Vehicle Cybersecurity Anomaly Detection via Node State Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex vehicles, such as aircraft, face challenges in cybersecurity as malicious actors can alter microprocessor instructions in hardware components, leading to abnormal operations or false alarms, which can impair flight safety and mission success, highlighting the need for improved cybersecurity measures specifically for hardware components.
Innovation Solution
A method implemented by a computing system on-board the vehicle differentiates between anomalies caused by cybersecurity threats and health degradation in hardware components by comparing node states with stored sets associated with cybersecurity threats and health degradation, using a Cybersecurity Configuration Model Based Reasoner (CCMBR) to identify and address potential breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cybersecurity measures are implemented for hardware components, then security against malicious alterations is improved, but system complexity increases
Solution Approach 1:
The patent introduces a Cybersecurity Configuration Model Based Reasoner (CCMBR) as an intermediary system that mediates between hardware components and the flight control system. The CCMBR receives data from hardware components, compares it against stored cybersecurity models, and determines whether anomalies indicate cybersecurity threats or normal operational variations, thereby protecting the system without requiring direct complex security measures in each hardware component
Solution Approach 2:
The patent creates a copy of the expected hardware behavior through stored cybersecurity models that contain configuration data and operational parameters. These models serve as reference copies that the CCMBR compares against actual hardware behavior to detect deviations indicating cybersecurity threats, allowing security monitoring without modifying the original hardware components
2Measurement precision
If hardware components contain microprocessors for self-monitoring, then operational status detection is improved, but vulnerability to malicious instruction alteration increases
Solution Approach 1:
The patent implements a feedback mechanism where the CCMBR continuously receives operational data from hardware microprocessors, compares it against expected behavior models, and provides feedback to identify when deviations indicate malicious instruction alterations. This feedback loop enables the system to detect cybersecurity threats while maintaining the microprocessors' self-monitoring capabilities
Solution Approach 2:
The patent performs preliminary action by storing cybersecurity models containing expected operational parameters and configuration data before any potential attack occurs. These pre-stored models serve as reference benchmarks that enable real-time detection of malicious alterations when actual hardware behavior deviates from expected patterns
3Measurement precision
If the system monitors all hardware states for security, then detection accuracy is improved, but processing time increases
Solution Approach 1:
The patent applies local quality by focusing security monitoring on specific critical parameters and configuration data rather than all possible hardware states. The CCMBR selectively monitors parameters that are most indicative of cybersecurity threats, such as configuration changes and operational anomalies, thereby maintaining high detection accuracy while reducing processing time by ignoring less relevant data
Data Source
AI summary
A method, implemented by a computing system on-board a vehicle, differentiates whether an anomaly originating from a hardware component of the vehicle is caused by a cybersecurity threat, by a degradation of the performance of the hardware component, or by both. States of the respective nodes in a first group of nodes of the first hardware component are compared with a stored table of sets of states of nodes in the first group. A determination is made of whether the anomaly associated with the first hardware component is caused by a cybersecurity threat or by health degradation of the first hardware component based on the comparison of the states of the nodes of the first group with the sets of possible states of the respective nodes where each set is associated with one of a cybersecurity threat and health degradation.


