Certified Software Image Switching for Cyberattack Disruption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity measures for aircraft engines are inefficient in mitigating cyberattacks due to the time-consuming process of certifying new software versions, leaving systems vulnerable during the certification process and potentially causing catastrophic failures.
Innovation Solution
A method and system for creating multiple functionally equivalent but structurally different software images, which are automatically verified, validated, and certified, allowing for rapid deployment of a second image to counteract detected cyberattacks, thereby reducing certification time and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional software certification processes are used to ensure system safety, then system reliability is improved, but the time required to respond to cyberattacks increases significantly
Solution Approach 1:
Multiple software images with different code level layouts are created in advance before cyberattacks occur. These pre-created images have already undergone verification and validation, so when a cyberattack is detected, a ready-to-deploy alternative image can be immediately activated without going through the full certification process, thus resolving the contradiction between maintaining reliability and reducing response time.
Solution Approach 2:
Instead of modifying and recertifying the original software image when a cyberattack is detected, the system uses pre-created copies (alternative images) with different code level layouts. These copies are functionally equivalent but structurally different, allowing immediate deployment to counter the attack while maintaining system safety without time-consuming recertification.
2Object-affected harmful factors
If software images are created with different code level layouts to disrupt cyberattacks, then security is improved, but system complexity increases
Solution Approach 1:
The software system is divided into multiple discrete images, each with a different code level layout. This segmentation allows the system to switch between images to disrupt cyberattacks. The management complexity is reduced by using automated tools to handle image creation, verification, validation, and deployment, making the segmented architecture practical despite the increased number of components.
Solution Approach 2:
The system changes the code level layout parameter of software images while maintaining functional equivalence. By varying this structural parameter across multiple images, the system can disrupt cyberattacks that target specific code layouts. Automated management tools handle the complexity of managing these parameter variations, balancing security improvement with manageable system complexity.
3Productivity
If automated verification and validation tools are used to create software images, then productivity is improved, but the extent of automation required increases system complexity
Solution Approach 1:
Automated verification and validation tools are used to enable the software image creation and certification process to serve itself. These tools automatically verify and validate the functional equivalence and structural differences of multiple images, reducing the need for manual intervention. This self-service automation dramatically improves productivity while the modular architecture keeps the automation complexity manageable.
Data Source
AI summary
A method includes creating a first image of a software system, creating a second image of the software system including a second code level layout different than the first code level layout, verifying and validating the first and second images of the software system, certifying the first and second images, deploying the first image of the software system on a first operating system, and automatically detecting a first cyberattack being executed on the first image of the software system operating in the first operating system. In response to detecting the first cyberattack being executed on the first image of the software system operating on the first operating system, deploying the second image of the software system on the first operating system in order to disrupt the first cyberattack on the first image of the software system.


