IP Library Granted Patent US 9,774,628
Granted Patent B2
US 9,774,628 · App. 14/829,889 · Granted Sep 26, 2017

Method for analyzing suspicious activity on an aircraft network

Inventors: Daniel Nguyen (Auburn, WA); Marissa A. Nishimoto (Seattle, WA); George C. Chang (Seattle, WA)
Assignee: THE BOEING COMPANY
H04L63/1491H04L63/1433H04L2463/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,774,628
App. No.
14/829,889
Granted
Sep 26, 2017
Kind
B2
Abstract

An aircraft includes an aircraft network having nodes and links and a sandbox network in communication with the aircraft network. The sandbox network simulates the aircraft network and includes sandbox nodes corresponding to the nodes of the aircraft network, a first set of sandbox links corresponding to the links of the aircraft network, and a second set of sandbox links providing communication between sandbox nodes not in communication via the first set of sandbox links. Computer executable instructions, when executed, perform the steps of: generating network traffic over the sandbox network such that the sandbox network models a behavior of the aircraft network; identifying a suspicious activity on the aircraft network; routing the suspicious activity from the aircraft network to the sandbox network; and analyzing the suspicious activity as the suspicious activity traverses through the sandbox network.

Claims (31)

1. A method for analyzing a suspicious activity on an aircraft network, comprising the steps of:

creating a sandbox network in communication with the aircraft network, the sandbox network simulating the aircraft network and comprising a plurality of sandbox nodes corresponding to a plurality of nodes of the aircraft network, a first set of sandbox links corresponding to a plurality of links of the aircraft network that provide communication between a subset of the plurality of nodes of the aircraft network, and a second set of sandbox links providing communication between sandbox nodes not in communication via the first set of sandbox links;

generating network traffic over the sandbox network such that the sandbox network models a behavior of the aircraft network;

routing the suspicious activity from the aircraft network to the sandbox network, wherein the suspicious activity originates from a node on the aircraft network or a user interface to an avionics system; and

analyzing the suspicious activity as the suspicious activity traverses through the sandbox network, wherein analyzing the suspicious activity comprises collecting forensic data about the suspicious activity.

2. The method of claim 1 , wherein at least a portion of the plurality of nodes comprise line replaceable units.

3. The method of claim 1 , wherein routing the suspicious activity is transparent to source of the suspicious activity.

4. The method of claim 1 , wherein the forensic data comprises at least one of communications traffic, attack chains, tendencies, and geographical location of the source of the suspicious activity.

5. The method of claim 1 , further comprising the step of creating, adapting, or updating a cyber-security procedure based on the collected forensic data.

6. A method for analyzing a suspicious activity on an aircraft network, comprising the steps of:

identifying the suspicious activity originating from a node on the aircraft network or a user interface to an avionics system;

routing the suspicious activity from the aircraft network to a sandbox network; and

analyzing the suspicious activity as the suspicious activity traverses through the sandbox network; wherein

the sandbox network simulates the aircraft network and includes a plurality of sandbox nodes corresponding to a plurality of nodes of the aircraft network, a first set of sandbox links corresponding to a plurality of links of the aircraft network between a subset of the plurality of nodes, and a second set of sandbox links providing communication between sandbox nodes not in communication via the first set of sandbox links; and

analyzing the suspicious activity comprises collecting forensic data about the suspicious activity.

7. The method of claim 6 , wherein at least a portion of the plurality of nodes of the aircraft network comprise line replaceable units.

8. The method of claim 6 , wherein routing the suspicious activity is transparent to source of the suspicious activity.

9. The method of claim 6 , wherein the forensic data comprises at least one of communications traffic, attack chains, tendencies, and geographical location of the source of the suspicious activity.

10. The method of claim 6 , further comprising the step of creating, adapting, or updating a cyber-security procedure based on the collected forensic data.

11. An aircraft, comprising:

an aircraft network comprising a plurality of nodes and a plurality of links providing communication between a subset of the plurality of nodes;

a sandbox network in communication with the aircraft network, the sandbox network simulating the aircraft network and comprising a plurality of sandbox nodes corresponding to the plurality of nodes of the aircraft network, a first set of sandbox links corresponding to the plurality of links of the aircraft network, and a second set of sandbox links providing communication between sandbox nodes not in communication via the first set of sandbox links; and

computer executable instructions that, when executed by a processor, perform the steps of:

generating network traffic over the sandbox network such that the sandbox network models a behavior of the aircraft network;

identifying a suspicious activity on the aircraft network, the suspicious activity originating from one of the plurality of nodes on the aircraft network or a user interface to an avionics system;

routing the suspicious activity from the aircraft network to the sandbox network; and

analyzing the suspicious activity as the suspicious activity traverses through the sandbox network, wherein analyzing the suspicious activity comprises collecting forensic data about the suspicious activity.

12. The aircraft of claim 11 , wherein the aircraft network comprises an Ethernet.

13. The aircraft of claim 11 , wherein at least a portion of the plurality of nodes comprise line replaceable units.

14. The aircraft of claim 11 , wherein routing the suspicious activity is transparent to source of the suspicious activity.

15. The aircraft of claim 11 , further comprising the step of creating, adapting, or updating a cyber-security procedure based on the collected forensic data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2015
From: NGUYEN, DANIEL; NISHIMOTO, MARISSA A.; CHANG, GEORGE C.
To: THE BOEING COMPANY
Reel/Frame 036361/0220 →
Continuity (1)
Related Publication 20170054752A1 · Feb 23, 2017