← Back to NASA Technology Projects
Avionics Intrusion Detection and Attack Identification
Completed
TRL 4 (started at 4, targeting 6)
Description
Cyber threat identification includes the ability to detect, track, and disrupt advanced persistent threats. While emerging avionics system architectures support limited cyber hygiene and rudimentary defense, well-tailored cyber-attacks remain elusive to current detection technology. Additionally, the inherent structure of avionics systems makes monitoring and detection difficult. To meet theNASAneed, QED proposes the CyberOverwatchtool that provides a host-based threat detection capability for identifying and correlating attacks targeting aircraft avionics. Overwatch is based onQEDshistory of developing and evaluating avionics malware for assessment and testing of aircraft and the positive results demonstrated during the Phase I effort. Overwatch epitomizes the innovations expected of a NASA sponsored project. To date, there is very little focus on host-based intrusion detection capabilities for embedded device real-time operating systems.The focus of this SBIR effort is novel in that the solution resides at the host-level and provides an ability to encompass end-point security for embedded systems, with flexibility to address the varying communications protocols. The solution also provides systematic reporting to enable in-depth analysis and event correlation.Overwatch shall be tested and validated in a relevant environment to include multiple instances of real-world avionics systems against associated sample malware. We anticipate that by the end of Phase II, we shall demonstrate the ability ofOverwatch to detect malware targeting aircraft avionics systems while adhering to the stringent requirements of operating in the aviation environment. There is not an effective capability for evaluating the security of integrated avionics systems and performing intrusion detection against the growing realization of advanced cyber threats. QED Secure Solutions proposes an Avionics Intrusion Detection and Attack Identification capability that operates in the unique technology environment of aircraft avionics systems with the express goal of detecting, tracking, and predicting threats. The Intrusion Detection and Attack Identification capability is a host-based capability for identifying and correlating attacks targeting aircraft avionics. The innovative technology will meet requirements not currently available to avionics systems: Monitoring of on-board avionics systems for real-time identification of intrusion attempts Effective across multiple platforms Enables data collection to support analysis, event correlation and forensics Requires no additional hardware for the aircraft Whitelist approach to discern legitimate software execution Has demonstrated the ability to detect sample malware targeted for aircraft avionics systems The Phase II effort will focus on further delivering a fully functional prototype of the capability, CYBER OVERWATCH, that can be incorporated into an operational environment against multiple end systems. OVERWATCH epitomizes the innovations expected of a NASA sponsored project.The Phase II effort shall focus on on furthering the novel techniques for host-based embedded device and avionics intrusion detection for developing a fully functional prototype that can be incorporated into an operational environment. Technical Objectives include: Mature the capability to demonstrate effectiveness for multiple avionics systems Demonstrate the ability to detect a range of targeted attacks through implementation of an extensive test corpus of malware Implement Data Analysis Engine that provides full functional ability to ingest, store, characterize, and automatically analyze events/artifacts for signs of vulnerability exploitation Demonstrate the capabilities in a relevant and/or full operational environment OVERWATCH should help provide NASA and the aviation industry, to include commercial airlines and DoD assets operating within the National AirSpace System, real-time capabilities to identify and alert to attacks targeting avionics.
Benefits
Expected benefits and applications for NASA: Ability to readily deploy host-based intrusion detection and distributed attack identification for air-vehicle based systems. Monitoring of critical systems to detect cyber-based attacks in real-time to mitigate safety of flight and operations concerns. Expand novel techniques for embedded device cybersecurity. Integration with In-Time Aviation Safety Management System. Leverage QED advanced experts in the area of avionics cybersecurity. Expected applications extending beyond NASA: Ability to apply solution to commercial fleet of aircraft. Transition technology to Department of Defense. Integration with existing solutions for safeguarding National AirSpace System. Leverage QED relationships to coordinate efforts with Department of Homeland Security, National Labs and industry. Extension to consumer IoT devices.
Details
| Technology area | Flight Computing and Avionics |
| Program | Small Business Innovation Research/Small Business Tech Transfer (SBIR/STTR) |
| Lead organization | Glenn Research Center, Cleveland, OH |
| Start date | 2023-06-02 |
| End date | 2025-06-01 |
Project contacts
Listed on TechPort itself — the most direct way to ask about this specific project.
How to get involved
This is early/mid-stage (TRL 4) — the most realistic path in is NASA SBIR/STTR, which funds small businesses and research institutions to develop technology aligned with NASA's needs (equity-free, phased funding). Check whether a current SBIR/STTR solicitation topic overlaps with this project's technology area, or contact the project directly (above) to ask.
None of these are guaranteed paths for this specific project — TechPort itself doesn't have an "apply" button. Reaching out to the contact(s) above with a specific question is usually the fastest way to find out what's actually open.