METHOD AND SYSTEM FOR MONITORING AN ONBOARD COMMUNICATION NETWORK OF AN AIRCRAFT

A monitoring system for avionics networks enforces a reference bandwidth profile to detect and counter attacks within allocated limits, enhancing network security by identifying unusual traffic patterns.

FR3169038A1Pending Publication Date: 2026-05-29AIRBUS OPERATIONS (SAS)

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
AIRBUS OPERATIONS (SAS)
Filing Date
2024-11-27
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing avionics communication network monitoring technologies fail to detect attacks that keep traffic within the allocated bandwidth limits, leaving the network vulnerable to security threats.

Method used

Implement a monitoring system with a security function that enforces a reference bandwidth consumption profile below the bandwidth limit, measuring parameters like average frames/bytes per second, minimum/maximum data rates, and data flow models, and takes actions if unusual behavior is detected.

Benefits of technology

Detects and mitigates attacks by monitoring bandwidth consumption patterns, ensuring network security even when traffic remains within allocated limits.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method for monitoring an aircraft's onboard communication network, comprising, for a data stream transmitted or received by a network switch, a flow limiting function (to enforce a bandwidth limit) and a security function (202) comprising: obtaining measurements of at least one stream parameter; based on the measurements obtained, calculating a value of at least one bandwidth consumption parameter, contributing to the definition of a measured bandwidth consumption profile; comparing the measured profile with a predetermined profile by comparing the calculated value with a reference value; and, if at least one difference criterion is met, performing at least one network security action. This allows the detection of an unusual (although remaining below the bandwidth limit) bandwidth consumption profile that could constitute a malicious act. Figure to be published with the abbreviation: Fig. 2
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: METHOD AND SYSTEM FOR MONITORING AN ONBOARD COMMUNICATION NETWORK OF AN AIRCRAFT Technical field

[0001] The field of the invention is that of monitoring communication networks embedded in aircraft. STATE OF PRIOR ART

[0002] Aircraft generally include one or more onboard communication networks, designed to enable communication between onboard equipment, particularly onboard computers. In order to meet the requirements of aircraft certification regulations, an onboard communication network must be deterministic, that is to say, it must allow the transmission of information from a transmitting device, subscribed to this communication network, to one or more receiving devices, also subscribed to this communication network, with a transmission time shorter than a predetermined time and a guarantee of no loss of information across the network.

[0003] The ARINC 664 Part 7 standard defines an onboard avionics communication network of the deterministic switched Ethernet type, based on full-duplex Ethernet technology. In such a network, which may, for example, correspond to an AFDX (registered trademark) communication network (for "Avionics Full Duplex Switched Ethernet"), each device subscribed to the communication network (also sometimes simply called a "subscriber") is connected to a network switch, and communications between the different devices (subscribers) use predefined virtual links established during the network definition and configuration. A virtual link is defined between a transmitting device and one or more receiving devices, via one or more network switches. Each virtual link follows a predetermined path within the network.Bandwidth is allocated to each virtual link, and the routing of the various virtual links in the network is performed in such a way that the sum of the bandwidths allocated to the virtual links using the same physical link does not exceed the bandwidth supported by that physical link. This is necessary to guarantee network determinism. All communications between devices are defined in advance, by defining the virtual links, to allow for switch configuration. Each switch has a configuration table based on the virtual links passing through that switch.

[0004] Future avionics systems will face increasing security threats. In particular, the avionics communication network is a potentially significant means of attacking avionics systems because it is connected to multiple systems and interfaces with other system domains and with communication infrastructure outside the aircraft. For this reason, the technology currently used to monitor an avionics communication network includes a traffic policing function to help protect against certain types of threats. Specifically, the traffic policing function verifies that the number and size of frames do not exceed a certain threshold (also called a bandwidth limit), for example, defined in a traffic contract.Thus, the ARINC 664 part 7 standard provides a flow limiting function, based on the byte or the frame, which follows the token bucket policy.

[0005] The flow limiting function protects against denial-of-service attacks, which use a large number of requests to exceed the recipient's capacity to process them, resulting in a failure. However, it does not detect any attack whose traffic footprint remains below the configured threshold (bandwidth limit). In other words, it verifies that the incoming traffic (flow) does not exceed the allocated bandwidth. It would, however, be desirable to also be able to detect attacks where the flow (traffic) remains within the allocated bandwidth.

[0006] Therefore, if the technology currently used to monitor an onboard communication network (avionics) is satisfactory, there is nevertheless a need to improve it further. Description of the invention

[0007] A method is proposed for monitoring an aircraft's onboard communication network, the communication network being a deterministic switched Ethernet network using virtual links and comprising a set of subscribers and a set of switches, the method being implemented by a monitoring system comprising electronic circuitry, the method comprising, for a data stream transmitted or received by a given switch, a flow limiting function configured to enforce a bandwidth limit for said data stream. The method further comprises, for said data stream, a security function configured to enforce a reference bandwidth consumption profile below the bandwidth limit, the security function comprising: - obtaining measurements of at least one parameter of said data stream; - based on the measurements obtained, calculate a value of at least one bandwidth consumption parameter, the calculated value contributing to the definition of a measured bandwidth consumption profile; - compare the measured profile with the reference profile, by comparing the calculated value of at least one bandwidth consumption parameter with a reference value defined in the reference profile; and - if at least one difference criterion is verified, identified by the comparison, perform at least one action to secure the communication network.

[0008] Thus, the proposed solution makes it possible to monitor the bandwidth consumption of a stream that remains below the bandwidth limit, in order to detect any unusual behavior that could constitute a malicious act. This makes it possible to detect and combat attacks generated by sending a stream (traffic) that remains within the allocated bandwidth (i.e., below the bandwidth limit).

[0009] According to a particular embodiment, at least one parameter of the data stream, for which measurements are obtained, belongs to the group comprising: an average number of frames per second; an average number of bytes per second; a minimum data stream rate; a maximum data stream rate; and an average data stream rate.

[0010] According to a particular embodiment, the at least bandwidth consumption parameter belongs to the group comprising: at least one parameter relating to a data flow envelope; and at least one parameter relating to a periodicity of the data flow.

[0011] According to a particular embodiment, at least one difference criterion belongs to the group comprising: - a peak in overconsumption, defined by a number of frames or bytes of the data stream, received or transmitted over a first time period, which is greater than a first high reference value; - persistent overconsumption, defined by a number of frames or bytes of the data stream, received or transmitted over a second time period longer than the first time period, which is greater than a second high reference value; - a peak of underconsumption, defined by a number of frames or bytes of the data stream, received or transmitted over a third time period, which is less than a first low reference value; - persistent underconsumption, defined by a number of frames or bytes of the data stream, received or transmitted over a fourth period temporal duration greater than the third temporal period, which is less than a second low reference value; - an average data flow rate that is higher than a reference average rate; and - a data flow model that has at least one difference from a reference model, the data flow model being obtained by applying, at times of transmission or reception of frames of the data flow, a mathematical time / frequency conversion function, the reference model being obtained by applying, at times of transmission or reception of frames of a standard data flow, said mathematical function.

[0012] According to a particular embodiment, at least one security action belongs to the group comprising: - record a security event indicating the verification of at least one difference criterion; - request the given switch to block a port of the given switch involved in the sending or receiving of the data stream; - request the given switch to block a virtual link involved in the sending or receiving of the data stream; - request the given switch to reroute the data stream to record it; - notify subscribers of the communication network so that they refuse the data flow; and - reduce the priority assigned to the data flow.

[0013] According to a particular embodiment, the data stream is sent or received by a given port of the given switch.

[0014] According to a particular embodiment, the data stream is sent or received via a given virtual link passing through a given port of the given switch.

[0015] A computer program product is also proposed, comprising instructions leading to the execution, by a processor, of the process mentioned above according to any one of its embodiments, when said instructions are executed by the processor.

[0016] A storage medium is also proposed, storing such instructions.

[0017] A system for monitoring a communication network is also proposed. onboard an aircraft, the communication network being a deterministic switched Ethernet network using virtual links and comprising a set of subscribers and a set of switches, the monitoring system comprising electronic circuitry configured to implement, for a data flow transmitted or received by a given switch, a flow limiting function configured to to respect a bandwidth limit for said data stream. The electronic circuitry is further configured to implement, for said data stream, a safety function configured to enforce a reference bandwidth consumption profile below the bandwidth limit, the safety function comprising: - obtain measurements of at least one parameter of said data stream; - Based on the measurements obtained, calculate a value of at least parameter bandwidth consumption, the calculated value contributing to the definition of a measured bandwidth consumption profile; - compare the measured profile with the reference profile, by comparing the calculated value of at least one bandwidth consumption parameter with a reference value defined in the reference profile; and - if at least one difference criterion is verified, identified by the comparison, perform at least one action to secure the communication network.

[0018] An aircraft is also proposed comprising an onboard communication network which is a deterministic switched Ethernet network using virtual links and comprising a set of subscribers and a set of switches. The aircraft includes a monitoring system as described above. Brief description of the drawings

[0019] The features of the invention mentioned above, as well as others, will become clearer upon reading the following description of at least one exemplary embodiment, said description being made in relation to the accompanying drawings, among which:

[0020] [Fig.1] schematically illustrates, in side view, an aircraft equipped with a monitoring system for an onboard communication network;

[0021] [Fig.2] schematically illustrates the communication network and the monitoring system, in a first embodiment;

[0022] [Fig.3] schematically illustrates an example of a reference bandwidth consumption profile under a bandwidth limit;

[0023] [Fig.4] schematically illustrates an example of a monitoring algorithm executed by the control device of [Fig.2], in one embodiment;

[0024] [Fig.5] schematically illustrates an example of a hardware architecture configured to implement the control device of the [Fig.2], in one embodiment;

[0025] [Fig.6] schematically illustrates the communication network and the monitoring system, in a second embodiment;

[0026] [Fig.7] schematically illustrates the communication network and the system of surveillance, in a third embodiment; and

[0027] [Fig.8] schematically illustrates an example of a difference criterion.

[0028] DETAILED DESCRIPTION OF IMPROVEMENTS

[0029] The detailed description below focuses on describing embodiments of the present invention in the context of an aircraft with an on-board communication network that needs to be monitored.

[0030] Figure 1 schematically illustrates, in side view, an aircraft 100 equipped with a communication network 101 and a monitoring system 102 for this network 101. The communication network 101 is a deterministic switched Ethernet network, using virtual links (or VLs) and comprising a set of subscribers and a set of switches. For example, it conforms to the ARINC 664 Part 7 standard.

[0031] Fig. 2 schematically illustrates the communication network 101 and the monitoring system 102, in a first embodiment.

[0032] The communication network 101 comprises switches 201a, 201b, and 201c. Each switch includes input ports (also called "receive communication ports") and output ports (also called "transmit communication ports"). In the example shown in [Fig. 2], switch 201a has three input ports Rxl, Rx2, and Rx3 and three output ports Txl, Tx2, and Tx3, with output ports Txl and Tx2 connected to switch 201b and output port Tx3 connected to switch 201c. Communications between the different devices (subscribers) use predefined virtual links. A virtual link is defined between a sending device and one or more receiving devices, via one or more switches in the network. Each virtual link follows a specific path in the network. Thus, one or more virtual links can pass through each input or output port of a switch.

[0033] In the following description, we consider, as an example, the monitoring of a data stream transmitted or received by switch 201a (also referred to hereafter as the "monitored stream"). In a first implementation, the monitored stream is a data stream received on one of the input ports (Rxl to Rx3) or transmitted on one of the output ports (Txl to Tx3) of switch 201a. In this first implementation, monitoring is therefore performed at the level of a given port. If several virtual links pass through this given port (input or output port), the monitored stream comprises several sub-streams, each corresponding to one of the virtual links. In a second implementation, the monitored stream is a data stream transmitted or received via a given virtual link passing through a given port (input or output) of switch 201a. In this second implementation, monitoring is therefore performed at the level of a given virtual link. This could be a given virtual link among a plurality of virtual links passing through that given port.

[0034] To perform this monitoring of a data stream transmitted or received by switch 201a (monitored stream), the monitoring system 102 includes a control device 202, external to switch 201a and connected to it via a link 203. In one embodiment, the control device 202 also monitors other data streams transmitted or received by switch 201a. In another embodiment, the control device 202 also monitors data streams transmitted or received by the other switches 201b and 201c. In an alternative implementation, each switch (among the plurality of switches 201a, 201b, and 201c) is connected to a separate control device, monitoring the data stream(s) transmitted or received by that switch.

[0035] The control device 202 includes electronic circuitry configured to implement, for the monitored flow: - a (classic) traffic policing function, configured to enforce a bandwidth limit for the monitored traffic; this traffic policing function (or "Traffic Policing Function") implements, for example, the token bucket policy (or "Token Bucket Policy"); and - a security function (according to the present invention), configured to enforce, for the monitored flow, a (predetermined) reference profile of bandwidth consumption below the bandwidth limit.

[0036] Figure 3 schematically illustrates an example of such a reference bandwidth consumption profile 301 under a bandwidth limit 302 (a constant value here equal to 30 Mb / s). The reference profile is presented as a curve 301 representing the variation of the throughput R (in Mb / s) as a function of time T (in minutes). The reference profile (also called a "model") corresponds to the standard state of the traffic and can, for example, be defined based on the content of interface configuration documents (ICDs, which precisely define the data and their size to be sent on each flow) or by measurement on a representative test bench.

[0037] Fig. 4 schematically illustrates an example of a monitoring algorithm executed by the control device 202, in one embodiment.

[0038] In a step 401, the control device 202 obtains measurements of at least one parameter of the monitored flow. In the detailed example above, this is a data flow transmitted or received on one of the ports (output or input respectively) of the switch 201a, or a data flow transmitted or received via a virtual link passing through one of the ports (output or input respectively) of the switch 201a.

[0039] The measurements are, for example, taken in the switch under consideration (the one referenced 201a in the aforementioned example), on all frames of the monitored flow. In this case, the Traffic Policing Function can be used as the source for these measurements. The control device 202 receives, via link 203, the measurements taken by switch 201a. The measurements are, for example, sent periodically to the control device 202, in the form of discrete measured values, in the form of pre-calculated average values, or in the form of a hash of measurements indicating the state of the traffic over a predefined period.

[0040] In one embodiment, the measurements obtained relate to one or more of the following parameters: - an average number of frames per second (obtained for example from an average token consumption provided by the flow limiting function); - an average number of bytes per second (obtained for example from an average amount of consumption provided by the flow limiting function); - a minimum data flow rate (obtained for example from a minimum fill level of the token bucket provided by the flow limiting function); - a maximum flow rate of the monitored flow (obtained for example from a maximum fill level of the token bucket provided by the flow limitation function); - an average flow rate of the monitored flow (obtained for example from an average filling level of the token bucket provided by the flow limitation function);

[0041] In step 402, based on the measurements obtained, the control device 202 calculates a value for at least one bandwidth consumption parameter. The value thus calculated contributes to defining a measured bandwidth consumption profile. In one embodiment, the control device 202 calculates a value for at least one parameter relating to an envelope of the monitored flow and / or a value for at least one parameter relating to a periodicity of the monitored flow.

[0042] In a step 403, the control device 202 compares the measured profile with the reference profile, comparing, for each consumption parameter used, the calculated value with a reference value defined in the reference profile.

[0043] In step 404, the control device 202 determines, based on the results of the comparison, whether at least one (predetermined) criterion of difference between the measured profile and the reference profile is met. An appropriate uncertainty (number (of violations over a given period, margin in the violation threshold...) can be applied to the assessment of the difference between the reference profile and the measured profile, in order to avoid false positive situations.

[0044] In one embodiment, the control device 202 uses one or more of the following difference criteria (the first five items relate to a parameter concerning an envelope of the monitored flow, while the sixth item relates to a parameter concerning a periodicity of the monitored flow): - a peak in overconsumption, defined by a number of frames or bytes of the monitored stream, received or transmitted over a first time period (short, for example 1 second), which is greater than a first high reference value; - persistent overconsumption, defined by a number of frames or bytes of the monitored stream, received or transmitted over a second time period (long, for example 10 seconds) of duration greater than the first time period, which is greater than a second high reference value; - a peak of underconsumption, defined by a number of frames or bytes of the monitored stream, received or transmitted over a third time period, which is less than a first low reference value; - persistent underconsumption, defined by a number of frames or bytes of the monitored stream, received or transmitted over a fourth time period longer than the third time period, which is less than a second low reference value; - an average data flow rate that is higher than a reference average rate; and - a model of the monitored flow which has at least one difference with a reference model, the model of the monitored flow being obtained by applying, at times of transmission or reception of frames of the monitored flow, a mathematical function of time / frequency conversion (Fourier Transform for example), the reference model being obtained by applying, at times of transmission or reception of frames of a standard data flow (reference flow), the same mathematical function.

[0045] Figure 8 schematically illustrates an example of a difference criterion according to the sixth item. The upper part 801 of Figure 8 represents the reference model, that is, here, the result of the Fourier Transform calculated from the transmission or reception times of the frames of the standard stream, comprising three frequency peaks 801a, 801b, and 801c. The lower part 802 of Figure 8 represents the model of the monitored stream, that is, here, the result of the Fourier Transform calculated at starting from the times of transmission or reception of the frames of the monitored stream, comprising two pulses 802b and 802c. In the example of [Fig.8], the model of the monitored stream presents two differences 803 and 804 with the reference model: on the one hand (difference 803) the absence of pulse corresponding to pulse 801a and on the other hand (difference 804) pulse 802c has an amplitude greater than that of pulse 801c.

[0046] If the test in step 404 is successful, the control device 202 proceeds to step 405, in which it performs at least one action to secure the communication network, and then to the final step 406. If the test in step 404 is unsuccessful, the control device 202 proceeds directly to the final step 406.

[0047] In one embodiment, the control device 202 performs one or more of the following security actions: - record a security event indicating verification of at least one difference criterion (i.e., a positive response to the test in step 404); - request the given switch 201a (by sending a request) to block the port involved in sending or receiving the monitored stream; - request the given switch 201a (by sending a request) to block the virtual link involved in the sending or receiving of the monitored stream; - request the given switch 201a (by sending a request) to reroute the monitored flow for recording; - notify subscribers of the 101 network (by sending a request) so that they refuse the monitored stream; - request the given switch 201a (by sending a request) to reduce a priority assigned to the monitored flow;

[0048] [Fig.5] schematically illustrates an example of a hardware architecture (platform) 500 configured to implement the control device 202 of [Fig.2], in one embodiment.

[0049] The hardware architecture 500 comprises, connected by a communication bus 510: a processor or CPU (Central Processing Unit) 501; a RAM (Random Access Memory) 502; a ROM (Read Only Memory) 503, for example, Flash memory; a data storage device, such as a HDD (Hard Disk Drive), or a storage media reader, such as an SD (Secure Digital) card reader 504; at least one communication interface 505 allowing the control device 202 to interact with other elements, including switch 201a.

[0050] The processor 501 is capable of executing instructions loaded into RAM 502 from ROM 503, external memory (not shown), a storage medium such as an SD card, or a communication network (not shown). When the control device 202 is powered on, the processor 501 is able to read instructions from RAM 502 and execute them. These instructions form a computer program causing the processor 501 to implement the behaviors, steps, and algorithm described herein.

[0051] All or part of the behaviors, steps, and algorithms described herein can thus be implemented in software form by executing a set of instructions by a programmable machine, such as a DSP (Digital Signal Processor) or a microcontroller, or be implemented in hardware form by a dedicated machine or component (chip) or a dedicated set of components (chipset), such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit). Generally, the control device 202 comprises electronic circuitry arranged and configured to implement the behaviors, steps, and algorithms described herein.

[0052] Figure 6 schematically illustrates the communication network 101 and the monitoring system 102 in a second embodiment. The communication network 101 is identical to that of Figure 2 and comprises switches 201a, 201b, and 201c. The monitoring system 102 differs from that of Figure 2 in that the control device (referred to here as 601) is internal (and not external) to switch 201a. In this case, the control device 601 monitors and triggers actions only on switch 201a itself (it therefore does not act as a centralized function for several switches in the network).

[0053] Figure 7 schematically illustrates the communication network 101 and the monitoring system 102 in a third embodiment. The communication network 101 is identical to that of Figure 2 and includes switches 201a, 201b, and 201c. The monitoring system 102 differs from that of [Fig.2] in that the control device comprises a first part 701 and a second part 702, respectively internal and external to the switch 201a, and connected to each other by a link 703. The two parts 701 and 702 are for example complementary (no redundancy): the first part 701 provides a first level of monitoring, for immediate action within the switch 201a, and the second part 702 provides a second level of monitoring, for a wider view and action at the level of the network 101 (centralized function for several switches in the network).

Claims

Demands

1. Method for monitoring an onboard communication network (101) of an aircraft (100), the communication network being a deterministic switched Ethernet network using virtual links and comprising a set of subscribers and a set of switches (201a, 201b, 201c), the method being implemented by a monitoring system (102) comprising electronic circuitry, the method comprising, for a data stream transmitted or received by a given switch, a flow limiting function configured to enforce a bandwidth limit for said data stream, the method being characterized in that it further comprises, for said data stream, a security function (202; 601; 701, 702), configured to enforce a reference bandwidth consumption profile below the bandwidth limit, the security function comprising: - obtaining (401) measurements of at least one parameter of said data stream;- based on the measurements obtained, calculate (402) a value for at least one bandwidth consumption parameter, the calculated value contributing to the definition of a measured bandwidth consumption profile; - compare (403) the measured profile with the reference profile, by comparing the calculated value of at least one bandwidth consumption parameter with a reference value defined in the reference profile; and - if at least one difference criterion, identified by the comparison, is verified (404), perform (405) at least one action to secure the communication network.

2. A method according to claim 1, wherein at least one parameter of the data stream, for which measurements are obtained, belongs to the group comprising: - an average number of frames per second; - an average number of bytes per second; - a minimum data stream rate; - a maximum data stream rate; and - an average data stream rate.

3.

4. A method according to any one of claims 1 and 2, wherein the at least one bandwidth consumption parameter belongs to the group comprising: - at least one parameter relating to a data stream envelope; and - at least one parameter relating to a periodicity of the data flow. A method according to any one of claims 1 to 3, wherein at least one differentiation criterion belongs to the group comprising: - a peak in overconsumption, defined by a number of frames or bytes of the data stream, received or transmitted over a first time period, which is greater than a first high reference value; - persistent overconsumption, defined by a number of frames or bytes of the data stream, received or transmitted over a second time period longer than the first time period, which is greater than a second high reference value; - a peak of underconsumption, defined by a number of frames or bytes of the data stream, received or transmitted over a third time period, which is less than a first low reference value; - persistent underconsumption, defined by a number of frames or bytes of the data stream, received or transmitted over a fourth time period longer than the third time period, which is less than a second low reference value; - an average data flow rate that is higher than a reference average rate; and - a data stream model that exhibits at least one difference from a reference model, the data stream model being obtained by applying, at times of transmission or reception of frames of the data stream, a mathematical time / frequency conversion function, the reference model being obtained by applying, at times of transmission or reception of frames of a standard data stream, said mathematical function.

5. A method according to any one of claims 1 to 4, wherein at least one security action belongs to the group comprising: - recording a security event indicating the verification of at least one difference criterion; - requesting the given switch to block a port of the given switch involved in the transmission or reception of the data stream; - requesting the given switch to block a virtual link involved in the transmission or reception of the data stream; - requesting the given switch to reroute the data stream for recording; - notifying subscribers of the communication network to reject the data stream; and - reducing a priority assigned to the data stream.

6. A method according to any one of claims 1 to 5, wherein the data stream is transmitted or received through a given port of the given switch.

7. A method according to any one of claims 1 to 5, wherein the data stream is transmitted or received via a given virtual link passing through a given port of the given switch.

8. Product computer program, comprising instructions causing a processor (501) to execute the method according to any one of claims 1 to 7, when said instructions are executed by the processor.

9. Storage medium (503), storing a computer program comprising instructions causing a processor (501) to execute the method according to any one of claims 1 to 7, when said instructions are read and executed by the processor.

10. Monitoring system (102) of an onboard communication network (101) of an aircraft (100), the communication network being a deterministic switched Ethernet network using virtual links and comprising a set of subscribers and a set of switches (201a, 201b, 201c), the monitoring system comprising configured electronic circuitry

11. to implement, for a data flow transmitted or received by a given switch, a flow limiting function configured to enforce a bandwidth limit for said data flow, the monitoring system being characterized in that the electronic circuitry is further configured to implement, for said data flow, a safety function configured to enforce a reference bandwidth consumption profile below the bandwidth limit, the safety function comprising: - obtain measurements of at least one parameter of said data stream; - based on the measurements obtained, calculate a value of at least one bandwidth consumption parameter, the calculated value contributing to the definition of a measured bandwidth consumption profile; - compare the measured profile with the reference profile, by comparing the calculated value of at least one bandwidth consumption parameter with a reference value defined in the reference profile; and - if at least one difference criterion is verified, identified by the comparison, perform at least one action to secure the communication network. Aircraft (100) comprising an onboard communication network (101) which is a deterministic switched Ethernet network using virtual links and comprising a set of subscribers and a set of switches (201a, 201b, 201c), the aircraft being characterized in that it comprises a monitoring system (102) according to claim 10.