On-Board Cyber Security Monitor for Aircraft Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Aircraft networks using AFDX/ARINC 664 protocols are vulnerable to cyber security threats and anomalies, with existing solutions relying on data links that are susceptible to attacks and slow in response, lacking real-time on-board detection and mitigation capabilities.

Innovation Solution

An on-board self-contained cyber security system utilizing artificial intelligence/machine intelligence and advanced machine learning to detect, alert, and optionally mitigate cyber security events and anomalies in real-time without off-aircraft data transmissions, using network taps or software agents to monitor traffic and provide visual and aural warnings to flight crews.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ground-based twin systems with data links are used to detect cyber security events, then detection capability is provided, but response time is slow and the system is vulnerable to attacks on data links and SATCOM terminals

Engineering Contradiction:
Improvecyber security detection reliabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an on-board cyber security monitor as an intermediary system that sits between the aircraft's network devices and the external environment. This monitor intercepts and analyzes network traffic locally without requiring external data links, thereby eliminating the vulnerability to SATCOM attacks and reducing response time while maintaining detection capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cyber security monitor is designed to be self-contained and autonomous, performing all detection and analysis functions on-board the aircraft without requiring external ground-based systems. The monitor independently evaluates security events, determines anomalies, and generates alerts, making the system self-sufficient and immune to external communication vulnerabilities

Inventive Principle:
Principle #25Self-service

2Speed

If AFDX/ARINC 664 networks with TCP/IP protocols are implemented, then data bus speed and hardware commonality are improved, but vulnerability to cyber security threats increases

Engineering Contradiction:
Improvedata bus speedVSAvoidcyber security vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The cyber security monitor acts as an intermediary security layer that sits transparently within the AFDX network architecture. It intercepts traffic flows, applies security policies, and blocks malicious packets without disrupting the high-speed data bus operation, thereby maintaining speed while adding security protection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes security parameters such as packet filtering rules, access control policies, and anomaly detection thresholds based on real-time network conditions and threat levels. This allows the system to adapt to emerging threats while maintaining optimal network performance and speed

Inventive Principle:
Principle #35Parameter changes

3Reliability

If on-board self-contained cyber security system is implemented, then response time and reliability are improved, but device complexity increases

Engineering Contradiction:
Improvecyber security detection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cyber security monitor is segmented into distinct functional modules including traffic interception, packet analysis, anomaly detection, policy enforcement, and alert generation. Each module performs a specific function, making the overall complex system manageable through modular design and independent testing

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cyber security monitor is designed as a universal platform that can protect multiple different AFDX network configurations and device types across various aircraft models. The system provides multi-functional capabilities including intrusion detection, malware analysis, and security policy enforcement that can be applied to diverse network architectures

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11838302B2Method and system for on-board cyber security
Publication Date: 2023.12.05 STUCK ERIC EDWARD
  • US11838302B2 patent drawing
  • US11838302B2 patent drawing
  • US11838302B2 patent drawing

AI summary

A system, method, and computer readable and executable media for detecting, alerting, managing, and optionally mitigating cyber security events on an aircraft's networks using an on-board cyber security appliance and applications that monitors and detects cyber security events in real time. A software selectable cyber security agent within the cyber security appliance mitigates (if enabled) the effects of a cyber security events and/or anomalies on the aircrafts networks while the aircraft is in-flight and/or on the ground.