IP Library Granted Patent US 11,425,155
Granted Patent B2
US 11,425,155 · App. 16/817,503 · Granted Aug 23, 2022

Monitoring the integrity of a space vehicle

Inventors: Adam Neal Jones (Santa Clarita, CA); Nicholas Cameron Cohen (Long Beach, CA); Jonathan Lin (El Segundo, CA); Douglas Robert Woodward (Redondo Beach, CA); Jacquelyn Christina Andrade (Rancho Cucamonga, CA); Eric John McDonald (Newbury Park, CA); Michael Harvey Cole (Torrance, CA)
Assignee: THE AEROSPACE CORPORATION
H04L63/1425G06N5/04G06N20/00H04L43/08H04L63/145H04L67/12G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,425,155
App. No.
16/817,503
Granted
Aug 23, 2022
Kind
B2
Abstract

Space system TT&C monitoring includes analyzing network traffic comprising of data packets between a front-end processor (FEP) and a cryptographic unit. A JavaScript Object Notation (JSON) object is created when the network traffic containing a vehicle command is detected. The JSON object is transmitted, by way of a data transport mechanism, to either a cyber defense module or a security information and event management (SIEM) module for further ingestions and visualization. The JSON object is analyzed using machine learning (ML) module or a rule-based intrusion detection system (IDS) module to generate an anomaly score for the SIEM module for further ingestions and visualization.

Claims (52)

1. A computer-implemented method, comprising:

analyzing network traffic comprising of data packets between a front-end processor (FEP) and a cryptographic unit;

creating a JavaScript Object Notation (JSON) object when the network traffic containing a vehicle command is detected;

transmitting the JSON object, by way of a data transport mechanism, to either a cyber defense module or a security information and event management (SIEM) module for further ingestions and visualization;

analyzing the JSON object using machine learning (ML) module or a rule-based intrusion detection system (IDS) module to generate an anomaly score for the SIEM module for further ingestions and visualization.

2. The computer-implemented method of claim 1 , further comprising:

capturing the data packets containing one or more vehicles commands prior to the data packets entering a cryptographic unit to negate manipulation of the data packets by a third party intruder device, wherein

a one-way network test access point (TAP) is deployed to capture the data packets.

3. The computer-implemented method of claim 1 , wherein the creating of the JSON object comprises creating the JSON object with the network traffic and vehicle command, and enhancing the JSON object with data for a specific mission.

4. The computer-implemented method of claim 1 , wherein the analyzing of the JSON object comprising detecting an attempt to upload a known malware to a vehicle by analyzing contents of upload frames in the data packets and a specific binary signature of the known malware.

5. The computer-implemented method of claim 4 , wherein the analyzing of the JSON object comprising utilizing one or more indicators to detect a cyber-attack in the data packet.

6. The computer-implemented method of claim 4 , wherein the analyzing of the JSON object comprising utilizing one or more rules to detect specific patterns in the one or more indicators that signal a cyber-attack within a context of a space system.

7. The computer-implemented method of claim 1 , wherein the analyzing of the JSON object comprising monitoring and detecting, using the ML module, anomalies in the vehicle command sent by mission systems to a vehicle.

8. An apparatus, comprising:

at least one processor; and

memory comprising a set of instructions, wherein

the set of instructions is configured to cause the at least one processor to execute:

analyzing network traffic comprising of data packets between a front-end processor (FEP) and a cryptographic unit;

creating a JavaScript Object Notation (JSON) object when the network traffic containing a vehicle command is detected;

transmitting the JSON object, by way of a data transport mechanism, to either a cyber defense module or a security information and event management (SIEM) module for further ingestions and visualization;

analyzing the JSON object using machine learning (ML) module or a rule-based intrusion detection system (IDS) module to generate an anomaly score for the SIEM module for further ingestions and visualization.

9. The apparatus of claim 8 , wherein the set of instructions is further configured to cause the at least one processor to execute:

capturing the data packets containing one or more vehicles commands prior to the data packets entering a cryptographic unit to negate manipulation of the data packets by a third party intruder device, wherein

a one-way network test access point (TAP) is deployed to capture the data packets.

10. The apparatus of claim 8 , wherein the set of instructions is further configured to cause the at least one processor to execute:

creating the JSON object with the network traffic and vehicle command, and enhancing the JSON object with data for a specific mission.

11. The apparatus of claim 8 , wherein the set of instructions is further configured to cause the at least one processor to execute:

detecting an attempt to upload a known malware to a vehicle by analyzing contents of upload frames in the data packet and a specific binary signature of the known malware.

12. The apparatus of claim 11 , wherein the set of instructions is further configured to cause the at least one processor to execute:

utilizing one or more indicators to detect a cyber-attack in the data packet.

13. The apparatus of claim 11 , wherein the set of instructions is further configured to cause the at least one processor to execute:

utilizing one or more rules to detect specific patterns in the one or more indicators that signal a cyber-attack within a context of a space system.

14. The apparatus of claim 8 , wherein the set of instructions is further configured to cause the at least one processor to execute:

monitoring and detecting, using the ML module, anomalies in the vehicle command sent by mission systems to a vehicle.

15. A non-transitory computer readable comprising a computer program to be executed by at least one processor to perform;

analyzing network traffic comprising of data packets between a front-end processor (FEP) and a cryptographic unit;

creating a JavaScript Object Notation (JSON) object when the network traffic containing a vehicle command is detected;

transmitting the JSON object, by way of a data transport mechanism, to either a cyber defense module or a security information and event management (SIEM) module for further ingestions and visualization;

analyzing the JSON object using machine learning (ML) module or a rule-based intrusion detection system (IDS) module to generate an anomaly score for the SIEM module for further ingestions and visualization.

16. The non-transitory computer readable medium of claim 15 , wherein the computer program is further configured to cause the at least one processor to execute:

capturing the data packets containing one or more vehicles commands prior to the data packets entering a cryptographic unit to negate manipulation of the data packets by a third party intruder device, wherein

a one-way network test access point (TAP) is deployed to capture the data packets.

17. The non-transitory computer readable medium of claim 15 , wherein the computer program is further configured to cause the at least one processor to execute:

creating the JSON object with the network traffic and vehicle command, and enhancing the JSON object with data for a specific mission.

18. The non-transitory computer readable medium of claim 15 , wherein the computer program is further configured to cause the at least one processor to execute:

detecting an attempt to upload a known malware to a vehicle by analyzing contents of upload frames in the data packets and a specific binary signature of the known malware.

19. The non-transitory computer readable medium of claim 18 , wherein the computer program is further configured to cause the at least one processor to execute:

utilizing one or more indicators to detect a cyber-attack in the data packet.

20. The non-transitory computer readable medium of claim 18 , wherein the computer program is further configured to cause the at least one processor to execute:

utilizing one or more rules to detect specific patterns in the one or more indicators that signal a cyber-attack within a context of a space system.

21. The non-transitory computer readable medium of claim 15 , wherein the computer program is further configured to cause the at least one processor to execute:

monitoring and detecting, using the ML module, anomalies in the vehicle command sent by mission systems to a vehicle.

Assignments (2)
CONFIRMATORY LICENSE Recorded Sep 7, 2023
From: THE AEROSPACE CORPORATION
To: THE GOVERNMENT OF THE UNITED STATES AS REPRESENTED BY THE SECRETARY OF THE AIR FORCE
Reel/Frame 064823/0494 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2020
From: JONES, ADAM NEAL; COHEN, NICHOLAS CAMERON; LIN, JONATHAN; WOODWARD, DOUGLAS ROBERT; ANDRADE, JACQUELYN CHRISTINA; MCDONALD, ERIC JOHN; COLE, MICHAEL HARVEY
To: THE AEROSPACE CORPORATION
Reel/Frame 052103/0114 →
Continuity (1)
Related Publication 20210288984A1 · Sep 16, 2021