IP Library Granted Patent US 10,051,475
Granted Patent B2
US 10,051,475 · App. 15/279,425 · Granted Aug 14, 2018

Unmanned aerial vehicle intrusion detection and countermeasures

Inventors: Steve Shattil (Cheyenne, WY); Robi Sen (McLean, VA)
Assignee: Department 13, Inc.
H04W12/12H04L27/0012H04L27/265H04L43/18H04L63/1433H04W12/06H04L69/323
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,051,475
App. No.
15/279,425
Granted
Aug 14, 2018
Kind
B2
Abstract

A system detects unmanned aerial vehicles (UAVs) and deploys electronic countermeasures against one or more UAVs that are determined to be a threat. A signal detector detects radio signals communicated between a remote control unit and UAV. A feature extractor extracts signal features from the detected radio signals, and a classifier processes the detected radio signals based on its signal features and determines whether the detected radio signals correspond to a known or unknown radio protocol. A threat analyzer determines if a detected UAV is a threat based on at least one of remote-sensing data and classification(s) of the detected radio signals. When a UAV system employs an unknown radio protocol, a mitigation engine synthesizes an exploit based on corresponding extracted signal features. A response analyzer detects a response from the UAV system when an exploit is activated and may adapt the exploit based on the response. In some cases, the exploits can be configured against a UAV in autopilot mode.

Claims (37)

1. An apparatus, comprising:

a radio receiver coupled to at least one antenna and configured to detect radio signals communicated between a remote control unit and a remote-controlled vehicle;

a feature extractor comprising at least one processor configured to extract signal features from detected radio signals;

a classifier comprising at least one processor coupled to a classification database and configured to classify the detected radio signals based on the signal features and determine whether the detected radio signals correspond to a known or unknown radio protocol;

a threat analyzer comprising at least one processor configured to determine if a detected remote-controlled vehicle is a threat based on at least one of remote-sensing data and classification of the detected radio signals; and

a mitigation engine comprising at least one processor configured to synthesize an exploit for a remote-control system that employs an unknown radio protocol based on corresponding extracted signal features.

2. The apparatus recited in claim 1 , further comprising a response analyzer configured to detect a response from at least one of the remote-controlled vehicle and the remote control unit when an exploit is activated, update classification of the detected radio signals, and adapt the exploit based on the response.

3. The apparatus recited in claim 1 , wherein the radio receiver is configured to measure a plurality of signal attributes from the detected radio signals, filter the detected radio signals based on the plurality of signal attributes, and couple filtered radio signals to the feature extractor.

4. The apparatus recited in claim 1 , wherein the radio receiver comprises a Fourier transform and the detected radio signals comprise spectrum data produced by the Fourier transform, and a filter configured to select at least one portion of the spectrum data based on at least one filter criterion, the radio receiver configured to couple the at least one portion of the spectrum data to the feature extractor.

5. The apparatus recited in claim 1 , wherein the feature extractor employs at least one of automatic modulation recognition and cyclostationary processing.

6. The apparatus recited in claim 1 , wherein the threat detector is configured to evaluate detected radio signals to determine that at least one remote-controlled vehicle is a threat before the at least one remote-controlled vehicle is airborne.

7. The apparatus recited in claim 1 , wherein the threat detector is configured to evaluate a target system's behavior to determine if it spoofed its authentication data.

8. The apparatus recited in claim 1 , wherein the mitigation engine is configured to employ a protocol attack.

9. A non-transitory computer readable storage medium including processor-executable code for storing instructions operable to:

detect radio signals communicated between a remote control unit and a remote-controlled vehicle;

extract signal features from detected radio signals;

classify the detected radio signals based on the signal features and determine whether the detected radio signals correspond to a known or unknown radio protocol;

determine if a detected remote-controlled vehicle is a threat based on at least one of remote-sensing data and classification of the detected radio signals; and

synthesize an exploit for a remote-control system that employs an unknown radio protocol based on corresponding extracted signal features.

10. The medium recited in claim 9 , further comprising instructions operable to detect a response from at least one of the remote-controlled vehicle and the remote control unit when an exploit is activated, update classification of the detected radio signals, and adapt the exploit based on the response.

11. The medium recited in claim 9 , further comprising instructions operable to measure a plurality of signal attributes from the detected radio signals, filter the detected radio signals based on the plurality of signal attributes, and couple filtered radio signals to a feature extractor.

12. The medium recited in claim 9 , further comprising instructions operable to process the detected radio signals with a Fourier transform to provide detected radio signals comprising spectrum data produced by the Fourier transform, filter the spectrum data based on at least one filter criterion to produce at least one portion of the spectrum data, and couple the at least one portion of the spectrum data to a feature extractor.

13. The medium recited in claim 9 , wherein extract signal features comprises at least one of automatic modulation recognition and cyclostationary processing.

14. The medium recited in claim 9 , wherein determine if the detected remote-controlled vehicle is a threat comprises evaluating detected radio signals to determine that at least one remote-controlled vehicle is a threat before the at least one remote-controlled vehicle is airborne.

15. The medium recited in claim 9 , wherein determine if the detected remote-controlled vehicle is a threat comprises evaluating a target system's behavior to determine if it spoofed its authentication data.

16. The medium recited in claim 9 , wherein synthesize an exploit comprises employing a protocol attack.

17. A method, comprising:

detecting radio signals communicated between a remote control unit and a remote-controlled vehicle;

extracting signal features from detected radio signals;

classifying the detected radio signals based on the signal features to determine whether the detected radio signals correspond to a known or unknown radio protocol;

determining if a detected remote-controlled vehicle is a threat based on at least one of remote-sensing data and classification of the detected radio signals; and

synthesizing an exploit for a remote-control system that employs an unknown radio protocol based on the signal features.

18. The method recited in claim 17 , synthesizing comprises detecting a response from at least one of the remote-controlled vehicle and the remote control unit when an exploit is activated, updating classification of the detected radio signals, and adapting the exploit based on the response.

19. The method recited in claim 17 , wherein detecting comprises measuring a plurality of signal attributes from the detected radio signals, filtering the detected radio signals based on the plurality of signal attributes, and coupling filtered radio signals to a feature extractor.

20. The method recited in claim 17 , wherein the detecting comprises applying a Fourier transform such that the detected radio signals comprise spectrum data, selecting at least one portion of the spectrum data based on at least one filter criterion, and coupling the at least one portion of the spectrum data to the feature extractor.

21. The method recited in claim 17 , wherein determining that at least one remote-controlled vehicle is a threat is based on at least one of the detected radio signal and additional sensor data.

22. The method recited in claim 17 , wherein determining that at least one remote-controlled vehicle is a threat comprises evaluating a target system's behavior to determine if it spoofed authentication data.

Assignments (5)
NUNC PRO TUNC ASSIGNMENT Recorded Mar 8, 2022
From: DEPARTMENT 13, LLC
To: DEPARTMENT 13, INC.
Reel/Frame 059198/0425 →
RELEASE OF SECURITY INTEREST Recorded Feb 14, 2020
From: SARGON CT PTY LTD
To: DEPARTMENT 13, INC. C/O RESAGENT, INC.
Reel/Frame 051825/0752 →
RELEASE OF SECURITY INTEREST Recorded Feb 14, 2020
From: DOMAZET FT3 PTY LTD AS TRUSTEE FOR THE DOMAZET FAMILY TRUST NO. 3
To: DEPARTMENT 13, INC. C/O RESAGENT, INC.
Reel/Frame 051825/0729 →
SECURITY INTEREST Recorded May 14, 2019
From: DEPARTMENT 13, INC.
To: SARGON CT PTY LTD ACN 106 424 088
Reel/Frame 049167/0022 →
SECURITY INTEREST Recorded May 14, 2019
From: DEPARTMENT 13, INC.
To: DOMAZET FT3 PTY LTD AS TRUSTEE FOR THE DOMAZET FAMILY TRUST NO. 3
Reel/Frame 049166/0607 →
Continuity (2)
Provisional Application 62233982 · Sep 28, 2015
Related Publication 20170094527A1 · Mar 30, 2017
Cited By (5)
US 12,266,269 US 12,315,233 US 12,431,030 US 12,610,224 US 12,633,222