Automated IFEC Data Wiping via Attack Severity Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for responding to attacks on in-flight entertainment and communications (IFEC) systems are inadequate, as they require manual and error-prone remote login via Secure Shell (SSH) over IP links, which is time-consuming and inefficient, especially when sensitive data is at risk.
Innovation Solution
A secure application programming interface (API) for remotely wiping selected sensitive data from IFEC systems, utilizing a remote control interface, attack classifier, data sensitivity classification, and data removal engine to automate the deletion of data based on attack severity, thereby reducing the impact of intrusions and associated costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual remote login via SSH is used to respond to attacks, then system administrators can access and manage the IFEC system, but the response time is time-consuming and the process is error-prone
Solution Approach 1:
The system pre-configures multiple attack response plans before attacks occur. Each plan specifies predetermined actions (such as data deletion, service shutdown, or configuration changes) for different attack scenarios. When an attack is detected, the system automatically executes the corresponding pre-configured plan, eliminating the need for manual analysis and decision-making during the attack response phase.
Solution Approach 2:
The IFEC system automatically detects attacks, classifies them by severity, selects appropriate response plans, and executes remediation actions without requiring manual administrator intervention. The system autonomously monitors security events, evaluates threat levels, and implements countermeasures, thereby reducing both response time and human error in attack response operations.
2Productivity
If automated data removal is implemented, then response time is reduced and efficiency is improved, but system complexity increases due to the need for attack classifiers and response plan management
Solution Approach 1:
The automated response system is divided into distinct functional modules: attack detection module, severity classification module, response plan selection module, and execution module. Each module has a specific responsibility, making the overall complex system manageable through clear separation of concerns. The response plans themselves are segmented into different severity levels (first, second, third levels) with corresponding predetermined actions, allowing systematic handling of various attack scenarios.
3Object-affected harmful factors
If all data is deleted in response to attacks, then data security is maximized, but useful data and operational continuity are lost
Solution Approach 1:
Different data deletion policies are applied based on the severity and type of attack detected. First-level attacks trigger deletion of only the specific data files targeted by the attack. Second-level attacks result in deletion of data within affected directories or partitions. Third-level attacks trigger complete system data deletion. This graduated approach ensures that data deletion is proportional to the threat level, minimizing unnecessary loss of useful data while maintaining security for severe threats.
Data Source
AI summary
In the selective wiping of data stored on an aircraft Inflight Entertainment and Communications (IFEC) computer system, a potential attack indicator generated in response to a detection of an attack attempt that is received from a remote manager client computer system. The potential attack indicator includes an attack severity classification, which is correlated to one of a plurality of attack attempt responses. Each of the attack attempt responses correspond to a data sensitivity classification, and each predefined block of data stored on the IFEC computer system is assigned a data sensitivity classification. According to the attack attempt response that was correlated to the received attack severity classification, the predefined blocks of data assigned to the data sensitivity classification corresponding to the attack attempt response are deleted.


