustrated and / or incorporated herein. In addition, unless explicitly excluded, the process steps, structures, components, functions and / or variations described, illustrated and / or incorporated herein in conjunction with this teaching can be included in other similar devices and methods, including being interchangeable between disclosed examples. The description of the following various examples is essentially illustrative and is by no means intended to limit the present disclosure, its application or uses. In addition, the advantages provided by the examples described below are essentially illustrative, and not all examples provide the same advantages or the same degree of advantages.
[0016] This detailed description includes the following sections, followed by: (1) Overview; (2) Examples, Components, and Alternatives; (3) Illustrative Combinations and Additional Examples; (4) Advantages, Features, and Benefits; and (5) Conclusion. The Examples, Components, and Alternatives section is further divided into subsections A through E, each labeled accordingly.
[0017] Overview
[0018] Typically, a method for obfuscating the mapping of a computer network includes operatively inserting a network module between an external access point and the rest of the computer network. The network can be associated with a passenger vehicle having a network that passengers can access using a suitable data processing system, and the network can be included in an airplane, a ship or other watercraft, a train, a subway, a bus, a car and / or a truck. For example, the vehicle can be an airplane having a network system that is configured to allow passengers to access the network using their personal devices (also referred to as passenger devices). Passengers can use passenger devices connected to the vehicle network to communicate with, for example, an in-flight entertainment system, an external network such as the Internet, and / or any other suitable system that can be accessed via the vehicle network.
[0019] Access to a vehicle network can increase passenger convenience and / or entertainment. However, there is a possibility that a passenger may attempt to access passenger-restricted portions of the vehicle network system using a device connected to the vehicle network. For example, a passenger may connect their device to the passenger-based portion of the vehicle network via a network access device provided for passenger use and then attempt to communicate with a restricted network system to which the passenger is not authorized to access.
[0020] Unauthorized intrusion by passengers or other actors into restricted systems on a vehicle network typically begins with a reconnaissance phase, which includes activities such as determining a network map, port scanning, and / or gathering other network information. Most network security is static, allowing for accurate assessment of defenses. The network module is configured to disrupt this reconnaissance phase by blocking and altering the network map accessible to passengers, thereby preventing intrusion or attacks.
[0021] The network module is configured to act as an interface, such as a gateway or proxy, between the external access point and the rest of the vehicle's network and to present an artificial network map to all devices connected to the external access point. The network module is further configured to change the presented artificial network map based on one or more predetermined criteria. For example, the network module may change the presented artificial network map at regular intervals, at random intervals, and at a selected geographic location of the vehicle in response to selected network conditions or monitored network activity and / or any desired criteria.
[0022] The criteria may be selected by a user of the network module (such as an administrator of the vehicle network). Criteria may be selected as part of other network operations, such as when installing the network module, during routine network maintenance, and / or as part of changing network security. Criteria may additionally or alternatively be selected as part of other vehicle operations, such as during a pre-flight checklist for an airplane, when a train is assigned to a new route, or during routine vehicle maintenance. Criteria may additionally or alternatively be selected in response to security information or concerns such as the emergence of new network penetration techniques, an increase in network penetration attempts by vehicle passengers, and / or the addition of highly sensitive systems to the vehicle network.
[0023] Disclosed herein are technical solutions for preventing unauthorized access to restricted systems of a computer network. Specifically, the disclosed system / method addresses a technical problem related to computer technology and arising in the field of computer networks, namely, the technical problem of preventing unauthorized users from compiling accurate network mappings. The disclosed system and method address this technical problem by masking the actual static network mapping and presenting a false dynamic network mapping to the user of the network access device. Thus, the disclosed system and method not only enumerates the implementation of some known practices, but also enumerates the requirements for executing them on a computer. Instead, the disclosed system and method provides a solution that must be based on computer technology to overcome problems that arise, particularly in the field of networks.
[0024] Various aspects of the method of network mapping fuzzification and / or fuzzification module can be embodied as a computer method, a computer system, or a computer program product. Thus, various aspects of the fuzzification method or fuzzification module can take the form of an entirely hardware example, an entirely software example (including firmware, resident software, microcode, etc.), or an exemplary combination of software and hardware aspects, all of which are generally referred to herein as a "circuit," "module," or "system." Furthermore, various aspects of the fuzzification method or fuzzification module can take the form of a computer program product implemented in a computer-readable medium having computer-readable program code / instructions implemented thereon.
[0025] Any combination of computer-readable media may be utilized. The computer-readable medium may be a computer-readable signal medium and / or a computer-readable storage medium. The computer-readable storage medium may include an electronic, magnetic, optical, electromagnetic, infrared and / or semiconductor system, apparatus or device or any suitable combination of these. More specific examples of computer-readable storage media may include the following: an electrical connection with one or more wires, a portable computer floppy disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device and / or any suitable combination of these, etc. In the context of the present disclosure, a computer-readable storage medium may include any suitable non-transitory tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus or device.
[0026] A computer-readable signal medium may include, for example, a propagated data signal in baseband or as part of a carrier wave, having computer-readable program code embodied therein. Such a propagated signal may take any of a variety of forms, including but not limited to electromagnetic, optical, and / or any suitable combination thereof. A computer-readable signal medium may include any computer-readable medium that is not a computer-readable storage medium but that is capable of communicating, propagating, or transporting a program for use by or in connection with an instruction execution system, apparatus, or device.
[0027] Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., and / or any suitable combination of these.
[0028] The computer program code for implementing the operations of various aspects of the network mapping fuzzification method or module can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as C. Mobile applications can be developed using any suitable language (including the languages mentioned above) as well as Objective-C, Swift, C#, HTML5, etc. The program code can run entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), and / or a connection can be established with an external computer (e.g., via the Internet using an Internet service provider).
[0029] The following describes various aspects of the network mapping fuzzy method and module with reference to the flowcharts and / or block diagrams of the method, apparatus, system and / or computer program product. Each block and / or combination of blocks in the flowchart and / or block diagram can be implemented by computer program instructions. The computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine, so that the instructions implemented by the processor of the computer or other programmable data processing device create a device for implementing the functions / actions specified in the flowchart and / or block diagram blocks. In some examples, the machine-readable instructions can be programmed onto a programmable logic device such as a field programmable gate array (FPGA).
[0030] These computer program instructions may also be stored in a computer-readable medium that can direct a computer, other programmable data processing apparatus and / or other devices to operate in a specific manner, so that the instructions stored in the computer-readable medium produce a manufactured product including instructions for implementing the functions / actions specified in the flowchart and / or block diagram blocks.
[0031] The computer program instructions may also be loaded onto a computer, other programmable data processing apparatus and / or other devices to cause a series of operational steps to be performed on the devices to produce a computer-implemented process, so that the instructions running on the computer or other programmable apparatus provide a process for implementing the functions / actions specified in the flowchart and / or block diagram blocks.
[0032] Any flow chart and / or block diagram in the accompanying drawings is intended to illustrate the architecture, functionality and / or operation of possible implementations of the system, method and computer program product according to various aspects of the network mapping fuzzy method or module. In this regard, each box can represent a module, segment or portion of a code, which includes one or more executable instructions for implementing a specified logical function. In some embodiments, the functions indicated in the box may not occur in the order indicated in the accompanying drawings. For example, depending on the functions involved, two boxes shown in succession can actually be run essentially simultaneously, or the boxes can sometimes be run in the opposite order. Each box and / or the combination of boxes can be implemented by a dedicated hardware-based system (or a combination of dedicated hardware and computer instructions) that performs a specified function or action.
[0033] Examples, Components, and Alternatives
[0034] The following subsections describe selected aspects of exemplary methods for mapping obfuscated computer networks and related systems and / or devices. The examples in these subsections are intended to be illustrative and should not be construed as limiting the overall scope of this disclosure. Each subsection may include one or more different examples and / or context or related information, functionality, and / or structure.
[0035] A. Illustrative aircraft and related methods
[0036] In illustrative aircraft manufacturing and maintenance method 100 (see Figure 1 ) and illustrative aircraft 120 (see Figure 2 ). The examples disclosed herein are described in the context of a method 100. The method 100 includes multiple processes, periods, or stages. During pre-production, the method 100 may include a specification and design stage 104 of the aircraft 120 and a material procurement stage 106. During production, a component and subassembly manufacturing stage 108 of the aircraft 120 and a system integration stage 110 may occur. Thereafter, the aircraft 120 may undergo a certification and delivery stage 112 to enter an in-service stage 114. While in service (e.g., by an operator), the aircraft 120 may be scheduled for routine maintenance and repair 116 (which may also include modification, reconfiguration, refurbishment, etc. of one or more systems of the aircraft 120). Although the examples described herein generally relate to operational use of the aircraft 120 during the in-service stage 114, the method 100 may be practiced during other stages of the method 100.
[0037] Each process of method 100 may be performed or implemented by a system integrator, a third party, and / or an operator (e.g., a customer). For ease of description, a system integrator may include, but is not limited to, any number of aircraft manufacturers and major system subcontractors; a third party may include, but is not limited to, any number of suppliers, subcontractors, and vendors; and an operator may include, for example, an airline, a leasing company, a military entity, a service organization, or the like.
[0038] The illustrative method 100 may be used to manufacture an aircraft 120. The aircraft 120 is an example of a vehicle having a vehicle network as described above. Figure 2 As shown, aircraft 120 may include a frame 122 having a plurality of systems 124 and an interior 126. Examples of plurality of systems 124 include one or more of a propulsion system 128, an electrical system 130, a hydraulic system 132, an environmental system 134, a cargo system 136, a landing system 138, and a vehicle network system 150. Vehicle network system 150 may include, for example, passenger-based systems 160 to which passengers may be authorized to access and aircraft operating systems 170 to which passengers generally do not have access.
[0039] Depending on the functions involved, each of the plurality of systems 124 may include various subsystems such as controllers, processors, actuators, effectors, motors, generators, and the like. Any number of other systems may be included. Although an aviation example is shown, the principles disclosed herein may be applied to other industries such as the automotive, rail, and marine industries. Thus, in addition to aircraft 120, the principles disclosed herein may be applied to other vehicles such as land vehicles, marine vehicles, and the like. The apparatus and methods shown or described herein may be employed in any one or more stages of the manufacturing and service method 100.
[0040] B. Illustrative Data Processing System
[0041] like Figure 3 As shown, this example describes a data processing system 200 (also referred to as a computer, computing system, and / or computer system) according to aspects of the present disclosure. In this example, data processing system 200 is an illustrative data processing system suitable for implementing aspects of the network mapping fuzzification method. More specifically, in some examples, a device (e.g., a smartphone, a tablet computer, a personal computer) as an example of a data processing system can include a network system, can include a fuzzification module, and / or can be connected to a network through a fuzzification module.
[0042] In this illustrative example, data processing system 200 includes system bus 202 (also referred to as a communications framework). System bus 202 may provide communications between processor unit 204 (also referred to as one or more processors), memory 206, persistent storage 208, communications unit 210, input / output (I / O) unit 212, codec 230, and / or display 214. Memory 206, persistent storage 208, communications unit 210, input / output (I / O) unit 212, display 214, and codec 230 are examples of resources that processor unit 204 may access via system bus 202.
[0043] Processor unit 204 is configured to execute instructions that may be loaded into memory 206. Depending on the specific implementation, processor unit 204 may include multiple processors, multiple processor cores, and / or one or more processors of a specific type (e.g., a central processing unit (CPU), a graphics processing unit (GPU), etc.). Furthermore, processor unit 204 may be implemented using a plurality of heterogeneous processor systems, in which a main processor resides with secondary processors on a single chip. As another illustrative example, processor unit 204 may be a symmetric multi-processor system containing multiple processors of the same type.
[0044] Memory 206 and persistent storage 208 are examples of storage devices 216. A storage device may include any suitable hardware capable of storing information (eg, digital information) such as data, program code in functional form, and / or other suitable information, either temporarily or permanently.
[0045] Storage device 216 may also be referred to as a computer-readable storage device or computer-readable medium. Memory 206 may include volatile storage memory 240 and non-volatile memory 242. In some examples, a basic input / output system (BIOS), such as during the startup process, which contains the basic routines that transfer information between elements within data processing system 200, may be stored in non-volatile memory 242. Persistent storage 208 may take various forms, depending on the particular implementation.
[0046] Persistent storage 208 may include one or more components or devices. For example, permanent storage 208 may include one or more devices such as a magnetic disk drive (also known as a hard disk drive or HDD), a solid-state disk (SSD), a floppy disk drive, a tape drive, a Jaz drive, a Zip drive, a flash memory card, a memory stick, or any combination thereof. One or more of these devices may be removable and / or portable, such as a removable hard disk drive. Persistent storage 208 may include one or more storage media, alone or in combination with other storage media, including optical drives such as compact disc ROM devices (CD-ROMs), compact disc recordable drives (CD-R drives), compact disc rewritable drives (CD-RW drives), and / or digital versatile disc ROM drives (DVD-ROMs). To facilitate connecting permanent storage 208 to system bus 202, a removable or non-removable interface, such as interface 228, is typically used.
[0047] Input / output (I / O) unit 212 allows for input and output of data with other devices (i.e., input devices and output devices) that may be connected to data processing system 200. For example, input devices 232 may include one or more pointing and / or information input devices such as a keyboard, mouse, trackball, stylus, touchpad or touch screen, microphone, joystick, game pad, satellite dish, scanner, television tuner card, digital camera, digital video camera, webcam, etc. These and other input devices may connect to processor unit 204 through system bus 202 via interface port(s) 236. Interface port(s) 236 may include, for example, a serial port, a parallel port, a game port, and / or a universal serial bus (USB).
[0048] Output devices 234 may use some of the same types of ports, and in some cases, may use the same actual ports, as input device(s) 232. For example, a USB port may be used to provide input to data processing system 200 and to output information from data processing system 200 to output devices 234. Output adapters 238 are provided to illustrate that there are some output devices 234 (e.g., monitors, speakers, and printers) that require special adapters. Output adapters 238 may include, for example, graphics cards and sound cards that provide a connection between output devices 234 and system bus 202. Other devices and / or systems of devices may provide both input and output functionality, such as remote computer(s) 260. Display 214 may include any suitable human-computer interface or other mechanism configured to display information to a user (e.g., a CRT, LED, or LCD monitor or screen, etc.).
[0049] Communications unit 210 refers to any suitable hardware and / or software employed to provide communications with other data processing systems or devices. Although communications unit 210 is shown as being internal to data processing system 200, in some examples, it may be at least partially external to data processing system 200. Communications unit 210 may include both internal and external technology, such as modems (including conventional telephone-grade modems, cable modems, and DSL modems), ISDN adapters, and / or wired and wireless Ethernet cards, hubs, routers, and the like. Data processing system 200 may operate in a networked environment using logical connections to one or more remote computers 260. Remote computer(s) 260 may include personal computers (PCs), servers, routers, network PCs, workstations, microprocessor-based applications, peer devices, smartphones, tablet computers, other network notebooks, and the like. Remote computer(s) 260 generally include many of the elements described with respect to data processing system 200. Remote computer(s) 260 may be logically connected to data processing system 200 via network interface 262, which is connected to data processing system 200 via communications unit 210. The network interface 262 encompasses wired and / or wireless communication networks such as local area networks (LANs), wide area networks (WANs), and cellular networks. LAN technologies may include fiber distributed data interface (FDDI), copper distributed data interface (CDDI), Ethernet, token ring, and the like. WAN technologies include point-to-point links, circuit switching networks (e.g., integrated services digital networks (ISDN) and their variants), packet switching networks, and digital subscriber lines (DSL).
[0050] The codec 230 may include an encoder, a decoder, or both, including hardware, software, or a combination of hardware and software. The codec 230 may include any suitable device and / or software configured to encode, compress, and / or encrypt a data stream or signal for transmission and storage, and to decode, decompress, and / or decrypt the data stream or signal (e.g., for playing or editing video). Although the codec 230 is described as a separate component, the codec 230 may be included or implemented in a memory (e.g., non-volatile memory 242).
[0051] The non-volatile memory 242 may include a read-only memory (ROM), a programmable ROM (PROM), an electrically programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), a flash memory, or the like, or any combination thereof. The volatile memory 240 may include a random access memory (RAM), which may be used as an external cache memory. The RAM may include a static RAM (SRAM), a dynamic RAM (DRAM), a synchronous DRAM (SDRAM), a double data rate SDRAM (DDR SDRAM), an enhanced SDRAM (ESDRAM), or the like, or any combination thereof.
[0052] Instructions for the operating system, applications, and / or programs may be located in storage devices 216, which are in communication with processor unit 204 through system bus 202. In these illustrative examples, these instructions are present in functional form in persistent storage 208. These instructions may be loaded into memory 206 to be executed by processor unit 204. The processes of one or more examples of the present disclosure may be performed by processor unit 204 using computer-implemented instructions, which may be located in a memory such as memory 206.
[0053] These instructions are referred to as program instructions, program code, computer usable program code, or computer readable program code that are executed by the processor in processor unit 204. The program code in different examples may be embodied on different physical or computer-readable storage media, such as memory 206 or persistent storage 208. Program code 218 may be located in functional form on computer-readable media 220, which may be selectively removable and loaded onto or transferred to data processing system 200 for execution by processor unit 204. In these examples, program code 218 and computer-readable media 220 form computer program product 222. In one example, computer-readable media 220 may include computer-readable storage media 224 or computer-readable signal media 226.
[0054] Computer-readable storage media 224 may include, for example, an optical or magnetic disk that is inserted or placed in a drive or other device that is part of permanent storage 208 for transfer to a storage device, such as a hard drive, that is part of permanent storage 208. Computer-readable storage media 224 may also take the form of a permanent storage device, such as a hard drive, a thumb drive, or a flash memory, that is connected to data processing system 200. In some instances, computer-readable storage media 224 cannot be removed from data processing system 200.
[0055] In these examples, computer-readable storage media 224 is a non-transitory, physical or tangible storage device used to store program code 218, rather than a medium that propagates or transmits program code 218. Computer-readable storage media 224 is also referred to as a computer-readable tangible storage device or a computer-readable physical storage device. In other words, computer-readable storage media 224 is a medium that can be touched by a person.
[0056] Alternatively, program code 218 can be transmitted to data processing system 200 remotely using computer-readable signal media 226, for example, over a network. Computer-readable signal media 226 can be, for example, a propagated data signal containing program code 218. For example, computer-readable signal media 226 can be an electromagnetic signal, an optical signal, and / or any other suitable type of signal. These signals can be transmitted via a communication link, such as a wireless communication link, a fiber optic cable, a coaxial cable, an electrical wire, and / or any other suitable type of communication link. In other words, in the illustrative examples, the communication link and / or connection can be physical or wireless.
[0057] In some illustrative examples, program code 218 may be downloaded from another device or data processing system to persistent storage 208 via computer readable signal media 226 over a network for use within data processing system 200. For example, program code stored in a computer readable storage medium in a server data processing system may be downloaded from the server over a network to data processing system 200. The computer providing program code 218 may be a server computer, a client computer, or some other device capable of storing and transmitting program code 218.
[0058] In some examples, program code 218 may include an operating system (OS) 250. Operating system 250, which may be stored on persistent storage 208, controls and allocates resources of data processing system 200. One or more applications 252 utilize the operating system to manage resources via program modules 254 and program data 256 stored in storage device 216. OS 250 may include any suitable software system configured to manage and expose the hardware resources of computer 200 for sharing and use by applications 252. In some examples, OS 250 provides application programming interfaces (APIs) that facilitate connection to different types of hardware and / or provide applications 252 with access to hardware and OS services. In some examples, such as with so-called "middleware," certain applications 252 may provide other services used by other applications 252. Aspects of the present disclosure may be implemented with respect to various operating systems or combinations of operating systems.
[0059] The different components shown for data processing system 200 are not meant to provide architectural limitations to the manner in which different examples may be implemented. One or more examples of the present disclosure may be implemented in a data processing system that includes fewer components or components in addition to and / or in place of those shown for computer 200. Figure 3 Other components shown in the examples may vary from the depicted examples. The various examples may be implemented using any hardware device or system capable of running program code. As an example, data processing system 200 may include organic components integrated with inorganic components and / or may be composed entirely of organic components (excluding humans). For example, a memory device may be composed of an organic semiconductor.
[0060] In some examples, the processor unit 204 can take the form of a hardware unit having hardware circuits that are specially manufactured or configured for a specific purpose or to produce a specific result or progress. This type of hardware can perform operations without loading program code 218 from a storage device into memory to be configured to perform the operations. For example, the processor unit 204 can be a circuit system, an application-specific integrated circuit (ASIC), a programmable logic device, or some other suitable type of hardware that is configured (e.g., preconfigured or reconfigured) to perform multiple operations. For example, for a programmable logic device, the device is configured to perform multiple operations and can be reconfigured at a later time. Examples of programmable logic devices include programmable logic arrays, field programmable logic arrays, field programmable gate arrays (FPGAs), and other suitable hardware devices. With this type of implementation, executable instructions (e.g., program code 218) can be implemented as hardware, for example, by specifying the FPGA configuration using a hardware description language (HDL) and then (re)configuring the FPGA using the generated binary file.
[0061] In another example, data processing system 200 can be implemented as a set of specialized state machines (e.g., finite state machines (FSMs)) based on an FPGA (or in some cases, an ASIC), which can allow critical tasks to be isolated and run on custom hardware. Whereas a processor such as a CPU can be described as sharing a general-purpose state machine that executes instructions provided to it, the FPGA-based state machine(s) are constructed for a specific purpose and can execute hard-coded logic without sharing resources. Such systems are typically used for safety-related and critical tasks.
[0062] In another illustrative example, processor unit 204 may be implemented using a combination of processors found in computers and hardware units. Processor unit 204 may have multiple hardware units and multiple processors configured to run program code 218. For the depicted example, some processes may be implemented with multiple hardware units, while other processes may be implemented with multiple processors.
[0063] In another example, system bus 202 may include one or more buses such as a system bus or an input / output bus. Of course, any suitable type of architecture for data transmission between different components or devices attached to a bus system may be used to implement a bus system. System bus 202 may include several types of bus structures including a memory bus or memory controller, a peripheral bus or external bus, and / or a local bus using any number of available bus architectures (e.g., Industry Standard Architecture (ISA), Micro Channel Architecture (MSA), Extended ISA (EISA), Intelligent Drive Electronics (IDE), VESA Local Bus (VLB), Peripheral Component Interconnect (PCI), Card Bus, Universal Serial Bus (USB), Advanced Graphics Port (AGP), Personal Computer Memory Card International Association bus (PCMCIA), FireWire (IEEE 1394), and Small Computer System Interface (SCSI)).
[0064] In addition, the communication unit 210 may include multiple devices that transmit data, receive data, or both transmit and receive data. The communication unit 210 may be, for example, a modem or a network adapter, two network adapters, or some combination thereof. In addition, the memory may be, for example, the memory 206 or a cache found in an interface and memory controller hub that may be present in the system bus 202.
[0065] The flowcharts and block diagrams described herein illustrate the architecture, functionality, and operation of possible implementations of the systems, methods, and computer program products according to various illustrative examples. In this regard, each box in the flowchart or block diagram may represent a module, section, or portion of a code that includes one or more executable instructions for implementing one or more specified logical functions. It should also be noted that in some alternative embodiments, the functions indicated in the box may not occur in the order indicated in the accompanying drawings. For example, depending on the functions involved, the functions of two boxes shown in succession may be performed substantially simultaneously, or the functions of the boxes may sometimes be performed in reverse order.
[0066] C. Illustrative Distributed Data Processing System
[0067] like Figure 4As shown, this example depicts a general network data processing system 300, which may be interchangeably referred to as a computer network, a network system, a distributed data processing system, or a distributed network, the mapping of which may be protected by illustrative examples of the obfuscation modules and / or obfuscation methods disclosed herein. For example, a network module as described above may be operably connected to a network to act as a proxy for an access node such as a wireless router or an Ethernet device.
[0068] It should be understood that Figure 4 The illustration is provided as one embodiment and is not intended to imply any limitation with respect to the environments in which different examples may be implemented. Many modifications to the depicted environments are possible.
[0069] Network system 300 is a network of devices (e.g., computers), each of which may be an example of data processing system 200, as well as other components. Network data processing system 300 may include network 302, which is a medium configured to provide communication links between the various devices and computers connected within network data processing system 300. Network 302 may include, for example, wired or wireless communication links, fiber optic cables, and / or any other suitable medium for transmitting and / or communicating data between network devices, or any combination thereof.
[0070] In the depicted example, first network device 304 and second network device 306 are connected to network 302, as are one or more computer-readable memory or storage devices 308. As described above, network device 304 and network device 306 are each examples of data processing system 200. In the depicted example, device 304 and device 306 are shown as server computers that communicate with one or more server data storage devices 322, which can be used to store information local to server computers 304 and 306, among other things. However, network devices may include, but are not limited to, one or more personal computers, mobile computing devices (such as personal digital assistants (PDAs), tablets and smartphones, handheld gaming devices, wearable devices, tablet computers, routers, switches, voice gates, servers, electronic storage devices, imaging devices, media players, and / or other network-enabled tools that can perform mechanical or other functions. These network devices may be interconnected via wired, wireless, optical, or other suitable communication links.
[0071] Additionally, client electronic device 310 and client electronic device 312 and / or client smart device 314 may be connected to network 302. Figure 3As depicted, each of these devices is an example of data processing system 200. Client electronic devices 310, 312, and 314 may include, for example, one or more personal computers, network computers, and / or mobile computing devices (such as personal digital assistants (PDAs), smartphones, handheld gaming devices, wearable devices, and / or tablet computers). In some examples, such client computers may include communication-enabled data processing systems on one or more vehicles (such as aircraft) connected to network 302. In the depicted example, server 304 provides information such as boot files, operating system images, and applications to one or more client electronic devices 310, 312, and 314. In the context of the relationship of client electronic devices 310, 312, and 314 to a server (such as server computer 304), client electronic devices 310, 312, and 314 may be referred to as "clients." The client devices may communicate with one or more client data storage devices 320, which may be used to store information local to the client (e.g., cookie(s) and / or associated contextual information). Network data processing system 300 may include more, fewer, or no servers and / or clients, as well as other devices not shown.
[0072] In some examples, the first client electronic device 310 can pass the encoded file to the server 304. The server 304 can store the file, decode the file, and / or transmit the file to the second client electronic device 312. In some examples, the first client electronic device 310 can pass the uncompressed file to the server 304, and the server 304 can compress the file. In some examples, the server 304 can encode the text, audio, and / or video information and transmit the information to one or more clients via the network 302.
[0073] Client smart device 314 can include any suitable portable electronic device (such as a smart phone or tablet computer) capable of wireless communication and software operation. Generally speaking, the term "smart phone" can describe any suitable portable electronic device configured to perform computer functions, typically with a touch screen interface, Internet access, and an operating system capable of running downloaded applications. In addition to making calls (e.g., via a cellular network), a smart phone can also send and receive emails, text and multimedia messages, access the Internet, and / or be used as a web browser. Smart devices (e.g., smart phones) can also include features of other known electronic devices (such as media players, personal digital assistants, digital cameras, video cameras, and / or global positioning systems). Smart devices (e.g., smart phones) can be capable of wirelessly connecting to other smart devices, computers, or electronic devices, such as through near field communication (NFC), Bluetooth, WiFi, or a mobile broadband network. A wireless connection is established between smart devices, smart phones, computers, and / or other devices to form a mobile network that can exchange information.
[0074] As described above, the data and program code located in the system 300 can be stored in or on a computer-readable storage medium (such as a network-attached storage device 308 and / or a permanent storage device 208 of one of the network computers) and can be downloaded to a data processing system or other device for use. For example, program code can be stored on a computer-readable storage medium on a server computer 304 and downloaded to a client 310 via a network 302 for use on the client 310. In some examples, the client data storage device 320 and the server data storage device 322 reside on one or more storage devices 308 and / or 208.
[0075] The network data processing system 300 can be implemented as one or more different types of networks. For example, the system 300 can include an intranet, a local area network (LAN), a wide area network (WAN), or a personal area network (PAN). In some examples, the network data processing system 300 includes the Internet, wherein the network 302 represents a global collection of networks and gateways that communicate with each other using the Transmission Control Protocol / Internet Protocol (TCP / IP) protocol suite. The core of the Internet is the backbone of high-speed data communication lines between major nodes or hosts. Thousands of commercial computer systems, government computer systems, educational computer systems, and other computer systems can be used to route data and messages. In some examples, the network 302 can be referred to as a "cloud." In those examples, each server 304 can be referred to as a cloud computing node, and the client electronic device can be referred to as a cloud consumer, etc. Figure 4 It is intended as an example and not as an architecture for any illustrative example.
[0076] D. Illustrative Aircraft Networking System
[0077] like Figures 5 to 7 As shown, this section describes an illustrative network system 400. Network system 400 is an example of a network system, such as network data processing system 300, that includes a network module for network mapping obfuscation as described above. Network system 400 can be included on aircraft 120 and / or any other suitable vehicle.
[0078] like Figure 5 As shown, network system 400 includes aircraft network 410. Aircraft network 410 includes a medium configured to provide communication links between various devices within network system 400. Devices connected to aircraft network 410 may include one or more data processing systems, which, as described above, are examples of data processing system 200. Aircraft network 410 may include connections such as wired or wireless communication links, fiber optic cables, and / or any other suitable medium for transmitting and / or communicating data between devices on the aircraft network.
[0079] Aircraft network 410 includes a network bus 412, which may also be referred to as a network communication framework and / or an avionics bus. Network bus 412 is connected to a network processor 420, a network input / output interface 424, and a network storage area 422 including at least a first storage device. Network bus 412 is configured to facilitate communication (e.g., data transfer) between network processor 420, input / output interface 424, storage area 422, and / or any other suitable network devices.
[0080] Network processor 420 includes one or more processors configured to execute instructions and may generally be an example of processor unit 204 described above. Network storage area 422 may include any suitable hardware or combination of hardware capable of storing information (e.g., digital information) such as data, program code in functional form, and / or other suitable information, either temporarily or permanently. This storage area may include a combination of one or more computer-readable storage devices (including computer-readable media, volatile memory, non-volatile memory, permanent storage devices, and / or non-permanent storage devices).
[0081] The network input / output interface 424 is configured to facilitate the input and output (e.g., reception and transmission) of data between the network bus 412 and other devices connected to the aircraft network 410. The network input / output interface 424 may include, for example, one or more switches, routers, hubs, gateways, repeaters, bridge routers, protocol converters, modulators, modems, and / or any other suitable hardware and / or software. The network input / output interface is connected to a plurality of network nodes 428 (e.g., via wired and / or wireless communication links), each of which is configured to receive, create, store, and / or transmit data. A network node may also be described as a network access device and may include wired and / or wireless access devices. The network node 428 is included in the passenger-based system 414 and the aircraft operating system 416.
[0082] The aircraft operating system 416 may include network devices and / or communication links that are reserved for use by the aircraft's systems and / or employees. For example, the aircraft operating system 416 may be configured to operate HVAC equipment, activate safety equipment (e.g., oxygen masks, fire suppression systems, etc.), provide human-perceivable information to passengers (e.g., fire alarms, signals directing passengers to fasten their seat belts, etc.), and / or perform any other functions typically limited to authorized vehicle personnel. Additionally or alternatively, the aircraft operating system 416 may include or provide access to systems associated with aircraft controls (such as primary controls, secondary controls, autopilot systems, envelope protection systems, thrust asymmetry compensation systems, etc.). Although an illustrative aircraft operating system 416 is described herein in conjunction with an aircraft (e.g., aircraft 120), the network system 400 on any suitable type of vehicle may include a vehicle operating system similar to the aircraft operating system 416 or other systems appropriate to the particular vehicle.
[0083] In this example, aircraft operating system 416 includes a network access device 432 for network node 428. Network access device 432 of aircraft operating system 416 communicates directly with network input / output interface 424. Other network nodes 428 of the aircraft operating system can similarly communicate with the input / output interface. The network nodes of aircraft operating system 416 can only be accessed by authorized personnel and can be considered secure. Therefore, as described below, the network nodes of the aircraft operating system can communicate with network bus 412 through network input / output interface 424 without ambiguity.
[0084] Passenger-based system 414 includes devices, media, and communication links intended for passenger use. Passenger-based system 414 may also include, for example, network nodes and / or devices configured to connect passenger devices 440 to external networks 444. Additionally, or alternatively, components of passenger-based system 414 may be configured to enable passengers to use devices 440 to access in-flight entertainment options (e.g., stream or download movies or music stored on aircraft network 410), order food or drinks, request assistance from cabin crew, obtain updates on aircraft status (such as position, speed, and / or estimated time of arrival), etc.
[0085] In this example, passenger-based system 414 includes wireless network access device 430 of network node 428. Wireless network access device 430 can provide access to aircraft network 410 to passenger device 440. Passenger device 440 can be a smartphone, computer, laptop, tablet, and / or any other suitable electronic device capable of wireless communication. Passenger device 440 can be the personal property of the passenger or any suitable electronic device operated by the passenger.
[0086] Passenger device 440 includes a wireless communication device 442 configured to facilitate communications with other data processing systems or devices. For example, as described above, wireless communication device 442 may be an example of communication unit 210 of data processing system 200. Wireless communication device 442 may connect to aircraft network 410 via wireless network access device 430, thereby enabling passenger device 440 to communicate with the aircraft network. When wireless communication device 442 is connected to aircraft network 410, passenger device 440 may be referred to as being on a network, connected to a network, and / or networked.
[0087] The wireless network access device 430 communicates with the network input / output interface 424 through the obfuscation module 510. More specifically, all communications between the wireless network access device 430 and the network input / output interface 424 occur through the virtual container 516 on the obfuscation module. The virtual container 516 is configured to act as a network input / output interface and can be described as performing some or all of the functions of a router, a gateway, and / or a proxy server.
[0088] Obfuscation module 510 can take the form of a separate hardware module of data processing system 200, such as described above, or can take the form of a software module running on the hardware of network input / output interface 424, or can combine software and hardware aspects in any effective manner. In this example, obfuscation module 510 includes a dedicated memory area 512 and a dedicated processor 514. Processor 514 communicates directly with network input / output interface 424, separately from virtual container 516. Virtual container 516 can be described as a virtual software environment executed by processor 514 using memory area 512. References herein to virtual container 516 and / or other virtual containers can be understood to encompass software and / or processes executed within the virtual software environment.
[0089] In some examples, aircraft network 410 can include multiple obfuscation modules to protect the network from users of multiple network access devices. For example, an obfuscation module can be operably inserted between each network access device of network node 428 of passenger-based system 414 and network input / output interface 424. In some examples, obfuscation module 510 can be operably inserted between multiple network access devices of network node 428 of passenger-based system 414 and network input / output interface 424. Any number of obfuscation modules can be used as appropriate for the architecture of aircraft network 410. In some examples, multiple obfuscation modules can be connected in sequence to coordinate obfuscation functionality.
[0090] Once passenger device 440 is connected to aircraft network 410, it can send and receive data communications over the network, but all such communications are routed through obfuscation module 510. In a typical example, a non-malicious passenger may connect to aircraft network 410 in order to gain access to network storage area 422. For example, a passenger may connect a smartphone to watch a movie.
[0091] In such an example, passenger device 440 sends a communication to wireless network access device 430 requesting the network address of network storage area 422. Wireless network access device forwards the request to obfuscation module 510, which in turn forwards the request to network input / output interface 424. Input / output interface 424 provides a reply communication back to module 510 with the static network address assigned to network storage area 422.
[0092] Module 510 masks the provided static network address by communicating an alternate network address to passenger device 440 via wireless network access device 430. Subsequently, packets sent by passenger device 440 to network storage area 422 are addressed to the alternate network address. When packets are delivered to module 510 by wireless network access device 430, the module edits each packet address to the static network address assigned to network storage area 422. The packets are then delivered to network input / output interface 424 and transferred to storage area 422.
[0093] The obfuscation module 510 can be described as performing basic or one-to-one network address translation (NAT) between the network address space or mapping of the aircraft network 410 and the generated artificial network mapping. That is, the obfuscation module edits intercepted packets to replace the static addresses of the aircraft network 410 with replacement addresses from the generated artificial network mapping, and vice versa. In some examples, the obfuscation module 510 can additionally or alternatively edit other packet information, such as port numbers.
[0094] In addition to masking the static network mapping of the aircraft network 410, the obfuscation module 510 is also configured to change the generated artificial network mapping used for NAT. Figure 6 As shown, the fuzzy module 510 includes a plurality of virtual containers, each virtual container having an associated network map. To change the generated artificial map, the fuzzy module changes which virtual container is active.
[0095] Reference again Figure 5 Continuing with the above example, the replacement network address of the network storage area 422 provided to the passenger device 440 by the obfuscation module 510 is obtained from the first network mapping. After changing to the network mapping 546, packets sent from the passenger device 440 are no longer validly addressed for delivery to the network storage area 422. When the passenger device 440 again requests the network address of the network storage area 422 and receives the new replacement network address for the network storage area from the second network mapping, the passenger may experience a brief interruption in connectivity.
[0096] The obfuscation module 510 can thereby obfuscate the network mapping of the aircraft network 410 from the passenger device 440. Changes to the network mapping used by the module 510 can minimize disruption to communications between the passenger device 440 and approved network devices. That is, authorized activity of the passenger device 440 on the aircraft network 410 can generally include inter-system communications that include protocols for automatically reestablishing communications after a network address change. Such communications can be minimally disrupted. However, as described below with reference to Figure 7As further discussed, detection of unauthorized activity on a network map may be disrupted by changes to the network map.
[0097] Figure 6 is a schematic diagram of an illustrative example of obfuscation module 510. The module's memory area is divided into two partitions: secure avionics partition 556 and external partition 558. Data flow between avionics partition 556 and external partition 558 is limited to a unidirectional flow from the avionics partition to the external partition. In this example, data flow is restricted by software data diode 518. In some examples, partitions 556 and 558 may include separate storage devices and / or data processing systems, and data flow may be restricted by hardware data diodes.
[0098] The external partition 558 includes a virtualization system that is configured to manage multiple separate virtual environments and allocate hardware and / or software resources, such as memory or operating system (OS) services, between the virtual environments. In this example, the virtualization system is a real-time hypervisor 536 that manages multiple containers. In some examples, the virtualization system may include a container manager, and the virtual environments may include virtual machines and / or may use any effective virtualization.
[0099] The hypervisor 536 maintains active containers 516 and a container library 538. Figure 6 As shown, the active container is currently container 540. Active container 516 communicates with wireless network access device 430 and network input / output interface 424 and acts as a proxy server or gateway as described above.
[0100] Container library 538 includes at least one inactive container. An inactive container does not communicate with or is not connected to aircraft network 410. In the depicted example, the library has N inactive containers, including container 544, container 548, and container 552. N can be any integer, but the number of inactive containers included in library 538 can be limited to reduce processing and memory requirements associated with managing the library.
[0101] Hypervisor 536 may rotate the container, selecting the next container in container library 538 to become the active container. For example, hypervisor may select container 544 as the next active container. Container 540 may be disconnected from aircraft network 410, thereby temporarily severing communication between wireless network access device 430 and network input / output interface 424. Container 540 may be shut down or returned to container library 538 as an inactive container. Container 544 may then be connected to aircraft network 410 to re-facilitate communication between wireless network access device 430 and network input / output interface 424. Container 544 then becomes active container 516. Hypervisor 536 rotates the container upon receiving a rotation instruction from secure avionics partition 556.
[0102] Each container includes a different network mapping. In this example, container 540 includes network mapping 542, container 544 includes network mapping 546, container 548 includes network mapping 550, and container 552 includes network mapping 554. Obfuscation module 510 performs basic NAT between the network mapping of aircraft network 410 and the network mapping of the active container. For example, when container 540 is active, the obfuscation module performs NAT based on network mapping 542.
[0103] The obfuscation module 510 is configured to generate new containers and network maps when containers are rotated by the hypervisor 536. The secure avionics partition 556 includes a network map generator 530 and a container generator 534. The network map generator 530 includes a randomization engine 532 to facilitate the generation of random network maps. The generated network map may include Internet Protocol (IP) addresses, ports, network asset identifiers, and / or any other information used in network communications.
[0104] In some examples, generating the network map may include associating a randomly selected network address with each network address currently assigned to a network device or connected data processing system on the aircraft network 410. Associating the randomly selected network address only with network addresses currently in use may reduce processing and memory requirements associated with generating and storing each network map, but may require communication between the secure avionics partition 556 and the network input / output interface 424.
[0105] In some examples, generating the network map may include associating a randomly selected network address with each network address valid for the communication protocol used by the aircraft network. Such a complete map may require additional processing and memory to generate and store, but may allow the secure avionics partition 556 to operate without being connected to the network input / output interface 424.
[0106] The network mapping may be randomized within the constraints of the communication protocol used by aircraft network 410 and / or may be randomized within constraints selectable by an administrator of aircraft network 410. For example, the network address of aircraft network 410 may be associated with a randomly selected network address from any IP address reserved for use as a private IP address. For another example, the network administrator may limit the randomly selected address to a block of private IP addresses between 192.168.0.0 and 192.168.255.255.
[0107] Each generated network map is stored in a corresponding generated container. Each container and stored network map is then passed to the external partition 558 to be added to the container library 538.
[0108] The secure avionics partition 556 further includes a switch 520 configured to initiate a rotation of a container in the external partition 558. The switch 520 may transmit a rotation request to the hypervisor 536 based on one or more preselected criteria. The criteria may be selected by an administrator of the aircraft network 410 and / or the obfuscation module 510. Typically, the criteria may include that the aircraft operated by the network 410 is in flight, in addition to any desired additional criteria.
[0109] For example, switch 520 may receive geolocation data regarding the location of an aircraft from a navigation system included in aircraft operating system 416. When assigning an aircraft to a particular flight path or commercial route, an administrator may select one or more geolocations. Subsequently, when the aircraft arrives at the selected geolocations, switch 520 may transmit a rotation request to hypervisor 536.
[0110] For another example, the switch 520 may communicate with a database in the aircraft operating system 416 that includes passenger data. The switch 520 may receive an alert from the database when a passenger in the flight has previously traveled or boarded the same aircraft, has a marked travel status, and / or any criteria selected by the administrator. The switch 520 may then transmit a rotation request once during the flight when no alerts are received for the flight, but may transmit a rotation request every half hour when at least one alert has been received.
[0111] For another example, the switch 520 can communicate with the network input / output interface 424 regarding network activity. When specific network activity occurs or exceeds a selected threshold, the switch 520 can transmit a rotation request. For example, a rotation can be initiated if an intrusion into a restricted system is detected or if passenger device activity on the network exceeds typical levels.
[0112] Exchange 520 may also be configured to allow container rotations to be dynamically triggered by hypervisor 536. For example, exchange may be configured to receive rotation requests from a computer used by an aircraft pilot over network 410 and / or from a local interface of obfuscation module 510 that is physically accessible to authorized personnel, such as cabin crew.
[0113] In this example, switching device 520 includes a security mode selector 522. The security mode selector includes a user interface configured to simplify the selection of rotation criteria. A user can select between a low security setting 524, a medium security setting 526, and a high security setting 528. Each mode selects a corresponding set of criteria for switching device 520. For example, each security setting can specify criteria based on time intervals. Low security setting 524 can select rotation intervals of two hours. Medium security setting 526 can select rotation intervals of one hour. High security setting 528 can select rotation intervals of random intervals, with each interval not exceeding 30 minutes.
[0114] When safety concerns are limiting, it may be advantageous to select a lower safety setting because this reduces the processing load. In aircraft, the effects of additional processing requirements (such as increased heat generation and power requirements) are particularly undesirable.
[0115] Security mode selector 522 can facilitate the use of obfuscation module 510 by users with limited knowledge or expertise regarding cybersecurity. For example, security mode selector 522 can allow flight crews to update the criteria selected for obfuscation module 510 before each flight. Administrators of aircraft network 410, technical support personnel of the airline operating the aircraft, the manufacturer of obfuscation module 510, or other qualified individuals or organizations can use security mode selector 522 to update the definition of selectable modes. For example, as new cyber reconnaissance techniques become commonplace, software updates can be released for the obfuscation module that reduce the time between container rotations in each mode.
[0116] The security mode selector may also include a sleep or standby mode. In this mode, obfuscation module 510 may relay packets between network input / output interface 424 and wireless network access device 430 without requiring editing. Such a mode may facilitate maintenance of aircraft network 410 by technicians. For example, on a static network, troubleshooting a malfunctioning wireless network access device or installing a new node in passenger-based system 414 may be significantly simplified. In some examples, this standby mode may be utilized whenever the aircraft is not in flight. However, for aircraft in highly secure areas, continued operation of obfuscation module 510 may be appropriate.
[0117] The secure avionics partition 556 is configured to be inaccessible to the passenger devices 440. The secure avionics partition communicates only with the network input / output interface 424 of the aircraft network 410 and not with other network nodes or passenger devices. In some examples, the secure avionics partition 556 may not be connected to the aircraft network 410 and may need to perform management functions for the obfuscation module 510 locally.
[0118] The obfuscation module 510 can also be configured to ensure that the secure avionics partition 556 is inaccessible to the passenger device 440. Such configuration can include hardware features and / or software features. For example, the secure avionics partition 556 can run on a dedicated processor and storage device separate from the external partition 558.
[0119] Figure 7 is a schematic diagram illustrating module 510 obfuscating the map of aircraft network 410 under attacker reconnaissance. In this example, the attacker is a passenger of the aircraft using passenger device 440. The attacker can include any actor, on or off the aircraft, with access to a network access device such as wireless network access device 430. Generally, reconnaissance involves locating network assets by sending queries to a series of valid network addresses until a response is received. Common queries may include pings (Internet packet explorers) or other echo request packets. In this example, passenger device 440 sends a ping 560 to the local network address 192.168.2.5.
[0120] Ping 560 is sent from passenger device 440 to wireless network access device 430 and forwarded to obfuscation module 510. The subsequent path of ping 560 depends on which container of obfuscation module 510 is currently active. If container 540 is active, ping 560 will follow the path indicated by dotted line 562. Container 540 receives ping 560 and edits the ping packet address according to network map 542. Figure 7 As shown, network map 542 associates address 192.168.2.5 with the actual address 192.168.1.1 of aircraft network 410. The edited ping is forwarded to network input / output interface 424, which passes the edited ping to 192.168.1.1. This address is assigned to avionics system 423 connected to network bus 412, so passenger device 440 will receive a reply at address 192.168.2.5 indicating the presence of a restricted-access system.
[0121] If container 544 is active, ping 560 will follow the path indicated by dashed line 564. Container 544 receives ping 560 and edits the ping packet address according to network map 546. Figure 7 As shown, network map 546 associates address 192.168.2.5 with the actual address 192.168.1.2 of aircraft network 410. The edited ping is forwarded to network input / output interface 424, which transmits the edited ping to 192.168.1.2. This address is assigned to network storage area 422, so passenger device 440 will receive a reply indicating that an accessible network device exists at address 192.168.2.5.
[0122] If container 548 is active, ping 560 will follow the path indicated by solid line 566. Container 548 receives ping 560 and edits the ping packet address according to network map 550. Figure 7 As shown, network map 550 does not associate address 192.168.2.5 with any address currently in use on aircraft network 410. A ping will not be transmitted, and passenger device 440 will return a timeout message indicating that there is no network asset at address 192.168.2.5.
[0123] Consider the example of sending ping 560 while container 540 is active. The attacker has noted the presence of a limited-access system at address 192.168.2.5 and continues to ping other valid addresses to locate additional network assets. As reconnaissance progresses, fuzzing module 510 rotates the container as described above, causing container 548 to become active. When the attacker attempts to communicate with 192.168.2.5 again, the network will indicate that there is no device at that address.
[0124] The attacker must therefore repeat the reconnaissance phase in order to further penetrate the restricted systems of the aircraft network 410. Ideally, the attacker can remain in the reconnaissance phase for the duration of the flight and be unable to attack or intrude upon any system of the aircraft network 410.
[0125] Additionally, depending on the reconnaissance techniques utilized, the obfuscation module 510 can remain undetected on the network. The obfuscation module 510 and the container can be configured to reduce the likelihood of discovery. For example, the obfuscation module can be configured to edit packets intercepted between the wireless network access device 430 and the network input / output interface 424 to mask or anonymize the static network address assigned to the obfuscation module.
[0126] E. Illustrative Methods
[0127] See also Figure 8 This section describes the steps of an illustrative method for obfuscating the mapping of an avionics network. Aspects of the aircraft network and / or network modules described above can be utilized in the method steps described below. Where appropriate, reference is made to components and systems that can be used to implement each step. These references are for illustration only and are not intended to limit the possible manner in which any particular step of the method may be implemented.
[0128] Figure 8 is a flowchart showing steps performed in an illustrative method and may not list the complete process or all steps of the method. Although described below and in Figure 8 The various steps of method 600 are described in , but these steps do not necessarily have to be performed all at once, and in some cases, can be performed simultaneously or in an order different from that shown.
[0129] At step 610, the method includes inserting a module between the access node and the network bus. In some examples, the module can be inserted between the access node and another type of network communication system and / or all other nodes of a network having any network topology. The module can be a distinct hardware module such as the data processing system 200 described above, or a software module running on hardware such as a network interface of a gateway, or can combine software and hardware aspects in any effective manner. The module can include and / or run on a processor and a computer-readable storage device.
[0130] The module can be operably connected to an access node and a network bus. The module can communicate directly with the access node and / or the network bus, and / or can communicate through a network interface such as a gateway, router, or proxy. The module can be connected to the access node, the network bus, and / or the network interface via any suitable communication link, including but not limited to a wireless communication link, a fiber optic cable, or a coaxial cable.
[0131] Step 612 of the method includes generating N containers, where N is any positive integer. Each container may include operating system-level virtualization configured to allow an isolated virtualized system to run on the module. Generating the container may include storing, configuring, and / or initializing software or processes within the container. In some examples, this step may include generating other virtual environments such as virtual machines through methods such as full virtualization and / or hardware-assisted virtualization.
[0132] Step 614 of the method includes generating N network maps, where N is any positive integer. Each map may include multiple pairs of associated network addresses. Each map may be randomly generated and associates a random network address with each address in a set of network addresses, where the set of network addresses may include each static address assigned on a network including a network bus and / or each network address valid in one or more communication protocols operating on the network. Each map may additionally or alternatively include other network communication data, such as a port number or a physical address.
[0133] The method includes storing each network map in the container at step 616. Storing the network map in the container may include storing data associated with the network map in a storage device or area provided to the container and / or making the data accessible to software and / or processes running in the container.
[0134] Steps 612 through 616 can be performed simultaneously and / or can be repeated sequentially. For example, the container and network map can be generated simultaneously. For another example, a first container can be generated, a first network map can be generated, and the first network map can be stored in the first container. Then, a second network map can be generated and stored in the second container. Throughout method 600, steps 612 through 616 can be repeated as additional containers and network maps are needed.
[0135] Step 618 includes loading the first container onto the module. A sub-step 620 of step 618 includes partitioning the module into a secure partition and an external partition. This partitioning can be hardware and / or software. For example, the partitions can be formed by disk partitions of a single storage device and can share a processor. For another example, each partition can include a separate storage device and processor.
[0136] Sub-step 622 of step 618 includes restricting data flow to a unidirectional flow between partitions. Data can be restricted to flow from the secure partition to the external partition. This restriction can be performed using data diodes, including software or hardware diodes. Sub-steps 620 and 622 can be performed before step 610 as part of the module's setup process. Steps 612 through 616 can then be performed on the secure partition.
[0137] Sub-step 624 includes loading the first container from the secure partition to the external partition. Loading the container may include transferring and / or communicating data associated with the first container from the secure partition to the external partition via a data diode. Loading the container may also include launching the container and / or assuming control of the container by a hypervisor, container manager, and / or other virtualization system. In some examples, loading the container may include storing the container in a library of inactive containers.
[0138] At step 626, method 600 includes making the network map stored in the first container accessible to the access node. Making the network map accessible may include selecting the first container from a library of inactive containers and designating the first container as the active container. Making the network map accessible may further include establishing communication between the first container and the access node. For example, server software running in the container may be configured to communicate with the access node. Based on the network map, the first container may communicate with the access node.
[0139] Step 628 includes limiting communication between the access node and the network bus to communication through the first container. Limiting communication may include configuring the network architecture so that the access node is connected only to the module. Limiting communication may further include configuring the module so that the access node communicates only with selected virtual containers on an external partition of the module.
[0140] The first container can be configured to act as a network interface such as a gateway, router, or proxy server. Such configuration can include initialization of software and / or processes within the container, such as a server operating system or a virtual router. The first container can facilitate communication between the access node and the network bus and can communicate with the access node based on the network mapping stored in the first container.
[0141] Step 630 of the method includes changing a network mapping accessible to the access node. Sub-step 632 of step 630 includes removing communications through the first container. Removing communications may include disconnecting the first container and / or the software or process running in the container from the access node and the network bus. Removing communications may further include shutting down or terminating the software or process running in the container.
[0142] Sub-step 634 of step 630 includes replacing the first container with a second container. The second container may be one of the N containers generated in steps 612 to 616 and may be loaded onto the module according to step 618. The second container may be selected from a library of inactive containers and designated as the active container. The first container may be closed.
[0143] Sub-step 636 of step 630 includes establishing communication through the second container. Similar to steps 626 and 628, the sub-step may include making the network mapping stored in the second container accessible to the access node and limiting communication between the access node and the network bus to communication through the second container. Based on the network mapping stored in the second container, software and / or processes similar to or matching the software and / or processes in the first container may be run in the second container to facilitate communication between the access node and the network bus.
[0144] Illustrative combinations and additional examples
[0145] This section describes additional aspects and features of methods and apparatus for fuzzy mapping of computer networks, which are presented in the form of a series of paragraphs, but are not limited thereto. For clarity and effectiveness, some or all of these paragraphs may be represented by alphanumeric characters. Each of these paragraphs may be combined with one or more other paragraphs in any appropriate manner and / or with the disclosure elsewhere in this application. Certain paragraphs below explicitly reference and further qualify other paragraphs, providing, but not limiting, examples of some suitable combinations.
[0146] A0. A method for mapping a fuzzy avionics network, comprising:
[0147] a network module operatively coupled between an external access node and an avionics bus of the avionics network, with all communications between the external access node and the avionics bus passing through the network module;
[0148] generating a first network map identifying network addresses of a first set of components on at least a first portion of the avionics bus;
[0149] loading the first network map onto the network module;
[0150] making the first network mapping on the network module accessible to the external access node;
[0151] generating at least a second network map identifying network addresses of a second set of components on at least a second portion of the avionics network, the second network map being different from the first network map;
[0152] loading the second network map onto the network module; and
[0153] The network mapping accessible to the external access node is changed from the first network mapping to the second network mapping.
[0154] A1. The method according to A0, further comprising:
[0155] generating at least a first virtual environment and a second virtual environment;
[0156] storing the first network map in the first virtual environment; and
[0157] storing the second network mapping in the second virtual environment; and
[0158] Loading the first network mapping onto the network module includes loading the first virtual environment storing the first network mapping onto the network module, and loading the second network mapping onto the network module includes loading the second virtual environment storing the second network mapping onto the network module.
[0159] A2. The method of A1, further comprising limiting communications between the avionics bus and the external access node to communications through the first virtual environment.
[0160] A3. A method according to A2, wherein changing the network mapping accessible to the external access node from the first network mapping to the second network mapping includes removing communication between the external access node and the first virtual environment; and establishing communication between the external access node and the second virtual environment.
[0161] A4. A method according to A2 or A3, wherein changing the network mapping accessible to the external access node from the first network mapping to the second network mapping includes replacing the first virtual environment storing the first network mapping with the second virtual environment storing the second network mapping on the network module.
[0162] A5. The method of any one of A1-A4, wherein each of the first virtual environment and the second virtual environment is a container.
[0163] A6. The method of any one of A1-A5, wherein each of the first virtual environment and the second virtual environment is a virtual machine.
[0164] A7. A method according to any one of A1-A6, wherein loading the first virtual environment storing the first network mapping onto the network module includes loading the first virtual environment from the avionics partition of the network module to an external partition on the network module, and the method further includes limiting the data flow between the avionics partition of the module and the external partition to a unidirectional data flow from the avionics partition to the external partition.
[0165] A8. The method of A7, wherein limiting data flow between the avionics partition and the external partition of the module to a unidirectional data flow includes transmitting data from the avionics partition to the external partition through a data diode.
[0166] A9. The method according to any one of A1-A8, further comprising generating a plurality of N virtual environments including the first virtual environment and the second virtual environment, wherein N is an integer greater than 2.
[0167] A10. The method according to A9, further comprising:
[0168] The virtual environment of the plurality of virtual environments accessible to the external access node is rotated.
[0169] A11. A method according to any one of A0-A10, wherein changing the network mapping accessible to the external access node includes changing the network mapping accessible to the external access node in response to satisfying at least a first predetermined criterion.
[0170] A12. The method of A11, wherein the at least first predetermined criterion for changing the network mapping accessible to the external access node comprises a fixed benchmark for changing the network mapping accessible to the external access node.
[0171] A13. The method of A12, wherein the fixed reference is a set time period.
[0172] A14. The method of A12 or A13, wherein the fixed reference is a predetermined sequence of a set of network mappings including the first network mapping and the second network mapping.
[0173] A15. A method according to any one of A12-A14, wherein the fixed reference is a predetermined geographic location of the aircraft.
[0174] A16. A method according to any one of A11-A15, wherein the at least first predetermined criterion for changing the network mapping accessible to the external access node includes a random benchmark for changing the network mapping accessible to the external access node.
[0175] A17. The method of A16, wherein the random benchmark comprises a varying time period.
[0176] A18. A method according to any of A11-A17, wherein the at least first predetermined criterion for changing the network mapping accessible to the external access node is based at least in part on a relative security level of the avionics network.
[0177] B0. A network module for obfuscating a mapping of an avionics network, wherein the network module is operably coupled to the avionics network and is configured to:
[0178] operatively interposed between an avionics bus of the avionics network and an external access node, with all communications between the external access node and the avionics bus passing through the network module;
[0179] generating a first network map identifying network addresses of a first set of components on at least a first portion of the avionics network;
[0180] making the first network mapping on the network module accessible to the external access node;
[0181] generating a second network map identifying network addresses of a second set of components on at least a second portion of the avionics network, the second network map being different from the first network map; and
[0182] The network mapping accessible to the external access node is changed from the first network mapping to the second network mapping.
[0183] B1. The network module according to B0, wherein the network module is configured to:
[0184] generating at least a first virtual environment and a second virtual environment;
[0185] storing the first network mapping in the first virtual environment;
[0186] making the first virtual environment accessible to the external access node;
[0187] storing the second network mapping in the second virtual environment; and
[0188] The virtual environment accessible to the external access node is changed from the first virtual environment to the second virtual environment.
[0189] B2. The network module according to B1, comprising a first partition and a second partition, wherein:
[0190] the first partition being operatively coupled to the avionics network and configured to generate at least a first virtual environment and a second virtual environment, to load the first virtual environment storing the first network map onto the second partition, and to not conduct communication between the avionics bus and the external access node; and
[0191] The second partition is configured to be operably interposed between the avionics bus and the external node.
[0192] B3. The network module according to B2, wherein the second partition is configured to remove communication between the external access node and the first virtual environment and establish communication between the external access node and the second virtual environment.
[0193] B4. The network module according to B2 or B3, wherein the first partition is configured to replace the first virtual environment storing the first network mapping with the second virtual environment storing the second network mapping on the second partition.
[0194] B5. The network module according to any one of B1-B4, wherein each of the first virtual environment and the second virtual environment is a container.
[0195] B6. The network module according to B5, wherein the network module is configured to rotate the container accessible to the external access node.
[0196] B7. The network module according to any one of B1-B6, wherein each of the first virtual environment and the second virtual environment is a virtual machine.
[0197] B8. The network module according to any one of B0-B7, wherein the network module is configured to change the network mapping accessible to the external access node in response to satisfying at least a first predetermined criterion.
[0198] B9. The network module according to B8, wherein the at least first predetermined criterion for changing the network mapping accessible to the external access node includes a fixed benchmark for changing the network mapping accessible to the external access node.
[0199] B10. The network module according to B9, wherein the fixed reference is a set time period.
[0200] B11. The network module according to B9 or B10, wherein the fixed reference is a predetermined sequence of a set of network mappings including the first network mapping and the second network mapping.
[0201] B12. A network module according to any one of B9-B11, wherein the fixed reference is a predetermined geographic location of an aircraft having the avionics network.
[0202] B13. A network module according to any one of B8-B12, wherein the at least first predetermined criterion for changing the network mapping accessible to the external access node includes a random benchmark for changing the network mapping accessible to the external access node.
[0203] B14. The network module of B13, wherein the random benchmark comprises a varying time period.
[0204] B15. The network module of any one of B8-B14, wherein the at least first predetermined criterion for changing the network mapping accessible to the external access node is based at least in part on a relative security level of the avionics network.
[0205] B16. A network module according to any one of B1-B15, comprising a first partition and a second partition, wherein the first partition is operably coupled to the avionics network and is configured to load the first virtual environment storing the first network map from the first partition to the second partition, the second partition is configured to be operably inserted between the avionics bus and the external node, and the network module is configured to limit the data flow between the first partition and the second partition to a unidirectional data flow from the first partition to the second partition.
[0206] B17. The network module according to B16, further comprising a data diode that limits the data flow between the first partition and the second partition to a unidirectional data flow from the first partition to the second partition.
[0207] C0. A system for network mapping of an avionics network of an obfuscated aircraft, comprising:
[0208] a first container comprising a first network map identifying network addresses of network components of at least a first portion of the avionics network;
[0209] a second container comprising a second network map identifying network addresses of network components of at least a second portion of the avionics network, the second network map being different from the first network map; and
[0210] a switching device configured to insert the first container between an avionics bus of the avionics network and an external access node, and, in response to at least a first criterion, replace the first container with the second container inserted between the avionics bus and the external access node to change the network mapping accessible to the external access node from the first network mapping to the second network mapping.
[0211] C1. The system of C0, wherein the at least first criterion comprises a fixed basis for changing the network mapping accessible to the external access node from the first network mapping to the second network mapping.
[0212] C2. The system of C0 or C1, wherein the at least first criterion comprises a random basis for changing the network mapping accessible to the external access node from the first network mapping to the second network mapping.
[0213] C3. A system according to any one of C0-C2, further comprising:
[0214] a security partition, which includes a switching device;
[0215] an external partition, which can be accessed by the external access node; and
[0216] A data diode provides unidirectional data flow from the secure partition to the external partition.
[0217] C4. A system according to any one of C0-C3, wherein the switching device has a first mode of operation and a second mode of operation different from the first mode, the first mode and the second mode being configured to provide different security levels.
[0218] C5. A system according to any one of C0-C4, wherein the system includes a container manager that operates on a host and runs the first container and the second container.
[0219] C6. The system of C5, wherein the host has a secure partition including the switch device and an external partition including the container manager.
[0220] C7. A system according to C6, wherein only one-way data flow is allowed between the secure partition and the external partition, wherein the one-way data flow is from the secure partition to the external partition.
[0221] C8. The system according to C7 further includes a data diode that provides the unidirectional data flow.
[0222] C9. A system according to any one of C0-C8, wherein the system is configured as a network gateway.
[0223] C10. A system according to any one of C0-C9, wherein the system is a proxy server.
[0224] C11. A system according to any one of C0-C10, wherein each container is configured as a network gateway.
[0225] C12. The system of any one of C0-C11, further comprising a randomization engine configured to generate the first network mapping and the second network mapping.
[0226] D0. An intermediate network gateway for fuzzy network mapping of an avionics network, comprising:
[0227] an external partition configured to be operatively positioned in the avionics network between an external network access point and an avionics bus, the external partition comprising:
[0228] a plurality of containers, each of the plurality of containers including an associated different network mapping; and
[0229] a container manager that runs the plurality of containers; and
[0230] a secure partition in data communication with the external partition, the secure partition comprising a switch device configured to select an active container from the plurality of containers, wherein the active container acts as a proxy server between the external network access point and the avionics bus, and provide the associated network mapping to the external network access point.
[0231] D1. The intermediate network gateway according to D0, wherein the switching device selects the active container from the plurality of containers based on rotation.
[0232] D2. The intermediate network gateway according to D0 or D1, wherein the security partition further comprises a random engine operably coupled to the switching device, the random engine generating different network mappings based on randomness.
[0233] D3. The intermediate network gateway of D2, wherein the security partition further comprises a container generator operably coupled to the randomization engine and configured to generate the plurality of containers.
[0234] Advantages, Features, and Benefits
[0235] The various examples of the methods and apparatus described herein provide several advantages over known solutions for protecting computer networks from cyberattacks. For example, the illustrative examples described herein prevent attacks in the reconnaissance phase before unauthorized intrusion occurs.
[0236] Additionally, among other benefits, the illustrative examples described herein allow for thwarting attacks without alerting the attacker to the presence of the obfuscation module.
[0237] Additionally, among other benefits, the illustrative examples described herein allow for selection of a security level based on a number of preset and dynamic variables.
[0238] Additionally, among other benefits, the illustrative examples described herein protect the obfuscation module from direct attacks.
[0239] Especially under such limited processing requirements, no known system or device can perform these functions. Therefore, the illustrative examples described herein are particularly useful for networks on vehicles such as aircraft. However, not all examples described herein provide the same advantages or the same degree of advantages.
[0240] in conclusion
[0241] The disclosure set forth above may include multiple different examples with independent practicality. Although each of these specific examples has been disclosed in its preferred form, because many variations are possible, the specific examples disclosed and shown herein should not be considered restrictive. With respect to the use of section headings within this disclosure, such headings are only used for organizational purposes. The subject matter of the present disclosure includes all novel and non-obvious combinations and sub-combinations of the various elements, features, functions and / or characteristics disclosed herein. The attached claims specifically point out certain combinations and sub-combinations that are considered to be novel and non-obvious. In applications claiming priority to this application or a related application, other combinations and sub-combinations of features, functions, elements and / or characteristics may be claimed. Such claims, whether broader, narrower, the same or different in scope than the original claims, are considered to be included in the subject matter of the present disclosure.
Claims
1. A method (600) for mapping an fuzzy avionics network (410), comprising: a network module (510) operatively coupled (610) between an external access node (430) and an avionics bus (412) of the avionics network, with all communications between the external access node and the avionics bus passing through the network module; generating (614) a first network map (542) identifying network addresses of a first set of components on at least a first portion of the avionics bus; loading (618) the first network map onto the network module; enabling (626) the first network mapping on the network module to be accessible to the external access node; generating (614) at least a second network map (546) identifying network addresses of a second set of components on at least a second portion of the avionics network, the second network map being different from the first network map, loading (618) the second network map onto the network module; disrupting any reconnaissance of the avionics network by changing (630) the network mapping accessible to the external access node from the first network mapping to the second network mapping; wherein sabotage detection maintains authorization for external devices to access said network through said external access node; and Wherein once the accessible network mapping changes, any scanned network mapping of the avionics network from external access nodes becomes no longer valid.
2. The method (600) of claim 1, further comprising: generating (612) at least a first virtual environment (540) and a second virtual environment (544); storing (616) the first network map (542) in the first virtual environment (540); as well as storing (616) the second network map (546) in the second virtual environment (544); and wherein loading (618) the first network mapping onto the network module (510) includes loading (624) the first virtual environment storing the first network mapping onto the network module, and loading (618) the second network mapping onto the network module includes loading (624) the second virtual environment storing the second network mapping onto the network module.
3. The method (600) of claim 2, further comprising limiting (628) communications between the avionics bus (412) and the external access node (430) to communications through the first virtual environment (540).
4. The method (600) of claim 3, wherein changing (630) the network mapping accessible to the external access node (430) from the first network mapping (542) to the second network mapping (546) includes removing (632) communication between the external access node and the first virtual environment (540) and establishing (636) communication between the external access node and the second virtual environment (544).
5. The method (600) of any one of claims 1-4, wherein changing (630) the network mapping accessible to the external access node (430) comprises changing the network mapping accessible to the external access node in response to satisfying at least a first predetermined criterion (524, 526, 528).
6. A method (600) according to claim 5, wherein the at least first predetermined criterion (524, 526, 528) for changing the network mapping that the external access node (430) can access includes at least one of a fixed basis for changing the network mapping that the external access node can access or a random basis for changing the network mapping that the external access node can access.
7. A network module (510) for performing the method of any one of claims 1-6 to obfuscate the mapping of an avionics network (410), wherein the network module is operatively coupled to the avionics network and is configured to: operatively interposed between an avionics bus (412) of the avionics network and an external access node (430), with all communications between the external access node and the avionics bus passing through the network module; generating a first network map (542) that identifies network addresses of a first set of components on at least a first portion of the avionics network; enabling the first network mapping on the network module to be accessible to the external access node; generating a second network map (546) that identifies network addresses of a second set of components on at least a second portion of the avionics network, the second network map being different from the first network map; and The network mapping accessible to the external access node is changed from the first network mapping to the second network mapping.
8. The network module (510) according to claim 7, wherein the network module is configured to: generating at least a first virtual environment (540) and a second virtual environment (544); storing the first network map (542) in the first virtual environment (540); enabling the first virtual environment to be accessible to the external access node (430); storing the second network map (546) in the second virtual environment (544); and The virtual environment accessible to the external access node is changed from the first virtual environment to the second virtual environment.
9. The network module (510) of claim 8, comprising a first partition (556) and a second partition (558), wherein: The first partition is operatively coupled to the avionics network (410) and is configured to: generate at least the first virtual environment (540) and the second virtual environment (544), load the first virtual environment (540) storing the first network map (542) onto the second partition, and not perform communication between the avionics bus (412) and the external access node (430); and The second partition is configured to be operably interposed between the avionics bus and the external access node.
10. The network module (510) of claim 8, comprising a first partition (556) and a second partition (558), wherein the first partition is operatively coupled to the avionics network (410) and configured to load the first virtual environment (540) storing the first network map (542) from the first partition to the second partition, the second partition being operatively interposed between the avionics bus (412) and the external access node (430), and the network module being configured to limit data flow between the first partition and the second partition to a unidirectional data flow from the first partition to the second partition.
11. The network module (510) of claim 10, further comprising a data diode (518) that limits data flow between the first partition (556) and the second partition (558) to a unidirectional data flow from the first partition to the second partition.
12. A system for obfuscating a network map of an avionics network (410) of an aircraft (120) by performing the method of any one of claims 1-6, the system comprising: a first container comprising a first network map (542) identifying network addresses of network components of at least a first portion of the avionics network; a second container comprising a second network map (546) identifying network addresses of network components of at least a second portion of the avionics network, the second network map being different from the first network map; and A switching device (520) is configured to insert the first container between an avionics bus (412) of the avionics network and an external access node (430), and in response to at least a first criterion, replace the first container with the second container and insert the second container between the avionics bus and the external access node for changing the network mapping accessible to the external access node from the first network mapping to the second network mapping.
13. The system of claim 12, wherein the switching device has a first mode of operation (524) and a second mode of operation (526) different from the first mode, the first mode and the second mode being configured to provide different levels of security.
14. The system of claim 12, wherein the system includes a container manager (536) operating on a network module (510) and running the first container and the second container.
15. The system of claim 14, wherein the network module (510) has a secure partition (556) including the switch device (520) and an external partition (558) including the container manager (536).
16. The system of any one of claims 12-15, wherein each container is configured as a network gateway.
Citation Information
Patent Citations
System for creating an air-to-ground IP tunnel in an airborne wireless cellular network to differentiate individual passengers
US20090010200A1
Configuring a user device to remotely access a private network
US20090129301A1