ADS-B Cyber-Attack Detection Using Machine Learning Anomaly Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

ADS-B systems are vulnerable to cyber-attacks due to the use of unencrypted plaintext messages, which can lead to potential disruptions or catastrophic events in air traffic control.

Innovation Solution

A cyber-attack detection and mitigation system that uses machine learning algorithms and statistical models to identify anomalies in ADS-B messages, extracting specific signal parameters to detect jamming, message injection, and message modification attacks without requiring additional antennas or encrypted communication protocols, and implements Bayesian inference for probability calculations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If unencrypted plaintext messages are used for ADS-B communication, then transmission and interpretation are simplified, but the system becomes vulnerable to cyber-attacks

Engineering Contradiction:
Improvetransmission and interpretation simplicityVSAvoidcyber-attack vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by extracting signal characteristics and generating attack type identifications before final attack detection. Machine learning models are trained in advance on labeled ADS-B data to recognize patterns of various attack types (jamming, message injection, message modification), enabling the system to detect attacks proactively rather than reactively

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary detection layer between the ADS-B message transmission and the air traffic control system. This intermediary system extracts signal characteristics (energy, signal-to-noise ratio, packet error rate) and uses machine learning models to identify attack types, acting as a mediator that filters and analyzes messages before they reach the control system

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If machine learning algorithms are used for attack detection, then detection accuracy is improved, but computational complexity increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The detection system is segmented into distinct functional modules: signal characteristic extraction, attack type identification using machine learning, and mitigation determination. Each module processes specific aspects of the ADS-B signals independently, allowing the complex detection task to be divided into manageable segments that can be processed efficiently

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes parameters by extracting multiple different signal characteristics (energy, signal-to-noise ratio, packet error rate, message interval) and using these varied parameters as inputs to the machine learning models. This multi-parameter approach improves detection accuracy while the models are optimized to process these parameters efficiently

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If comprehensive signal analysis is performed to detect all attack types, then detection coverage is improved, but processing time increases

Engineering Contradiction:
Improveattack type coverageVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system extracts a focused subset of the most relevant signal characteristics (energy, signal-to-noise ratio, packet error rate, message interval) rather than analyzing all possible signal parameters. This partial action approach maintains high detection coverage for different attack types while reducing processing time by concentrating on the most discriminative features

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12149560B2Detection of cyber attacks targeting avionics systems
Publication Date: 2024.11.19 UNIVERSITY OF NORTH DAKOTA
  • US12149560B2 patent drawing
  • US12149560B2 patent drawing
  • US12149560B2 patent drawing

AI summary

The present subject matter provides various technical solutions to technical problems facing ADS-B cyber-attacks. One technical solution for detecting and mitigating ADS-B cyber-attacks includes receiving extracting information from received ADS-B signals, detecting a cyber-attack based on a selected subset of ADS-B information, determining a detection probability, and outputting a ADS-B cyber-attack type and probability. This solution may further include determining and implementing a cyber-attack mitigation to reduce the probability or effect of the detected cyber-attack. These solutions operate based on current ADS-B receiver technology, and can be combined with existing ADS-B receivers to detect message injection attacks, modification attacks, and jamming attacks. The technical solutions described herein use machine learning (ML) algorithms and statistical models to detect anomalies in incoming ADS-B messages. This enables these solutions to be trained in different environments, which further improves the cyber-attack detection accuracy and reduces likelihood of false alarms or miss detections.