Avionics Network Jitter Surveillance for Cyberattack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Asynchronous communication networks in avionics systems are vulnerable to cybersecurity threats and lack robustness in detecting cyberattacks due to their sensitivity to potential malicious equipment replacements and abnormal network usage.
Innovation Solution
An electronic receiving device is configured to estimate network jitter from the minimum time gap and reception times of data frames, comparing it to an authorized range of values to enhance surveillance and detect anomalies, such as cyberattacks, by using a verification module that can be implemented in software or programmable logic components like FPGAs, and is designed for avionics systems conforming to ARINC 664 standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional surveillance methods using frame number windows are used, then basic redundancy management is achieved, but the system remains vulnerable to cyberattacks and malicious equipment replacement
Solution Approach 1:
The patent implements feedback mechanisms by continuously monitoring received frames and comparing actual reception patterns against expected patterns derived from the sending table. The system uses feedback loops to detect deviations in frame reception timing and sequence, enabling real-time detection of cyberattacks or malicious equipment while maintaining systematic surveillance without excessive complexity
Solution Approach 2:
The patent applies preliminary action by pre-defining sending tables that specify expected frame transmission patterns, including time gaps and sequences. These predetermined patterns serve as reference models against which actual network traffic is compared, allowing the system to proactively identify anomalies before they can cause harm, thus improving cybersecurity robustness without requiring complex real-time analysis
2Reliability
If the network accepts all frames within the predetermined interval, then data reception continuity is maintained, but abnormal frames from cyberattacks cannot be detected
Solution Approach 1:
The patent changes the surveillance parameter from simple frame number verification to comprehensive reception pattern analysis, including timing intervals, sequence continuity, and conformity to predefined sending tables. By monitoring multiple parameters simultaneously, the system can detect subtle anomalies indicative of cyberattacks while maintaining the ability to accept legitimate frames, thus improving anomaly detection capability without making detection excessively difficult
3Adaptability or versatility
If the minimum time gap between frames is not enforced, then network flexibility is improved, but jitter increases making cyberattack detection harder
Solution Approach 1:
The patent applies dynamics by allowing the system to adaptively handle variable frame intervals while maintaining surveillance capabilities. The sending table dynamically defines expected time gaps for different traffic patterns, enabling the network to accommodate flexible traffic requirements while the surveillance mechanism continuously measures actual intervals against expected values, maintaining jitter measurement accuracy even as network conditions change
Data Source
AI summary
This electronic device for receiving data via an asynchronous communication network including at least one elementary network, is configured to be connected to said elementary network and comprises:a receiving module configured to receive several successive data frames via the asynchronous communication network, each frame being sent over the elementary network according to a predefined sending table and with a minimum time gap between the sending time instants of two successive frames,a verification module configured, for at least two received data frames, to estimate a network jitter from the minimum time gap and reception time instants of at least two frames received on said elementary network, then to compare the estimated jitter to an authorized range of network jitter values.


