Method and system of context aware threat anomaly detection in satellite navigation communications

EP4716859A1Pending Publication Date: 2026-04-01ZIGHRA INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-23
Publication Date
2026-04-01

AI Technical Summary

Technical Problem

Existing GNSS threat anomaly detection systems are limited by their reliance on predefined statistical thresholds and are vulnerable to sophisticated attacks, as they focus on individual threat vectors and fail to account for the complex and dynamic nature of the receiver's context, making them susceptible to targeted and mass attacks.

Method used

A context-aware, adaptive solution that models the receiver's environment using a combination of physical and socio-economic factors, employing machine learning and hybrid models to detect anomalies by learning the normal context and identifying deviations, thereby increasing the complexity for attackers to simulate the context and conduct successful attacks.

Benefits of technology

This approach significantly reduces the likelihood and feasibility of successful attacks by requiring attackers to accurately model and reproduce the complex receiver context, limiting threat vectors to targeted attacks and increasing the complexity barrier, thus enhancing the robustness against growing attacker sophistication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2024055000_28112024_PF_FP_ABST
    Figure IB2024055000_28112024_PF_FP_ABST
Patent Text Reader

Abstract

Method and system of detecting a threat anomaly in a satellite navigation and communication network. The method includes receiving, at a receiver device, data transmitted from a satellite navigation network, determining context data associated with the receiver device, and detecting that the received data communicated from the satellite navigation network constitutes a threat anomaly based at least in part on the determined context data and the data transmitted from the satellite as received at the receiver device.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD AND SYSTEM OF CONTEXT AWARE THREAT ANOMALY DETECTION IN SATELLITE NAVIGATION COMMUNICATIONSRELATED APPLICATIONS

[0001] This application claims benefit of priority to Provisional U.S. Patent Application No. 63 / 468,511, filed May 23, 2023; the aforementioned priority application being hereby incorporated by reference in its entirety.TECHNICAL FIELD

[0002] Examples described herein relate to detecting threat anomalies, and more specifically emergent threat anomalies in an integrated satellite navigation and communication platform.BACKGROUND

[0003] A satellite navigation and communication uses a network of satellites that transmit signals to terrestrially- located receiver devices to provide real-time, accurate position, navigation, and time information. There are multiple satellite navigation and communication in operation, including the Global Positioning System (GPS), Globalnaya Navigazionnaya Sputnikovaya Sistema (GLONASS), Galileo, and BeiDou systems, with Global navigation satellite system (GNSS) being a general term describing any satellite constellation that provides positioning, navigation, and timing services on a global or regional basis.

[0004] GNSS has become a critical infrastructure due to its wide range of applications. These include, but are not limited to, transportation (aviation, maritime, and terrestrial), agriculture, emergency services, surveying, telecommunications, and military operations. GNSS has revolutionized the way we navigate and conduct business, leading to increased efficiency, safety, and productivity across multiple industries.

[0005] As GNSS becomes increasingly integrated into modern society, the system also faces growing threats. These threats can be categorized as unintentional (e.g., signal interference and space weather) and intentional (e.g., jamming, spoofing, and cyber-attacks). Unintentional threats are generally caused by natural events or human-made sources that disruptGNSS signals, while intentional threats are deliberate acts aiming to disrupt, manipulate, or disable GNSS services.BRIEF DESCRIPTION OF THE DRAWINGS

[0006] FIG. 1 illustrates a satellite navigation and communication system according to one or more examples.

[0007] FIG. 2 illustrates an example computer system architecture for threat anomaly detection within a satellite navigation and communication system.

[0008] FIG. 3 illustrates an example system for threat anomaly detection within a satellite navigation and communication system.

[0009] FIG. 4 illustrates, in an example embodiment, an implementation of a system for threat anomaly detection within a satellite navigation and communication system.

[0010] FIG. 5 illustrates, in an example embodiment, a further implementation of a system for threat anomaly detection within a satellite navigation and communication system.

[0011] FIG. 6 illustrates, in an example embodiment, a method of threat anomaly detection within a satellite navigation and communication system.

[0012] FIG. 7 illustrates, in an example embodiment, a method of threat anomaly detection within a satellite navigation and communication system.DETAILED DESCRIPTION

[0013] Embodiments herein, among other aspects, provide solutions for detecting attempted attacks upon the integrity of the navigation and communication satellite infrastructure. Embodiments herein recognize that existing solutions for GNSS threat anomaly detection rely on checking if multiple signals are coming from a single, terrestrial or multiple closely located sources, looking for unexpected deviations in signal characteristics based on predefined statistical thresholds or monitoring discrepancies across multiple sources of information by combining different sensor data. While such solutions can detect attacks belonging to the specific threat vectors that they have been designed for, they are, however, susceptible to more sophisticated attacks. Thus, embodiments herein recognize that existing solutions focus on identifying individual problems in a given threat vector.The detection capabilities of existing approaches are limited to the assumptions they make about the underlying threat vectors, leaving them vulnerable to growing attacker sophistication.

[0014] Among other benefits, embodiments herein provide a receivercontext-aware solution that advantageously captures and models the complex and dynamic nature of the local environment of the receiver device (also referred to herein as "receiver"), and leverages same to decrease likelihood of success from a targeted attack, recognizing that in order for an attacker to simulate the context, the attacker must have the same device in the same place at the same time as a target receiver. Modeling receiver context in this manner advantageously reduces the feasibility of a mass attack and increases the complexity barrier required for an attacker to successfully conduct a targeted attack. In particular, embodiments herein recognize that context associated with the receiver device is difficult to simulate as any attack necessitates deviating from the context, and by using a context-aware adaptive solution both the feasibility and impact of an attack are negated or at least limited. By modelling the underlying receiver- centric context, threat vectors are then fundamentally limited to following the context in order to conduct a successful attack. Since context depends on several factors and will vary across receiver devices, the threat vectors are thus limited to a targeted attack. And in the case of a targeted attack, it is difficult for the attacker to both model and accurately reproduce the receiver context, in order to conduct a material attack.

[0015] As referred to herein, a threat anomaly (also referred to as "anomaly" herein) means a data communication anomaly that is indicative of an attack threat or an attempted attack that adversely affects, or has the potential to adversely affect, data integrity in accordance with satellite signals as broadcasted to and received by a receiver device. Embodiments herein employ receiver- centric context considerations in assessing the existence of threat anomalies. A receiver device, or module, as referred to herein is configured to receive a satellite communication and navigation signal. By positioning a stationary receiver at a fixed location, in some embodiments, in close proximity to critical infrastructure dependent on GNSS, the system detects threat anomalies within the given region. One or more embodiments described herein can be implemented using programmatic modules, engines,or components. A programmatic module, engine, or component can include a program, a sub-routine, a portion of a program, or a software component or a hardware component capable of performing one or more stated tasks or functions. As used herein, a module or component can exist on a hardware component independently of other modules or components. Alternatively, a module or component can be a shared element or process of other modules, programs or machines.

[0016] Some embodiments described herein can generally require the use of computing devices, including processing and memory resources. For example, one or more embodiments described herein may be implemented, in whole or in part, on computing devices such as servers, desktop computers, cellular or smartphones, tablets, wearable electronic devices, laptop computers, printers, digital picture frames, network equipment (e.g., routers) and tablet devices. Memory, processing, and network resources may all be used in connection with the establishment, use, or performance of any embodiment described herein (including with the performance of any method or with the implementation of any system).

[0017] Furthermore, one or more embodiments described herein may be implemented through the use of instructions that are executable by one or more processors. These instructions may be carried on a computer-readable medium. Machines shown or described with figures below provide examples of processing resources and computer-readable mediums on which instructions for implementing embodiments of the invention can be carried and / or executed. In particular, the numerous machines shown with embodiments of the invention include processor(s) and various forms of memory for holding data and instructions. Examples of computer-readable mediums include permanent memory storage devices, such as hard drives on personal computers or servers. Other examples of computer storage mediums include portable storage units, such as CD or DVD units, flash memory (such as carried on smartphones, multifunctional devices or tablets), and magnetic memory. Computers, terminals, network enabled devices (e.g., mobile devices, such as cell phones) are all examples of machines and devices that utilize processors, memory, and instructions stored on computer-readable mediums. Additionally, embodiments may beimplemented in the form of computer programs, or a computer usable carrier medium capable of carrying such a program.SYSTEM DESCRIPTION

[0018] FIG. 1 illustrates satellite navigation and communication system 100 according to one or more examples. Receiver device 101 is communicatively coupled with satellite devices 102a- n and a terrestrially based transceiver or transmitting tower 104. An embodiment implemented for a stationary receiver in a fixed location may be based on a mobile device as receiver device 101, which incorporates threat anomaly detection module 105, which over time models the environmental context of the receiver. Based on this, threat anomaly detection module 105 can detect threat anomalies and issue alerts in areas such as ports with incoming maritime traffic or busy airports. Solutions herein may also be implemented for a dynamic system with a mobile receiver device 101, where an initial model for the receiver context can be created using a training harness such as a drone or a vessel that slowly travels in advance over a finite space encompassing the expected set of trajectories for the dynamic system.

[0019] To illustrate the context complexity problem consider a sample environment for a mobile-device based satellite navigation and communication receiver 101. In this example, the receiver may experience obstruction and multipath effects due to buildings 103a, trees 103b or aerial objects 103. The receiver may experience unintentional radio interferences from aerial vehicles or cell towers. A truck 103d using a personal privacy device (PPD) to jam its own GNSS receiver, potentially interfering with mobile receivers. The surface of the ground near the receiver may have certain radio frequency (RF) reflective properties that affect the reception and integrity of incoming signals. This provides an example yet limited view of the objects present in a receiver's environment, directly influencing the receiver's perceived context. Physical phenomena related to satellite signal characteristics as measured relative to the receiver device also influence the receiver's perception of the environment. Receiver context as referred to herein encompasses not just physical parameters, but also other factors including prevailing ambient socio-economic factors such as a busy day where several vehicles are around, a high-security event taking place nearby,strikers and protestors with ham radios. All of these factors influence the local RF environment and influences the receiver device 101 perception of the environment, or its context as referred to herein.

[0020] FIG. 2 illustrates an example computer system 200 architecture for threat anomaly detection within a satellite navigation and communication system. A computer system 200 can be implemented on, for example, a server or combination of servers, or reside on the receiver device 101. In one implementation, the computer system 200 includes processor resources 201, memory resources 202 (e.g., read-only memory (ROM) or random-access memory (RAM)), and a communication interface 207 communicatively coupled within satellite navigation and communication system 100. The communication interface 207 enables the computer system 200 to communicate with one or more user computing devices, over one or more networks (e.g., cellular network). Memory resources 202 may include instructions constituting threat anomaly detection module 105 that are executable in processor 201. The memory resources 202 may also be used to store temporary variables or other intermediate information during execution of program instructions by the processor 201.

[0021] Computer system 200 may include display screen 203 and input mechanisms 204. As described by various examples, the processor 201 can detect and process any number of sensor inputs from input sensor devices 205. By way of example, such sensor inputs can include, but are not necessarily limited to, various sensor devices providing physical parameter measurements related to timing anomalies of signals as received from satellite navigation service, orbital mechanics of one or more satellites of the satellite navigation service relative to properties of signals as propagated, RF signal characteristics in relation to satellite geospatial parameters, carrier-to- noise ratio associated with a satellite elevation relative to the receiver device 101, observed obstruction and signal propagation effects across frequency bands, and observed obstruction and signal propagation effects in relation to satellite geospatial parameters.

[0022] In addition to physical phenomena and physical parameters as sensed by sensor devices 205, system 200 can consume various kinds of inputs to represent context such as socio-economic factors. For example, the system can be connected to a live calendar application, or similar currentevents application data 206 that indicates whether a high traffic event is taking place in the receiver device local surroundings. This can be a useful measure of context since a busy day may imply a noisier RF environment.

[0023] As such, examples described herein are related to the use of the computer system 200 for implementing the techniques described herein. According to an aspect, techniques are performed by the computer system 200 in response to the processor 201 executing one or more sequences of one or more instructions contained in the memory 202. Such instructions may be read into memory 202 from another machine-readable medium. Execution of the sequences of instructions contained in the memory 202 causes the processor 201 to perform the process steps described herein, including process steps of the embodiments described herein in conjunction with, for example, the embodiments as described in FIGS. 3- 7. In alternative implementations, hard-wired circuitry may be used in place of or in combination with software instructions to implement examples described herein. Thus, the examples described are not limited to any specific combination of hardware circuitry and software.

[0024] FIG. 3 illustrates example system 300 for threat anomaly detection within a satellite navigation and communication system based on a context- aware adaptive approach to anomaly detection that captures the complex and evolving nature of the receiver device's environment. The system depicted in the embodiment of FIG. 3 may employ a hybrid machine learning and context-based model on a set of sensor data. The system models normality by not only looking at the sensor data, but a set of expectations representing the context. This system is flexible and can ingest any number of sensor data across different sensors. The more sensor inputs there are, the more precisely it can model context. The use of the context-based model allows the system to be context-aware and the use of machine learning provides adaptivity, intended to capture any complex and evolving nature of the receiver's environment, thus providing robustness against growing attacker sophistication.

[0025] System 300 illustrates an overview of a context-aware threat anomaly detection process, where various sensor inputs are provided by different sensor devices 205 measuring physical phenomena associated with the receiver device within satellite navigation and communication system100. The sensors can include but are not limited to global navigation satellite system (GNSS) 301, IMU 302, Bluetooth 304, and also Wifi, Cellular, temperature, ambient air pressure and humidity, though it is contemplated that other input sources can be used to capture context associated with the receiver device 101. The sensor inputs 305 are consumed by the contextbased model 304 in accordance with FIG. 3 to extract a set of features representative of the receiver device context. Both the sensor inputs and the context-based features are provided as inputs to a machine learning model 306 which uses these two groups of inputs to both learn the receiver's perceived context and determine when the behavior deviates from the learned context. The deviation from the learned context, in embodiments, can be represented as a confidence measure 307 indicating an extent to which the system believes the observed behavior does not follow the expectations and constitutes a threat anomaly.

[0026] The following provides a non-exhaustive list of the sensor inputs usable to measure variable parameters shown and used as inputs to the anomaly detection process. Although depicted as physical phenomena, the system can consume various kinds of inputs to represent context such as socio-economic factors. For example, the system can be connected to a live calendar application that indicates whether a high traffic event is taking place in the receiver device surroundings. This can be a useful measure of context since a busy day may imply a noisier RF environment.

[0027] As an example, the context-based model can extract a set of features based on a variety of different phenomena using a single variable or a multivariable measurement using two or more related variables either within the same input group or across different groups. Here context is implicitly described by the expected deviation of a set of measurements from a physics-based model. If the apparent deviation is within expectation, the behavior adheres to the context, and if the apparent deviation is outside the expectation, the behavior includes external sources of error not explained by the context. Examples of how such variables can be related include but are not limited to:

[0028] Relating Timing Information with Signal Properties: For example. Comparing rates of change across Pseudorange and Carrier phase. Deviations between these measurements may indicate cycle slips, signal disruptions, or other anomalies in the satellite communication signal.

[0029] Relating Signal Properties with Orbital Mechanics: For example. Comparing the observed Doppler shift for a satellite with the expected value based on the satellite's relative motion.

[0030] Relating RF Characteristics with Geospatial Parameters: Comparing Carrier-to-Noise with Satellite elevation relative to the receiver.

[0031] Relating Obstruction and Propagation Effects across frequency bands: Comparing the occurrence of cycle slips across frequency bands for the same satellite.

[0032] Relating Obstruction and Propagation Effects with Geospatial Parameters: Comparing the impact of multipath effects on different satellitesaccounting for geospatial parameters to look for inconsistencies based on potential obstructions or changes in the local environment / receiver devices' locality.

[0033] In this example, context can be measured implicitly through a physical para meter- based approach. Several physical parameters can be used to measure context related to satellite navigation anomaly detection. However, it is contemplated that the term context as used herein encompasses a much broader definition and a wider range of variables, physical and otherwise. Measuring whether a given day is a busy day or not, knowing if a high-security event is taking place nearby, socioeconomic factors, business requirements, political events, strikes are all examples of context. There are also several ways to model context, for example it can also be modeled explicitly by using a contextual variable as a conditional variable to model the probability distribution of a measured variable, for example using time-of-day as a conditional variable to model the probability distribution of carrier-to-noise ratio as a measured variable.

[0034] In embodiments, the anomaly detection method can be implemented to provide not only a confidence measure of there being an anomaly, but also an explanation as to why it constitutes a threat anomaly. Using a statistical method with dynamically generated thresholds and weights, the confidence measure as scored can then be explained through the relative contribution (in terms of low, moderate or high deviations) of each of the inputs to the model against the learned thresholds and weights representing the context of the model.

[0035] This system can be implemented for a stationary receiver in a fixed location using a mobile device, which over time models the environmental context. Based on this the system can detect anomalies and issue alerts in areas such as ports with incoming maritime traffic or busy airports. It may also be implemented for a dynamic system with a mobile receiver, where an initial model for the context can be created using a training harness such as a drone or a vessel that slowly travels in advance over a finite space encompassing the expected set of trajectories for the dynamic system.

[0036] FIG. 4 illustrates, in example embodiment 400, an implementation of threat anomaly detection within a satellite navigation and communication system 100. In embodiments, the physical parameter-based modelingprovides a source that defines receiver device context, as several different physical concepts apply to the sensor inputs gathered by the receiver device. The physical parameters can be used to build a set of expectations that can then be applied to model and learn the receiver context and test the inputs against it. In embodiments, the anomaly detection system depicted in FIG. 4 is designed to identify and characterize satellite signal interference within a specified region. In embodiments, threat anomalies are detected by way of positioning a stationary receiver device 101 at a fixed location, in proximity to critical infrastructure dependent on satellite navigation and communication. Based on the findings of the anomaly detection system, appropriate measures can be taken to alleviate the effects of communication signal interference on the surrounding infrastructure that relies on its accuracy and repeatability.

[0037] In an embodiment of FIG. 4, the system includes a satellite receiver device at a fixed location 401 collecting raw satellite communication signal data 402 and other sensor data as described herein. The acquired data from the device is then pre-processed, and both a physical parameter-based model (as the context-based model) and basic approach to feature extraction are applied to generate two sets of features 403, 404. These features are then consumed by the anomaly detection module which uses a machine learning model 405 to learn the specific context of the receiver device 101, adapting over time and detecting anomalies. In addition to detecting threat anomalies, a separate but interconnected module 407 may be used to classify and assign severity to detected anomalies. Furthermore, the machine learning model 407 may be constructed in such a way that it can be used to provide modelbased explanations 408 for the generated inferences. These include generating explanations in accord with confidence measure 406 indicating presence of an anomaly, the classification of the anomaly as well as the assigned class and severity 407.

[0038] Receiver device and data sources. In an example implementation, the receiver device 401 may be a Google Pixel 7, equipped with a dual-band GNSS receiver. However, it is contemplated that other android devices equipped with satellite navigation and communication receiver in conjunction with an android version that supports collecting raw GNSS data using the android. location library may be deployed. It is further contemplated thatother mobile devices and operating systems, including iOS devices, that support raw sensor data collection may be similarly deployed. The data is acquired through an android app running persistently on the device. The app accesses raw GNSS data using the android. location library. Accessing this data requires location permissions to be enabled allowing the app to access the location data. In embodiments, the app can be used for acquiring the data and sending it to a remote server for further processing or can be done directly on the receiver device. In a particular implementation herein, all processing will be done directly on the receiver device through the app.

[0039] With regard to reprocessing of raw GNSS data 402, Most of the data preprocessing is specific to the formulations for each of the features extracted. Certain GNSS observables are expressed in different formats or are not natively provided through the android. location API. This may apply to variables across different sensor inputs that may be acquired in different implementations.

[0040] In this implementation this primarily applies to Pseudorange, which is not natively provided through the android. location API. Other variables however are provided through the API which can then be used to calculate the Pseudorange. This is done by taking the local time as reported by the receiver clock and transmitted time as given by the satellite clock, adjusting for time related biases, and calculating the transmission time that is the time taken for the message to be received by the receiver. This transmission time can then be multiplied by the speed of light to determine the Pseudorange.

[0041] In embodiments, parameter-based feature extraction may be based on the following features:

[0042] Consecutive Transmission Interval. This feature is based on classical physics surrounding atomic clocks which generates a highly precise and stable time reference based on the vibrations of atoms, such as cesium or rubidium. The errors in delay between two consecutive transmissions are bounded by the physical nature of the atomic clock and expected functioning of satellite hardware. The feature related to this is the difference in the Received Satellite Vehicle Time across two consecutive transmissions for which the formula may be expressed as:^Received SV Time = Received SV Timet— Received SV Time^^ Consecutive Transmission Discrepancy = ^Received SV Time

[0043] The general expectation is that this feature should tend towards 1, but it may skew and the error may vary depending on the clock biases or drift factors. These contextual factors include receiver locations, satellite position, time of the year and others. This context is captured by the machine learning model, where Consecutive Transmission Discrepancy represents a satellite level feature which can be calculated for each satellite of a given satellite navigation and communication network.Carrier-Code Consistency. There are two sources of range measurements for a GNSS receiver, one being the Pseudorange and the other being the Accumulated Delta Range.

[0044] The pseudorange calculation involves the principles of classical physics, specifically the concepts of distance, time, and the speed of light. Pseudorange is the estimated distance between a GNSS satellite and a receiver. It is calculated by multiplying the time it takes for a signal to travel from the satellite to the receiver by the speed of light. Since the signal transmission time is affected by factors such as satellite clock bias, receiver clock bias, and atmospheric delays, the pseudorange is an approximation of the true distance, hence the name "pseudo."

[0045] Accumulated Delta Range (ADR) calculation is based on the carrier phase measurement, which utilizes the principles of wave physics. The carrier phase measurement tracks the continuous phase of the GNSS signal's carrier wave as it travels from the satellite to the receiver. By counting the number of whole cycles and measuring the fractional part of the last cycle, the receiver can estimate the change in distance between the satellite and the receiver over time.This change in distance, or the Accumulated Delta Range, is a more precise measurement compared to the pseudorange, as it is less susceptible to noise and other factors affecting the signal. However, it does require a continuous lock on the carrier wave to maintain its accuracy.

[0046] Under normal conditions, we expect Psuedorange and ADR to change together over time with some error based on the context. We can measure the consistency in this change using the following formula:Carrier Code Discrepancy = ADR — PseudorangeCarrier Code Discrepancy is a satellite level feature and, again, can be calculated for each satellite.

[0047] Carrier-range Motion Consistency. This feature is based on the principles of kinematics and signal propagation. The movement of the satellite relative to the fixed receiver, as well as the time it takes for the signal to travel between them, are key factors in determining the expected change in carrier-based range measurements. We expect the measured carrier-based range to follow the expected behavior with some error.

[0048] The error may be related to atmospheric effects such as ionospheric and tropospheric delays that influence the signal propagation, and relativistic effects resulting from the satellite's motion in Earth's gravitational field also need to be considered. All of these may be tied to the specific context of the receiver relative to its position, time and other factors. We can measure the discrepancy using the following formula:ADR Discrepancy = ADRt— ADRtADRt= ADRt-+ Pseudorange Ratet-

[0049] The pseudorange rate represents the satellite vehicle's velocity, and it is the first derivative to the ADR. The expected ADR Is based on a first- order Taylor approximation. The discrepancy in part will be related to the estimation error, and in part captures implicitly the receiver's context. Deviation from the context may indicate an anomaly.ADR Discrepancy is a satellite level feature. This feature can be calculated for each satellite.

[0050] Relative Motion Consistency. This is based on satellite orbital mechanics and the Doppler effect, which dictate how GNSS satellites move relative to a receiver on Earth. This feature checks if the observed change in elevation angle and the Doppler shift are consistent with the expected satellite motion. A match in signs indicates that the relative motion between the satellite and receiver aligns with the underlying physics. We measure this using the following formula which we call Pseudorange Rate Elevation Consistency Indicator or PECI:

[0051] This represents a strong consistency check, and can be extended to capture context or more precise modeling of the physics based on the relative motion consistency. This can be done by converting Pseudorange Rate into Doppler Shift, and using the Doppler Shift along with Range measurement to determine the expected Elevation change and compare it with the measure Elevation change which is expected to have some error that captures the underlying context.

[0052] PECI is a satellite level feature. This feature can be calculated for each satellite.

[0053] Geospatial Propagation (or Obstruction) based LOS Modelling. The physics behind satellite position related effects on GNSS observables are based on the principles of electromagnetic wave propagation through the atmosphere and the interactions of the satellite signal with the Earth's topography around the receiver. Using multiple satellites distributed and the propagation and obstruction effects observed by the receiver based on the satellites' relative positions we can implicitly model the environment or line- of-sight for the receiver. This can be done two ways. One by measuring the Multipath effects, by taking a satellite signal and comparing the observed multipath effects against the rest of the satellites, using the following formula:

[0054] Here MI is the multipath indicator. And position provides the 3D unit vector of the satellite's position relative to the receiver based on the azimuth and elevation. This allows us to compare the deviation in measurements across several satellites and apply a weighted sum based on how close the satellites are in position. The expectation is that satellites closer in relative position, have a similar line-of-sight and should thereby expect to see similar propagation effects as measured by the multipath indicator.

[0055] The same can be said for obstruction effects, using another formula to model that:Here CSI is the cycle slip indicator, we use it to measure local obstruction or even atmospheric effects that may cause cycle slips. The same expectation applies in that satellites closer in relative position, have a similar line-of-sight and should thereby expect to see similar obstruction effects as measured by the cycle slip indicator.

[0056] Both Implicit LOS Propagation Consistency and implicit LOS Obstruction Consistency are satellite level features calculated for each satellite.

[0057] Now with regard to basic feature extraction 404, in an embodiment based, for example, on Average Frequency domain RF characteristics, several sensor inputs can be fed directly into the system with or without significant preprocessing. In this example implementation, only a set of features is encompassed based on calculating the average of RF characteristics within a frequency band across several satellites.

[0058] The average Carrier-to-Noise ratio can be measured for a given time across several signals from different satellites within a frequency band such as the GPS LI or GAL El. This provides us some measure of how noisy the receiver's environment is:

[0059] The gain measurement can also be used to monitor to measure how loud the environment is within a certain frequency band such as the GPS LI or GAL El. If strong unfamiliar sources emerge it would be apparent when monitoring changes in the measure:4GCt

[0060] Both Average C / NO and AGC are RF level features. These features can be calculated for each RF Input. For example GPS LI, GAL e5 are examples of RF Inputs. These are tied to specific frequency bands thatsignals from different satellites across the different constellations operate within.

[0061] FIG. 5 illustrates, in example embodiment 500, an implementation of a system for threat anomaly detection within a satellite navigation and communication system 100 based on additional receiver device contextbased feature extraction methods covering a broader scope of context defined beyond the physical parameter-based modeling techniques described herein. In particular, additional ways in which different types of context based modeling can be applied may include:

[0062] Seasonality Effects. Based on the time of day, time of week or time of year, there may be different levels of traffic, whether that is nearby vehicles or foot traffic. The traffic in a broad sense can affect the RF environment. More people and attendant infrastructure may imply more devices which means a noisier RF environment. Socioeconomic factors for example, patterns of the five-day work week or the 8 hour work day can influence the RF environment. One way, we can capture these effects by modeling the noise based on time of day, and applying a vector to represent the time of day in continuous format:

[0063] Here time t is given in seconds, and the time vector is a unit vector which represents time of day. Next, define K points around a unit sphere where the range of possible values is given by:

[0064] For each point, calculate a mean and standard deviation meani and sdi for a given measurement variable x with respect to the time-of-day context TimeVect. These can be updated using the following formula:

[0065] The update criteria can be to update the mean and standard deviation mean and sd for all points Point such that

[0066] This can be used to create a model for measurement variable x with respect to the time-of-day context TimeVect

[0067] Using this, next calculate a discrepancy measure for suppose average carrier-to-noise ratio called ToD Noise Inconsistency

[0068] This gives a weighted sum of z-scores using the learned gaussian distributions over the defined points. Based on this we can measure the extent to which the average carrier-to-noise ratio at time t deviates from the expectation based on the time of day.

[0069] This can be extended to using a live calendar which provides a "busy-ness factor" between 0 to 1 to indicate how busy the environment is expected to be based on any high traffic events occurring. This would require replacing the TimeVectwith a scalar measuring "busy-ness" which can represent the Busy and Point would now just be a scalar between 0 to 1 given by:

[0070] Next the previous equations would require replacing:And then update criteria with the following :2 cos (7i(Pointi — Busyty) > K

[0071] Now with regard to machine learning model 405 applied to threat anomaly detection module 105, for each of the features fed into the machine learning model, assign a running mean and standard deviation. These are initialized to a set of nominal values based on statistically observed phenomenon. The running mean and standard deviation can then be used to calculate a probability measure that an observed point belongs to the distribution. The observed point itself is used to update the running meanand standard deviation. The probability measures for each of the features are then multiplied by their relative weight which are all initialized uniformly and the weighted sum subtracted from 1 is used as the confidence score that there is an anomaly. A confidence score near 1 would indicate high probability of an anomaly whereas one near 0 would indicate a low probability of an anomaly. The relative weights for the feature are then updated based on the individual probabilities. This updating of the running mean and standard deviation as well as the relative weights allows for the model to adapt over the ingested sensor input. These values are then updated over time as the model adapts over the ingested sensor inputs.

[0072] In embodiments related to model initialization, learning and inference, consider a process for model initialization, learning and inference as follows:Starting with model initialization:1. Assign running mean and standard deviation for each of the features across the physics model based features and basic feature sets. a. These include a total of 6 features per satellite and 2 features per RF input. b. The initial values for running mean and standard deviation are set based on general observed phenomenon. c. The initial values are more flexible and allow greater range of variability. The model will eventually adjust for the skew and spread as the model adapts to the receiver's specific context.2. Assign relative weights for each of the features across the physics model based features and basic feature sets. a. These include a total of 6 features per satellite and 2 features per RF input. b. Therefore the weight for each feature across the two sets would be 1 / 6 and 1 / 2 respectively.For model learning:1. Calculate the measured value of each of the features across the physics model based features and basic feature sets. Use this to update the running mean and standard deviation.a. These include a total of 6 features per satellite and 2 features per RF input. b. For each feature update the running mean using the following formula. Whereis the previous running mean and xtis the measurement for the feature.c. For each feature update the running standard deviation using the following formula, whereis the previous running mean and xtis the measurement for the feature.d. In the previous two formulas a and y are the updating factors which are used for updating the model. These can be based on a number of time steps T in seconds to configure the recency or long-term effect. In an alternative implementation several configurations can be used to do trend analysis.2. Next, calculate the probability measure that a measurement belongs to the distribution for each of the features across the physical-parameter model based features and basic feature sets. Use this to update the relative weights for the features. a. These include a total of 6 features per satellite and 2 features per RF input. Note that for binary indicators which have a 0 or 1 value we take these as is and skip the next set of steps. Also a fixed weight may be applied to these instead of a dynamic weighting. For example, the PECI, would be assigned a fixed weight. b. For each feature calculate the probability it belongs to the distribution based on the running mean and standard deviation. Here F is the CDF for the standard normal distribution.c. Update each of the relative weights based on the probability calculations.

[0073] Hererepresents the weight for feature k for the previous time step, pkitis the current probability measure calculate for feature k. Finally p = 1 represents an update factor for the relative weights based on K time steps which is supposed to be greater than T used to update running mean and standard deviation. Note that weights for features with fixed weights are not included in the summation above. Note the model weights are only updated if it is determined that an anomaly has not occurred at time t. The criteria for what an anomaly is explained in model inference as follows.

[0074] For model inference:1. Calculate the confidence score of an anomaly based on the weighted sum of the probability measures for each of the features for all the satellites and RF sources.Pm,t ~ ’wk,t ’ (1—Pfc.t) kHere m denotes a specific satellite or RF source. Note also that since certain indicators may be given a fixed weight and the resulting score may add up to more than 1, we set the max cutoff for this value at 1, so that it remains between 0 and 1.2. Calculate the confidence score by taking the max across all the probabilities across both the satellite and RF source probabilities calculated in the previous step.Confidence Scoret= max{Pfc t} k3. Determine if there is an anomaly by testingConfidence Scoret> CHere C is the cutoff for the Confidence Score value for the system to consider that there is anomaly. For example, a value of 0.8 can be used, in which > 0.8 is detected as a threat anomaly.

[0075] Next with regard to model explainability in accordance with model based explanations 407, model-based explainability can be produced for the score using the following approach:1. Rank each of the features for a satellite source or RF input based on the weighted probability that is wkf■ (1 - pk t)2. For each of the ranked features produce the following sentence: [General name for feature] explains [wk t■ 100]% of the receiver's context. It measures [high-level description of what it measures]. There is a [pk t■ 100]% likelihood for its apparent value [%t][appropriate unit] to deviate from its usual value K~ / ][appropriate unit].

[0076] For each of these explainability messages a more specific or customized message can be created depending on the feature. Additionally, the deviation and reliance of the feature can be described using umbrella categorizations of threat anomaly such as low, moderate or high.METHODOLOGY

[0077] FIG. 6 illustrates an example embodiment method 600 of threat anomaly detection within a satellite navigation and communication system. Method 600 may be performed by one or more computing devices and / or processes. In embodiments, the techniques of method 600 proceed in relation to the devices, systems and techniques described with reference to FIGS. 1- 7 herein.

[0078] At block 610, receiving, at a receiver device 101, data transmitted from a satellite navigation network 100. In embodiments, the receiver device may be such as a mobile phone, a manned vehicle, an unmanned vehicle, a terrestrial vehicle, a maritime vehicle and an aerial vehicle. In some aspects, the computing system 200 may be incorporated within or co-located with one of the receiver device 101 and / or a terrestrial base station communicatively connected within the satellite navigation network 100.

[0079] At block 620, determining context data associated with the receiver device. In embodiments, the context data is broadly defined in accordance with both (i) a real time assessment of one or more attendant socioeconomic factors that likely influence a radio frequency (RF) noise factor in relation to a local area encompassing the receiver device, and (ii) a set ofphysical parameter measurements relating to one or more of: timing anomalies of signals as received from satellite navigation service, orbital mechanics of one or more satellites of the satellite navigation service relative to properties of signals as propagated, RF signal characteristics in relation to satellite geospatial parameters, carrier-to-noise ratio associated with a satellite elevation relative to the receiver device; observed obstruction and signal propagation effects across frequency bands, and observed obstruction and signal propagation effects in relation to satellite geospatial parameters.

[0080] At block 630, detecting that the received data communicated from the satellite navigation network constitutes a threat anomaly based at least in part on the determined context data and the data transmitted from the satellite as received at the receiver device.

[0081] FIG. 7 illustrates, in example embodiment 700, a method of threat anomaly detection within a satellite navigation and communication system. In embodiments, method 700 may be performed in conjunction with any method steps as described herein with regard to techniques of method 600, for example, as depicted in embodiments of FIG. 6.

[0082] At block 710, generating a confidence measure that there is a threat anomaly, the confidence measure being representative of an extent of a deviation from an expected behavior; and detecting the threat anomaly in accordance with the confidence measure being one of above and below a cutoff threshold confidence measure.

[0083] At block 720, generating at least one of a classification of the threat anomaly and an assigned severity of the threat anomaly. In some aspects, a trained machine learning model, trained in accordance with the descriptions herein with regard to FIGS. 3- 5, generates the classification of the threat anomaly and assigned severity of the threat anomaly.

[0084] At block 730, the trained machine learning model further generates a model-based explanation associated with the at least one of the classification of the threat anomaly and assigned severity of the threat anomaly in accordance with confidence measure.

[0085] At block 740, activating, responsive to detecting the threat anomaly, a threat anomaly remediation action, wherein the threat anomaly remediation action includes generating an alert to a set of receiver devicesand a set of computing devices within a spatial region encompassed by the satellite navigation network 100.

[0086] In embodiments, the anomaly detection system can be extended to include a component for learning patterns of false positives. Instances of the detected anomalies can be flagged as false positives. One way to do this is to use a human guided approach in which analysts monitoring anomalies can view the underlying data to determine occurrences of false positives. The component would then over time learn patterns of false positives, and be used as an additional check to determine whether there is an anomaly or not. This functions as an "alarm silencing" feature to reduce occurrences of false positives over time.

[0087] In related variations, somewhat similar to learning patterns of false positives, the system can be extended to include a component for learning patterns of flexibly-defined classes. Instances of anomalies can be flagged using custom defined tags that represent flexibly-defined classes. This can be done using a human guided approach similar to learning patterns of false positives. Over time the system would learn patterns of different classes of anomalies, and automatically classify them as one or the other.CONCLUSION

[0088] Although examples are described in detail herein with reference to the accompanying drawings, it is to be understood that the concepts are not limited to those literal examples. Accordingly, it is intended that the scope of the concepts be defined by the following claims and their equivalents. Furthermore, it is contemplated that a particular feature described either individually or as part of an example can be combined with other individually described features, or parts of other examples, even if the other features and examples make no mention of the particular feature. Thus, the absence of describing combinations should not preclude having rights to such combinations.

Claims

WHAT IS CLAIMED IS:

1. A method performed in a computing system, the method implemented by one or more processors of the computing system and comprising: receiving, at a receiver device, data transmitted from a satellite navigation network; determining context data associated with the receiver device; and detecting that the received data communicated from the satellite navigation network constitutes a threat anomaly based at least in part on the determined context data and the data transmitted from the satellite as received at the receiver device.

2. The method of claim 1 wherein the receiver device comprises at least one of a mobile phone, a manned vehicle, an unmanned vehicle, a terrestrial vehicle, a maritime vehicle and an aerial vehicle.

3. The method of claim 1 wherein the computing system is incorporated within or co-located with one of the receiver device and / or a terrestrial base station communicatively connected within the satellite navigation network.

4. The method of claim 1 wherein determining the context data associated with the receiver device includes a real time assessment of one or more attendant socio-economic factors that likely influence a radio frequency (RF) noise factor in relation to a local area encompassing the receiver device.

5. The method of claim 1 wherein determining the context data associated with the receiver device includes a set of physical parameter measurements relating to at least one of: timing anomalies of signals as received from satellite navigation service, orbital mechanics of one or more satellites of the satellite navigation service relative to properties of signals as propagated, RF signal characteristics in relation to satellite geospatial parameters, carrier-to-noise ratio associated with a satellite elevation relative to the receiver device; observed obstruction and signal propagation effects across frequency bands, and observed obstruction and signal propagation effects in relation to satellite geospatial parameters.

6. The method of claim 1 wherein detecting the threat anomaly comprises: generating a confidence measure that there is a threat anomaly, the confidence measure being representative of an extent of a deviation from an expected behavior; and detecting the threat anomaly in accordance with the confidence measure being one of above and below a cutoff threshold confidence measure.

7. The method of claim 6 further comprising generating at least one of a classification of the threat anomaly and an assigned severity of the threat anomaly.

8. The method of claim 7 wherein a trained machine learning model generates the at least one of a classification of the threat anomaly and an assigned severity of the threat anomaly.

9. The method of claim 8 wherein the trained machine learning model further generates a model-based explanation associated with the at least one of the classification of the threat anomaly and assigned severity of the threat anomaly in accordance with confidence measure.

10. The method of claim 7 further comprising activating, responsive to detecting the threat anomaly, a threat anomaly remediation action, wherein the threat anomaly remediation action includes generating an alert to one or more devices that a potential cyber-attack is underway, the one or more devices including at least one of a set of receiver devices and a set of computing devices within at least a portion of a spatial region encompassed by the satellite navigation network.

11. A computing system comprising: one or more processors; a memory storing a set of instructions, the set of instructions when executed in the one or more processors causing the one or more processors to perform operations that include:receiving, at a receiver device, data transmitted from a satellite navigation network; determining context data associated with the receiver device; and detecting that the received data communicated from the satellite navigation network constitutes a threat anomaly based at least in part on the determined context data and the data transmitted from the satellite as received at the receiver device.

12. The computing system of claim 11 wherein the receiver device comprises at least one of a mobile phone, a manned vehicle, an unmanned vehicle, a terrestrial vehicle, a maritime vehicle and an aerial vehicle.

13. The computing system of claim 11 wherein the computing system is incorporated within or co-located with one of the receiver device and / or a terrestrial base station communicatively connected within the satellite navigation network.

14. The computing system of claim 11 wherein determining the context data associated with the receiver device includes a real time assessment of one or more attendant socio-economic factors that likely influence a radio frequency (RF) noise factor in relation to a local area encompassing the receiver device.

15. The computing system of claim 11 wherein determining the context data associated with the receiver device includes a set of physical parameter measurements relating to at least one of: timing anomalies of signals as received from satellite navigation service, orbital mechanics of one or more satellites of the satellite navigation service relative to properties of signals as propagated, RF signal characteristics in relation to satellite geospatial parameters, carrier-to-noise ratio associated with a satellite elevation relative to the receiver device; observed obstruction and signal propagation effects across frequency bands, and observed obstruction and signal propagation effects in relation to satellite geospatial parameters.

16. The computing system of claim 1 wherein detecting the threat anomaly comprises instructions executable by the one or more processors to cause operations including: generating a confidence measure that there is a threat anomaly, the confidence measure being representative of an extent of a deviation from an expected behavior; and detecting the threat anomaly in accordance with the confidence measure being one of above and below a cutoff threshold confidence measure.

17. The computing system of claim 16 further comprising instructions executable by the one or more processors to cause operations including generating at least one of a classification of the threat anomaly and an assigned severity of the threat anomaly.

18. The computing system of claim 17 wherein a trained machine learning model generates the at least one of a classification of the threat anomaly and an assigned severity of the threat anomaly.

19. The computing system of claim 18 wherein the trained machine learning model further generates a model-based explanation associated with the at least one of the classification of the threat anomaly and assigned severity of the threat anomaly in accordance with confidence measure.

20. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors of a computing device, cause the one or more processors to perform operations comprising: receiving, at a receiver device, data transmitted from a satellite navigation network; determining context data associated with the receiver device; and detecting that the received data communicated from the satellite navigation network constitutes a threat anomaly based at least in part on the determined context data and the data transmitted from the satellite as received at the receiver device.