IP Library › Granted Patent US 9,938,019
Granted Patent B2
US 9,938,019 · App. 14/718,820 · Granted Apr 10, 2018

Systems and methods for detecting a security breach in an aircraft network

Inventors: David H. Floyd (Kirkland, WA); Jason W. Shelton (Edgewood, WA); John E. Bush (Bothell, WA)
Assignee: THE BOEING COMPANY
B64D45/0015H04L63/14H04L63/1441B64D2045/0045H04L67/12H04W4/046
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,938,019
App. No.
14/718,820
Granted
Apr 10, 2018
Kind
B2
Abstract

A network system of an aircraft implements a target system to attract, detect, log, and mitigate a potential breach by the malicious entities. The target system simulates the systems of the aircraft in order to attract a potential breach. The target system simulates the data, file structure, communications, etc., of the systems of the aircraft. The target system includes little, or no security or access controls in order to attract a potential breach and allow the malicious entity to gain access. Once a breach occurs, the target system can be configured to log, report, and/or mitigate the potential breach.

Claims (56)

1. A system, comprising:

a network system comprising a hardware electronic processor on-board an aircraft;

a plurality of aircraft systems on-board the aircraft and comprising a hardware electronic processor coupled to the network system; and

a target system comprising a hardware electronic processor coupled to the network system, wherein the target system is implemented in at least one of:

the network system on-board the aircraft, or

one or more of the plurality of aircraft systems on-board the aircraft;

wherein the target system comprises a virtual machine instantiated on the network system and is configured to simulate data, file structure, communications, and operations of the plurality of aircraft systems, wherein the plurality of aircraft systems comprises flight systems, operator information systems, an in-flight entertainment system, and an off-board communication system, and

wherein the target system is configured to detect an attempted access of the target system;

monitoring access to the target system;

determining, based on the monitoring, that the attempted access of the target system has occurred; and

logging the attempted access as an attempted breach of the plurality of aircraft systems.

2. The system of claim 1 , wherein the network system is configured to implement security controls to prevent access to the plurality of aircraft systems, and wherein access to the target system is not controlled by the security controls.

3. The system of claim 2 , wherein the target system is configured to alter the security controls in response to the attempted access.

4. The system of claim 1 further comprising:

one or more memory device that are configured to store data representing the attempted access of the target system, wherein the data comprises a network address of an entity attempting access, one or more simulated aircraft systems which were attempted to be accessed, or a time of the attempted access.

5. The system of claim 1 , wherein the target system is configured to report the attempted access to an entity associated with the aircraft.

6. A method, comprising:

initiating a target system that communicates with a network system of an aircraft,

simulating, by the target system, operations of a plurality of aircraft systems on-board the aircraft,

wherein the target system is implemented in at least one of:

the network system on-board the aircraft, or

one or more of the plurality of aircraft systems on-board the aircraft, and

wherein the target system comprises a virtual machine instantiated on the network system and is configured to simulate data, file structure, communications, and operations of the plurality of aircraft systems, wherein the plurality of aircraft systems comprises flight systems, operator information systems, an in-flight entertainment system, and an off-board communication system; and

wherein the target system is configured to detect an attempted access of the target system;

monitoring access to the target system;

determining, based on the monitoring, that the attempted access of the target system has occurred; and

logging the attempted access as an attempted breach of the plurality of aircraft systems.

7. The method of claim 6 , the method further comprising:

reporting the attempted breach to an entity associated with the aircraft.

8. The method of claim 6 , the method further comprising:

determining that the attempted breach targeted a critical system of the plurality of aircraft systems; and

reporting the attempted breach based on the attempted breach targeted the critical system.

9. The method of claim 6 , the method further comprising:

altering security controls of the network system based on detecting the attempted breach.

10. The method of claim 6 , wherein logging the attempted access comprises:

storing data representing the attempted access of the target system, wherein the data comprises a network address of an entity attempting access, one or more simulated aircraft systems which were attempted to be accessed, or a time of the attempted access.

11. A non-transitory computer readable medium comprising instructions for causing one or more processors to perform a method, the method comprising:

initiating a target system that communicates with a network system of an aircraft,

simulating, by the target system, operations of a plurality of aircraft systems on-board the aircraft,

wherein the target system is implemented in at least one of:

the network system on-board the aircraft, or

one or more of the plurality of aircraft systems on-board the aircraft, and

wherein the target system comprises a virtual machine instantiated on the network system and is configured to simulate data, file structure, communications, and operations of the plurality of aircraft systems, wherein the plurality of aircraft systems comprises flight systems, operator information systems, an in-flight entertainment system, and an off-board communication system; and

wherein the target system is configured to detect an attempted access of the target system;

monitoring access to the target system;

determining, based on the monitoring, that the attempted access of the target system has occurred; and

logging the attempted access as an attempted breach of the plurality of aircraft systems.

12. The non-transitory computer readable medium of claim 11 , the method further comprising:

reporting the attempted breach to an entity associated with the aircraft.

13. The non-transitory computer readable medium of claim 11 , the method further comprising:

determining that the attempted breach targeted a critical system of the plurality of aircraft systems; and

reporting the attempted breach based on the attempted breach targeted the critical system.

14. The non-transitory computer readable medium of claim 11 , the method further comprising:

altering security controls of the network system based on detecting the attempted breach.

15. The non-transitory computer readable medium of claim 11 , wherein logging the attempted access comprises:

storing data representing the attempted access of the target system, wherein the data comprises a network address of an entity attempting access, one or more simulated aircraft systems which were attempted to be accessed, or a time of the attempted access.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2015
From: FLOYD, DAVID H.; SHELTON, JASON W.; BUSH, JOHN E.
To: THE BOEING COMPANY
Reel/Frame 035692/0501 →
Continuity (1)
Related Publication 20160340055A1 · Nov 24, 2016