False data injection method, medium and device for afdx network security testing

By constructing a test data stream that conforms to the constraints of the AFDX network, and by injecting reset frames or spoof data frames into the sending device to trigger the protocol mechanism of the receiving device, the problem of being unable to simulate malicious attacks in the existing technology is solved, and the security and stability of the AFDX network are effectively evaluated.

CN122120038AActive Publication Date: 2026-05-29CIVIL AVIATION UNIV OF CHINA
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CIVIL AVIATION UNIV OF CHINA
Filing Date
2026-04-28
Publication Date
2026-05-29

Smart Images

  • Figure CN122120038A_ABST
    Figure CN122120038A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of network security, and particularly relates to a false data injection method, medium and equipment for AFDX network security testing, which generates baseline configuration information and network security testing configuration information, takes into account normal communication specifications and security testing requirements, and the test data stream constructed can contain reset frames or false data frames on the premise of meeting AFDX protocol constraints, thereby ensuring compliance of attack traffic while realizing precise construction of attack payloads; the test data stream is injected into the AFDX network, and preset rules are used to realize reset attacks or false data injection attacks, respectively, so as to realize attack effects by using the protocol mechanism of the AFDX network itself, make the attack behavior have concealment, repeatability and controllability, and truly simulate malicious attack scenarios, thereby making up for the shortcomings of the prior art which only faces occasional fault testing, and effectively evaluating the security, availability and stability of the AFDX network under malicious attack conditions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method, medium, and device for injecting fake data for AFDX network security testing. Background Technology

[0002] As the core communication backbone of avionics systems, the security and reliability of AFDX networks are directly related to flight safety. Existing AFDX network security testing technologies are mainly divided into two categories: one is the protocol layer-based software simulation method, which builds an AFDX network model through a simulation platform or mathematical modeling and injects errors in protocol layer fields to verify the network's fault tolerance; the other is to inject hardware electrical signal faults through the access bus, affecting the communication process by interfering with electrical parameters such as bus voltage and current, and testing the equipment's anti-interference capability.

[0003] However, the above methods have the following technical shortcomings: On the one hand, existing testing technologies are mainly aimed at verifying reliability and fault tolerance under occasional failure conditions. The test scenarios are concentrated on natural anomalies or accidental failures such as link jitter, packet loss, and bit flipping, and lack specialized testing methods for scenarios of malicious attacks. On the other hand, traditional methods are based on the assumption that the AFDX network is physically isolated, has clear boundaries, and has trustworthy nodes. As airborne networks are gradually connected to external networks such as ground operation and maintenance networks and airborne wireless data links, the environment in which the AFDX network is located is changing from closed to open interconnection. Existing testing methods based on the trust assumption can hardly effectively simulate strategic, time-sequential, and covert attack behaviors such as fake data injection, and cannot truly evaluate the security, availability, and stability of the AFDX network under malicious attack conditions.

[0004] Therefore, how to conduct effective security testing of AFDX networks in the face of malicious attack scenarios has become an urgent problem to be solved. Summary of the Invention

[0005] To address the aforementioned technical problems, the present invention provides a method for injecting fake data for AFDX network security testing. This method includes the following steps: S1. Generate baseline configuration information and network security test configuration information using the AFDX network configuration tool. The baseline configuration information includes at least virtual link parameters and network constraints. The network constraints include redundancy management rules for network A and network B, as well as data frame integrity check rules. The network security test configuration information includes at least the target virtual link identifier, test start time, and injection strategy.

[0006] S2, based on the baseline configuration information and network security test configuration information, construct a test data stream that meets the network constraints through the sending device of the AFDX network. The test data stream contains at least an injected data frame, which includes a reset frame with sequence number SN=0 or a spoof data frame from the A network.

[0007] S3. The target virtual link is determined by the target virtual link identifier. The test data stream is injected into the AFDX network from the target virtual link according to the test start time and injection strategy. If the injected data frame is a reset frame with sequence number SN=0, the integrity check rule of the receiving device of the AFDX network is triggered by the reset frame, causing the receiving device to discard the first normal data frame after the reset frame. If the injected data frame is a fake data frame in network A, jitter delay is added to the corresponding normal data frame in network B, and the redundancy management rule causes the receiving device to prioritize receiving the fake data frame.

[0008] S4: Acquire and record the response data generated by the AFDX network during the test data stream injection, and generate security test results based on the response data.

[0009] The present invention also provides a non-transitory computer-readable storage medium storing at least one instruction or at least one program, wherein the at least one instruction or at least one program is loaded and executed by a processor to implement the above-described method for injecting fake data for AFDX network security testing.

[0010] The present invention also provides an electronic device, including a processor and the aforementioned non-transitory computer-readable storage medium.

[0011] This invention has at least the following beneficial effects: By decoupling normal communication parameters and security test parameters through baseline configuration information and network security test configuration information, it takes into account both normal communication specifications and security test requirements; and by constructing a test data stream that conforms to network constraints based on the sending device of the AFDX network, the test data stream can contain a reset frame with sequence number SN=0 or a fake data frame from the A network, under the premise of satisfying the AFDX protocol constraints. This ensures the compliance of attack traffic while achieving accurate construction of the attack payload, avoiding the risk of uncontrollable network. By injecting the test data stream into the AFDX network through an injection strategy, and using integrity check rules and redundancy management rules to achieve a reset attack or a fake data injection attack on the receiving device, the attack effect is achieved by utilizing the protocol mechanism of the AFDX network itself. This makes the attack behavior covert, repeatable, and controllable, realistically simulating network behavior under malicious attack scenarios. It makes up for the shortcomings of existing technologies that are only for testing occasional failures, and provides an objective quantitative evaluation basis for the performance degradation degree, security impact range, and security protection capability of the AFDX network, providing effective support for the verification and subsequent improvement of the AFDX network's security protection mechanism. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other related drawings can be obtained based on the above drawings without creative effort.

[0013] Figure 1 A flowchart illustrating a method for injecting fake data in AFDX network security testing, provided in Embodiment 1 of the present invention; Figure 2 This is a schematic diagram of the sending device in a fake data injection method for AFDX network security testing provided in Embodiment 1 of the present invention; Figure 3 This is a schematic diagram of the AFDX switch in a fake data injection method for AFDX network security testing provided in Embodiment 1 of the present invention. Detailed Implementation

[0014] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0015] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It is understood that, where appropriate, the terms used to distinguish similar objects can be interchanged so that the invention can also be implemented in other embodiments besides the illustrated or described embodiments. Furthermore, the terms "including," "having," and any variations are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to these processes, methods, products, or devices.

[0016] Example 1 This first embodiment provides a method for injecting fake data for AFDX network security testing, such as... Figure 1 As shown, the fake data injection method used for AFDX network security testing includes the following steps: S1 generates baseline configuration information and network security test configuration information using the AFDX network configuration tool.

[0017] The normal operation of an AFDX network requires strict parameter constraints, such as bandwidth allocation intervals, traffic shaping, and redundancy management. This embodiment employs a two-layer configuration mechanism, separating the baseline configuration required for normal communication from the attack configuration required for security testing, forming two sets of independent yet interconnected configuration information. The baseline configuration defines the rules for the normal operation of the AFDX network, while the network security testing configuration defines the strategies for attack behavior. The combination of the two provides a unified parameter constraint basis for the construction of subsequent attack traffic.

[0018] Specifically, baseline configuration information consists of fundamental communication parameters essential for the normal operation of the AFDX network. It contains no attack / test content and is used to ensure that network topology, virtual links, redundancy mechanisms, speed, latency, etc., comply with avionics standards, ensuring the test environment is a genuine and usable AFDX network. Network security test configuration information is specifically designed for executing spoofing and reset attacks, providing precise control over "when to inject, which link to inject into, how to inject, and for how long." This embodiment uses the AFDX network configuration tool to generate two types of configuration files based on user-input parameters. These are typically saved in INI file format and deployed to end systems and switches within the AFDX network, serving as unified parameter constraints and experimental scenario definitions for security test simulations.

[0019] The baseline configuration information includes at least virtual link parameters and network constraints. Network constraints include redundancy management rules for networks A and B, as well as data frame integrity check rules. Network security test configuration information includes at least the target virtual link identifier, test start time, and injection strategy. Specifically, virtual link parameters include virtual link ID, bandwidth allocation interval, maximum frame length, end-system output rate, and token bucket parameters (ρ, σ, where ρ is the rate limit and σ is the bucket depth / allowed burst size), used to define the communication resource allocation for each virtual link, ensuring the determinism and predictability of data transmission.

[0020] Redundancy management rules are a dual-redundancy management mechanism for networks A and B. This mechanism determines which frame the receiving end chooses to deliver to the upper layer upon receiving data frames from both networks. It includes the maximum allowable offset time to define the dual-network redundancy processing logic and ensure high availability of communication. The maximum offset time is the maximum allowed time difference between the two redundant signals from networks A and B. It is used to determine whether two network replicas belong to the same message; if the time difference exceeds this maximum, they are considered independent messages.

[0021] Integrity check rules include a sliding window range for data frame sequence numbers and a reset flag for SN=0. These rules ensure that the receiving device can correctly identify out-of-order, duplicate, or abnormal frames and process them accordingly. The sliding window range is the range of sequence numbers the receiving device can accept, typically [PSN+1, PSN+2]. This allows for out-of-order reception while preventing erroneous reception due to excessively large sequence number jumps. The reset flag for SN=0 is a special sequence number indicating a system reset at the sending end, used to trigger the receiving device to reset the sequence number record.

[0022] The target virtual link identifier determines which virtual link the test data stream will be injected into the AFDX network from, thus identifying the target virtual link as the link for injecting the test data stream. The test start time identifies the attack's initiation moment, controlling the precise timing of the attack and supporting timed and coordinated attack scenarios. The injection strategy defines the specific parameters of the attack behavior, determining the attack type (reset attack or fake data injection) and its execution method.

[0023] As described above, the AFDX network configuration tool is used to generate baseline configuration information and network security test configuration information respectively, which decouples normal communication parameters from security test parameters, takes into account both normal communication standards and security test requirements, and provides a unified parameter constraint basis for the accurate construction of subsequent attack traffic.

[0024] In one specific implementation, when the injection strategy is a receiver reset test, the injection strategy includes at least an injection period and an injection duration. When the injection strategy is a sender spoof data injection test, the injection strategy includes at least an injection start time, an injection duration, a jitter delay duration, and a maximum interval time window.

[0025] Correspondingly, S1 includes the following steps: S11, obtain the network topology scale, network speed, link latency, link jitter and priority parameters of the AFDX network as the network structure and link conditions in the baseline configuration information. The network topology scale includes the number of end systems, the number of switches and the connection relationship.

[0026] S12, based on the network structure and link conditions, configure the virtual link ID, bandwidth allocation interval, maximum frame length, end system output rate and token bucket parameters, and generate virtual link parameters.

[0027] S13, based on the virtual link parameters, configure the maximum allowable offset time for redundancy in network A and network B, and generate redundancy management rules.

[0028] S14. Based on the redundancy management rules, configure the sliding window range of the data frame sequence number and the reset flag for sequence number SN=0, and generate integrity check rules.

[0029] S15. Based on the virtual link parameters, configure the test start time, target virtual link identifier, injection period, injection duration, injection start time, jitter delay duration, and maximum interval time window to generate network security test configuration information.

[0030] The communication behavior of an AFDX network is influenced by its physical topology and link quality. The network topology determines the data forwarding path and complexity; parameters such as network speed, link latency, and link jitter directly affect the transmission timing of data frames, thus influencing the triggering conditions of redundancy management rules and integrity check rules. Therefore, based on the actual physical deployment of the AFDX network, the number of end systems, the number of switches and their interconnections, as well as the transmission speed, latency, jitter, and priority configuration of each link are obtained as the basis for baseline configuration.

[0031] Virtual links are logical channels for data communication in an AFDX network. The bandwidth allocation interval and token bucket parameters of each virtual link jointly determine its traffic characteristics. By configuring virtual link parameters, the transmission rate and burst characteristics of normal service traffic can be precisely controlled, providing a reference benchmark for the superposition effect of subsequent attack traffic and normal traffic. Therefore, a unique virtual link ID is assigned to each virtual link, and the bandwidth allocation interval, maximum frame length, and end-system output rate are set according to network bandwidth and service requirements. The token bucket parameters ρ and σ are also configured.

[0032] The AFDX network employs an A / B dual-network redundancy mechanism, where the same message is transmitted independently on both networks. The receiving end determines whether the messages belong to the same network based on the arrival times and maximum offset times of the two signals. Therefore, configuring the maximum offset time determines the merging window for redundancy management, affecting the processing logic of redundant data. Specifically, based on the bandwidth allocation interval of the virtual link and the network link characteristics, the maximum allowable offset time for redundancy in networks A and B is set as the core parameter of the redundancy management rules.

[0033] AFDX networks ensure data frame integrity through a sequence number (SN) mechanism. The receiver maintains a sliding window, accepting only sequence numbers within the window's range; data frames outside this range are discarded. Sequence number SN=0 is reserved as a special flag for sender reset. Upon receiving SN=0, the receiver resets the sequence number record, expecting the window to reset to {1, 2}. Correspondingly, the sliding window range (typically from the most recently received sequence number PSN+1 to PSN+2) is set, and the reset semantics for sequence number SN=0 are defined as the core content of the integrity check rules.

[0034] The network security test configuration information defines the execution parameters of the attack behavior. Different attack types (reset attack or spoofing injection) require different parameter combinations. The test start time controls when the attack begins; the injection period (the interval between two reset frame transmissions) and injection duration (the duration of the attack) control the rhythm of the reset attack; the injection start time, injection duration, jitter delay duration, and maximum interval time window control the execution method of spoofing injection. Specifically, for the receiver reset test: configure the injection period and injection duration; for the sender spoofing injection test: configure the injection start time, injection duration, jitter delay duration (the delay of the B network data frame), and maximum interval time window (the upper limit of the time difference between the arrival of A and B network data frames).

[0035] The above-mentioned systematic parameter configuration organically integrates the basic communication specifications of the AFDX network with the security testing requirements, laying the foundation for the entire fake data injection testing method and ensuring the compliance of attack traffic, the controllability of attack behavior, and the reliability of test results in subsequent steps.

[0036] S2, based on the baseline configuration information and network security test configuration information, construct a test data stream that meets the network constraints through the sending device of the AFDX network. The test data stream contains at least an injected data frame, which includes a reset frame with sequence number SN=0 or a spoof data frame from the A network.

[0037] Among them, the sending end device is the AFDX end system that performs data transmission, that is, the test injection device of the AFDX network, which is responsible for constructing and sending test data streams that conform to protocol constraints.

[0038] The configuration information is read through the configuration file interface of the sending device, and normal business messages and injected data frames are generated respectively. After a series of processes such as virtual link mapping, UDP / IP encapsulation, queuing scheduling, traffic shaping, and A / B dual redundancy replication, a test data stream that conforms to the AFDX protocol constraints is output.

[0039] It should be noted that in this embodiment, normal service messages and injected data frames are generated independently and processed in parallel. All processing steps strictly follow the AFDX protocol specification, and the injected data frames are identical in format to normal data frames, differing only in content (sequence number or payload).

[0040] In one specific implementation, such as Figure 2 As shown, the sending device includes a configuration file interface 201, a message parameter configuration unit 202, a message generation unit 203, a security test message parameter configuration unit 204, a security test message generation unit 205, a virtual link mapping and AFDX encapsulation unit 206, a virtual link sending queue and scheduling selection unit 207, a traffic shaping unit 208, and a redundancy control unit 209. S2 includes the following steps: S21 reads and parses baseline configuration information and network security test configuration information through configuration file interface 201.

[0041] S22, based on the virtual link parameters, the bandwidth allocation interval and token bucket parameters are obtained through the message parameter configuration unit 202, and normal service messages are generated through the message generation unit 203.

[0042] S23, according to the injection strategy, the injection parameters are obtained through the security test message parameter configuration unit 204, and the injection data frame is generated through the security test message generation unit 205.

[0043] S24, normal service messages and injected data frames are mapped to the target virtual link and encapsulated by the AFDX encapsulation unit 206 through the virtual link mapping, thus completing the mapping and UDP / IP encapsulation.

[0044] S25, the encapsulated data frame is queued and scheduled through the virtual link transmission queue and scheduling selection unit 207.

[0045] S26, the scheduled data frame is shaped by the traffic shaping unit 208 according to the bandwidth allocation interval and token bucket parameters.

[0046] S27, the shaped data frame is copied to network A and network B using the redundancy control unit 209 to obtain a test data stream that meets the network constraints.

[0047] In one specific embodiment, S23 includes the following steps: When the injection strategy is receiver reset test, a reset frame with sequence number SN=0 is generated by the security test message generation unit 205.

[0048] When the injection strategy is to inject fake data into the sender, fake data frames in network A are generated by the security test message generation unit 205.

[0049] The configuration file interface 201 is an interface module in the sending device used to read configuration information, specifically baseline configuration information and network security test configuration information. The message parameter configuration unit 202 is used to obtain normal service message generation parameters, extracting information such as source / destination IP, port number, bandwidth allocation interval, and token bucket parameters from the configuration information. The message generation unit 203 is used to generate normal service messages, generating normal data messages that meet business requirements based on the message parameters.

[0050] The security test message parameter configuration unit 204 is used to obtain injection parameters (such as injection start time, jitter delay duration, etc.) from the network security test configuration information. The security test message generation unit 205 is used to generate injection data frames (attack payloads), and can generate reset frames with sequence number SN=0 or fake data frames from network A according to the injection strategy. The virtual link mapping and AFDX encapsulation unit 206 maps messages to a specified virtual link and completes UDP / IP encapsulation, used to complete data encapsulation of the AFDX protocol stack and generate standard AFDX data frames. The virtual link sending queue and scheduling selection unit 207 is used to queue and schedule the encapsulated data frames, used to determine the sending order of the data frames, and supports timing control such as periodic injection. The traffic shaping unit 208 is used to perform rate control and traffic shaping of data frames, used to constrain the sending rate according to the bandwidth allocation interval and token bucket parameters to ensure compliance with protocol specifications. If the sending rate of a data frame exceeds the allowable range, it will be delayed or discarded. The redundancy control unit 209 is the unit that performs A / B dual-network redundancy replication. It is used to copy data frames into two copies and send them to the transmission queues of network A and network B respectively, and finally output them to the AFDX network through physical ports. Queuing and scheduling refers to queuing multiple data frames to be sent according to priority or timing rules and sending them in sequence, controlling the transmission order and timing of data frames, and supporting requirements such as periodic attacks.

[0051] Normal service messages are data streams that operate normally in the AFDX network. Their generation must adhere to constraints in the virtual link parameters, such as bandwidth allocation interval, maximum frame length, and token bucket parameters. The message parameter configuration unit 202 extracts these parameters from the configuration information, and the message generation unit generates data messages that conform to the specifications accordingly.

[0052] Injected data frames are special data frames carrying attack payloads. The security test message generation unit 205 generates the corresponding injected data frame based on the type of injection strategy (receiver reset test or sender spoofing data injection test). Specifically, when the injection strategy is receiver reset test: a reset frame with sequence number SN=0 is generated. This reset frame is formatted identically to a normal data frame, and its other fields (source / destination IP, port number, virtual link ID, data payload, etc.) remain in normal configuration, but the sequence number field is forcibly set to 0. When the injection strategy is sender spoofing data injection test: a spoofing data frame in network A is generated. This spoofing data frame is formatted identically to a normal data frame, but its payload content is modified to preset spoofing data (such as tampered sensor readings, erroneous status information, etc.).

[0053] Multiple data frames may need to be sent through the same virtual link. The virtual link sending queue and scheduling selection unit 207 is responsible for managing the sending order of these data frames. For reset attacks, reset frames need to be sent periodically, and the timing of the reset frame sending can be precisely controlled according to the injection period.

[0054] According to redundancy management rules, the receiving end prioritizes receiving the first arriving data frame and discards any later-arriving copies as duplicate frames. This mechanism is exploited by spoofing attacks: a spoofed data frame is sent on network A, while a normal data frame is sent on network B with added jitter delay, causing the network A frame to arrive before the network B frame, thus forcing the receiving end to actively select the spoofed data.

[0055] As described above, through systematic data flow construction, normal business messages and attack payloads are fused and processed in accordance with the constraints of the AFDX protocol, generating a test data flow that both meets the protocol specifications and carries the attack intent, providing a precise and controllable attack payload for subsequent injection operations.

[0056] In one specific implementation, the AFDX network includes an AFDX network switch, which is used to exchange and manage AFDX network data traffic. According to a pre-configured virtual link forwarding table, it deterministically forwards unicast and multicast frames. Simultaneously, it performs consistency checks and traffic control on each virtual link entering the AFDX switch, thereby ensuring the determinism and isolation of the network.

[0057] like Figure 3As shown, the AFDX network switch includes: a switch input unit 301, a virtual link identification unit 302, a consistency check and flow control unit 303, a forwarding unit 304, and a switch output unit 305.

[0058] The execution flow of each module of the AFDX network switch is as follows: After receiving the data frame (including normal service data and test data) from the system, the switch input unit 301 first enters the virtual link identification unit 302, which performs virtual link identification on the data frame according to the pre-configured virtual link information. Then, in the consistency check and traffic control unit 303, consistency and policing processing is performed according to the virtual link dimension, including BAG check, frame length check and traffic overspeed check, to determine whether the data frame meets the configuration constraints. When the data frame passes the above checks, the switch determines its target output port and completes the deterministic forwarding decision in the forwarding unit 304 according to the virtual link forwarding table. At the same time, the data frame to be forwarded is sent to the corresponding switch output unit 305, and after being queued and scheduled by the output port queue, it is output from the corresponding port.

[0059] S3. The target virtual link is determined by the target virtual link identifier. The test data stream is injected into the AFDX network from the target virtual link according to the test start time and injection strategy. If the injected data frame is a reset frame with sequence number SN=0, the integrity check rule of the receiving device of the AFDX network is triggered by the reset frame, causing the receiving device to discard the first normal data frame after the reset frame. If the injected data frame is a fake data frame in network A, jitter delay is added to the corresponding normal data frame in network B, and the redundancy management rule causes the receiving device to prioritize receiving the fake data frame.

[0060] Specifically, by receiving test data streams and injecting them into the AFDX network at precise times via a specified target virtual link, based on the configured test start time and injection strategy, the AFDX network's own protocol mechanisms (integrity check rules or redundancy management rules) are triggered according to the type of injected data frames contained in the test data stream, thereby achieving controllable interference to the receiving device.

[0061] In one specific embodiment, S3 includes the following steps: S31, determine the start time of the injection operation based on the test start time.

[0062] S32, determine the target virtual link for injecting the test data stream based on the target virtual link identifier.

[0063] S33, according to the injection strategy, injects the test data stream into the AFDX network through the target virtual link at startup.

[0064] The test start time is the configured attack start time. The sending device reads the test start time parameter from the network security test configuration information and uses it as the start time of the injection operation. When the system time reaches this time, the injection operation is triggered to ensure that the attack can start at the preset precise time.

[0065] The target virtual link is the actual virtual link channel determined based on the target virtual link identifier. It serves as the logical channel carrying the test data stream and is the necessary path for attack traffic to reach the receiving end. The sending device reads the target virtual link identifier from the network security test configuration information, maps it to the corresponding virtual link channel, and subsequently sends the test data stream through this channel.

[0066] For reset attacks: Reset frames are periodically sent after the startup time according to the injection period in the injection strategy. For spoofing injection attacks: Spoofing data frames from network A are continuously sent within a specified time period according to the injection start time and injection duration in the injection strategy. At the same time, jitter delay is added to the corresponding normal data frames from network B, so that the attack behavior can be executed precisely according to the configured strategy, achieving precise control of the attack timing. This provides execution guarantee for the periodic reset of reset attacks and the delay control of spoofing injection.

[0067] As described above, by leveraging precise timing control, accurate path positioning, and protocol mechanisms, the test data stream was precisely injected into the AFDX network within the policy framework, achieving secure and controllable interference with the receiving device and laying the foundation for attack execution for subsequent response data collection and test result evaluation.

[0068] In one specific implementation, the integrity check rules include: Rule A: The receiving device only accepts data frames whose sequence number falls within a sliding window range determined based on the most recently received sequence number.

[0069] Rule B: The receiving device accepts data frames with sequence number SN=0 and uses them as a reset flag for the sending device.

[0070] Rule C: Data frames that do not satisfy Rule A or Rule B are discarded.

[0071] In one specific implementation, triggering the integrity check rules of the receiving device in the AFDX network through a reset frame, causing the receiving device to discard subsequent normal data frames, includes: S301, at startup, periodically sends reset frames to the receiving device through the target virtual link according to the injection cycle.

[0072] S302, after receiving the reset frame, the receiving device identifies the reset frame as a reset flag of the sending device according to rule B in the integrity check rules, and records the sequence number as reset.

[0073] S303, the receiving device accepts only subsequent data frames whose sequence number falls within the sliding window range according to rule A in the integrity check rules. After receiving the reset frame, the sliding window range of the receiving device is reset to the initial state, so that the first normal data frame whose sequence number is not 1 or 2 is discarded, and subsequent normal data frames are received normally according to the updated sliding window range.

[0074] The reset attack requires continuously triggering the reset logic of the receiving device to cause continuous data frame loss. By periodically sending reset frames, the receiving device repeatedly enters a reset state, preventing it from receiving subsequent normal data frames. Specifically, at startup, the sending device begins the injection operation, according to the injection period (e.g., every T). r (One frame is sent at a time). The reset frame with sequence number SN=0 is periodically sent to the receiving device through the target virtual link, and the sending stops after the injection duration is exceeded.

[0075] The reset frame is identical in format to a normal AFDX data frame, except that the sequence number field is set to 0. The injection period can be adjusted according to testing requirements; the shorter the period, the more severe the service degradation.

[0076] In the AFDX protocol, sequence number SN=0 is reserved as a special value, indicating that the sending device has completed a reset and has resumed transmitting data. Corresponding to rule B, when the receiving device receives a data frame with SN=0, it interprets it as the sending end having reset and resets its own sequence number records to their initial state. The sliding window range is typically [PSN+1, PSN+2]. After the reset, PSN=0, so the window is [1, 2], meaning the expected sequence number window for the next frame is reset to {1, 2}.

[0077] After a reset, the sliding window range of the receiving device is reset to its initial state. According to rule A, the receiving end only accepts data frames whose sequence numbers fall within the sliding window range. The initial state of the sliding window range is usually [1, 2] (i.e., the expected sequence number of the next frame is 1 or 2, allowing for some out-of-order delivery). Subsequent normal data frames with sequence numbers other than 1 or 2 (e.g., 3, 4, 5, etc.) will be deemed invalid and discarded by rule A. Since the sequence numbers of normal service data frames are usually continuously increasing (e.g., if 5 was sent before the reset, it continues to start from 6 after the reset), the sequence numbers are often greater than 2, and therefore are discarded. Only service flows that are retransmitted after the reset and whose sequence numbers start from 1 can be received. This allows a reset attack to utilize the AFDX protocol's own sequence number verification mechanism to block normal traffic. The attack effect is entirely driven by the protocol mechanism, requiring no additional control, thus achieving a precise attack effect.

[0078] The above-mentioned method fully utilizes the integrity check rules of the AFDX protocol by periodically injecting reset frames with sequence number SN=0. It achieves precise blocking of normal business traffic while maintaining full compliance with the protocol, providing a reliable technical means for testing the security, availability and stability of AFDX networks under reset attack conditions.

[0079] Redundancy management rules are the mechanism in the AFDX protocol for handling redundant data frames in both A and B networks. They are used to determine which frame the receiving end chooses to deliver to the upper layer when it receives data frames from both networks, and are the core target of spoofing attacks.

[0080] In one specific implementation, the redundancy management rules include: Rule D: The receiving device performs redundancy management on A network data frames and B network data frames received on the same virtual link according to their arrival time. If the arrival time difference between two frames is less than or equal to the maximum interval time window, they are regarded as two redundant copies of the same message. The first frame that arrives is delivered to the upper layer service, and the second frame that arrives is discarded as a duplicate frame.

[0081] Rule E: If the arrival time difference between data frames from network A and network B is greater than the maximum interval time window, they are considered as two independent messages and are delivered to the upper-layer business processing respectively.

[0082] Rule F: The receiving device performs a sequence number continuity check on the delivered data frames. If the sequence numbers are not continuous, it will be processed accordingly according to the integrity check rules.

[0083] In one specific implementation, a jitter delay is added to the corresponding normal data frames in network B, and redundancy management rules are used to make the receiving device prioritize receiving spoof data frames, including: S304, based on the injection start time and injection duration set in the injection strategy, sends fake data frames in network A through the sending device.

[0084] S305, based on the jitter delay duration, adds jitter delay to the normal data frame corresponding to the false data frame in the B network through the transmitting device, so that the arrival time of the normal data frame is later than the arrival time of the false data frame, and the difference between the two arrival times is less than the maximum interval time window.

[0085] S306, the receiving device, according to the redundancy management rules, delivers the first arriving false data frames to the upper-layer service and discards the subsequent arriving normal data frames as duplicate frames.

[0086] The spoofing attack requires continuously sending spoofed data frames carrying modified content to network A within a preset time window. The start and end times of the attack are controlled according to the time parameters in the injection strategy to ensure that the attack can be executed accurately according to the test plan. Specifically, the sending device reads the injection start time in the injection strategy. When the system time reaches that time, the spoofing attack is initiated. During the injection duration, spoofed data frames are continuously generated and sent to network A. The payload content of the spoofed data frames is modified with preset spoofed data (such as incorrect sensor readings, forged status information, etc.), while other fields (serial number, source / destination IP, virtual link ID, etc.) remain normal.

[0087] The maximum interval time window serves as the time threshold for determining whether frames A and B belong to the same message. The core of the fake data injection attack lies in controlling the arrival time order of fake data frames from network A and normal data frames from network B. By adding a jitter delay time 'd' to the normal data frames from network B, frame B arrives later than frame A, while ensuring that the time difference between their arrivals is less than the maximum interval time window, thus satisfying the condition of "considering them as copies of the same message" in the redundancy management rule. The jitter delay is implemented by delaying the data frames from network B in the sending queue by 'd' before sending them, or by buffering them internally at the sending end by 'd' before outputting them.

[0088] The receiving device processes data frames arriving from both networks A and B according to redundancy management rules. When the arrival time difference between two frames is less than the maximum interval window, they are considered two redundant copies of the same message. The receiving end only delivers the first arriving frame, and the later arriving copy is discarded. Attackers exploit this mechanism by allowing a fake data frame from network A to arrive first, causing the receiving end to deliver fake data to upper-layer services while discarding the later arriving frame from network B carrying normal data. This allows a fake data injection attack to fully utilize the redundancy management mechanism of the AFDX protocol to tamper with data. The attack is completely compliant at the protocol level, without needing to break or bypass any security mechanisms, realistically simulating network behavior under malicious attack scenarios.

[0089] In one specific implementation, the receiving device of the AFDX network includes a lower-layer interface, a MAC port, an AFDX frame parsing unit, a virtual link identification and reception filtering unit, a redundancy management and deduplication unit, a sequence number and consistency check unit, and an upward delivery / distribution unit. Specifically, the receiving device receives data frames from the physical link through the lower-layer interface. The data frames enter the AFDX frame parsing unit via the MAC port to extract the virtual link identifier and UDP / IP information. The virtual link identification and reception filtering unit then performs validity filtering based on constraints such as the destination MAC address, destination IP / UDP port, and frame length. The filtered data frames enter the redundancy management and deduplication unit for dual-network redundancy processing. Finally, the sequence number and consistency check unit verifies the sequence number continuity and consistency. Data that passes the verification is delivered to upper-layer services through the upward delivery / distribution unit.

[0090] Specifically, the receiving device performs redundancy management on data frames from network A and network B according to redundancy management rules: when the arrival time difference between network A frames and network B frames is less than or equal to the maximum interval time window, the redundancy management and deduplication unit delivers the first arriving frame to the upper-layer service, and discards the second arriving frame as a duplicate frame. The receiving device verifies the sequence number of data frames according to integrity check rules: the sequence number and consistency check unit only accepts data frames whose sequence numbers fall within the sliding window range, and identifies data frames with sequence number SN=0 as a reset flag for the sending device.

[0091] The above-described coordinated operation of sending fake data frames on network A and increasing jitter delay on network B fully utilizes the redundancy management rules of the AFDX protocol. While maintaining full compliance with the protocol, it achieves the injection of fake data into upper-layer services, providing a reliable technical means for testing the security, availability, and data processing correctness of the AFDX network under fake data injection attack conditions.

[0092] S4: Acquire and record the response data generated by the AFDX network during the test data stream injection, and generate test results for evaluating the network security of AFDX based on the response data.

[0093] The response data comprises various data generated by the AFDX network during the test data stream injection, including performance metrics and raw data packets. The behavior of the AFDX network during the attack is recorded in real time as response data. This response data is then statistically analyzed and quantified to generate objective test results, which are used to evaluate the security, availability, and stability of the AFDX network under spoofed data injection conditions.

[0094] In one specific embodiment, S4 includes the following steps: S41, during the test data stream injection, captures key indicator data of the AFDX network in real time through the data acquisition module and generates log files.

[0095] S42 captures PCAP data packets sent and received by the AFDX network mid-level system through the data acquisition module.

[0096] S43, when the injected data frame is a reset frame with sequence number SN=0, according to the log file and PCAP data packets, the data frame loss rate of the AFDX network under the condition of false data injection is calculated, and the service degradation degree and security impact range of the AFDX network are determined based on the data frame loss rate.

[0097] S44. When the injected data frame is a fake data frame in network A, the system analyzes the data frame payload received by the receiving device in the PCAP data packet to determine whether the fake data frame has been successfully received and delivered to the upper layer service, calculates the fake data injection success rate, and evaluates the security protection capability of the AFDX network under fake data injection attacks based on the injection success rate.

[0098] S45, based on the degree of business degradation, the scope of security impact, and security protection capabilities, generates test results.

[0099] The AFDX network generates various performance metrics under normal operation and under attack, such as queue depth, throughput, end-to-end latency, latency jitter, sequence number continuity, redundancy drop rate, and error frame count. These metrics can objectively reflect changes in network behavior. By capturing these metrics in real time and saving them as log files, the degree of network performance degradation can be quantitatively assessed.

[0100] Besides performance metrics, the raw data packets themselves contain a wealth of information, such as the data frame sequence number, timestamp, payload content, and protocol fields. PCAP packets are captured AFDX network raw data packet files that can preserve complete network data packets, support in-depth protocol analysis and anomaly localization, and can accurately pinpoint which data frames were dropped, which data frames were received, and whether spoofed data frames were successfully injected.

[0101] For reset attacks, the data frame loss rate (FR) is used to quantify the degree of network performance degradation under the attack, reflecting the proportion of normal data frames dropped by the receiver due to integrity check rules. Specifically, the total number of data frames sent by the sender during the test (including normal frames and attack frames) is counted from the PCAP data packets, and the number of data frames successfully received and delivered to the upper layer by the receiver is counted from the PCAP data packets. The data frame loss rate is calculated as (total sent - total received) / total sent × 100%. During the statistics, it is necessary to distinguish between different virtual links, calculate the data frame loss rate for each virtual link separately, and further analyze the number of frames dropped due to integrity check rules and their sequence number distribution.

[0102] For spoofing attacks, the spoofing success rate is used to evaluate the effectiveness of the attack. Specifically, the data frame payloads received by the receiving device are extracted from the PCAP packets, frames containing spoofing payloads are identified, the number of spoofing frames successfully received and delivered to the upper layer is counted, and the spoofing success rate is calculated as: (Number of successfully received spoofing frames / Total number of sent spoofing frames) × 100%. The injection success rate can be used to evaluate the security protection capability of the AFDX network against spoofing attacks.

[0103] Service degradation level refers to the extent to which an attack affects normal services, reflecting the degree of availability reduction in the AFDX network under attack. Security impact scope refers to the number of virtual links and end systems affected by the attack, reflecting the degree of attack spread and the boundary of impact. Specifically, for reset attacks, the service degradation level is determined based on the data frame loss rate: loss rate < 1%: minor degradation; 1% ≤ loss rate < 10%: moderate degradation; loss rate ≥ 10%: severe degradation. The security impact scope is determined based on the number and distribution of affected virtual links: single virtual link affected: local impact; multiple virtual links affected: widespread impact; multiple end systems affected: global impact.

[0104] For fake data injection attacks, the degree of business impact is determined based on the success rate of the fake data injection: a success rate <1% indicates a minor impact; 1% ≤ success rate <10% indicates a moderate impact; and a success rate ≥10% indicates a severe impact. The scope of security impact is determined based on the number of virtual links and end systems to which the fake data frames are distributed: local impact within a single virtual link; widespread impact across multiple virtual links; and global impact across multiple end systems. The specific values ​​for the thresholds for data frame loss rate and injection success rate can be set by the implementer based on the actual situation.

[0105] The test results report is generated by combining indicators such as data frame loss rate, success rate of fake data injection, degree of business degradation, scope of security impact, and security protection capabilities.

[0106] The above-mentioned systematic response data collection, statistical analysis and result generation comprehensively evaluated the performance degradation and security impact of the AFDX network under reset attack conditions, as well as the success rate of fake data injection and security protection capabilities under fake data injection attack conditions. This achieved a quantitative assessment of the network security resilience of AFDX and provided a reliable technical means for security testing and protection mechanism verification of avionics networks.

[0107] The above-mentioned approach decouples normal communication parameters from security test parameters by using baseline configuration information and network security test configuration information, thus balancing normal communication standards with security test requirements. Furthermore, it constructs test data streams that conform to network constraints based on the sending device of the AFDX network. This ensures that the test data streams can include reset frames with sequence number SN=0 or spoofed data frames from the A network, while meeting AFDX protocol constraints. This achieves precise construction of attack payloads while ensuring the compliance of attack traffic, avoiding uncontrollable network risks. The test data streams are injected into the AFDX network using injection strategies, and integrity check rules or redundancy management rules are used to implement reset attacks or spoofed data injection attacks on the receiving device, respectively. This leverages the AFDX network's own protocol mechanisms to achieve the attack effect, making the attack behavior covert, repeatable, and controllable. It realistically simulates network behavior under malicious attack scenarios, overcoming the shortcomings of existing technologies that only address occasional fault testing. It also provides an objective quantitative assessment of the performance degradation degree, security impact scope, and security protection capabilities of the AFDX network, effectively supporting the verification and subsequent improvement of the AFDX network's security protection mechanisms.

[0108] Example 2 Embodiment 2 of the present invention provides a non-transitory computer-readable storage medium, which can be disposed in an electronic device to store at least one instruction or at least one program related to implementing a method in the method embodiment. The at least one instruction or the at least one program is loaded and executed by the processor to implement the fake data injection method for AFDX network security testing provided in the above embodiment.

[0109] Example 3 Embodiment 3 of the present invention provides an electronic device, which includes a processor and the non-transitory computer-readable storage medium of Embodiment 2 of the present invention.

[0110] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.

Claims

1. A method for injecting fake data for AFDX network security testing, characterized in that, Includes the following steps: S1. Generate baseline configuration information and network security test configuration information using the AFDX network configuration tool. The baseline configuration information includes at least virtual link parameters and network constraints. The network constraints include redundancy management rules for network A and network B, as well as data frame integrity check rules. The network security test configuration information includes at least the target virtual link identifier, test start time, and injection strategy. S2, based on the baseline configuration information and the network security test configuration information, construct a test data stream that conforms to the network constraints through the sending end device of the AFDX network, wherein the test data stream contains at least an injected data frame, and the injected data frame includes a reset frame with sequence number SN=0 or a fake data frame from the A network; S3, the target virtual link is determined by the target virtual link identifier, and the test data stream is injected into the AFDX network from the target virtual link according to the test start time and the injection strategy. If the injected data frame is a reset frame with sequence number SN=0, the integrity check rule of the receiving device of the AFDX network is triggered by the reset frame, causing the receiving device to discard the first normal data frame after the reset frame. If the injected data frame is a fake data frame in network A, jitter delay is added to the corresponding normal data frame in network B, and the redundancy management rule causes the receiving device to prioritize receiving the fake data frame. S4, acquire and record the response data generated by the AFDX network during the test data stream injection, and generate security test results based on the response data.

2. The method for injecting fake data for AFDX network security testing according to claim 1, characterized in that, When the injection strategy is a receiver reset test, the injection strategy includes at least an injection period and an injection duration; When the injection strategy is a fake data injection test at the sending end, the injection strategy includes at least the injection start time, injection duration, jitter delay duration, and maximum interval time window; Correspondingly, S1 includes the following steps: S11, Obtain the network topology scale, network speed, link latency, link jitter and priority parameters of the AFDX network as the network structure and link conditions in the baseline configuration information, wherein the network topology scale includes the number of end systems, the number of switches and the connection relationship; S12, Based on the network structure and link conditions, configure the virtual link ID, bandwidth allocation interval, maximum frame length, end system output rate and token bucket parameters, and generate the virtual link parameters; S13, Based on the virtual link parameters, configure the maximum allowable offset time for redundancy in network A and network B, and generate the redundancy management rules; S14, According to the redundancy management rules, configure the sliding window range of the data frame sequence number and the reset flag of sequence number SN=0, and generate the integrity check rules; S15, based on the virtual link parameters, configure the test start time, target virtual link identifier, injection period, injection duration, injection start time, jitter delay duration, and maximum interval time window, and generate the network security test configuration information.

3. The method for injecting fake data for AFDX network security testing according to claim 2, characterized in that, The sending device includes a configuration file interface, a message parameter configuration unit, a message generation unit, a security test message parameter configuration unit, a security test message generation unit, a virtual link mapping and AFDX encapsulation unit, a virtual link sending queue and scheduling selection unit, a traffic shaping unit, and a redundancy control unit. S2 includes the following steps: S21, read and parse the baseline configuration information and the network security test configuration information through the configuration file interface; S22, based on the virtual link parameters, obtain the bandwidth allocation interval and token bucket parameters through the message parameter configuration unit, and generate normal service messages through the message generation unit; S23, according to the injection strategy, the injection parameters are obtained through the security test message parameter configuration unit, and the injection data frame is generated through the security test message generation unit; S24, the normal service message and the injected data frame are mapped to the target virtual link and encapsulated by the virtual link mapping and AFDX encapsulation unit; S25, the encapsulated data frame is queued and scheduled through the virtual link transmission queue and scheduling selection unit; S26, The scheduled data frame is shaped by the traffic shaping unit according to the bandwidth allocation interval and the token bucket parameters; S27, the shaped data frame is copied to network A and network B through the redundant control unit to obtain a test data stream that meets the network constraints.

4. The method for injecting fake data for AFDX network security testing according to claim 3, characterized in that, S23 includes the following steps: When the injection strategy is a receiver reset test, a reset frame with sequence number SN=0 is generated by the security test message generation unit. When the injection strategy is to perform a fake data injection test at the sending end, a fake data frame in network A is generated through the security test message generation unit.

5. The method for injecting fake data for AFDX network security testing according to claim 2, characterized in that, S3 includes the following steps: S31, Determine the start time of the injection operation based on the test start time; S32, determine the target virtual link for injecting the test data stream based on the target virtual link identifier; S33, according to the injection strategy, the test data stream is injected into the AFDX network through the target virtual link at the startup time.

6. The method for injecting fake data for AFDX network security testing according to claim 5, characterized in that, The integrity check rules include: Rule A: The receiving device only accepts data frames whose sequence number falls within a sliding window range determined based on the most recently received sequence number; Rule B: The receiving device accepts data frames with sequence number SN=0 and uses data frames with sequence number SN=0 as a reset flag for the sending device; Rule C: Data frames that do not satisfy Rule A or Rule B are discarded.

7. The method for injecting fake data for AFDX network security testing according to claim 6, characterized in that, The step of triggering the integrity check rule of the receiving device in the AFDX network through the reset frame, causing the receiving device to discard the first normal data frame after the reset frame, includes: S301, at the startup time, according to the injection period, the reset frame is periodically sent to the receiving device through the target virtual link; S302, after receiving the reset frame, the receiving device identifies the reset frame as a reset flag of the sending device according to rule B in the integrity check rules, and records the sequence number as reset; S303, the receiving device accepts only subsequent data frames whose sequence numbers fall within the sliding window range according to rule A in the integrity check rules. After receiving the reset frame, the sliding window range of the receiving device is reset to the initial state, so that the first normal data frame whose sequence number is not 1 or 2 is discarded, and subsequent normal data frames are received normally according to the updated sliding window range.

8. The method for injecting fake data for AFDX network security testing according to claim 6, characterized in that, The step of adding jitter delay to the corresponding normal data frames in network B, and using the redundancy management rules to make the receiving device prioritize receiving the spoof data frames, includes: S304, according to the injection start time and injection duration set in the injection strategy, the fake data frame is sent in network A through the sending device; S305, based on the jitter delay duration, the transmitting device adds a jitter delay to the normal data frame in the B network corresponding to the fake data frame, so that the arrival time of the normal data frame is later than the arrival time of the fake data frame, and the difference between their arrival times is less than the maximum interval time window. S306, the receiving device delivers the first arriving false data frame to the upper-layer service according to the redundancy management rule, and discards the later arriving normal data frame as a duplicate frame.

9. A non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores at least one instruction or at least one program segment, characterized in that, The at least one instruction or the at least one program segment is loaded and executed by the processor to implement the fake data injection method for AFDX network security testing as described in any one of claims 1-8.

10. An electronic device, characterized in that, Includes a processor and the non-transitory computer-readable storage medium as described in claim 9.