Avionics Network Obfuscation via Dynamic Map Rotation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems are inadequate in preventing unauthorized users from compiling accurate network mappings, particularly in aircraft networks, which can lead to reconnaissance and potential attacks.
Innovation Solution
A network module is interposed between external-access nodes and avionics buses, generating and switching between multiple artificial network maps to obfuscate the actual network structure, thereby disrupting reconnaissance efforts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If network security systems use static network maps to provide accurate network information, then network transparency and ease of operation are improved, but reconnaissance and unauthorized access become easier
Solution Approach 1:
The patent implements dynamic network map rotation where the network module periodically switches between multiple pre-generated artificial network maps. This dynamic behavior prevents attackers from compiling accurate network mappings through reconnaissance activities, as the network topology appears to change over time. The system maintains ease of operation for authorized users while introducing uncertainty for malicious actors.
Solution Approach 2:
The system creates multiple artificial copies of network maps that differ from the actual network topology. These fabricated network maps are generated in advance and stored in the network module, allowing the system to present misleading network information to external-access nodes. The copies are indistinguishable from real network maps to unauthorized users, effectively obscuring the true network structure.
2Reliability
If network security systems implement comprehensive monitoring and authentication, then unauthorized access is reduced, but system complexity and processing requirements increase
Solution Approach 1:
The network module serves as an intermediary component positioned between the avionics bus and external-access nodes. It handles all authentication and access control functions centrally, filtering malicious requests before they reach critical network resources. This intermediary approach improves security without requiring complex monitoring throughout the entire network, as the network module acts as a single point of control.
Solution Approach 2:
The patent extracts the network mapping function from the actual network topology and places it in the network module as a separate, controllable component. By taking out the network map generation and storage functions into the network module, the system can manage complexity centrally rather than distributed throughout the network. The module handles map rotation and presentation independently from the avionics bus architecture.
3Object-affected harmful factors
If the system rotates network maps frequently to disrupt reconnaissance, then security is improved, but network stability and reliability may deteriorate
Solution Approach 1:
The network module implements periodic rotation of network maps at predetermined time intervals. This periodic action provides consistent security coverage while maintaining predictable behavior patterns that authorized applications can accommodate. The timing mechanism ensures that map rotations occur at intervals long enough to maintain connection stability for legitimate traffic but frequent enough to prevent accurate reconnaissance mapping.
Data Source
AI summary
Mapping of an avionic network is obfuscated by interposing a network module between an external-access node and a bus of an avionics network. First and second network maps are generated and loaded on the network module. The network map accessible to the external-access node is changed from the first network map to the second network map, to disrupt any reconnaissance of the avionics network.


