A method and system for testing the communication security of a drone, and an electronic device
By using a drone communication security testing method, the flight status of drones can be judged in real time, which solves the problem of interference from forged information in drone communication and ensures the security and reliability of drone communication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- FIFTH ELECTRONICS RES INST OF MINIST OF IND & INFORMATION TECH
- Filing Date
- 2022-11-30
- Publication Date
- 2026-04-21
AI Technical Summary
When drones communicate wirelessly with their flight control systems, they are susceptible to interference from forged control information, which prevents ground-based remote control equipment from determining the drone's flight status in real time.
A method for testing the communication security of unmanned aerial vehicles (UAVs) is provided. This method involves receiving a data test request from the control terminal, obtaining a data identifier, selecting target test data, and conducting data testing based on the data type settings to determine whether the UAV communication is normal.
It enables real-time assessment of the drone's flight status and evaluates the drone's communication security, ensuring the safety and reliability of drone communication.
Smart Images

Figure CN115913737B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of unmanned aerial vehicle (UAV) communication technology, and in particular to a UAV communication security testing method, system, and electronic device. Background Technology
[0002] With the development of industrial and communication technologies, more and more intelligent devices are being used in daily life, bringing convenience. For example, drones can be used in fields such as crop protection, search and rescue, inspection, and panoramic photography.
[0003] In daily life, a drone typically consists of five main parts: the fuselage, the power system, the flight control system, the link system, and the payload. The flight control system receives commands from the ground remote control equipment via wireless communication. Then, the flight control system distributes the received commands to the drone's power system, link system, and payload. Finally, the flight control system receives feedback information from the power system, link system, and payload, and transmits the feedback information back to the ground remote control equipment so that the ground remote control equipment can judge the drone's flight status based on the feedback information.
[0004] It is evident that while drones bring convenience to life, their control relies on a flight control system. Furthermore, the flight control system is susceptible to interference from forged control information during wireless communication. Consequently, ground remote control equipment cannot obtain timely feedback from the power system, link system, and mission payload, thus failing to determine the drone's flight status in real time.
[0005] Therefore, there is an urgent need for a testing method to determine in real time whether the drone's flight status is normal. Summary of the Invention
[0006] This invention application provides a method, system, and electronic device for testing the communication security of unmanned aerial vehicles (UAVs), used to determine the flight status of UAVs in real time and assess their communication security. The specific technical solution is as follows:
[0007] Firstly, this application provides a method for testing the communication security of unmanned aerial vehicles (UAVs), including:
[0008] Receive a data test request sent by the control terminal, and obtain the data identifier of the data to be tested from the data test request;
[0009] Select the target test data that matches the data identifier from the candidate test data set;
[0010] Based on the data testing method set according to the data type of the target test data, data testing is performed on the target test data to obtain the corresponding data test results;
[0011] When the data test results are determined to meet the communication security conditions associated with the data type of the target test data, the communication of the UAV is determined to be normal.
[0012] The above methods enable real-time assessment of the drone's flight status and evaluation of its communication security.
[0013] In one possible design, the target test data is port attribute data. The data testing method based on the data type corresponding to the target test data, performing data testing on the target test data, includes:
[0014] Obtain the interface type of the port attribute data and install the driver that matches the interface type; wherein, the port attribute data represents: the port configuration information of each type of network port;
[0015] The driver obtains management permissions for various network ports, and based on the obtained management permissions, selects target network ports that meet preset port operating conditions from among the various network ports.
[0016] Based on the target network port and the data testing method corresponding to the data type, the port attribute data is tested.
[0017] The above method can be used to filter out target network ports that meet the preset operating conditions and test the port attribute data.
[0018] In one possible design, the process of performing data testing on the port attribute data further includes:
[0019] Scan each sub-port corresponding to the target network port to determine the service type corresponding to each sub-port.
[0020] Based on the port testing methods associated with each service type, the sub-ports are tested.
[0021] The above method allows for scanning of each sub-port corresponding to the target network port, determining whether each port has vulnerabilities and the type of vulnerabilities.
[0022] In one possible design, the target test data is port transmission data. The data testing method based on the data type corresponding to the target test data, performing data testing on the target test data, includes:
[0023] When extracting the corresponding port transmission data from the target network port, the security level of the port transmission data is determined based on the set type of the data feature set corresponding to the port transmission data.
[0024] Based on the security level and the data testing method corresponding to the data type, data transmission data is tested on the port.
[0025] The above methods enable corresponding data tests to be performed on the data transmitted through each port.
[0026] In one possible design, if the port transmission data is flight control data, then after extracting the corresponding port transmission data from the target network port, the process further includes:
[0027] The flight control data is analyzed for communication format to obtain the control data packets corresponding to each flight state of the UAV.
[0028] By comparing the obtained control data packets, the field information of the control data packets is determined, wherein the field information includes at least a sequence number field and a control command field;
[0029] Modify the field information of the control data packet to obtain the test data packet;
[0030] The communication security of the UAV is tested based on the test data packet, and the corresponding test results are obtained.
[0031] Using the above method, the field information of each control data packet can be identified, the field information can be modified, and changes in the drone's flight status can be determined.
[0032] In one possible design, prior to performing communication format analysis on the flight control data, the following steps are also included:
[0033] Extract the firmware of the target network port and check whether the data transmitted through the port contained in the firmware is encrypted;
[0034] If the data transmitted through the port is encrypted, a preset program analysis algorithm is used to test whether the password for the data transmitted through the port can be obtained.
[0035] If the data transmitted through the port is not encrypted, then test whether the data transmitted through the port can be tampered with.
[0036] The above methods can be used to test the communication security of data transmitted through the drone's port.
[0037] Secondly, this application provides a drone communication security testing system, comprising:
[0038] The data acquisition module is used to receive data test requests sent by the control terminal and obtain the data identifier of the data to be tested from the data test requests;
[0039] The data extraction module is used to select target test data that matches the data identifier from the candidate test data set;
[0040] The data testing module is used to perform data testing on the target test data based on the data testing method set according to the data type of the target test data, and obtain the corresponding data test results.
[0041] When the data test results are determined to meet the communication security conditions associated with the data type of the target test data, the communication of the UAV is determined to be normal.
[0042] In one possible design, the port transmission data is flight control data. After extracting the corresponding port transmission data from the target network port, the data testing module is further used for:
[0043] The flight control data is analyzed for communication format to obtain the control data packets corresponding to each flight state of the UAV.
[0044] By comparing the obtained control data packets, the field information of the control data packets is determined, wherein the field information includes at least a sequence number field and a control command field;
[0045] Modify the field information of the control data packet to obtain the test data packet;
[0046] The communication security of the UAV is tested based on the test data packet, and the corresponding test results are obtained.
[0047] Thirdly, this application provides an electronic device, comprising:
[0048] Memory, used to store computer programs;
[0049] When the processor executes the computer program stored in the memory, it implements the steps of the above-described UAV communication security testing method.
[0050] Fourthly, this application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the above-described UAV communication security testing method.
[0051] For the various aspects of the second to fourth aspects mentioned above, and the technical effects that each aspect may achieve, please refer to the above description of the technical effects that can be achieved for the first aspect or the various possible solutions in the first aspect, which will not be repeated here. Attached Figure Description
[0052] Figure 1 A flowchart of a UAV communication security testing method provided in this application;
[0053] Figure 2 This is a schematic diagram of the UAV communication security testing system architecture provided in this application;
[0054] Figure 3 This application provides a schematic diagram of the structure of an unmanned aerial vehicle (UAV) communication security testing system.
[0055] Figure 4 This is a schematic diagram of the structure of an electronic device provided in this application. Detailed Implementation
[0056] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The specific operational methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of this application, "multiple" is understood as "at least two". "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. A connected to B can represent: A and B directly connected, and A and B connected through C. Furthermore, in the description of this application, terms such as "first" and "second" are used only for distinguishing the purpose of description and should not be construed as indicating or implying relative importance or order.
[0057] The embodiments of this application will now be described in detail with reference to the accompanying drawings.
[0058] With the development of industrial and communication technologies, more and more intelligent devices are being used in daily life, bringing convenience. For example, drones can be used in fields such as crop protection, search and rescue, inspection, and panoramic photography.
[0059] In daily life, a drone typically consists of five main parts: the fuselage, the power system, the flight control system, the link system, and the payload. The flight control system receives commands from the ground remote control equipment via wireless communication. Then, the flight control system distributes the received commands to the drone's power system, link system, and payload. Finally, the flight control system receives feedback information from the power system, link system, and payload, and transmits the feedback information back to the ground remote control equipment so that the ground remote control equipment can judge the drone's flight status based on the feedback information.
[0060] It is evident that while drones bring convenience to life, their control relies on a flight control system. Furthermore, the flight control system is susceptible to interference from forged control information during wireless communication. Consequently, ground remote control equipment cannot obtain timely feedback from the power system, link system, and mission payload, thus failing to determine the drone's flight status in real time.
[0061] Therefore, there is an urgent need for a testing method to determine in real time whether the drone's flight status is normal.
[0062] In view of this, in order to determine the flight status of the UAV in real time and assess its communication security, this application provides a UAV communication security testing method, which specifically includes: first, receiving a data test request sent by the control terminal, and obtaining the data identifier of the data to be tested from the data test request; then, selecting the target test data that matches the data identifier from the candidate data set; then, performing data testing on the target test data based on the data test method set according to the data type of the corresponding target test data, obtaining the corresponding data test results; and finally, determining that the UAV's communication is normal when the data test results meet the communication security conditions associated with the data type of the target test data.
[0063] It is easy to see that, through the above method, based on the data identifier in the data test request sent by the control terminal, the target test data that matches the data identifier can be tested according to the data test method set according to the data type of the target test data, and the corresponding data test results can be obtained. Finally, the data test results are determined to be normal when they meet the communication security conditions associated with the target test data type. In this way, the flight status of the drone can be judged in real time, and the communication security of the drone can be assessed.
[0064] Reference Figure 1 The diagram shown is a flowchart of a UAV communication security testing method provided in an embodiment of this application. The method includes:
[0065] S1 receives a data test request sent by the control terminal and obtains the data identifier of the data to be tested from the data test request.
[0066] Firstly, the method provided in this application can be applied to Figure 2 The system architecture shown includes a drone 201, a camera 201a, a server 201b, a control terminal 202, and various functional modules of the drone (not shown in the figure).
[0067] This application embodiment does not impose any limitation on the number of the above-mentioned devices, such as Figure 2As shown, this description only takes the drone, camera, server, control terminal, and various functional modules of the drone as examples. The following is a brief introduction to the above-mentioned devices and their respective functions.
[0068] The camera is used to collect aerial image data and store it in the drone's memory. The server receives data test requests from the remote control device, obtains the data identifier of the data to be tested from the data test request, selects the target test data that matches the data identifier, performs data testing on the target test data according to the data test method set for the corresponding data type, and obtains the corresponding data test results. The control terminal sends data test requests to the server, receives the data test results from the server, and determines that the drone's communication is normal when the data test results meet the communication security conditions associated with the data type of the target test data.
[0069] In practical applications, before sending a data test request, the control end needs to clarify the drone's operation method, communication method, and upgrade method in order to test the target test data of various types of drones.
[0070] Specifically, the drone can be controlled by a mobile phone, a remote control, a mobile phone wirelessly connected to a remote control, or a mobile phone wired connected to a remote control. This application does not impose any restrictions on the drone's control method, and will not elaborate further here.
[0071] The communication methods for drones can be 2.4G, Bluetooth, and WiFi.
[0072] Drones can be upgraded via APP upgrade, SD card upgrade, or computer connection upgrade.
[0073] In this embodiment of the application, after clarifying the control method, communication method and upgrade method of the UAV, the server receives the data test request sent by the control terminal and obtains the data identifier of the data to be tested from the data test request.
[0074] For example, the data identifier can be the data identifier of each network port attribute assigned to each functional module of the UAV, as well as the data identifier corresponding to the data transmitted by each network port. For instance, the UAV's flight control module is assigned control ports 1, 2, and 3. Control port 1 has a corresponding port attribute data identifier Type1.1, control port 2 has a corresponding port attribute data identifier Type1.2, and control port 3 has a corresponding port attribute data identifier Type1.3. The data identifier corresponding to the data transmitted by each network port refers to the data identifier Type1.11 corresponding to the control data Data1.11 transmitted by control port 1.
[0075] Therefore, by using the above method, it is possible to obtain the data identifiers of the network port attributes assigned to each functional module of the UAV, as well as the data identifiers corresponding to the data transmitted by each network port.
[0076] S2, select the target test data that matches the data identifier from the candidate test data set.
[0077] In this embodiment of the application, after the server obtains the data identifiers of each network port attribute and the data identifiers corresponding to the data transmitted by each network port, it can select the target test data that matches the data identifier from the candidate data set. For example, assuming that the data identifier obtained by the UAV is Type1.1, the target test data is the port attribute data corresponding to control port 1. The port attribute data corresponding to control port 1 includes the configuration information of control port 1. The configuration information includes at least IP address information, port open status information and operating frequency band information, which will not be elaborated here.
[0078] It should be noted that the candidate test dataset can be the raw data inherent in the UAV, which includes the system's resource allocation information and the built-in code programs of each functional module.
[0079] Therefore, after obtaining the data identifier of the data to be tested, the server can select the target test data that matches the data identifier. That is, based on the data identifier, it can determine whether the target test data is the data of each network port attribute allocated by each functional module, or the data transmitted by each network port.
[0080] S3, based on the data type settings of the corresponding target test data, performs data testing on the target test data and obtains the corresponding data test results.
[0081] In one possible implementation, when performing step 3, the target test data is port attribute data. The interface type of the port attribute data is obtained, and the driver that matches the interface type is installed. Through the driver, management permissions for various network ports are obtained, and based on the obtained management permissions, target network ports that meet the preset port operating conditions are selected from various network ports. Based on the data test method corresponding to the target network port and data type, data testing is performed on the port attribute data.
[0082] In this embodiment of the application, in order to test the port attribute data, it is first necessary to obtain the interface type of the port attribute data. For example, for drones designed using the Android operating system, a driver matching the communication interface type provided by the Android system can be downloaded, and the port attribute data corresponding to each functional module of the drone can be viewed through the driver. For drones that use the Remote Network Driver Interface Specification (RNDIS) for communication, the driver corresponding to RNDIS can also be downloaded to view the port attribute data corresponding to each functional module of the drone. Here, there are no specific restrictions on the interface type of drone communication, and they will not be elaborated further.
[0083] Then, after installing the driver that matches the interface type of the port attribute data, management permissions for various network ports can be obtained through the driver. The obtained management permissions are shown in Table 1 below:
[0084]
[0085] Table 1
[0086] Finally, with the management permissions obtained as shown in Table 1, target network ports that meet the preset port conditions are selected from various network ports. For example, in Table 1, the target network port (Type 1) corresponds to port 1 and port 2; the target network port (Type 2) corresponds to port 11 and port 13.
[0087] By using data testing methods corresponding to the target network port and data type, data testing of port attribute data can be performed to test the security configuration of port attribute data or to test the operation permissions of port attribute data.
[0088] The above method can be used to filter out target network ports that meet the preset operating conditions and test the port attribute data.
[0089] In one possible implementation, during the data testing of port attribute data, each sub-port corresponding to the target network port is scanned to determine the service type corresponding to each sub-port; based on the port testing methods associated with each obtained service type, each sub-port is tested.
[0090] In this embodiment of the application, after the server filters out the target network port that meets the preset operating conditions, it can also use a vulnerability scanning tool to scan each sub-port corresponding to the target network port to determine the service type of each sub-port.
[0091] After determining the service type of each sub-port, each sub-port can be tested using the port testing methods associated with each service type. The tests include weak password testing, vulnerability testing of each sub-port, and functional testing that affects the flight safety of the drone.
[0092] The above method allows for scanning of each subport corresponding to the target network port, determining whether vulnerabilities exist in each subport and the type of vulnerabilities.
[0093] In one possible implementation, the target test data is port transmission data. When the corresponding port transmission data is extracted from the target network port, the security level of the port transmission data is determined based on the set type of the data feature set corresponding to the port transmission data. Based on the security level and the data test method corresponding to the data type, the port transmission data is tested.
[0094] In this embodiment, after scanning each sub-port corresponding to the target network port, the server can attempt to extract the corresponding port transmission data from the target network port, such as Data1.11 in Table 1. Each port transmission data Data1.xx corresponds to a set type of data feature set. If some attack programs attempt to attack the port transmission data and obtain a portion of the port transmission data in the target network port, the security level of the port transmission data can be determined based on the threshold range of the obtained port transmission data. For example, if the port transmission data corresponding to the image transmission screen and sensor gyroscope can be obtained, the communication status of the port transmission data corresponding to the image transmission screen and sensor gyroscope is determined to be a moderately dangerous state; if the port transmission data corresponding to flight control authority and flight plan formulation can be obtained, the communication status of the port transmission data corresponding to flight control authority and flight plan formulation is determined to be a highly dangerous state.
[0095] Based on the security level and data type corresponding to the data testing method, data testing is performed on the port transmission data. It can also be used to perform data modification testing, firmware extraction testing, and communication network attack testing on the port transmission data corresponding to a certain data type.
[0096] The above methods enable corresponding data tests to be performed on the data transmitted through each port.
[0097] In one possible implementation, if the port transmission data is flight control data, then after extracting the corresponding port transmission data from the target network port, the flight control data is analyzed for communication format to obtain the control data packets corresponding to each flight state of the UAV; the obtained control data packets are compared to determine the field information of the control data packets, the field information of the control data packets is modified to obtain test data packets; the communication security of the UAV is tested based on the test data packets to obtain the corresponding data test results.
[0098] In this embodiment, the data extraction method for port-transmitted data can be determined by the data transmission and reception method of the port. For example, for radio frequency signals, the data extraction method for port-transmitted data can be determined based on the operating frequency band, modulation method, data format, and operating mode of the radio frequency signal; for sending control signals using a mobile APP, network data acquisition and analysis tools can be used to intercept data packets transmitted in the network and perform communication protocol analysis on the obtained data packets.
[0099] When performing communication analysis on data packets, the server can first extract the first control data packets, second control data packets, and third control data packets corresponding to the startup, ascent, and descent states, respectively. Then, by comparing the control data packets corresponding to the same flight state, such as the first control data packets, and examining the changing fields in each first control data packet, it can determine whether the first control data packet contains a check field and checksum algorithm, and can also identify the sequence number field of the first control data packet. Finally, by comparing the control data packets corresponding to different flight states, such as the first control data packet and the second control data packet, the control command fields in the control data packets can be identified.
[0100] It should be noted that the first, second, and third control data packets are intercepted when the drone is controlled using the joystick on the control terminal. When controlling each flight state of the drone, it is necessary to continuously send the corresponding control signal to the drone in order to achieve the purpose of real-time control of the drone.
[0101] After analyzing the data packets, the server can modify the identified sequence number field and control command field to obtain test data packets. For example, if the control terminal sends a set of control data packets to the drone server: control data packet 1, control data packet 2, control data packet 3, control data packet 4, then modifying the sequence number field could result in a set of control data packets: control data packet 1, control data packet 2, control data packet 3, control data packet 5.
[0102] After receiving the test data packet, the server can send the test data packet to the drone's flight control module and determine whether the drone's flight status has been affected by the modification of the control data packet sequence number field, resulting in the drone going out of control, and thus assess the drone's communication security.
[0103] In one possible implementation, before performing communication format analysis on the flight control data, the firmware of the target network port is extracted, and it is checked whether the port transmission data contained in the firmware is encrypted; if the port transmission data is encrypted, a preset program analysis algorithm is used to test whether the password of the port transmission data can be obtained; if the port transmission data is not encrypted, it is tested whether the port transmission data can be tampered with.
[0104] In this embodiment of the application, the server can first decompress the firmware, then extract the firmware from the target network port, and check whether the files contained in the firmware are encrypted. For encrypted files, a preset program analysis algorithm can be used to test whether the password of the file can be obtained, and the password can be cracked.
[0105] For unencrypted files, a debugger can be used to analyze the program in the file to determine if the data packet generation logic can be restored and to test if the port transmission data can be tampered with.
[0106] The above methods can be used to test the communication security of data transmitted through the drone's port.
[0107] In addition to the methods mentioned above for testing the drone's communication protocol, before takeoff, a fake GPS positioning signal can be sent to the drone using wireless equipment to test its communication protocol. This can be done by sending a GPS positioning signal from a prohibited flight area to a non-prohibited flight area to check the drone's takeoff status; similarly, during flight, a fake GPS positioning signal can be sent to the drone to see if it can be forced to land; and radio frequency interference signals can be sent to the drone to see if it causes it to lose control.
[0108] For example, the drone's hardware can be disassembled and its hardware circuit architecture analyzed to locate the drone's memory. Test whether system-related programs can be extracted from the memory. If system-related programs can be extracted from the memory, the drone's hardware is considered to be in a highly dangerous state. If system-related programs cannot be extracted from the memory, the drone's hardware is considered to be in a low-danger state. Here, the relevant programs can be extracted using the read / write tools corresponding to the drone's debugging interface.
[0109] Therefore, the communication security of a drone can be tested by modifying the data packets corresponding to the port transmission, the flight status of a drone can be tested by sending a fake GPS positioning signal to the drone, and the hardware of the drone can be disassembled to test the security of the drone's hardware status.
[0110] S4. When the data test results meet the communication security conditions associated with the data type of the target test data, the communication of the UAV is determined to be normal.
[0111] In this embodiment, similar to the example above, the control terminal sends a set of control data packets to the server: control data packet 1, control data packet 2, control data packet 3, and control data packet 4. The control data packet obtained by modifying the sequence number field can be control data packet 1, control data packet 2, control data packet 3, and control data packet 5. The order of control data packets 1, 2, and 3 remains unchanged; only the original control data packet 4 is modified to control data packet 5. For the UAV flight control module, the modification or loss of field information in one of the data packets will not cause a complete loss of control over the UAV. Therefore, if it is determined that the test result of the data obtained after modifying the sequence number field in the data packet meets the communication security conditions associated with the port transmission data type, it can be determined that the communication of the UAV is normal.
[0112] Similarly, when testing the port attribute data or port transmission data of each functional module, once the test results are determined and the communication security conditions associated with the data type of the target test data are met, the communication of the UAV is confirmed to be normal.
[0113] In summary, the UAV communication security testing method provided in this application can perform corresponding data tests on the UAV's port attribute data and port transmission data according to the data testing methods matched to their respective data types. It can also determine the UAV's flight status in real time and assess the UAV's communication security.
[0114] Based on the methods provided in the above embodiments, this application also provides a drone communication security testing system, such as... Figure 3 The above is a schematic diagram of the structure of a drone communication testing system according to an embodiment of this application. The system includes:
[0115] The data acquisition module 301 is used to receive a data test request sent by the control terminal and obtain the data identifier of the data to be tested from the data test request;
[0116] The data extraction module 302 is used to select target test data that matches the data identifier from the candidate test data set;
[0117] Data testing module 303 is used to perform data testing on the target test data based on the data testing method set according to the data type of the target test data, and obtain the corresponding data test results;
[0118] When the data test results are determined to meet the communication security conditions associated with the data type of the target test data, the communication of the UAV is determined to be normal.
[0119] In one possible design, the port transmission data is flight control data. After extracting the corresponding port transmission data from the target network port, the data testing module 303 is further used for:
[0120] The flight control data is analyzed for communication format to obtain the control data packets corresponding to each flight state of the UAV.
[0121] By comparing the obtained control data packets, the field information of the control data packets is determined, wherein the field information includes at least a sequence number field and a control command field;
[0122] Modify the field information of the control data packet to obtain the test data packet;
[0123] The communication security of the UAV is tested based on the test data packet, and the corresponding test results are obtained.
[0124] Based on the same inventive concept, this application also provides an electronic device that can realize the functions of the aforementioned UAV communication security testing method. (Refer to...) Figure 4 The electronic device includes:
[0125] At least one processor 401 and a memory 402 connected to at least one processor 401. In this embodiment, the specific connection medium between the processor 401 and the memory 402 is not limited. Figure 4 The example shown is the connection between processor 401 and memory 402 via bus 400. Bus 400 is... Figure 4 The connections between other components are indicated by thick lines and are for illustrative purposes only, not as limiting information. The 400 bus can be divided into address bus, data bus, control bus, etc., for ease of representation. Figure 4 The term is represented by a single thick line, but this does not imply that there is only one bus or one type of bus. Alternatively, processor 401 can also be called a controller; there is no restriction on the name.
[0126] In this embodiment, the memory 402 stores instructions executable by at least one processor 401. By executing the instructions stored in the memory 402, the at least one processor 401 can perform the UAV communication security testing method discussed above. The processor 401 can implement... Figure 3 The system shown illustrates the functions of each module.
[0127] The processor 401 is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory 402 and calling data stored in memory 402, the processor can perform various functions and process data, thereby monitoring the device as a whole.
[0128] In one possible design, processor 401 may include one or more processing units. Processor 401 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may also not be integrated into processor 401. In some embodiments, processor 401 and memory 402 may be implemented on the same chip; in some embodiments, they may also be implemented separately on separate chips.
[0129] Processor 401 can be a general-purpose processor, such as a central processing unit (CPU), digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the UAV communication security testing method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.
[0130] Memory 402, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 402 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 402 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 402 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.
[0131] By designing and programming the processor 401, the code corresponding to the UAV communication security testing method described in the foregoing embodiments can be embedded into the chip, enabling the chip to execute the code during runtime. Figure 1 The steps of the drone communication security testing method shown in the embodiment are described below. How to design and program the processor 401 is a technique well-known to those skilled in the art and will not be elaborated upon here.
[0132] Based on the same inventive concept, embodiments of this application also provide a storage medium storing computer instructions that, when executed on a computer, cause the computer to perform the drone communication security testing method described above.
[0133] In some possible implementations, various aspects of the UAV communication security testing method provided in this application can also be implemented in the form of a program product, which includes program code. When the program product is run on a device, the program code is used to cause the control device to perform the steps in the UAV communication security testing method according to the various exemplary embodiments of this application described above.
[0134] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0135] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0136] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0137] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0138] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for testing the communication security of unmanned aerial vehicles (UAVs), characterized in that, include: Receive a data test request sent by the control terminal, and obtain the data identifier of the data to be tested from the data test request; From the candidate test data set, target test data that matches the data identifier is selected; the target test data includes port attribute data and port transmission data. Obtain the interface type of the port attribute data and install the driver that matches the interface type; wherein, the port attribute data represents: the port configuration information of each type of network port; The driver obtains management permissions for various network ports, and based on the obtained management permissions, selects target network ports that meet preset port operating conditions from among the various network ports. Based on the data testing method corresponding to the data type of the target network port and the port attribute data, data testing is performed on the port attribute data. When extracting the corresponding port transmission data from the target network port, the security level of the port transmission data is determined based on the set type of the data feature set corresponding to the port transmission data. Based on the security level and the data testing method corresponding to the data type of the port transmission data, data testing is performed on the port transmission data to obtain the corresponding data test results. When the data test results are determined to meet the communication security conditions associated with the data type of the target test data, the communication of the UAV is determined to be normal.
2. The method as described in claim 1, characterized in that, The process of performing data testing on the port attribute data also includes: Scan each sub-port corresponding to the target network port to determine the service type corresponding to each sub-port. Based on the port testing methods associated with each service type, the sub-ports are tested.
3. The method as described in claim 1, characterized in that, If the port transmission data is flight control data, then after extracting the corresponding port transmission data from the target network port, the process further includes: The flight control data is analyzed for communication format to obtain the control data packets corresponding to each flight state of the UAV. By comparing the obtained control data packets, the field information of the control data packets is determined, wherein the field information includes at least a sequence number field and a control command field; Modify the field information of the control data packet to obtain the test data packet; The communication security of the UAV is tested based on the test data packet, and the corresponding test results are obtained.
4. The method as described in claim 3, characterized in that, Before performing communication format analysis on the flight control data, the method further includes: Extract the firmware of the target network port and check whether the data transmitted through the port contained in the firmware is encrypted; If the data transmitted through the port is encrypted, a preset program analysis algorithm is used to test whether the password for the data transmitted through the port can be obtained. If the data transmitted through the port is not encrypted, then test whether the data transmitted through the port can be tampered with.
5. A UAV communication security testing system, characterized in that, include: The data acquisition module is used to receive data test requests sent by the control terminal and obtain the data identifier of the data to be tested from the data test requests; The data extraction module is used to select target test data that matches the data identifier from the candidate test data set; the target test data includes port attribute data and port transmission data; The data testing module is used to obtain the interface type of the port attribute data and install a driver that matches the interface type. The port attribute data represents the port configuration information of various network ports. Through the driver, management permissions for each type of network port are obtained, and based on these permissions, target network ports that meet preset port operating conditions are selected from the various network ports. Data testing is performed on the port attribute data based on the target network port and the data testing method corresponding to the data type. When corresponding port transmission data is extracted from the target network port, the security level of the port transmission data is determined based on the set type of the data feature set corresponding to the port transmission data. Based on the security level and the data testing method corresponding to the data type, data testing is performed on the port transmission data to obtain corresponding data test results. When the data test results are determined to meet the communication security conditions associated with the data type of the target test data, the communication of the UAV is determined to be normal.
6. The system as described in claim 5, characterized in that, If the port transmission data is flight control data, then after extracting the corresponding port transmission data from the target network port, the data testing module is further used for: The flight control data is analyzed for communication format to obtain the control data packets corresponding to each flight state of the UAV. By comparing the obtained control data packets, the field information of the control data packets is determined, wherein the field information includes at least a sequence number field and a control command field; Modify the field information of the control data packet to obtain the test data packet; The communication security of the UAV is tested based on the test data packet, and the corresponding test results are obtained.
7. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, when executing a computer program stored in the memory, implements the method steps of any one of claims 1-4.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method described in any one of claims 1-4.
Citation Information
Patent Citations
Automatic penetration testing method and system
CN105827642A
Analysis method of security of communication system of unmanned aerial vehicle
CN109379128A