A method for detecting a spoofing attack based on signal quality monitoring

By adopting a signal quality monitoring method based on KS statistical test and combining the coherent integral sample distribution characteristics of E and L correlators, the accuracy and robustness issues of SQM technology in detecting intermediate spoofing attacks are solved, and efficient detection of GNSS spoofing attacks is achieved.

CN115327579BActive Publication Date: 2026-02-13Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210965732.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-20
Publication Date
2026-02-13
Estimated Expiration
2042-07-20

AI Technical Summary

Technical Problem

Existing signal quality monitoring (SQM) technologies suffer from low detection accuracy and poor robustness when detecting GNSS spoofing attacks. In particular, when facing intermediate-level spoofing attacks, they struggle to effectively identify signal energy switching and correlation function symmetry distortion caused by spoofing signals.

Method used

A signal quality monitoring method based on KS statistical test is adopted. By statistically analyzing the coherent integral sample distribution characteristics of E correlators and L correlators respectively, the theoretical distribution parameters are determined using maximum likelihood estimation (MLE). The difference between the coherent integral sample and the theoretical distribution is evaluated by combining the OR principle with the KS test statistic, thereby realizing the detection of spoofing attacks.

Benefits of technology

It improves the detection performance and robustness of intermediate spoofing attacks, enabling sensitive and robust identification of spoofing signals under different modes of spoofing attacks, reducing false alarm rate, and improving detection accuracy and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115327579B_ABST
    Figure CN115327579B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of based on signal quality monitoring's deception attack detection method, belong to GNSS deception attack detection technical field.The present application is directed to the change of the coherent integration value distribution characteristics of E or L correlator caused by deception attack, in calibration phase, MLE is used to determine the coherent integration value rices distribution parameter;In evaluation phase, using the method based on Kolmogorov-Smirnov test respectively monitor the change of the correlation integration amplitude statistical characteristics of E and L correlator, respectively, the coherent integration sample of E, L correlator is established suitable detection statistics, two detection statistics are integrated, final decision is made based on OR principle.The present application is advantageous to analyze the difference of E and L coherent integration value distribution characteristics and then effectively detect the change of correlation peak symmetry, on the other hand, it is advantageous to detect the coherent integration amplitude characteristic change of E or L correlator caused by spoofing signal, can effectively solve the performance defect problem faced by traditional SQM technology, improve the performance and robustness of middle-level deception attack detection.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to a signal quality monitoring-based spoofing attack detection method and belongs to the technical field of GNSS spoofing attack detection. BACKGROUND

[0002] The accuracy, availability and continuity of a global satellite navigation system (GNSS) are the basis for providing various high-precision PNT services for users. Due to the low power and open characteristics of civil navigation signals, spoofing attacks can mislead users to output incorrect position, time and other information without their knowledge, have unpredictable spoofing and lethality, and seriously threaten the security of GNSS applications. At present, spoofing detection has become the core problem of anti-spoofing attack technology, and has attracted widespread attention in the satellite navigation field.

[0003] Known spoofing attack techniques can be divided into three types of primary, intermediate and advanced attacks according to the implementation difficulty. The intermediate spoofing attack has better concealment and higher attack success rate than the primary spoofing attack, and has lower complexity and stronger implementation feasibility than the advanced spoofing attack, and is the mainstream spoofing attack method at present. It gradually detaches the target receiver lock loop from the real signal correlation peak by adjusting the power, carrier phase, code rate and other parameters of the spoofing signal, and then locks the correlation peak of the spoofing signal, so that the purpose of successfully spoofing the victim can be achieved in the state that the target receiver is always locked.

[0004] Countermeasures against spoofing attacks have attracted great interest in the satellite navigation community. Signal quality monitoring (SQM) techniques, which are based on detecting the distortion of the correlation function symmetry caused by spoofing attacks, have been proven to be effective in spoofing detection since they were first proposed in 2001 due to their low complexity, strong implementability, and high detection efficiency. Delta metric is designed to detect the asymmetry of the correlation function, while Ratio metric is used to detect whether there is a "dead zone" at the top of the correlation function. They have been verified to be able to detect spoofing signals. Mubarak proposed ELP metric (early-late phase metric) to perform detection using the phase difference between the E and L correlator outputs, which has also been determined to be a useful discriminator for detecting multipath and spoofing. Wesson proposed Magnitude Difference Metric, which mainly uses the difference between the magnitudes of the early-late correlators to determine the distortion of GNSS signals and the influence of multipath. In addition, there are other reasonable spoofing detection metrics, such as implementing two-dimensional (2D) time-frequency analysis in the code delay domain and Doppler frequency domain to improve the spoofing detection performance and reliability, but this method causes additional computational complexity. Some people proposed a multi-scale joint detection method using Ratio, Delta, and Early-Late Phase metric, which combines different SQM metrics into a composite SQM metric to detect spoofing attacks, and proposed amplitude combination mode and false alarm probability combination mode (PfaM), but the actual effect is general.

[0005] With the continuous development of spoofing attack modes, SQM technology faces two main challenges in practical applications: first, for the frequency unlocked mode, due to the time-varying nature of the relative carrier phase drift between spoofing and real signals, the signal energy constantly switches between the in-phase (I) and quadrature (Q) channels, causing the SQM metric to fluctuate as the influence of system noise is not obvious, making it difficult for SQM technology to detect; second, as the power advantage of spoofing signals increases, the effect of correlation function symmetry distortion gradually decreases, and the detection performance of SQM technology is significantly lost. To address the first problem, an improved SQM method based on moving variance has been proposed, although the detection probability reaches 80% under a false alarm rate of 10%, the impact of spoofing signal power is not considered, and the detection performance still has a lot of room for improvement. In the face of the above problems, it is urgent to research SQM technology with better detection robustness to cope with different modes of spoofing attacks.

[0006] In order to overcome the above-mentioned defects, some people use statistical test method to analyze coherent integration data to improve the SQM technology and improve the detection performance. As a mature mathematical analysis method, statistical test has the characteristics of low calculation complexity and high accuracy in analyzing a large amount of data, and is fully used in radar jamming detection. In the field of GNSS spoofing detection, only the Chi-Square Goodness-of-fit test and Sign test methods proposed by Motella and Gamba can be used for detecting spoofing attacks. The two methods have high calculation efficiency, but are sensitive to samples and have poor robustness to distortion of correlation function shape, which further affects the detection accuracy. SUMMARY

[0007] The purpose of the present application is to provide a spoofing attack detection method based on signal quality monitoring, to solve the problems of low detection accuracy and poor robustness in the current SQM spoofing attack detection.

[0008] The present application provides a spoofing attack detection method based on signal quality monitoring, which comprises the following steps:

[0009] 1) respectively statistics the distribution characteristics of the coherent integration samples of the E correlator and the L correlator in the non-spoofing attack stage, and obtains the corresponding theoretical distribution parameters;

[0010] 2) obtaining the output values of the E correlator and the L correlator in the tracking stage of the GNSS receiver;

[0011] 3) respectively evaluating the difference between the coherent integration samples of the E correlator and the L correlator and the theoretical distribution population in each time window according to the output values of the E correlator and the L correlator, and respectively obtaining the test statistics of the E correlator and the L correlator;

[0012] 4) using the OR principle to judge whether the current GNSS receiver is in the spoofing attack stage according to the test statistics of the E correlator and the L correlator.

[0013] The present application is aimed at the change of the distribution characteristics of the coherent integration values of the E or L correlator caused by spoofing attack, respectively statistics the distribution characteristics of the coherent integration samples of the E correlator and the L correlator in the non-spoofing attack stage as the theoretical distribution parameters, respectively establishes suitable detection statistics for the coherent integration samples of the E and L correlators according to the obtained theoretical distribution parameters, and uses the OR principle to make the final decision by comprehensively considering the two detection statistics. On the one hand, it is beneficial to analyze the difference between the E and L coherent integration value distribution characteristics and effectively detect the symmetry change of the correlation peak, and on the other hand, it is beneficial to detect the change of the coherent integration amplitude characteristics of the E or L correlator caused by spoofing signal, which can effectively solve the performance defects of the traditional SQM technology and improve the performance and robustness of the intermediate spoofing attack detection.

[0014] Further, the step 3) uses KS test method to evaluate the difference between the coherent integration samples of the E correlator and the L correlator and the theoretical distribution population respectively.

[0015] The present application uses KS test statistical test method to analyze the change of coherent integration value, which can not only independently process a large amount of coherent integration data of E or L correlator in real time, but also can more sensitively and robustly identify the subtle influence caused by spoofing attack.

[0016] Further, the step 3) further includes converting the obtained test statistic into a variable with uniform distribution by probability conversion, and the converted variable is:

[0017]

[0018]

[0019] wherein D N is the test statistic, N is the total number of samples of the E correlator and the L correlator output in the time window, H is an m x m order matrix describing the CDF, m = 2k-1, is the element of the jth row and the jth column of the nth power of the matrix H, j and h are positive integers, and 0≤h<1.

[0020] The present application converts D N into a uniform distribution Uniform(0, 1) variable p-value by probability conversion p = P(D N ), and then compares the p-value with the significance level γ directly to determine whether to accept the hypothesis H0, which solves the problem that the distribution characteristics of the test statistic D N are difficult to determine, and is beneficial to obtain the test threshold according to the significance level.

[0021] Further, the theoretical distribution parameter in the step 1) is the distribution parameter of the Rice distribution, which is determined by MLE.

[0022] Further, the theoretical distribution parameter determined by MLE is:

[0023]

[0024]

[0025] wherein and are the distribution parameters of the Rice distribution determined by MLE, I k and Q k represent the components of the I and Q branches respectively, k is a sliding interval, and N is the number of samples in the window. The code phase is determined.

[0026] The present application adopts the maximum likelihood estimation (MLE) to calculate the distribution parameters of the Rice distribution, and can quickly and simply determine the theoretical Rice distribution of the E correlator and the L correlator.

[0027] Further, the method further comprises the step of calibrating the theoretical distribution parameters determined by the MLE method by using the QQ plot.

[0028] The present application adopts the Quantile-Quantile (QQ) plot to accurately calibrate the Rice distribution parameters of the coherent integration value, and provides accurate theoretical data for subsequent attack detection and judgment.

[0029] Further, the OR principle is that: if the judgment result of any test statistic in the test statistics of the E correlator and the L correlator is that the GNSS is in the spoofing attack stage, then the GNSS is in the spoofing attack stage; if the judgment results of the test statistics of the E correlator and the L correlator are that the GNSS is not in the spoofing attack stage, then the GNSS is not in the spoofing attack stage.

[0030] Further, the false alarm rate of the OR principle is:

[0031] P FA,OR (alert E ∨alert L |H0)=P(alert E |H0)+P(alert L |H0) E ∧alert L |H0)≤P(alert E |H0)+P(alert L |H0)

[0032] Wherein P FA,OR is the false alarm rate adopted by the OR principle, alert E and alert L respectively represent the alarms of the E and L correlators, H0 represents the no-spoofing attack scene condition, P(alert E |H0) and P(alert L |H0) respectively represent the false alarm rates of the E and L correlators.

[0033] The present application allocates the false alarm rate budget between the decisions of the two test statistics to ensure the overall compliance constraint, so that the OR principle joint can make accurate decisions on whether the spoofing attack exists. BRIEF DESCRIPTION OF DRAWINGS

[0034] Figure 1is a schematic diagram of the process of tracking and peeling off the relevant peaks in the intermediate deception attack phase;

[0035] Figure 2 is a schematic diagram of the graphical definition of D N in the embodiment of the present application;

[0036] Figure 3 is a flowchart of the deception attack detection method based on signal quality monitoring of the present application;

[0037] Figure 4 is a schematic diagram of the QQ plot of the sample data relative to the Rice distribution in the embodiment of the present application;

[0038] Figure 5 is a schematic diagram of the time-domain instantaneous response variation process of the correlation function in the "super-power" frequency unlocking deception attack experiment;

[0039] Figure 6 is the time-domain transient response of the coherent integration value of the E and L correlators in the entire deception attack process in the "super-power" frequency unlocking deception attack experiment;

[0040] Figure 7 is a schematic diagram of the time-domain transient response of the three traditional SQM methods and the KS test-based method in the "super-power" frequency unlocking deception attack experiment;

[0041] Figure 8 is a schematic diagram of the time-domain transient variation of the detection probability in the "super-power" frequency unlocking deception attack experiment;

[0042] Figure 9 is the receiver operating characteristic (ROC) curve of the five detection methods in the "super-power" frequency unlocking deception attack experiment;

[0043] Figure 10 is a schematic diagram of the time-domain instantaneous response variation process of the correlation function in the "low-power" frequency unlocking deception attack experiment;

[0044] Figure 11 is the time-domain transient response of the coherent integration value of the E and L correlators in the entire deception attack process in the "low-power" frequency unlocking deception attack experiment;

[0045] Figure 12 is a schematic diagram of the time-domain transient response of the three traditional SQM methods and the KS test-based method in the "low-power" frequency unlocking deception attack experiment;

[0046] Figure 13 is a schematic diagram of the time-domain transient variation of the detection probability in the "low-power" frequency unlocking deception attack experiment;

[0047] Figure 14 is the receiver operating characteristic (ROC) curve of five detection methods in the “low power” frequency deception attack experiment;

[0048] Figure 15 is the time-domain instantaneous response variation of the correlation function in the “power matching” (+0 dB) carrier phase alignment deception attack experiment;

[0049] Figure 16 is the time-domain transient response of the coherent integration values of the E and L correlators in the entire deception attack process in the “power matching” (+0 dB) carrier phase alignment deception attack experiment;

[0050] Figure 17 is the time-domain transient response of three traditional SQM methods and the KStest-based method in the “power matching” (+0 dB) carrier phase alignment deception attack experiment;

[0051] Figure 18 is the time-domain transient variation of the detection probability in the “power matching” (+0 dB) carrier phase alignment deception attack experiment;

[0052] Figure 19 is the receiver operating characteristic (ROC) curve of five detection methods in the “power matching” (+0 dB) carrier phase alignment deception attack experiment;

[0053] Figure 20 is the variation of the detection quantity p-value under different k in the “power matching” (+0 dB) carrier phase alignment deception attack experiment;

[0054] Figure 21 is the variation of the detection quantity p-value under different time window sizes in the “power matching” (+0 dB) carrier phase alignment deception attack experiment. DETAILED DESCRIPTION

[0055] The specific embodiments of the present application will be further described below with reference to the accompanying drawings.

[0056] Intermediate deception is considered an effective deception attack method, which can initiate a deception attack without interrupting the normal function of the GNSS receiver. The process of tracking the deception signal and stripping the receiver correlation peak is as shown in Figure 1 Figure 1 ​As shown in the upper left, the deceiver probes the target receiver's antenna to estimate the target receiver's position, generates a low-power spoofing signal with an initial code phase offset of more than 2 chips from the real signal, and then gradually approaches the real signal by adjusting the code rate; in the attack (T2), the spoofing signal gradually synchronizes with the code phase of the real signal and keeps a power much smaller than that of the real signal, until Figure 1 As shown in the upper right, the spoofing signal reaches the phase center of the target receiver's antenna and is aligned with the code phase of the real signal (with an error of less than 0.5 chip), which is the signal synchronization process; thereafter, as shown in the lower left, the power and code rate of the spoofing signal are increased, the target receiver is caused to peel off the real signal tracking loop by using the power advantage of the spoofing signal, and the spoofing signal is successfully tracked, which is the signal peeling process; after the attack (T3), as shown in the lower right, the spoofing signal continues to adjust the code rate to pull away from the real signal correlation peak, until the spoofing signal is about 2 chips ahead of the real signal, and then gradually reduces the power to the normal level, and completely controls the target receiver. Figure 1 Figure 1 As shown in the lower right, the spoofing signal continues to adjust the code rate to pull away from the real signal correlation peak, until the spoofing signal is about 2 chips ahead of the real signal, and then gradually reduces the power to the normal level, and completely controls the target receiver. As can be seen from the above, the amplitude or correlation function symmetry of the mixed signal changes obviously in the process of peeling off the real signal correlation peak in the intermediate spoofing attack, and this feature can be used as a basis for detecting spoofing attacks.

[0057] Before the specific implementation process of the present application is described in detail, the signal model of the GNSS receiver is introduced. The receiver converts the radio frequency (RF) signal received by a single antenna into a digital intermediate frequency (IF) signal through a radio frequency front end. The mixed GNSS digital intermediate frequency signal in the tracking stage can be modeled as a combination of digitized signals corresponding to different PRNs, including real satellite signals, spoofing signals and noise, which can be represented as:

[0058]

[0059] where p, τ, φ, f are the satellite signal power, code delay, carrier phase, and carrier Doppler frequency, respectively, D is the navigation data bit, and c represents the nT s instant PRN sequence, T s is the sampling interval, J a and J s represent the real and spoofing signal sets, and η(nT s ) is additive white Gaussian noise (AWGN) with a mean of zero and a variance of σ 2 . The superscripts a and s indicate that the received signals are real and spoofing signals, respectively, and the subscripts m and q indicate the real and spoofing satellite PRN numbers. In the tracking stage, the signal is despread, the receiver correlates the received signal with a local code replica, and then performs low-pass filtering. The correlator output u l [k] is represented as:

[0060]

[0061] where N is the coherent integration interval, k is the number of coherent integrations, kNT s denotes the update time of the correlator output, and denote the code delay and Doppler frequency estimation, respectively. Assuming that the receiver receives the satellite PRN l, the non-coherent tracking receiver correlates the received signal with the local code, and when in the steady tracking state, the local code and the real signal have almost the same carrier frequency and code delay (Δf l a,L ≈0, ). Since the coherent integration time is usually 1 ms, which is much smaller than the length of the data code D (20 ms), the influence of the data code D can be excluded. At this time, the correlator output can be approximately expressed as:

[0062]

[0063] where Δf l a,L 、 denote the phase difference of the lth real signal and the local signal code, the carrier frequency difference, and the initial carrier phase difference, respectively, Δf l s,L 、 denote the phase difference of the lth spoofing signal and the local code, the carrier frequency difference, and the initial carrier phase difference, respectively, and R(·) denotes the normalized cross-correlation function of the real signal or the spoofing signal and the local signal ranging code, which is expressed as formula (4), and a is the amplitude ratio of the spoofing signal to the real signal, which is determined by the spoofing signal to real signal ratio (SSR) and is expressed as formula (5), denotes the variance of the lth correlator output as σ 2 is a low-pass filtered additive Gaussian noise component composed of noise and residual cross-correlation terms with approximately zero-mean Gaussian in-phase (I) and quadrature (Q) phase components.

[0064]

[0065] α = 10 SSR / 20 (5)

[0066] T c denotes a code chip duration, when the code phase difference between the spoofing signal and the real signal is greater than 2 code chips, the correlation peaks of the two ranging codes will not overlap, and the code domain correlator output is a triangular function with a width of 2T c , which is symmetric to zero with code offset.

[0067] When the towed spoofing attack occurs, the spoofing signal and the real signal have the same carrier frequency and carrier phase but different code phases (Δfl a,L = Δf l s,L , ), called "frequency lock". At this time, the in-phase component and the quadrature component of the correlator output can be modeled as:

[0068]

[0069] η I [kNT s ] and η Q [kNT s ] are the Gaussian white noise of the I and Q branches, ignoring the Doppler shift error when the spoofing signal does not exist, η I [kNT s ] and η Q [kNT s ] are uncorrelated, I l and Q l are theoretically subject to Gaussian distribution, which can be expressed as:

[0070]

[0071] μ I , μ Q , respectively represent the mean and variance of the I and Q branch outputs, the covariance σ IQ of the I-Q branch is zero. is the basic variance of the post-correlation noise, N0 is the noise power spectral density, and C / N0 is the carrier-to-noise ratio of the received signal.

[0072] For intermediate spoofing attacks, according to formula (6), the spoofing signal mainly implements the attack by adjusting α, three parameters, and this adjustment has certain time-varying characteristics. Humphreys divides the intermediate spoofing attack into frequency lock and frequency unlock modes according to the adjustment mode of , also known as Doppler consistency spoofing attack and non-consistency spoofing attack.

[0073] For general frequency unlock mode, the carrier phase change rate is proportional to the corresponding code phase change rate, which is expressed as

[0074]

[0075] f RF is the frequency of the radio frequency front-end signal. For higher frequency lock mode, when the relative code delay of the spoofing signal changes, the spoofer will try to align the Doppler frequency of the spoofing signal with the real signal, and the carrier phase difference remains 0 or a constant value (Δf l s,L≈Δf l a,L , However, if the jammer attempts to achieve this alignment within 1 / 6 of the carrier period, it requires precise knowledge of the target receiver antenna position to about 3 cm, imposing a higher requirement on the implementation of the spoofing attack.

[0076] In combination with the above intermediate spoofing attack model, the statistical characteristics of the coherent integration value in the process of intermediate spoofing attack are analyzed below.

[0077] In the non-spoofing attack stage (T1), let The amplitude of the coherent integration Λ can be simplified as:

[0078]

[0079] In the above formula, η I and η Q are calculated to Λ and The Jacobian determinant is

[0080]

[0081] Therefore, the joint probability density of η I and η Q is

[0082]

[0083] By combining the above formula, the joint probability density function of Λ and is

[0084]

[0085] The one-sided integral of formula (12) with respect to the phase is

[0086]

[0087] where I m (μ) is the m-order first-order modified Bessel function, and its definition is:

[0088]

[0089] Taking m as 0, the first-order zero-order modified Bessel function I0(·) of formula (13) is obtained. As described above, the coherent integration amplitude in the non-spoofing stage is subject to the probability density function (PDF) of the Rice distribution of formula (13), and the Rice factor

[0090] In the spoofing attack stage (T2), the specific expression form of the mixed signal Λ under the frequency unlocking attack is

[0091]

[0092] For the frequency-locked spoofing attack, the carrier phase of the spoofing signal is nearly consistent with that of the real signal The above equation can be simplified as

[0093]

[0094] For the code phase offset of the spoofing signal from the real signal, the Rician factor K' can be expressed as

[0095]

[0096] For the frequency-unlocked spoofing attack, it is known from equation (15) that the distribution characteristics of the coherent integration value are different from those of the real signal scenario, and the distribution characteristics are no longer Rician distribution. For the frequency-locked spoofing attack, it is known from equation (16) that only the coherent integration value at a certain moment is considered to be subject to the Rician distribution with the parameter K'. Because α, is unpredictable and variable, the Rician distribution parameter of the coherent integration value is constantly changing. It is worth noting that when the power advantage of the spoofing signal is obvious, that is, the amplitude ratio α is large enough, the changes of equations (15) and (16) mainly depend on At this time, the change of will not have a significant impact on the symmetry of the correlation peak, and the spoofing detection performance of the SQM technology will decrease.

[0097] At the end of the spoofing attack (T3), the correlation peak stripping ends, the receiver stably tracks the spoofing signal, and the power of the spoofing signal gradually decreases to the normal level. During this process, the coherent integration amplitude is irrelevant to the real signal, and the distribution characteristics are similar to those of the real signal scenario (T1), and the Rician factor K" can be expressed as

[0098]

[0099] During this process, the symmetry of the correlation peak will not change, and the SQM technology will completely fail, but due to the continuous adjustment of α, the Rician factor K" is constantly changing, and the distribution characteristics are still different from those of the real scenario.

[0100] From the above process, it can be seen that the change of the symmetry of the correlation peak only occurs in the correlation peak stripping stage, and when the power advantage of the spoofing signal is obvious or at the end of the spoofing attack, the SQM technology has a large performance loss. In addition, during the stage without spoofing attack, the distribution characteristics of the coherent integration value do not change, and during any period of the attack stage, due to the gradual adjustment of the power and code phase of the spoofing signal, the Rician factor changes are always relatively obvious. Therefore, the difference between the distribution characteristics of the coherent integration value caused by the intermediate spoofing attack and those of the real scenario can be used to detect the spoofing attack.

[0101] On this basis, the application provides a spoofing attack detection method of a satellite navigation positioning system. The KStest-based SQM method can be regarded as a binary detection problem. The consistency of the statistical distribution of coherent integration samples and the theoretical distribution without spoofing attack is mainly evaluated. If the detection statistic p-value is less than the specified significant level, it is declared that spoofing attack exists, otherwise, it is indicated that spoofing attack does not exist. In order to solve this binary detection problem, the KStest-based method needs to first determine the theoretical distribution function of the real coherent integration samples, then evaluate the difference between it and the sample empirical distribution function to obtain the test statistic, and finally compare the test statistic with the significant level to make a decision. The overall detection framework is shown in Figure 3 The calibration and evaluation stages are included. The calibration stage is the preliminary of the KS test-based method, mainly completes the estimation and calibration of the coherent integration value PDF parameters in the real scene, and whether the parameter calibration is accurate directly determines the performance of the later evaluation. The evaluation stage mainly evaluates the difference between the coherent integration samples of the E and L correlators and the theoretical distribution population in each time window T i , obtains the corresponding test statistics, and finally makes a comprehensive decision on whether the spoofing attack exists through the OR principle. The specific process of the method is as follows.

[0102] 1. The distribution characteristics of the coherent integration samples of the E correlator and the L correlator without spoofing attack are respectively counted, and the corresponding theoretical distribution parameters are obtained.

[0103] Under the spoofing attack-free scene, the statistical characteristics of the coherent integration samples of the E or L correlator are Rayleigh distribution, and the maximum likelihood estimators of the parameters β and are as follows:

[0104]

[0105] In the formula, I k and Q k represent the components of the I and Q branches respectively. According to the parameter fitting theory distribution function and randomly generating the theoretical distribution samples, then the QQ plot is used to qualitatively judge whether the empirical sample data and the theoretically fitted data come from the same distribution. Each coordinate pair of the defined point position in the QQ plot is composed of the corresponding estimates of the empirical data value and the data value derived from the quantile function of the fitted distribution. Figure 4The QQ plot of sample data relative to the Rice distribution is illustrated as an example. In the non-spoofing attack scenario, all points theoretically fall on the 1:1 diagonal line. The purpose of using the QQ plot in the non-spoofing attack scenario is to qualitatively assess the distribution difference between the empirical distribution data and the fitted theoretical distribution data, and to determine whether the parameter calibration is accurate. If the scatter points in the graph deviate from the diagonal line, it indicates that the data distribution is significantly different, and the MLE parameter estimation step is fed back for correction to ensure the accuracy of the parameter calibration.

[0106] 2. Evaluate the difference between the coherent integration samples of the E and L correlators and the theoretical distribution population in each time window, respectively, to obtain the test statistics of the E and L correlators.

[0107] The detection time window T i is divided into k equal-length sub-intervals b N , and the sample values are sorted in ascending order. i The number of samples falling into each interval b i is counted as the real axis, and the number of samples falling into each interval b k is counted as the imaginary axis, denoted as y N , and the sample empirical cumulative distribution function (ECDF) is expressed as

[0108]

[0109] Assuming F(x) is the sample theoretical cumulative distribution function (TCDF), based on the Neyman-Pearson (NP) detector, the problem of whether a spoofing attack exists is converted into a binary detection problem, which is formulated as follows:

[0110]

[0111] In the non-spoofing attack scenario, S N (x) is an unbiased estimate of F(x), representing the probability of X≤x in N independent repeated experiments. According to the W. Clivenko theorem When the sample size is large enough (N→∞), the degree of agreement between the two sample distributions from the empirical distribution population and the theoretical distribution population is high, and it is reasonable to believe that the sample comes from a specific theoretical distribution population.

[0112] The KS test mainly analyzes the maximum absolute difference between the CDFs of the empirical sample vector and the theoretical sample vector. By comparing with the set threshold, it is determined whether the two sample vectors come from the same distribution population. The test statistic is defined as

[0113] D N = max{|S N (x i) - F(x i |}, i = 1, 2,..., k (22)

[0114] Test statistic D N has distribution characteristics difficult to determine, its graphical definition as shown in Figure 2 is not conducive to determine the test threshold according to the significance level. Marsaglia provides a fast approximation method, by probability conversion p = P(D N < d) to convert D N into a uniform distribution Uniform (0, 1) variable p-value, and then p-value is directly compared with the significance level γ to determine whether to accept the hypothesis H0. For p-value of D N distribution far end (ie p-value > 0.999), the following calculation method significantly improves the calculation efficiency and provides up to 7 decimal places of accuracy.

[0115] In order to evaluate P(D N < d), define

[0116]

[0117] k is a positive integer, 0 ≤ h < 1, then

[0118]

[0119] H is an m x m matrix describing the CDF, m = 2k - 1. is the kth row, kth column element of the nth power of matrix H. As described by Marsaglia, the above way represents the probability as an element in the nth power of the matrix. The decision of the hypothesis test is represented as

[0120]

[0121] The larger the p-value, the more similar the sample vector is to the theoretical distribution population, when , it means that the sample vector is almost identical to the theoretical distribution population.

[0122] For this embodiment, the difference between the coherent integration samples of the E and L correlators and the theoretical distribution population is evaluated in each time window T i , and the obtained test statistics p-value E , p-value L are compared with the test thresholds α E , α LIn comparison, KStest is suitable for both small and large sample detection to some extent, with low computational complexity and good robustness, making it suitable for detecting deception attacks. It is worth noting that the detection performance of KStest is affected by several parameters, such as the number of subintervals k and the size of the time window N.

[0123] 3. Using the OR principle, determine whether the current GNSS receiver is in the deception attack stage based on the test statistics of the E correlator and L correlator.

[0124] The premise of joint decision-making based on the OR principle is to allocate a budget for the false alarm probability (false alarm rate) between the two test statistic decisions to ensure that the population meets the constraints. The false alarm rate P... FA Defined as the conditional probability of an alarm given a threshold, P is the conditional probability of an alarm triggered under the combined OR principle of the two test statistics. FA Defined as:

[0125]

[0126] Therefore, P was obtained by combining the two sets of tests using OR. FA,OR False alarm rate P less than or equal to E and L FA,E P FA,L The sum of . Given the total false alarm rate P. FA,max Then the actual generated P FA,OR Less than or equal to P FA,max Since the E and L correlator samples are equivalent in distribution, P is set... FA,E P FA,L Both are P FA,max Half of it. It's worth noting that, compared to independently setting P... FA,E P FA,L In comparison, the OR principle increases the overall false alarm rate to some extent, therefore P must be set more cautiously. FA,max .

[0127] In summary, the fraud attack detection process of the application is mainly divided into two stages of calibration and evaluation, and the method features are reflected in three aspects: first, the OR principle effectively combines the independent test evaluation results of the coherent integration samples of E and L correlators, which can effectively monitor the shape change of the correlation function caused by low-power advantage fraud attack on the basis of the distribution characteristics of E or L correlator coherent integration samples, and can also monitor the amplitude characteristics change of coherent integration caused by high-power advantage fraud attack, thereby improving the robustness of fraud attack detection; second, based on the accurate calibration of MLE, the high sensitivity of KS test-based SQM method to data distribution change is conducive to accurately identifying the influence caused by fraud attack, thereby improving the sensitivity of fraud attack detection; finally, using coherent integration value samples as the basis for detection, the energy of I and Q branches can be comprehensively utilized, and the problem of energy switching of I and Q branches caused by fraud and real signal carrier phase drift in the frequency unlocking mode can be effectively solved, and the detection performance of the traditional SQM metric is seriously lost.

[0128] Two aspects of analysis are made about the above fraud attack detection method:

[0129] 1) Detection performance analysis.

[0130] Define the false alarm probability P MD The conditional probability of not issuing an alarm under H1. Under the assumption of independence, the total P MD of the two test decisions is combined by the OR principle. It is equal to the product of the single false alarm probability. It is expressed as:

[0131] P MD,OR = P MD,P * P MD,E、L (27)

[0132] The detection probability is:

[0133] P D,OR = 1-P MD,OR (28)

[0134] The comprehensive decision is established by the OR principle, which improves the ability to identify the distortion of the symmetry of the correlation peak and the abnormal power, and the total detection success rate of fraud attack will be improved. However, it should be noted that the OR principle will increase the false alarm rate to some extent, and the implementer needs to be careful to set the detection threshold.

[0135] 2) Analysis of calculation efficiency.

[0136] The computation of the present application mainly concentrates on the MLE parameter estimation process in the calibration phase and the sample evaluation process in each time window in the evaluation phase. The MLE parameter estimation can be implemented only once in the initial phase of the receiver startup, assuming that the slight change of the signal parameters caused by the receiver movement can be ignored, the theoretical distribution parameters obtained by the calibration can remain unchanged for a period of time, therefore, theoretically the calibration process can be implemented only once, of course, the implementer can decide whether to recalibrate within a period of time according to the needs. Therefore, the computation burden of the calibration phase is very small, which is very beneficial to the computation efficiency of the present application. The evaluation phase needs to evaluate the distribution characteristics of the samples in each time window, but the Kstest method adopted by the present application has a simple computation structure, only involving simple multiplication and division operations, therefore, the computation efficiency is very high.

[0137] Experimental verification

[0138] In order to further verify the effectiveness and robustness of the detection method of the present application, the detection performance of the present application in different spoofing scenarios is evaluated qualitatively by simulation below, TEXBAT is a public spoofing database, including two groups of real signal scenarios and eight groups of high-fidelity digital real-time GPS L1 C / A code data sets of different spoofing scenarios, which adopts a sampling rate of 25Msps and high-quality front-end filtering, and can provide frequency steady-state response of more than 20MHz bandwidth near L1. TEXBAT is a fact standard for testing the anti-spoofing performance of GPS receivers, which can support anti-spoofing receivers for these attacks, containing the attributes of eight spoofing scenarios, as shown in Table 1.

[0139] Table 1

[0140]

[0141] Code Phase Proportional in the table represents that the carrier phase of the spoofing signal is proportional to the change of the code phase, Frequency lock mode represents the frequency lock mode, indicating that the initial phase offset between the spoofing and real signals remains unchanged throughout the spoofing scenario, Carrier Phase Aligned represents that the carrier phase of the spoofing signal is accurately aligned with the real signal, Low-Power-Adv. represents signal power advantage spoofing, and Matched represents that the spoofing signal power is matched, but the exact value is unknown.

[0142] The real test is to evaluate the detection method for different carrier phase adjustment mode, different power advantage deception attack detection performance. Scenario 2 and Scenarios 3, 7 represent the frequency unlocked, frequency unlocked mode of deception attack, and Scenario 2, 3, 7 deception signal power advantage gradually decreased, therefore mainly consider Scenario 2, 3, 7 three typical deception attack, in addition, with CleanStatic as the true contrast scene. Don't choose other deception attack scene reason lies in: Scenario 4 and Scenario 3 only exist power small difference, with Scenario 7 only exist carrier phase alignment accuracy weak difference, considering the article space limit, therefore no longer consider Scenario 4; Due to the receiver hardware limitations and the challenges brought by the natural environment, Scenario 5, 6 based on mobile receiver platform deception scene is not considered; In addition, Scenario 1 signal switching attack and Scenario 8 security code estimation attack scene are not considered, which are not related to this study.

[0143] Scenario 2 is "super power" unlocked deception attack, the time domain instantaneous response change process of correlation function is as Figure 5 The "super power" (+10dB) deception signal invades and gradually peels off the lock loop of the victim receiver in the frequency unlocked mode in about 110s to 250s, eventually leading to the code phase difference between the deception and the real signal being 2 chips. After 250s, the deception signal reduces the power and keeps it higher than the real signal power level, and the receiver locks the deception signal stably. It needs to be clarified that Sun et al. study that the deception attack under Scenario 2 only occurs between 150s and 250s, ignoring the 110s to 150s and 250s after the power adjustment stage of the deception signal, but these stages also belong to the deception attack process, and Scenario 3 is similar.

[0144] Figure 6 For the time domain transient response of the coherent integration value of E and L correlators in the whole deception attack process, it can be seen that there is only a slight difference in the coherent integration value of the two correlators. The reason is that the super power advantage deception signal makes the overall value of the correlation function improve significantly, and the "noise filling" effect of the deception signal causes the real signal to be submerged below the noise floor, and the deception signal correlation peak dominates, and the symmetry change of the correlation function is not obvious. In this case, the influence of power advantage on SQM metric fluctuation is much greater than that caused by carrier phase drift. Therefore, Scenario 2 "super power" unlocked deception attack is mainly used to evaluate the influence of power advantage on the detection performance of the method.

[0145] Comparison of time-domain transient response of three traditional SQM methods and KS test-based method under "superpower" frequency-unlocking spoofing attack Figure 7 It can be seen that, between 110s and 250s, due to the interaction between the spoofing and real signals, the symmetry distortion of the mixed signal correlation function causes the fluctuation difference of the measurement values of the four methods to the real scene to different degrees, and the difference in this stage can be used to detect spoofing attacks. After 250s, the receiver locks the spoofing signal, although the spoofing signal still exists signal power adjustment, but due to the locking of the spoofing signal, the correlation function does not exist symmetry distortion, the traditional SQM technology detection fails. It is worth noting that due to the "superpower" frequency locking attack mode of the spoofing signal, the fluctuation of the traditional SQM metric is not obvious, but the measurement value of the KS test-based method fluctuates significantly, and the E and L fluctuation changes are mostly consistent, because the KS test-based method additionally monitors the amplitude change of the coherent integration value of the E and L correlators, which makes up for the detection performance loss of the SQM technology caused by the not obvious symmetry distortion. Therefore, the KS test-based SQM method produces more sensitive and stable detection quantity changes during the entire spoofing process.

[0146] Figure 8 For the comparison of the time-domain transient changes of the detection probability in the entire process, the false alarm rate of the traditional SQM metric and the Ratio corresponding to the MV-based method is set to 10%, and the false alarm rate budget of the KS test-based method is set to 0.001%. From the figure, it can be seen that during the first 110s, except that the KS test-based method is more sensitive to noise and the false alarm rate fluctuates more obviously, but overall, the false alarm rates of the five methods are consistent with the settings. During the 110s to 300s spoofing attack stage, due to the influence of carrier phase drift and high power advantage, the detection probability of the three traditional SQM metrics is below 60%, the detection probability of the MV-based method is improved to a certain extent compared with the Ratio metric, but most of the time is below 80%, and the detection probability of the KS test-based method reaches 100% at 120s, with excellent detection performance. After 300s, only the KS test-based method can capture the weak power adjustment change of the spoofing signal. Therefore, the KS test-based SQM technology method has good advantages in detection sensitivity.

[0147] In order to more comprehensively evaluate the detection performance of the method, Figure 9Receiver operating characteristic (ROC) curves for the five detection methods are plotted for detection time ranging from 110 s to 400 s. Compared with the three traditional SQM metrics and the MV-based method corresponding to the Ratio, the detection probability of the KS test-based method is significantly improved at different false alarm rates. It is worth noting that the detection probability is improved more obviously at a low false alarm rate (such as 1%), and has good application value for receiver deception early warning (the actual false alarm rate is generally set to 1%).

[0148] Table 2 compares the first alarm time delay (after the occurrence of a deception attack), the detection probability under the condition of a false alarm rate of 10%, and the method running time of the five detection methods. Compared with the three traditional SQM metrics, the alarm time delay and detection probability of the KS test-based method are significantly improved. Compared with the MV-based method with the best detection performance, although the KS test-based method takes more time of 0.026 s, the detection probability is significantly improved by 27.71%, and the deception attack alarm time delay is equal. It is worth noting that the 0.026 s increase in operation time has a negligible effect on deception detection. The above can prove that the KS test-based SQM method has superior detection performance under the "superpower" frequency unlocking mode deception attack.

[0149] Table 2

[0150]

[0151] In order to further better evaluate the detection performance of the method under different frequency locking modes and power advantage deception attacks, the following uses Scenario 3 "low power" (+1.3 dB) frequency locking deception attack scene to test the five methods. Figure 10 For the time-domain transient response change of the correlation function, Scenario 3 is similar to Scenario 2, except that the power advantage of the deception signal is reduced from 10 dB to 1.3 dB after 100 s, and the frequency locking mode of the deceiver is enabled. Compared with Scenario 2, the fluctuation change of the correlation function is more significant without changing the carrier phase and keeping a low power advantage.

[0152] Figure 11For the time-domain transient response of the coherent integration values of the corresponding E and L correlators, the power of the spoofing signal is boosted during 100s-200s, and the symmetry of the correlation function is mainly affected by the power advantage. During 200s-300s, the main reason for the distortion of the symmetry is the constant carrier phase. After 300s, the receiver locks the spoofing signal, and at this time there is only power adjustment. If the distortion of the symmetry and the change of the coherent integration amplitude are comprehensively monitored, the detection performance will be further improved. Scenario 3 can be compared with Scenario 2 to evaluate the comprehensive influence of power advantage and constant carrier phase on the detection performance of the method under the frequency-locked spoofing attack of “low power”.

[0153] Figure 12 The time-domain transient responses of the traditional SQM method and the KS test-based method under Scenario 3 are plotted. It can be observed that during 100s-200s, the changes of the three traditional SQM metrics are less than the normal level, because the power of the spoofing signal is increased, which leads to the increase of the carrier-to-noise ratio of the mixed signal, and then the fluctuation of the traditional SQM metric is small, which causes the detection performance loss of the traditional SQM metric. In contrast, the KS test-based method always changes significantly, because it can detect the change of the coherent integration amplitude characteristics. During 200s-300s, due to the distortion of the symmetry of the correlation function caused by the frequency locking of the spoofing and real signals, the fluctuations of the four methods are relatively obvious. After 300s, the spoofing signal is gradually reduced to the normal level, and the fluctuation of the SQM metric changes little, while the obvious change of the KS test-based method can still be reflected on the L correlator. Therefore, using the KS test-based method to perform detection on the E and L correlators respectively can have good sensitivity to the influence caused by the distortion of the correlation function symmetry and the power boost.

[0154] Figure 13 For the comparison of the time-domain transient changes of the detection probabilities of the traditional SQM metric, the MV-based method and the KS test-based method during the whole process, the false alarm rate is set to be consistent with Scenario 2. It can be observed that during the whole spoofing attack period after 100s, the detection probability of the KS test-based method reaches 100% most of the time, and compared with the other four methods, the advantage is particularly reflected during the power adjustment period of the spoofing signal from 100s to 200s. In this case, the detection probability of the traditional SQM metric decreases to below the false alarm rate of 10%, and compared with the MV-based method, the detection probability of the KS test-based method is higher than 90% during the whole process. Figure 12with the analysis, the detection probability of MV-based and KS test-based method both reach above 95. Since the detection performance of MV-based method declines seriously after 200s, the overall detection performance of KS test-based method is better than MV-based method. It is worth noting that the detection probability of KS test-based method reaches 100% within 20s after the occurrence of spoofing attack, which is not inferior to other four methods in terms of detection sensitivity. Figure 14 The ROC curves of five detection methods are compared. It can be observed that the overall detection probability of KS test-based method reaches above 90%, which is significantly better than other four detection methods. Different from Scenario 2, the detection probability decreases when the false alarm rate is less than 20%, because in Scenario 3 the spoofing signal can more accurately adjust the power close to the real level after 300s.

[0155] Similar to Scenario 2, Table 3 is the performance comparison of five detection methods under the "low power" frequency locking spoofing attack mode in Scenario 3. Through comparison, it can be seen that KS test-based method has great advantages in detection probability and alarm time delay compared with traditional SQM metric. Compared with MV-based method with better detection performance, the detection performance is improved by 17.71% without spending 0.025s of method running time, and the alarm time delay is equal. Therefore, KS test-based method has good detection sensitivity and detection efficiency under the "low power" frequency locking spoofing attack mode.

[0156] Table 3

[0157]

[0158] Next, Scenario 7 is used to further evaluate the performance of the method under the "power matching" (+0dB) carrier phase alignment spoofing attack mode, Figure 15 The time domain transient change of the mixed signal correlation function. This scenario is similar to Scenario 3, except that the spoofing signal power is accurately matched with the real signal, and the carrier phase between the spoofing and real signals is accurately calibrated, so after the occurrence of spoofing attack (110s) Figure 15 The correlation function change in is more subtle.

[0159] Figure 16The changes in the coherent integral values ​​of the E and L correlators were plotted. Compared to Scenario 2, Scenario 7 exhibits predominantly symmetry distortion in its correlation function. This is because the spoofing matches the power of the real signal and the carrier phase is precisely aligned. Under these conditions, the SQM metric is expected to achieve better detection performance. Notably, between 110s and 160s, similar to Scenario 3, the carrier-to-noise ratio of the mixed signal increases due to the phase alignment of the spoofing with the real signal code, resulting in a simultaneous decrease in the coherent integral values ​​of E and L. Symmetry distortion is not significant. Adding an amplitude monitoring module during this period would improve detection performance. The more advanced "power matching" spoofing attack mode in Scenario 7 can be compared with Scenario 2 to evaluate the impact of the low-power advantage on detection performance. Furthermore, the carrier phase alignment spoofing attack can be compared with Scenario 3 to evaluate the impact of alignment accuracy on the method's detection performance.

[0160] Figure 17 The time-domain transient responses of the traditional SQM metric and the KStest-based method under the "power-matched" carrier phase alignment spoofing attack mode were plotted. The three traditional SQM metrics showed varying degrees of change after 110 s, with more pronounced changes after 160 s. In the KStest-based method, the E-correlator showed a more significant change than the L-correlator. Figure 16 This is consistent because the correlation peak stripping is directed towards the E correlator. Compared to Scenario 2 and Scenario 3, the fluctuations of the four detection methods are more significant. Figure 18 The transient changes in detection probability over time were compared using the traditional SQM metric, MV-based, and KS test-based methods, with the false alarm rate set consistent with the aforementioned scenario. Compared to the Delta metric, which performs best among traditional SQM techniques, the KS test-based method's detection performance advantage is mainly evident between 110s and 200s, during which the correlation function symmetry distortion is not significant. The KS test-based method compensates for the performance deficiencies of the SQM metric by detecting changes in the coherent integral amplitude, thus shortening the alarm time and improving the detection probability. Compared to the MV-based method, the KS test-based method shows a significant improvement in detection probability, essentially reaching 100%. Therefore, the KS test-based method is not only effective in quantifying the correlation function symmetry distortion but also improves the detection probability by detecting changes in the coherent integral amplitude.

[0161] Figure 19The ROC curves of the five detection methods are compared. It can be observed that the overall detection performance of the KS test-based method is better than that of the other four detection methods, and the detection probability can reach nearly 100% under different false alarm rates. The detection probability is more obvious under low false alarm rates (such as 10%). Therefore, the overall detection performance of the KS test-based method is more outstanding.

[0162] Table 4 is the statistical results of several detection performance indicators of the five methods. Compared with the traditional SQM metric, the KS test-based method has obvious improvement in alarm time and detection probability. Compared with the MV-based method with the best detection performance, the additional 0.026s operation time is negligible, but the alarm time delay is shortened by 20s, and the detection probability is improved by 23.72%. In summary, under the "power matching" carrier phase alignment deception attack mode, the KS test-based method can not only shorten the alarm time, but also improve the detection probability, which helps the receiver to alarm the deception attack more quickly and accurately.

[0163] Table 4

[0164]

[0165] Several parameters that affect the performance of the KS test.

[0166] 1) The number of sub-intervals k.

[0167] Detection time window T i The N samples are divided into k equal-length sub-intervals, and k is limited by the sample size N (k≤N), but also affects the sensitivity of the KS test method to detect deception attacks. Figure 20 The detection quantity p-value results under Scenario 7 after changing k are plotted. It can be seen that the detection quantity p-value increases exponentially with the increase of k, so increasing k is significant for improving the detection sensitivity. It is worth noting that as k increases, not only the sample size N is required to be larger, but also the computational burden of the evaluation process is increased.

[0168] 2) The size of the time window T.

[0169] The time window is divided into a calibration time window T j and a detection time window T i . The reliability of the detection results of the non-parametric KS test depends on the parameter calibration accuracy, T jThe larger the sample size used for calibration, the higher the parameter calibration accuracy, and the more reliable the detection result. However, the MLE method is used to improve the parameter calibration accuracy in the calibration phase, which improves the reliability of the detection result, so the impact of the size of T j can be ignored. The detection time window T i is generally much smaller than T j . Figure 21 The change in p-value after changing T i under Scenario 7 is shown. Before 110s, as T i decreases, the impact of system noise increases, and p-value gradually deviates from the set false alarm rate. After 110s, changing T i has no effect on the overall trend of the detection quantity. The reason is that the accuracy of the MLE parameter calibration ensures that the false alarm rate meets the requirements under the no-fraud scenario, and improves the stability of the detection result under different T i . It is worth noting that the smaller T i , the shorter the alarm time delay. The implementer can make a comprehensive trade-off between the false alarm rate budget and the alarm time delay to reasonably select the size of the detection time window T i .

[0170] 3) False alarm rate budget P FA,max .

[0171] According to the principle of the NP detector, P FA,max directly determines the size of the detection threshold. For the KS test-based method, increasing the detection threshold is beneficial to improving the detection effect, but it is easy to cause the false alarm rate to increase, and reducing the detection threshold is easy to cause the detection effect to decline. Neither too large nor too small threshold is conducive to effectively distinguishing whether a fraud attack exists, and the implementer needs to reasonably set P FA,max according to actual needs.

[0172] In view of the problem that the detection performance of the traditional SQM technology is easily affected by the power advantage of the spoofing signal and the phase drift of the true and false signals, resulting in loss of detection performance, the KS test-based SQM spoofing attack detection method is provided, which can be used for detecting various power advantages and various frequency locking mode intermediate spoofing attacks. Detailed steps of the spoofing attack detection are given: calibration and evaluation, the core of the method is to evaluate the difference between the empirical distribution and the theoretical distribution characteristics of the E and L coherent integration values respectively, and finally the integrated decision is fused through the OR principle. Through the TEXBAT dataset Scenario 2, 3, 7 different power advantage, different frequency locking mode spoofing attack scene test, and compared with three kinds of traditional SQM metric and MV-based SQM method, the results show that, compared with the MV-based SQM method with better detection performance, the detection probability of the KStest-based SQM method is increased by about 20% under the condition of 10% false alarm rate, and the spoofing alarm delay time is also better than the other four methods. In addition, the factors influencing the detection performance of the new method are analyzed in detail.

[0173] Therefore, the present application can not only effectively detect the symmetry distortion of the correlation function, but also monitor the power change of the spoofing signal, make up for the deficiency of the detection performance of the traditional SQM technology, and has excellent detection sensitivity and robustness under different modes of spoofing attacks. In addition, the new method does not need to change the receiver hardware, and has low computational complexity, and has good potential application value for studying the receiver equipped with an anti-spoofing performance module.

Claims

1. A spoofing attack detection method based on signal quality monitoring, characterized in that, The detection method includes the following steps: 1) Statistically analyze the distribution characteristics of coherent integral samples of the E-correlator and L-correlator in the non-spoofing attack phase, and obtain the corresponding theoretical distribution parameters; 2) Obtain the output values ​​of the E-correlator and L-correlator during the tracking phase of the GNSS receiver; 3) Using the KS test method, the differences between the empirical and theoretical cumulative distribution functions of the E and L correlators are evaluated within each time window based on their output values, yielding the test statistics for each correlator. The empirical cumulative distribution function is determined by dividing the coherent integral sample sequence into k equal-length sub-intervals after sorting it from smallest to largest, counting the number of samples falling into each sub-interval, and summing the proportions of the number of samples falling into each sub-interval to the total number of coherent integral samples. The test statistics are then transformed into uniformly distributed variables through probability transformation. The transformed variables are: ; ; in It is the test statistic, where N is the total number of samples within the time window output by the E-correlator and L-correlator, and H is... The matrix of order describing CDF, , Let h be the element in the j-th row and j-th column of matrix H raised to the power of n, where j and h are both positive integers. ; 4) Using the OR principle, determine whether the current GNSS receiver is in the spoofing attack stage based on the test statistics of the E correlator and L correlator.

2. The spoofing attack detection method based on signal quality monitoring according to claim 1, characterized in that, The theoretical distribution parameters in step 1) are the distribution parameters of the Rice distribution, determined using the MLE method.

3. The spoofing attack detection method based on signal quality monitoring according to claim 2, characterized in that, The theoretical distribution parameters determined by the MLE method are: ; in and The distribution parameters of the Rice distribution determined using the MLE method are: and Let I and Q represent the components of the I and Q branches, respectively, and N be the number of samples within the window. This refers to the code phase.

4. The spoofing attack detection method based on signal quality monitoring according to claim 2, characterized in that, The method also includes a step of calibrating the theoretical distribution parameters determined by the MLE method using QQ plot.

5. The spoofing attack detection method based on signal quality monitoring according to any one of claims 1-4, characterized in that, The OR principle is as follows: if the result of any test statistic of the E correlator and L correlator is that the GNSS is in the deception attack stage, then the GNSS is in the deception attack stage; if the result of the test statistics of the E correlator and L correlator are both that the GNSS is not in the deception attack stage, then the GNSS is not in the deception attack stage.

6. The spoofing attack detection method based on signal quality monitoring according to claim 5, characterized in that, The false alarm rate of the OR principle for: ; in The false alarm rate used in the OR principle. and These represent alarms from the E and L related devices, respectively. This indicates a scenario where there is no deception attack. and These represent the false alarm rates of the E and L correlators, respectively.