Avionics Network Obfuscation via Dynamic Map Rotation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems are inadequate in preventing unauthorized users from compiling accurate network mappings, particularly in aircraft networks, which can lead to reconnaissance and potential attacks.

Innovation Solution

A network module is interposed between external-access nodes and avionics buses, generating and switching between multiple artificial network maps to obfuscate the actual network structure, thereby disrupting reconnaissance efforts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network security systems use static network maps to provide accurate network information, then network transparency and ease of operation are improved, but reconnaissance and unauthorized access become easier

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidreconnaissance vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic network map rotation where the network module periodically switches between multiple pre-generated artificial network maps. This dynamic behavior prevents attackers from compiling accurate network mappings through reconnaissance activities, as the network topology appears to change over time. The system maintains ease of operation for authorized users while introducing uncertainty for malicious actors.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system creates multiple artificial copies of network maps that differ from the actual network topology. These fabricated network maps are generated in advance and stored in the network module, allowing the system to present misleading network information to external-access nodes. The copies are indistinguishable from real network maps to unauthorized users, effectively obscuring the true network structure.

Inventive Principle:
Principle #26Copying

2Reliability

If network security systems implement comprehensive monitoring and authentication, then unauthorized access is reduced, but system complexity and processing requirements increase

Engineering Contradiction:
Improveaccess securityVSAvoidnetwork module complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network module serves as an intermediary component positioned between the avionics bus and external-access nodes. It handles all authentication and access control functions centrally, filtering malicious requests before they reach critical network resources. This intermediary approach improves security without requiring complex monitoring throughout the entire network, as the network module acts as a single point of control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the network mapping function from the actual network topology and places it in the network module as a separate, controllable component. By taking out the network map generation and storage functions into the network module, the system can manage complexity centrally rather than distributed throughout the network. The module handles map rotation and presentation independently from the avionics bus architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If the system rotates network maps frequently to disrupt reconnaissance, then security is improved, but network stability and reliability may deteriorate

Engineering Contradiction:
Improvereconnaissance disruptionVSAvoidnetwork connection stability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The network module implements periodic rotation of network maps at predetermined time intervals. This periodic action provides consistent security coverage while maintaining predictable behavior patterns that authorized applications can accommodate. The timing mechanism ensures that map rotations occur at intervals long enough to maintain connection stability for legitimate traffic but frequent enough to prevent accurate reconnaissance mapping.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11889392B2Aircraft network cybersecurity apparatus and methods
Publication Date: 2024.01.30 THE BOEING CO
  • US11889392B2 patent drawing
  • US11889392B2 patent drawing
  • US11889392B2 patent drawing

AI summary

Mapping of an avionic network is obfuscated by interposing a network module between an external-access node and a bus of an avionics network. First and second network maps are generated and loaded on the network module. The network map accessible to the external-access node is changed from the first network map to the second network map, to disrupt any reconnaissance of the avionics network.