Cyber Warning Receiver for MIL-STD-1553 Bus Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack effective passive monitoring, active defense, and forensic data collection capabilities to detect and prevent cyberattacks, especially zero-day attacks, on embedded bus systems used in critical applications, as they are not well-suited for non-traditional communication networks and are vulnerable to unknown threats.

Innovation Solution

A cyber warning receiver (CWR) system that employs an anomaly-based approach using machine learning techniques to detect and classify anomalous bus traffic, fusing data from multiple sources to identify normal and abnormal behavior, and providing real-time alerts and post-mission analysis, specifically designed for legacy platforms like avionics systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based detection methods are used, then known threats can be identified, but zero-day attacks and unknown threats cannot be detected

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcapability to detect unknown threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system transitions from signature-based detection to anomaly-based detection by changing the fundamental detection parameter from known threat patterns to deviations from normal behavior. The anomaly detector continuously learns normal bus traffic patterns and identifies threats as anomalies, enabling detection of zero-day attacks while maintaining reliability through machine learning techniques.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary learning of normal behavior patterns before actual threat detection begins. During a training phase, the anomaly detector establishes a baseline of normal bus traffic characteristics without requiring any threat signatures. This preliminary action enables the system to detect unknown threats from the start of operational monitoring.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If passive monitoring capabilities are added to legacy systems, then cyber threat detection is improved, but system complexity increases

Engineering Contradiction:
Improvecyber security monitoring capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring function is segmented as a separate anomaly detector module that interfaces with the legacy bus system without modifying existing components. The CWR architecture divides the system into distinct functional blocks (bus monitor, anomaly detector, data fuser, behavior logger) that can be added incrementally to legacy platforms, managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The anomaly detector serves as an intermediary component between the legacy bus system and the security monitoring functions. It translates legacy bus traffic into analyzable data formats and provides a standardized interface for threat detection, allowing passive monitoring capabilities to be added without directly modifying the complex legacy system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If real-time anomaly detection is implemented, then active defense capability is improved, but processing requirements and system resource usage increase

Engineering Contradiction:
Improveactive defense capabilityVSAvoidprocessing resource consumption
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The anomaly detector focuses on detecting specific anomalous patterns rather than analyzing every aspect of bus traffic in real-time. The system uses heuristics and machine learning models that process only the most relevant features of bus traffic, providing sufficient active defense capability while managing processing resources through selective rather than exhaustive analysis.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10728265B2Cyber warning receiver
Publication Date: 2020.07.28 BAE SYSTEMS INFORMATION ANDELECTRONIC SYSTEMS INTEGRATION INC
  • US10728265B2 patent drawing
  • US10728265B2 patent drawing
  • US10728265B2 patent drawing

AI summary

Techniques are provided for cyber warning. One technique includes a cyber warning receiver (CWR). The CWR includes a bus sensing circuit to sense traffic on a communications bus over time, an anomaly detecting circuit to detect anomalous behavior in the sensed bus traffic, a data fusing circuit to fuse the detected anomalous behavior into groups having similar characteristics, a decision making circuit to decide if the fused anomalous behavior is normal or abnormal, and a behavior logging circuit to log the detected anomalous behavior on an electronic storage device. In one embodiment, the CWR further includes a behavior alerting circuit to alert an operator to the fused anomalous behavior identified as abnormal. In one embodiment, the communications bus is an embedded communications bus, such as a MIL-STD-1553 bus, and the CWR is a standalone device configured to connect to the MIL-STD-1553 bus as a bus monitor.