SYSTEM AND METHOD FOR PLATFORM CYBER VULNERABILITY ASSESSMENT - Patent application
By modeling and scoring platform architecture to simulate cyber attack vectors, the system predicts vulnerabilities before the design stage, addressing subjective limitations of existing methods and enhancing cybersecurity through automated resilience analysis.
Patent Information
- Application Number
- JP2024544778
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-02-17
- Filing Date
- 2023-01-17
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2043-01-17
AI Technical Summary
Existing methods for measuring platform security are subjective and limited to post-design implementation, focusing on detection and vulnerability scoring, failing to predict vulnerabilities during the design phase and lacking objective metrics for resilience analysis.
A system and method for assessing cyber vulnerabilities by modeling a platform's architecture, scoring components and connections, and simulating cyber attack vectors to predict vulnerabilities before the design stage, using automated processes to identify and rank weaknesses.
Enables the identification of cyber vulnerabilities during the design phase, reducing analysis time, improving cybersecurity posture, and providing objective metrics for resilience, enabling informed security design and cost justification.
Smart Images

Figure 0007761773000001 
Figure 0007761773000002 
Figure 0007761773000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to systems and methods for cyber vulnerability assessment of platforms. [Background technology]
[0002] A cyberattack is an offensive operation targeting a computer information system, computer network, infrastructure, or personal computing device. An attacker is a person or process attempting to access a system's data, functions, or other restricted areas without authorization, potentially with malicious intent. Depending on the context, a cyberattack can be part of cyberwarfare or cyberterrorism. Cyberattacks can be conducted by sovereign nations, individuals, groups, societies, or organizations and can originate from anonymous sources. Products that enable cyberattacks are sometimes called cyberweapons. Cyberattacks can steal, tamper, or destroy designated targets by hacking into susceptible systems. Cyberattacks range from installing spyware on personal computers to attempting to destroy the infrastructure of an entire nation.
[0003] Vulnerability assessment is the process of identifying, quantifying, and prioritizing (or ranking) vulnerabilities within a system. Penetration testing, commonly known as pen testing or ethical hacking, is a sanctioned, simulated cyber attack on a computer system performed to assess its security. Penetration testing is performed to identify weaknesses (also called vulnerabilities), including the potential for unauthorized parties to access the system's functions and data, and strengths, allowing a full risk assessment to be completed. The process typically involves identifying a target system and a specific goal, then considering available information and implementing various measures to achieve that goal. Summary of the Invention
[0004] In one example, the system may include a memory for storing machine-readable instructions. The system may include one or more processors for accessing the memory and executing the machine-readable instructions. The machine-readable instructions may include a component analyzer programmed to calculate an individual part score for each part of the platform based on a part property table and an individual connection score for each connection of the platform based on a connection property table. The component analyzer may be programmed to provide the individual part scores and the individual connection scores as score data. The machine-readable instructions may further include an architecture modeling engine that may be programmed to calculate a probabilistic model based on the score data and an architecture model. The probabilistic model may include part probability values and connection probability values, and the architecture model may characterize a target architecture of the platform. The machine-readable instructions may further include a survivability analysis engine that may be programmed to evaluate the probabilistic model and the architecture model to determine the likelihood that one or more potential cyberattacks against the platform based on the target architecture will be successful or unsuccessful in compromising at least a portion of the platform.
[0005] In yet another example, the computer-implemented method may include generating a part property table based on the part survey data, the part property table identifying individual part properties for one or more parts of the platform. The property table may include individual binary values and weight values associated with one of the one or more parts. The computer-implemented method may further include generating a connection property table based on the connection survey data, the connection property table identifying individual connection properties for one or more connections of the platform. The connection property table may include individual binary values and weight values associated with one of the one or more connections. The computer-implemented method may further include calculating a part score for each part of the platform based on the individual binary values and weight values for the individual parts of the one or more parts from the part property table; calculating a connection score for each connection of the platform based on the individual binary values and weight values for the individual connections of the one or more connections from the connection property table; and calculating a probabilistic model based on the part scores and connection scores and an architecture model. The probabilistic model may include part probability values and connection probability values, and the architecture model may characterize a target architecture of the platform. The computer-implemented method may further include evaluating the probabilistic model and the architecture model to determine the likelihood that one or more potential cyber-attacks against a platform based on the target architecture will be successful or unsuccessful in compromising at least a portion of the platform.
[0006] In a further example, the non-transitory machine-readable medium can include machine-readable instructions that can include a component analyzer, which can include a score calculator programmed to calculate an individual component score and an individual connection score for each component and each connection of the platform, and an architecture modeling engine. The architecture modeling engine can include a probability score calculator that can be programmed to calculate a probabilistic model including component probability values and connection probability values for corresponding components and connections of the platform based on the individual component scores and individual connection scores, and an architecture modeling module that is programmed to provide start conditions and end conditions to the architecture model that indicate where at least one potential cyber-attack starts and ends, respectively, with respect to the platform, based on architecture description data characterizing a target architecture of the platform and start condition data and end condition data. The machine-readable instructions can include a fault tolerance analysis engine that can be programmed to evaluate the probabilistic model and the architecture model to determine the likelihood that one or more potential cyber-attacks will be successful or unsuccessful in compromising at least one component of the platform. [Brief explanation of the drawings]
[0007] [Figure 1] FIG. 1 illustrates an example system for assessing platforms for cyber vulnerabilities. [Figure 2] FIG. 1 illustrates an example component analyzer. [Figure 3] FIG. 1 illustrates an example architecture modeling engine. [Figure 4] FIG. 10 illustrates an example of a part property table. [Figure 5] FIG. 10 illustrates an example connection property table. [Figure 6] FIG. 10 illustrates an example bus property table. [Figure 7] FIG. 10 is a diagram illustrating an example score table. [Figure 8] FIG. 1 illustrates an example architecture model. [Figure 9] FIG. 10 illustrates an example partial probability table. [Figure 10] FIG. 10 illustrates an example fault tolerance table. [Figure 11] FIG. 10 illustrates another example fault tolerance table. [Figure 12] FIG. 1 illustrates a graphical representation of an example evaluated architecture model. [Figure 13] FIG. 10 illustrates a graphical representation of another example post-evaluation architecture model. [Figure 14] FIG. 10 illustrates a graphical representation of a further example post-evaluation architecture model. [Figure 15] FIG. 1 illustrates a graphical representation of an example evaluated architecture model. [Figure 16] FIG. 1 illustrates an example method for assessing a platform for cyber threat vulnerabilities. [Figure 17] FIG. 1 illustrates an example method for assessing a platform for cyber threat vulnerabilities. [Figure 18] FIG. 1 illustrates an example computing system that can be used to perform an analysis of a platform's target architecture for cyber vulnerabilities. DETAILED DESCRIPTION OF THE INVENTION
[0008] Existing methods for measuring platform security include manually filling out red, yellow, and green risk cubes and relying solely on the experience of internal subject matter experts (SMEs). These methods subjectively measure risk and are not suitable for further analysis, such as worst-case attack vectors. Furthermore, current methods for cyber-physical attacks focus on detection, penetration testing, threat analysis, and vulnerability scoring. These techniques focus on detecting attacks in real time after a platform has been designed and implemented (e.g., used, manufactured, etc.). Real-time detection systems for cyber attacks or threats rely on machine learning or other methods to recognize patterns in normal network traffic, allowing such systems to alert administrators to anomalous cyber behavior. Penetration testing is similar to real-time detection but acts as a stress test for the system. While it is an important tool for discovering vulnerabilities, it is a separate function that also occurs after a platform has been designed and implemented.
[0009] Threat analysis is generally based on software that attempts to identify system weaknesses. For robust software applications, such software is limited to discovering vulnerabilities within other software packages. Several methods exist for modeling and identifying security threats, such as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Privilege Escalation (STRIDE), Process for Attack Simulation and Threat Analysis (PASTA), or Trike, which attempt to uncover cyberattack vectors by focusing on data such as software protocols. These methods are implemented in tools such as the Microsoft® Threat Modeling Tool, but are limited to reducing software vulnerabilities within computer applications.
[0010] Described herein are systems and methods for identifying and ranking cyber vulnerabilities for a platform based on the platform's architecture. In contrast to existing tools and techniques, the systems and methods described herein can be used to predict vulnerabilities and prevent attacks during the platform's design phase or before such phase is complete. The systems and methods described herein can assess non-kinetic cyber system resilience to improve the platform's cybersecurity posture. For example, the systems and methods described herein enable a user to define one or more systems or subsystems (referred to herein in some examples as "parts" or "components") of a platform through its physical architecture and SME-identified attributes. The described systems and methods can use this information to score one or more parts of the platform based on risk. These scores enable further analysis regarding worst-case attack vectors, cost-benefit analysis, and indicators of the system's overall resilience. The systems and methods described herein provide objective metrics for resilience, enabling the identification of cyber weaknesses and enabling comparisons to inform security design, justify integration costs, and save time during budgeting.
[0011] According to examples described herein, components can be factually defined to model the physical architecture of a platform, and the modeled physical architecture of the platform can be simulated to simulate the impact of cyber attack vectors on the platform, allowing for analysis of cyber threats to a platform during or before the platform's design stage rather than relying on real-time monitoring software. Thus, the systems and methods described herein can be used to identify or capture cyber vulnerabilities at the design stage, which reduces analysis time by replacing time-consuming manual processes with automated processes, reduces testing time by identifying components or interfaces that require more detailed scrutiny, saves budgeting time by providing reliable evidence, and saves mitigation time through the exploration of alternative physical architectures for the platform.
[0012] FIG. 1 illustrates an example system 100 for assessing a platform for cyber vulnerabilities. As used herein, the term “platform” may refer to a system, device, vehicle (e.g., a ground vehicle, aircraft, or vessel), information machine (e.g., a computer, telephone system, etc.), or any type of technology that may be subject to a cyberattack. As an example, the platform may be an unmanned aircraft system (UAS). In some examples, referred to herein as “given examples,” the platform is an aircraft system that may include multiple subsystems. In some cases, the subsystems may include one or more line replaceable units (LRUs). The LRUs are modular components of the aircraft. In some cases, one or more LRUs may include line maintenance parts (LMPs). In the given example, the aircraft system may be accessed (e.g., by an unauthorized user) using a WiFi interface (e.g., an internal modem), a Bluetooth interface (e.g., a radio), a universal serial bus (USB) interface, or a data interface (e.g., an on-board data connector (OBD) connector). In general, a point of entry into a platform is a physical device that an unauthorized user (e.g., a cyber attacker) can utilize to enter the platform. In the given example, for example, an unauthorized user can enter through a computer connected to a data interface, through a USB connected to a radio, wirelessly via Bluetooth via a radio, or wirelessly via WiFi via an internal modem.
[0013] In some examples, once an unauthorized user has compromised the system, the unauthorized user may use the aircraft system's communications network to access subsystems of the aircraft. The communications network may include any number of networks, switches, routers, etc., capable of communicating data (e.g., between subsystems of the aircraft system). The communications network may include a controller area network (CAN) bus, which may serve as a central network through which components of the aircraft system can communicate with each other. The unauthorized user may inject false data or malicious code (e.g., viruses) into the communications network to target respective subsystems of the aircraft system. For example, the unauthorized user may attach a device (e.g., a USB device) with false data to the CAN bus of the aircraft electronics system to inject false data to alter engine telemetry readings, compass and altitude data, altitude, airspeed, and angle of attack.
[0014] In the given example, the aircraft system includes an aircraft braking system, a steering control system, and an engine control system coupled to a communications network. For clarity and brevity, the given example is described herein with respect to an unauthorized user accessing or attacking one of the aircraft's braking, steering control, and engine control systems. However, it should be understood that an unauthorized user may access other subsystems of the aircraft system (e.g., communications, navigation, etc.) not described herein. Thus, the examples herein are equally applicable to identifying cyber vulnerabilities (or cyber weaknesses) in other subsystems of the aircraft system.
[0015] Continuing with the example of FIG. 1 , system 100 includes computing platform 102. Computing platform 102 may be configured to model the platform's architecture. Accordingly, computing platform 102 may model the platform's physical architecture (e.g., via one or more logical models). The logical models or views may be composed of conceptual design drawings, circuit diagrams, and block diagrams that define the form of the platform and the arrangement of system components and associated interfaces. In the given example, computing platform 102 may be configured to define the physical architecture of aircraft systems such as hardware access points, communications networks, aircraft braking, steering control, and engine control systems.
[0016] The computing platform 102 may include a memory 104 for storing machine-readable instructions and data and a processing unit 106 for accessing the memory 104 and executing the machine-readable instructions. The memory 104 represents a non-transitory machine-readable memory (or other medium) such as a random access memory (RAM), a solid-state drive, a hard disk drive, or a combination thereof. The processing unit 106 may be implemented as one or more processor cores. The computing platform 102 may be implemented within a computing cloud. In such a context, the functionality of the computing platform 102, such as the processing unit 106 and the memory 104, may represent a single instance of hardware or multiple instances of hardware where an application runs across multiple (e.g., distributed) instances of hardware (e.g., computers, routers, memory, processors, or combinations thereof). Alternatively, the computing platform 102 may be implemented on a single dedicated server or workstation.
[0017] The processing unit 106 can access the memory 104 to execute the platform description generator 108. The platform description generator 108 can generate a part property table 110 that identifies respective part properties for one or more parts of the platform, a connection property table 112 that identifies respective connection properties for each connection of the platform, and a bus property table 114 that identifies respective bus properties for one or more buses of the platform. Because all connections on the same bus share similar properties, at least some of the bus properties in the bus property table 114 can be similar to part properties and connection properties. For example, the platform description generator 108 can break down the platform into factual queries that can consist of inputting information that characterizes the platform and answering several cybersecurity questions about each component or part and interface in the platform. The survey questions can be about attributes identified by the SME, which, along with information that characterizes the platform's architecture, enable the underlying model to aggregate the data into useful information about the entire platform.
[0018] As an example, respective part properties for one or more components of a platform may include general part properties, source properties, and target properties. In a given example, the general part properties for each component may indicate whether the respective component is commercially accessible, custom-built, recently patched, software-encrypted at rest, has write-protected memory, is capable of in-band cyber detection, and / or is capable of out-of-band cyber detection. The source properties for each component may indicate whether the respective component is radio frequency (RF) capable, supports removable media, requires a direct connection for access, and / or requires physical access. The target properties for each component may indicate whether the respective component is safety-critical, flight-critical, and / or stores data files. In a given example, the connection properties for one or more connections within the platform may indicate whether the respective connection is based on a published open specification, based on a government-controlled specification, uses a custom protocol, is a serial connection, is a discrete connection, is a non-data connection, uses encryption (e.g., via message hashing), and / or uses cryptographic authentication. In the given example, the bus properties for each bus may indicate whether the respective bus employs a master controller or does not employ a master controller.
[0019] For example, the platform description generator 108 may query a user via the output device 116 (e.g., a display) for a part survey, a connection survey, and a bus survey. In some examples, one or more surveys described herein may be implemented as checkbox surveys. A party survey may include one or more fields for entering one or more parts of the platform. In some cases, a part survey may identify different part properties for each part that a user can assign based on user input at the input device 118 (e.g., a mouse, a keyboard, etc.). A connection survey may include one or more fields for entering one or more connections of the platform. In some cases, a connection survey may identify different connection properties for each connection that a user can assign based on user input at the input device 118. A bus survey may include one or more fields for entering one or more buses of the platform. In some cases, a bus survey may identify different bus properties for each bus that a user can assign based on user input at the input device 118.
[0020] In some examples, the platform description generator 108 can output each of the part property table 110, the connection property table 112, and the bus property table 114 on the output device 116. A user can use the input device 118 to adjust or modify the properties assigned to corresponding parts, connections, and buses of the platform. In other examples, the platform description generator 108 can output the part property table 110, the connection property table 112, and the bus property table 114 on the output device 116, and a user can add corresponding properties, such as by assigning them to each part, connection, and bus in the respective part property table 110, connection property table 112, and bus property table 114 (e.g., by placing an “X”). In these examples, the platform description generator 108 can survey the user for the parts, connections, and buses and provide the part property table 110, connection property table 112, and bus property table 114 for property assignment (e.g., via the input device 118).
[0021] Each property in each of the component property table 110, the connection property table 112, and the bus property table 114 may be associated with a binary value (e.g., 0 or 1), a weight value (e.g., ranging from a negative value such as −1 to a positive value such as +1). Each property assigned or selected for each component, connection, or bus may be associated with or assigned a binary value of 1 in each of the tables 110, 112, and 114. In some instances, a cost value may be assigned to each property in each of the tables 110, 112, and 114. The weight value may have a positive magnitude indicating that the respective property has a positive characteristic and a negative magnitude indicating that the respective property has a negative characteristic. Thus, properties for components, connections, and buses may have positive or negative characteristics.
[0022] The weights for each property may be determined in several ways. In one example, the weights may be determined by a user. For example, one or more cyber experts may input subjective weights based on their experience. In another example, the weights may be determined by matching the fault-tolerance data 142 to real-world data. For example, if the fault-tolerance data 142 is a predicted list of vulnerable parts, the predicted list may be compared to a human-compiled list of vulnerable parts. The weights may be fine-tuned until the predicted list matches the human-compiled list.
[0023] The processing unit 106 can access the memory 104 to execute the component analyzer 120. The component analyzer 120 can process the part property table 110 to calculate a part score for each identified part in the part property table 110. The part score can indicate the cyber resiliency of the platform's parts to withstand a potential cyber-attack. Thus, the part score can indicate the cyber resiliency of the component. For example, the component analyzer 120 can process the associated binary value and weight value for each identified part to calculate an individual part score. The component analyzer 120 can process the connection property table 112 to calculate a connection score for each identified connection in the connection property table 112. The connection score can indicate the likelihood that each connection in the platform will be used during a potential cyber-attack. Thus, the connection score can indicate the interface cyber-resilience of each interface used during a cyber-attack. For example, the component analyzer 120 can process the associated binary value and weight value for each identified connection to calculate an individual connection score. The component analyzer 120 may process the bus property table 114 to calculate a bus score for each identified bus in the bus property table 114. The bus score may indicate the likelihood that the platform's buses will be used during a potential cyber-attack. For example, the component analyzer 120 may process the associated binary values and weight values for each identified bus to calculate a respective bus score.
[0024] The component analyzer 120 can generate score data 122 for processing by the architecture modeling engine 124. The score data 122 can include scores calculated for each component, connection, and bus. The component analyzer 120 can generate a partitioned component property table 126. The component analyzer 120 can process the component property table 110 to identify source and target properties for each component and provide the partitioned component property table 126 to the architecture modeling engine 124. Thus, the component analyzer 120 can partition the component property table 110 to provide the partitioned component property table 126. The source properties in the partitioned component property table 126 can be used by the architecture modeling engine 124 to determine which components are considered as points of entry into the platform. The target properties in the partitioned component property table 126 can be used by the architecture modeling engine 124 to determine which components lead to an end state corresponding to a successful attack on the respective component.
[0025] For example, the architecture modeling engine 124 may receive architecture description data 128 that characterizes a target architecture of a platform. For example, the architecture description data 128 may provide a topology description of how parts (e.g., subsystems) should be connected within the platform based on the target architecture. The architecture modeling engine 124 may be programmed to generate an architecture model 132 based on the architecture description data 128. The architecture modeling engine 124 may further receive attack target description data 130 that may identify source properties and target properties. One or more source properties identified by the attack target description data 130 may be used by the architecture modeling engine 124 to flag (e.g., associate) a portion of the platform as a source of a potential cyber-attack. The architecture modeling engine 124 may compare the one or more source properties of the attack target description data 130 with the partitioned part property table 126 to identify corresponding parts that should be identified (e.g., labeled, flagged) in the architecture model 132 as sources (e.g., entry points) of a potential cyber-attack. The one or more target properties identified by the attack target description data 130 may be used by the architecture modeling engine 124 to flag (e.g., associate) portions of the platform as targets of potential cyber-attacks. The architecture modeling engine 124 may compare the one or more target properties of the attack target description data 130 with the partitioned part property table 126 to identify corresponding parts that should be identified (e.g., labeled, flagged) as targets of potential cyber-attacks in the architecture model 132 of the platform's target architecture.
[0026] As a further example, the architecture modeling engine 124 can add start conditions and end conditions to the architecture model 132. The start condition can indicate a starting condition of a cyber-attack. For example, in a given example, the start condition can be a removable media condition (e.g., indicating that the cyber-attack is launched via a portable device such as a USB or CD). In some examples, the start condition can be an RF enabled condition (e.g., indicating that the cyber-attack is launched via a wireless connection) or a direct connection (e.g., indicating that the cyber-attack is launched via a wired connection). The end condition can indicate an end condition of the cyber-attack. For example, in a given example, the end condition can be a safety-critical condition or a flight-critical condition (e.g., indicating which respective components may be successful as a result of the attack). As an example, if the goal of an unauthorized user is to endanger human life, the end condition can be a safety-critical condition. A component having a safety-critical component property can be a target (e.g., can transition to an end state corresponding to a successful attack). In another example, the end condition can be when the attack is thwarted. One or more parts of the platform may transition to an end state corresponding to an unsuccessful attack.
[0027] The architecture modeling engine 124 may calculate a probabilistic model 134 based on the score data 122. The probabilistic model 134 may include a part probability value for each part representing the likelihood that the respective part will prevent or thwart a potential cyber-attack (e.g., from spreading to other downstream parts or from compromising the part within the platform). A part probability value close to zero may indicate that the respective part is unlikely to prevent or thwart the potential cyber-attack. A part probability value close to one may indicate that the respective part is likely to prevent or thwart the potential cyber-attack. Further, the probabilistic model 134 may include a connection probability value for each connection representing the likelihood of a potential cyber-attack using the respective connection. A connection probability value close to zero may indicate that the respective connection is unlikely to be used during a potential cyber-attack. A connection probability value close to one may indicate that the respective connection is likely to be used during a potential cyber-attack. Further, the probabilistic model 134 may include a bus probability value for each bus representing the likelihood of a potential cyber-attack using the respective bus. A bus probability value close to zero may indicate that the respective bus is unlikely to be used during a potential cyber-attack. A bus probability value close to one may indicate that the respective bus is likely to be used during a potential cyber-attack.
[0028] In a further example, the processing unit 106 can access the memory 104 to execute the fault-tolerance analysis engine 136. The fault-tolerance analysis engine 136 can include a first analysis tool 138. In one example, the first analysis tool 138 can be implemented to use a Markov model as a matrix equation to calculate a part contribution probability value for a part. The first analysis tool 138 can use the architecture model 132 and the probabilistic model 134 to determine the likelihood (e.g., as a percentage) that a potential cyber-attack will be successful or unsuccessful in compromising one or more target parts. The first analysis tool 138 can calculate a part contribution probability value indicating the contribution of each part to a successful cyber-attack on the target part. Thus, the part contribution probability value can indicate that a given percentage of cyber-attacks reaching the respective cyber-attack will result in a successful cyber-attack on the target part. In a given example, the first analysis tool 138 may determine that 85% of potential cyber-attacks arriving at the WiFi interface (e.g., the built-in modem) will result in a successful cyber-attack on one or more of the braking system, steering system, and engine control system.
[0029] In some cases, the first analysis tool 138 can identify each entry point of a potential cyberattack that is most likely to lead to a successful or unsuccessful compromise of one or more target components. For example, the first analysis tool 138 can evaluate the part contribution probability value of each component that is an entry point against a part contribution threshold to identify one or more components of the platform that are equal to or greater than the part contribution threshold. The part contribution threshold can represent an entry point that is most likely to lead to a successful compromise of one or more target components. In some cases, the first analysis tool 138 can calculate a platform resilience score (e.g., a resilience metric) that indicates whether the platform can withstand a potential cyberattack based on a worst-case scenario. For example, the first analysis tool 138 can evaluate the part contribution probability value of each component that is an entry point to identify a given part contribution probability value that has the highest value. The first analysis tool 138 can calculate the resilience score by subtracting the given part contribution probability value from a reference value (e.g., 1) to obtain the platform's resilience score.
[0030] In the given example, the first analysis tool 138 may determine that 85% of potential cyber-attacks arriving at the WiFi interface (e.g., the internal modem), 65% of potential cyber-attacks arriving at the Bluetooth interface, and 70% of potential cyber-attacks arriving at the data interface will result in a successful cyber-attack on one or more of the braking system, steering system, and engine control system. The first analysis tool 138 may select the WiFi interface because it has the largest component contribution probability value and calculate that the platform has a fault tolerance score of 15% (e.g., 100% - 85% = 15%). Because the WiFi interface has a fault tolerance score of 15% and is therefore the weakest point of the platform, this may control the overall fault tolerance rate of the platform for the target architecture.
[0031] In some examples, the fault tolerance analysis engine 136 includes a second analysis tool 140. In one example, the second analysis tool 140 is implemented as a Monte Carlo analysis tool. The second analysis tool 140 can simulate a potential cyber-attack by stepping through the architecture model 132 to identify possible next moves in a cyber-attack vector. The next moves are randomly selected according to a probability distribution derived from the probabilistic model 134. As used herein, the term “cyber-attack vector” and its derivatives can refer to one or more attack paths or attack avenues that unauthorized users and / or malicious code can utilize to infiltrate and / or attack a portion of the platform. The cyber-attack vectors can identify platform entry points that can be exploited by unauthorized users and / or malicious code into the platform. Although an example is described herein in which the first analysis tool 138 is implemented as a Markov model and the second analysis tool 140 is implemented as a Monte Carlo analysis tool, in different examples, different tools may be used to implement the respective tool functions as described herein.
[0032] In some instances, the second analysis tool 140 can calculate the frequency of each cyber-attack vector across multiple simulation iterations to identify the platform's most vulnerable components. In some instances, the fault-tolerance data 142 can include a fault-tolerance score for each identified cyber-attack vector, indicating whether a platform based on the target architecture will withstand the corresponding cyber-attack vector. In some instances, the fault-tolerance data 142 can include an architecture model 132 for rendering on the output device 116. For example, in a further example, the processing unit 106 can access the memory 104 to execute a graphical user interface (GUI) generator 144. The GUI generator 144 can render the architecture model 132 on the output device 116 and annotate the architecture model 132 to indicate how far the cyber-attack has progressed in the platform and identify the most vulnerable components.
[0033] In some instances, the resilience data 142 may be used to modify the platform's target architecture to eliminate one or more identified cyber attack vectors and / or reduce the likelihood that one or more identified cyber attack vectors will harm the platform (e.g., impair a mission objective). Thus, the resilience data 142 may be used as cyber vulnerability analysis feedback data to enable one or more users (e.g., systems engineers) to improve the platform's effectiveness and overall cyber vulnerability by enabling them to improve the platform's based target architecture.
[0034] FIG. 2 is an example component analyzer 200, such as the component analyzer 120 shown in FIG. 1. Accordingly, in some examples, reference will be made to FIG. 1 in the example of FIG. 2. The component analyzer 200 can process the part property table 110 to calculate a part score 202 for each identified part in the part property table 110. For example, the component analyzer 200 can include a linear score calculator 204. The linear score calculator 204 can implement a linear score calculation formula to calculate the part score 202 based on the binary values and weight values for each part from the part property table 110. For example, if each part has two assigned part properties, and each assigned part property is assigned a binary value and weight value, such as B1, W1 and B2, W2, the part score 202 can be calculated by the linear score calculator 204 as SP=B1×W1+B2×W2, where SP is the part score 202.
[0035] In some instances, the component analyzer 200 includes a polynomial calculator 206. The polynomial score calculator 206 can implement a polynomial score formula to calculate the part score 202 based on the binary values and weight values for each part from the part property table 110. For example, if each part has two assigned part properties and each assigned part property is assigned a binary value and weight value, such as B1, W1 and B2, W2, the part score 202 can be calculated by the polynomial score calculator 206 as SP = B1 × W1 + B2 × W2 + B1 × W1 × B2 × W2, where SP is the part score 202. In some examples, the component analyzer 200 can include a nonlinear calculator 208. The nonlinear calculator 208 can implement a nonlinear score formula to calculate the part score 202 based on the binary values and weight values for each part from the part property table 110. For example, if each part has two assigned part properties, and each assigned part property is assigned a binary value and a weight value, such as B1, W1 and B2, W2, then the part score 202 may be calculated by the non-linear calculator 208 as SP=B1×W1+e^(B2×W2), where SP is the part score 202.
[0036] In some examples, the component analyzer 200 may include a machine learning score calculator 210. The machine learning score calculator 210 may employ a machine learning algorithm that may be trained to calculate the part score 202 based on the binary values and weight values for each part from the part property table 110. As a further example, the linear score calculator 204, the polynomial score calculator 206, the nonlinear score calculator 208, and the machine learning score calculator 210 may each calculate an individual part score, and the component analyzer 200 may calculate an average part score as the part score 202 based on the individual part scores calculated by each calculator 204, 206, 208, and 210. The component analyzer 200 may calculate a connection score 212 for each connection and a bus score for each bus in the same or similar manner as described herein for the part score 202. The component analyzer 200 can provide the part scores 202, the connection scores 212, and the bus scores 214 to the architecture modeling engine 124 as or as part of the score data 122. Although particular calculators for calculating the corresponding scores are described herein with respect to FIG. 2, in other examples, different and / or similar calculators can be used for score calculation.
[0037] FIG. 3 illustrates an example architecture modeling engine 300, such as the architecture modeling engine 124 shown in FIG. 1. Accordingly, in some examples, reference is made to FIG. 1 in the example of FIG. 3. The architecture modeling engine 300 may include an architecture modeling module 302. The architecture modeling module 302 may process the architecture description data 128 to calculate the architecture model 132. The architecture modeling module 302 may receive start condition data 304 and end condition data 306 that indicate where a cyber-attack may begin and end, respectively. In some examples, the architecture modeling engine 300 includes a squashing calculator 308. The squashing calculator 308 may implement a sigmoid function to calculate a part probability value for each part based on the part score from the score data 122. By way of example, the sigmoid function may be expressed as f(x)=0.5±0.5*tanh(x), where x is the part score value for each part.
[0038] In some instances, the architecture modeling engine 300 includes a scaling calculator 310. The scaling calculator 310 can implement a scaling function to calculate a part probability value for each part based on the part scores from the score data 122. As an example, the scaling function can be expressed as (value-minimum) / (maximum-minimum), where the minimum and maximum represent the minimum and maximum scores for the entire system. As a further example, the architecture modeling engine 300 includes a machine learning calculator 312. The machine learning calculator 312 can employ a machine learning algorithm that can be trained to calculate part probability values based on the part scores from the score data 122. The architecture modeling engine 300 can calculate a connection probability value for each connection and a bus probability value for each bus in the same or similar manner as described herein for the part probability values. The architecture modeling engine 300 can output the calculated part probability values, connection probability values, and bus probability values as a probabilistic model 134, which can be provided to the fault-tolerance analysis engine 136. Although a particular calculator for calculating the corresponding probability values is described herein with respect to FIG. 3, in other examples, different and / or similar calculators may be used for the probability calculations.
[0039] 4 is an example party property table 400, such as the part property table 110 shown in FIG. 1. Accordingly, in some examples, reference may be made to FIGS. 1-2 in the example of FIG. 4. The part property table 400 may include a first general property (labeled as "Part Property 1"), a second general property (labeled as "Part Property 2"), a first source property (labeled as "Source Property 1"), a second source property (labeled as "Source Property 2"), a first target property (labeled as "Target Property 1"), and a second target property (labeled as "Target Property 2"). While the example of FIG. 4 shows two of each of the general properties, source properties, and target properties defined for a platform part, in other examples, any given number of general properties, source properties, and target properties may be defined for a platform part.
[0040] In the example of FIG. 4 , the platform's parts are identified as A, B, and C. As described herein, the platform description generator 108 can provide a part property table 400 with properties associated with each one of parts A, B, and C. In the example of FIG. 4 , the association is indicated by the inclusion of an “X” in a cell of the part property table 400. To determine a part score for each part, the platform description generator 108 can assign a binary value of zero (0) to each cell of the part property table 400 that does not contain an “X” and a binary value of one (1) to each cell that does contain an “X.” As described herein, each of the general properties, source properties, and target properties can be associated with a weight value. The component analyzer 120 or 200 can identify a respective binary value for each of parts A, B, and C by evaluating each part's column in the part property table 400 to calculate each part's individual part score (e.g., part score 202 as shown in FIG. 2 ). For example, component analyzer 120 or 200 may determine that part A has binary values 1,0,1,0,0,0, part B has binary values 0,1,0,0,0,1, and part C has binary values 1,1,0,1,1,0.
[0041] FIG. 5 is an example connection property table 500, such as the connection property table 112 shown in FIG. 1. Accordingly, in some examples, reference is made to FIGS. 1-2 in the example of FIG. 5. The connection property table 500 may include a first connection property (labeled as “Connection Property 1”), a second connection property (labeled as “Connection Property 2”), and a third connection property (labeled as “Connection Property 3”). The example of FIG. 5 shows three connection properties defined for connections between platform components, but in other examples, any given number of connection properties may be defined for a platform connection. In the example of FIG. 5, the connections include a first connection (labeled as “A::B”) between a first component (labeled as “A”) and a second component (labeled as “B”), and a second connection (labeled as “A::C”) between the first component (labeled as “C”) and a third component. As described herein, the platform description generator 108 may provide connection properties associated with each one of the first and second connections in a connection property table 500. In the example of Figure 5, the association is indicated by the inclusion of an "X" in the cell of the connection property table 500.
[0042] To determine the connection scores for the first and second connections, the platform description generator 108 may assign a binary value of zero (0) to each cell in the connection property table 500 that does not contain an "X" and a binary value of one (1) to each cell that does contain an "X." Each of the first, second, and third connection properties may be associated with a weight value. The component analyzer 120 or 200 may identify the respective binary values for each of the first and second connections by evaluating each connection's column in the connection property table 500 to calculate an individual connection score for each connection (e.g., connection score 212 as shown in FIG. 2 ). For example, the component analyzer 120 or 200 may be programmed to determine that the first connection has a binary value of 1,1,1 and that the second connection has a binary value of 1,1,0.
[0043] FIG. 6 is an example bus property table 600, such as the bus property table 114 shown in FIG. 1. Accordingly, in some examples, reference may be made to FIGS. 1-2 in the example of FIG. 6. The bus property table 600 may include a first bus property (labeled as “Bus Property 1”), a second bus property (labeled as “Bus Property 2”), and a third bus property (labeled as “Bus Property 3”). The example of FIG. 6 shows three bus properties defined for a first bus (labeled as “Bus 1”) of the platform, although in other examples, any given number of bus properties may be defined for one or more buses of the platform. As described herein, the platform description generator 108 may provide the bus properties associated with the first bus in the bus property table 600. In the example of FIG. 6, the association is indicated by the inclusion of an “X” in the cell of the bus property table 600.
[0044] To determine the bus score for the first bus, the platform description generator 108 may assign a binary value of zero (0) to each cell in the bus property table 600 that does not contain an "X" and a binary value of one (1) to each cell that contains an "X." Each of the first, second, and third bus properties may be associated with a weight value. The component analyzer 120 or 200 may identify the respective binary values for the first bus by evaluating the column for each connection in the connection property table 500 to calculate a respective bus score for each connection (e.g., bus score 214 as shown in FIG. 2 ). For example, the component analyzer 120 or 200 may determine that the first bus has binary values 0, 1, 1.
[0045] FIG. 7 is an example score table 700. Score table 700 may be part of or included as part of score data 122, as shown in FIG. 1. Thus, in some examples, reference is made to FIGS. 1-2 and 4-6 in the example of FIG. 7. Component analyzer 120 may provide score table 700. For example, component analyzer 120 or 200 may calculate a component score for each of components A, B, and C, a connection score for each of the first and second connections, and a bus score for the first bus in the same or similar manner as described herein.
[0046] FIG. 8 is an example architecture model 800, such as the architecture model 132 shown in FIG. 1. Accordingly, in some examples, reference is made to FIGS. 1-7 in the example of FIG. 8. The architecture model 800 may be generated by the architecture modeling engine 124 or 300 based on architecture description data 128 related to a target architecture of a platform. In the given example, the platform is an aircraft system, and thus the target architecture may be the physical architecture of the aircraft system. The architecture model 800 may represent the target architecture of the platform. In the example of FIG. 8, the architecture model 800 includes a first part 802 (labeled as "A"), a second part 804 (labeled as "B"), a third part 806 (labeled as "C"), and a first bus 808 (labeled as "Bus 1"). A first connection 808 can connect a first component 802 and a second component 804, a second connection 812 can connect the first component 802 and a third component 806, and a third connection 814 can connect the first component 802 and a first bus 808. A fourth connection 816 can connect the second component 804 and the first bus 808, and a fifth connection 818 can connect the third component 806 and the first bus 808. As an example, the architecture model 800 can represent an autonomous vehicle, where the first component 802 can be a satellite communication link for updates, the second component B 804 can be a steering wheel, the third component 806 can be a smartphone-compatible USB port, and the first bus 808 can be a vehicle bus network. In another example, the architecture model 800 can represent a different platform.
[0047] As an example, source properties in partitioned part property table 126 may be used by architecture modeling engine 124 to determine which parts of architecture model 800 to consider as points of entry into the platform. Target properties in partitioned part property table 126 may be used by architecture modeling engine 124 to determine which parts of architecture model 800 will lead to an end state corresponding to a successful attack on the respective part. Architecture modeling engine 124 may use one or more source properties identified by attack target description data 130 to flag (e.g., associate) parts of architecture model 800 as points of entry for a potential cyber-attack, and may use one or more target properties identified by attack target description data 130 to flag (e.g., associate) portions of architecture model 800 as targets for a potential cyber-attack.
[0048] FIG. 9 illustrates an example partial probability table 700. The partial probability table 700 may represent a portion of the probabilistic model 134, as shown in FIG. 1. Accordingly, in some examples, reference is made to FIGS. 1-8 in the example of FIG. 9. The architecture modeling engine 124 or 300 may provide the probability table 700 in the same or similar manner as described herein. For example, the architecture modeling engine 124 or 300 may calculate respective part property values, connection property values, and bus property values for each of the parts 802, 804, 806, the connections 810, 812, 814, and the first bus 808, as shown in FIG. 8. As an example, the part 804 is shown in the probability table 700 with a part property value of 75%, indicating that there is a 75% probability that the part 804 in FIG. 8 will prevent or thwart a potential cyber-attack. These transition probabilities are part of the probabilistic model 134, which may be based on the connection and bus scores 122.
[0049] In FIG. 9 , the bottom row labeled “Start” indicates the probability of starting an attack from a particular part. For example, because part A is the only entry point, the attack has a 100% probability of starting from part A. In another example, if there were multiple entry points, these probabilities could be divided evenly across all entry points. In FIG. 9 , the two right-most columns labeled “End 1” and “End 2” indicate the probability of ending an attack at a particular part. End 1 corresponds to a successful attack, and End 2 corresponds to an unsuccessful attack. In one example, each time an attack reaches part A, there is a 12% chance that the attack will be thwarted, resulting in an unsuccessful attack. If the attack is not thwarted at part A, the attacker can continue to part B, part C, or bus 1. In some examples, each time an attack reaches part B, there is a 67% chance that the attack will be thwarted; otherwise, the attack is successful and moves to end 2. These probabilities are part of a probability model 134, which can be based on the part and bus scores 122.
[0050] FIG. 10 is an example fault-tolerance table 1000. The fault-tolerance table 1000 may be generated by the fault-tolerance analysis engine 136 as shown in FIG. 1. Accordingly, in some examples, reference is made to FIGS. 1 and 8 in the example of FIG. 10. The fault-tolerance table 1000 may be provided as part of the fault-tolerance data 142 and thus may be rendered on the output device 116. The fault-tolerance table 1000 includes a fault-tolerance score for each component of the platform. For example, the fault-tolerance table 1000 includes a respective fault-tolerance score for each of the components 802, 804, 806, and the first bus 808. In some instances, the fault-tolerance analysis engine 136 may use the first and second tools 138 and 140 to calculate the respective fault-tolerance scores for the components 802, 804, 806, and the first bus 808. In the example of FIG. 10 , a first column (labeled “Tool 1”) may include fault-tolerance scores calculated by the first tool 138, and a second column (labeled “Tool 2”) may include fault-tolerance scores calculated by the second tool 140. Each fault-tolerance score in the fault-tolerance table 1000 may indicate whether the respective component or bus is resistant to a potential cyberattack. As an example, component 802 may have a low fault-tolerance score, indicating that component 802 requires a cybersecurity vulnerability update, thus allowing the overall cybersecurity performance of the platform to be improved. For example, a user may modify the target architecture of the platform, and the system and method may process the modified target architecture to calculate a new fault-tolerance table and determine whether the fault-tolerance score of component 802 has increased.
[0051] The fault tolerance analysis engine 136, in some examples, can have one or more tools as described herein. Each tool can be programmed in more than one way to output a fault tolerance score. In one example, the first tool 138 represents the architecture model 132 and the probabilistic model 134 as a system of equations that describes how each component, connection, and bus affects each other. In the example of table 1000, each equation in the system of equations is 0.0*VA + 0.75*VB + 0.01*VC + 0.12*VBUS1 + 0.0*VEND1 + 0.12*VEND2 = 0. Here, the goal is to solve for the values of VA, VB, VC, and VBUS1. The solution can be scaled by the selection of VEND1 and VEND2. To scale these values in terms of attack success, the values can be VEND1 = 1.0 and VEND2 = 0.0. The values VA, VB, VC, and VBUS1 can represent the contribution of each component and bus to the attack. Thus, 1 minus these values can represent their contribution to the overall fault tolerance of the system. These fault tolerance estimates are shown in the Tool 1 column of table 1000. The component and bus scores can be extended to connections by combining the scores and probabilities of the components or buses to which they are connected. The fault tolerance estimates for components, connections, and buses can provide or create a picture of which components are most likely to lead to a successful attack. For example, the fault tolerance table 1000 under Tool 1 shows that component A has the lowest score, which may indicate that component A is a desirable pivot point for an attacker.
[0052] In another example, the second tool 134 simulates attacks one at a time. After a certain number of runs, the value in the fault tolerance table 1000 under Tool 2 is the percentage of runs in which the attack did not reach a component, connection, or bus. For example, out of 100 runs, the attack did not reach component C 79 times. In the other 21 times, the attack used component A. This results in different fault tolerance estimates for components, connections, and buses, creating a penetration picture of how far an attacker can penetrate the system. For example, the table 1100 under Tool 2 shows that the connection between Bus 1 and component B has the lowest score, which may indicate that the connection needs more preventative measures.
[0053] FIG. 11 is another example fault-tolerance table 1100. The fault-tolerance table 1100 may be generated by the fault-tolerance analysis engine 136 as shown in FIG. 1. Accordingly, in some examples, reference is made to FIGS. 1, 8, and 10 in the example of FIG. 11. For example, reference is made to FIG. 10 with respect to FIG. 11 for how fault-tolerance scores such as those shown in FIG. 11 may be calculated. The fault-tolerance table 1100 may be provided as part of the fault-tolerance data 142 and thus may be rendered on the output device 116. The fault-tolerance table 1100 includes a fault-tolerance score for each connection of the platform. For example, the fault-tolerance table 1100 includes a respective fault-tolerance score for each of the connections 810, 812, 814, 816, and 818. In some instances, the fault tolerance analysis engine 136 may use first and second tools 138 and 140 to calculate a fault tolerance score for each of the connections 810 , 812 , 814 , 816 , 818 .
[0054] In the example of FIG. 11 , a first column (labeled “Tool 1”) may include a fault-tolerance score calculated by the first tool 138, and a second column (labeled “Tool 2”) may include a fault-tolerance score calculated by the second tool 140. Each fault-tolerance score in the fault-tolerance table 1100 may indicate whether the respective connection will withstand a potential cyber-attack. As an example, connection 814 may have a low fault-tolerance score and indicate that the connection needs an update of cybersecurity vulnerabilities (e.g., by using encryption), thus allowing the overall cybersecurity performance of the platform to be improved. As an example, connection 814 may be a physical wire and a protocol for passing through connection 814. For example, a user may modify the target architecture of the platform, and the system and method may process the modified target architecture to calculate a new fault-tolerance table 1100 and determine whether the fault-tolerance score for connection 814 has increased corresponding to the improvement in the cybersecurity of connection 814. As an example, connection 814 may be modified to include encryption, thereby making it more difficult to attack.
[0055] FIG. 12 is a graphical representation of an example architecture model 1200 after evaluation by the fault-tolerance analysis engine 136, as shown in FIG. 1. Accordingly, in some examples, reference is made to FIGS. 1-11 in the example of FIG. 12. The graphical representation of the architecture model 1200 may be rendered by the GUI generator 144 based on the fault-tolerance data 142 and the architecture model 132. The architecture model 1200 may be the architecture model 800, as shown in FIG. 8, and therefore, similar reference numbers are used in FIG. 12. The graphical representation of the architecture model 1200 may be visualized on the output device 116. The graphical representation of the architecture model 1200 may include entry points 1202 for a potential cyber-attack and may indicate at 1204 (e.g., by shading the part 804) that the cyber-attack has successfully attacked or compromised the part 804. In the example of FIG. 12, the part 804 is the target of the cyber-attack.
[0056] FIG. 13 is a graphical representation of an example architecture model 1300 after evaluation by the fault-tolerance analysis engine 136 as shown in FIG. 1. Accordingly, in some examples, reference is made to FIGS. 1-11 in the example of FIG. 13. The graphical representation of the architecture model 1300 may be rendered by the GUI generator 144 based on the fault-tolerance data 142 and the architecture model 132. The architecture model 1300 may be the architecture model 800 as shown in FIG. 8, and therefore, similar reference numbers are used in FIG. 13. The graphical representation of the architecture model 1200 may be visualized on the output device 116. The graphical representation of the architecture model 1300 may include entry points 1302 for a potential cyber-attack and may indicate at 1304 (e.g., by shading the part 804) that the cyber-attack successfully attacked or compromised the part 804. In the example of FIG. 13, the part 804 is the target of the cyber-attack. As a further example, the graphical representation of the architecture model 1300 may include, at 1306 and 1308, a representation of the vectors of potential cyber-attacks, thus identifying the components and connections most vulnerable to potential cyber-attacks.
[0057] FIG. 14 is another graphical representation of an example of an architecture model 1400 after evaluation by the fault-tolerance analysis engine 136 shown in FIG. 1 . Accordingly, in some examples, reference may be made to FIGS. 1-11 in the example of FIG. 14 . The architecture model 1400 may represent a target architecture of an aircraft system, as described herein with respect to a given example. Accordingly, in some examples, a graphical representation of the architecture model 1400 may be rendered by the GUI generator 144 based on the fault-tolerance data 142 and the architecture model 132. In the example of FIG. 14 , the graphical representation of the architecture model 1400 may identify intrusion points into the aircraft system, such as WiFi 1402, Bluetooth 1404, USB media 1406, and test equipment 1408. The intrusion points may be exploited by unauthorized parties to gain access to targets in the aircraft system. In the example of FIG. 14 , the targets are a braking system 1410, a steering control system 1412, and an engine control system 1414.
[0058] In the example of FIG. 14 , an unauthorized user may utilize intrusion point 1402 to access internal modem 1416 and use modem 1416 to access one of targets 1410, 1412, 1414 over communications network 1418. Communications network 1418 may include a CAN bus. In some instances, an unauthorized user may utilize intrusion point 1404 or 1406 to access radio 1420 and use radio 1420 to access one of targets 1410, 1412, 1414 over communications network 1418. In some instances, an unauthorized user may utilize intrusion point 1408 to access OBD connector 1422 and use OBD connector 1422 to access one of targets 1410, 1412, 1414 over communications network 1418. In the example of FIG. 14 , cyber attack vectors 1424, 1426, 1428 are identified for one or more potential cyber attack vectors. One or more potential cyber-attack vectors 1424, 1426, 1428 may be identified by the fault tolerance analysis engine 136 in the same or similar manner as described herein. A user may use the graphical representation of the architecture model 1400 to identify possible cyber-attack vectors for a potential cyber-attack and use such vectors to update the target architecture of the platform to mitigate or eliminate the ability of unauthorized users to exploit such vectors within the platform based on the target architecture. For example, a user may update the target architecture of the aircraft system to eliminate at least one potential cyber-attack vector 1424, 1426, 1428 by updating the security of the internal modem 1416 and radio 1420.
[0059] FIG. 15 is another graphical representation of an example of an architecture model 1500 after evaluation by the fault-tolerance analysis engine 136 shown in FIG. 1 . Accordingly, in some examples, reference may be made to FIGS. 1-11 in the example of FIG. 15 . The architecture model 1500 may represent a target architecture of an aircraft system, as described herein with respect to a given example. Accordingly, in some examples, a graphical representation of the architecture model 1500 may be rendered by the GUI generator 144 based on the fault-tolerance data 142 and the architecture model 132. In the example of FIG. 15 , the graphical representation of the architecture model 1500 may identify intrusion points into the aircraft system, such as WiFi 1502, Bluetooth 1504, USB media 1506, and test equipment 1508. The intrusion points may be exploited by unauthorized parties to gain access to targets in the aircraft system. In the example of FIG. 15 , the targets are a braking system 1510, a steering control system 1512, and an engine control system 1514.
[0060] In the example of FIG. 15 , an unauthorized user may utilize intrusion point 1502 to access internal modem 1516 and use modem 1516 to access one of targets 1510, 1512, 1514 over communications network 1518. The communications network may include a CAN bus. In some instances, an unauthorized user may utilize intrusion point 1504 or 1506 to access radio 1520 and use radio 1520 to access one of targets 1510, 1512, 1514 over communications network 1518. In some instances, an unauthorized user may utilize intrusion point 1508 to access OBD connector 1522 and use OBD connector 1522 to access one of targets 1510, 1512, 1514 over communications network 1518. The architecture model 1500 may be generated based on a Markov model and may identify transition probabilities (e.g., the probability that an unauthorized user will use such a connection or passage) and attack success probabilities (e.g., indicating whether such an attack will be successful). In the example of FIG. 15 , the architecture model 1500 may include or identify best moves 1524 and 1526 for an attacker to attack the target and a worst-case attack scenario 1528. A user may use the graphical representation of the architecture model 1500 to update the target architecture of the platform to mitigate or eliminate the ability of an unauthorized user to exploit a particular passage within the platform based on the target architecture. For example, a user may update the target architecture of an aircraft system to eliminate the worst-case attack scenario 1528 by updating the security of the internal modem 1516.
[0061] With the structural and functional features described above in mind, the exemplary method will be better understood with reference to Figures 16-17. For ease of explanation, the exemplary method of Figures 16-17 is shown and described as being performed sequentially; however, it should be understood and appreciated that the present example is not limited by the order shown, as in other examples, some operations may be performed multiple times and / or simultaneously in an order different from that shown and described herein. Furthermore, not all illustrated operations need to be performed to implement the method.
[0062] FIG. 16 illustrates an example method 1600 for assessing a platform for cyber-threat vulnerabilities. Method 1600 may be implemented by a computing platform 102 such as that shown in FIG. 1. Accordingly, in some examples, reference is made to FIG. 1 in the example of FIG. 16. Method 1600 may begin at 1602 by generating (e.g., using platform description generator 108 as shown in FIG. 1 ) a part property table (e.g., part property table 110 as shown in FIG. 1 ) that identifies part properties for each of one or more parts of the platform based on part survey data (e.g., user input data received at input device 118 as shown in FIG. 1 ). The property table may include a respective binary value and weight value associated with one of the one or more parts. At 1604, generating (e.g., using platform description generator 108 as shown in FIG. 1 ) a connection property table (e.g., connection property table 112 as shown in FIG. 1 ) that identifies connection properties for each of one or more connections of the platform based on connection survey data (e.g., user input data received at input device 118). The connection property table may include a respective binary value and weight value associated with one of the one or more connections.
[0063] At 1606, a part score for each part of the platform is calculated (e.g., using the component analyzer 120 as shown in FIG. 1 ) based on the respective binary values and weight values of each of the one or more parts from the part property table. At 1608, a connection score for each connection of the platform is calculated based on the respective binary values and weight values of each of the one or more connections from the connection property table. At 1610, a probabilistic model (e.g., the probabilistic model 134 as shown in FIG. 1 ) is calculated (e.g., using the architecture modeling engine 124 as shown in FIG. 1 ) based on the part scores and connection scores and the architecture model (e.g., the architecture model 132 as shown in FIG. 1 ). The probabilistic model may include part probability values and connection probability values, and the architecture model may characterize the target architecture of the platform.
[0064] At 612, the probabilistic model and the architecture model are evaluated to determine (e.g., using the fault-tolerance analysis engine 136 as shown in FIG. 1 ) a likelihood that one or more potential cyber-attacks against the platform based on the target architecture will be successful or unsuccessful in compromising at least a portion of the platform. In some examples, method 1600 may include, at 1614, causing an output device to display fault-tolerance data characterizing the likelihood that one or more potential cyber-attacks against the platform based on the target architecture will be successful or unsuccessful. In some cases, method 1600 may include generating a bus property table and providing a bus score in the same or similar manner as described herein. The bus score may be used by the architecture modeling engine to calculate a probabilistic model in the same or similar manner as described herein.
[0065] FIG. 17 is another example method 1700 for assessing a platform for cyber-threat vulnerabilities. Method 1700 may be performed by computing platform 102 such as that shown in FIG. 1. Accordingly, in some examples, reference is made to FIG. 1 in the example of FIG. 17. Method 1700 may begin at 1702 by calculating an individual part score and an individual connection score for each part and each connection of the platform (e.g., using component analyzer 120 as shown in FIG. 1). At 1704, based on the individual part scores and individual connection scores, a probabilistic model (e.g., probabilistic model 134 as shown in FIG. 1) including part probability values and connection probability values for corresponding parts and connections of the platform is calculated (e.g., using architecture modeling engine 124 as shown in FIG. 1).
[0066] At 1706, based on architecture description data (e.g., architecture description data 128 as shown in FIG. 1 ) characterizing the target architecture of the platform and the entry condition data and the exit condition data, an architecture model (e.g., architecture model 132 as shown in FIG. 1 ) having entry conditions and exit conditions indicating where at least one potential cyber-attack may begin and end, respectively, with respect to the platform is provided (e.g., using architecture modeling engine 124 as shown in FIG. 1 ). At 1708, the probabilistic model and the architecture model are evaluated (e.g., using fault-tolerance analysis engine 136 as shown in FIG. 1 ) to determine a likelihood that the one or more potential cyber-attacks will be successful or unsuccessful in compromising at least a portion of the platform. In some examples, method 1700 may include, at 1710, causing an output device to display the fault-tolerance data characterizing the likelihood that the one or more potential cyber-attacks against the platform based on the target architecture will be successful or unsuccessful. In some cases, method 1700 may include calculating a bus score for each bus of the platform in the same or similar manner as described herein, wherein the probabilistic model is calculated based on the bus scores.
[0067] Examples herein may be implemented on virtually any type of computing system, regardless of the platform used. For example, the computing system may be one or more mobile devices (e.g., laptop computers, smartphones, personal digital assistants, tablet computers, or other mobile devices), desktop computers, servers, blades in a server chassis, or any other type of computing device that includes at least the minimum processing power, memory, and input and output device(s) for performing one or more embodiments. As shown in FIG. 18 , computing system 1800 may include a computer processor 1802, memory 1804 (e.g., RAM, cache memory, flash memory, etc.), one or more storage devices 1806 (e.g., solid-state drives, hard disk drives, optical drives (e.g., compact disc (CD) drives or digital versatile disc (DVD) drives), flash memory sticks, etc.), and numerous other elements and functionality. Computer processor 1802 may be an integrated circuit for processing instructions. For example, computer processor 1802 may be one or more cores or micro-cores of a processor. Components of computing system 1800 may communicate via a data bus 1808.
[0068] Computing system 1800 may also include input device(s) 1810, such as any combination of one or more of a touchscreen, keyboard, mouse, microphone, touchpad, electronic pen, or any other input device. Input device(s) 1810 may be input device(s) 118 as shown in FIG. 1. Additionally, computing system 1800 may include output device(s) 1812, such as one or more of a screen (e.g., a light-emitting diode (LED) display, an organic light-emitting diode (OLED) display, a liquid crystal display (LCD), a plasma display, a touchscreen, a cathode ray tube (CRT) monitor, a projector, or other display device), a printer, external storage, or any other output device. Output device(s) 1812 may be output device(s) 116 as shown in FIG. 1.
[0069] In some examples, the output device(s) 1812, such as a touchscreen, may be the same physical device as the input device(s) 1810. In other examples, the output device(s) 1812 and the input device(s) 1810 may be implemented as separate physical devices. The computing system 1800 may be coupled to a network 1814 (e.g., a local area network (LAN), a wide area network (WAN) such as the Internet, a mobile network, or any other type of network) via a network interface (not shown). The input device(s) 1810 and the output device(s) 1818 may be coupled to the computer processor 1802, the memory 1804, and / or the storage device(s) 1806 locally and / or remotely (e.g., via the network 1814). Many different types of computing systems exist, and the input device(s) 1810 and the output device(s) 1812 may take other forms.
[0070] Software instructions in the form of computer-readable program code for implementing the embodiments disclosed herein may be stored, in whole or in part, temporarily or permanently, on a non-transitory computer-readable medium such as a CD, DVD, storage device, diskette, tape, flash memory, physical memory, or any other computer-readable storage medium. Specifically, the software instructions may correspond to computer-readable program code configured to perform the operations disclosed herein when executed by a processor. The computing system 1800 may communicate with a server 1816 via a network 1814. The memory 1804 may include multiple applications and / or modules that may be employed to implement target architecture analysis techniques as described herein. More specifically, the memory 1804 may include a component analyzer 1818 (e.g., such as the component analyzer 120 or 200 described herein), an architecture modeling engine 1820 (e.g., such as the architecture modeling engine 124 or 300 described herein), a fault tolerance analysis engine 1822 (e.g., such as the fault tolerance analysis engine 136 described herein), and a GUI generator 1826 (e.g., such as the GUI generator 144 described herein).
[0071] Additionally, one or more elements of computing system 1800 may be located remotely and coupled to other elements via network 1814. Additionally, some examples may be implemented on a distributed system having multiple nodes, with portions of the embodiments being located on different nodes within the distributed system. In one example, the nodes in the example of FIG. 18 correspond to separate computing devices. Alternatively, the nodes may correspond to computer processors with associated physical memory. Alternatively, the nodes may correspond to computer processors or micro-cores of computer processors with shared memory and / or resources.
[0072] The above description is illustrative. Of course, it is not possible to describe every conceivable combination of elements or methodologies, but one skilled in the art will recognize that many more combinations and permutations are possible. Accordingly, this disclosure is intended to embrace all such changes, modifications, and variations that are within the scope of this application, including the appended claims. As used herein, the term "comprising" means including without limitation. The term "based on" means based at least in part on. Furthermore, when this disclosure or claims recite "a," "first," or "another" element, or equivalents thereof, it should be construed as including one or more such elements, and does not require or exclude more than one element. The technical concepts that can be understood from the above-described embodiment will be described below as supplementary notes. [Appendix 1] 1. A system comprising: a memory for storing machine-readable instructions, a part property table for one or more parts of a platform, and a connection property table for one or more connections of said platform; one or more processors for accessing the memory and executing the machine-readable instructions, the machine-readable instructions comprising: 1. A component analyzer comprising: an individual part score for each part of the platform based on the part property table; and the component analyzer is programmed to calculate an individual connection score for each connection of the platform based on the connection property table; and the component analyzer is programmed to provide the individual part scores and the individual connection scores as score data; an architecture modeling engine programmed to calculate a probabilistic model based on the score data and an architecture model, the probabilistic model including part probability values and connection probability values, the architecture model characterizing a target architecture of the platform; and a fault tolerance analysis engine programmed to evaluate the probabilistic model and the architecture model to determine the likelihood that one or more potential cyber attacks against the platform based on the target architecture will be successful or unsuccessful in compromising at least a portion of the platform. [Appendix 2] 10. The system of claim 1, wherein the resilience analysis engine is programmed to generate resilience data that records the frequency with which each component and each connection is used in the one or more potential cyber-attacks. [Appendix 3] 10. The system of claim 1, wherein the resilience data is used to modify the target architecture of the platform to eliminate or mitigate one or more cyber-attack vectors, and the platform implemented based on the modified target architecture exhibits improved cybersecurity as opposed to the platform based on the target architecture. [Appendix 4] the individual component score indicating the cyber resilience of the individual component of the one or more components of the platform to withstand the one or more potential cyber attacks against the platform based on the target architecture for the platform; 10. The system of claim 1, wherein the individual connection score indicates a likelihood that an individual connection of the one or more connections of the platform will be used during the one or more potential cyber-attacks against the platform based on the target architecture for the platform. [Appendix 5] The component analyzer an associated binary value and weight value in the part property table for each part of the one or more parts of the platform for calculating the individual part score; 5. The system of claim 4, programmed to process an associated binary value and weight value in the connection property table for each connection of the one or more connections of the platform to calculate the individual connection score. [Appendix 6] 6. The system of claim 5, wherein the component analyzer includes a score calculator for calculating each individual component score and each individual connection score based on the associated binary values and weight values in corresponding component property tables and connection property tables. [Appendix 7] 7. The system of claim 6, wherein the weight value assigned to each of part properties and connection properties associated with a respective one of the one or more parts and one or more connections has one of a positive or negative magnitude, the weight value having a positive magnitude based on a positive characteristic of the respective one of the one or more parts and one or more connections, and the weight value having a negative magnitude based on a negative characteristic of the respective one of the one or more parts and one or more connections. [Appendix 8] 8. The system of claim 7, wherein the part property table includes general part properties, source properties, and target properties, and the component analyzer is programmed to analyze the part property table and output a partitioned part property table including the source properties and the target properties to provide the architecture model. [Appendix 9] The machine-readable instructions further include a platform description generator, the platform description generator: causing an output device to render a respective part lookup and connection lookup on said output device, wherein in response to rendering a respective one of the parts and connections, the lookup on said output device receives respective part lookup data and connection lookup data based on user input at an input device; providing the part property table identifying individual part properties for the one or more parts of the platform based on the part survey data; 9. The system of claim 8, programmed to provide the connection property table, which identifies individual connection properties for the one or more connections of the platform based on the connection investigation data. [Appendix 10] 10. The system of claim 9, wherein the architecture modeling engine includes an architecture modeling module programmed to provide the architecture model with entry and exit conditions indicating where the one or more potential cyber-attacks start and end, respectively, against the platform. [Appendix 11] 11. The system of claim 10, wherein the architecture modeling engine includes a probability calculator programmed to provide part and component probability values based on individual part and component scores. [Appendix 12] 12. The system of claim 11, wherein the fault tolerance analysis engine includes a first analysis tool programmed to calculate a component contribution probability value for each component of the one or more platform of components, the component contribution probability value indicative of an individual component contribution to the one or more potential cyber-attacks. [Appendix 13] 13. The system of claim 12, wherein the fault-tolerance analysis engine includes a second analysis tool programmed to simulate the one or more potential cyber-attacks through the architecture model and record a frequency with which each component and each connection is used in the one or more potential cyber-attacks. [Appendix 14] 1. A computer-implemented method comprising: generating a part property table based on the part survey data that identifies individual part properties for one or more parts of the platform, the part property table including individual binary values and weight values associated with one of the one or more parts; generating a connection property table based on the connection interrogation data to identify individual connection properties for one or more connections of the platform, the connection property table including individual binary values and weight values associated with one of the one or more connections; calculating a part score for each part of the platform based on the individual binary values and weight values for the individual parts of the one or more parts from the part property table; calculating a connection score for each connection of the platform based on the individual binary values and weight values for the individual connections of the one or more connections from the connection property table; calculating a probabilistic model based on the component scores and the connection scores and an architecture model, the probabilistic model including component probability values and connection probability values, the architecture model characterizing a target architecture of the platform; evaluating the probabilistic model and the architecture model to determine the likelihood that one or more potential cyber-attacks against the platform based on the target architecture will be successful or unsuccessful in compromising at least a portion of the platform. [Appendix 15] 15. The computer-implemented method of claim 14, comprising generating fault-tolerance data that records the frequency with which each component and each connection is used in the one or more potential cyber-attacks. [Appendix 16] 16. The computer-implemented method of claim 15, comprising modifying the target architecture of the platform to remove or eliminate one or more cyber-attack vectors, such that the platform implemented based on the modified target architecture exhibits improved cybersecurity as opposed to the platform based on the target architecture. [Appendix 17] 17. The computer-implemented method of claim 16, further comprising: causing an output device to render individual component surveys and connection surveys on the output device; and receiving the component survey data and the connection survey data based on user input at an input device in response to rendering the individual one of the component surveys and the connection surveys on the output device. [Appendix 18] A non-transitory machine-readable medium having machine-readable instructions, the machine-readable instructions comprising: a component analyzer including a score calculator programmed to calculate an individual component score and an individual connection score for each component and each connection of the platform; 1. An architecture modeling engine, comprising: a probability score calculator programmed to calculate a probabilistic model including part probability values and connection probability values for corresponding parts and connections of the platform based on the individual part scores and the individual connection scores; the architecture modeling engine including: an architecture modeling module programmed to provide an architecture model with start conditions and end conditions indicating where at least one potential cyber-attack begins and ends, respectively, with respect to the platform, based on architecture description data characterizing a target architecture of the platform and start condition data and end condition data; a fault tolerance analysis engine programmed to evaluate the probabilistic model and the architectural model to determine the likelihood that one or more potential cyber-attacks will be successful or unsuccessful in compromising at least a portion of the platform. [Appendix 19] 19. The non-transitory machine-readable medium of Claim 18, wherein the fault-tolerance analysis engine is programmed to generate fault-tolerance data that records the frequency with which each component and each connection is used in the one or more potential cyber-attacks. [Appendix 20] 20. The non-transitory machine-readable medium of Claim 19, wherein the fault-tolerance data is used to modify the target architecture of the platform to eliminate or mitigate one or more cyber-attack vectors such that the platform implemented based on the modified target architecture exhibits improved cybersecurity as opposed to the platform based on the target architecture.
Claims
1. 1. A system comprising: a memory for storing machine-readable instructions, a part property table for one or more parts of a platform, and a connection property table for one or more connections of said platform; one or more processors for accessing the memory and executing the machine-readable instructions, the machine-readable instructions comprising:
1. A component analyzer comprising: an individual part score for each part of the platform based on the part property table; and the component analyzer is programmed to calculate an individual connection score for each connection of the platform based on the connection property table; and the component analyzer is programmed to provide the individual part scores and the individual connection scores as score data; an architecture modeling engine programmed to calculate a probabilistic model based on the score data and an architecture model, the probabilistic model including part probability values and connection probability values, the architecture model characterizing a target architecture of the platform; and a fault tolerance analysis engine programmed to evaluate the probabilistic model and the architecture model to determine the likelihood that one or more potential cyber attacks against the platform based on the target architecture will be successful or unsuccessful in compromising at least a portion of the platform.
2. 10. The system of claim 1, wherein the fault-tolerance analysis engine is programmed to generate fault-tolerance data that records how frequently each component and each connection is used in the one or more potential cyber-attacks.
3. 10. The system of claim 1, wherein fault tolerance data is used to modify the target architecture of the platform to eliminate or mitigate one or more cyber attack vectors, and wherein the platform implemented based on the modified target architecture exhibits improved cybersecurity as opposed to the platform based on the target architecture.
4. the individual component score indicating the cyber resilience of an individual component of the one or more components of the platform to withstand the one or more potential cyber attacks against the platform based on the target architecture for the platform; 2. The system of claim 1, wherein the individual connection score indicates a likelihood that an individual connection of the one or more connections of the platform will be used during the one or more potential cyber-attacks against the platform based on the target architecture for the platform.
5. The component analyzer an associated binary value and weight value in the part property table for each part of the one or more parts of the platform for calculating the individual part score; and an associated binary value and weight value in the connection property table for each connection of the one or more connections of the platform to calculate the individual connection score.
6. 6. The system of claim 5, wherein the component analyzer includes a score calculator for calculating each individual component score and each individual connection score based on the associated binary and weight values in corresponding component property tables and connection property tables.
7. 7. The system of claim 6, wherein the weight value assigned to each of part properties and connection properties associated with a respective one of the one or more parts and one or more connections has one of a positive or negative magnitude, the weight value having a positive magnitude based on a positive characteristic of the respective one of the one or more parts and one or more connections, and the weight value having a negative magnitude based on a negative characteristic of the respective one of the one or more parts and one or more connections.
8. 8. The system of claim 7, wherein the part property table includes general part properties, source properties, and target properties, and the component analyzer is programmed to analyze the part property table and output a partitioned part property table including the source properties and the target properties for providing the architecture model.
9. The machine-readable instructions further include a platform description generator, the platform description generator: causing an output device to render a respective component lookup and a connection lookup on said output device, wherein in response to rendering a respective one of the component and connection lookups, said lookup on said output device receives respective component lookup data and connection lookup data based on user input at an input device; providing the part property table identifying individual part properties for the one or more parts of the platform based on the part survey data; The system of claim 8 , programmed to provide the connection property table, based on the connection probing data, that identifies individual connection properties for the one or more connections of the platform.
10. 10. The system of claim 9, wherein the architecture modeling engine includes an architecture modeling module programmed to provide the architecture model with entry and exit conditions that indicate where the one or more potential cyber-attacks start and end, respectively, against the platform.
11. The system of claim 10 , wherein the architecture modeling engine includes a probability calculator programmed to provide part and connection probability values based on individual part and connection scores.
12. 12. The system of claim 11, wherein the fault tolerance analysis engine includes a first analysis tool programmed to calculate a component contribution probability value for each component of the one or more platform of components, the component contribution probability value indicative of an individual component contribution to the one or more potential cyber-attacks.
13. 13. The system of claim 12, wherein the fault-tolerance analysis engine includes a second analysis tool programmed to simulate the one or more potential cyber-attacks through the architecture model and record the frequency with which each component and each connection is used in the one or more potential cyber-attacks.
14. 1. A computer-implemented method comprising: generating a part property table based on the part survey data that identifies individual part properties for one or more parts of the platform, the part property table including individual binary values and weight values associated with one of the one or more parts; generating a connection property table based on the connection interrogation data to identify individual connection properties for one or more connections of the platform, the connection property table including individual binary values and weight values associated with one of the one or more connections; calculating a part score for each part of the platform based on the individual binary values and weight values for the individual parts of the one or more parts from the part property table; calculating a connection score for each connection of the platform based on the individual binary values and weight values for the individual connections of the one or more connections from the connection property table; calculating a probabilistic model based on the component scores and the connection scores and an architecture model, the probabilistic model including component probability values and connection probability values, the architecture model characterizing a target architecture of the platform; and evaluating the probabilistic model and the architecture model to determine the likelihood that one or more potential cyber-attacks against the platform based on the target architecture will be successful or unsuccessful in compromising at least a portion of the platform.
15. 15. The computer-implemented method of claim 14, comprising generating fault tolerance data that records how frequently each component and each connection is used in the one or more potential cyber-attacks.
Citation Information
Patent Citations
Risk evaluation system and risk evaluation method
JP2016143299A
Risk evaluation system and risk evaluation method
JP2022002057A
Adaptive enterprise risk evaluation
US20200311630A1