<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Integrity control algorithms in the system for telemetry data collecting, storing and processings</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>V V Berkholts</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>A I Frid</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>M B Guzairov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>A D Kirillova</string-name>
          <email>kirillova.andm@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Ufa State Aviation Technical University</institution>
          ,
          <addr-line>K. Marks st., 12, Ufa, Russia, 450008</addr-line>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2019</year>
      </pub-date>
      <fpage>487</fpage>
      <lpage>503</lpage>
      <abstract>
        <p>The issues of improving the security of the modular system for collecting, storing and processing telemetric information on the state of the onboard subsystems of the aircraft in automatic mode are considered. It is based on an analysis of the use of modern technologies for the protection and processing of telemetric information to ensure certain aspects of the guaranteeability of the system as a whole.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Emerging malfunctions and pre-failure states of the onboard equipment of the aircraft can be
diagnosed based on telemetric information (TMI). This allows the specialists of ground technical
services to plan repair and preventive measures based on an assessment of the current state of the
equipment. Accumulated and processed TMI will allow specialists of the manufacturer to provide
reasonable support to engineers of ground services in making decisions in case of technical failure of
the blocks and modules of the aircraft. TMI analysis will improve the operational efficiency of the
aircraft in case of any malfunctions and attacks by intruders.</p>
      <p>The aim of the study is to increase the security of the system for collecting, storing and processing
TMI on the state of the onboard aircraft subsystems in automatic mode. It is based on an analysis of
the use of modern (including intellectual) technologies for the protection and processing of TMI.</p>
      <p>To achieve this goal, a structural diagram of a protected system for collecting, storing and
processing telemetric information on the state of the aircraft subsystems on the basis of a modular
principle has been developed.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Analysis of the problem of secure collection, storage and processing of TMI in a geographically distributed information system</title>
      <p>The proposed automated information system (AIS) of ground maintenance services is a set of software
and hardware. They are necessary for the reception, storage and processing of information about the
parameters of the state of complex technical products (CTP) on the aircraft. AIS is a geographically
distributed system that combines the infrastructure of the information systems of ground-based
maintenance stations and the information system of the manufacturer through secure communication
channels. Preparation TMI realized by reading a status log for CTP aircraft during inspection and
maintenance at ground stations via wireless and / or wired sensor networks.</p>
      <p>The dependability of the TMI transmission systems with an aircraft allows for a comprehensive
solution of the tasks of ensuring reliability, fault tolerance, availability, security, maintainability, and
observability. An urgent task is to build a hierarchy of models that allow a comprehensive assessment
of various aspects of the TMI transmission system and the development of a methodology for
assessing the integral indicator of the system’s guaranteed performance.</p>
      <p>Ensuring the availability of TMI transmission systems is the primary task of ensuring the effective
functioning of the aircraft (A/C). The volume of TMI collected is significant. It is an incentive for the
development of the concept of the industrial Internet of things (IIoT). It is a promising platform for use
in solving such problems [1]. For example, a jet airliner demonstrated at the Bombardier Paris Air
Show, whose engine is equipped with more than 5,000 sensors that generate up to 10 GB of data per
second. One twin-engine aircraft can generate up to 844 TB of data average in 12-hour flight [2].</p>
      <p>The ability to transfer TMI about the actual state of individual modules during operation and the
entire A/C equipment complex in real time to the manufacturer of aeronautical engineering
components will improve the operational efficiency of the aircraft in its normal state and in the event
of malfunctions and attacks by intruders when investigating incidents. Thus, a study of ground-to-air
communication systems showed that ACARS, despite its versatility and widespread use, is vulnerable,
and if hacked in conjunction with ADS-B, an attacker can gain access to the flight control system,
download flight plans and detailed commands [3].</p>
      <p>Ensuring the availability of telemetry information on the state of the aircraft</p>
      <p>An automated information system (AIS) of ground maintenance services is a set of software and
hardware. They are necessary for receiving, storing and processing information on the technological
parameters of complex technical products (CTP) on board the aircraft.</p>
      <p>
        A review of the main approaches to the relevance of the problem of ensuring the reliability of such
systems is considered in the works of the authors [
        <xref ref-type="bibr" rid="ref1">4, 5, 6</xref>
        ]. AIS solves the main problems associated
with the reception of TMI on the state of the onboard aircraft systems. The main methods of obtaining
data are presented in the figure (Figure 1):
1. Directly from the CTP
2. By means of reading devices of the event log from the sensors of modules CTP. When carrying
out technical inspection and maintenance, devices of this type read and store data on the state of the
modules throughout the entire previous period of operation [5].
      </p>
      <p>3. Entering events into the database manually. The operator processes the information and enters
the information through the WEB application [4].</p>
      <p>In the first case, telemetry information is transmitted from the aircraft through a radio channel. To
create a transmission channel, the following approaches can be used:
• Communication satellites (IRIDIUM, SATCOM).</p>
      <p>Existing telemetry data transmission technologies use satellite communications. For example, the
GE Aviation concern, producing aircraft engines, transmits telemetry from the aircraft in this way.</p>
      <p>The obvious disadvantage of such way of transfer is its high cost. Streaming telemetry information
involves the transfer of significant amounts (gigabytes) of data sent. The second disadvantage is the
low noise immunity of the satellite communication channel. Incorrectly transmitted data can serve as a
signal for a false alarm, or there is a chance to miss a system failure.
• Channel of wireless high-speed data transmission LTE and LTE-a</p>
      <p>Air to ground (A2G) LTE is capable of providing data rates of up to 75 Mbps for ground-to-air
communications and up to 25 Mbps for air-to-ground communications at distances of 100 kilometers
and speeds of 1,200 kilometers per hour using licenses. FDD 2x15 MHz. The standard 4G LTE can be
used for continental flights, developed by Nokia.</p>
      <p>Despite the currently available satellite and hybrid A2G systems, there is still no low-cost,
highthroughput solution for broadband in-flight.</p>
      <p>Thus, none of these technologies has no set of properties that allow for continuous broadcast
telemetry data. ACARS does not allow to transfer a large amount of accumulated data, satellite
communication is too expensive, and LTE-A is still at the development and implementation stage, and
in the future it will cover only the continental part of flights.</p>
      <p>Moreover, the current TMI transmission and processing systems demonstrate vulnerabilities that
allow an attacker to gain access not only to passenger and airline data, but also to significantly affect
flight parameters.</p>
      <p>In the second and third cases, the information enters the database through a WEB application,
which is an insulating layer between external networks and the internal structure of the AIS, since
access from the external network is one of the most vulnerable points of the system. Improving the
security of access to the database (DB) containing critical information about the product in use is
based on the development of the architecture of a secure WEB application that acts as an insulating
layer for external AIS clients, which allows for the possibility of transferring and analyzing
groundbased service points from the aircraft and provide the ability to remotely access the necessary data.
The architecture of this solution is presented in [5].</p>
      <p>Preventing the appearance of vulnerabilities in the WEB application was carried out by
implementing measures to develop secure software established by GOST R ISO / IEC 12207.
Modeling security threats and identified vectors of possible attacks, as well as analyzing them, made it
possible to formulate countermeasures for each of the vectors at different architectural levels
WEBapplications. However, the analysis of the security of the entire TMI transmission system requires
advanced modeling and the construction of a detailed model of interaction between the onboard
information system of the aircraft and the ground-based AIS.</p>
      <p>The growth of telemetry information forces the aviation industry to consider new approaches to the
collection and analysis of a large amount of data on the state of individual components and elements
of the aircraft. The concept of the industrial Internet of Things is being actively developed - an
expanded network consisting of a large number of devices equipped with a set of sensors that
communicate with each other through low-power and short-term wireless connections. The first step is
to collect data from the sensors. One of the most promising solutions is a protocol with low power
consumption and small radius of IEEE 802.15.4 IEEE 802.15.4e transmission. Short range is sufficient
for data transmission within the ground service station. The IEEE 802.15.4 and IEEE 802.15.4e
protocols and their architecture layers comply with IETF standards.</p>
      <p>The question of analyzing the security of the system for collecting, transmitting and receiving
telemetry information about the state of individual elements of the onboard aircraft systems during
data transmission over the first two channels remains open.</p>
      <p>The decomposition of the TMI transfer in the form of a hierarchical model of interacting levels of
collecting, transmitting and analyzing information with the corresponding protocol stack is the basis
for analyzing and building a system for analyzing the transmission system security (Figure 2).</p>
      <p>In recent years, satellite communication systems in accordance with the Regulations of the
International Telecommunication Union (ITU) are switching to a higher-frequency Ka-band
(15.4026.50 and 27.00-30.20 GHz).</p>
      <p>The grouping of satellites in geostationary orbit and ground control centers make it possible to
form a network infrastructure with high reliability indicators and the possibility of building distributed
state networks. Channels of transmission of such networks provide a fairly high level of encryption
and data protection.</p>
      <p>Transmission of information in such networks is characterized by a low level of errors - no more
than one per 10 million transmitted information bits and reliable operation - up to 100 thousand hours.
The speed of work on the satellite channel is from 16 Kbps to 10 Mbps and more, which is comparable
with the data transfer rate in the terrestrial channel.</p>
      <p>The main methods for ensuring the security of telemetry information transmission in a wireless
satellite channel is the use of software and hardware means of information protection. Widely used
standards for secure protocols IPsec.</p>
      <p>IPsec protocol (set of protocols) provides:
• integrity of the virtual connection, authentication of the source of information using the AH
protocol (Authentication Header);
• encryption of information transmitted via the ESP (Encapsulating Security Payload) protocol;
• initial connection setup, mutual authentication and confidential key exchange.</p>
      <p>At present, modern bilateral satellite communication networks use coding systems at the software
and hardware level, which makes the interception and decoding of information over the radio channel
almost impossible.</p>
      <p>All data transmitted via satellite channel pass through a multi-stage system of transformation and
encryption. The result of this:
• application of proprietary data encryption algorithms;
• terminal authentication when it is registered on the operator’s network (hardware key);
• encryption of both the entire session (software key) and each session separately (session keys);
• application of proprietary algorithms for converting source data into internal data formats
(structures), which are then transmitted via satellite channel; thus, the tasks of additional
protection of information, delivery of service information and error correction are solved;
• in the created virtual channels, source data in TCP sessions are grouped, compressed, and
prioritized.</p>
      <p>Satellite channels in the direction from A/C to TMI processing centers are reverse satellite
channels. Currently, the most common ways of functioning of transmitters in such channels are the
principles of access with time-frequency division of TDMA / FDMA channels. Each reverse channel
is located in a certain frequency range or has a carrier with frequency modulation and with a given
coding algorithm for detecting and correcting errors of transmitted data - Turbo Coding.</p>
      <p>To transmit TMI from the aircraft, it is necessary to provide a mechanism for changing the
frequencies of the carrier reverse channels, which makes it much more difficult to intercept the
transmitted data.</p>
      <p>Data encryption in the satellite channel is carried out with the participation of both satellite
terminals on board the aircraft and specialized high-performance servers at the TMI ground collection
station. The server of the ground station for collection and processing of TMI hosts a secure database
of encryption keys and session keys of all satellite terminals. In order for the aircraft board to operate
in the transmission network, the information in the key database must match the hardware onboard
key.</p>
      <p>Telecommunications systems using the UMTS (Universal Mobile Telecommunications System)
standards are third-generation mobile communication systems - 3G. For mobile communication of the
third generation, the decimeter frequency band is used (about 2 GHz), and data transmission is
provided at a speed of 2 Mbit / s.</p>
      <p>All information security threats in the UMTS network can be distributed depending on the location
of the impact of their respective attacks:
• on the radio access area (radio interface);
• on other parts of the network.</p>
      <p>The radio section between the aircraft and the service network is one of the most vulnerable points
of attack in UMTS. The threats related to this site and described below are divided into the following
categories:
• unauthorized access to data;
• threats to data integrity;
• “denial of service”;
• unauthorized access to services.</p>
      <sec id="sec-2-1">
        <title>Violators can intercept user traffic and Violators can intercept alarm data and control data Table 2. Threats to the integrity of information.</title>
      </sec>
      <sec id="sec-2-2">
        <title>Violators can be disguised as a network element Violators can monitor the characteristics of messages Violators can actively initiate a connection and then access information</title>
      </sec>
      <sec id="sec-2-3">
        <title>Threat description</title>
      </sec>
      <sec id="sec-2-4">
        <title>Violators can modify, insert, repeat or destroy user</title>
        <p>traffic. This manipulation may be accidental or
intentional.</p>
        <p>The intruder can modify, insert, repeat, or destroy
alarm or control data.
Т1с
Т1d
Т1е</p>
        <p>Interception of user traffic
Interception of alarm
control data
Masking as a participant
Passive traffic analysis</p>
        <p>Active traffic analysis</p>
      </sec>
      <sec id="sec-2-5">
        <title>Threat designation Т2а</title>
      </sec>
      <sec id="sec-2-6">
        <title>Threat name User traffic manipulation Т2b Alarm data manipulation</title>
      </sec>
      <sec id="sec-2-7">
        <title>Threat</title>
        <p>designation
Т3а
Т3b
Т3с</p>
        <p>Below are tables with descriptions of information security threats. The accepted designations of the
threat TAn correspond to: T - the first letter of the English word "threat" (threat): A - the number
corresponds to the number of the threat group (table number); n - the letter corresponds to the ordinal
number of the threat in the threat group (in accordance with the list of threats in the ETSI document.</p>
      </sec>
      <sec id="sec-2-8">
        <title>The intruder is disguised as another network user. First, the intruder is disguised as a base station with respect to the user.</title>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Threats related to attacks on other parts of the system</title>
      <p>Although attacks on a radio channel represent the most serious threats, attacks on other parts of the
system also require analysis from the point of view of information security.</p>
      <sec id="sec-3-1">
        <title>Threat designation T5e T5f</title>
        <p>T6с
T6f
T7а
T7b
T7с
T7d
T8а
T8b
T9а</p>
      </sec>
      <sec id="sec-3-2">
        <title>Threat name</title>
      </sec>
      <sec id="sec-3-3">
        <title>Threat description</title>
        <p>Unauthorized access to data Violators (by physical influence or logical control)
on the system object can gain access to local or remote data.
Compromising information A legitimate user of a UMTS service may obtain
about the location information about the location of other users of the
system
Manipulation of masking as a Violators can be disguised as a network element in
communication partner order to modify, insert, repeat or destroy traffic
Manipulation of data on the Violators can modify, insert, destroy data that is
objects of the system contained in the objects of the system.
Physical intervention Violators may interfere with transmission on any
system interface (wired or wireless). For example, the
physical method of an obstacle on a wired interface
could be a broken wire.</p>
        <p>Protocol intervention Violators can interfere with the transmission of user
traffic or signaling data on any interface of the system
(wired or wireless) or by signaling the protocol to fail.</p>
        <p>Denial of service by masking Violators can deny service to users by impeding the
communication partners transmission of user traffic and signaling data,
controlling them by blocking as a result of masking as
a network element.</p>
        <p>Incorrect use of emergency Violators can interfere with access to the services of
services other users and at the same time cause disruption of
the equipment to perform functions in emergency
situations.</p>
        <p>Disagreement with the Disagreement with the submitted invoice. This may be
submitted invoice expressed in the refusal of the service or in the refusal
that the service was actually provided.</p>
        <p>Failure of user traffic source The user can refuse to send traffic.</p>
        <p>Custom masking Violators can introduce themselves as a user in order
to use the authorized services of this user. The
intruder was able to get this opportunity from other
objects such as the serving network, home
environment and even the user himself.</p>
      </sec>
      <sec id="sec-3-4">
        <title>Threat designation T10h T9b</title>
        <p>T9с
T9d
T9е
T10j
T4а,
Т9а,
Т9с
T4а,
Т8а,
Т9d,
T9e
T7b,
Т7с
T7а,
Т7b,
Т7с
T1a,
Т1b
T10h,
T10k</p>
        <p>Masking under the serving Violators can introduce themselves as a service
network network or part of a service network infrastructure.
Home environment masking Violators can introduce themselves as a home
environment in order to obtain information that
enables them to disguise themselves as users.</p>
        <p>Misuse of user priorities Users may misuse their assigned priorities in order to
gain unauthorized access to services or simply use
their subscription intensively for free.</p>
        <p>Incorrect use of serving Service networks may misuse their priorities to gain
network priorities unauthorized access to services.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Development of a block diagram of a secure system for collecting, storing and processing telemetric information on the state of the aircraft subsystem</title>
      <p>The generalized structure of a geographically distributed hierarchical system for the collection, storage
and processing of TMIs arriving from airplanes based on ground maintenance stations is presented in
Figure 4.</p>
      <p>The creation of a secure channel through global communication networks and the transfer of TMI
to a part of the AIS EM is realized at the transmission level of accumulated data. Organization levels
of reception and distribution of information at the enterprise are realized according to the three-layer
CISCO model. There is a level in the corporate information network of EM. It includes subsystems for
storage and processing of TMI. Also, there is a segment designed to support and implement the
business processes of the enterprise.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Development of the structure of the collection and storage subsystem TMI at the ground stations of aircraft maintenance</title>
      <p>The vast majority of Industrial Ethernet protocols do not have built-in security mechanisms.
Consequently, the actual problem is the security of industrial networks.</p>
      <p>To ensure the security of subsystems that implement the first two levels of the proposed structure,
it is necessary to be guided by the normative documents of the international and federal standards.
When designing the wireless sensor network collection subsystem of the TMI, take into account the
requirements of GOST R ISO / IEC 27033-1-2011 and GOST R ISO / IEC 27033-3-2014.</p>
      <p>The physical architecture of the TMI collection and storage subsystem at the ground is presented in
Figure 5.</p>
      <p>Mechanisms for collecting and storing a large amount of TMI on the state of individual
components and elements of aircraft should take into account the actively developing concepts of the
industrial Internet of things (IIoT). It is proposed to use heterogeneous wired (physical RS-485
interface) and wireless sensor networks (IEEE 802.15.4, IEEE 802.15.4e) to collect protocol-based
TMI using embedded Modbus over TCP mechanisms to ensure the protection of transmitted data
(streaming encryption). The IEEE 802.15.4 and IEEE 802.15.4e protocols and their architecture levels
follow the IETF standards.</p>
    </sec>
    <sec id="sec-6">
      <title>6. Development of the structure of the subsystem for receiving, storing and processing TMI in AIS</title>
      <p>The organizations for receiving and distributing TMIs on PIs are implemented according to the
threetier CISCO model and Security Architecture for Enterprise (SAFE) design methodology, which allows
to take into account modern experience in deploying secure networks based on the deep-echelon
defense against external and internal attacks.</p>
      <p>The main element of the TMI distributed processing system is the distributed file system HDFS.
Additional measures to ensure the confidentiality of stored data is encryption at the level of individual
database columns. To audit access to big data, you need to apply Database Activity Monitoring class
solutions.</p>
    </sec>
    <sec id="sec-7">
      <title>7. The concept of data integrity and verification of data sources</title>
      <p>
        The actual problem is the security of industrial networks, which is not solved by existing approaches,
since the attacker's intervention is possible not only at the network level from outside or inside, but
also at the level of the data sources themselves. The main hardware and software part of the CTP is
free from possible "bookmarks", which is guaranteed by the manufacturer, but it is necessary to
comprehensively analyze the progress of the object, identifying abnormal situations not related to
equipment breakdowns or failure of individual components and assemblies, but potentially caused by
the intervention of an attacker. It is necessary to improve the monitoring system of CTP as an element
of the intrusion detection system, considering the complexity of the control object, the nonlinearity of
the processes and the possible conditions of the equipment that lead to emergency or catastrophic
situations. The system of monitoring the condition of CTP, implemented as a component of the
intrusion detection system, involves continuous monitoring of the parameters of CTP to identify
significant deviations from the" normal behavior", which in turn will indicate possible malicious
intentions. This approach is a development of the concept of Data Centric Security [
        <xref ref-type="bibr" rid="ref2">7</xref>
        ], which implies
the security of the data itself. To determine deviations from the" normal behavior " it is proposed to
use the system model of the object – the CTP, which is the development of the concept of Fault
Detection and Identification [
        <xref ref-type="bibr" rid="ref3">8</xref>
        ]. The process of monitoring the state of the CTP is a sequential
operation of collection, processing and analysis of technological information, the main of which is to
detect the impact of an attacker on the course of the CTP and the components of the information
system by comparing the mathematical model of the CTP and the current performance of the real
object will improve the security of the object. Using the proposed concept of monitoring the CTP
comparing the fixed state of the object with the real model is a tool that allows you to control the
presence of hardware and software interventions in the infrastructure of the information system.
      </p>
      <p>The algorithm is based on a comparison of the characteristics of time series arriving from the
aircraft, and time series generated by the gas turbine engine (GTE) model which is simulating the
same mode and the same flight conditions in which the GTE operates in real time. Information
receiving from A/C is the result of GTE and its ACS operation.</p>
      <p>Figure 7 shows the block diagram of the monitoring system of GTE A/C TMI parameters. The AIS
of the manufacturer receives the vector of specified values of the controlled coordinates of the object
Y0, the vector of perturbing factors F and the vector of measured perturbing factors F’. The control
object receives the vector of control actions U generated by the control system. Data from the
monitoring system via a communication channel is sent to the manufacturer. The communication
channel can be exposed both to an attacker (the Z vector) and to the external environment that
generates noise (the N vector). Similar control signals are received in a model that simulates signals
from A/C sensors.</p>
      <p>A set of GTE parameters was selected to analyze the data discrepancies obtained from the model
and data obtained from the aircraft. The k-means clustering method was performed on the training
sample, during which nine types of GTE behavior dynamics were identified.</p>
      <p>For carrying out preliminary experiments and learning the decision block for each type of
dynamics, its own neural network NARX model was built.</p>
      <p>
        For real-time integrity monitoring, a multidimensional time series (TS) of the mismatch parameters
of model data and TMI indicators for a sliding window is constructed [
        <xref ref-type="bibr" rid="ref4">9</xref>
        ].
      </p>
      <p>
        To make a final decision on the state of the data transmission system from the aircraft and the
presence or absence of intruder interventions into the data channel, a decision block was built that
takes into account not only the type of data mismatch from the aircraft and the data generated by the
model, but also the signal control systems about the state of the GTE, obtained from the aircraft in real
time, as well as the type of dynamics of the GTE at a given time. All these three parameters are taken
into account for the block to make a decision on the state of the data transmission channel ("break",
"normal operation", "integrity violation", etc.). The second output signal of the decision block is an
estimation of the degree of confidence about the decision made, namely the estimate of the probability
of such a state, calculated from the three input parameters [
        <xref ref-type="bibr" rid="ref5">10</xref>
        ].
      </p>
    </sec>
    <sec id="sec-8">
      <title>8. Simulation of possible situations arising during the A/C operation</title>
      <p>Experiment 1.</p>
      <p>In this example, a hardware failure or interruption in signal transmission occurs. From the figure it is
clear that, starting with iteration 85, the values of the data received from the object have changed
dramatically and the value of their average value has decreased relative to the average value of the
previous values obtained from the sensor of the technological process. The changes in the values are
shown in Fig. 8. The fall of the amplitude of the received signal occurred almost at the last iterations
in the current time window.</p>
      <p>When calculating the correlation and determination coefficients, the following results were</p>
      <p>In this example, the signal drop occurred earlier than in the previous one. This explains the lower
values of the correlation coefficients and determination, and the percentage of errors, on the contrary,
The average value of the coefficients indicates possible problems with the data obtained from the
For an additional test of this data, the MAP coefficient was calculated:
Check the value of the MAPE coefficient before the jump:</p>
      <p>As can be seen, the MAPE coefficient has changed, but not critically. Such a small change in the
level of MAPE error and the average value of the correlation and determination coefficients is due to
the late signal jump in the time window.</p>
      <sec id="sec-8-1">
        <title>Experiment 2.</title>
        <p>In this example, the signal transmission is also interrupted. At about 77 iterations, the average value of
the transmitted signal has changed dramatically in comparison with previous data. As in the previous
example, in the current time series, signal distortion occurs at late iterations, which will reduce the
sensitivity of the coefficients of determination and correlation.</p>
        <p>When calculating the correlation and determination coefficients, the following results were
The values of both coefficients are too low, which indicates a serious problem with the received
data. Calculate the coefficient MAPE:
transmission channel.</p>
        <p>The MAPE error rate is high, which confirms the hypothesis that there are problems in the data
Calculate the MAPE coefficient before the start of problems with the signal:
= 0.19
= 0.08
MAPE=16,31%</p>
        <p>MAPE = 4.11%
is higher. It is also worth noting that the percentage of errors before the start of the signal jumps is
approximately the same in both examples.</p>
      </sec>
      <sec id="sec-8-2">
        <title>Experiment 3.</title>
        <p>This experiment also illustrates problems with signal transmission or equipment failure. The fall in the
average value occurs in the time window fairly early, at about 37 iterations.</p>
        <p>When calculating the correlation and determination coefficients, the following results were</p>
        <p>The values of both coefficients are too low, which indicates a serious problem with the received
data. Calculate the coefficient MAPE:
transmission channel.</p>
        <p>The MAPE error rate is high, which confirms the hypothesis that there are problems in the data
Calculate the MAPE coefficient before the start of problems with the signal:</p>
        <p>= 0,36</p>
        <p>The correlation coefficient is not too different from the previous example, but the MAPE error rate
is very high. Such a large value is due to the early appearance of signal distortion in the time window.</p>
      </sec>
      <sec id="sec-8-3">
        <title>Experiment 4. This experiment is different from previous ones. Here, starting from the 69th iteration, there is a smooth growth of data values obtained from the technological process in parallel with the growth of</title>
        <p>and determination.
model values; however, the average value of the received signal is significantly higher than the
reference data. Such data behavior may have a weak effect on the values of the correlation coefficient
When calculating the correlation and determination coefficients, the following results were
As shown by calculations, the coefficients of determination and correlation take a very high value.
However, when paired with a high MAPE, the values obtained should raise suspicions. There may be
problems with the equipment, as well as falsification of the transmitted data.</p>
      </sec>
      <sec id="sec-8-4">
        <title>Experiment 5.</title>
        <p>This experiment is a case where nothing happened to the data and it is transmitted normally.</p>
        <p>The values of both coefficients are too low, which indicates a serious problem with the received
data. Calculate the coefficient MAPE:
transmission channel.</p>
        <p>The MAPE error rate is high, which confirms the hypothesis that there are problems in the data
Calculate the MAPE coefficient before the start of problems with the signal:</p>
        <p>When calculating the correlation and determination coefficients, the following results were</p>
      </sec>
      <sec id="sec-8-5">
        <title>Calculate the coefficient MAPE:</title>
        <p>resulting data can be trusted.</p>
      </sec>
      <sec id="sec-8-6">
        <title>Experiment 6. and not distorted in any way. obtained: The combination of these three factors indicates that there are no problems with the signal. The</title>
        <p>This example is similar to the previous one. Here the data obtained from the aircraft is just noisy
When calculating the correlation and determination coefficients, the following results were</p>
      </sec>
      <sec id="sec-8-7">
        <title>Calculate the coefficient MAPE:</title>
        <p>= 0.98
= 0.97
MAPE=23.11%
MAPE = 5.01%</p>
        <p>= 0.94
 = 0.90
MAPE=4.72%</p>
        <p>= 0.76
 = 0.58</p>
        <p>MAPE=2.38%</p>
        <p>The correlation and determination coefficients show the average value of the relationship between
the data obtained from the model and the data obtained from the object of the technological process.
However, the MAPE value is low. This combination of the three coefficients allows us to say that
everything is in order with the obtained data and that they can be trusted.</p>
      </sec>
      <sec id="sec-8-8">
        <title>Experiment 7. This experiment explains the low correlation coefficient from example two. Here, as well as in the two previous experiments, data is presented that has not been changed by the attacker. Figure 13. Simulation experiment №6 of hardware failure.</title>
        <p>When calculating the correlation and determination coefficients, the following results were</p>
      </sec>
      <sec id="sec-8-9">
        <title>Calculate the coefficient MAPE:</title>
        <p />
        <p>= 0.21
 = 0.04</p>
        <p>MAPE=4.25%</p>
        <p>Such a low correlation coefficient and determination may appear not only in case of equipment
failure or fake messages. In the case when the model readings are close to a constant, and the data
from the technological object undergo analog-digital transformations and undergo slight distortions
during transmission, the correlation coefficient takes very low values. However, the MAPE coefficient
shows a small percentage of errors, which means that the deviations of the model and TP object values
are insignificant. Data can be trusted.</p>
      </sec>
    </sec>
    <sec id="sec-9">
      <title>9. The rule base for decision making</title>
      <p>For the decision block, the following set of rules was developed, on the basis of which the decision on
the integrity of the transmitted TMI was made.</p>
      <p>CMS is the channel monitoring system. In case if CMS = 1, everything is normal with the channel,
otherwise - CMS = 0;
signal breakage occurred;</p>
      <p>Rule 1. 

=</p>
      <p>′ middle′</p>
      <sec id="sec-9-1">
        <title>Rule</title>
        <p>Rule
breakage occurred;
breakage occurred;




=′ low′ 
=′ low′ 
=′ high′)
=′ high′)
operation.
10. Conclusion
(
(
(
(
(
( =
′ middle′)
(
=</p>
        <p>′ middle′) AND(CMS=0) THEN
( =′ low′)
( =′ low′)
( =′ high′)
(  =′ high′)
=′ high′)AND
=′ high′)AND
= ′high′) 
(CMS=0) THEN</p>
        <p>signal
(CMS=0) THEN</p>
        <p>signal
(CMS=1) THEN data fraud
= ′high′) AND (CMS=1) THEN normal
=′ средний′)И( =′ средний′)И(
= ′низкий′) И (CMS=1) THEN normal
Rule 7. ( 
=′ low′) 
( =′ low′)
= ′low′) AND (CMS=1) THEN normal
A block diagram of a protected system for collecting, storing and processing telemetric information on
the state of aircraft subsystems based on the modular principle is proposed. The difference of the
proposed solution is that it contains rather large subsystems with a high degree of connectivity of the
components inside and a sufficient degree of autonomy at the level of interaction of the subsystems
themselves. Each subsystem is built on the basis of organizational principles specific to the specifics
of the problem being solved, and is governed by existing regulatory documents to ensure specific
aspects of the system's reliability.</p>
        <p>An algorithm for monitoring the integrity of the TMI on the state of the GTE in service has been
developed, which determines the type of TS dynamics coming not only from the aircraft, but also the
type of the TS model and GTE mismatch dynamics, which allows evaluating the actual state of the
GTE ACS and detecting intrusion interference.
11. References</p>
        <p>Internet of Things Volume G4: Security Framework URL: http://www.iiconsortium.org/
Rapolu B 2016 Internet of Aircraft Things: An Industry Set to be Transformed AVIATION
WEEK NETWORK URL: http://aviationweek.com/connected-aerospace/internet
aircraft-thingsAircraft</p>
        <p>Hacking</p>
      </sec>
      <sec id="sec-9-2">
        <title>Practical</title>
      </sec>
      <sec id="sec-9-3">
        <title>Aero</title>
      </sec>
      <sec id="sec-9-4">
        <title>Series</title>
        <p>n.runs</p>
        <sec id="sec-9-4-1">
          <title>Professionals</title>
        </sec>
        <sec id="sec-9-4-2">
          <title>Stations</title>
        </sec>
      </sec>
      <sec id="sec-9-5">
        <title>URL: http:// www.sita.aero/file/3744/Aircom (10.11.2018) Frid A I, Vulfin A M, Zakharov D Ju, Berkholts V V and Mironov K V 2017 Architecture of the security access system for information on the state of automatic control systems of aircraft</title>
        <p>Proc. of the 19th Int. Workshop on Computer Science and Information Technologies 2 21-27
Frid A I, Vulfin A M and Berkholts V V 2018 Analysis of the methods of constructing
information attack models for the system of telemetric information transmission Proc. of the
Information Technology Intelligent Decision Support (Russia: Ufa) 226-229</p>
      </sec>
    </sec>
    <sec id="sec-10">
      <title>Acknowledgments</title>
      <p>This work is partially supported by the Russian Science Foundation under grants № 17-07-00351.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Rapolu</surname>
            <given-names>B 2016</given-names>
          </string-name>
          <article-title>Internet of aircraft things: an industry set to be transformed AVIATION WEEK NETWORK URL: http://aviationweek.com/connected-aerospace/internet-aircraft-thingsindustry-set-be-</article-title>
          <string-name>
            <surname>transformed</surname>
          </string-name>
          (
          <volume>13</volume>
          .
          <fpage>11</fpage>
          .
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Zhang</surname>
            <given-names>L</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Afanasyev</surname>
            <given-names>A</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Burke</surname>
            <given-names>J</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jacobson</surname>
            <given-names>V</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Crowley</surname>
            <given-names>P</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Papadopoulos</surname>
            <given-names>C</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            <given-names>L</given-names>
          </string-name>
          and
          <string-name>
            <surname>Zhang B 2014 Named Data Networking ACM SIGCOMM Computer Communication</surname>
          </string-name>
          Review
          <volume>44</volume>
          (
          <issue>3</issue>
          )
          <fpage>66</fpage>
          -
          <lpage>73</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Choi</surname>
            <given-names>S W</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lee</surname>
            <given-names>C</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lee J M</surname>
            ,
            <given-names>Park J H and Lee I B 2005</given-names>
          </string-name>
          <article-title>Fault detection and identification of nonlinear processes based on kernel PCA Chemometrics</article-title>
          and
          <source>Intelligent Laboratory Systems</source>
          <volume>75</volume>
          (
          <issue>1</issue>
          )
          <fpage>55</fpage>
          -
          <lpage>67</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Kropotov</given-names>
            <surname>Yu</surname>
          </string-name>
          <string-name>
            <given-names>A</given-names>
            ,
            <surname>Proskuryakov</surname>
          </string-name>
          <string-name>
            <surname>A Yu</surname>
          </string-name>
          and
          <article-title>Belov A A 2018 A method for predicting changes in the parameters of time series in digital information control systems</article-title>
          <source>Computer Optics</source>
          <volume>42</volume>
          (
          <issue>6</issue>
          )
          <fpage>1093</fpage>
          -
          <lpage>1100</lpage>
          DOI: 10.18287/
          <fpage>2412</fpage>
          -6179-2018-42-6-
          <fpage>1093</fpage>
          -1100
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Plotnikov</surname>
            <given-names>D E</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kolbudaev</surname>
            <given-names>P A</given-names>
          </string-name>
          and
          <string-name>
            <surname>Bartalev</surname>
            <given-names>S A</given-names>
          </string-name>
          <year>2018</year>
          <article-title>Identification of dynamically homogeneous areas with time series segmentation of remote sensing data</article-title>
          <source>Computer Optics</source>
          <volume>42</volume>
          (
          <issue>3</issue>
          )
          <fpage>447</fpage>
          -
          <lpage>56</lpage>
          DOI: 10.18287/
          <fpage>2412</fpage>
          -6179-2018-42-3-
          <fpage>447</fpage>
          -456
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>