=Paper= {{Paper |id=Vol-1304/STIDS2014_T06 |storemode=property |title=Security Requirements Analysis of ADS-B Networks |pdfUrl=https://ceur-ws.org/Vol-1304/STIDS2014_T06_KacemEtAl.pdf |volume=Vol-1304 |dblpUrl=https://dblp.org/rec/conf/stids/KacemWCB14 }} ==Security Requirements Analysis of ADS-B Networks== https://ceur-ws.org/Vol-1304/STIDS2014_T06_KacemEtAl.pdf
 Security Requirements Analysis of ADS-B Networks
    Thabet Kacem, Duminda Wijesekera, Paulo Costa                                                Alexandre Barreto
                   Center of Excellence in C4I                                          Instituto de Controle do Espaço Aéreo
                    George Mason University                                              Centro Tecnológico da Aeronáutica
                        Fairfax, Virginia                                                 São José dos Campos, SP - Brazil
              [tkacem, dwijesek, pcosta]@gmu.edu                                                barretoabb@icea.gov.br


Abstract— Due to their many advantages over their hardware-                 Francillon [4] and Schäfer et al. [5], who described the
based counterparts, Software Defined Radios are becoming the                possibility of eavesdropping, man-in-the-middle and denial of
new paradigm for radio and radar applications. In particular,               service attacks in simulated environments.
Automatic Dependent Surveillance-Broadcast (ADS-B) is an
emerging software defined radar technology, which has been                      Unfortunately, most research efforts aimed at detecting and
already deployed in Europe and Australia. Deployment in the US              mitigating ADS-B vulnerabilities lack a systems engineering
is underway as part of the Next Generation Transportation                   methodology, therefore failing to address the problem from a
Systems (NextGen). In spite of its several benefits, this technology        holistic perspective. For instance, many lack a comprehensive
has been widely criticized for being designed without security in           approach to perform attack analysis and mitigation, and assess
mind, making it vulnerable to numerous attacks. Most                        their impact on applications of ADS-B technology, which we
approaches addressing this issue fail to adopt a holistic                   propose in this paper. Conversely, system engineering
viewpoint, focusing only on part of the problem. In this paper, we          techniques such as use cases and interaction diagrams have
propose a methodology that uses semantic technologies to address            been widely used in other domains to model the system’s
the security requirements definition from a systemic perspective.           behavior and its interaction with users, which is done from the
More specifically, knowledge engineering focused on misuse                  early designing steps in the system lifecycle.
scenarios is applied for building customized resilient software
defined radar applications, as well as classifying cyber attack                 Misuse cases [6] extend the concept of use case
severity according to measurable security metrics. We showcase              development to model potential undesirable behaviors. The
our ideas using an ADS-B-related scenario developed to evaluate             technique has been gaining popularity in recent years as a
our research.                                                               means to enhance system security, by modeling undesirable
                                                                            behaviors, ensuring these are addressed during systems design.
   Keywords— Ontologies, Misuse case, Cybersecurity, ADS-B                  Misuse cases represent the threats to a system at a high level
                                                                            perspective, while the step-by-step details are represented using
                       I.    INTRODUCTION
                                                                            mal-activity diagrams. The latter is key for devising ways of
    Since first proposed in 1991 by Joe Mitola [1], the concept             thwarting attacks, but both are essential for designing resilient
of Software Defined Radio (SDR) has received considerable                   systems.
research interest. The idea of migrating hardware-based radio
functionality to software and, among other benefits,                            Another important technology for designing systems is
dynamically optimize the spectrum use is compelling. Not                    Ontology engineering. Ontologies represent knowledge within
surprisingly, the concept is now applied to applications whose              a specific domain by formally describing its key concepts and
focus spans from cognitive radios to radar applications.                    the relationships among them. They allow for automated
                                                                            knowledge management and discovery via logical inferences
    In particular, Air Traffic Control (ATC) systems research               and have been applied to a variety of applications, such as
became a natural area for SDRs, due to a pressing need for                  health care and artificial intelligence. Yet, there has been a
modernizing its current standards, most stemming from the                   surprising lack of research in the ontology community for
1970s. In this context, Automatic Dependent Surveillance-                   designing secure SDR applications, and only a few have been
Broadcast (ADS-B) has emerged as the leading technology for                 proposing to leverage ontologies in this area (e.g. [7]).
radar surveillance, and has been already deployed in Europe,
Canada and Australia. The U. S. Federal Aviation                               Our work bridges this gap by proposing a new
Administration plans to have it deployed by 2020 as part of                 methodology for building resilient SDR applications that relies
NextGen [2]. Most aircraft manufacturers are already                        on ontologies. We leverage their reasoning capabilities to
equipping their newest models with ADS-B, which is present                  automate the modeling of use cases, misuse cases, mal-activity
in aircraft such as the Boeing 777 and the Airbus A380.                     diagrams, mitigation case diagrams and mitigation activity
                                                                            diagrams, all within the design phase of the radar application in
    In spite of its success, ADS-B has several critics.                     question. We present the approach in this paper, and
Strohmeier et al. [3] point out the huge lack of security caused            contextualize our ideas using an ADS-B ATC scenario.
by the fact that ADS-B sends its packets in clear text, making it
vulnerable to attacks that target the confidentiality, integrity,               Our methodology brings three main contributions to the
availability and non-repudiation properties of the data. This               design of secure ADS-B systems. First, we applied semantic
concern is consistent with research done by Costin and                      technologies in support to security and requirements modeling,




                                                                       40
formalizing knowledge relevant to SDR systems for building                 than the incoming reflected pulses, radar circuitry is extremely
resilient radar networks. To the best of our knowledge, this is            complex. ADS-B also has an advantage over Secondary
the first approach to do so. Other research efforts that leveraged         Surveillance Radars (SSR), which relies on aircraft-borne
security ontologies either focused on security in general, such            transponders to transmit their positions. Unlike ADS-B, SSR
as [8], or on a specific domain, such as [9]. The work in this             must rely on cooperation by pilots and – mostly for that reason
paper formalizes the knowledge of secure ADS-B systems in a                - its operation tends to be error-prone.
way that can be extended to other SDR applications.
                                                                               In spite of these advantages, ADS-B has its own share of
    The second major contribution of this paper is the                     limitations due to its vulnerability to cyber attacks. Several
application of inferential reasoning to enhance security-related           publications on ADS-B security (e.g. [4], [5] and [14]) used a
design activities. Examples include automated verification of              simulated environment to demonstrate various types of attacks
whether the mal-activity and mitigation activity diagrams are              targeting this technology, mostly using low cost equipment.
consistent with misuse case and mitigation case diagrams                   The primary source of vulnerability is that data is sent in clear
respectively, and checking whether the mitigation techniques               text, without authentication or encryption. Some of the ADS-B
can effectively thwart the potential attacks. In this initial work,        attacks demonstrated in simulated environments are:
we used Protégé [10] to develop our ontology and the Pellet
reasoner [11] to support the automated verification.                          x Eavesdropping: performed with low cost radio devices
                                                                                operating at 1090 MHz combined with an open source
    The third major contribution of our paper is the                            implementation of ADS-B receiver. Basically, one can
development of measurable security metrics to classify the                      eavesdrop on all air traffic within the range of the radio
detected attacks according to a taxonomy that we also define in                 device. Although eavesdropping is technically not an
this paper. We use the work in [12] as a reference when                         attack by itself, it is a prerequisite step for many others.
developing the metrics we defined for ADS-B applications.
                                                                              x Injection Attacks: performed by an attacker that emits
    The rest of the paper is organized as follows. Section II                   ADS-B messages referencing a fake aircraft (i.e.
presents background information about ADS-B and enumerates                      “injects”  a  fake  aircraft)  that interacts with the trajectory
some of the security issues discussed in the literature. Section                of a real aircraft, forcing its pilot and the ATC services
III describes our methodology. Section IV illustrates the use of                to adopt unintended actions to avoid collisions. These
our methodology by presenting an application scenario. In                       attacks usually rely on a preceding eavesdropping phase
Section V, we show how to classify the detected attacks using                   for capturing the required parameters.
ontological rules and security metrics. Section VI describes
related work in securing ADS-B applications, misuse cases,                    x Denial of Service: these are basically   a   “brute   force”  
and mal-activities in security-related operations. Section VII                  version of injection attacks, if less elaborate. The idea is
has our conclusions.                                                            to insert a large number of fake aircrafts to the  ATC’s  
                                                                                screen, causing a denial of service. Air traffic
                       II.   BACKGROUND                                         controllers will not be able to distinguish fake aircraft
    One of the main contributions of ADS-B to ATC is its                        from real ones, or to prevent system crashes due to the
ability to provide better coverage, flexibility, cost-                          heavy load.
effectiveness, and simplicity than traditional radar. Further,                x Man in the middle: these can be variations of the
ADS-B can either extend radar coverage or provide a similar                     above, but with a person in the control of the attack. It is
service in locations without radar coverage - such as oceanic                   possible for an attacker to intercept live traffic, store
routes. It also reduces cockpit activity, since pilots would not                ADS-B packets, modify them and retransmit the
need to provide constant updates. The costs involved in                         tampered ones back to create confusion in air traffic
deploying and operating an ADS-B station are much lower                         control operations.
than those observed in traditional radar stations [13].
                                                                                                 III.   METHODOLOGY
    The ADS-B protocol has two modes of operation: ADS-B
Out and ADS-B In. The first broadcasts aircraft position along                 The main goal of our work is to help the software architect
with other data over the 1090MHz frequency band for                        in designing the core system components with security as a
commercial flights and 948MHz band for general aviation.                   first class citizen, instead of an afterthought. A key concept is
ADS-B packets are encapsulated in Mode S Extended Squitter                 our reliance on ontologies to provide the ADS-B system
frames consisting of an 8 bits preamble used for                           designer with an automated way of testing the security features
synchronization and a 56 or 112 bits data block containing the             in a cohesive fashion. We adopted Protégé [10] in this research
ADS-B data. It is modulated via Pulse Position Modulation                  due to its popularity and built-in reasoners, such as Pellet [11]
(PPM) at 1 Mbit per second rate. ADS-B In receives broadcasts              - which we use to verify the correctness of the attack mitigation
from nearby aircraft. This feature is mostly used by ATC                   techniques. Figure 1 shows a high-level view of our
services so its deployment is not mandatory to aircraft.                   methodology, and highlights the input it requires from the
                                                                           systems engineer. More specifically :
   ADS-B presents considerable advances when compared to
Primary Surveillance Radar (PSR), which determines the                        x Use case diagrams: system functionalities.
approximate aircraft position by measuring the time a reflected
                                                                              x Misuse case diagrams: undesired functionalities.
pulse takes to reach back to its originating radar antenna.
Because the emitted pulse is many orders of magnitude greater




                                                                      41
                                                                                        evaluates pre-defined security constraints, such as
                                                                                        separation between helicopters.
                                                                                     x Telecommunication Sites: the scenario includes three
                                                                                       (named T1, T2 and T3), which convey location updates
                                                                                       to the ATC server and broadcast navigation instructions
                                                                                       to helicopters using ADS-B stations.
                                                                                     x ADS-B Stations: each of the five stations (s1 to s5)
                                                                                       receives ADS-B packets from helicopters, broadcasts
                                                                                       these to the telecommunication site it is connected to,
                                                                                       and forwards navigation instructions to the pilots.
                                                                                     x Communication Links: transmit data between the ATC
                                                                                       server, ADS- B stations and telecommunication sites.
               Figure 1: High level view of the methodology                           Our scenario leverages work such as Magazu [14] shows
                                                                                  that attacking ADS-B networks can be relatively simple and
    x Mal-activity diagrams: sequence of actions refining a                       inexpensive by purchasing a basic radio device (even a
      Misuse case.                                                                computer dongle) and using open source software such as
    x Mitigation case diagrams: counteractive functionalities                     GNU Radio [15] and Gr-Air-Modes [16] as an ADS-B
      that detect or mitigate undesired functionalities.                          receiver. In the scenario, the attacker can:

    x Mitigation activity diagrams: sequence of actions that                         x Tamper position: The attacker receives location
      refine a Mitigating use case.                                                    updates from a legitimate helicopter using an ADS-B
                                                                                       receiver placed within the transmission range. Then,
    x Base ontology: Models classes, their relationships, and                          modifies ADS-B packets by either altering the
      properties of the SDR domain.                                                    hexadecimal content or by inserting GPS coordinates
Figure 2 shows the main concepts we have included in the                               into the packet that may be inconsistent with the logical
                                                                                       flight path.
base ontology. Our methodology precisely defines the
meaning   of   “security”   by   specifying   security   in   terms   of             x Create a ghost helicopter: The attacker introduces a
desired and undesired system behavior. The proposed design                             new helicopter in the range of an ADS-B station so that
process involves supporting the system designer to model the                           it gets propagated to the ATC center, and consequently
required and undesirable system functionalities using the                              alters flight paths of legitimate helicopters. That is, if
classes, inter-class and intra-class relationships, and properties                     the fake trajectory interferes with the real aircraft, this
of the base ontology to produce the input listed in Figure 1.                          will force active interference by the flight controllers.
Logical reasoning is used in the process to ensure that the                          x Flood an ADS-B station: The attacker overwhelms an
design entails the desired and undesired system properties,                            ADS-B station with fake packets, affecting the control
empowering the design team with an automated verification of                           of helicopters within range of that station. That is, a
the fact that their design is compliant with the design’s  
security objectives (i.e. design by contract). The process
outcomes can also be used as formal, accountable artifacts that
can be independently verified.
                          IV.    EVALUATION
   To evaluate if our ideas would result in a more secure
ADS-B network, we have designed an ATC scenario and
developed an ADS-B application for this scenario using the
proposed methodology. Our scenario includes a network
topology consisting of the following components:
    x Helicopters: the scenario focus on a helicopter operation
      that is supported by an ADS-B network.
    x ATC Center: one main ATC Terminal receives aircraft
      track information from a radar and an ADS-B server to
      provide navigation instructions to the helicopters.
    x ATC server: receives location updates from the
      remotely connected telecommunication sites and ADS-
      B stations. It stores the updates in a database and
                                                                                                      Figure 2: Base Ontology




                                                                             42
       Denial-of-Service attack.                                                  x Comm Link 1 lane: oval  “Transmit”  indicates how the
                                                                                    data inside the packet is physically transmitted. This
   x Flood ATC/RADAR: similar to the previous attack but                            activity  is  part  of  “Transmit  data”  use  case.  
     this is done at a larger scale to overwhelm many or all
     ADS-B stations. If successful, this would adversely                          x ATC Server: oval  “Receive”  designates that the ADS-B
     affect regional air traffic.                                                   packets   are   received.   However,   oval   “Check   Hash”  
                                                                                    represents a mitigation activity as part of “Check  Hash”  
The following mitigations are viable against these attacks:
                                                                                    mitigation case. It indicates that the ATC server checks
   x Check Hash: Embed a hash of the ADS-B payload in                               the received hash against the hash it computes based on
       the packet to preserve data integrity using pre-shared                       the payload of the received packet. The diamond
       hashing metadata.                                                            indicates a decision node. Based on the outcome of the
   x Rate Limiting: Rate control the packets received from                          computation of the above described condition, the ATC
     communication links of the ADS-B stations.                                     server directs the flow of the whole scenario
                                                                                    accordingly. If the result is a mismatch, then it connects
    The core functionalities of the application are represented                     to   the   oval   “Discard”   which   is   a   normal activity
with use cases. The attacks to be prevented during the design                       indicating that the ATC server would just ignore the
phase are represented using misuse cases, and counteraction                         packet before ending the scenario by connecting to the
techniques are represented using mitigation cases. Taken                            double-edged black circle.
together, these represent the high-level security objectives of
the system.                                                                       x ATC Center lane: if the result of the previous decision
                                                                                    is a match, the oval   “Display   air   traffic” will be
    To achieve security design objectives, our methodology                          connected. This oval is part  of  “Display  air  traffic”  use  
requires more detail from the system architect, who has to                          case”. Similarly, the scenario would end at this point by
define diagrams conveying the activities, mal-activities, and                       connecting to the double-edged black circle.
mitigation activities – all consistent with contemporary design
activities for large-scale resilient systems. Figure 3 illustrates                 All the elements of Figure 3 can be mapped to the base
the combined view of these diagrams. In the figure, every lane                 ontology classes where, each lane is an individual of the
is annotated with a name of an actor and the actions. Black                    Swimlane class and every label has the actor’s  name. However,
ovals indicate mal-activities while white ovals indicate normal                this mapping depends on the characteristics of each sub-class
or mitigation activities. To facilitate understanding for the                  of Actor. More specifically:
methodology, we now provide an overview of each lane:
                                                                                  x Helicopter and Attacker: mapped to the Helicopter
   x Helicopter lane: the black-filled circle designate the                         class.
     start of the “Broadcast   location”   usage   scenario. Ovals
                                                                                  x ADS-B station 2: mapped to the ADS-B_Station class.
     “Get   self   location”   and   “Broadcast   location” designate
     the two activities that are responsible, respectively, for                   x The black-filled circle: mapped to an individual of the
     getting the location of the helicopter and sending it via                      Initial_Node class
     ADS-B Out. The black rectangle indicates a fork node.
     It models how location data is broadcasted to all nearby                     x Double-edged black circle: mapped to an individual of
     helicopters.                                                                   the Final_Node class.

   x Attacker lane: the three back ovals show how the                             x Black rectangles: can be mapped to either the
     misuse   case   “Tamper   position”   works. Oval “Receive                     Join_Node class or the Fork_Node class, depending on
     location”   indicates that the attacker received the                           the incoming and outgoing arrows. This is modelled by
     location update from the legitimate helicopter. Oval                           ontological restrictions linking each member of this
     “Tamper   location”   describes how the attacker crafts                        class to the number of instance of the Node class
     fake location inside the ADS-B  packet  while  oval  “Send                     connected to it.
     fake  location”  broadcasts  the  altered  packet  back  to  the             x White ovals: indicate a normal activity and are
     nearby ADS-B stations.
   x ADS-B Station 2 lane: the black rectangle indicates a
     join node showing how the ADS-B station receives
     location updates from the helicopter and the attacker.
     The two ovals “Receive  location”  and  “Send  location”  
     in this lane are  two  activities  as  part  of  “Replay  Data”  
     use case.
   x Telecom Site 1 lane: the  two  ovals  “Receive   location”  
     and  “Send  location”  are  also  part  of  “Replay  Data”  use  
     case and show how the ADS-B packets are replayed
     through the telecom sites.
                                                                               Figure 3: Combined view of activity, mal-activity and mitigation activity
                                                                                                             diagrams




                                                                          43
        considered individuals of the Normal_Activity_Node,
        while those indicating a mitigation activity are
        considered         individuals       of         the
        Mitigation_Activity_Node.
    x Black ovals: are individuals of the Mal-Activity_Node.
    Arrows connecting the elements described above are
mapped to object properties that relate two instances of two
different classes. In our work, this is done using (Protégé)
ontology rules, previously known as Semantic Web Rule
Language (SWRL) rules [17]. Each rule implies the consequent
(right hand side, a.k.a. head) from the antecedent (left hand
side, a.k.a. body).
    Let S be the statement of Theorem 1, described in Listing 1.
It shows a rule that models the fact that “tamper location”  
misuse  case  “threatens”  the  “monitor  air  traffic”  use  case.  The  
rule is   part   of   the   “threatens”   use   case / misuse case
relationship in the scenario where every helicopter sends an
ADS-B packet containing the required information.
     Each packet has a location defined as {latitude, longitude,
altitude}. When two packets sent from two different helicopters
reach the ATC Server, the server compares their timestamps
and their locations. If the timestamps are the same and the
differences in the received longitudes, latitudes, and altitudes
                                                                                                                       Listing 2
are greater than the predefined H, then the reasoner will infer
the   “threatens”   object   property.   The Pellet reasoner then                 the names of the mal-activities associated with the attack.
gathers the data and object properties of the individuals
concerned by the defined rule, and tries to infer the head - in                       The main idea here is that if the ATC Server receives a
this case the “threatens”  object  property.  If it succeeds in doing             packet from a helicopter, then it computes its corresponding
“threatens”   will appear as highlighted and we can get the                       hash based on the packet’s  payload  and  compares  it to the hash
corresponding explanation.                                                        received in the packet. We assume that the ADS-B packet
                                                                                  contains a hash in its payload. If these values match, then the
    Let  ψ  be  the  statement  of  Theorem 2 provided in Listing 2.              ATC Server proceeds with broadcasting the packet. Otherwise,
It shows the rule proving that the mitigation case succeeds in                    it marks the helicopter that sent the forged packet as malicious
thwarting the previously detected misuse case that threatens a                    and   the   “mitigates”   object   property   is   proven   to   be   valid.   In  
given use case of the system. It also tags the actor in question                  order to prove this theorem, the Pellet reasoner checks the data
as malicious, and associates the attack with its swimlane (cf.                    and object properties of the individuals concerned by this rule
Figure 3). Therefore tagging the associated object properties as                  and tries to infer the head of the rule. In this case, if it succeeds
                                                                                  in doing so, the object relations in the head appear as
                                                                                  highlighted and we can get the explanation of the proof.
                                                                                          V.      CLASSIFICATION OF ATTACKS USING METRICS
                                                                                      In this section, we describe the taxonomy we have
                                                                                  developed for the message injection ADS-B attacks. It is
                                                                                  composed by three classes of attacks, classified based on the
                                                                                  difficulty of implementation and the location of the radio
                                                                                  device that was used by the attacker. These classes are as
                                                                                  follows:
                                                                                      x Medium-level attacks: in this type of attacks, the
                                                                                        attacker generates the malicious ADS-B messages to be
                                                                                        injected in a typically random way and he does not
                                                                                        move the equipment used to launch the attack. For
                                                                                        instance, the attacker can send a massive amount of
                                                                                        ADS-B messages whose locations are within the reach
                                                                                        of the ATC Sever with fake aircraft identifier in order to
                                                                                        obstruct the view of the radar display and thus prevent
                                                                                        the air traffic controller from performing his duties.
                                Listing 1




                                                                             44
   x Advanced-level attacks: where an attacker uses                              are equal to zero. The estimated-to-real difference
     sophisticated flight simulator programs along with the                      would be within the predefined thresholds.
     radio device in order to send a more realistic flight path              x Expert-level attacks: An attack belongs to this class if
     that cannot be detected as fake easily. For example, one                  the velocity is comparable to the one of a real aircraft.
     popular program that can be used to achieve this is                       Besides, the sender location difference cannot be equal
     FlightGear [18]. In this case, the location of the                        to zero, and the estimated-to-real difference has to be
     equipment used to perform the attack is fixed.                            within the predefined thresholds.
   x Expert-level attacks: similar to the advanced-level                      We now focus on how the proofs of the theorems are
     attacks, except for the fact that the equipment used to              generated using ontological rules, similarly to the previous
     launch the attack is located in an aircraft. This kind of            section of this paper. Due to space limitations, we restrict the
     attack is harder to test, since it requires sophisticated            explanation to the ontological rules used for computing the
     equipment and procedures.                                            estimated-to-real difference metric, and for classifying an
                                                                          attack as belonging to medium-level attacks class respectively
    Classifying attacks detected using the techniques described
                                                                          in Listings 3 and 4.
in the previous section requires collecting parameters, needed
for deciding if an attack belongs to a particular attack class                In Listing 3, we collect GPS properties of the malicious
modelled in an ontology rule. We leveraged the work in [12], a            actor, after verifying that the packet he sent had reached the
well-known standard that provided us with a reference for                 ATC Server. Then, we compute the properties of the estimated-
checking under which category our metrics fell into. We                   to-real metric relatively to longitude, latitude and altitude.
defined three security metrics, which are described as follows:
                                                                              In Listing 4, we collect the data provided by all the metrics
   x Sender Location Difference: the absolute value of the                and define the conditions for deciding whether an observed
     difference between the triangulated  sender’s  location  at          attack belongs to the medium-level attacks class.
     two consecutive times ti and tj. We assumed having
                                                                              We had to make several assumptions regarding the metrics.
     appropriated means of triangulation, which is needed
                                                                          Firstly, we assumed that there is a mechanism to triangulate the
     for determining the location of the sender based on the
                                                                          true location of the sender of the packet, which would facilitate
     received ADS-B packet. This metric is broken down
                                                                          computing its location difference metric. Secondly, we
     into three sub-metrics which correspond to the
                                                                          assumed that it is possible to estimate the location of an aircraft
     differences between longitudes, latitudes, and altitudes.
                                                                          at all times, which is required for computing the estimated-to-
   x Velocity: which is the speed of the aircraft at a time t.            real difference metric.
   x Estimated-to-Real Difference: which is the absolute                       For each metric used in this evaluation we have written a
     value of the difference between the estimated location               corresponding rule that the Pellet reasoner can use against the
     of an aircraft and the location retrieved from the ADS-B             defined individuals to determine its value. The first rule is
     packet at time t. We assumed the capability of                       related to the sender location difference metric. Basically, it
     estimating aircraft locations at all times. This metric is           gets the triangulated sender locations at two consecutive time
     also composed by three sub-metrics, corresponding to                 steps and calculates the absolute value of the difference of
     difference of longitudes, latitudes and altitudes.                   altitude, latitude and longitude. The second rule addresses the
                                                                          velocity metric, and extracts its value at a certain time by using
    After careful consideration, we came to a conclusion that             the ADSBPacket and TimedRelation entities. The third rule,
these three defined metrics fell under the Cyber Intelligence
Threat Analysis category. After all, these metrics collect
practical data about the attacks, and allow the security analyst
to classify cyber attacks based on patterns of wrong behavior.
In our methodology, these metrics are used by the Pellet
reasoner to automatically classify the type of attack. The
relationships between the described classes of attacks and the
security metrics are described as follows:
    x    Medium-level attacks: an attack belongs to this class
         if the sender location difference and the velocity are
         equal to zero. An attacker, whose physical location
         does not change, is of course very likely to have such
         characteristics. Further, the estimated-to-real
         difference has to be greater than a predefined
         threshold for the longitude, latitude and altitude.
         Consequently, if the location retrieved from the
         ADS-B packet is not within the aircraft envelope,
         then such packet most likely comes from an attacker.
    x    Advanced-level attacks: An attack belongs to this                                               Listing 3
         class if the sender location difference and the velocity




                                                                     45
                                                                          problem of security within the SDR domain by leveraging
                                                                          knowledge from semantic models and ontologies.
                                                                              In [9], Ekelhart et al. introduced a framework for building
                                                                          security ontologies that assists in providing risk analysis. The
                                                                          authors used an incremental approach where they start with a
                                                                          generic security taxonomy formalized in an ontology and they
                                                                          enhance it by integrating risk factors, constraints, threats and
                                                                          countermeasures. This work concentrates on risk management
                                                                          involving IT-security tasks in a company, while our goal is to
                                                                          create a methodology to secure ADS-B networks.
                                                                              In [20], Magklaras and Furnell proposed an approach to
                                                                          address internal IT misuse via a classification of misusers and
                            Listing 4
                                                                          their motives, as well as the implications of the misuse on the
which deals with the estimated-to-real difference, gets the               system. In our paper, we adopted a more flexible representation
coordinates of both the estimated position and the real position          of misuses, which relies on misuse case and mal-activity
before calculating the absolute value of the difference in terms          diagrams. Moreover, their work describes security in general
of latitude, longitude and altitude.                                      while ours focuses on security in ADS-B networks. The
                                                                          authors provided a mechanism of determining the threat level
    The knowledge derived from these rules can provide                    that is similar to our work, in which we classify the attacks
reasonable insights into attack classification. We developed              according to the taxonomy. The main difference is that we
different rules to classify an attack according to its category in        employ theorem proving with a semantic-web inspired rule
the taxonomy. For example, an attack that belongs to the                  system, while their work is based on an analyzer module built
medium-level category would have a null velocity, a null                  as part of their proposed framework.
sender location difference, and its estimated-to-real metric
would exceed the defined threshold. Conversely, the advanced-                 In [21], McCallie et al. assessed ADS-B security by
level category would have its attacks with a null velocity and a          detecting and classifying attacks that may target ADS-B
null sender location difference, but its estimated-to real metric         applications. They provide some general recommendations on
would not exceed the defined threshold. This is expected, given           how to thwart these attacks. In contrast, we provide a
the use of flight simulator versus generating random values in            methodology to be applied when analyzing the security of SDR
the medium-level category. Finally, an attack would be in the             applications.
expert-level category if the velocity is comparable to a real                 Similarly, Costin and Francillon [4] demonstrated the lack
aircraft, while its sender location difference would be greater           of security of ADS-B by implementing attacks in a low-cost
than zero and its estimated-to-real metric would not exceed the           simulated environment. They did not focus on attack
pre-defined threshold.                                                    mitigation. In contrast, our methodology assists the systems
                                                                          engineer in formulating security requirements by precisely
                    VI.   RELATED WORK                                    defining and verifying these for SDR applications, while using
    In [7], Massacci et al. proposed an ontology for security             automated design verification for attacks and their mitigations.
requirements by extending existing ontologies with situational                In [22], Whittle et al. proposed a technique for modeling
and context awareness. The authors contextualize their ideas by           possible attacks and mitigating them. They employ misuse
an ADS-B case study. This work is similar to ours but the main            cases to model undesirable system behavior. The approach
difference is that they focused on GPS spoofing attacks, while            models misuse cases as aspects, inserts these in the core system
we address message-injection attacks that are more difficult to           features before integrating mitigation techniques. Then, they
realize, as stated by [3].                                                use the attacks as test cases to evaluate the design robustness.
    Oltramari et al. [19] described an approach to support cyber          Although our objective is similar to theirs, but we base our
operations by enhancing the situational awareness via a                   methodology on ontologies to support the system design from
combination of cognitive modelling and ontology engineering.              the ground up with security as an integral design aspect. In
They plan to evaluate their approach by applying it to design a           contrast, they use prior work on state machines.
cyber defense application. However, their work is not specific                In [23], Sindre introduced the concept of mal-activity
to SDR applications, but to cyber operations in general.                  diagrams as an enhanced form of activity diagrams where each
   In [8], Obrst et al. presented a methodology for building              actor of the system, normal or malicious, occupies a swimlane
cyber security ontologies based on a malware ontology. This               and starts normal or malicious activity nodes. Our approach
methodology outlines the steps that are required for building a           uses the concept of a mal-activity diagram and integrates it in
cyber security ontology, and provide general guidelines for               the design process with the support of ontologies.
enhancing the cyber security domain with semantic models.                     In [24], El-Attar presented a tool to convert a textual
The main difference between this work and ours is their focus             description of the system to a model taking into consideration
on security from a general standpoint, starting from a wide               the security aspects in term of misuse case and mal-activity
characterization of malware. In our paper, we tackle the                  diagram. This is achieved with support from two tools. One
                                                                          transforms the textual description to a context-free grammar,




                                                                     46
which is used to build the first meta-model. The other creates                                     [9]    A.   Ekelhart,   S.   Fenz,   M.   Klemen,   and   E.   Weippl,   “Security  
the meta-model that captures the mal-activity diagrams. This                                              Ontologies:   Improving   Quantitative   Risk   Analysis,”   presented   at   the  
                                                                                                          40th Annual Hawaii International Conference on System Sciences,
work appears similar to ours, but El-Attar’s   main   goal   is   to                                      2007. HICSS 2007, 2007, p. 156a–156a.
create meta-models from textual description. In contrast, we                                       [10]   H.  Knublauch,  R.  W.  Fergerson,  N.  F.  Noy,  and  M.  A.  Musen,  “The  
formally capture the diagrams using ontological rules and                                                 Protégé OWL Plugin: An Open Development Environment for
verify that the stated relationships between them exist using a                                           Semantic  Web  Applications,”  in  The Semantic Web – ISWC 2004, S.
theorem prover.                                                                                           A. McIlraith, D. Plexousakis, and F. van Harmelen, Eds. Springer
                                                                                                          Berlin Heidelberg, 2004, pp. 229–243.
                             VII. CONCLUSION                                                       [11]   E.  Sirin,  B.  Parsia,  B.  C.  Grau,  A.  Kalyanpur,  and  Y.  Katz,  “Pellet:  A  
                                                                                                          practical OWL-DL   reasoner,”   Web Semantics: Science, Services and
    ADS-B has emerged as a promising technology for                                                       Agents on the World Wide Web, vol. 5, no. 2, pp. 51–53, Jun. 2007.
optimizing the use of the air space while lowering costs and                                       [12]   “MITRE’s   Making   Security   Measurable,”   MITRE’s   Making   Security  
increasing the security of air traffic operations. Hindering this                                         Measurable. Available: http://makingsecuritymeasurable.mitre.org/.
                                                                                                   [13]   “ADS-B  Frequently  Asked  Questions  (FAQs),”  07-Apr-2014.
progress, many security vulnerabilities in the protocol have                                              Available at:
been discovered, generating a pressing need for a holistic,                                               http://www.faa.gov/nextgen/implementation/programs/adsb/faq/#3.
systems-oriented approach to properly address the problem.                                         [14]   D.   Magazu   III,   “Exploiting   the   Automatic   Dependent   Surveillance-
Within this context, in this paper we present a methodology                                               Broadcast  System  via  False  Target  Injection,”  2012.
that relies on time-tested, traditional requirements engineering                                   [15]   GNU Radio. Available at www.gnuradio.org.
                                                                                                   [16]   N.               Foster,                “Gr-air-modes,”                   Available:  
while leveraging advanced semantic technology concepts to                                                 https://github.com/bistromath/gr-air-modes.
automate the process of requirement verification. We have                                          [17]   I. Horrocks, P. Patel-Schneider, H. Boley, S. Tabet, B. Grosof, and M.
tested the methodology in an ADS-B scenario, and were able to                                             Dean,   “SWRL:   A   Semantic   Web   Rule   Language   Combining   OWL  
support the system design by translating security requirements                                            and  RuleML,”  May  2004.
into formally verifiable claims. Finally, we used logical                                          [18]   “FlightGear.”  Available:  www.flightGear.com.
                                                                                                   [19]   A. Oltramari,  C.  Lebiere,  W.  Zhu,  L.  Vizenor,  and  R.  Dipert,  “owards  
reasoning to ascertain the validity of the mitigating solutions                                           a   Cognitive   System   for   Decision   Support   in   Cyber   Operations,”  
and classify the attacks using security metrics.                                                          presented at the International Conference on Semantic Technologies
                                                                                                          for Intelligence, Defense, and Security (STIDS), 2013.
    We plan to further evaluate the methodology in complex                                         [20]   G.   B.   Magklaras   and   S.  M.   Furnell,   “Insider   Threat   Prediction   Tool:  
simulation environments that will provide a better                                                        Evaluating  the  probability  of  IT  misuse,”  Computers & Security, vol.
understanding of its broader impact in designing resilient SDR                                            21, no. 1, pp. 62–73, Jan. 2001.
applications. Future work on the methodology also involves                                         [21]   D.  McCallie,  J.  Butts,  and  R.  Mills,  “Security  analysis  of  the  ADS-B
standardizing its procedures, so they would be applicable to the                                          implementation   in   the   next   generation   air   transportation   system,”  
field of SDR applications in a consistent fashion. In this paper                                          International Journal of Critical Infrastructure Protection, vol. 4, no.
                                                                                                          2, pp. 78–87, Aug. 2011.
we have focused on the initial phases of the system engineering                                    [22]   J.  Whittle,  D.  Wijesekera,  and  M.  Hartong,  “Executable  misuse  cases  
life-cycle, but the methodology can be easily expanded to                                                 for modeling security concerns,”   presented   at   the   ACM/IEEE   30th  
formalize and automate other parts of the systems engineering                                             International   Conference   on   Software   Engineering,   2008.   ICSE      ’08,  
life cycle. Examples of the latter include supporting trade-off                                           2008, pp. 121–130.
analysis of adding security features against their associated                                      [23]   G.  Sindre,  “Mal-Activity Diagrams for Capturing Attacks on Business
                                                                                                          Processes,”   in   Requirements Engineering: Foundation for Software
cost, validation and verification of the actual system based on                                           Quality, P. Sawyer, B. Paech, and P. Heymans, Eds. Springer Berlin
stakeholder requirements (e.g. FAA specs for different types of                                           Heidelberg, 2007, pp. 355–366.
systems), and others that would benefit from the formalization                                     [24]   M. El-Attar,   “From   misuse   cases   to   mal-activity diagrams: bridging
of the design process with a focus on its security requirements.                                          the   gap   between   functional   security   analysis   and   design,”   Software
                                                                                                          Systems Modelling, vol. 13, no. 1, pp. 173–190, Feb. 2014.

                               REFERENCES
[1]   J.   Mitola,   “The   software   radio   architecture,”   IEEE Communications
      Magazine, vol. 33, no. 5, pp. 26–38, May 1995.
[2]   “NASA  - NextGen,”  24-Oct-2014. Available at:
      http://www.hq.nasa.gov/office/aero/asp/airspace/index.htm.
[3]   M.  Strohmeier,  V.  Lenders,  and  I.  Martinovic,  “On  the  Security  of  the  
      Automatic           Dependent           Surveillance-Broadcast          Protocol,”  
      arXiv:1307.3664 [cs], Jul. 2013.
[4]   A.  Costin  and  A.  Francillon,  “Ghost  in the Air(Traffic): On insecurity
      of ADS-B protocol and practical attacks on ADS-B  devices,”  2012.
[5]   M.  Schäfer,  V.  Lenders,  and  I.  Martinovic,  “Experimental  Analysis  of  
      Attacks  on  Next  Generation  Air  Traffic  Communication,”  in   Applied
      Cryptography and Network Security, Springer Berlin Heidelberg,
      2013, pp. 253–271.
[6]   G.   Sindre   and   A.   L.   Opdahl,   “Eliciting   security   requirements   with  
      misuse  cases,”  Requirements Eng, vol. 10, no. 1, pp. 34–44, Jan. 2005.
[7]   F. Massacci, J. Mylopoulos, F. Paci, T. T. Tun, and   Y.   Yu,   “An  
      Extended   Ontology   for   Security   Requirements,”   in   Advanced
      Information Systems Engineering Workshops, C. Salinesi and O.
      Pastor, Eds. Springer Berlin Heidelberg, 2011, pp. 622–636.
[8]   L. Obrst, P. Chase, and R. Markeloff, Developing an Ontology of the
      Cyber Security Domain. .




                                                                                              47