System and method for detection and mitigation of cybersecurity vulnerabilities and wireless cybersecurity threats
Patent Information
- Application Number
- PCT/IB2026/052930
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-27
- Filing Date
- 2026-03-26
- Publication Date
- 2026-10-01
Smart Images

Figure IB2026052930_01102026_PF_FP_ABST
Abstract
Description
[0001] SYSTEM AND METHOD FOR DETECTION AND MITIGATION OF CYBERSECURITY VULNERABILITIES AND WIRELESS CYBERSECURITY THREATS TECHNICAL FIELD
[0002] The present disclosure relates to cybersecurity and Unmanned Aerial Systems (UAS). Particularly, the present disclosure relates to securing Unmanned Aerial Systems (UAS) against wireless cybersecurity threats and attacks. More particularly, the present disclosure relates to the use of artificial intelligence (Al) and machine learning (ML)-based computer-executable cybersecurity frameworks to identify and mitigate the cybersecurity threats and attacks directed to Unmanned Aerial Vehicles (UAV), Ground Control Stations (GCS), and the Global Navigation Satellite System (GNSS).
[0003] BACKGROUND
[0004] Dual use aerospace systems, especially Unmanned Aerial Systems (UAS), and the allied control systems including the Ground Control Station (GCS) that monitors and controls the flight, landing, and operations of Unmanned Aerial Vehicles (UAV), and the wireless communication links between the Ground Control Station and Unmanned Aerial Vehicles are subject to a variety of cybersecurity attacks given a significant increase in their usefulness in a multitude of domains including logistics management, remote surveillance, and defense. With the increased use of Unmanned Aerial Vehicles in a multitude of fields, including defense, search & rescue operations, logistics, geographical mapping, precision agriculture, remote surveillance, and remote inspection, inter alia, the likelihood of UAVs and GCSs being targeted and sabotaged by cyberattacks has also increased. Such cyberattacks expose the UAV and the GCS, and by extension the UAS, to a variety of security risks that are likely to sabotage the operational capabilities and effectiveness of the UAVs and the GCS. Since the UAVs work entirely based on wireless communication and remote monitoring and control, with the operational nature of the UAVs rendering any other non-remote, wired command and control mechanisms moot, they (the UAVs) are much more susceptible to cybersecurity threats and attacks that could compromise their integrity, safety, functionality, operational efficiency, and effectiveness.
[0005] Cybersecurity for UAVs, GCS, and the UAS as a whole is particularly challenging due to their reliance on real-time wireless communication for control and data transmission, and the dearth of safer, equally effective alternatives to wireless control mechanisms.Typically, UAS are susceptible to a range of cyberattacks, including, but not limited to, cyber hijacking, eavesdropping, man-in-the-middle, GPS spoofing, denial of service, malware, ransomware, and jamming attacks, inter alia. Such cyberattacks can cause severe, often irreparable adverse effects, including unauthorized use of UAS for nefarious activities, prolonged disruption of UAS operations, and a significant decrease in UAS operational efficiency and effectiveness.
[0006] One of the most critical concerns when it comes to safeguarding the UAS against cyberattacks is the security and continued protection of the wireless communication bands and the underlying wireless communication channels on which UAVs are heavily, and in some cases entirely, reliant for communicating with and receiving commands from the Ground Control Station (GCS). Typically, UAVs make use of a variety of wireless communication methods, including Wi-Fi, mobile networks (4G / 5G), and specialized radio frequencies. Each of these wireless communication channels and the corresponding wireless communication bands have unique vulnerabilities, ranging from limited Wi-Fi security to potential interception risks in mobile networks. Additionally, UAVs must operate in real-time, dynamic environments, often encountering unpredictable factors such as signal interference, physical obstacles, and communication delays, further complicating the implementation of security systems for these wireless communication methods.
[0007] Further, UAS are also plagued by software vulnerabilities that typically metamorphosize significant security threats. Such software vulnerabilities include buffer overflows, injection of malicious program codes, and unpatched bugs, inter alia. In addition, malicious hardware components, such as inertial measurement units (IMUs) and electronic speed controllers (ESCs), introduced through the supply chain or at the point of manufacturing, could introduce security vulnerabilities that attackers could exploit to gain control of the UAV. Furthermore, human error, insider threats, and inadequate training typically create additional security gaps in the operations of UAVs.
[0008] Several attempts have been made to resolve the security vulnerabilities associated with UAV operations. In addition, several attempts have been made to enhance the overall security of Unmanned Aerial Systems and to thwart cybersecurity attacks targeting UAVs and their operations. One such attempt, a part of the prior art, involves the use of secured hardware components such as Trusted Platform Modules (TPMs), Hardware Security Modules (HSM), and Physically Unclonable Functions (PUFs) to facilitate isolated, thus secured, enclaves for cryptographic key generation and storage, with the cryptographickeys being used to encrypt the wireless communication band established between the UAV and the GCS, and the corresponding communication channel. However, a prominent drawback of this hardware-based approach is the reliance on the availability and installation of secure hardware. Yet another approach, also part of the prior art, involves using Controlled Reception Pattern Antennas (CRPA) on the UAVs to block interference signals and allow only high-gain signals to reach the intended destinations, i.e., the satellites. However, this approach also relies heavily on the availability, installation, and use of specialized hardware, such as the Controlled Reception Pattern Antennas.
[0009] Therefore, in view of the drawbacks discussed hitherto, there was a need for a cybersecurity system that addresses a wide range of wireless and cybersecurity threats solely through software and application-layer-driven methodologies. There was a need for a security solution purpose-built to address the cybersecurity challenges prevalent in UAV operations. There was also a need for a security solution that specifically and diligently addressed wireless and cyber vulnerabilities that traditional enterprise security solutions are unable to address effectively.
[0010] OBJECTS
[0011] The principal objective of the present disclosure is to enhance the security and integrity of Unmanned Aerial Systems, including Unmanned Aerial Vehicles (UAVs), Ground Control Station (GCS), and Global Navigation Satellite System (GNSS), and the wireless communication bands and channels that interconnect the UAVs, GCS, and GNSS, through a dedicated cybersecurity system and method.
[0012] Yet another object of the present disclosure is to envisage a cybersecurity system and method that accurately identifies and mitigates a wide range of cybersecurity threats, including unauthorized access, unauthorized data interception and manipulation, and communication disruptions, by utilizing advanced encryption, authentication, and antijamming technologies.
[0013] Another object of the present disclosure is to envisage a cybersecurity system and method that facilitates a secure, reliable, and resilient wireless communication between Unmanned Aerial Vehicles (UAVs), the Ground Control Stations (GCS), and the Global Navigation Satellite System (GNSS), and renders the underlying wireless communication bands and channels immune to cybersecurity attacks.Another object of the present disclosure is to envisage a cybersecurity system and method that protects operations of UAVs from malicious attacks, safeguards sensitive command and control data, and ensures continuous and efficient functioning of the subcomponents of the UAVs.
[0014] Another object of the present disclosure is to envisage a cybersecurity system and method that enhances the cybersecurity of Ground Control Stations (GCS) by safeguarding critical Ground Control Station components from cybersecurity vulnerabilities and cybersecurity attacks.
[0015] Another object of the present disclosure is to envisage a cybersecurity system and method that secures the wireless network infrastructure critical for the functioning of UAVs and protects the wireless network infrastructure from unauthorized and malicious activities.
[0016] Yet another object of the present disclosure is to envisage a cybersecurity system and method that leverages a cloud-based machine learning solution to analyze wireless link packets (data packets) to identify and subsequently prevent cybersecurity attacks.
[0017] Another object of the present disclosure is to envisage a cybersecurity system and method that detects and mitigates a wide variety of cybersecurity attacks, including man-in-the-middle attack, GPS spoofing attack, denial of service attack, signal jamming attack, and eavesdropping attack inter alia, and ensures robust protection for UAV operations. Yet another object of the present disclosure is to envisage a cybersecurity system and method that utilizes standardized, robust cryptographic protocols to secure wireless communications and the data exchanged between the UAVs and the GCS.
[0018] Another object of the present disclosure is to envisage a cybersecurity system and method that offers an improvement in terms of identifying and mitigating cybersecurity threats and attacks, over standardized encryption protocols and message-signaling applications used in well-known enterprise security solutions.
[0019] Another object of the present disclosure is to envisage a cybersecurity system and method that functions independent of trusted, secured hardware components such as Trusted Platform Modules (TPM) and Controlled Reception Pattern Antennas (CRPA) by utilizing advanced cybersecurity algorithms.SUMMARY
[0020] The present disclosure envisages a computer-implemented system and method for realtime detection and mitigation of cybersecurity vulnerabilities found in Unmanned Aerial Systems (UAS), including Unmanned Aerial Vehicles (UAV), Ground Control Stations (GCS), and the Global Navigation Satellite System (GNSS). The computer-implemented system and method also facilitate a real-time detection and mitigation of cybersecurity attacks and cybersecurity threats directed at Unmanned Aerial Systems. The computer-implemented system and method programmatically acquire, in real-time, pre-flight information corresponding to an Unmanned Aerial Vehicle and the ground station control unit controlling the Unmanned Aerial Vehicle. The pre-flight information includes, for example, the version of the operating systems used in the Ground Control Station, the channel and the bandwidth used by the Ground Control Station to communicate with the Unmanned Aerial Vehicle, and the encryption standards used by the Ground Control Station to communicate with the Unmanned Aerial Vehicle.
[0021] Subsequently, the pre-flight information is processed using a predetermined statistical and mathematical model, for example, a Gaussian fitting function. Alternatively, the computer-implemented system and method could also use the least squares method, neural networks, support vector machines, or Bayesian approximation to process the preflight information. Preferably, the computer-implemented system and method automatically fit the mathematical function (for example, the Gaussian fitting function) to real-time data distribution, viz., the arrangement, spread, and frequency of values representative of said pre-flight information. Further, the computer-implemented system and method recalibrate or adjust the mathematical function being used, based on the arrangement, spread, and frequency of values representative of said pre-flight information. Preferably, the mathematical function that fits the pre-flight information as closely as possible is utilized to process the pre-flight information and quantify the variables indicative of the pre-flight information. In accordance with the present disclosure, the variables indicative of the pre-flight information are Boolean indicators, for example, the presence of multi-factor authentication, the presence of strong encryption standards, and the presence of updated and secure operating systems.
[0022] In accordance with the present disclosure, the computer-implemented system and method also acquire in-flight information corresponding to the Unmanned Aerial Vehicle, in the form of data packets, and analyze the in-flight information embodied in the datapackets to identify at least one manipulation to the data packets. In response to determining a manipulation of the data packets, the computer-implemented system and method execute remedial actions that would, in turn, mitigate or diminish the security risks posed by the manipulation of the data packets. In accordance with the present disclosure, the computer-implemented system and method mitigate or diminish the security risks posed by a Global Positioning System (GPS) spoofing attack by navigating the Unmanned Aerial Vehicle to a corrected flight path determined based on historical, valid telemetry data, instead of the compromised and manipulated GPS data embodied in the data packets exchanged between said Unmanned Aerial Vehicle and Ground Control Station. Further, in response to identifying an eavesdropping attack on the Unmanned Aerial Vehicle or the Ground Control Station, the computer-implemented system and method will introduce dynamically modified error correction codes into the wireless communication band used by the Unmanned Aerial Vehicle and the Ground Control Station for communication.
[0023] In accordance with the present disclosure, in response to identifying a signal jamming attack on the Unmanned Aerial Vehicle, the computer-implemented system and method will trigger the Ground Control Station to switch from a first wireless communication band currently-in-use, to a predetermined second wireless communication band, in synchronism with the Unmanned Aerial Vehicle (UAV) (for example, from the first wireless communication band that has a frequency of 2.4 GHz to the second wireless communication band that has a frequency of 5.8 GHz). In addition, the computer-implemented system and method would also introduce dynamically generated error correction codes into the second wireless communication band, thus securing the second wireless communication band against the signal jamming attack.
[0024] In accordance with the present disclosure, on detecting the execution of either a denial of service attack or man-in-the-middle attack, or the eavesdropping attack, the computer-implemented system and method will introduce dynamically modified error correction codes into the currently-in-use first wireless communication band (and, in turn, the underlying wireless communication channel) interconnecting the Unmanned Aerial Vehicle and the Ground Control Station, to maximize the data throughput and the reliability of the wireless communication link (between the Unmanned Aerial Vehicle and the Ground Control Station). Preferably, the error correction codes are dynamically generated based on the real-time signal quality exhibited by the first wireless communication band.In accordance with the present disclosure, the computer-implemented method and system will dynamically change the encryption levels of the first wireless communication band utilized by the Unmanned Aerial Vehicle and the Ground Control Station, in response to detecting intentional and repetitive disruptions in the first wireless communication band, by automatically initiating a new encryption exchange protocol and without terminating the underlying wireless communication link. The change in the encryption levels of the first wireless communication band will be communicated synchronously to both the Unmanned Aerial Vehicle and the Ground Control Station to avoid any network latency. Additionally, the computer-implemented method and system will synchronously signal any change of the wireless communication band (for example, from the first wireless communication band having a frequency of 2.4 GHz to the second wireless communication band having a frequency of 5.8 GHz) to both the Unmanned Aerial Vehicle and the Ground Control Station, thereby reducing the network latency associated with switching both the Unmanned Aerial Vehicle and the Ground Control Station from the first wireless communication band to the second wireless communication band.
[0025] In accordance with the present disclosure, the computer-implemented system and method, as a first line of defense, initiate a frequency hopping spread spectrum (FHSS) protocol in response to identifying intentional and repetitive disruptions in the first wireless communication band, thereby rapidly switching between, for example, the first wireless communication band and the second wireless communication band in a pseudo-random sequence. Subsequently, the computer-implemented system and method will execute a machine learning (ML) model trained at least with a plurality of network quality metrics as training vectors to differentiate normal network interference from intentional and repetitive disruptions in the currently-in-use first wireless communication band.
[0026] In accordance with the present disclosure, the computer-implemented system and method will analyze the packet header, payload, and traffic pattern of the data packets exchanged between the Unmanned Aerial Vehicle and the Ground Control Station, and execute a second machine learning (ML) model trained with a plurality of network infrastructure-related metrics as training vectors, to identify a wireless network communication layer at which the data packets are manipulated. Likewise, based on the analysis of the packet header, the payload, and the traffic pattern, the computer-implemented system and method will execute a third machine learning (ML) model trained with a plurality of network behavior-related metrics as training vectors, to identify at leasta type of the cybersecurity attack executed on any of the Unmanned Aerial Vehicle, the Ground Control Station, and the first wireless communication band (interconnecting the Unmanned Aerial Vehicle and the Ground Control Station). Subsequently, the computer-implemented system and method will trigger the Ground Control Station and the Unmanned Aerial Vehicle to switch from the first wireless communication band currently in use to the second wireless communication band, based on the type of the cybersecurity attack (directed to the Unmanned Aerial Vehicle or the Ground Control Station, or the first wireless communication band) and the identification of the wireless network communication layer at which the data packets were determined to be manipulated. In accordance with the present disclosure, the computer-implemented system and method will analyze the header and payload of the data packets, network traffic passing through the first wireless communication band, characteristics of sessions executed using the first wireless communication band (that interconnects the UAV and the GCS), and execute a fourth machine learning (ML) model trained at least with a baseline of normal wireless network activity, signatures of known threats, signatures of malicious executables, signatures of malicious command and control communications, known characteristics of secured encrypted sessions, and signatures of secured packet flow characteristics, to detect, in real-time, the execution of a malware-based cybersecurity attack on any of the Unmanned Aerial Vehicle, the Ground Control Station, and the first wireless communication band.
[0027] In accordance with the present disclosure, the computer-implemented system and method will analyze the packet metadata stored in the packet header of the data packets, the payload of the data packets, the network traffic passing through the first wireless communication band, and file-sharing patterns across the first wireless communication band, and executes a fifth machine learning (ML) model trained at least with unusual file sharing patterns, data exfiltration signatures, and the signatures of malicious command and control communications, to identify at least one of high volume server message block (SMB) traffic on the first wireless communication band, rapid and repetitive file read / write operations performed via the first wireless communication band, encrypted payloads embodied in any of the data packets, unusual time delays between consecutive data packets, and unusual data packet lengths, and to thereby detect, in real-time, execution of a ransomware-based cybersecurity attack on any of the Unmanned Aerial Vehicle, the Ground Control Station, and the first wireless communication band.In accordance with the present disclosure, the computer-implemented system and method will receive the real-time telemetry data indicative of the Unmanned Aerial Vehicle’s real-time position, altitude, and acceleration, from an inertial measurement unit (IMU) embedded in the Unmanned Aerial Vehicle. The computer-implemented system and method will programmatically compare the Unmanned Aerial Vehicle’s real-time position, altitude, and acceleration with the GPS data embodied in the data packets exchanged between the Unmanned Aerial Vehicle and the Ground Control Station, and will classify the GPS data as manipulated GPS data, in case of a mismatch between the GPS data and the real-time telemetry data. Subsequently, the computer-implemented system and method will execute a sixth machine learning (ML) model trained at least with baseline values for maximum physical velocity exhibited by the Unmanned Aerial Vehicle at predetermined time intervals, change in the velocity of the Unmanned Aerial Vehicle in relation to a change in the acceleration of the Unmanned Aerial Vehicle, a number of satellites communicably coupled to the Unmanned Aerial Vehicle at each of the predetermined time intervals, camer-to-noise density ratio observed at each of the satellites communicably coupled to the Unmanned Aerial Vehicle, difference between a GPS receiver’s internal clock and GPS system time, horizontal dilution of precision (HDOP), and vertical dilution of precision (VDOP) as training vectors, to identify the data packets containing the manipulated GPS data, and to differentiate the data packets containing manipulated GPS data from the data packets containing authentic GPS data.
[0028] BRIEF DESCRIPTION OF THE ACCOMPANYING DRAWINGS
[0029] The features and functionalities of the computer-implemented system and method envisaged by the present disclosure are described with reference to the following figures. FIG.1 illustrates a network environment for the detection and mitigation of cybersecurity vulnerabilities and cybersecurity attacks in an Unmanned Aerial System (UAS), in accordance with the present disclosure;
[0030] FIG.2 is a block diagram illustrating the components of a computer-implemented system for detection and mitigation of cybersecurity vulnerabilities and cybersecurity attacks in an Unmanned Aerial System (UAS), in accordance with the present disclosure; and FIG.3 is a flowchart illustrating the steps involved in the computer-implemented method for detection and mitigation of cybersecurity vulnerabilities and cybersecurity attacks in an Unmanned Aerial System (UAS), in accordance with the present disclosure.DETAILED DESCRIPTION
[0031] In order to address the drawbacks and the disadvantages associated with the prior art, the present disclosure envisages a computer-implemented system and method for detecting and mitigating cybersecurity vulnerabilities in Unmanned Aerial Systems (UAS) that, in turn, include Unmanned Aerial Vehicles (UAV) controlled by Ground Control Stations (GCS) and guided by the Global Navigation Satellite System (GNSS). The present disclosure also envisages a computer-implemented system and method for detecting and mitigating cybersecurity threats and attacks in the Unmanned Aerial Vehicles, the Ground Control Stations, and the wireless communication bands and wireless communication channels interconnecting the Unmanned Aerial Vehicles and the Ground Control Stations.
[0032] The present disclosure primarily envisages a computer-implemented system and method for the detection and mitigation of cybersecurity vulnerabilities and cybersecurity threats in Unmanned Aerial Systems. The present disclosure also envisages a comprehensive security framework for Unmanned Aerial Systems, addressing four critical dimensions, viz., wireless communication security, collision avoidance, safe operations of Unmanned Aerial Vehicles, and cybersecurity of Ground Control Stations.
[0033] The present disclosure further envisages safeguarding the wireless communication links between the UAV and the GCS, thereby preventing unauthorized access, data interception, disruption of communication between the UAV and the GCS, and unauthorized use of data intended for the UAV and the GCS. The present disclosure also envisages securing the GCS from cyberattacks, protecting sensitive data, and safeguarding the wireless network infrastructure that interconnects the UAV and the GCS. To detect, thwart, or at least mitigate the cybersecurity attacks such as the man-in-the-middle attack and GPS spoofing attack, the present disclosure proposes a cloud-based machine learning model that analyses wireless data packets (exchanged between the UAV and the GCS through a wireless communication channel, which, in turn, is a part of a specific wireless communication band operating at a particular frequency) and identifies the underlying attack patterns, and offers real-time detection and mitigation of the cybersecurity attacks by undertaking requisite real-time remedial actions.
[0034] The present disclosure envisages detecting and mitigating a plurality of cybersecurity-related vulnerabilities embodied in the GCS, including but not restricted to Wi-Fi security-related vulnerabilities, password protection-related vulnerabilities, email security-related vulnerabilities, operating system-related vulnerabilities, multi-factor authentication-related vulnerabilities, data storage and security-related vulnerabilities, and cloud security-related vulnerabilities.
[0035] The present disclosure also envisages detecting and mitigating a plurality of cybersecurity attacks directed at sabotaging the operations of the UAV and the GCS, including but not restricted to GPS spoofing attack, GPS jamming attack, eavesdropping attacks, signal jamming attacks, denial of service attacks, man-in-the-middle attack, cyber hijacking attack, malware attack, and ransomware attack.
[0036] In accordance with the present disclosure, FIG.1 illustrates a network environment 100 for the detection and mitigation of cybersecurity vulnerabilities and cybersecurity attacks in Unmanned Aerial Systems (UAS). The term “Unmanned Aerial Systems”, as used in the present disclosure, refers to a communicable coupling between at least one Unmanned Aerial Vehicle 101, at least one Ground Control Station (GCS) 109, and the Global Navigation Satellite System (GNSS) 103, via the first wireless communication band 117 operating at a particular wireless communication frequency. The network environment 100 includes the Unmanned Aerial Vehicle 101 communicably coupled to the GCS 109, which, in turn, controls the operations of the UAV 101. The network environment 100 further includes a cloud-based server 111 that stores statistical and probabilistic models 112 and machine learning models 113 trained to detect and thwart, or at least mitigate, the cybersecurity vulnerabilities and cybersecurity attacks directed to the GCs 109 and UAV 101.
[0037] In accordance with the present disclosure, each of the plurality of machine learning models 113 can be trained to identify the onset of a specific type of cybersecurity attack. For example, while a first machine learning model 113 can be trained exclusively to detect the onset of a GPS spoofing attack, a second machine learning model 113 can be trained exclusively to identify the onset of man-in-the-middle attacks. In such a case, the number of machine learning models 113 deployed by the system 115 will at least be equivalent to the number of cybersecurity attacks, the onset of which has to be identified in real-time and subsequently thwarted or at least mitigated. Alternatively, a single machine learning model 113 can be recursively trained with different sets of training data, each data set corresponding to a particular type of cybersecurity attack, to identify and thwart (or atleast mitigate) the onset of different types of cybersecurity attacks described in the present disclosure.
[0038] Likewise, each of the plurality of statistical and probabilistic models 112 can be trained to identify a specific type of cybersecurity vulnerability. For example, while a first statistical and probabilistic model 112 can be trained exclusively to detect Wi-Fi security-related vulnerabilities, a second statistical and probabilistic model 112 can be trained exclusively to identify operating system-related vulnerabilities. In such a case, the number of statistical and probabilistic models 112 deployed by the system 115 will at least be equivalent to the number of cybersecurity vulnerabilities that are to be identified and thwarted, or at least mitigated, in real-time. Alternatively, a single statistical and probabilistic model 112 can be recursively trained with different sets of training data, each data set corresponding to a particular type of cybersecurity vulnerability, to identify and thwart (or at least mitigate) the different types of cybersecurity vulnerabilities described in the present disclosure.
[0039] In accordance with the present disclosure, preferably, the computer-implemented method and system envisaged by the present disclosure are executed on the UAV 101 and the GCS 109. Alternatively, the computer-implemented method and system envisaged by the present disclosure are executed only on the GCS 109. In accordance with the present disclosure, the UAV 101 communicates with the GCS 109 over the first wireless communication band 117, which is powered by Wi-Fi or radio links. Preferably, the communication between the UAV 101, GCS 109, and GNSS 103 is governed by Micro Air Vehicle Link (MAVLink) protocol. For the sake of brevity, the UAS described in FIG.1 incorporates one UAV 101 and one GCS 109. However, it is possible that there will be a plurality of UAVs 101 communicably coupled to one or more GCS 109 via the first wireless communication band 117, and guided by the GNSS 103.
[0040] In accordance with the present disclosure, FIG. 2 illustrates the block diagram of a computer-implemented system 115 for the detection and mitigation of cybersecurity vulnerabilities and cybersecurity attacks in Unmanned Aerial Systems (UAS). As illustrated in FIG.2, the system 115 comprises a processor 201, a memory 203, and a communication interface 205. The processor 201 is connected to the communication interface 205 and the memory 203, through either a wired connection or a wireless connection.In accordance with the present disclosure, the processor 201 is one of a Central Processing Unit (CPU), an x86-based processor, an x64-based processor, a Reduced Instruction Set Computing (RISC) processor, an Application-Specific Integrated Circuit (ASIC) processor, and a Complex Instruction Set Computing (CISC) processor.
[0041] In accordance with the present disclosure, the memory 203 is a non-transitory computer-readable storage medium that stores a set of computer-executable instructions executable by the processor 201 for detecting and mitigating the cybersecurity vulnerabilities and cybersecurity attacks in the UAS. In accordance with the present disclosure, the memory 203 would also store the plurality of statistical and probabilistic models 112 (for example, the least squares model, the Gaussian fitting function) and machine learning models (for example, unsupervised learning models, supervised learning models, and deep learning models) 113.
[0042] In accordance with the present disclosure, the machine learning models 113 are pretrained and pre-programmed to analyze the data packets exchanged between the UAV 101 and GCS 109 during the flight and operation of the former, and detect, in real-time, the cybersecurity threats or cybersecurity attacks directed to the UAV 101 or the GCS 109, or both. Preferably, the machine learning models are trained on datasets containing both normal wireless communication patterns and various cybersecurity attack signatures, including the man-in-the-middle attack, GPS spoofing attack, range spoofing attack, denial of service attack, eavesdropping attack, malware attack, and ransomware attack, inter alia.
[0043] In accordance with the present disclosure, the machine learning models 113 are trained to recognize and differentiate the cybersecurity attack signatures from normal wireless communication patterns. In accordance with the present disclosure, as the data packets are exchanged between the UAV 101 and the GCS 109 via the first wireless communication band 117, the machine learning models 113 continuously monitor and process the data packets, thereby identifying anomalous or suspicious signatures that may indicate an impending cybersecurity attack on the UAV 101 or the GCS 109, or both.
[0044] In accordance with the present disclosure, the processor 201 is configured to perform a packet analysis for each of the data packets exchanged between the UAV 101 and the GCS 109 via the first wireless communication band 117, and machine learning models 113 are trained to identify subtle differences in packet structure, timing, and data flowindicative of a cybersecurity breach. The system 115 subsequently triggers alerts and executes countermeasures to thwart or at least mitigate the cybersecurity threats, thereby ensuring that the UAV 101 and GCS 109 remain secure from cyberattacks and cyberthreats. The computer-implemented system and method envisaged by the present disclosure enables the UAS to respond to cybersecurity attacks and threats well before such attacks and threats attempt to sabotage the operations of the UAS, thereby envisaging a robust layer of cybersecurity for the UAV 101 , the GCS 109, and any other systems, for example, the Global Navigation Satellite System (GNSS) (103), that are communicably coupled to the UAV 101, the GCS 109, or both.
[0045] In accordance with the present disclosure, the memory 203 stores the map information received from the UAS. The map information typically includes the route to be followed by the UAV 101 and the location of the GCS 109. The memory 203 may also store the images captured by the UAV 101 and the data gathered by the sensors (not shown) onboard the UAV 101. In accordance with the present disclosure, the first wireless communication band 117 that interconnects the UAV 101 and the GCS 109 is supported by at least one of an antenna, a frequency modulation (FM) transceiver, a radio frequency (RF) transceiver, one or more amplifiers, a tuner, one or more oscillators, a digital signal processor, a coder-decoder (CODEC) chipset, a subscriber identity model (SIM) card, and a local buffer.
[0046] In accordance with the present disclosure, the system 115 employs unsupervised machine learning models and deep learning models (collectively referenced by reference numeral 113) to detect data packet anomalies and data packet exchange patterns that deviate predominantly from normal communication behavior typically exhibited by the data packets exchanged between the UAV 101 and the GCS 109. The unsupervised machine learning models 113 envisaged by the present disclosure do not necessitate prelabelled training data. Instead, unsupervised machine learning models 113 detect the onset of new or previously unknown threats based on the structure and behavior of the wireless data packets exchanged between the UAV 101 and the GCS 109. Since the unsupervised machine learning models work independently from the pre-labelled training data, they are able to identify subtle and newer cybersecurity attack strategies that may not have been previously known and categorized as malicious.
[0047] By analyzing the patterns underlying the data packets exchanged between the UAV 101 and the GCS 109, the system 115 identifies, using the unsupervised machine learningmodels 113, each of the suspicious activities that are indicative of a cybersecurity attack, thereby offering a proactive approach to cybersecurity threat detection. In addition, the system 115 incorporates deep learning models (also referenced by reference numeral 113), which are best suited for complex pattern recognition tasks. The deep learning models are capable of analyzing the higher-level features of the data packets exchanged between the UAV 101 and the GCS 109, including the time series anomalies, and are trained to classify various cybersecurity threats and attacks, including GPS spoofing attack, range spoofing attack, signal jamming attack, man-in-the-middle attack, denial of service attack, inter alia. The cybersecurity threat detection capabilities of the system 115 are enhanced by the deep learning models 113, for the deep learning models 113 envisage an enhancement in terms of accuracy and robustness of detection of cyberattacks.
[0048] In accordance with the present disclosure, the unsupervised machine learning model and the deep learning model 113 are executed on the cloud-based server 111 that also embodies the system 115. Both the unsupervised machine learning model and the deep learning model 113 are trained to process humongous amounts of cybersecurity-related data and information in real-time. The execution of the unsupervised machine learning model and the deep learning model 113 promotes scalability and flexibility of the said models, all the while enabling the system 115 to dedicate its processing capabilities to handle the deployment and operation of UAVs, without depending upon and stretching the computational capabilities and resources of the UAS for the execution of the unsupervised machine learning model and the deep learning model 113, and the subsequent detection and mitigation of cybersecurity attacks and threats.
[0049] The execution of the unsupervised machine learning model and the deep learning model 113 on the cloud-based server 111 also provisions timely updates to the machine learning models and deep learning models 113, thereby ensuring that the machine learning model and the deep learning model 113 are rendered capable of handling and mitigating emerging and hitherto unknown cybersecurity threats in real-time. Furthermore, the cloud-based server 111 also facilitates the simultaneous execution of the unsupervised machine learning model and the deep learning model 113, thereby increasing the prowess of the system 115 to detect, thwart, or at least mitigate a wide range of cybersecurity threats in real-time.In accordance with the present disclosure, the system 115 embodied in the cloud-based server 111 continuously analyzes the in-flight information characterized by the data packets exchanged between the UAV 101 and the GCS 109 via the first wireless communication band 117, when the UAV 101 is in flight, by executing the unsupervised machine learning model and the deep learning model 113. The system 115 determines the probability of specific cybersecurity attacks occurring in real-time on either the UAV 101 or the GCS 109, or both. In accordance with the present disclosure, if the predicted probability of a cybersecurity attack exceeds a predefined threshold, the system 115 triggers an alarm to the GCS 109. The alarm serves as a critical alert to the GCS 109, thereby enabling an immediate implementation of mitigatory actions from the GCS 109.
[0050] In accordance with the present disclosure, the system 115 of the present disclosure also envisages mitigating the risk of collision of the UAV 101 with other UAVs or other aircraft, for example, airplanes and helicopters. In accordance with the present disclosure, the system 115 captures real-time flight surveillance data corresponding to the other UAVs and aircraft from inter alia the Automatic Dependent Surveillance-Broadcast (ADS-B) system embedded in the plurality of UAVs and the aircraft, camera feeds from the plurality of the UAVs and the aircraft, and radar information (corresponding to the plurality of the UAVs and aircraft) from the GCS 109. The real-time flight surveillance data provides crucial flight-related information, including the position coordinates (X, Y, Z), speed, and acceleration of each of the plurality of UAVs and the aircraft. Further, by consolidating the flight-related information corresponding to the multiple UAVs and the aircraft, the system 115 generates a comprehensive view of the operational environment of the plurality of UAVs. Subsequently, an unsupervised machine learning model 113 analyzes the collected flight-related information and forecasts the likelihood of a collision between any of the multiple UAVs and the aircraft, based on the flight-related information corresponding to the multiple UAVs and the aircraft. If the predicted probability of collision exceeds a predefined threshold, an alarm is triggered and sent to the GCS 109. The alarm triggers the GCS 109 to undertake requisite corrective measures to mitigate the possibility of the collision, including adjusting the flight path and / or the altitude of the UAV 101 or activating additional avoidance mechanisms, including the TCAS (Traffic Alert and Collision Avoidance System).
[0051] In accordance with the present disclosure, the cybersecurity vulnerabilities arising from the cybersecurity-related operational characteristics exhibited by the GCS 109 are alsodetected, thwarted, or at least mitigated by the system 115. In accordance with the present disclosure, such cybersecurity-related operational characteristics are codified based on the pre-flight information corresponding mainly to the GCS 109. Typically, the pre-flight information comprises information describing the cybersecurity landscape and the cybersecurity posture of the GCS 109.
[0052] The computer-implemented system 115, and specifically the processor 201 embodied therein, programmatically acquires, in real-time, pre-flight information corresponding to the GCS 109. The pre-flight information is characterized by a plurality of variables indicative of the cybersecurity status and cybersecurity posture of the GCS 109. In accordance with the present disclosure, the variables indicative of the cybersecurity status and cybersecurity posture of the GCS 109 are assigned pre-determined values (for example, Boolean values, non-Boolean values) based at least on the level of compliance with well-established cybersecurity standards.
[0053] For example, the variables indicative of the cybersecurity status and cybersecurity posture of the GCS 109 include at least the channel and the bandwidth used by the GCS 109 to communicate with the UAV 101, the encryption standards used by the GCS 109 to communicate with the UAV 101, the security standards (for example, WEP, WPA, WPA3) employed by the Wi-Fi network of the GCS 109, level of password protection for the Wi-Fi network of the GCS 109, the enablement of multifactor authentication for accessing the computers of the GCS 109, the enablement of multifactor authentication for accessing the web services hosted of the GCS 109, the enablement of multifactor authentication for accessing the email accounts associated with of the GCS 109, the system version, patch level, service pack level, and version currency corresponding to the operating systems used by the computers of the GCS 109, the access control mechanism implemented by the GCS 109, the data safety protocols (for example, the remote desktop protocol - RDP) implemented by the GCS 109, the type of firewalls used at the GCS 109, and the cloud security measures employed by the GCS 109.
[0054] In accordance with the present disclosure, a predetermined statistical and probabilistic model 112 is deployed to analyze the pre-flight information and, in turn, determine the cybersecurity posture of the GCS 109 and identify the cybersecurity vulnerabilities embodied by the GCS 109. Based on the cybersecurity vulnerabilities embodied by the GCS 109, the statistical and probabilistic model 112 forecasts the probability of the occurrence of cyberattacks against the GCS 109. The cybersecurity vulnerabilitiesidentified by the statistical and probabilistic model 112, based on the pre-flight information and, in turn, the cybersecurity posture of the GCS 109, include but are not restricted to Wi-Fi security-related vulnerabilities, password protection-related vulnerabilities, email security-related vulnerabilities, operating system-related vulnerabilities, multi-factor authentication-related vulnerabilities, data storage and security-related vulnerabilities, and cloud security-related vulnerabilities. The predetermined statistical and mathematical model 112 is, for example, one of a Gaussian fitting function, a least squares model, and a Bayesian approximation model.
[0055] In accordance with the present disclosure, the statistical and probabilistic model 112 forecasts the potential cybersecurity risks and / or cybersecurity threats caused by each of the above-identified cybersecurity vulnerabilities exhibited by the GCS 109. The statistical and probabilistic model 112 is trained to identify specific types of cybersecurity vulnerabilities, for example, such as Wi-Fi vulnerabilities or phishing email attacks, and to correlate the presence of the cybersecurity vulnerabilities in the GCS 109 to the possible onset of specific types of cyberattacks on the GCS 109.
[0056] In accordance with the present disclosure, if the probability of a specific type of cybersecurity attack on the GCS 109 exceeds a predefined threshold level, the system 115 sends an alert to the GCS 109, and triggers the GCS 109 to initiate specific corrective measures to thwart or at least mitigate the risk of cybersecurity attacks on the GCS 109, and thus to protect the UAS from the various types of cybersecurity attacks.
[0057] By using the statistical and probabilistic models 112 and the machine learning models 113, the system 115 identifies and responds to cybersecurity threats and attacks in realtime. The system 115 also undertakes appropriate countermeasures to detect, thwart, or at least mitigate the cybersecurity vulnerabilities plaguing the GCS 109 and rendering the GCS 109 vulnerable to subsequent cybersecurity attacks.
[0058] In accordance with the present disclosure, FIG.3 illustrates, by way of a flowchart, the steps involved in a computer-implemented method for detecting and mitigating, in realtime, cybersecurity-related vulnerabilities embodied in GCS 109 controlling the flight and aerial operations of the UAV 101 , and cybersecurity attacks directed to the UAV 101 and the GCS 109. The execution of the method begins at step 300 when the processor 201 programmatically acquires the real-time pre-flight information corresponding to the UAV 101.In accordance with the present disclosure, the cybersecurity vulnerabilities arising from the cybersecurity-related operational characteristics exhibited by the GCS 109 are also detected, thwarted, or at least mitigated by the system 115. In accordance with the present disclosure, such cybersecurity-related operational characteristics are codified based on the pre-flight information corresponding mainly to the GCS 109. Typically, the pre-flight information comprises information describing the cybersecurity landscape and the cybersecurity posture of the GCS 109.
[0059] As specified hitherto, at step 300, the processor 201 embodied in the computer-implemented system 115 programmatically acquires, in real-time, pre-flight information corresponding to the GCS 109. The pre-flight information is characterized by a plurality of variables indicative of the cybersecurity status and cybersecurity posture of the GCS 109. In accordance with the present disclosure, the variables indicative of the cybersecurity status and cybersecurity posture of the GCS 109 are assigned predetermined values (for example, Boolean values or non-Boolean values) based at least on the level of compliance with well-established cybersecurity standards.
[0060] For example, the variables indicative of the cybersecurity status and cybersecurity posture of the GCS 109 include at least the channel and the bandwidth used by the GCS 109 to communicate with the UAV 101, the encryption standards used by the GCS 109 to communicate with the UAV 101, the security standards (for example, WEP, WPA, WPA3) employed by the Wi-Fi network of the GCS 109, level of password protection for the Wi-Fi network of the GCS 109, the enablement of multifactor authentication for accessing the computers of the GCS 109, the enablement of multifactor authentication for accessing the web services hosted of the GCS 109, the enablement of multifactor authentication for accessing the email accounts associated with of the GCS 109, the system version, patch level, service pack level, and version currency corresponding to the operating systems used by the computers of the GCS 109, the access control mechanism implemented by the GCS 109, the data safety protocols (for example, the remote desktop protocol - RDP) implemented by the GCS 109, the type of firewalls used at the GCS 109, and the cloud security measures employed by the GCS 109.
[0061] For example, the value ‘one’ is assigned to the variable “channel and the bandwidth used by the GCS 109”, if the said channel at said particular bandwidth is protected by strong encryption. Likewise, the value ‘one’ is assigned to the variable “encryption standards” if the encryption standard deployed by the GCS 109 is optimum and an industry-standardencryption. Likewise, the value ‘one’ is assigned to the variable “enablement of multifactor authentication” if the GCS 109 incorporates multifactor authentication.
[0062] In accordance with the present disclosure, at step 302, the statistical and probabilistic model 112 is deployed to analyze the pre-flight information and, in turn, determine the cybersecurity posture of the GCS 109, and subsequently identify the cybersecurity vulnerabilities embodied by the GCS 109. Based on the cybersecurity vulnerabilities embodied by the GCS 109, the statistical and probabilistic model 112 forecasts the probability of the occurrence of cyberattacks against the GCS 109. The cybersecurity vulnerabilities identified by the statistical and probabilistic model 112, based on the preflight information and, in turn, the cybersecurity posture of the GCS 109, include but are not restricted to Wi-Fi security-related vulnerabilities, password protection-related vulnerabilities, email security-related vulnerabilities, operating system-related vulnerabilities, multi-factor authentication-related vulnerabilities, data storage and security-related vulnerabilities, and cloud security-related vulnerabilities. The predetermined statistical and mathematical model 112 is, for example, one of a Gaussian fitting function, a least squares model, and a Bayesian approximation model. For the sake of explanation, the predetermined statistical and mathematical model 112 is considered to be the Gaussian fitting function. The Gaussian fitting function, when executed by the processor 201 , analyses the pre-flight information indicative of the security posture of the GCS 109, determines the cybersecurity posture of the GCS 109, and the probability of the occurrence of cyberattacks against the GCS 109. In accordance with the present disclosure, the processor 201 automatically fits the pre-flight information and the underlying variables indicative of the cybersecurity status and cybersecurity posture of the GCS 109 into the Gaussian fitting function.
[0063] In accordance with the present disclosure, the Wi-Fi security-related vulnerabilities, password protection-related vulnerabilities, email security-related vulnerabilities, operating system-related vulnerabilities, multi-factor authentication-related vulnerabilities, data storage and security-related vulnerabilities, and cloud security-related vulnerabilities are considered as the “cybersecurity attack events”, while the values (for example, the Boolean values or the non-Boolean values) assigned to the variables, i.e. , the channel and the bandwidth used by the GCS 109 to communicate with the UAV 101, the encryption standards used by the GCS 109 to communicate with the UAV 101, the security standards employed by the Wi-Fi network of the GCS 109, level ofpassword protection for the Wi-Fi network of the GCS 109, the enablement of multifactor authentication for accessing the computers, web services, and email accounts associated with the GCS 109, the system version, patch level, service pack level, and version currency corresponding to the operating systems used by the computers of the GCS 109, the access control mechanism implemented by the GCS 109, the data safety protocols implemented by the GCS 109, the type of firewalls used at the GCS 109, and the cloud security measures employed by the GCS 109, are considered the “root causes” that facilitate the occurrence of the cybersecurity attack events.
[0064] In accordance with the present disclosure, the Gaussian fitting function calculates the probability of the occurrence of cyberattacks against the GCS 109 by programmatically correlating the root causes to the occurrence of the cybersecurity attack events. Preferably, based on an arrangement, spread, and frequency of the values assigned to the variables that characterize the pre-flight information, the processor 201 chooses to execute one of the Gaussian fitting function, the least squares model, and the Bayesian approximation model to calculate the probability of the occurrence of cyberattacks against the GCS 109. Furthermore, the processor 201 shifts from the Gaussian fitting function to the least squares model in an event at least one of the arrangement, spread, and frequency of the values (assigned to the above-identified variables) is changed, and accordingly refits the pre-flight information and the underlying variables indicative of the cybersecurity status and cybersecurity posture of the GCS 109 into the least squares model.
[0065] In accordance with the present disclosure, the processor 201 typically shifts from the Gaussian fitting function to the least squares method when the variables embodied in the pre-flight information are uniformly distributed in a specific range and do not follow the Gaussian normal distribution, since the least squares model does not require a normal distribution to be computationally effective. Additionally, the processor 201 shifts from the Gaussian fitting function to the least squares model when the variables embodied in the pre-flight information exhibit a very large range and extreme values (outliers), since the Gaussian fitting function is too sensitive to such a large range of values and the outliers.
[0066] Likewise, the processor 201 shifts from the Gaussian fitting function to the least squares model when the range of the variables constituting the pre-flight information is very short or sparse, thereby making a verification of the assumption of normality, a crucial requirement for the Gaussian fitting function, difficult. Furthermore, the processor 201shifts from the Gaussian fitting function to the least squares model when the variables constituting the pre-flight information are available only over a restricted local range, for in such cases, a locally estimated weighted least squares model is likely to be more effective than a global Gaussian distribution. In accordance with the present disclosure, the processor 201 utilizes the Gaussian fitting function to process the pre-flight information when the variables codifying the pre-flight information are symmetric and bellshaped (in terms of the spread and distribution), and contain a manageable number of extreme values (outliers). Further, the processor 201 utilizes the least squares model to process the pre-flight information when the variables embody a skewed distribution, are spread over a large range, and contain a comparatively larger number of extreme values (outliers).
[0067] In accordance with the present disclosure, at step 304, the processor 201 acquires, in real-time, the in-flight information corresponding to the UAV 101 in the form of data packets. Preferably, the processor 201 accesses and inspects the wireless telecommunication signals exchanged between the UAV 101 and the GCS 109 through the first wireless communication band 117, and acquires such signals, in the form of data packets, for further analysis. Preferably, the first wireless communication band 117 that interconnects the UAV 101 and the GCS 109 is a part of at least one of a Wi-Fi network, WiMAX network, Long term evolution (LTE) telecommunication network, and 4G / 5G cellular network. Preferably, the UAV 101 and the GCS 109 are interconnected by a wireless communication band that operates at a predetermined frequency, including the 2.4 GHz frequency (the first wireless communication band 117, in accordance with the present disclosure), the 5.8 GHz band (the second wireless communication band 117a, in accordance with the present disclosure), the 900 MHz frequency, the 433 MHz frequency, or the 5.2 GHz frequency. Preferably, the exchange of the data packets between the UAV 101 and the GCS 109 through the wireless communication band is governed by the MAVLink (Micro Vehicle to Air Link) protocol.
[0068] In accordance with the present disclosure, the processor 201 performs an analysis of the data packets acquired from the inspection of the first wireless communication band 117 interconnecting the UAV 101 and the GCS 109. In accordance with the present disclosure, the analysis of the data packets (i.e. , packet analysis) by the processor 201 reveals inconsistencies in the transmission of the data / information between the UAV 101 and the GCS 109, which, in turn, acts as a pointer to the onset of cybersecurity attackson either the UAV 101 , the GCS 109, or both. Typically, the onset of a cybersecurity attack on either the GCS 109 or the UAV 101 , or both, is accompanied by a manipulation of the data packets exchanged between the UAV 101 and the GCS 109. The processor 201, by analyzing the said data packets, uncovers the data-related inconsistencies, data traffic-related inconsistencies, data security-related inconsistencies, or the network behavior-related inconsistencies embodied therein, and determines whether the data packets have been wrongfully manipulated (step 306).
[0069] Preferably, the processor 201 implements the machine learning model 113 to differentiate between data packets containing genuine GPS data and data packets containing manipulated GPS data or fake and malicious GPS data. Preferably, the machine learning model 113 has been pre-trained with training vectors that signify manipulated GPS signals-based attack behavior and normal data packet behavior, and has been configured to differentiate normal data packets from data packets that have been manipulated as a part of either the GPS spoofing attack or the GPS signal jamming attack.
[0070] The processor 201 analyzes the data packets (exchanged between the UAV 101 and the GCS 109, during the flight of the UAV 101) and determines the data packet behavior. Subsequently, the processor 201 implements the machine learning model 113 to further analyze the data packet behavior and differentiate normal packet behavior from the behavior of the data packets that contain manipulated, fake, and malicious GPS signals.
[0071] Preferably, the UAV 101 comprises an inertial measurement unit (IMU) that generates real-time telemetry data corresponding to the UAV 101, indicative of at least the UAV’s real-time position, altitude, and acceleration. While the GPS data shared by the UAV 101 with the GCS 109 also indicates the UAV’s acceleration, speed, and rotation, the IMU also tracks the UAV’s position, altitude, and acceleration in real-time. The IMU accordingly generates and shares with the GCS 109 the real-time telemetry data indicative of the UAV’s position, altitude, and acceleration.
[0072] The processor 201 cooperates with the IMU (embedded in the UAV 101) to receive the real-time telemetry data. Subsequently, the processor 201 programmatically compares the UAV’s real-time position, altitude, and acceleration, derived from the IMU’s real-time telemetry data, with the GPS data embodied in the data packets exchanged between the UAV 101 and GCS 109. The processor 201 classifies the GPS data embodied in the datapackets as manipulated / malicious GPS data, only in an event where the GPS data does not match the real-time telemetry data received from the IMU of the UAV 101.
[0073] Preferably, the machine learning model 113 envisaged by the present disclosure is also trained with the baseline values for maximum physical velocity exhibited by the UAV 101 at various points in time, change in the velocity of the UAV 101 in relation to a change in the acceleration of the UAV 101 , a number of satellites communicably coupled to the UAV 101 at various points in time, camer-to-noise density ratio observed at each of the satellites communicably coupled to the UAV 101 , the difference between the internal clock of a GPS receiver (embedded in the UAV 101), and system time recorded by the GPS unit (embedded in the GCS 109), horizontal dilution of precision (HDOP), and vertical dilution of precision (VDOP) (both HDOP and VDOP recorded by a GNSS receiver embedded in the UAV 101) as training vectors. The machine learning model 113, based on the above-identified training vectors, identifies data packets that contain manipulated / malicious GPS data and also differentiates the data packets containing the manipulated GPS data from data packets containing authentic GPS data.
[0074] In accordance with the present disclosure, the processor 201 analyzes the telemetry data exchanged between the UAV 101 and the GCS 109 (in the form of data packets) and determines if any counterfeit signals have been transmitted to the UAV 101 in order to either sabotage the operations of the UAV 101 or to take unlawful control of the UAV 101 , or both.
[0075] In accordance with the present disclosure, the processor 201 analyzes the GPS coordinates stored in the data packets received by the UAV 101 against the RSSI (received signal strength indicator) and noise fields in the data packets transmitted from the UAV 101 back to the GCS 109. The processor determines if there exists any abnormal and suspicious correlation between the GPS coordinates, RSSI, and noise, and correlates the presence of abnormal and suspicious correlation, during the analysis of the data packets, to the onset of the GPS spoofing attack on either the UAV 101 or the GCS 109, or both.
[0076] Further, the processor 201 analyzes the data packets (exchanged between the UAV 101 and the GCS 109, during the flight of the UAV 101) to identify if the data from the GPS (Global Positioning System) onboard the UAV 101 is in synchrony with the acceleration and rotation-related telemetry data generated by an IMU (Inertial Measurement Unit)onboard the UAV 101. In an event the packet analysis performed by the processor 201 reveals any glaring mismatch between the real-time GPS data (received from the GPS onboard the UAV 101) and the telemetry data (received from the IMU onboard the UAV 101 ), the processor 201 correlates such a mismatch between the real-time GPS data and the real-time telemetry data to the onset of a GPS spoofing attack on the UAV 101. The processor 201 , by performing packet analysis, also acquires the UAV altitude-related data from a barometric pressure sensor onboard the UAV 101. In an event the packet analysis performed by the processor 201 reveals any glaring mismatch between the real-time altitude-related data (received from the barometric pressure sensor onboard the UAV 101 ) and the real-time altitude-related data received from the GPS onboard the UAV 101 , the processor 201 correlates such a mismatch between the real-time altitude-related data received from the GPS and the barometric pressure sensor, respectively, to the onset of a GPS spoofing attack on the UAV 101.
[0077] In addition, the processor 201 performs packet analysis on the data packets exchanged between the UAV 101 and the GCS 109 to also identify a) sudden position jumps from the UAV 101 that are far beyond the physical capabilities of the UAV 101, b) glaring mismatch between location coordinates of the UAV 101 received from the onboard GPS and the speed-related telemetry data received either from the GNSS 103 (Global Navigation Satellite System, which calculates the UAV’s speed by monitoring the UAV’s change in position with relation to time) or the IMU, c) spontaneous and unnatural spikes in the strength of the GPS signal received by the UAV 101, d) spontaneous and uniform spike in the carrier-to-noise density observed by all the satellites communicably coupled to the UAV 101, e) a spontaneous loss of communicable connection between a plurality of satellites and the UAV, and an equally spontaneous reconnection between the UAV and a hitherto unknown, new constellation of satellites, and f) a microsecond-level jump or accelerated drift in the GPS receiver’s internal clock bias.
[0078] In accordance with the present disclosure, when the packet analysis performed by the processor 201 identifies sudden position jumps from the UAV 101 that are far beyond the physical capabilities of the UAV 101, the processor 201 identifies such sudden positional jumps as being a result of the introduction of a fake, malicious GPS signal into the UAV 101 , and generates an alert directed to the GCS 109, indicative of a GPS spoofing attack on the UAV 101. Likewise, when the packet analysis performed by the processor 201 identifies a glaring mismatch between the real-time location coordinates of the UAV 101received from the onboard GPS and the real-time speed-related telemetry data received either from the GNSS 103 or the IMU, the processor 201 identifies such a mismatch as a resultant of the introduction of a fake, malicious GPS signal into the UAV 101, and generates an alert directed to the GCS 109, indicative of a GPS spoofing attack on the UAV 101.
[0079] Likewise, when the packet analysis performed by the processor 201 identifies spontaneous and unnatural spikes in the strength of the GPS signal received by the UAV 101, the processor 201 attributes such a spontaneous and unnatural increase in the strength of the GPS signal (received by the UAV 101) to the introduction of a fake, malicious GPS signal into the UAV 101, and generates an alert directed to the GCS 109, indicative of a GPS spoofing attack on the UAV 101.
[0080] Likewise, when the packet analysis performed by the processor 201 identifies a spontaneous and uniform spike in the camer-to-noise density observed by all the satellites communicably coupled to the UAV 101, the processor 201 attributes such a spontaneous and uniform spike in the carrier-to-noise density to the introduction (into the UAV 101) of a GPS signal transmitted at an abnormally high transmission power, and accordingly flags-off such a GPS signal as fake and malicious, in addition to generating an alert indicating the onset of a GPS spoofing attack on the UAV 101.
[0081] Further, typically, genuine GPS signals transmitted from the satellites (that are a part of the GNSS 103) to the UAV 101 vary based on the respective satellites’ orbital altitude, inclination, and longitude. On the contrary, when the processor 201, based on the packet analysis, identifies GPS signals shared in a rapid succession from a single terrestrial source, the processor 201 categorizes such GPS signals originating from a single terrestrial source in a rapid succession as fake and malicious GPS signals, and generates an alert directed to the GCS 109, indicative of a GPS spoofing attack on the UAV 101.
[0082] Further, when the UAV disconnects from a plurality of satellites (that are a part of the GNSS 103) and rapidly reconnects with a new, full constellation of satellites embodying usually high signal strengths, the processor 201 , based on the packet analysis, identifies the onset of a GPS spoofing attack on the UAV 101, and accordingly generates a cybersecurity attack warning directed to the GCS 109, signaling the onset of a GPS spoofing attack on the UAV 101.Further, when the processor 201 identifies, based on the packet analysis, a microsecond level-jump or an accelerated drift in the GPS receiver’s (onboard the UAV 101 ) clock bias, the processor 201 correlates such a microsecond level-jump or the accelerated drift to the introduction of a fake GPS signal into the UAV 101 and the consequential transition of the UAV 101 from receiving genuine GPS signals to receiving fake GPS signals. Subsequently, the processor 201 generates a cybersecurity attack warning directed at the GCS 109, signaling the onset of a GPS spoofing attack on the UAV 101.
[0083] In accordance with the present disclosure, the processor 201 , based on packet analysis, also identifies GPS or signal jamming attacks, which are brute-force denial of service attacks directed at the UAV 101. The processor 201 also envisages thwarting, or at least mitigating, the occurrence of the said GPS and signal jamming attacks. The processor 201 , based on the packet analysis, identifies a) any significant drop in the signal-to-noise ratio of the RF signals transmitted from any of the satellites (that are a part of the GNSS 103) to the UAV 101, b) any sudden, sharp, and unnatural increase in the RF noise floor at any of the satellites communicably coupled to the UAV 101, c) any spontaneous and unnatural crash of the signal-to-noise ratio values at any of the satellites communicably coupled to the UAV 101, d) a sudden increase in the values that indicate the geometry and the positional accuracy exhibited by the satellites communicably coupled to the UAV 101 (i.e., a sudden and unnatural spike in the values of horizontal and vertical dilution of position that are indicative of the satellite’s geometry and positional accuracy - HDOP and VDOP), e) any spontaneous and abnormal changes in the status flags embodied in the flight controller of the UAV 101, f) any spontaneous and abnormal changes in the state of the GPS onboard the UAV 101 (for example, from “2D GPS fix” to “3D GPS fix” and vice-versa in a spontaneous, rapid, and unnatural manner), g) any spontaneous and abnormal non-availability of the GPS data on the part of the UAV 101, despite the availability of the telemetry data from the IMU onboard the UAV 101 , h) spontaneous and undesired changes in the operational mode of the UAV 101 (for instance, a spontaneous and rapid change in the UAV status from “auto” to “altitude hold” to “land”), i) any spontaneous and abnormal increase in the number of corrupt packets (that fail the cyclic redundancy check) received by the GCS 109, j) any failure on the part of the GCS 109 to capture the “acknowledgment” packets from the UAV 101 in response to sending the GPS data thereto, k) any abnormal increase in the retransmission of the GPS data from the GCS 109 to the UAV 101 , and I) any sudden and abnormal increase in the loss of MAVLink heartbeat packets at the GCS 109. Subsequently, the processor 201 correlates theoccurrence of any of the above-identified phenomena with the onset of the GPS jamming attack on the UAV 101 and accordingly generates a cybersecurity attack warning directed to the GCS 109, indicating the onset of the GPS signal jamming attack on the UAV 101.
[0084] In accordance with the present disclosure, when the processor 201 identifies, based on the packet analysis, the onset of the GPS spoofing attack on the UAV 101 , the processor 201 communicates directly with the UAV 101, preferably through a specialized, preprogrammed, and secured communication interface 120, and instructs the UAV 101 to ignore the fake and malicious GPS signals and the manipulated GPS data contained therein. In this manner, the processor 201 protects the UAV 101 and the GCS 109 from a GPS spoofing attack. Subsequently, at step 308a, the processor 201 generates a corrected flight path for the UAV 101 based on historical, valid, and genuine telemetry data, upon verifying that such telemetry data had not been previously compromised by the GPS spoofing attack or the GPS signal jamming attack. Typically, the processor 201 derives latitude and longitude coordinates from historical, valid telemetry data and determines the waypoints for the corrected flight path of the UAV 101. Subsequently, the processor 201 navigates the UAV 101 on the said corrected flight path, thereby preventing the UAV 101 from being sabotaged by the GPS spoofing attack.
[0085] In accordance with the present disclosure, the processor 201 continuously monitors the first wireless communication band 117 (interconnecting the UAV 101 and the GCS 109) and its encryption levels. In the event the processor 201 determines that the first wireless communication band 117 is no longer strongly encrypted to thwart the cybersecurity attacks directed to the UAV 101 and the GCS 109, the processor 201 generates an alert directed to the GCS 109, indicting the vulnerability of the first wireless communication band 117 to various cybersecurity attacks, including the GPS signal jamming attack, eavesdropping attack, man-in-the-middle attack, denial of service attack, malware attack, and ransomware attack, inter alia.
[0086] In accordance with the present disclosure, the machine learning model 113 is also trained with signing keys indicative of both strong encryption and weaker encryption. Further, the machine learning model 113 is also trained to identify spontaneous and anomalous deauthentication frames and spontaneous renegotiation of symmetric keys, and to correlate the occurrence of such phenomena with the onset of eavesdropping attacks, in particular. In accordance with the present disclosure, when the processor 201 identifies the encryption levels of the first wireless communication band 117 to be inadequate forthwarting any of the above-identified cybersecurity attacks, the processor 201 automatically and dynamically enhances the symmetric key length and reinitiates the key exchange between the UAV 101 and the GCS 109 by using the RSA algorithm. The processor 201 hands over a renegotiated and enhanced symmetric key for a symmetric block cipher. Subsequently, the processor 201 executes a predetermined block cipher algorithm (e.g., AES, DES, Triple DES, and the like) to facilitate the transfer of data packets (encrypted and decrypted using the symmetric key) between the UAV 101 and the GCS 109.
[0087] In accordance with the present disclosure, the processor 201 evaluates the current channel conditions (i.e., the first set of channel conditions) and the security-related requirements of the first wireless communication band 117. The channel conditions of the first wireless communication band 117 are defined by interference, signal attenuation, and packet loss, inter alia. Further, the security-related requirements of the first wireless communication band 117 include data confidentiality, data integrity, strong authentication, and non-repudiation, inter alia. Subsequently, based on the channel conditions (i.e., the first set of channel conditions) and the security requirements for the first wireless communication band 117, the processor 201 determines the bit length for the RSA key exchange and the key length for the symmetric block cipher algorithm. Subsequently, the processor 201, by implementing the RSA algorithm, securely negotiates and transmits the symmetric key to the UAV 101 and the GCS 109. Further, in the event of changes to the channel conditions and / or the security-related requirements, the processor 201 dynamically triggers the creation and exchange of a new symmetric key, thereby dynamically modifying the encryption levels of the first wireless communication band 117, in line with the change in the channel conditions and the security-related requirements, but without terminating the underlying wireless communication channel.
[0088] In accordance with the present disclosure, when the processor 201 detects the onset of any of the GPS signal jamming attack, eavesdropping attack, man-in-the-middle attack, and denial of service attack, the processor 201 instructs both the UAV 101 and the GCS 109 to switch from the first wireless communication band 117 to the predetermined second wireless communication band 117a (step 308b).
[0089] In accordance with an alternative embodiment of the present disclosure, the processor 201, after triggering a switch of the UAV 101 and the GCS 109 from the first wireless communication band 117 to the second wireless communication band 117a, changes theencryption levels of the second wireless communication band 117a as well, to protect the second wireless communication band 117a from GPS signal jamming attack, denial of service attack, and man-in-the-middle attack, by repeating the hitherto explained procedure used for dynamically changing the encryption levels of the first wireless communication band 117. However, the encryption levels of the second wireless communication channel 117a are dynamically modified based on the current channel conditions corresponding to the second wireless communication band 117a (i.e., the second set of channel conditions) and the security-related requirements of the second wireless communication band 117a.
[0090] In accordance with the present disclosure, the processor 201 dynamically changes the encryption levels (for the first wireless communication band 117 or the second wireless communication band 117a, or both) using the MAVLink protocol, which governs the exchange of data packets between the UAV 101 and the GCS 109.
[0091] In accordance with the present disclosure, the processor 201 instructs the GCS 109 to switch from the first wireless communication band 117 to the second wireless communication band 117a, in synchrony with the UAV 101, to minimize the latency associated with switching both the UAV 101 and the GCS 109 from the first wireless communication band 117 to the second wireless communication band 117a.
[0092] In accordance with the present disclosure, the processor 201 triggers the GCS 109 to switch from the first wireless communication band 117 to the predetermined and secured second wireless communication band 117a, only in response to identifying intentional and repetitive disruptions in the transmission of the data packets through the first wireless communication band 117. Subsequently, the processor 201 dynamically changes the encryption levels across the second wireless communication band 117a to thwart, or at least mitigate, the occurrence of intentional and repetitive disruptions.
[0093] In accordance with the present disclosure, when the processor 201 detects the onset of any of the GPS signal jamming attack, eavesdropping attack, man-in-the-middle attack, and denial of service attack, the processor 201 introduces dynamically generated error correction codes into the first wireless communication band 117 - used by the UAV 101 and the GCS 109 to exchange the data packets - to thwart or at least mitigate the otherwise harmful effects intended by the above-identified cybersecurity attacks, and to minimize the disruptions in the first wireless communication band 117 (step 308c).In accordance with the present disclosure, the error correction codes are dynamically generated by processing a Hamiltonian bipartite graph of high girth and large shortest cycle (i.e., a Hamiltonian bi-partite graph having a high even girth), based on the propagation conditions and statistics corresponding to the first wireless communication band 117, which are determined by the processor 201, based on the packet analysis performed on the data packets exchanged between the UAV 101 and GCS 109.
[0094] In accordance with the present disclosure, the processor introduces dynamically generated error control codes (for example, low-density parity check codes) into the first wireless communication band 117, based on the real-time signal quality determined across the first wireless communication band 117, to maintain the integrity of the first wireless communication band 117 during the onset of any of the GPS signal jamming attack, denial of service attack, man-in-the-middle attack, and cyber hijacking attack, and thereby renders the first wireless communication band 117, the UAV 101 and the GCS 109 resilient to the above-identified cybersecurity attacks.
[0095] In accordance with the present disclosure, the first wireless communication band 117 (that interconnects the UAV 101 and the GCS 109) forms the physical layer of the corresponding wireless communication network 119. The MAVLink protocol that governs the communication between the UAV 101 and the GCS 109 via the first wireless communication band 117, forms the application layer or the datalink layer. In accordance with the present disclosure, the processor 201 infers the conditions and statistics corresponding to the first wireless communication band 117, including but not restricted to path loss, shadowing, multipath fading, time variation, flat fading, doppler shift, and interference, by performing packet analysis on the data packets exchanged between the UAV 101 and the GCS 109 via the first wireless communication band 117. Subsequently, the processor 201 analyzes the path loss, shadowing, multipath fading, time variation, flat fading, Doppler shift, and interference exhibited by the first wireless communication band 117, and generates a catalog of graphs usable for dynamically creating the error correction codes.
[0096] In accordance with the present disclosure, the graphs generated by the processor 201 are Hamiltonian bipartite graphs of girth ’g’. Typically, Hamiltonian bipartite graphs are three-regular (cubic) bipartite graphs with the girth (i.e., the length of the shortest cycle) that contains a Hamiltonian cycle (i.e., a cycle that visits every vertex of the graph exactly once). Preferably, the Hamiltonian bipartite graphs created by the processor 201 are non-vertex transitive (i.e. , possess at least two distinct sets of vertices that differ in structural properties, including the degree of the vertices and the number of triangles the vertices belong to). Preferably, the processor 201 , based on the analysis of the channel conditions (i.e., the first set of channel conditions) of the first wireless communication band 117, generates a catalog of Hamiltonian bipartite graphs having a high girth (g), preferably an even girth, and a large shortest cycle.
[0097] In accordance with the present disclosure, the processor 201 generates a catalog of error correction codes (e.g., low-density parity check codes) from the catalog of Hamiltonian bipartite graphs. Preferably, the catalog of error correction codes is generated based at least on the size of the matrix that defines the error correction codes, the code rate, the degree distribution (the degree distribution refers to the number of ‘ones’ - typically, irregular LDPC codes embody varying row / column degrees), and girth (the length of the shortest cycle in the Hamiltonian Bipartite graph representing the matrix).
[0098] Preferably, each error code contained in the catalog of error correction codes embodies a specific code rate, a specific number of input bits, and a specific number of output bits. In accordance with the present disclosure, the processor 201 selects at least one error correction code from the catalog, based at least on a variance of noise exhibited by the first wireless communication band 117. Preferably, the processor 201 maps every error correction code (contained in the catalog) against the variance of noise (exhibited by the first wireless communication band 117) and the code parameters that are influenced by the variance of noise. For example, such parameters include maximum achievable code rate, the number of input bits in the wireless communication signal (exchanged between the UAV 101 and GCS 109 via the first wireless communication band 117), and the number of output bits in the wireless communication signal.
[0099] Therefore, preferably, the processor 201 maps each of the error correction codes to the variance of noise (exhibited by the first wireless communication band 117) and the maximum achievable code rate, the number of input bits in the wireless communication signal (exchanged between the UAV 101 and GCS 109 via the first wireless communication band 117), and the number of output bits in the wireless communication signal.
[0100] In accordance with the present disclosure, the processor 201 identifies an error correction code with the lowest bit error rate (BER), given a specific variance of noise and specific code parameters (viz., code rate, number of input bits, and number of output bits), as theoptimal error correction code and introduces the optimal error correction code into the first wireless communication band 117, thereby at least mitigating the otherwise harmful effects of GPS signal jamming attack, denial of service attack, and man-in-the-middle attack for the UAV 101, GCS 109, and the first wireless communication band 117.
[0101] In accordance with the present disclosure, the processor 201 determines the variance of the noise (modeled, for example, as Additive White Gaussian Noise -AWGN) based on the physical environment factors relevant to the first wireless communication band 117, namely, the thermal noise, interference, and operating bandwidth. Likewise, the processor 201 determines the variance of the noise, also based on the propagation conditions of the first wireless communication band 117, including the transmission bandwidth and frequency, path loss, thermal noise, shot noise, signal-to-noise ratio (SNR), fade margin, and impulse noise.
[0102] In accordance with the present disclosure, the processor 201 introduces the dynamically generated optimum error correction code into the second wireless communication band 117a as well (when the UAV 101 and the GCS 109 shift from the first wireless communication band 117 to the second wireless communication band 117a), to protect the second wireless communication band 117a from GPS signal jamming attack, denial of service attack, and man-in-the-middle attack, by repeating the hitherto explained procedure used for introducing the dynamically generated optimum error correction code into the first wireless communication band 117. However, in the case of the second wireless communication channel 117a, the second set of channel conditions corresponding to the second wireless communication band 117a are used to generate the catalog of Hamiltonian bipartite graphs having a high girth (g), preferably an even girth, and a large shortest cycle. Likewise, in the case of the second wireless communication band 117a, at least one error correction code is selected from the catalog as the optimum error correction code, based at least on a variance of noise exhibited by the second wireless communication band 117a and the code parameters influenced by the variance of noise associated with the second wireless communication band 117a. In accordance with the present disclosure, on detecting the onset of GPS signal jamming attack, man-in-the-middle attack, denial of service attack, and cyber hijacking attack, the processor 201 implements Frequency-Hopping Spread Spectrum (FHSS), and transmits the wireless communication signals from the UAV 101 to the GCS 109 and vice-versa, by rapidly switching the carrier frequency in a pseudo-random sequence. Typically, changesin the carrier frequency are known only to UAV 101 and GCS 109. In addition, as described hitherto, the processor 201 instructs both the UAV 101 and the GCS 109 to switch from the first wireless communication band 117 to the predetermined second wireless communication band 117a, and also introduces the dynamically changing error correction codes into the second wireless communication band 117a to thwart or at least mitigate the otherwise harmful and adverse effects brought about by the GPS signal jamming attack, man-in-the-middle attack, denial of service attack, and cyber hijacking attack.
[0103] In accordance with the present disclosure, the machine learning model 113 is trained using training vectors that include a plurality of key network quality metrics and their ideal or acceptable ranges indicative of normal network inference. Such network quality metrics include, but are not limited to, signal-to-noise ratio (SNR), received signal strength indicator (RSSI), noise floor, jitter, packet loss rate, retransmission rate, latency, channel utilization, and throughput. In this manner, the machine learning model 113 is configured to differentiate between normal network interference and intentional and repetitive disruptions in the first wireless communication band 117.
[0104] In accordance with the present disclosure, the processor 201 is configured to analyze the packet header, packet pay load, and traffic pattern for each data packet exchanged between the UAV 101 and the GCS 109, and derive specific packet signatures corresponding to the said data packets. The packet signatures derived by the processor 201 are passed to the machine learning model 113, which compares the packet signatures with key network quality metrics and their ideal or acceptable ranges indicative of normal network operation, and determines whether the first wireless communication band 117 has been intentionally disrupted. The machine learning model 113 subsequently correlates any such intentional disruptions in the first wireless communication band 117 to the onset of at least one of GPS signal jamming attack, man-in-the-middle attack, denial of service attack, and cyber hijacking attack on the first wireless communication band 117, and by extension on either the UAV 101 or the GCS 109, or both.
[0105] In response to detecting intentional and repetitive disruptions in the first wireless communication band 117, the machine learning model 113 triggers the processor 201 to instruct both the UAV 101 and the GCS 109 to switch from the first wireless communication band 117 to the second wireless communication band 117a in synchrony, and to also introduce the dynamically changing error correction codes into the secondwireless communication band 117a, as an addendum to the implementation of the FHSS protocol, to thwart or at least mitigate the otherwise harmful and adverse effects brought about by the GPS signal jamming attack, man-in-the-middle attack, denial of service attack, and cyber hijacking attack.
[0106] In accordance with the present disclosure, the machine learning model 113 is also trained using training vectors that include a plurality of ideal packet analysis signatures and network infrastructure-related metrics, both indicative of normal network behavior. The machine learning model 113 is configured to analyze the specific packet signatures corresponding to the data packets exchanged between the UAV 101 and GCS 109, identify any aberrations in the packet signatures corresponding to the said data packets, and based on the identified aberrations, pinpoint the wireless network communication layer at which the data packets exchanged between the UAV 101 and GCS 109 are manipulated.
[0107] In accordance with the present disclosure, the machine learning model 113 is trained to identify the presence of a high volume of 802.11 de-authentication or disassociation frames in the data packets, multiple access points (APs) broadcasting the same SSID (service set identifier) but different BSSIDs (basic service set identifiers - unique MAC addresses), abnormal signal strengths corresponding to the data packets, and unexpected (spontaneous) changes in MAC addresses for the data packets emanating from known IP addresses, and correlate the occurrence of any of the above-identified phenomena to the onset of a cybersecurity attack (preferably, a denial of service attack) on the data link layer of the wireless communication network 119 incorporating the first wireless communication band 117.
[0108] Likewise, the machine learning model 113 is also trained to identify a sudden drop in the data frames (during the exchange of data packets between the UAV 101 and the GCS 109), a large amount of CRC (cyclic redundancy check) errors, with frames not being properly decoded, extremely low signal strength, and high noise floor in the data packets captured either at the UAV 101 or the GCS 109, and correlate the occurrence of any of the above-identified phenomena to the onset of a cybersecurity attack (preferably, a denial of service attack) on the physical layer of the wireless communication network 119 incorporating the first wireless communication band 117.
[0109] Likewise, the machine learning model 113 is also trained to identify unusual routing behavior on the part of the data packets exchanged between the UAV 101 and the GCS109, the appearance of unusual session cookies in the data packets exchanged between the UAV 101 and the GCS 109, a downgrade from HTTPS to HTTP (secured socket layer stripping) for the data packets exchanged between the UAV 101 and the GCS 109, and a massive, abnormal spike in the TCP SYN, UDP, or ICMP packets targeting either the UAV 101 or the GCS 109, and correlate the occurrence of any of the above-identified phenomena to the onset of a cybersecurity attack (preferably, a man-in-the-middle attack or a cyber hijacking attack) on either the network layer or the transport layer of the wireless communication network 119 incorporating the first wireless communication band 117.
[0110] In accordance with the present disclosure, on the detection (by the machine learning model 113) of the onset of a cybersecurity attack (viz., denial of service attack, man-in-the-middle attack, cyber hijacking attack) on either the physical layer, datalink layer, network layer, or transport layer of the wireless communication network 119 incorporating the first wireless communication band 117, the processor 201 instructs both the UAV 101 and the GCS 109 to switch from the first wireless communication band 117 to the second wireless communication band 117a in synchrony, and also introduces the dynamically changing error correction codes into the second wireless communication band 117a, as an addendum to the implementation of the FHSS protocol, to thwart or at least mitigate the otherwise harmful and adverse effects brought about by the man-in-the-middle attack, denial of service attack, and cyber hijacking attack, on either the physical layer, datalink layer, network layer, or transport layer of the wireless communication network 119 incorporating the first wireless communication band 117.
[0111] In accordance with the present disclosure, the machine learning model 113 is also trained using training vectors that include a plurality of ideal packet analysis signatures and network behavior-related metrics, both indicative of normal network behavior. The machine learning model 113 is configured to analyze the specific packet signatures corresponding to the data packets exchanged between the UAV 101 and GCS 109, identify any aberrations in the packet signatures corresponding to the data packets, and based on the identified aberrations, identify the type of cybersecurity attack that has been implemented on any of the UAV 101 , GCS 109, and the first wireless communication band 117.
[0112] In accordance with the present disclosure, the machine learning model 113 is trained to identify an abnormally high number of TCP SYN or UDP, or ICMP packets flooding thewireless communication network 119 embodying the first wireless communication band 117, and correlate the flooding of the TCP SYN, UDP, or ICMP packets to the onset of a denial of service attack on the wireless communication network 119 incorporating the first wireless communication band 117, and by extension, the UAV 101 or the GCS 109, or both.
[0113] In accordance with the present disclosure, the machine learning model 113 is trained to identify abnormal address resolution protocol (ARP) packets and abnormal DNS traffic, including multiple unsolicited ARP replies from a single MAC address falsely claiming to be a gateway IP, and abnormal DNS responses that do not match the IP address of the authorized DNS server and redirect the data traffic to malicious network locations. Furthermore, the machine learning model 113 is also trained to identify any sudden and abnormal increase in the round trip time (RTT) between the UAV 101 and the GCS 109, any sudden and abnormal increase in the arrival of consecutive data packets either at the UAV 101 or the GCS 109, duplication of sequence numbers in the data packets exchanged between the UAV 101 and the GCS 109, any missing sequence numbers or a sudden, unexpected increase in the sequence numbers in the data packets, any sudden and unexpected increase in the number of dropped data packets, a sudden and unexpected increase in the data packet retransmission requests either at the UAV 101 or the GCS 109, any sudden and abnormal shifts in the received signal strength indicator (RSSI), any sudden arrival of unencrypted data traffic either at the UAV 101 or the GCS 109, and any sudden increase in the number of corrupt data packets arriving either at the UAV 101 or the GCS 109. The machine learning model 113 is further configured to correlate the identification of any of the above-mentioned phenomena with the onset of a man-in-the-middle attack on the wireless communication network 119, incorporating the first wireless communication band 117, and, by extension, the UAV 101 or the GCS 109, or both.
[0114] In accordance with the present disclosure, the machine learning model 113 is trained to identify any unusual, spontaneous, and persistent outbound connections from internal hosts at regular intervals, any unusually high volume of DNS requests to a single domain, a sudden surge in the outgoing data, either from the GCS 109 or the UAV 101, and correlate the occurrence of any of the above-described phenomena to the onset of a malware attack on the wireless communication network 119 incorporating the first wireless communication band 117, and by extension, the UAV 101 or the GCS 109, or both.In accordance with the present disclosure, the machine learning model 113 is trained to identify any massive burst of crucial flight commands at the UAV 101, any new flight commands originating suddenly from a new system ID or an impersonated system ID in contradiction with the established connection state, massively contradictory telemetry data received at the GCS 109 from the UAV 101 , a sudden and abnormal increase in deauthentication or disassociation requests, and a sudden and abnormal increase in reauthentication requests, and correlate the occurrence of any of the above-described phenomena to the onset of a cyber hijacking attack on the wireless communication network 119 incorporating the first wireless communication band 117, and by extension, the UAV 101 or the GCS 109, or both.
[0115] In accordance with the present disclosure, on the detection (by the machine learning model 113) of the onset of any of the denial of service attack, man-in-the-middle attack, cyber hijacking attack, and malware attack on the wireless communication network 119 incorporating the first wireless communication band 117, and, by extension, the UAV 101 or the GCS 109, or both, the processor 201 instructs both the UAV 101 and the GCS 109 to switch from the first wireless communication band 117 to the second wireless communication band 117a in synchrony, and also introduces the dynamically changing error correction codes into the second wireless communication band 117a, as an addendum to the implementation of the FHSS protocol, to thwart or at least mitigate the otherwise harmful and adverse effects brought about by the man-in-the-middle attack, denial of service attack, cyber hijacking attack, and the malware attack.
[0116] In accordance with the present disclosure, the processor 201 analyzes the packet header, packet metadata (stored in the packet header), and the packet payload of the data packets exchanged between the UAV 101 and the GCS 109, the network traffic passing through the first wireless communication band 117, the characteristics of the sessions executed using the first wireless communication band 117, and the file sharing patterns observed across the first wireless communication band 117. Subsequently, the processor 201 generates specific packet signatures that define the characteristics of the data packets (exchanged between the UAV 101 and the GCS 109) and the characteristics of the first wireless communication band 117.
[0117] The machine learning model 113, in accordance with the present disclosure, is trained using a baseline of normal network activity, signatures of known threats, signatures of malicious executables, signatures of malicious command-and-control communications,known characteristics of secure, encrypted sessions, and signatures of secure packet flow characteristics.
[0118] The machine learning model 113 compares the specific packet signatures, generated by the processor 201, with the signatures of known threats, signatures of malicious executables, signatures of malicious command and control communications, and also analyzes the packet signatures for any substantial similarities with signatures that indicate the common characteristics of secured encrypted sessions and signatures of secured packet flow characteristics, and subsequently identifies the onset of a malware-based cybersecurity attack on any of the UAV 101 and the GCS 109. Preferably, the machine learning model 113 triggers a warning, directed to the GCS 109, indicating the onset of a malware-based cybersecurity attack, on the UAV 101 or the GCS 109, or both, in an event the packet signatures of the data packets match with any of the signatures of known threats, signatures of malicious executables, signatures of malicious command and control communications or if the packet signatures of the data packets are not substantially similar, and thus structurally differ, from the signatures of common characteristics of secured encrypted sessions and signatures of secured packet flow characteristics.
[0119] In accordance with the present disclosure, the machine learning model 113 is also trained on signatures of unusual file-sharing patterns, data exfiltration, and malicious command-and-control communications. Based on the signatures of unusual file sharing patterns, data exfiltration signatures, and signatures of malicious command and control communications, the machine learning model 113 identifies, from the data packets exchanged via the first wireless communication band 117 between the UAV 101 and the GCS 109, any high volume server message block (SMB) traffic on the first wireless communication band 117, any rapid and repetitive file read / write operations performed via the first wireless communication band 117, any encrypted payloads embodied in any of the data packets that are in their default unencrypted state, any unusual time delays between the arrival of consecutive data packets at either the UAV 101 or the GCS 109, and unusual data packet lengths.
[0120] Subsequently, if the data packets exchanged between the UAV 101 and the GCS 109 via the first wireless communication band 117 are found, by the machine learning model 113, to signify any unusual file sharing patterns, data exfiltration signatures, or signatures of malicious command and control communications, the machine learning model 113subsequently flags the first wireless communication band 117, and by extension, the UAV 101 or the GCS 109, or both as being prone to a ransomware-based cybersecurity attack. Further, the machine learning model 113 identifies, from the data packets exchanged between the UAV 101 and the GCS 109 via the first wireless communication band 117, any high volume server message block (SMB) traffic, any rapid and repetitive file read / write operations, any encrypted payloads embodied in any of the data packets that are in their default unencrypted state, any unusual time delays between the arrival of consecutive data packets at either the UAV 101 or the GCS 109, and unusual data packet lengths. Upon determining any of the above-identified phenomena to be true, the machine learning model 113 triggers a warning to the GCS 109, indicating the possible onset of the ransomware-based cybersecurity attack, either on the GCS 109 or the UAV 101, or both.
[0121] TECHNICAL ADVANTAGES
[0122] The cybersecurity system and method envisaged by the present disclosure provide significant technical advantages in detecting and mitigating cybersecurity threats and operational risks for Unmanned Aerial Systems (UAS), including Unmanned Aerial Vehicles (UAV), Ground Control Stations (GCS), and Global Navigation Satellite System (GNSS). A key advantage of the cybersecurity system and method of the present disclosure is the real-time monitoring of wireless communication links (interconnecting the UAVs, GCS, and GNSS) using a cloud-based machine learning model. The monitoring of wireless communication links by a cloud-based machine learning model enables the detection and mitigation of a wide variety of cyberattacks, including man-in-the-middle attack, denial of service attack, signal jamming attack, eavesdropping attack, and GPS spoofing attack, inter alia. The cloud-based machine learning model analyzes packet structures, timing, and flow rates and patterns to detect the onset of cybersecurity threats and attacks. The proactive threat detection by the cloud-based machine learning model enables the cybersecurity system to respond before a security breach compromises UAV operations, thereby securing UAVs and serving as an additional layer of defense for UAVs and allied systems, including GCS and GNSS.
[0123] Another technical advantage realized by the cybersecurity system and method is the use of unsupervised machine learning models to identify emerging and previously unseen cybersecurity threats. Unsupervised machine learning models analyze intercepted communication patterns for anomalies without relying on pre-labeled data. Additionally,the deep learning models implemented by the cybersecurity system and method enable the recognition of complex attack signatures and time-series anomalies. The combination of unsupervised and deep learning models used by the cybersecurity system and method facilitates the effective processing of voluminous data, the detection of new attack vectors, and continued adaptability to evolving cybersecurity threats. The cloud-based infrastructure employed by the cybersecurity system and method ensures scalability and flexibility, enables seamless analysis of complex attack signatures and time-series anomalies, and provides real-time updates to the underlying machine learning models, thereby relieving the UAS of the burden of performing the above-mentioned tasks.
[0124] Furthermore, the cybersecurity system and method envisage mitigating collision risk. By collecting and analyzing real-time data from multiple radars and satellites, the cybersecurity system and method predict potential collision risks and trigger alarms, when necessary, thereby enabling UAV operators to make informed decisions regarding corrective actions. The ability to perform real-time risk prediction, combined with a machine learning model that assesses collision likelihood, enhances the UAV's operational safety. In addition, the cybersecurity system and method address vulnerabilities arising from the cyber behaviors of UAVs and allied systems. The cybersecurity system and method continuously assess cybersecurity risks, including phishing, Wi-Fi vulnerabilities, and multi-factor authentication flaws. The use of specialized machine learning models for each vulnerability ensures that the security of the UAVs is continuously monitored and maintained, and not compromised, thereby providing a resilient, fool-proof, and secure framework for conducting and managing UAV operations.
[0125] The cybersecurity system continuously monitors wireless communication links in real time, thereby enabling immediate detection of a variety of cyberattacks, including man-in-the-middle attack, GPS spoofing attack, denial of service attack, and signal jamming attack. The real-time detection of cybersecurity threats enables the cybersecurity system and method to respond immediately to them, regardless of their diversity and seventy, providing timely mitigation and preventing them from escalating beyond control.
[0126] By integrating multiple machine learning models for diverse types of vulnerabilities, viz., Wi-Fi vulnerabilities, phishing-related vulnerabilities, and email phishing-related vulnerabilities, the cybersecurity system and method incorporate a holistic approach to cybersecurity and comprehensively identify and mitigate a wide range of attack vectors. Further, the use of unsupervised machine learning models allows the cybersecuritysystem and method to detect new, previously unseen cybersecurity threats by recognizing anomalies in wireless communication patterns. The use of unsupervised machine learning models introduces adaptability to the cybersecurity system and method and ensures that it can identify hitherto unknown attack strategies without relying on prelabeled training data.
[0127] Further, the use of deep learning models by the cybersecurity system and method enhances the recognition and subsequent classification of complex and diversified cybersecurity attack patterns. The deep learning models also enable analysis of substantial amounts of data and provide a thorough understanding of the higher-level features of communication packets exchanged between the UAVs, GCS, and GNSS. Further, the cloud-based cybersecurity system and method envisaged by the present disclosure facilitate the scalable, flexible processing of vast amounts of data in real time. The ability of the cloud-based cybersecurity system and method to manage large-scale UAS deployments ensures that substantial amounts of data are efficiently processed without overwhelming native data processing resources.
[0128] Further, given the cloud-based setup, the machine learning model deployed by the cloudbased cybersecurity system and method is continuously updated with new data and emerging cybersecurity threats, thereby ensuring the efficiency and effectiveness of the cybersecurity system and method, even in the face of evolving cybersecurity threats and attacks. Further, if the probability of a cybersecurity threat or attack exceeds a predefined threshold, the cybersecurity system triggers an alarm to the GCS, enabling UAV operators to take immediate action to mitigate identified cybersecurity-related risks and secure the UAVs and allied systems against cybersecurity threats and attacks. Further, by continuously monitoring and identifying cybersecurity-related vulnerabilities relevant to the operations of the UAVs, the cybersecurity system also pinpoints the loopholes or weak points (for example, outdated operating systems, weaker user authentication protocols), in the command structure and the operations of the UAVs, thereby ensuring timely remediation and enhancing the overall UAV-specific cybersecurity infrastructure against cyber security threats and attacks.
Claims
CLAIMSWhat is claimed is:
1. A computer-implemented system for detecting and mitigating, in real-time, cybersecurity-related vulnerabilities embodied in a Ground Control Station (GCS) controlling aerial operations of at least one Unmanned Aerial Vehicle (UAV), and cybersecurity attacks directed to said Unmanned Aerial Vehicle and said Ground Control Station, said computer-implemented system comprising:a processor;a memory communicably coupled to said processor, said memory storing computer-executable instructions, which, when executed by said processor, cause said processor to:programmatically acquire, in real-time, pre-flight information corresponding to at least one Unmanned Aerial Vehicle controlled by said Ground Control Station;identify said cybersecurity-related vulnerabilities associated with at least one of said Ground Control Station and said Unmanned Aerial Vehicle, by processing said pre-flight information, and wherein said processor processes said pre-flight information by automatically fitting said pre-flight information into a predetermined mathematical model, based at least on an arrangement, spread, and frequency of values representative of said pre-flight information, and further by iteratively refitting said pre-flight information into a mutually different mathematical model based on a change in at least one of said arrangement, spread, and frequency of values representative of said pre-flight information;programmatically acquire, in real-time, in-flight information corresponding to said Unmanned Aerial Vehicle, as data packets, from wireless communication signals exchanged in-flight between said Unmanned Aerial Vehicle and said Ground Control Station, and analyze said in-flight information embodied in said data packets, and identify at least one manipulation to said data packets; said processor further configured to implement at least one remedial action in response to identifying said manipulation to said data packets, said at least one remedial action comprising:navigating said Unmanned Aerial Vehicle to a corrected flight path determined based on historical, valid telemetry data, instead of GPS data embodied in said data packets exchanged between said Unmanned Aerial Vehicle and Ground Control Station, only in an event any of said data packets are determined as comprising manipulated GPS data; introducing dynamically generated error correction codes into a first wireless communication band used by said Unmanned Aerial Vehicle and said Ground Control Station to exchange said wireless communication signals; andtriggering said Ground Control Station to switch from said first wireless communication band to a predetermined second wireless communication band, in synchronism with said Unmanned Aerial Vehicle, and dynamically changing encryption levels utilized by said second wireless communication band to encrypt said in-flight information.
2. The system as claimed in claim 1 , wherein said processor navigates said Unmanned Aerial Vehicle to said corrected flight path by interfacing directly with said aerial unmanned vehicle, and by relaying to said Unmanned Aerial Vehicle, GPS data corresponding to said corrected flight path, derived from said historical, valid telemetry data, said processor further configured to relay said GPS data corresponding to said corrected flight path, at least until said data packets transmitted from said Ground Control Station are determined to contain genuine GPS data.
3. The system as claimed in claim 2, wherein said processor dynamically updates a plurality of waypoints based on latitude and longitude coordinates derived from said historical, valid telemetry data, and determines said corrected flight path based on updated waypoints.
4. The system as claimed in claim 1 , wherein said processor:triggers said Unmanned Aerial Vehicle and said Ground Control Station to shift from said first wireless communication band to said second wireless communication band in synchrony, thereby reducing a latency associated with switching from said first wireless communication band to said second wireless communication band;triggers said Unmanned Aerial Vehicle to disregard location-related instructions embodied in said data packets transmitted by said GCS via said first wireless communication band, in response to determining that any of said data packets comprise said manipulated GPS data.dynamically modifies said error correction codes implemented on said first wireless communication band, in response to determining that any of said data packets comprise said manipulated UAV-range-related data.
5. The system as claimed in claim 1 , wherein said processor triggers said Ground Control Station to switch from said first wireless communication band to said second wireless communication band, in response to identifying intentional and repetitive disruptions in transmission of said data packets through said first wireless communication band, and wherein said processor dynamically changes said encryption levels across said second wireless communication band and introduces said dynamically generated error correction codes into said second wireless communication band, to mitigate an occurrence of said intentional and repetitive disruptions across said second wireless communication band.
6. The system as claimed in claim 5, wherein said processor is further configured to: dynamically modify said encryption levels of said second wireless communication band by implementing a predetermined asymmetric cryptographic system to initiate a secure key exchange between said UAV and said GCS;generate a session key for a symmetric block cipher, and implement a predetermined cryptographic algorithm to encrypt said data packets based on said session key prior to transm ission of said data packets through said second wireless communication band; andwherein a bit length for said secure key exchange and a length of said session key are determined by said processor based at least on a second set of channel conditions exhibited by said second wireless communication band and said cybersecurity-related vulnerabilities created across said second wireless communication band due to said second set of channel conditions.
7. The system as claimed in claim 5, wherein said processor is further configured to initiate a Frequency Hopping Spread Spectrum (FHSS) protocol, in response to identifying said intentional and repetitive disruptions in said first wirelesscommunication band, said processor further configured to execute a machine learning (ML) model trained at least with a plurality of network quality metrics as training vectors, to differentiate normal network interference from said intentional and repetitive disruptions in said first wireless communication band.
8. The system as claimed in claim 1 , wherein said processor is further configured to: analyze at least one of a packet header, payload, and traffic pattern of each of said data packets, said processor further configured to execute a second machine learning (ML) model trained with a plurality of network infrastructure-related metrics as training vectors, to identify a wireless network communication layer at which said data packets are manipulated; andanalyze at least one of said packet header, said payload, and said traffic pattern of each of said data packets, said processor further configured to execute a third machine learning (ML) model trained with a plurality of network behavior-related metrics as training vectors, to identify at least a type of said cybersecurity attack executed on any of said Unmanned Aerial Vehicle, said Ground Control Station, and said first wireless communication band;said processor further configured to trigger said Ground Control Station and said Unmanned Aerial Vehicle to switch from said first wireless communication band to said second wireless communication band, in response to at least one of said type of said cybersecurity attack and an identification of said wireless network communication layer at which said data packets are manipulated.
9. The system as claimed in claim 8, wherein said processor is further configured to analyze at least one of said header of said data packets, said payload of said data packets, network traffic passing through said first wireless communication band, and characteristics of sessions executed using said first wireless communication band, said processor further configured to execute a fourth machine learning (ML) model trained at least with a baseline of normal wireless network activity, signatures of known threats, signatures of malicious executables, signatures of malicious command and control communications, known characteristics of secured encrypted sessions, and signatures of secured packet flow characteristics, to identify, in real-time, execution of a malwarebased cybersecurity attack on any of said Unmanned Aerial Vehicle, said Ground Control Station, and said first wireless communication band.
10. The system as claimed in claim 9, wherein said processor is further configured to analyze at least one of said header of said data packets and packet metadata stored thereon, said payload of said data packets, said network traffic passing through said first wireless communication band, and file-sharing patterns corresponding to said first wireless communication band, said processor further configured to execute a fifth machine learning (ML) model trained at least with unusual file sharing patterns, data exfiltration signatures, and said signatures of malicious command and control communications, to identify at least one of high volume server message block (SMB) traffic on said first wireless communication band, rapid and repetitive file read / write operations performed via said first wireless communication band, encrypted payloads embodied in any of said data packets, unusual time delays between consecutive data packets, and unusual data packet lengths, and thereby further identify, in real-time, execution of a ransomware-based cybersecurity attack on any of said Unmanned Aerial Vehicle, said Ground Control Station, and said first wireless communication band.
11. The system as claimed in claim 1 , wherein said processor is further configured to: cooperate with an inertial measurement unit (IMU) embodied in said UAV to receive real-time telemetry data indicative of at least said UAV’s real-time position, altitude, and acceleration, said processor further configured to programmatically compare said UAV’s real-time position, altitude, and acceleration with said GPS data embodied in said data packets, said processor further configured to classify said GPS data as said manipulated GPS data, only in an event there exists a mismatch between said GPS data and said real-time telemetry data; and execute a sixth machine learning (ML) model trained at least with baseline values for maximum physical velocity exhibited by said UAV at predetermined time intervals, change in velocity of said UAV in relation to a change in said acceleration of said UAV, a number of satellites communicably coupled to said UAV at each of said predetermined time intervals, carrier-to-noise density ratio observed at each of said satellites communicably coupled to said UAV, difference between a GPS receiver’s internal clock and GPS system time, horizontal dilution of precision (HDOP), and vertical dilution of precision (VDOP) as training vectors, to identify said data packets containing said manipulated GPS data, and to differentiate saiddata packets containing said manipulated GPS data from said data packets containing authentic GPS data.
12. The system as claimed in claim 1, wherein said processor is further configured to programmatically construct at least one predetermined graph embodying at least a high girth and a large shortest cycle, to dynamically generate said error correction codes based at least on said at least one predetermined graph embodying said high girth and said large shortest cycle, and further based on a first set of channel conditions corresponding to said first wireless communication band, determined from an analysis of said data packets exchanged between said UAV and said GCS through said first wireless communication band, said processor further configured to select an optimal error correction code to be introduced into said first wireless communication band, based at least on a variance of noise exhibited by said first wireless communication band and code parameters corresponding to said first wireless communication band, and wherein said processor determines said variance of noise based at least on wireless communication environment and propagation conditions influencing an exchange of said wireless communication signals in-flight between said UAV and GCS via said first wireless communication band, and wherein said code parameters include at least a code rate, a number of input bits, and a number of output bits.
13. A computer-implemented method for detecting and mitigating, in real-time, cybersecurity-related vulnerabilities embodied in a Ground Control Station (GCS) controlling aerial operations of at least one Unmanned Aerial Vehicle (UAV), and cybersecurity attacks directed to said Unmanned Aerial Vehicle and said Ground Control Station, said computer-implemented method comprising the following steps: programmatically acquiring, by a computer-based processor, in real-time, pre-flight information corresponding to said at least one Unmanned Aerial Vehicle; identifying, by said processor, said cybersecurity-related vulnerabilities associated with at least one of said Ground Control Station and said Unmanned Aerial Vehicle, by automatically fitting said pre-flight information into a predetermined mathematical model, based at least on an arrangement, spread, and frequency of values representative of said pre-flight information, and further by iteratively refitting said pre-flight information into a mutually different mathematical modelbased on a change in at least one of said arrangement, spread, and frequency of values representative of said pre-flight information;programmatically acquiring, by said processor, in real-time, in-flight information corresponding to said Unmanned Aerial Vehicle, as data packets, from wireless communication signals exchanged in-flight between said Unmanned Aerial Vehicle and said Ground Control Station, and analyzing said in-flight information embodied in said data packets, and identifying at least one manipulation to said data packets; implementing, by said processor, at least one remedial action in response to identifying said manipulation to said data packets, said at least one remedial action comprising:navigating said Unmanned Aerial Vehicle to a corrected flight path determined based on historical, valid telemetry data, instead of GPS data embodied in said data packets exchanged between said Unmanned Aerial Vehicle and Ground Control Station, only in an event any of said data packets are determined as comprising manipulated GPS data;introducing dynamically generated error correction codes into a first wireless communication band used by said Unmanned Aerial Vehicle and said Ground Control Station to exchange said wireless communication signals; and triggering said Ground Control Station to switch from said first wireless communication band to a predetermined second wireless communication band, in synchronism with said Unmanned Aerial Vehicle, and dynamically changing encryption levels utilized by said second wireless communication band to encrypt said in-flight information.
14. The method as claimed in claim 13, wherein the step of navigating said Unmanned Aerial Vehicle to said corrected flight path further includes:interfacing, by said processor, directly with said Unmanned Aerial Vehicle, and relaying to said Unmanned Aerial Vehicle, GPS data corresponding to said corrected flight path, derived from said historical, valid telemetry data; relaying, by said processor, said GPS data corresponding to said corrected flight path, at least until said data packets transmitted from said Ground Control Station are determined to contain genuine GPS data; anddynamically updating, by said processor, a plurality of waypoints based on latitude and longitude coordinates derived from said historical, valid telemetry data, and determining said corrected flight path based on updated waypoints.
15. The method as claimed in claim 13, wherein the method further includes the following steps:triggering, by said processor, said Unmanned Aerial Vehicle and said Ground Control Station to shift from said first wireless communication band to said second wireless communication band in synchrony, thereby reducing a latency associated with switching from said first wireless communication band to said second wireless communication band;triggering, by said processor, said Unmanned Aerial Vehicle to disregard location-related instructions embodied in said data packets transmitted by said GCS via said first wireless communication band, in response to determining that said data packets contain said manipulated GPS data; anddynamically modifying, by said processor, said error correction codes implemented on said first wireless communication band, in response to determining that any of said data packets contain said manipulated UAV-range- related data.
16. The method as claimed in claim 13, wherein the method further includes a step of triggering, by said processor, said Ground Control Station to switch from said first wireless communication band to said second wireless communication band, in response to identifying intentional and repetitive disruptions in transmission of said data packets through said first wireless communication band; andwherein the step of dynamically modifying said encryption levels across said second wireless communication band includes the following steps:implementing, by said processor, a predetermined asymmetric cryptographic system to initiate a secure key exchange between said UAV and said GCS; generating a session key for a symmetric block cipher, and implementing a predetermined cryptographic algorithm to encrypt said data packets based on said session key prior to transm ission of said data packets through said second wireless communication band; andwherein the method further includes a step of determining, by said processor, a bit length for said secure key exchange and a length of said session key, based at least on a second set of channel conditions exhibited by said second wireless communication band and said cybersecurity-related vulnerabilities created across said second wireless communication band due to said second set of channel conditions.
17. The method as claimed in claim 16, wherein the method further includes a step of initiating, by said processor, a frequency hopping spread spectrum (FHSS) protocol, in response to identifying intentional and repetitive disruptions in said first wireless communication band, and executing, by said processor, a machine learning (ML) model trained at least with a plurality of network quality metrics as training vectors, to differentiate normal network interference from said intentional and repetitive disruptions in said first wireless communication band.
18. The method as claimed in claim 13, wherein the method further includes the following steps:analyzing, by said processor, at least one of a packet header, payload, and traffic pattern of each of said data packets, and executing, by said processor, a second machine learning (ML) model trained with a plurality of network infrastructure- related metrics as training vectors, to identify a wireless network communication layer at which said data packets are manipulated; andanalyzing, by said processor, at least one of said packet header, said payload, and said traffic pattern of each of said data packets, and executing, by said processor, a third machine learning (ML) model trained with a plurality of network behavior- related metrics as training vectors, to identify at least a type of said cybersecurity attack executed on any of said Unmanned Aerial Vehicle, said Ground Control Station, and said first wireless communication band;and wherein the method further includes triggering, by said processor, said Ground Control Station and said Unmanned Aerial Vehicle to switch from said first wireless communication band to said second wireless communication band, in response to at least one of said type of said cybersecurity attack and an identification of said wireless network communication layer at which said data packets are manipulated.
19. The method as claimed in claim 18, wherein the method further includes the following steps:analyzing, by said processor, at least one of said headers of said data packets, said payload of said data packets, network traffic passing through said first wireless communication band, and characteristics of sessions executed using said first wireless communication band;executing, by said processor, a fourth machine learning (ML) model trained at least with a baseline of normal wireless network activity, signatures of known threats, signatures of malicious executables, signatures of malicious command and control communications, known characteristics of secured encrypted sessions, and signatures of secured packet flow characteristics, to identify, in real-time, execution of a malware-based cybersecurity attack on any of said Unmanned Aerial Vehicle, said Ground Control Station, and said first wireless communication band; analyzing, by said processor, at least one of said headers of said data packets and packet metadata stored thereon, said payload of said data packets, said network traffic passing through said first wireless communication band, and file-sharing patterns corresponding to said first wireless communication band; executing, by said processor, a fifth machine learning (ML) model trained at least with unusual file sharing patterns, data exfiltration signatures, and said signatures of malicious command and control communications, to identify at least one of high volume server message block (SMB) traffic on said first wireless communication band, rapid and repetitive file read / write operations performed via said first wireless communication band, encrypted payloads embodied in any of said data packets, unusual time delays between consecutive data packets, and unusual data packet lengths, and thereby further identify, in real-time, execution of a ransomwarebased cybersecurity attack on any of said Unmanned Aerial Vehicle, said Ground Control Station, and said first wireless communication band.
20. The method as claimed in claim 13, wherein the method further includes the following steps:receiving, by said processor, from an inertial measurement unit (IMU) embedded in said UAV, real-time telemetry data indicative of at least said UAV’s real-time position, altitude, and acceleration;programmatically comparing, by said processor, said UAV’s real-time position, altitude, and acceleration with said GPS data embodied in said data packets, and classifying, by said processor, said GPS data as said manipulated GPS data, only in an event where there exists a mismatch between said GPS data and said realtime telemetry data;executing, by said processor, a sixth machine learning (ML) model trained at least with baseline values for maximum physical velocity exhibited by said UAV at predetermined time intervals, change in velocity of said UAV in relation to a change in said acceleration of said UAV, a number of satellites communicably coupled to said UAV at each of said predetermined time intervals, camer-to-noise density ratio observed at each of said satellites communicably coupled to said UAV, difference between a GPS receiver’s internal clock and GPS system time, horizontal dilution of precision (HDOP), and vertical dilution of precision (VDOP) as training vectors, to identify said data packets containing said manipulated GPS data, and to differentiate said data packets containing said manipulated GPS data from said data packets containing authentic GPS data.
21. The method as claimed in claim 13, wherein the step of introducing said dynamically generated error correction codes into said first wireless communication band further includes the following steps:programmatically constructing at least one predetermined graph embodying at least a high girth and a large shortest cycle, and dynamically generating said error correction codes, based at least on said at least one predetermined graph embodying said high girth and said large shortest cycle, and further based on a first set of channel conditions corresponding to said first wireless communication band, determined from an analysis of said data packets exchanged between said UAV and said GCS through said first wireless communication band; selecting an optimal error correction code to be introduced into said first wireless communication band, based at least on a variance of noise exhibited by said first wireless communication band and code parameters corresponding to said first wireless communication band; anddetermining, by said processor, said variance of noise, based at least on wireless communication environment and propagation conditions influencing an exchange of said wireless communication signals in-flight between said UAV and GCS viasaid first wireless communication band, and wherein said code parameters include at least a code rate, a number of input bits, and a number of output bits.
22. A non-transitory computer-readable storage medium having computer-executable instructions embodied thereon, said computer-executable instructions, when executed by a processor, cause said processor to:programmatically acquire, in real-time, pre-flight information corresponding to at least one Unmanned Aerial Vehicle (UAV);identify cybersecurity-related vulnerabilities associated with at least one of a Ground Control Station and said Unmanned Aerial Vehicle, by automatically fitting said pre-flight information into a predetermined mathematical model, based at least on an arrangement, spread, and frequency of values representative of said preflight information, and further by iteratively refitting said pre-flight information into a mutually different mathematical model based on a change in at least one of said arrangement, spread, and frequency of values representative of said pre-flight information;programmatically acquire, in real-time, in-flight information corresponding to said Unmanned Aerial Vehicle, as data packets, from wireless communication signals exchanged in-flight between said Unmanned Aerial Vehicle and said Ground Control Station, and analyze said in-flight information embodied in said data packets, and identify at least one manipulation to said data packets; implement at least one remedial action in response to identifying said manipulation to said data packets, said at least one remedial action comprising: navigating said Unmanned Aerial Vehicle to a corrected flight path determined based on historical, valid telemetry data, instead of GPS data embodied in said data packets exchanged between said Unmanned Aerial Vehicle and Ground Control Station, only in an event any of said data packets are determined as comprising manipulated GPS data;introducing dynamically generated error correction codes into a first wireless communication band used by said Unmanned Aerial Vehicle and said Ground Control Station to exchange said wireless communication signals; andtriggering said Ground Control Station to switch from said first wireless communication band to a predetermined second wireless communication band in synchronism with said Unmanned Aerial Vehicle, and dynamically changing encryption levels utilized by said second wireless communication band to encrypt said in-flight information.
23. The non-transitory computer-readable storage medium as claimed in claim 22, wherein said computer-executable instructions, when executed by said processor, further cause said processor to:interface directly with said aerial unmanned vehicle, and relay to said Unmanned Aerial Vehicle, GPS data corresponding to said corrected flight path, derived from said historical, valid telemetry data;relay said GPS data corresponding to said corrected flight path, at least until said data packets transmitted from said Ground Control Station are determined to contain genuine GPS data;dynamically update a plurality of waypoints based on latitude and longitude coordinates derived from said historical, valid telemetry data, and determine said corrected flight path based on updated waypoints.trigger said Unmanned Aerial Vehicle and said Ground Control Station to shift from said first wireless communication band to said second wireless communication band in synchrony, thereby reducing a latency associated with switching from said first wireless communication band to said second wireless communication band;trigger said Unmanned Aerial Vehicle to disregard location-related instructions embodied in said data packets transmitted by said GCS via said first wireless communication band, in response to determining that said data packets contain said manipulated GPS data; anddynamically modify said error correction codes implemented on said first wireless communication band, in response to determining that any of said data packets contain said manipulated UAV-range-related data.
24. The non-transitory computer-readable storage medium as claimed in claim 22, wherein said computer-executable instructions, when executed by said processor, further cause said processor to:trigger said Ground Control Station to switch from said first wireless communication band to said second wireless communication band, in response to identifying intentional and repetitive disruptions in transmission of said data packets through said first wireless communication band;dynamically change said encryption levels used by said second wireless communication band, to mitigate an occurrence of said intentional and repetitive disruptions across said second wireless communication band, by:implementing a predetermined asymmetric cryptographic system to initiate a secure key exchange between said UAV and said GCS;generating a session key for a symmetric block cipher, and implementing a predetermined cryptographic algorithm to encrypt said data packets based on said session key prior to transmission of said data packets; and determine a bit length for said secure key exchange and a length of said session key, based at least on a second set of channel conditions exhibited by said second wireless communication band and said cybersecurity- related vulnerabilities created across said second wireless communication band due to said second set of channel conditions; andinitiate a frequency hopping spread spectrum (FHSS) protocol, in response to identifying intentional and repetitive disruptions in said first wireless communication band, and execute a machine learning (ML) model trained at least with a plurality of network quality metrics as training vectors, to differentiate normal network interference from said intentional and repetitive disruptions in said first wireless communication band.
25. The non-transitory computer-readable storage medium as claimed in claim 22, wherein said computer-executable instructions, when executed by said processor, further cause said processor to:analyze at least one of a packet header, payload, and traffic pattern of each of said data packets, and execute a second machine learning (ML) model trainedwith a plurality of network infrastructure-related metrics as training vectors, to identify a wireless network communication layer at which said data packets are manipulated; andexecute a third machine learning (ML) model trained with a plurality of network behavior-related metrics as training vectors, to identify at least a type of said cybersecurity attack executed on any of said Unmanned Aerial Vehicle, said Ground Control Station, and said first wireless communication band; trigger said Ground Control Station and said Unmanned Aerial Vehicle to switch from said first wireless communication band to said second wireless communication band, in response to at least one of said type of said cybersecurity attack and an identification of said wireless network communication layer at which said data packets are manipulated;analyze at least network traffic passing through said first wireless communication band, and characteristics of sessions executed using said first wireless communication band;execute a fourth machine learning (ML) model trained at least with a baseline of normal wireless network activity, signatures of known threats, signatures of malicious executables, signatures of malicious command and control communications, known characteristics of secured encrypted sessions, and signatures of secured packet flow characteristics, to identify, in real-time, execution of a malware-based cybersecurity attack on any of said Unmanned Aerial Vehicle, said Ground Control Station, and said first wireless communication band;analyze packet metadata corresponding to said data packets and file-sharing patterns corresponding to said first wireless communication band;execute a fifth machine learning (ML) model trained at least with unusual file sharing patterns, data exfiltration signatures, and said signatures of malicious command and control communications, to identify at least one of high volume server message block (SMB) traffic on said first wireless communication band, rapid and repetitive file read / write operations performed via said first wireless communication band, encrypted payloads embodied in any of said data packets, unusual time delays between consecutive data packets, and unusual datapacket lengths, and thereby further identify, in real-time, execution of a ransomware-based cybersecurity attack on any of said Unmanned Aerial Vehicle, said Ground Control Station, and said first wireless communication band.
26. The non-transitory computer-readable storage medium as claimed in claim 22, wherein said computer-executable instructions, when executed by said processor, further cause said processor to:receive, from an inertial measurement unit (IMU) embedded in said UAV, realtime telemetry data indicative of at least said UAV’s real-time position, altitude, and acceleration;programmatically compare said UAV’s real-time position, altitude, and acceleration with said GPS data embodied in said data packets, and classify said GPS data as said manipulated GPS data, only in an event that there exists a mismatch between said GPS data and said real-time telemetry data; execute a sixth machine learning (ML) model trained at least with baseline values for maximum physical velocity exhibited by said UAV at predetermined time intervals, change in velocity of said UAV in relation to a change in said acceleration of said UAV, a number of satellites communicably coupled to said UAV at each of said predetermined time intervals, carrier-to-noise density ratio observed at each of said satellites communicably coupled to said UAV, difference between a GPS receiver’s internal clock and GPS system time, horizontal dilution of precision (HDOP), and vertical dilution of precision (VDOP) as training vectors, to identify said data packets containing said manipulated GPS data and to differentiate said data packets containing said manipulated GPS data from said data packets containing authentic GPS data; and programmatically construct at least one predetermined graph embodying at least a high girth and a large shortest cycle, and dynamically generate said error correction codes, based at least on said at least one predetermined graph embodying said high girth and said large shortest cycle, and further based on a first set of channel conditions corresponding to said first wireless communication band, determined from an analysis of said data packets exchanged between said UAV and said GCS through said first wireless communication band; andselect an optimal error correction code to be introduced into said first wireless communication band, based at least on a variance of noise exhibited by said first wireless communication band and code parameters corresponding to said first wireless communication band; anddetermine said variance of noise, based at least on wireless communication environment and propagation conditions influencing an exchange of said wireless communication signals in-flight between said UAV and GCS via said first wireless communication band, and wherein said code parameters include at least a code rate, a number of input bits, and a number of output bits.