Unmanned aerial vehicle group endogenous safety detection method

By implementing multi-dimensional security detection methods in the drone swarm, the problem of insufficient safety detection and evaluation of drone swarms in the prior art is solved, and the comprehensive safety detection and risk assessment of drone swarms are realized, and the overall safety of drone swarms is improved.

CN120030545APending Publication Date: 2025-05-23AEROSPACE SCI & IND INTELLIGENT OPERATION RES & INFORMATION SECURITY RES INST (WUHAN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411933498.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-26
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The existing technology lacks comprehensive and overall safety detection and evaluation methods for drone groups, and it is difficult to effectively detect and protect security threats within drone groups.

Method used

It provides an endogenous security detection method for drone groups. Through the active defense security detection link at the drone system level and the drone application-level security detection link at the drone, it detects the endogenous security of drone from multiple dimensions, including operating system security, application security, account security authentication, port defense, process detection, software security detection, critical file security detection, outreach security detection and hardware information complete security strategies, and evaluates the detection results through algorithms to judge the risk level of drone.

Benefits of technology

The comprehensive overall safety inspection and evaluation of the drone swarm has been achieved, the safety of the drone swarm has been improved, and the safety of the drone swarm can be effectively identified and deal with security threats, ensuring the normal mission execution and protection of the drone swarm.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030545A_ABST
    Figure CN120030545A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of unmanned aerial vehicle group safety detection and protection, and particularly relates to an unmanned aerial vehicle group endogenous safety detection method, which comprises an unmanned aerial vehicle system-level active defense safety detection link and an unmanned aerial vehicle application-level safety detection link, according to the method, the endogenous safety of the unmanned aerial vehicle is detected and evaluated from multiple dimensions, the detection result is evaluated through an algorithm, and the risk level of the unmanned aerial vehicle is judged and detected. Based on the background of the prior art, the endogenous safety detection method for the unmanned aerial vehicle group is provided, unmanned aerial vehicle safety detection and safety baseline configuration are carried out from multiple dimensions of unmanned aerial vehicle operation system safety and application safety, and the overall safety of the unmanned aerial vehicle group is guaranteed. The method provides technical support for safety detection evaluation and emergency alarm processing of the unmanned aerial vehicle group, and meets the overall safety requirements of the unmanned aerial vehicle group.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of safety detection and protection of drone swarms, and in particular relates to an endogenous safety detection method for drone swarms. Background Art

[0002] In recent years, the technology of unmanned aerial vehicles (UAVs) has developed rapidly. Due to its advantages of low deployment difficulty, low maintenance cost, high maneuverability and strong hovering ability, it has been widely used in disaster relief, remote sensing detection, construction inspection, package delivery, real-time traffic monitoring and other fields. In addition to the civilian field, drones are also widely used in the military field. Countries around the world are constantly promoting the development of the concepts and technologies of "unmanned clusters" and "loyal wingmen". In this regard, many exploratory projects have been carried out to form swarm combat capabilities. Drone swarms have the advantages of large number, wide range, fast speed and low cost.

[0003] As drones are increasingly used, they are also facing serious security vulnerabilities and hidden dangers, especially in adversarial environments. For example, in a military environment, the enemy may intercept and tamper with the drone's information or capture the drone for their own use. Therefore, security threats and protection technologies for drone systems have been a research hotspot in the drone field in recent years. There is an increasing amount of research on technologies such as security authentication, communication encryption, and attack detection of drone communication networks to protect the normal mission execution of individual drones and drone swarms from malicious network attacks.

[0004] Current drone security testing focuses on testing in one dimension, such as vulnerability testing or external testing for drones, but lacks comprehensive and holistic testing and evaluation methods for drones. Summary of the invention

[0005] 1. Technical issues to be resolved

[0006] The technical problem to be solved by the present invention is: how to provide an endogenous safety detection method for a drone swarm.

[0007] (II) Technical solution

[0008] In order to solve the above technical problems, the present invention provides a method for detecting endogenous safety of a drone group, the method comprising:

[0009] UAV system-level active defense security testing link and UAV application-level security testing link;

[0010] The method detects and evaluates the inherent safety of drones from multiple dimensions, evaluates the detection results through an algorithm, and determines the risk level of the detected drones.

[0011] Among them, the UAV system-level active defense security detection link realizes security detection at the overall operating system level of the UAV group by configuring multiple dimensions of detection of the UAV system environment, key information, network connection, and identity authentication.

[0012] Among them, the concept of executable body is defined in the drone application-level security detection link, and all executable programs, processes, services, registries, and files in the drone information system are defined as executable bodies. In the drone system, basic security preset values ​​are formulated for related executable bodies to form basic security baselines and security rules; in addition, the behavior of all executable bodies is monitored through different technical means, and the overall application-level security of the drone group is evaluated through systems such as executable body blacklists and whitelists.

[0013] Among them, in the drone group endogenous safety detection method,

[0014] Conduct security testing of the drone operating system operating environment, and conduct security testing of vulnerabilities, patch repairs, shared directories, and system logs for the drone system; configure the known vulnerability information baseline of the drone system, set the number of vulnerabilities, vulnerability levels, repairability, and corresponding patch status; perform operating system patch repairs, and specify a list of patches to be installed for different operating systems; set up drone operating system shared directory configuration items, and specify a list of shared directories that need to be closed; detect system log alarm records, and perform alarm operations and emergency disposal for intermediate and advanced system logs;

[0015] Carry out account security authentication testing on the drone system, establish a trusted user list database, match the drone account with the trusted user list in the database when performing network authentication, and implement isolation measures when unauthorized drone accounts are found to prohibit them from performing networking and communication operations, and record illegal authentication behaviors; port defense detection, set up a black and white list of sensitive ports for the current drone, and only allow specific programs to access and use them. When an unauthorized application uses a sensitive port, block the use of the sensitive port and isolate the application; process detection and software security detection, implement black and white list feature matching, set up a black and white list of processes and software, monitor processes and software outside the white list, and record the startup and running behavior logs of illegal processes and software.

[0016] Carry out key file security detection for drones in the local area network, perform security detection on key file names, file directories, and key configuration items, and check the correctness and compliance of key files through name matching, file path matching, and hash value verification. If key files are found to be modified or deleted, risk warnings will be issued immediately, and applications that maliciously modify key files will be isolated;

[0017] Conduct external security detection on drone networks, conduct statistical analysis on legitimate drone networks and identities, and ensure that drones in the network are mutually trusted. When an untrusted device is connected to the LAN, an alarm is immediately sounded and all devices are disconnected and isolated.

[0018] Set up a security policy for the completeness of drone hardware information. For legal drones on the network, record the CPU model, memory model, and hardware model, and generate a unique hash value. When a change in the drone hardware system hash value is detected, it indicates that the drone hardware device has changed. The drone will be shut down and banned immediately, and the hash value change and hardware device change record of the current drone will be recorded. The drone will be marked as a non-trusted device, and relevant information about the drone hardware change will be reported.

[0019] Develop a regular scanning strategy for drone executives, perform baseline checks according to executive security, use immediate or regular scanning to perform security scans on executives in drones, and record the executive creation date, modification date, executive name, executive location, digital signature, signature attributes, and hash value attributes.

[0020] Establish an executable whitelist library, and compare the scanned executables with the executable information in the whitelist library by matching names, file locations, creation dates, and modification dates. For executables in the whitelist, release operations are taken, and for executables outside the whitelist, warning and blocking operations are taken. The operation logs of illegal executables are recorded and reported;

[0021] Establish an executable blacklist library based on the names and locations of common executables of Trojan programs. Match the scanned executables with the executable information in the blacklist library by matching the names, file locations, creation dates, and modification dates. For the successfully matched blacklisted executables, take killing and isolation measures to block all operations of the executables, track the operation logs of the blacklisted executables, and take security measures.

[0022] For executables that are not on the whitelist or blacklist, develop executable security detection, preset executable scores according to the executable process operation behavior, including process creation and process modification behavior; score the executable when the executable creates a process with a specific name, specific hash value, or specific digital signature; score the executable when the executable creates or modifies any process; set a minimum score for the executable, and when the executable score is lower than the minimum score, the executable is considered a high-risk executable and isolated, its operation behavior is tracked, and the created or modified process is closed and isolated;

[0023] Develop executable file security detection, preset executable scores according to the executable file operation behavior, including file creation and file modification, and score the executable when the executable creates a file with a specific name, specific hash value, or specific digital signature, or set a unified detection method to score the executable when the executable creates or modifies any file; set a minimum score for the executable, and when the executable score is lower than the minimum score, the executable is regarded as a high-risk executable and isolated, its operation behavior is tracked, and the created or modified files are closed for isolation.

[0024] Detect the network behavior of the executor and determine whether the executor has the right to access other drone information in the LAN and whether it has the right to use sensitive ports for monitoring. Prevent executors without relevant permissions from using specific ports or accessing other drone information in the LAN. Isolate and detect executors that illegally access the LAN.

[0025] Formulate a risk behavior tracing and investigation mechanism for abnormal execution bodies. When abnormal files, processes, and services are found in the system, initiate an abnormal event tracing investigation, record the name, file location, digital signature, hash value and other information of the abnormal files, processes, and services, use the recorded information for feature matching, find the source of the creator or modifier of the abnormal file, and after locking the source of the execution body, isolate and kill the execution body that created or modified the abnormal file, process, or service, and add it to the execution body blacklist, and isolate the abnormal files, processes, and services found;

[0026] Finally, the risk level of drone safety is determined by combining the results of the detection items in drone system safety and application safety, and the drone risk level determination formula is obtained;

[0027]

[0028] Variable R = [R 1 , R 2 , ..R n ]: represents the risk vector level of n detection items;

[0029] Variable W = [W 1 , W 2 , …, W n ]: represents the weight vector of n detection items, where each weight W i Satisfy 0≦W i ≦1;

[0030] F i (R i ), which represents the nonlinear transformation function of the risk level of the i-th detection item, and is used to adjust the impact of the risk level;

[0031] a is an adjustment factor used to control the influence degree of weight Wi on the comprehensive risk level S; when a = 1, the formula simplifies to an ordinary weighted average; when a > 1, the influence of the detection item with a larger weight on the comprehensive risk level will be amplified; when 0 < a < 1, the influence of the detection item with a larger weight on the comprehensive risk level will be reduced;

[0032] When S < 0.3, the risk level of the UAV is low risk; when 0.3 ≤ S < 0.6, the risk level of the UAV is medium risk; when S ≥ 0.6, the risk level of the UAV is high risk.

[0033] (III) Beneficial effects

[0034] Compared with the prior art, based on the prior art background, the present invention provides an in - built security detection method for UAV swarms, which conducts UAV security detection and security baseline configuration from multiple dimensions such as UAV operating system security and application security, ensuring the overall security of the UAV swarm. This method provides technical support for the security detection, evaluation, emergency warning and disposal of the UAV swarm, meeting the overall security requirements of the UAV swarm. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 It is the schematic diagram of the in - built security detection method for UAV swarms of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0036] To make the objectives, contents, and advantages of the present invention clearer, the following further describes in detail the specific embodiments of the present invention with reference to the drawings and embodiments.

[0037] To solve the above - mentioned technical problems, the present invention provides an in - built security detection method for UAV swarms, and the method includes:

[0038] The active defense security detection link at the UAV system level and the security detection link at the UAV application level;

[0039] The method detects and evaluates the in - built security of UAVs from multiple dimensions, and evaluates the detection results through an algorithm to determine the risk level of the detected UAV.

[0040] Among them, the active defense security detection link at the UAV system level realizes the security detection at the overall operating system level of the UAV swarm through the detection of multiple dimensions such as configuring the UAV system environment, key information, network connection, and identity authentication.

[0041] Among them, the concept of executable body is defined in the drone application-level security detection link, and all executable programs, processes, services, registries, and files in the drone information system are defined as executable bodies. In the drone system, basic security preset values ​​are formulated for related executable bodies to form basic security baselines and security rules; in addition, the behavior of all executable bodies is monitored through different technical means, and the overall application-level security of the drone group is evaluated through systems such as executable body blacklists and whitelists.

[0042] Among them, in the drone group endogenous safety detection method,

[0043] Conduct security testing of the drone operating system operating environment, and conduct security testing of vulnerabilities, patch repairs, shared directories, and system logs for the drone system; configure the known vulnerability information baseline of the drone system, set the number of vulnerabilities, vulnerability levels, repairability, and corresponding patch status; perform operating system patch repairs, and specify a list of patches to be installed for different operating systems; set up drone operating system shared directory configuration items, and specify a list of shared directories that need to be closed; detect system log alarm records, and perform alarm operations and emergency disposal for intermediate and advanced system logs;

[0044] Carry out account security authentication testing on the drone system, establish a trusted user list database, match the drone account with the trusted user list in the database when performing network authentication, and implement isolation measures when unauthorized drone accounts are found to prohibit them from performing networking and communication operations, and record illegal authentication behaviors; port defense detection, set up a black and white list of sensitive ports for the current drone, and only allow specific programs to access and use them. When an unauthorized application uses a sensitive port, block the use of the sensitive port and isolate the application; process detection and software security detection, implement black and white list feature matching, set up a black and white list of processes and software, monitor processes and software outside the white list, and record the startup and running behavior logs of illegal processes and software.

[0045] Carry out key file security detection for drones in the local area network, perform security detection on key file names, file directories, and key configuration items, and check the correctness and compliance of key files through name matching, file path matching, and hash value verification. If key files are found to be modified or deleted, risk warnings will be issued immediately, and applications that maliciously modify key files will be isolated;

[0046] Conduct external security detection on drone networks, conduct statistical analysis on legitimate drone networks and identities, and ensure that drones in the network are mutually trusted. When an untrusted device is connected to the LAN, an alarm is immediately sounded and all devices are disconnected and isolated.

[0047] Set up a security policy for the completeness of drone hardware information. For legal drones on the network, record the CPU model, memory model, and hardware model, and generate a unique hash value. When a change in the drone hardware system hash value is detected, it indicates that the drone hardware device has changed. The drone will be shut down and banned immediately, and the hash value change and hardware device change record of the current drone will be recorded. The drone will be marked as a non-trusted device, and relevant information about the drone hardware change will be reported.

[0048] Develop a regular scanning strategy for drone executives, perform baseline checks according to executive security, use immediate or regular scanning to perform security scans on executives in drones, and record the executive creation date, modification date, executive name, executive location, digital signature, signature attributes, and hash value attributes.

[0049] Establish an executable whitelist library, and compare the scanned executables with the executable information in the whitelist library by matching names, file locations, creation dates, and modification dates. For executables in the whitelist, release operations are taken, and for executables outside the whitelist, warning and blocking operations are taken. The operation logs of illegal executables are recorded and reported;

[0050] Establish an executable blacklist library based on the names and locations of common executables of Trojan programs. Match the scanned executables with the executable information in the blacklist library by matching the names, file locations, creation dates, and modification dates. For the successfully matched blacklisted executables, take killing and isolation measures to block all operations of the executables, track the operation logs of the blacklisted executables, and take security measures.

[0051] For executables that are not on the whitelist or blacklist, develop executable security detection, preset executable scores according to the executable process operation behavior, including process creation and process modification behavior; score the executable when the executable creates a process with a specific name, specific hash value, or specific digital signature; score the executable when the executable creates or modifies any process; set a minimum score for the executable, and when the executable score is lower than the minimum score, the executable is considered a high-risk executable and isolated, its operation behavior is tracked, and the created or modified process is closed and isolated;

[0052] Develop executable file security detection, preset executable scores according to the executable file operation behavior, including file creation and file modification, and score the executable when the executable creates a file with a specific name, specific hash value, or specific digital signature, or set a unified detection method to score the executable when the executable creates or modifies any file; set a minimum score for the executable, and when the executable score is lower than the minimum score, the executable is regarded as a high-risk executable and isolated, its operation behavior is tracked, and the created or modified files are closed for isolation.

[0053] Detect the network behavior of the executor and determine whether the executor has the right to access other drone information in the LAN and whether it has the right to use sensitive ports for monitoring. Prevent executors without relevant permissions from using specific ports or accessing other drone information in the LAN. Isolate and detect executors that illegally access the LAN.

[0054] Formulate a risk behavior tracing and investigation mechanism for abnormal execution bodies. When abnormal files, processes, and services are found in the system, initiate an abnormal event tracing investigation, record the name, file location, digital signature, hash value and other information of the abnormal files, processes, and services, use the recorded information for feature matching, find the source of the creator or modifier of the abnormal file, and after locking the source of the execution body, isolate and kill the execution body that created or modified the abnormal file, process, or service, and add it to the execution body blacklist, and isolate the abnormal files, processes, and services found;

[0055] Finally, the risk level of drone safety is determined by combining the results of the detection items in drone system safety and application safety, and the drone risk level determination formula is obtained;

[0056]

[0057] Variable R = [R 1 , R 2 , ..R n ]: represents the risk vector level of n detection items;

[0058] Variable W = [W 1 , W 2 , …, W n ]: represents the weight vector of n detection items, where each weight W i Satisfy 0≦W i ≦1;

[0059] F i (R i ), which represents the nonlinear transformation function of the risk level of the i-th detection item, and is used to adjust the impact of the risk level;

[0060] a is an adjustment factor used to control the influence degree of the weight Wi on the comprehensive risk level S; when a = 1, the formula is simplified to an ordinary weighted average; when a > 1, the influence of the detection item with a larger weight on the comprehensive risk level will be amplified; when 0 < a < 1, the influence of the detection item with a larger weight on the comprehensive risk level will be reduced;

[0061] When S < 0.3, the risk level of this drone is low risk; when 0.3 ≤ S < 0.6, the risk level of this drone is medium risk; when S ≥ 0.6, the risk level of this drone is high risk.

[0062] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

Claims

1. A method for detecting endogenous safety of drone groups, characterized in that: The method comprises: UAV system-level active defense security testing link and UAV application-level security testing link; The method detects and evaluates the inherent safety of drones from multiple dimensions, evaluates the detection results through an algorithm, and determines the risk level of the detected drones.

2. The drone group endogenous safety detection method according to claim 1, characterized in that: The UAV system-level active defense security detection link realizes security detection at the overall operating system level of the UAV group by configuring multiple dimensions of detection of the UAV system environment, key information, network connection, and identity authentication.

3. The drone group endogenous safety detection method according to claim 2, characterized in that: The concept of executable body is defined in the drone application-level security detection link, and all executable programs, processes, services, registries, and files in the drone information system are defined as executable bodies. Basic security preset values ​​are set for related executable bodies in the drone system to form basic security baselines and security rules. In addition, the behavior of all executable bodies is monitored through different technical means, and the overall application-level security of the drone group is evaluated through systems such as executable body blacklists and whitelists.

4. The drone group endogenous safety detection method according to claim 3, characterized in that: In the drone group endogenous safety detection method, Conduct security testing of the drone operating system operating environment, and conduct security testing of vulnerabilities, patch repairs, shared directories, and system logs for the drone system; configure the known vulnerability information baseline of the drone system, set the number of vulnerabilities, vulnerability levels, repairability, and corresponding patches; perform operating system patch repairs, and specify a list of patches that need to be installed for different operating systems; set the drone operating system shared directory configuration items, and specify a list of shared directories that need to be closed; Detect system log alarm records, and perform alarm operations and emergency disposal on intermediate and advanced system logs; Carry out account security authentication testing on the drone system, establish a trusted user list database, match the drone account with the trusted user list in the database when performing network authentication, and implement isolation measures when unauthorized drone accounts are found to prohibit them from performing networking and communication operations, and record illegal authentication behaviors; port defense detection, set up a black and white list of sensitive ports for the current drone, and only allow specific programs to access and use them. When an unauthorized application uses a sensitive port, block the use of the sensitive port and isolate the application; process detection and software security detection, implement black and white list feature matching, set up a black and white list of processes and software, monitor processes and software outside the white list, and record the startup and running behavior logs of illegal processes and software.

5. The drone group endogenous safety detection method according to claim 4, characterized in that: In the drone swarm endogenous security detection method, key file security detection is carried out on drones in the local area network, and security detection is carried out on key file names, file directories, and key configuration items. The correctness and compliance of key files are checked through name matching, file path matching, and hash value verification. If a key file is found to be modified or deleted, a risk warning is immediately issued, and the application that maliciously modifies the key file is isolated; Conduct external security detection on drone networks, conduct statistical analysis on legitimate drone networks and identities, and ensure that drones in the network are mutually trusted. When an untrusted device is connected to the LAN, an alarm is immediately sounded and all devices are disconnected and isolated. Set up a security policy for the completeness of drone hardware information. For legal drones on the network, record the CPU model, memory model, and hardware model, and generate a unique hash value. When a change in the drone hardware system hash value is detected, it indicates that the drone hardware device has changed. The drone will be shut down and banned immediately, and the hash value change and hardware device change record of the current drone will be recorded. The drone will be marked as a non-trusted device, and relevant information about the drone hardware change will be reported.

6. The drone group endogenous safety detection method according to claim 5, characterized in that: In the drone swarm endogenous security detection method, a regular scanning strategy for drone executives is formulated, baseline detection is performed according to executive security, and executives in drones are scanned for security using immediate or regular scanning methods. The creation date, modification date, executive name, executive location, digital signature, signature attributes, and hash value attributes of the executive are registered for record.

7. The drone group endogenous safety detection method according to claim 6, characterized in that: In the drone group endogenous safety detection method, Establish an executable whitelist library, and compare the scanned executables with the executable information in the whitelist library by matching names, file locations, creation dates, and modification dates. For executables in the whitelist, release operations are taken, and for executables outside the whitelist, warning and blocking operations are taken. The operation logs of illegal executables are recorded and reported; Establish an executable blacklist library according to the common executable names and locations of Trojan programs. Match the scanned executables with the executable information in the blacklist library by matching the name, file location, creation date, modification date, etc. For the successfully matched blacklisted executables, take detection and isolation measures to block all operations of the executables, track the operation logs of the blacklisted executables, and perform security processing measures.

8. The drone group endogenous safety detection method according to claim 7, characterized in that: In the drone group endogenous safety detection method, For executables that are not on the whitelist or blacklist, develop executable security detection, preset executable scores according to the executable process operation behavior, including process creation and process modification behavior; score the executable when the executable creates a process with a specific name, specific hash value, or specific digital signature; score the executable when the executable creates or modifies any process; set a minimum score for the executable, and when the executable score is lower than the minimum score, the executable is considered a high-risk executable and isolated, its operation behavior is tracked, and the created or modified process is closed and isolated; Formulate the security detection of the executive body files. According to the file operation behaviors of the executive body, including file creation and modification behaviors, preset the executive body score. When the executive body creates a file with a specific name, specific hash value, and specific digital signature, perform a scoring operation on the executive body, or set a unified detection method. When the executive body creates or modifies any file, score the executive body; set a minimum score for the executive body. When the executive body score is lower than the minimum score, regard the executive body as a high-risk executive body, perform isolation processing, track its operation behaviors, and close and isolate the created or modified files.

9. The drone group endogenous safety detection method according to claim 8, characterized in that: In the in-swarm security detection method of the unmanned aerial vehicle swarm, Detect the network behaviors of the executive body, and stipulate whether the executive body has the right to access the information of other unmanned aerial vehicles within the local area network and whether it has the right to use sensitive ports for monitoring; prevent the executive body without relevant permissions from using specific ports or accessing the information of other unmanned aerial vehicles within the local area network. For the executive body that illegally accesses the local area network, perform isolation and killing operations.

10. The drone group endogenous safety detection method according to claim 9, characterized in that: In the in-swarm security detection method of the unmanned aerial vehicle swarm, Formulate an abnormal executive body risk behavior trace investigation mechanism. When abnormal files, processes, and services are found in the system, initiate an abnormal event trace investigation, record information such as the names, file locations, digital signatures, and hash values of the abnormal files, processes, and services, perform feature matching using the recorded information, find the source of the creator or modifier of the abnormal file, and after locking the source of the executive body, isolate and kill the executive body that created or modified the abnormal file, process, and service, add it to the executive body blacklist, and isolate the found abnormal files, processes, and services; Finally, combine the results of the detection items in the unmanned aerial vehicle system security and application security to determine the risk level of the unmanned aerial vehicle security, and obtain the unmanned aerial vehicle risk level determination formula; Variable R = [R1, R2, ..R n ]: represents the risk vector level of n detection items; Variable W = [W1, W2, ..., W n ]: represents the weight vector of n detection items, where each weight W i Satisfy 0≦W i ≦1; F i (R i ), which represents the nonlinear transformation function of the risk level of the i-th detection item, and is used to adjust the impact of the risk level; a is an adjustment factor used to control the influence degree of the weight Wi on the comprehensive risk level S; When a = 1, the formula is simplified to an ordinary weighted average; when a is greater than 1, the influence of the detection item with a larger weight on the comprehensive risk level will be amplified; when 0 < a < 1, the influence of the detection item with a larger weight on the comprehensive risk level will be reduced; When S < 0.3, the risk level of the unmanned aerial vehicle is low risk; when 0.3 ≤ S < 0.6, the risk level of the unmanned aerial vehicle is medium risk; when S ≥ 0.6, the risk level of the unmanned aerial vehicle is high risk.