Context-Aware Aviation Network Filtering for Cybersecurity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Aviation platforms and infrastructures are vulnerable to cyber security threats due to increased use of networked computing systems and standards-based protocols, which can lead to errors and coverage gaps in network filter rules, necessitating enhanced filtering capabilities to prevent unauthorized network flows.

Innovation Solution

A context-aware message content filtering method and system that automatically filters network messages in aviation networks based on current system context, using processor-generated filter rules that consider attributes like flight phase, device state, and location, to determine message acceptability and enforce constraints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual interpretation is used to create network filter rules, then human control and understanding are maintained, but errors and coverage gaps occur in the filter rules

Engineering Contradiction:
Improvefilter rule accuracyVSAvoidautomatic filter rule generation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system enables automatic generation of network filter rules by having the computing device autonomously analyze its own network data flows and generate corresponding filter rules without requiring manual interpretation, thereby eliminating human errors while maintaining system control

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of interpreting network data flows and creating filter rules with an automated computational system that directly translates network traffic patterns into filter rules, eliminating the intermediate human interpretation step that causes errors

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If standard IETF IP based protocols are used for networking, then seamless integration of e-Enabled architecture is achieved, but vulnerability to cyber security attacks increases

Engineering Contradiction:
Improveintegration capabilityVSAvoidcyber security vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a context-aware filtering system as an intermediary layer between the standard IETF IP protocols and the aviation network devices, which monitors and controls network traffic to prevent unauthorized access while maintaining protocol compatibility and seamless integration

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security checks by establishing filter rules before cyber security threats can exploit the standardized protocols, proactively blocking potential attack vectors while allowing legitimate network communication to proceed uninterrupted

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If context-aware filtering is implemented, then unauthorized network flows are prevented, but system complexity increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidfiltering system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal filtering system that handles multiple network protocols, device types, and security scenarios through a single context-aware framework, reducing overall system complexity by consolidating diverse filtering requirements into one multi-functional solution

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10938689B2System and method for context aware network filtering within an aviation network
Publication Date: 2021.03.02 THE BOEING CO
  • US10938689B2 patent drawing
  • US10938689B2 patent drawing
  • US10938689B2 patent drawing

AI summary

In general, certain embodiments of the present disclosure provide techniques or mechanisms for automatically filtering network messages in an aviation network for an aircraft based on a current system context. According to various embodiments, a method is provided comprising receiving a network message transmitted from a source avionic device to a destination avionic device via one or more network packets within the aviation network. A current system context, indicating an aggregate status of avionic devices within the aviation network, is determined based on monitoring the avionic devices. The network message is analyzed by identifying a plurality of attributes corresponding to header and data fields of the one or more network packets corresponding to the network message. The acceptability of the network message within the current system context is determined based on one or more filter rules that specify what attributes are allowed within a particular system context.