On-Board Cyber Security Monitor for Aircraft Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Aircraft networks using AFDX/ARINC 664 protocols are vulnerable to cyber security threats and anomalies, with existing solutions relying on data links that are susceptible to attacks and slow in response, lacking real-time on-board detection and mitigation capabilities.
Innovation Solution
An on-board self-contained cyber security system utilizing artificial intelligence/machine intelligence and advanced machine learning to detect, alert, and optionally mitigate cyber security events and anomalies in real-time without off-aircraft data transmissions, using network taps or software agents to monitor traffic and provide visual and aural warnings to flight crews.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ground-based twin systems with data links are used to detect cyber security events, then detection capability is provided, but response time is slow and the system is vulnerable to attacks on data links and SATCOM terminals
Solution Approach 1:
The patent introduces an on-board cyber security monitor as an intermediary system that sits between the aircraft's network devices and the external environment. This monitor intercepts and analyzes network traffic locally without requiring external data links, thereby eliminating the vulnerability to SATCOM attacks and reducing response time while maintaining detection capability
Solution Approach 2:
The cyber security monitor is designed to be self-contained and autonomous, performing all detection and analysis functions on-board the aircraft without requiring external ground-based systems. The monitor independently evaluates security events, determines anomalies, and generates alerts, making the system self-sufficient and immune to external communication vulnerabilities
2Speed
If AFDX/ARINC 664 networks with TCP/IP protocols are implemented, then data bus speed and hardware commonality are improved, but vulnerability to cyber security threats increases
Solution Approach 1:
The cyber security monitor acts as an intermediary security layer that sits transparently within the AFDX network architecture. It intercepts traffic flows, applies security policies, and blocks malicious packets without disrupting the high-speed data bus operation, thereby maintaining speed while adding security protection
Solution Approach 2:
The system dynamically changes security parameters such as packet filtering rules, access control policies, and anomaly detection thresholds based on real-time network conditions and threat levels. This allows the system to adapt to emerging threats while maintaining optimal network performance and speed
3Reliability
If on-board self-contained cyber security system is implemented, then response time and reliability are improved, but device complexity increases
Solution Approach 1:
The cyber security monitor is segmented into distinct functional modules including traffic interception, packet analysis, anomaly detection, policy enforcement, and alert generation. Each module performs a specific function, making the overall complex system manageable through modular design and independent testing
Solution Approach 2:
The cyber security monitor is designed as a universal platform that can protect multiple different AFDX network configurations and device types across various aircraft models. The system provides multi-functional capabilities including intrusion detection, malware analysis, and security policy enforcement that can be applied to diverse network architectures
Data Source
AI summary
A system, method, and computer readable and executable media for detecting, alerting, managing, and optionally mitigating cyber security events on an aircraft's networks using an on-board cyber security appliance and applications that monitors and detects cyber security events in real time. A software selectable cyber security agent within the cyber security appliance mitigates (if enabled) the effects of a cyber security events and/or anomalies on the aircrafts networks while the aircraft is in-flight and/or on the ground.


