Vehicle Cybersecurity Anomaly Detection via Node State Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex vehicles, such as aircraft, face challenges in cybersecurity as malicious actors can alter microprocessor instructions in hardware components, leading to abnormal operations or false alarms, which can impair flight safety and mission success, highlighting the need for improved cybersecurity measures specifically for hardware components.

Innovation Solution

A method implemented by a computing system on-board the vehicle differentiates between anomalies caused by cybersecurity threats and health degradation in hardware components by comparing node states with stored sets associated with cybersecurity threats and health degradation, using a Cybersecurity Configuration Model Based Reasoner (CCMBR) to identify and address potential breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cybersecurity measures are implemented for hardware components, then security against malicious alterations is improved, but system complexity increases

Engineering Contradiction:
ImprovecybersecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Cybersecurity Configuration Model Based Reasoner (CCMBR) as an intermediary system that mediates between hardware components and the flight control system. The CCMBR receives data from hardware components, compares it against stored cybersecurity models, and determines whether anomalies indicate cybersecurity threats or normal operational variations, thereby protecting the system without requiring direct complex security measures in each hardware component

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the expected hardware behavior through stored cybersecurity models that contain configuration data and operational parameters. These models serve as reference copies that the CCMBR compares against actual hardware behavior to detect deviations indicating cybersecurity threats, allowing security monitoring without modifying the original hardware components

Inventive Principle:
Principle #26Copying

2Measurement precision

If hardware components contain microprocessors for self-monitoring, then operational status detection is improved, but vulnerability to malicious instruction alteration increases

Engineering Contradiction:
Improveoperational status detectionVSAvoidmalicious instruction alteration
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the CCMBR continuously receives operational data from hardware microprocessors, compares it against expected behavior models, and provides feedback to identify when deviations indicate malicious instruction alterations. This feedback loop enables the system to detect cybersecurity threats while maintaining the microprocessors' self-monitoring capabilities

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary action by storing cybersecurity models containing expected operational parameters and configuration data before any potential attack occurs. These pre-stored models serve as reference benchmarks that enable real-time detection of malicious alterations when actual hardware behavior deviates from expected patterns

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If the system monitors all hardware states for security, then detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies local quality by focusing security monitoring on specific critical parameters and configuration data rather than all possible hardware states. The CCMBR selectively monitors parameters that are most indicative of cybersecurity threats, such as configuration changes and operational anomalies, thereby maintaining high detection accuracy while reducing processing time by ignoring less relevant data

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11741226B2Adaptive cybersecurity for vehicles
Publication Date: 2023.08.29 NORTHROP GRUMMAN SYSTEMS CORP
  • US11741226B2 patent drawing
  • US11741226B2 patent drawing
  • US11741226B2 patent drawing

AI summary

A method, implemented by a computing system on-board a vehicle, differentiates whether an anomaly originating from a hardware component of the vehicle is caused by a cybersecurity threat, by a degradation of the performance of the hardware component, or by both. States of the respective nodes in a first group of nodes of the first hardware component are compared with a stored table of sets of states of nodes in the first group. A determination is made of whether the anomaly associated with the first hardware component is caused by a cybersecurity threat or by health degradation of the first hardware component based on the comparison of the states of the nodes of the first group with the sets of possible states of the respective nodes where each set is associated with one of a cybersecurity threat and health degradation.