Avionic Cybersecurity via ARINC 429 Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Aircraft systems are vulnerable to cyber-attacks due to the exposure of digital data exchanged over networks, and existing ground-based systems are not suitable for implementation in aircraft due to size, power, weight, and cost constraints, as well as the incompatibility of traditional IT cybersecurity solutions with ARINC 429 data bus protocols.

Innovation Solution

A computerized system for anomaly detection in avionic communication messages, featuring a bus-message queue, anomaly queue, Cyber-Built In Test mechanism, and rule engine for real-time anomaly detection and alerting, specifically designed for aircraft systems using ARINC 429 protocol, which operates on Commercial Off The Shelf (COTS) components and is airborne certified.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ground-based cyber security systems are implemented in aircraft, then cyber-attack detection capability is improved, but weight, power consumption, size, and cost increase

Engineering Contradiction:
Improvecyber-attack detection capabilityVSAvoidsystem weight
Core Design Contradiction:
ReliabilityVSWeight of moving object

Solution Approach 1:

The patent extracts and implements only the essential anomaly detection functionality needed for avionic systems, rather than deploying complete ground-based cyber security infrastructure. The C-BIT mechanism focuses specifically on detecting anomalies in ARINC 429 bus communications, separating the critical detection capability from the bulky ground-based system architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies localized anomaly detection specifically to ARINC 429 data bus communications within the aircraft, rather than implementing comprehensive security across all aircraft systems. The C-BIT mechanism monitors bus messages at specific points in the avionic network where cyber-attacks are most likely to occur, providing targeted protection without system-wide overhead.

Inventive Principle:
Principle #3Local quality

2Reliability

If traditional IT cyber security solutions are applied to aircraft networks, then security monitoring is improved, but compatibility with ARINC 429 protocol deteriorates

Engineering Contradiction:
Improvesecurity monitoringVSAvoidprotocol compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system changes the operational parameters of anomaly detection to match ARINC 429 protocol characteristics. The C-BIT mechanism uses protocol-specific rules that understand ARINC 429 message formats, labels, and data structures, transforming generic security monitoring into protocol-aware detection that is natively compatible with avionic communication standards.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary layer (the C-BIT mechanism) that sits between the ARINC 429 bus and the anomaly detection logic. This intermediary translates and interprets ARINC 429 specific protocols and message formats into detectable anomaly patterns, enabling security monitoring without direct compatibility requirements with traditional IT solutions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive anomaly detection is implemented for all bus messages, then detection accuracy is improved, but processing time and computational requirements increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidmessage processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the anomaly detection process into distinct modular components: message capture, protocol interpretation, rule evaluation, and anomaly classification. The C-BIT mechanism processes bus messages through separate detection rules that can be independently evaluated, allowing parallel processing and reducing bottlenecks while maintaining comprehensive detection coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial anomaly detection by focusing on the most critical and common attack vectors in ARINC 429 communications. Rather than analyzing every possible message attribute with equal depth, the C-BIT mechanism prioritizes detection of high-risk anomalies such as unauthorized message injection, protocol violations, and redundant system discrepancies, achieving sufficient accuracy with reduced processing overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11729195B1Computerized-system and computerized-method for detecting cyber-attacks on avionic communications of an airborne computerized-device
Publication Date: 2023.08.15 CYVIATION LTD
  • US11729195B1 patent drawing
  • US11729195B1 patent drawing
  • US11729195B1 patent drawing

AI summary

A computerized-system for anomaly detection of Point-to-Point avionic communication messages via a message-bus between an entity to one or more aircraft-systems in an aircraft during phases of flight, is provided herein. The computerized-system may include a bus-message queue to store bus-avionic-communication-messages transmitted via one or more input buses; an anomaly queue to store anomaly bus-messages; a memory to store the bus-message queue and the anomaly queue; a C-BIT mechanism to operate one or more preconfigured test routines; and one or more processors to operate a rule engine based on a preconfigured ruleset to detect one or more anomalies of bus-avionic-communication-messages for each bus-message in the bus-message queue; The rule engine may be configured to store each bus-message that is detected as an anomaly in the anomaly queue and to send one or more alerts to be presented via one or more external devices for each bus-message in the anomaly queue.