Airborne network security event processing system and processing method thereof

By constructing a multi-source event monitoring and diagnosis system and a centralized isolation execution mechanism, the problem of lack of real-time monitoring and manual decision-making in the civil aircraft network security system has been solved, realizing automated, refined management and rapid response to network threats, and improving security and the reliability of decision support.

CN121887829APending Publication Date: 2026-04-17COMMERCIAL AIRCRAFT CORP OF CHINA LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
COMMERCIAL AIRCRAFT CORP OF CHINA LTD
Filing Date
2026-01-15
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

The existing cybersecurity system for civil aircraft lacks real-time monitoring and intelligent diagnosis of its own status. The activation conditions for isolating switches are vague and rely on human experience for decision-making, making it difficult to respond quickly and accurately to cybersecurity incidents and posing security risks.

Method used

Construct an intelligent, hierarchical, and comprehensive processing mechanism. Through a multi-source event monitoring and diagnosis system, combined with ground and airborne systems, achieve automated monitoring, diagnosis, and isolation control of security events. Set quantitative judgment thresholds and design a centralized and reliable isolation execution mechanism, while retaining the pilot's final decision-making authority.

Benefits of technology

It enables automated and refined management of all-round security threats to airborne networks, improves response speed and decision support reliability, and reduces security risks caused by decision delays or misjudgments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887829A_ABST
    Figure CN121887829A_ABST
Patent Text Reader

Abstract

The invention provides an airborne network security event processing method, which comprises the following steps of: monitoring a first type of security event by a security log analysis system, carrying out severity diagnosis on the first type of security event, and generating a first isolation control signal when the severity of the first type of security event exceeds a first preset threshold value; monitoring a second type of security events by the airborne network security system, carrying out severity diagnosis on the second type of security events, and generating a second isolation control signal when the severity of the second type of security events exceeds a second preset threshold value; monitoring a third type of security events by the security self-monitoring system, carrying out severity diagnosis on the third type of security events, and generating a third isolation control signal when the severity of the third type of security events exceeds a third preset threshold value; and in response to the control signal, controlling a security switch in the airborne network by the isolation execution system so as to change the connection state of the airborne network and the external network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of avionics technology, and in particular to a security technology for airborne networks in civil aircraft, specifically, to an airborne network security incident handling system and method. Background Technology

[0002] With the deep integration of avionics and information technology, modern civil aircraft face higher demands for secure and reliable two-way data exchange between their avionics networks and external systems, such as ground maintenance networks, air traffic control networks, and satellite communication networks. While this interconnectivity improves operational efficiency and flight service quality, it also exposes the previously relatively closed avionics systems to increasingly severe cybersecurity threats, such as malware intrusions, unauthorized access, and cyberattacks.

[0003] To ensure flight safety, existing technologies generally employ certain cybersecurity measures in civil aircraft. A common practice is to install controllable isolating switches at the physical interface or logical boundary between the avionics network and external networks. When a security threat is suspected or confirmed, operating this switch can cut off or restrict data interaction between the internal and external networks, thereby physically or logically isolating the core avionics system from external threats and forming a basic security barrier.

[0004] However, existing isolation mechanisms of this kind have significant shortcomings. First, current aircraft network security systems primarily focus on defending against external attacks, lacking means to monitor the operational health of the network security architecture itself. This means that if system components responsible for performing security functions, such as monitoring software and firewall modules, malfunction, degrade in performance, or are maliciously tampered with, existing systems struggle to effectively detect and diagnose such "self-failure" security incidents.

[0005] Secondly, the existing decision-making process for activating disconnect switches has significant flaws. Their triggering conditions often lack clear, quantifiable definitions, typically relying on general descriptions in flight manuals or pilots' personal experience. For airlines and pilots, when facing complex, potential cybersecurity incidents, the lack of objective, real-time decision support information—such as the exact nature and severity of the threat, and the system's own status—makes it difficult to make a quick and accurate trade-off between ensuring flight safety and maintaining necessary communications, resulting in complex decisions with low tolerance for error.

[0006] In summary, existing technologies suffer from the following core problems: a lack of a comprehensive processing mechanism capable of real-time monitoring and intelligent diagnosis of the aircraft's network security architecture, and providing clear and automated basis for network isolation decisions. This deficiency makes it difficult for aircraft to promptly and effectively initiate isolation protection when facing security incidents originating within the system or external threats requiring complex judgment, posing a security risk. Summary of the Invention

[0007] This invention addresses the aforementioned problems by providing an airborne network security incident handling system and method. This system solves the issues of existing technologies, such as the lack of monitoring of the network security architecture's own status, ambiguous activation conditions for isolation switches, and reliance on human experience for decision-making. The core of this invention lies in constructing an intelligent, hierarchical, and comprehensive processing mechanism. This mechanism enables automated monitoring, diagnosis, alarming, and isolation control of various security incidents caused by external attacks and system anomalies.

[0008] Specifically, one of the objectives of this invention is to establish a multi-source event monitoring and diagnosis system covering both ground and airborne environments. This system integrates a ground-based security log analysis system, a real-time intrusion detection system deployed at critical in-flight network nodes, and a layered self-diagnostic system specifically designed to monitor the operational status of the security system itself. This enables comprehensive and specialized perception and intelligent diagnosis of three types of security events: the first type (security events triggered by the security log analysis system), the second type (security events triggered by the airborne network security system), and the third type (security events triggered by the security self-monitoring system). Furthermore, it sets quantified threshold values ​​for each type of event, transforming ambiguous threats into clear, action-triggering signals.

[0009] Another objective of this invention is to design a centralized, reliable isolation execution mechanism with human priority. This mechanism receives isolation control signals from the aforementioned multi-source diagnostic system through a unified security switch control unit and can automatically drive physical or logical isolation switches to perform network isolation actions. Simultaneously, this mechanism must retain and emphasize the pilot's final decision-making authority, providing a clear manual control interface, combining automatic control with human judgment, ensuring rapid response without depriving the highest level of human intervention.

[0010] Another objective of this invention is to form a complete, closed-loop event handling process through the synergistic operation of the aforementioned monitoring and diagnostic system and isolation execution mechanism. This process can seamlessly connect the perception, analysis, decision-making, and execution stages of an event, thereby significantly improving the aircraft's autonomous protection capabilities and response speed when facing complex cybersecurity threats, and providing pilots with objective and timely decision support, fundamentally reducing the security risks caused by decision delays or misjudgments.

[0011] This invention provides a method for handling airborne network security incidents, the method comprising the following steps: Monitor security incidents from various types of airborne networks originating from different sources. Diagnose security incidents detected from different sources separately; When the diagnostic results indicate that the severity of the security incident meets the predetermined conditions corresponding to the source of the incident, an isolation control signal is generated; In response to the isolation control signal, the isolation device in the airborne network is controlled to operate, disconnecting or restricting data interaction between the airborne network and the external network.

[0012] Specifically, for example, the isolation device in an airborne network can be implemented as a security switch.

[0013] Preferably, the security events include: a first type of security event, which is a security event triggered by the security log analysis system; a second type of security event, which is a security event triggered by the airborne network security system; and a third type of security event, which is a security event triggered by the security self-monitoring system.

[0014] In another embodiment of the method according to the present invention, the method includes the following steps: The security log analysis system monitors the first type of security event and diagnoses the severity of the first type of security event. When the severity of the first type of security event exceeds a first predetermined threshold, a first isolation control signal is generated. The airborne network security system monitors the second type of security incident and diagnoses the severity of the second type of security incident. When the severity of the second type of security incident exceeds a second predetermined threshold, a second isolation control signal is generated. The security self-monitoring system monitors the third type of security event and diagnoses the severity of the third type of security event. When the severity of the third type of security event exceeds a third predetermined threshold, a third isolation control signal is generated. In response to the first isolation control signal, the second isolation control signal, or the third isolation control signal, the security switch in the airborne network is controlled by the isolation execution system to change the connection status between the airborne network and the external network.

[0015] This technical solution employs three independent, specialized subsystems to monitor and diagnose security incidents of different natures. This collaborative architecture effectively avoids the logical complexity and decision-making delays that arise when a single system handles multi-source, heterogeneous events. Each subsystem focuses on a specific type of threat, improving diagnostic accuracy. Ultimately, a unified, isolated execution system responds to various control signals, ensuring consistency and reliability of response actions, thereby achieving comprehensive and efficient security protection for airborne networks.

[0016] In another embodiment of the method of the present invention, the step of monitoring and diagnosing the first type of security incident by the security log analysis system includes: The onboard system records abnormal network behavior to the security log; The security logs are transmitted to the ground-based security database server via air-to-ground communication; The security logs are analyzed by the ground-based security log analysis system and compared with the first predetermined threshold. When the first predetermined threshold is exceeded, the ground control tower issues a network disconnection command and generates the first isolation control signal.

[0017] In another embodiment of the method of the present invention, the step of monitoring and diagnosing the second type of security event by the airborne network security system includes: Monitor network attack events by deploying firewalls at key nodes of the airborne network; The severity of the network attack event is assessed by the firewall or its associated analysis module and compared with the second predetermined threshold. When the second predetermined threshold is exceeded, an on-board network disconnection alarm is triggered, and the second isolation control signal is generated.

[0018] The aforementioned technical solution establishes a collaborative, space-ground-based processing mechanism. By delegating in-depth analysis tasks based on historical logs to the ground system, it fully utilizes the powerful computing resources of the ground, enabling in-depth mining of potential threats while reducing the computational load on the airborne system. Conversely, by assigning real-time network attack monitoring and response tasks to the airborne system, it leverages the low latency of the airborne system to ensure rapid handling of immediate threats. This architecture, which optimizes resource allocation based on task characteristics, significantly improves the overall processing efficiency for security incidents with varying timeframes.

[0019] In another embodiment of the method of the present invention, the third type of security event is an abnormal operation event of the airborne network security system itself.

[0020] Preferably, the steps for monitoring and diagnosing the third type of security incident by the security self-monitoring system include a multi-level diagnostic process: Security data is collected and first-level diagnostics are performed by monitoring components deployed at the module level, and then compared with module-level thresholds. When the module-level threshold is exceeded, the diagnostic information will be reported to the system-level analysis software. The system-level analysis software performs a second-level diagnosis and compares it with the third predetermined threshold to determine whether to generate the third isolation control signal.

[0021] Preferably, the first-level diagnosis is performed by a security management software plugin deployed on multiple functional modules. The security management software plugin reports the collected security monitoring data to the module-level security monitoring component for the first-level diagnosis.

[0022] Preferably, the second-level diagnosis is performed by system-level security management analysis software, and the method further includes: If the second-level diagnostic result does not exceed the third predetermined threshold, the event will be recorded in the security log. If the third predetermined threshold is exceeded, the security alarm component will be triggered to issue an alarm to the pilot and automatically generate the third isolation control signal to switch the security switch.

[0023] Preferably, after generating the third isolation control signal, the method further includes: displaying alarm information to the pilot through the security management software interface and providing a manual control interface for the pilot to manually operate the security switch.

[0024] The aforementioned technical solutions collectively define a multi-layered monitoring and closed-loop management mechanism for the system's own health status. The module-level diagnostic unit enables early detection and preliminary filtering of local anomalies, preventing minor issues from disrupting the entire system. The system-level diagnostic unit comprehensively analyzes reported information, avoiding unnecessary isolation actions triggered by single-point false alarms and improving decision-making accuracy. This mechanism links event logging, threshold judgment, automatic response, and manual intervention into a complete processing closed loop. In particular, the design of automatically generating control signals while retaining the highest priority manual control rights further enhances the system's robustness and ultimate security while ensuring response speed.

[0025] In another embodiment of the method according to the invention, the isolation execution system includes an automatic processing module and a manual processing module; the automatic processing module is used to automatically switch the security switch in response to an isolation control signal; the manual processing module is used to allow the pilot to manually switch the security switch.

[0026] This technical solution clearly defines the isolated execution system as consisting of two independent modules: automatic and manual. The automatic processing module ensures rapid response capabilities when preset conditions are met. The manual processing module serves as a critical redundancy backup, not only functioning in case of automatic module failure but also granting operators final decision-making authority in complex situations. This dual-mode structure establishes a safety principle of human-machine collaboration at the system level, forming a crucial foundation for ensuring absolute reliability of control.

[0027] The present invention also provides an airborne network security incident handling system, the system comprising: The event monitoring and diagnosis module is configured to, The security log analysis system monitors the first type of security incidents and diagnoses their severity. When the first predetermined threshold is exceeded, a first isolation control signal is generated. The airborne network security system monitors the second type of security incidents and diagnoses their severity. When the second type of security incident exceeds a second predetermined threshold, a second isolation control signal is generated. The security self-monitoring system monitors the third type of security incidents and diagnoses their severity. When the incidents exceed a third predetermined threshold, a third isolation control signal is generated. The isolation execution module is communicatively connected to the event monitoring and diagnosis module and is configured to control the security switch in the airborne network in response to the first, second, or third isolation control signal, so as to change the connection status between the airborne network and the external network.

[0028] Preferably, the security self-monitoring system in the event monitoring and diagnosis module for handling the third type of security event further includes a hierarchical diagnosis unit: The module-level diagnostic unit is deployed on each functional module of the airborne network. It is configured to collect security data of the module and perform first-level diagnosis. When the diagnostic results exceed the module-level threshold, the diagnostic information is reported. The system-level diagnostic unit is communicatively connected to the module-level diagnostic unit and is configured to receive reported diagnostic information and perform a second-level diagnosis. When the diagnostic result exceeds the third predetermined threshold, the third isolation control signal is generated.

[0029] Preferably, the system-level diagnostic unit is further configured to record the event to the security log when the second-level diagnostic result does not exceed the third predetermined threshold; and to trigger an alarm and generate the third isolation control signal when it exceeds the threshold. The isolation execution module includes an automatic control submodule and a manual control interface. The automatic control submodule is used to automatically switch the security switch, and the manual control interface is used for manual operation by the pilot.

[0030] The airborne network security incident handling system of the present invention achieves distributed deployment and centralized management of monitoring and diagnostic functions at the system architecture level. Module-level diagnostic units are responsible for collecting and initially processing data locally, reducing the load on the central processing unit and improving local response speed. The system-level diagnostic unit, as the decision-making center, is responsible for information integration and final judgment; its logical flow supports system status tracing and decision auditing. The coexistence of automatic control and manual interfaces solidifies a security redundancy mechanism at both the hardware and software levels, ensuring the system's controllability under different operating conditions.

[0031] The overall technical effect of this invention lies in the fact that by constructing a three-in-one, space-ground coordinated intelligent diagnosis and isolation system that integrates ground log analysis, airborne real-time protection, and system self-monitoring, it achieves automated, refined, and reliable management of all-round security threats faced by airborne networks, including external attacks and internal faults. Based on a divide-and-conquer strategy, the system allocates security events of different types and timeliness to the optimal processing unit, utilizes a ground analysis system for in-depth post-event analysis, relies on the airborne system for low-latency real-time response, and conducts health management of the security architecture itself through a layered closed-loop self-monitoring mechanism from the module level to the system level. This ensures the accuracy and timeliness of threat diagnosis in principle. Finally, through an isolation execution mechanism combining automatic response and manual decision-making, it significantly improves the overall protection level, decision support reliability, and system robustness of civil aircraft in cybersecurity incidents. Attached Figure Description

[0032] The following figures are only used to provide a further understanding of the present invention and form part of this specification. They are used to explain the principles of the present invention and do not constitute a limitation thereof.

[0033] In the diagram: Figure 1 A schematic diagram of the architecture for self-monitoring and isolation of airborne information system network security; Figure 2 A schematic diagram of the airborne network security monitoring and isolation process; and Figure 3 This is a schematic diagram of the workflow of a security self-monitoring system for the third type of security incident.

[0034] List of reference numerals

[0035] 1200 Information Systems; 1210 Air-to-ground communication module; 1220 Firewall; 1230 Security Self-Monitoring Module; 1231 Security Management Software Plugin; 1232 Security monitoring components; 1233 Security Control Components; 1234 Security Management Analysis Component; 1235 Security Alarm Component; 1236 Security Management Software Interface; 1240 Security Switch; 1100 Avionics Core Network; 1110 Other systems; 1300 Cabin System; 1400 Ground System; 1410 Security Database Server; 1420 Log Analysis System. Detailed Implementation

[0036] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present application.

[0037] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate for the embodiments of this application described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion, for example, that a process, method, system, product, or apparatus comprising a series of steps or units must precede those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0038] In this application, the terms "upper," "lower," "left," "right," "front," "rear," "top," "bottom," "inner," "outer," "middle," "vertical," "horizontal," "lateral," and "longitudinal" indicate directions or positional relationships based on the orientations or positional relationships shown in the accompanying drawings. These terms are primarily for the purpose of better describing this application and its embodiments, and are not intended to limit the indicated devices, elements, or components to having a specific orientation, or to be constructed and operated in a specific orientation.

[0039] Furthermore, in addition to indicating location or positional relationship, some of the aforementioned terms may also have other meanings. For example, the term "above" may also be used in certain circumstances to indicate a certain dependency or connection relationship. Those skilled in the art can understand the specific meaning of these terms in this application according to the specific circumstances.

[0040] Furthermore, the terms "installation," "setting," "arrangement," "equipped with," "connection," "linking," and "socketing" should be interpreted broadly. For example, they can refer to fixed connections, detachable connections, or integral structures; they can refer to mechanical connections or electrical connections; they can refer to direct connections or indirect connections through an intermediary, or internal connections between two devices, components, or parts. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances. Airborne network: refers to the general term for the communication network within an aircraft used to interconnect various airborne equipment such as avionics systems, information systems, and cabin entertainment systems, responsible for transmitting critical flight data and non-critical mission data. Now, necessary explanations are provided for some terms used in this application. "Security incident" refers to any act or system state that endangers or potentially endangers the security of airborne networks, i.e., its data confidentiality, integrity, and availability, including external network attacks and internal system failures. "Security switch" refers to a control unit with logical or physical isolation functions, whose core function is to execute or disconnect the data communication link between the airborne core network and the external network; it is a key component for achieving network isolation. "Preset threshold" refers to a configurable, quantitative critical parameter pre-set based on security risk assessment, used to compare monitoring data with standard values ​​to objectively determine whether a corresponding level of security response is triggered. "Air-to-ground communication" refers to the two-way communication process where an aircraft transmits data to a ground system via links such as radio or satellite communication. Additionally, it should be noted that in this application, "Category I security event" refers to a ground analysis-triggered event, i.e., a security log analysis system-triggered security event, which refers to a potential or confirmed network threat identified after transmitting operational and security logs recorded by airborne network equipment to a ground analysis center and undergoing in-depth analysis (such as big data analysis and threat intelligence matching) by the ground system. "Category II security event" refers to an airborne network security system-triggered security event, specifically a network attack detected in real-time or near real-time by active protection devices such as firewalls and intrusion detection systems deployed at the boundaries between the airborne network and external networks, such as air-to-ground communication links and cabin network boundaries. "Category III security incidents" refer to security incidents triggered by the security self-monitoring system, specifically incidents in which components, modules, or communication links of the airborne network security system itself experience functional abnormalities, performance degradation, or complete failure.

[0041] It should be noted that, where there is no conflict, the embodiments and features described in this application can be combined with each other. To make the solution of the present invention clearer, the present invention will be further described below with reference to the accompanying drawings and specific embodiments.

[0042] like Figure 1 The diagram illustrates the architecture of an airborne network security incident handling system according to an embodiment of the present invention. The system physically and logically constitutes the core entity for implementing the method of the present invention. Its hardware components are distributed across key nodes of the airborne network and ground facilities, interconnected via a specific data bus and communication link. The system includes at least an event monitoring and diagnosis module and an isolation execution module.

[0043] The event monitoring and diagnosis module, serving as the system's information perception and decision-making center, is responsible for the continuous monitoring and diagnosis of security threats from three different sources. This module is implemented through three functionally independent but potentially physically separate subsystems. First is the security log analysis system 210, which includes at least a security log analysis system 1420 and a security database server 1410 deployed at the ground operations center. These systems establish communication connections with the airborne system via an air-to-ground data link, such as a satellite communication link, forming a cross-regional security information channel. The security log software 1251 is uploaded to the ground server via the airborne communication management unit and the air-to-ground communication module 1210 of the information system 1200. After the ground system completes in-depth analysis, if the security threshold N1 is exceeded, the generated first isolation control signal, i.e., a network disconnection command, is transmitted back to the airborne information system 1200 via the same air-to-ground data link. Secondly, there is the airborne network security system 220, which is installed inside the aircraft. Its detection equipment, such as the firewall 1220, is directly embedded in the physical network links between the avionics core network 1100, the information system 1200, the cabin system 1300, and the ground system 1400. This system enables real-time deep detection and online analysis of the data flowing through it, and generates a second isolation control signal directly inside the aircraft when the attack is determined to exceed the security threshold N2. Thirdly, there is the security self-monitoring system 230, which is also installed in the airborne network and adopts a layered architecture combining distributed and centralized approaches. This security self-monitoring system includes at least a security management software plug-in 1231 and a security monitoring component 1232 installed on each functional module. The security self-monitoring system reports the collected security monitoring data and preliminary diagnostic results through the internal data bus of the airborne network. The security monitoring system also includes a system-level diagnostic unit, namely security management analysis software, which aggregates security monitoring data through the system bus, performs correlation analysis, and generates a third isolation control signal.

[0044] The airborne network security incident handling system according to the present invention also includes an isolation execution module. This isolation execution module further includes at least a security switch control unit. The security switch control unit establishes a reliable network communication connection with the three event monitoring and diagnostic modules mentioned above via discrete signals, continuously monitoring isolation control signals from the security log analysis system 210, the airborne network security system 220, or the security self-monitoring system 230. When the isolation execution module receives any valid isolation control signal, its automatic control function is activated, outputting a corresponding electrical control signal to the security switch 1240. The security switch 1240 is typically a software-controlled relay or an access control list (ACL) module integrated into a network switch, capable of directly disconnecting the protected network domain, such as physical or logical links connecting to other network domain ports. Simultaneously, the isolation execution module also integrates a manual control interface, which is hardwired to the cockpit security management software interface 1236 and related physical switches, ensuring that the pilot's commands have the highest priority and can directly manipulate the status of the security switch 1240 at any time.

[0045] The three subsystems within the event monitoring and diagnostic module are parallel threat perception sources. They asynchronously send isolation control signals to the isolation execution module via different physical media, such as air-to-ground data links and in-flight network buses, controlling the opening and closing of security switches or providing instructions to the pilots to operate the security switches based on the actual situation. The isolation execution module, as a unified signal aggregation and execution endpoint, integrates and processes the received multiple signals through its internal logic. All modules form a complete closed-loop control system via the airborne network and data bus, achieving automation and intelligence from threat perception, analysis and decision-making to isolation execution, while retaining a crucial channel for manual intervention.

[0046] This invention also provides a method for handling airborne network security incidents. For the first type of security incident, which typically involves complex threats requiring in-depth analysis by ground systems, the handling is triggered by a ground-based security log analysis system 210. During operation, various terminal devices and servers in the airborne network continuously monitor their own network behavior. When abnormal network behaviors such as abnormal login attempts, unauthorized access, IP packet intrusion, and routing spoofing are detected, these modules record the specific type of the event, including timestamps, source / destination IP addresses, and event type, in local security log software 1251. Subsequently, these logs are transmitted to a ground-based security database server 1410 for centralized storage via an air-to-ground communication module 1210 in the information system, such as a satellite communication link. The ground-based security log analysis system 1420 parses and performs correlation analysis on the received log data, for example, using big data technology to identify advanced persistent threats (APT) across time periods and flights. The system compares the analyzed threat level with a preset security threshold N1. Figure 2 As shown, if the analysis result exceeds the threshold, the ground control tower operator can confirm and directly send a network disconnection command 202, i.e., the first isolation control signal, to the aircraft via air-to-ground communication. After the command is sent to the aircraft, the system will issue an alarm to the pilot, who will then manually switch the security switch 1240 from the On (connected) state to the Off (disconnected) state.

[0047] When a security incident is not classified as a Category I security incident, a Category II security incident assessment is required. Category II security incidents are typically real-time onboard cyberattacks triggered by the onboard network security system 220. This patent designs a domain-specific network security architecture, deploying firewall 1220 between the avionics core network 1100 and the information system 1200, and also between the information system 1200 and the cabin system 1300 and the ground system 1400. These firewalls or intrusion detection systems (IDS) perform real-time deep inspection of all incoming network packets. When a packet is detected that matches a known attack signature database, such as syn Flood attacks or malware communication signatures, it is identified as a cyberattack incident. The analysis module associated with the firewall immediately assesses the severity of the incident, considering factors such as attack type and packet rate. Figure 2 As shown, if the severity of the issue exceeds the preset security threshold N2, the airborne network security system 220 immediately triggers an onboard network outage alarm 203 and generates a second isolation control signal. The security management analysis component 1234 will perform automatic processing, as shown in step 205, generating a control signal to switch the security switch 1240 from the On state to the Off state. After receiving the alarm, the pilot will check the situation. If the automatic processing does not proceed as expected, the pilot can manually operate the security switch 1240.

[0048] like Figure 2 As shown, when a security incident is neither a Category 1 nor a Category 2 security incident, Category 3 security incident analysis and processing are performed. As shown in step 204, the system will determine whether to execute a self-check network disconnection alarm. Category 3 security incidents are typically due to abnormal operation of the security system itself, such as... Figure 3The diagram illustrates the flow of a hierarchical diagnostic method according to an embodiment of the present invention. After the aircraft is powered on, the information system network security self-monitoring system starts 301. As shown in step 302, the security management software plug-in 1231 deployed on each functional module starts and collects security monitoring data for that module, including CPU utilization, memory usage, critical process status, network port error count, etc. As shown in step 303, this data is reported to the module-level security monitoring component 1232. As shown in step 304, the security monitoring component 1232 performs real-time diagnosis based on the security threshold M defined in the security event list 313, completing the first level of diagnosis. If the diagnosis result is less than the security threshold M, the system maintains continuous monitoring; if the diagnosis result is greater than or equal to the security threshold M, as shown in step 305, it needs to be summarized to the module-level security control component 1233. Subsequently, as shown in step 306, the summarized diagnostic information is reported to the system-level security management analysis component 1234 according to different methods and data formats based on the security event category.

[0049] Upon receiving the report, the system-level security management analysis component 1234 performs security event diagnosis, i.e., second-level systemic correlation analysis, as shown in step 307. The diagnosis result is compared with the more stringent security threshold N3 defined in the security event list 314. If the diagnosis result is less than the security threshold N3, as shown in step 308, it is recorded and stored in the security log 1251. If the diagnosis result is greater than or equal to the security threshold N3, as shown in steps 309 and 311, the security alarm component 1235 is triggered for display, directly on the security case analysis software interface, providing a security alarm to the pilot via audible and visual signals. Simultaneously, as shown in step 310, the security management analysis component 1234 automatically processes and generates a third isolation control signal to switch the security switch 1240 from On to Off. The security alarm information and system status are displayed on the security management software interface 1236, and a manual control interface is provided, as shown in 312. Pilots can select manual processing through the prompts on this interface, that is, manually intervene in the status of the security switch, including confirmation, delay or cancellation operations.

[0050] Finally, the isolation execution system comprehensively processes the isolation control signals triggered by the three types of events mentioned above. Upon receiving a valid control signal, the system's automatic processing module directly activates security switches, such as electronic switches controlling network exchange ports, to disconnect the aircraft's network control domain from other network domains. In addition, the isolation execution system always provides manual processing modules, such as physical or virtual switches in the cockpit, ensuring that the pilot always has final decision-making and control authority.

[0051] The implementation of this invention is not limited to the embodiments described above, and can be adjusted and optimized according to different design requirements and usage environments. The scope of protection of this invention should be determined by the content of the claims, and not limited to the embodiments described above. Although this invention has been described through specific embodiments, any modifications, changes, and combinations made by those skilled in the art to the various embodiments and implementation methods of this invention without departing from the spirit of this invention should be within the scope of protection of this invention.

Claims

1. A method for handling airborne network security incidents, characterized in that, Includes the following steps: Monitor security incidents from various types of airborne networks originating from different sources. Diagnose security incidents detected from different sources separately; When the diagnostic results indicate that the severity of the security incident meets the predetermined conditions corresponding to the source of the incident, an isolation control signal is generated; In response to the isolation control signal, the isolation device in the airborne network is controlled to operate, disconnecting or restricting data interaction between the airborne network and the external network.

2. The method according to claim 1, characterized in that, The security incidents include: The first category of security incidents refers to security incidents triggered by the security log analysis system. The second category of security incidents refers to security incidents triggered by airborne network security systems; and The third type of security incident refers to a security incident triggered by the security self-monitoring system.

3. The method according to claim 2, Its features are, The method includes the following steps: The security log analysis system monitors the first type of security event and diagnoses the severity of the first type of security event. When the severity of the first type of security event exceeds a first predetermined threshold, a first isolation control signal is generated. The airborne network security system monitors the second type of security incident and diagnoses the severity of the second type of security incident. When the severity of the second type of security incident exceeds a second predetermined threshold, a second isolation control signal is generated. The security self-monitoring system monitors the third type of security event and diagnoses the severity of the third type of security event. When the severity of the third type of security event exceeds a third predetermined threshold, a third isolation control signal is generated. In response to the first isolation control signal, the second isolation control signal, or the third isolation control signal, the security switch in the airborne network is controlled by the isolation execution system to change the connection status between the airborne network and the external network.

4. The method according to claim 3, characterized in that, The steps for monitoring and diagnosing the first type of security incident by the security log analysis system include: The onboard system records abnormal network behavior to the security log; The security logs are transmitted to the ground-based security database server via air-to-ground communication; The security logs are analyzed by the ground-based security log analysis system and compared with the first predetermined threshold. When the first predetermined threshold is exceeded, the ground control tower issues a network disconnection command and generates the first isolation control signal.

5. The method according to claim 3, characterized in that, The steps for monitoring and diagnosing the second type of security incident by the airborne cybersecurity system include: Monitor network attack events by deploying firewalls at key nodes of the airborne network; The severity of the network attack event is assessed by the firewall or its associated analysis module and compared with the second predetermined threshold. When the second predetermined threshold is exceeded, an on-board network disconnection alarm is triggered, and the second isolation control signal is generated.

6. The method according to claim 3, characterized in that, The steps for monitoring and diagnosing the aforementioned third type of security incidents by the security self-monitoring system include a multi-level diagnostic process: Security data is collected and first-level diagnostics are performed by monitoring components deployed at the module level, and then compared with module-level thresholds. When the module-level threshold is exceeded, the diagnostic information will be reported to the system-level analysis software. The system-level analysis software performs a second-level diagnosis and compares it with the third predetermined threshold to determine whether to generate the third isolation control signal.

7. The method according to claim 6, characterized in that, The first-level diagnosis is performed by the security management software plug-in deployed on each functional module. The security management software plug-in reports the collected security monitoring data to the module-level security monitoring component for the first-level diagnosis.

8. The method according to claim 6 or 7, characterized in that, The second-level diagnosis is performed by system-level security management analysis software, and the method further includes: If the second-level diagnostic result does not exceed the third predetermined threshold, the event will be recorded in the security log. If the third predetermined threshold is exceeded, the security alarm component will be triggered to issue an alarm to the pilot and automatically generate the third isolation control signal to switch the security switch.

9. The method according to claim 8, characterized in that, After generating the third isolation control signal, the method further includes: The security management software interface displays alarm information to the pilot and provides a manual control interface for the pilot to manually operate the security switch.

10. The method according to claim 3, characterized in that, The isolation execution system includes an automatic processing module and a manual processing module; the automatic processing module is used to automatically switch the security switch in response to the isolation control signal; the manual processing module is used for the pilot to manually switch the security switch.

11. An airborne network security incident handling system, characterized in that, The system includes at least: The event monitoring and diagnosis module is configured to, - Monitor the first type of security incident through the security log analysis system, and perform severity diagnosis on the first type of security incident. When the first predetermined threshold is exceeded, generate the first isolation control signal. - Monitor the second type of security incident through the airborne network security system, and perform severity diagnosis on the second type of security incident. When the second predetermined threshold is exceeded, generate a second isolation control signal. - Monitor third-category security incidents through a security self-monitoring system, diagnose the severity of these incidents, and generate a third isolation control signal when the incident exceeds a predetermined third threshold; and An isolation execution module, which is communicatively connected to the event monitoring and diagnosis module, is configured to control the security switch in the airborne network and change the connection status between the airborne network and the external network in response to the first isolation control signal, the second isolation control signal, or the third isolation control signal.

12. The system according to claim 11, characterized in that, The security self-monitoring system in the event monitoring and diagnosis module for handling the third type of security event further includes: A module-level diagnostic unit is installed on each functional module of the airborne network. This unit is configured to collect security data from its respective module and perform first-level diagnostics. When the diagnostic results exceed a module-level threshold, it reports the diagnostic information. A system-level diagnostic unit, which is communicatively connected to the module-level diagnostic unit, is configured to receive reported diagnostic information and perform a second-level diagnosis. When the diagnostic result exceeds the third predetermined threshold, the third isolation control signal is generated.

13. The system according to claim 12, characterized in that, The system-level diagnostic unit is further configured to record the event to the security log when the second-level diagnostic result does not exceed the third predetermined threshold; and to trigger an alarm and generate the third isolation control signal when it exceeds the threshold. The isolation execution module includes an automatic control submodule and a manual control interface. The automatic control submodule is used to automatically switch the security switch, and the manual control interface is used for manual operation by the pilot.