Potential Cyber Threats, Vulnerabilities, and Protections of Unmanned Vehicles

التهديدات السيبرانية المحتملة ونقاط الضعف والحماية للمركبات غير المأهولة

👤 Aybars Oruc (Aybars Oruç) 🏛 Norwegian University of Science and Technology, Gjøvik, Norway 📄 J. Unmanned Vehicle Systems 10(1), 67–82, 2022 🔗 10.1139/juvs-2021-0022 ✓ CC BY 4.0

الملخص

تهدف هذه الدراسة إلى المساهمة في الأدبيات العلمية من خلال تقديم نقاش حول المخاطر السيبرانية المحتملة والتدابير الاحترازية المتعلقة بالمركبات غير المأهولة ككل. في هذه الدراسة، تم تحديد انتحال نظام الملاحة العالمي عبر الأقمار الصناعية (GNSS)، والتشويش (jamming)، واختراق كلمات المرور، وهجمات حجب الخدمة (DoS)، وحقن البرامج الضارة (malware)، وتعديل البرامج الثابتة (firmware) كطرق هجوم إلكتروني محتملة ضد المركبات غير المأهولة. كما تم اقتراح وسائل ردع محتملة ضد طرق الهجوم الإلكتروني المذكورة. تشمل الأمثلة على هذه الضمانات إنشاء بنية نظام متعدد الوكلاء (multi-agent system)، واستخدام مكونات تخزين صلبة (solid-state storage)، وتطبيق أدوات وتقنيات البرمجة الموزعة، وتنفيذ تقنيات تشفير متطورة لتخزين البيانات ونقلها، ونشر أجهزة استشعار وأنظمة إضافية، ومقارنة البيانات الواردة من أجهزة استشعار مختلفة.

1. المقدمة

تتطور التكنولوجيا بسرعة، وتم دمج العديد من التقنيات المختلفة لتحويل المركبات غير المأهولة إلى واقع. تشمل الفئات التكنولوجية أجهزة الاستشعار، والاتصالات، والمعلومات، والشبكات، والأتمتة. تجمع الأتمتة بين أنظمة التحكم وأجهزة الاستشعار لإنجاز المهام التي تتطلب أنظمة متعددة. تعتمد المركبات غير المأهولة بشكل كامل على البيانات للتشغيل الموثوق (Madan et al. 2019). تقوم الأنظمة السيبرانية في المركبات ذاتية القيادة بجمع البيانات وكذلك تخزينها ومعالجتها وإنشاء بيانات جديدة لأداء المهام الموكلة إليها. تثير الثغرات غير المقصودة في برمجيات المركبات والهجمات السيبرانية التي يحاولها الجهات الخبيثة العديد من الشكوك حول سلامة وأمن وموثوقية المركبات غير المأهولة.

تعتبر هذه الدراسة مهمة لفهم المخاطر السيبرانية للمركبات غير المأهولة بما في ذلك تهديدات السلامة (integrity) والتوافر (availability) والسرية (confidentiality). علاوة على ذلك، تم تقديم طرق الهجوم المحتملة ضد المركبات غير المأهولة واقتراح تدابير وقائية ممكنة. تم إجراء مراجعة للأدبيات في المكتبات الرقمية العلمية المعروفة للإجابة على أسئلة البحث للدراسة. الدراسة مفيدة للباحثين العاملين في مجال الأمن السيبراني أو المركبات غير المأهولة. يبحث Parkinson et al. (2017) في التهديدات السيبرانية للمركبات المستقلة والمتصلة، مع تركيز خاص على المخاطر السيبرانية للسيارات الذكية. يلاحظ المؤلفون نقصاً في الأبحاث في الأدبيات حول الثغرات السيبرانية للجيروسكوبات وأجهزة استشعار الميل في المركبات غير المأهولة. في الوقت نفسه، يركز Madan et al. (2019) على الثغرات السيبرانية للمركبات الجوية غير المأهولة (UAVs)، ويناقش نمذجة التهديدات STRIDE وطريقة تقييم المخاطر لنظام تسجيل الثغرات المشترك (CVSS). تقدم دراسة أخرى (Yağdereli et al. 2015) العديد من تدابير تخفيف المخاطر ضد التهديدات والثغرات السيبرانية للمركبات غير المأهولة. ويذكر Hartmann and Steup (2013) نقاط ضعف المركبات الجوية غير المأهولة أمام الهجمات السيبرانية.

2. التهديدات السيبرانية وطرق الهجوم

تعمل الوظائف والاتصال على زيادة خطر التهديدات والثغرات السيبرانية (Parkinson et al. 2017). تؤثر التهديدات السيبرانية حالياً على المركبات غير المأهولة في ثلاث فئات أساسية: «تهديدات السرية» و«تهديدات السلامة» و«تهديدات التوافر». قد يعرض الفاعل الخبيث سرية المركبة غير المأهولة للخطر عن طريق التقاط البيانات الحساسة والكشف عنها. هذا النوع من التهديدات له أهمية أكبر للمركبات ذات الأغراض العسكرية، على وجه الخصوص، بسبب احتوائها على معلومات يحتمل أن تكون حساسة، مثل خطط العمليات والأهداف المحتملة وسجلات المراقبة (Madan et al. 2019). هناك تأثيران أساسيان على السلامة في هذه الفئة. أولاً، يمكن تغيير البيانات أو إفسادها من قبل فاعل خبيث قبل أن يستلمها المستلم. ثانياً، يفترض المهاجم هوية المرسل ويرسل بيانات مزيفة. تستخدم المركبات غير المأهولة أنواعاً مختلفة من البيانات المستلمة من أجهزة الاستشعار للتحكم في الحركة، والتي تتم معالجتها بواسطة برمجيات متنوعة.

2.1 انتحال GNSS (GNSS Spoofing)

في هجوم انتحال GNSS، يتم محاكاة إشارات GNSS الفعلية، ويتم إرسال إشارات مزيفة لخلق معرفة موقع خاطئة. يبرمج المصنعون أجهزة استقبال GNSS لاستخدام أقوى إشارة لتمكين الجهاز من الحصول على موقع أكثر دقة. وبالتالي، يجب أن تكون إشارات الانتحال أقوى من الإشارات الحقيقية في هجوم ناجح، مما يدفع جهاز استقبال GNSS لقبول إشارات GNSS المزيفة بدلاً من الإشارات الحقيقية (Humphreys et al. 2008; Parkinson et al. 2017). نتيجة لذلك، يصبح جهاز الاستقبال غير قادر على اكتشاف موقعه الحالي (والدقيق).

2.2 التشويش (Jamming)

التشويش (jamming) هو أحد أهم مشكلات بروتوكولات الاتصال اللاسلكي. يسبب هذا النوع من الهجمات تعطيلاً للخدمات عن طريق حجب الترددات الراديوية. قد تتأثر سلباً أجهزة وخدمات مختلفة بالتشويش، بما في ذلك الأجهزة التي تعمل بتقنية Bluetooth والشبكات اللاسلكية وخدمات GNSS والهواتف المحمولة. يرسل جهاز التشويش، المسمى جامر (jammer)، الإشارة على نفس تردد النظام أو الجهاز المستهدف. تسمح الطاقة الكافية لإشارة التشويش بتجاوز الإشارة الحقيقية. نتيجة لهذا الهجوم، يصبح جهاز الاستقبال غير قادر على استقبال البيانات من المرسل الحقيقي (Kesavulu et al. 2013). إجراء هجوم تشويش GNSS على مركبة غير مأهولة أبسط من انتحال GNSS (Parkinson et al. 2017). علاوة على ذلك، فإن تشويش GNSS أقل خطورة من انتحال GNSS لأن جهاز الاستقبال المستهدف قد يكتشف الحالة غير الطبيعية ويحذر مشغل المركبة غير المأهولة (Humphreys et al. 2008). ومع ذلك، لن يتمكن المشغل أو المركبة من تحديد الموقع الحالي باستخدام GNSS، وبالتالي يفقدان قدرتهما على الملاحة.

2.3 اختراق كلمات المرور (Password Cracking)

كلمة المرور مطلوبة بشكل عام للوصول إلى واجهات الصيانة للنظام. قد يتم اكتشاف كلمة المرور الصحيحة باستخدام عدة طرق لاختراق كلمات المرور، مثل هجوم القاموس (dictionary attack)، وهجوم جدول قوس قزح (rainbow table attack)، وهجوم القوة العمياء (brute force attack) (Parkinson et al. 2017). بمجرد اختراق كلمة المرور، يمكن للمهاجمين تعديل معلمات التشغيل، مما يؤثر سلباً على كفاءة وموثوقية النظام المتأثر. يستخدم هجوم القاموس قائمة من الكلمات بشكل فردي أو مجتمعة لاختراق كلمة مرور الضحية. بالمقارنة، هجوم القوة العمياء مشابه لهجوم القاموس، إلا أنه قد يستخدم كلمات غير موجودة في القواميس مع تركيبات أبجدية رقمية. على الرغم من أن استخدام هذه الطريقة قد يكون عملية مستهلكة للوقت، إلا أنه يمكن تحديد كلمة المرور في النهاية إذا لم يتخذ الضحية الاحتياطات اللازمة. يتميز هجوم جدول قوس قزح بقائمة من التجزئات المحسوبة مسبقاً (pre-computed hashes) المنشأة من كلمات المرور المحتملة، بما في ذلك خوارزمية معينة (Parkinson et al. 2017).

2.4 هجمات حجب الخدمة (DoS/DDoS)

يعد هجوم حجب الخدمة (DoS) طريقة هجوم إلكتروني فعالة ضد الشبكات. في هذه الحالة، يرسل الفاعل الخبيث حجماً كبيراً من حزم البيانات الفارغة إلى الشبكة. تستهلك حزم البيانات غير المفيدة موارد الشبكة. تصبح شبكة الضحية غير قادرة على الرد على الطلبات المفرطة المستلمة وتنهار في النهاية (David and Thomas 2019). هجوم حجب الخدمة الموزع (DDoS)، وهو أحد أشكال DoS، يصعب اكتشافه من حيث حركة المرور الخبيثة مقارنة بهجوم DoS لأن المهاجم يستخدم «أجهزة كمبيوتر زومبي» (zombie computers) خلال هذا الهجوم. يشير مصطلح «جهاز كمبيوتر زومبي» إلى جهاز كمبيوتر تمت إصابته ببرامج ضارة قبل الهجوم. يقوم المهاجم بتشغيل أجهزة الزومبي للمستخدمين غير المدركين لإرسال حزم بيانات خبيثة إلى شبكة الضحية (Gasti et al. 2013). نتيجة لهجوم DoS أو DDoS محتمل على أجهزة الاستشعار البدائية، قد تُجبر المركبة غير المأهولة نظرياً على السير بسرعة منخفضة جداً (Parkinson et al. 2017).

2.5 حقن البرامج الضارة (Malware Injection)

البرامج الضارة (malware) هي برمجيات ضارة مصممة للعمل على نظام تشغيل معين، مثل Mac OS أو Windows أو UNIX. تتوفر أنواع مختلفة من البرامج الضارة المستخدمة لأغراض مختلفة تحت أسماء متنوعة، بما في ذلك الفيروس (virus) والدودة (worm) وبرامج التجسس (spyware) والإعلانات الضارة (adware) وحصان طروادة (trojan) والروت كيت (rootkit) ومسجل المفاتيح (keylogger) وبرامج الفدية (ransomware). قد يؤدي برنامج ضار إلى إتلاف الملفات في الكمبيوتر، أو مراقبة أنشطة الضحية، أو إنشاء باب خلفي (backdoor) لهجمات أخرى. علاوة على ذلك، قد تُستخدم البرامج الضارة في الحرب السيبرانية. على سبيل المثال، يُزعم أن برنامج «Stuxnet» الضار تمت برمجته خصيصاً ضد منشأة نووية إيرانية من قبل أجهزة استخبارات أمريكية وإسرائيلية (Bettany and Halsey 2017). يمكن للبرامج الضارة إصابة أنظمة التحكم، خاصة المركبات غير المأهولة التي تحمل ركاباً، والتي قد تصاب عبر منفذ التشخيص onboard diagnostic port ومتصفحات الويب المدمجة ومشغلات الوسائط والمنافذ القابلة للإزالة (Parkinson et al. 2017).

2.6 تعديل البرامج الثابتة (Firmware Modification)

غالباً ما يصدر المصنعون إصدارات جديدة من البرامج الثابتة (firmware) المستخدمة لأنظمة المركبات غير المأهولة لإصلاح مشكلات مختلفة أو زيادة الأداء. قد يغير هذا البرنامج الثابت الجديد سلوك المركبة غير المأهولة بشكل كامل. إذا تمكن فاعل خبيث من إجراء أي تعديلات على البرامج الثابتة أو تثبيت برامج ثابتة معدلة تخص أي أنظمة في المركبة غير المأهولة، فقد تنتج حوادث (Parkinson et al. 2017).

3. نقاط الضعف في المركبات غير المأهولة

تؤدي زيادة الاتصال والوظائف في المركبات غير المأهولة إلى إدخال العديد من الثغرات الأساسية التي يمكن استغلالها من قبل الجهات الخبيثة. تمتد هذه الثغرات عبر مجالات الاتصالات والملاحة وتخزين البيانات والمكونات المادية، مما يخلق أسطح هجوم متعددة يجب معالجتها أثناء عملية التصميم والتطوير.

قنوات الاتصال اللاسلكية: تعتمد المركبات غير المأهولة بشكل كبير على الاتصالات اللاسلكية للقيادة والتحكم ونقل البيانات والملاحة. قنوات الاتصال هذه عرضة بطبيعتها للاعتراض والتشويش وهجمات الانتحال. نطاقات التردد التي تستخدمها المركبات غير المأهولة معروفة عادة ويمكن استهدافها بسهولة بمعدات متاحة تجارياً (Hartmann and Steup 2013; Parkinson et al. 2017).

الاعتماد على GNSS: تعتمد معظم أنظمة الملاحة في المركبات غير المأهولة بشكل كبير على أنظمة الملاحة العالمية عبر الأقمار الصناعية (GNSS) للحصول على معلومات الموقع والتوقيت. يخلق هذا الاعتماد نقطة فشل واحدة، مما يجعل المركبات غير المأهولة عرضة بشكل خاص لهجمات انتحال وتشويش GNSS. يُعتقد أن الاستيلاء على طائرة RQ-170 Sentinel الأمريكية بدون طيار في عام 2011 قد نتج عن هجوم انتحال GPS (Hartmann and Steup 2013).

قدرات المعالجة والطاقة المحدودة: تمتلك المركبات غير المأهولة، خاصة المركبات الجوية الصغيرة والمركبات تحت الماء غير المأهولة، قدرات معالجة محدودة على متنها وسعة بطارية محدودة. تقيد هذه القيود تنفيذ خوارزميات التشفير المعقدة وأنظمة كشف التسلل المتقدمة والتدابير الأمنية الشاملة التي تتطلب موارد حاسوبية كبيرة (Madan et al. 2019).

تحديثات البرامج الثابتة والبرمجيات غير الآمنة: تفتقر آليات تحديث البرامج الثابتة في المركبات غير المأهولة غالباً إلى تدابير أمنية كافية مثل التحقق من التوقيع الرقمي وعمليات الإقلاع الآمن (secure boot). تسمح هذه الثغرة للمهاجمين بتثبيت برامج ثابتة معدلة أو ضارة، مما قد يمنحهم السيطرة الكاملة على أنظمة المركبة (Parkinson et al. 2017).

الوصول المادي إلى واجهات التصحيح: تحتوي المركبات غير المأهولة عادةً على منافذ تشخيص وتصحيح (مثل JTAG و UART و USB) يمكن الوصول إليها فعلياً. يمكن للمهاجم الذي لديه وصول مادي ولو لفترة وجيزة استخدام هذه الواجهات لاستخراج البيانات الحساسة أو حقن البرامج الضارة أو تعديل تكوينات النظام. يُظهر إصابة برنامج تسجيل المفاتيح الخبيث (keylogger) لأنظمة قيادة طائرات Predator و Reaper الأمريكية بدون طيار في قاعدة كريتش الجوية عام 2011 أنه حتى الأنظمة العسكرية جيدة الحراسة معرضة للخطر (Shachtman 2011; Hartmann and Steup 2013).

4. تدابير الحماية والوقاية

تقدم تقنيات التشفير طرقاً فعالة لمنع تهديدات السرية؛ ومع ذلك، يجب على الخبراء استخدام طريقة قوية لمنع المهاجم من فك تشفير البيانات بسهولة. تقنيات السياسات والتشفير هي طرق تخفيف فعالة ضد تهديدات السلامة. علاوة على ذلك، يجب تخزين البيانات بشكل مشفر. بالإضافة إلى ذلك، إذا لزم الأمر، يجب نقل البيانات إلى مركز القيادة عبر بروتوكول اتصال مشفر (Madan et al. 2019). يشير التكرار (redundancy) إلى تكرار المكونات أو الوظائف في النظام (Lezoche and Panetto 2020)، ويجب مراعاته في مرحلة التصميم المبكرة للمركبة غير المأهولة، حيث قد يؤدي فقدان مكون واحد بسبب هجوم سيبراني محتمل إلى فقدان المركبة غير المأهولة.

4.1 بنية النظام متعدد الوكلاء

تتكون المركبات غير المأهولة من أنظمة فرعية متعددة—بمعنى آخر، أنظمة من أنظمة. GNSS ومعدات الاتصال وكاميرات الفيديو هي بعض الأمثلة على الأنظمة الفرعية في المركبات غير المأهولة. إنشاء بنية «نظام متعدد الوكلاء» (multi-agent system) ممكن على العديد من المركبات غير المأهولة. على وجه الخصوص، يمكن أن تكون الوكلاء البرمجيون (software agents) فعالين في اكتشاف الهجمات السيبرانية المحتملة (Yağdereli et al. 2015).

4.2 مكونات التخزين الصلبة

لتخزين البيانات في المركبات غير المأهولة، يُفضل استخدام حلول التخزين الصلبة (solid-state storage) على التخزين القائم على الأقراص الصلبة (Hartmann and Steup 2013). قد تعمل المركبات غير المأهولة في بيئات صعبة. الاهتزاز والقوى من اتجاهات مختلفة أو المجالات المغناطيسية يمكن أن تؤثر سلباً على التخزين القائم على الأقراص الصلبة، مما قد يؤدي إلى فقدان البيانات.

4.3 أدوات وتقنيات البرمجة الموزعة

يجب تطوير تدابير تخفيف للتشغيل الموثوق ضد الهجمات السيبرانية المحتملة وفشل مكونات الأجهزة أو البرمجيات. وفقاً لذلك، يجب استخدام أدوات وتقنيات البرمجة الموزعة في المركبات غير المأهولة (Yağdereli et al. 2015).

4.4 تقنيات التشفير المتطورة

يجب تطبيق تشفير قوي على جميع روابط الاتصال بين المركبة غير المأهولة ومحطة التحكم الخاصة بها، وكذلك على البيانات المخزنة على متنها. يجب تنفيذ معايير التشفير الحديثة مثل AES للبيانات المخزنة و TLS للبيانات المنقولة. يُظهر حادث 2009 حيث التقط المتمردون العراقيون بث الفيديو المباشر من طائرات أمريكية بدون طيار باستخدام برنامج SkyGrabber (بتكلفة 26 دولاراً فقط) الأهمية الحاسمة للتشفير—في ذلك الوقت، لم تستخدم الطائرات الأمريكية بدون طيار التشفير لتجنب إبطاء نقل البيانات في الوقت الفعلي (Mount and Quijano 2009; Hartmann and Steup 2013).

4.5 أجهزة استشعار وأنظمة إضافية

يجب مراقبة بيئة المركبات غير المأهولة باستمرار بواسطة أجهزة استشعار موثوقة. يوفر نظام الكشف الراديوي والمدى (RADAR) ونظام الملاحة الصوتية والمدى (SONAR) ونظام الكشف بالضوء والمدى (LIDAR) بيانات كمية عن الأجسام في البيئة بدقة في الظروف العادية (Onori et al. 2015). هذه المستشعرات مفيدة في تشغيل المركبة غير المأهولة، حيث توفر القدرة على اكتشاف وفهم حركة العوائق في البيئة وتجنب الحوادث المحتملة. تعتمد أنظمة التحكم الذاتي وأنظمة التحكم عن بعد على الوعي الظرفي (situational awareness). على الرغم من إمكانية استخدام الكاميرات لزيادة الوعي الظرفي للنظام، إلا أنه من الممكن نظرياً تشويش الكاميرات. على سبيل المثال، طائرة MQ9-Reaper بدون طيار مزودة بثلاث كاميرات (الأشعة تحت الحمراء، وضوء النهار، وتعزيز الضوء) لتقليل مخاطر التشويش (Hartmann and Steup 2013).

4.6 مقارنة البيانات من أجهزة استشعار مختلفة

مقارنة البيانات المستلمة من أجهزة استشعار مختلفة هي إجراء وقائي فعال؛ قد تستمر أجهزة الاستشعار المتأثرة بهجوم إلكتروني محتمل في نقل بيانات غير دقيقة إلى المكونات (Hartmann and Steup 2013). قد تؤثر هذه البيانات الخاطئة على عملية اتخاذ القرار في المركبات غير المأهولة. يجب الحصول على بيانات صحيحة حول مدى وسرعة الأجسام في محيط المركبة غير المأهولة. يمكن لأنظمة الاستشعار الفردية والمعزولة المساعدة في تحديد التهديدات المحتملة. يمكن تأكيد قيمة السرعة المقاسة على مستشعر سرعة العجلة من خلال مقارنتها بقيمة سرعة GNSS (Parkinson et al. 2017).

5. أنظمة الملاحة البديلة والهجينة

يمكن أيضاً تنفيذ أنظمة ملاحة بديلة للمركبات غير المأهولة. أحد الحلول المحتملة هو نظام الملاحة بالقصور الذاتي (INS)، الذي تم تطويره لتحديد المواقع دون أي إشارة خارجية. اليوم، تُستخدم هذه التقنية في الطائرات والغواصات والصواريخ الموجهة وكذلك المركبات غير المأهولة، مثل المركبات الفضائية غير المأهولة (Gaylor and Lightsey 2003)، والمركبات تحت الماء غير المأهولة (Ishibashi et al. 2007)، والمركبات الأرضية غير المأهولة (Meiling et al. 2017)، والمركبات الجوية غير المأهولة (Zhang and Hsu 2018). يمكن دمج INS مع GNSS للتحقق المتبادل من الموقع الحالي للمركبة غير المأهولة. علاوة على ذلك، فهو مفيد للبيئات التي تكون فيها المركبة خارج نطاق GNSS، مثل تحت الماء أو في الفضاء.

يمكن لوحدات GNSS الحديثة أيضاً حساب سرعة المركبة الأرضية غير المأهولة حتى لو لم تستطع GNSS توفير بيانات سرعة دقيقة مثل مستشعر العجلة. في هذه الحالة، يمكن تأكيد قيمة السرعة المقاسة على مستشعر سرعة العجلة من خلال مقارنتها بقيمة سرعة GNSS (Parkinson et al. 2017). لتقنيات GNSS أنواع مختلفة، مثل GPS الأمريكي و GLONASS الروسي و BeiDou الصيني و Galileo التابع للاتحاد الأوروبي (Jan and Tao 2016). يمكن أن يكون الجمع بين أنواع GNSS المختلفة إجراءً فعالاً للتخفيف من التهديدات السيبرانية (Moaiied and Mosavi 2016).

يمكن استخدام نظام eLORAN (Enhanced LORAN)، وهو نظام ملاحة راديوي أرضي عالي القدرة، كحل بديل لتحديد المواقع (Seo and Kim 2013). كمثال على التطبيق العملي، تخطط كوريا الجنوبية لاستخدام تقنية eLORAN على نطاق واسع لتوفير قدرة ملاحة آمنة للمركبات في محيطها (Seo and Kim 2013). قد يكون من الممكن أيضاً استخدام تقنية eLORAN لتعزيز قدرة الملاحة الآمنة للمركبات غير المأهولة. يؤكد الاستيلاء على طائرة RQ-170 Sentinel في عام 2011 من خلال هجوم انتحال GPS المشتبه به على الأهمية الحاسمة لوجود أنظمة ملاحة متكررة ومتنوعة.

6. الخاتمة

يجب تقييم المخاطر السيبرانية أثناء عملية تصميم وتطوير المركبات غير المأهولة. أُجريت هذه الدراسة لعرض المخاطر السيبرانية المحتملة وتدابير التخفيف الخاصة بالمركبات غير المأهولة. في هذه الدراسة، تم تقسيم المركبات غير المأهولة إلى ست فئات. تم إدراج التهديدات في ثلاث مجموعات كتهديدات للسرية وتهديدات للتوافر وتهديدات للسلامة. تم تحديد ست طرق للهجوم الإلكتروني ضد المركبات غير المأهولة، واقتراح تدابير حماية محتملة.

حددت مراجعة الأدبيات أيضاً فجوة بحثية تتعلق بالمركبات تحت الماء غير المأهولة (UUVs)، والتي تُستخدم على نطاق واسع في الصناعة والجيش والأوساط الأكاديمية ولكنها تتميز ببحوث علمية محدودة حول التهديدات السيبرانية. علاوة على ذلك، يمكن أن تكون دراسة شاملة مفيدة للغاية، تكشف عن الحوادث السيبرانية التي تشمل المركبات غير المأهولة، حيث تفتقر الأدبيات في هذا الصدد. تسلط الحوادث السيبرانية السابقة الضوء على أهمية الأمن السيبراني للمركبات غير المأهولة—بما في ذلك حادث 2009 لالتقاط بث الفيديو من طائرات بدون طيار أمريكية من قبل متمردين عراقيين، وحادث 2011 للاستيلاء على طائرة RQ-170 Sentinel في إيران، وإصابة أنظمة الطائرات بدون طيار الأمريكية ببرنامج تسجيل المفاتيح الخبيث في قاعدة كريتش الجوية عام 2011.

المراجع

[1] A. Oruc, "Potential Cyber Threats, Vulnerabilities, and Protections of Unmanned Vehicles," J. Unmanned Vehicle Systems, vol. 10, no. 1, pp. 67–82, 2022. doi: 10.1139/juvs-2021-0022.

[2] S. Parkinson, P. Ward, K. Wilson, and J. Miller, "Cyber threats facing autonomous and connected vehicles: future challenges," IEEE Trans. Intell. Transp. Syst., vol. 18, no. 11, pp. 2898–2915, 2017. doi: 10.1109/TITS.2017.2665968.

[3] B.B. Madan, M. Banik, and D. Bein, "Securing unmanned autonomous systems from cyber threats," J. Def. Model. Simul., vol. 16, no. 2, pp. 119–136, 2019. doi: 10.1177/1548512916628335.

[4] K. Hartmann and C. Steup, "The vulnerability of UAVs to cyber attacks - An approach to the risk assessment," in 5th Int. Conf. on Cyber Conflict (CYCON 2013), Tallinn, Estonia, IEEE, 2013, pp. 1–23.

[5] P. Gasti, G. Tsudik, E. Uzun, and L. Zhang, "DoS and DDoS in named data networking," in 2013 22nd Int. Conf. on Computer Communication and Networks (ICCCN), Nassau, Bahamas, IEEE, 2013, pp. 1–7. doi: 10.1109/ICCCN.2013.6614127.

[6] T.E. Humphreys, B.M. Ledvina, M.L. Psiaki, B.W. O'Hanlon, and P.M. Kintner, "Assessing the spoofing threat: Development of a portable GPS civilian spoofer," in Proc. 21st Int. Technical Meeting of the Satellite Division of ION (ION GNSS 2008), Savannah, GA, 2008, pp. 2314–2325.

[7] E. Yağdereli, C. Gemci, and A.Z. Aktaş, "A study on cyber-security of autonomous and unmanned vehicles," J. Def. Model. Simul., vol. 12, no. 4, pp. 369–381, 2015. doi: 10.1177/1548512915575803.

[8] J. David and C. Thomas, "Efficient DDoS flood attack detection using dynamic thresholding on flow-based network traffic," Comput. Secur., vol. 82, pp. 284–295, 2019. doi: 10.1016/j.cose.2019.01.002.

[9] A. Bettany and M. Halsey, "What is malware?" in Windows Virus and Malware Troubleshooting, Apress, 2017, pp. 1–8. doi: 10.1007/978-1-4842-2607-0_1.

[10] M. Mount and E. Quijano, "Iraqi insurgents hacked Predator drone feeds," CNN, 2009. Available: edition.cnn.com/2009/US/12/17/drone.video.hacked/index.html.

[11] N. Shachtman, "Computer virus hits U.S. drone fleet," 2011. Available: brookings.edu/opinions/computer-virus-hits-u-s-drone-fleet/.

[12] O.S.C. Kesavulu and P. Harini, "Enhanced packet delivery techniques using crypto-logic riddle on jamming attacks for wireless communication medium," Int. J. Latest Trends Eng. Technol., vol. 2, no. 4, pp. 469–478, 2013.

[13] D. Gaylor and E.G. Lightsey, "GPS/INS kalman filter design for spacecraft operating in the proximity of International Space Station," in AIAA Guidance, Navigation, and Control Conf., Austin, TX, 2003. doi: 10.2514/6.2003-5445.

[14] S. Ishibashi et al., "Accuracy improvement of an Inertial Navigation System brought about by the rotational motion," in OCEANS 2007 – Europe, Aberdeen, UK, IEEE, 2007, pp. 1–5. doi: 10.1109/OCEANSE.2007.4302282.

[15] W. Meiling et al., "Key technologies of GNSS/INS/VO deep integration for UGV navigation in urban canyon," in 11th Asian Control Conf. (ASCC), Gold Coast, Australia, IEEE, 2017, pp. 2546–2551. doi: 10.1109/ASCC.2017.8287576.

[16] G. Zhang and L.-T. Hsu, "Intelligent GNSS/INS integrated navigation system for a commercial UAV flight control system," Aerosp. Sci. Technol., vol. 80, pp. 368–380, 2018. doi: 10.1016/j.ast.2018.07.026.

[17] J. Seo and M. Kim, "eLoran in Korea – Current status and future plans," in European Navigation Conf., Vienna, Austria, 2013, pp. 23–25.

[18] S.-S. Jan and A.-L. Tao, "Comprehensive comparisons of satellite data, signals, and measurements between the BeiDou Navigation Satellite System and the Global Positioning System," Sensors, vol. 16, no. 5, p. 689, 2016. doi: 10.3390/s16050689.

[19] M.M. Moaiied and M.R. Mosavi, "Increasing accuracy of combined GPS and GLONASS positioning using fuzzy kalman filter," Iran. J. Electr. Electron. Eng., vol. 12, no. 1, pp. 21–28, 2016.

[20] D. Onori et al., "Coherent radar/lidar integrated architecture," in 2015 European Radar Conf. (EuRAD), Paris, France, IEEE, 2015, pp. 241–244. doi: 10.1109/EuRAD.2015.7346282.

[21] M. Lezoche and H. Panetto, "Cyber-physical systems, a new formal paradigm to model redundancy and resiliency," Enterp. Inf. Syst., vol. 14, no. 8, pp. 1150–1171, 2020. doi: 10.1080/17517575.2018.1536807.

Abstract

This study seeks to contribute to the literature by presenting a discussion of potential cyber risks and precautionary measures concerning unmanned vehicles as a whole. In this study, Global Navigation Satellite System (GNSS) spoofing, jamming, password cracking, denial-of-service (DoS), injecting malware, and modification of firmware are identified as potential cyberattack methods against unmanned vehicles. Potential deterrents against the aforementioned cyberattack methods are suggested as well. Illustrations of such safeguards include creating an architecture of the multi-agent system, using solid-state storage components, applying distributed programming tools and techniques, implementing sophisticated encryption techniques for data storage and transmission, deploying additional sensors and systems, and comparing the data received from different sensors.

1. Introduction

Technology is developing rapidly, and many different technologies have been combined to make unmanned vehicles a reality. Technological categories include sensors, communication, information, networking, and automation. Automation combines control systems and sensors to accomplish a task requiring many systems. Unmanned vehicles are totally dependent on data for reliable operation (Madan et al. 2019). The cyber systems in autonomous vehicles collect data as well as store, process, and compose new data to perform assigned tasks. Unintentional vulnerabilities in the vehicles' software and cyberattacks attempted by malicious actors arouse numerous suspicions regarding unmanned vehicles' safety, security, and reliability issues.

This study is important to understand the cyber risks of unmanned vehicles including integrity, availability, and confidentiality threats. Moreover, potential attack methods against unmanned vehicles are given and possible precaution measures are suggested. A literature review was performed in well-known scientific digital libraries in order to reply to the research questions of the study. The study is useful for researchers working on cyber security or unmanned vehicles. Parkinson et al. (2017) investigates the cyber threats of autonomous and connected vehicles, with a special focus on the cyber risks of intelligent automobiles. The authors note a lack of research in the literature about the cyber vulnerabilities of gyroscopes and inclination sensors in unmanned vehicles. Meanwhile, Madan et al. (2019) focuses on the cyber vulnerabilities of unmanned aerial vehicles (UAVs), discussing STRIDE threat modeling and risk assessment method of Common Vulnerability Scoring System belonging to UAVs. Another study (Yağdereli et al. 2015) propose several risk mitigation measures against cyber threats and vulnerabilities belonging to unmanned vehicles. Hartmann and Steup (2013) state the vulnerabilities of UAVs to cyberattacks.

2. Cyber Threats and Attack Methods

Functionality and connectivity enhance the risk of cyber threats and vulnerabilities (Parkinson et al. 2017). Cyber threats currently affect unmanned vehicles in three essential categories: "confidentiality threats," "integrity threats," and "availability threats." A malicious actor may endanger the confidentiality of an unmanned vehicle by capturing and disclosing sensitive data. This type of threat has more importance for military-purpose vehicles, in particular, because of having potentially sensitive information, such as operation plans, probable targets, and surveillance records (Madan et al. 2019). Two essential impacts on integrity are involved in this category. First, the data can be changed or corrupted by a malicious actor before the recipient receives them. Second, the attacker assumes the identity of the sender and sends fake data. Unmanned vehicles use different types of data received from sensors for motion control, which are processed by various software.

2.1 GNSS Spoofing

In a GNSS spoofing attack, actual GNSS signals are simulated, and fake signals are transmitted to create false location knowledge. Manufacturers program GNSS receivers to use the strongest signal to enable the receiver to acquire a more accurate position. Consequently, spoofing signals must be stronger than real signals in a successful attack, prompting the GNSS receiver to accept spoofed GNSS signals instead of real GNSS signals (Humphreys et al. 2008; Parkinson et al. 2017). As a result, the receiver is unable to detect its current (and accurate) position.

2.2 Jamming

Jamming is one of the most crucial problems of wireless communication protocols. This type of attack causes a disruption of services by blocking radio frequencies. Various devices and services may be affected negatively by jamming, including Bluetooth-enabled devices, wireless networks, GNSS services, and mobile phones. The jamming device, called a jammer, transmits the signal at the same frequency as the target system or device. Adequate power allows the jamming signal to override the genuine signal. As a result of this attack, the receiver is unable to receive data from the real transmitter (Kesavulu et al. 2013). Conducting a GNSS jamming attack on an unmanned vehicle is simpler than GNSS spoofing (Parkinson et al. 2017). Moreover, GNSS jamming is less dangerous than GNSS spoofing because the target receiver may detect the abnormal situation and warn an unmanned vehicle's operator (Humphreys et al. 2008). Nevertheless, the vehicle or the operator will be unable to determine the current location using the GNSS, thereby losing its navigation capability.

2.3 Password Cracking

A password is required to access maintenance interfaces of the system, in general. The correct password may be uncovered by the use of several password-cracking methods, such as a dictionary attack, rainbow table attack, and brute force attack (Parkinson et al. 2017). Once they have cracked the password, the attackers can modify the operational parameters, negatively impacting the efficiency and reliability of the affected system. A dictionary attack employs a list of words used individually or in combination to crack the victim's password. In comparison, a brute force attack is similar to a dictionary attack, except it may employ non-dictionary words with alphanumeric combinations. Although using this method may be a time-consuming process, the password can be identified eventually if the victim has not taken the requisite precautions. The rainbow table attack features a list of pre-computed hashes created from potential passwords, including a given algorithm (Parkinson et al. 2017).

2.4 Denial-of-Service (DoS/DDoS)

The DoS is an effective cyberattack method against networks. In this case, the malicious actor transmits a high volume of null data packages to the network. The useless data packages consume network resources. The victim's network is unable to reply to the excessive requests received and eventually breaks down (David and Thomas 2019). Distributed denial-of-service (DDoS), a variation of DoS, is harder to detect in terms of malicious traffic than a DoS attack because the attacker uses "zombie computers" during such an attack. The term "zombie computer" refers to a computer that has been infected with malware before the attack. The attacker triggers the unaware users' zombie computers to send malicious data packages to the victim's network (Gasti et al. 2013). As a consequence of a possible DoS or DDoS attack to primitive sensors, an unmanned vehicle may be theoretically forced to travel at too low a speed (Parkinson et al. 2017).

2.5 Malware Injection

Malware is harmful software designed to run on a specific operating system, such as Mac OS, Windows, or UNIX. Different types of malware employed for different purposes are available under various names, including virus, worm, spyware, adware, trojan, bot, rootkit, keylogger, and ransomware. A malware program may damage the files in a computer, monitor the victim's activities, or constitute a backdoor for further attacks. Moreover, malware may be used for cyber warfare. For instance, "Stuxnet" malware was allegedly specifically coded against an Iranian nuclear facility by U.S. and Israeli intelligence services (Bettany and Halsey 2017). Malware can infect control systems, especially unmanned automobiles having passengers, which may be infected through the onboard diagnostic port, embedded web browsers, media players, and removable ports (Parkinson et al. 2017).

2.6 Firmware Modification

Manufacturers often release new versions of the firmware used for systems in unmanned vehicles to fix various problems or increase performance. Such new firmware may completely change the behavior of an unmanned vehicle. If a malicious actor is able to make any modifications to the firmware or install modified firmware belonging to any systems in the unmanned vehicle, accidents may result (Parkinson et al. 2017).

3. Vulnerabilities of Unmanned Vehicles

The increasing connectivity and functionality of unmanned vehicles introduce several fundamental vulnerabilities that can be exploited by malicious actors. These vulnerabilities span across communication, navigation, data storage, and physical hardware domains, creating multiple attack surfaces that must be addressed during the design and development process.

Wireless Communication Channels: Unmanned vehicles rely heavily on wireless communications for command and control, data transmission, and navigation. These communication channels are inherently susceptible to interception, jamming, and spoofing attacks. The frequency bands used by unmanned vehicles are typically well-known and can be easily targeted with commercially available equipment (Hartmann and Steup 2013; Parkinson et al. 2017).

GNSS Dependency: Most unmanned vehicle navigation systems rely heavily on Global Navigation Satellite Systems (GNSS) for positioning and timing information. This reliance creates a single point of failure, making unmanned vehicles particularly vulnerable to GNSS spoofing and jamming attacks. The capture of the RQ-170 Sentinel UAV in 2011 is believed to have been caused by a GPS spoofing attack (Hartmann and Steup 2013).

Limited Power and Processing Capabilities: Unmanned vehicles, especially small UAVs and UUVs, have limited onboard processing power and battery capacity. These constraints restrict the implementation of complex encryption algorithms, advanced intrusion detection systems, and comprehensive security measures that would require significant computational resources (Madan et al. 2019).

Insecure Firmware and Software Updates: Firmware update mechanisms on unmanned vehicles often lack sufficient security measures such as digital signature verification and secure boot processes. This vulnerability allows attackers to install modified or malicious firmware, potentially gaining full control over the vehicle's systems (Parkinson et al. 2017).

Physical Access to Debug Interfaces: Unmanned vehicles typically have diagnostic and debug ports (such as JTAG, UART, and USB) that are physically accessible. An attacker with even brief physical access can use these interfaces to extract sensitive data, inject malware, or modify system configurations. The 2011 keylogger malware infection of U.S. Predator and Reaper drone cockpits at Creech Air Force Base demonstrates that even well-guarded military systems are vulnerable (Shachtman 2011; Hartmann and Steup 2013).

4. Protective and Preventive Measures

Encryption techniques offer effective methods to prevent confidentiality threats; however, experts must employ a strong method to prevent an attacker from easily decoding encrypted data. Policy-based and cryptography-based techniques are effective mitigation methods against integrity threats. Moreover, the data must be stored in encrypted form. Furthermore, if required, the data must be transmitted to the command center through an encrypted communication protocol (Madan et al. 2019). Redundancy, referring to the duplication of components or functions in a system (Lezoche and Panetto 2020), should be considered at the early design stage of an unmanned vehicle, as losing a single component due to a possible cyberattack may result in the loss of the unmanned vehicle.

4.1 Multi-Agent System Architecture

Unmanned vehicles comprise multiple subsystems—in other words, systems of systems. GNSS, communication equipment, and video cameras are some examples of subsystems on unmanned vehicles. Creating a "multi-agent system" architecture is possible on many unmanned vehicles. In particular, software agents can be effective in detecting potential cyberattacks (Yağdereli et al. 2015).

4.2 Solid-State Storage Components

For data storage in unmanned vehicles, solid-state storage solutions are preferable to hard drive-based storage (Hartmann and Steup 2013). Unmanned vehicles may work in challenging environments. Vibration, forces from different directions, or magnetic fields can affect hard-drive-based storage negatively, potentially resulting in data loss.

4.3 Distributed Programming Tools and Techniques

Mitigation measures for reliable operation must be developed against potential cyberattacks and failure of hardware or software components. Accordingly, distributed programming tools and techniques should be used in unmanned vehicles (Yağdereli et al. 2015).

4.4 Sophisticated Encryption Techniques

Strong encryption must be applied to all communication links between the unmanned vehicle and its control station, as well as to data stored onboard. Modern encryption standards such as AES for stored data and TLS for transmitted data should be implemented. The 2009 incident where Iraqi insurgents captured live video feeds from U.S. UAVs using SkyGrabber software (costing only $26) demonstrates the critical importance of encryption—at the time, U.S. UAVs did not use encryption to avoid slowing down real-time data transmission (Mount and Quijano 2009; Hartmann and Steup 2013).

4.5 Additional Sensors and Systems

The environment of unmanned vehicles must be observed constantly by reliable sensors. RAdio Detection And Ranging (RADAR), Sound Navigation And Ranging (SONAR), and LIght Detection And Ranging (LIDAR) provide quantified data of the objects in the environment accurately under normal circumstances (Onori et al. 2015). Such sensors are useful in deploying an unmanned vehicle, providing the ability to detect and understand the motion of obstacles in the environment and avoid possible accidents. Both self-control systems and remote control systems are dependent on situational awareness. Although cameras may be used to increase a system's situation awareness, it is theoretically possible to jam the cameras. For example, the MQ9-Reaper UAV is equipped with three cameras (infrared, daylight, and light enhancing) to decrease the jamming risk (Hartmann and Steup 2013).

4.6 Comparing Data from Different Sensors

Comparison of the received data from different sensors is an effective precaution; sensors affected by a potential cyberattack may go on to transmit inaccurate data to components (Hartmann and Steup 2013). This faulty data may affect unmanned vehicles' decision-making process. Correct data about the range and speed of objects in the vicinity of the unmanned vehicle must be obtained. Individual and isolated sensor systems can help identify potential threats. The measured speed value on a wheel speed sensor may be confirmed by comparing the speed value on GNSS (Parkinson et al. 2017).

5. Alternative and Hybrid Navigation Systems

Alternative navigation systems may also be implemented for unmanned vehicles. One potential solution is an Inertial Navigation System (INS), which was developed for positioning without any external signal. Today, this technology is used in aircraft, submarines, and guided missiles as well as unmanned vehicles, such as unmanned spacecraft (Gaylor and Lightsey 2003), UUVs (Ishibashi et al. 2007), UGVs (Meiling et al. 2017), and UAVs (Zhang and Hsu 2018). INS can be combined with GNSS to cross-check the current position of an unmanned vehicle. Moreover, it is useful for the environments where a vehicle would be out of range of GNSS, such as underwater or in space.

Modern GNSS units can also calculate the speed of a UGV even if GNSS cannot provide as sensitive speed data as a wheel sensor. In this case, the measured speed value on a wheel speed sensor may be confirmed by comparing the speed value on GNSS (Parkinson et al. 2017). GNSS technologies have different variations, such as the U.S.-based GPS, Russia-based Global'naya Navigatsionnaya Sputnikovaya Sistema (GLONASS), China's BeiDou, and the European Union's Galileo (Jan and Tao 2016). The combination of different GNSS variations can be an effective mitigation measure against cyber threats (Moaiied and Mosavi 2016).

Enhanced LORAN (eLORAN), a high-power terrestrial radio navigation system, can be used as an alternative positioning solution (Seo and Kim 2013). As one example of practical application, South Korea plans to widely use eLORAN technology to provide safe navigation capability to vehicles in its vicinity (Seo and Kim 2013). It may also be possible to use eLORAN technology to enhance the safe navigation capability of unmanned vehicles. The capture of the RQ-170 Sentinel in 2011 through a suspected GPS spoofing attack underscores the critical importance of having redundant and diverse navigation systems.

6. Conclusion

Cyber risks must be assessed during the design and development process of unmanned vehicles. This study was conducted to present potential cyber risks and mitigation measures of unmanned vehicles. In this study, unmanned vehicles were divided into six categories. Threats were listed in three groups as confidentiality threats, availability threats, and integrity threats. Six cyberattack methods against unmanned vehicles were identified, and probable protection measures were suggested.

The literature review also identified a research gap concerning UUVs, which are widely used in the industry, military, and academia but feature limited scientific research on cyber threats. Moreover, a comprehensive study could be highly beneficial, revealing cyber incidents involving unmanned vehicles, as the literature is lacking in this respect. Past cyber incidents highlight the importance of cybersecurity for unmanned vehicles—including the 2009 capture of UAV video feeds by Iraqi insurgents, the 2011 capture of the RQ-170 Sentinel in Iran, and the 2011 keylogger malware infection of U.S. drone systems at Creech Air Force Base.

References

[1] A. Oruc, "Potential Cyber Threats, Vulnerabilities, and Protections of Unmanned Vehicles," J. Unmanned Vehicle Systems, vol. 10, no. 1, pp. 67–82, 2022. doi: 10.1139/juvs-2021-0022.

[2] S. Parkinson, P. Ward, K. Wilson, and J. Miller, "Cyber threats facing autonomous and connected vehicles: future challenges," IEEE Trans. Intell. Transp. Syst., vol. 18, no. 11, pp. 2898–2915, 2017. doi: 10.1109/TITS.2017.2665968.

[3] B.B. Madan, M. Banik, and D. Bein, "Securing unmanned autonomous systems from cyber threats," J. Def. Model. Simul., vol. 16, no. 2, pp. 119–136, 2019. doi: 10.1177/1548512916628335.

[4] K. Hartmann and C. Steup, "The vulnerability of UAVs to cyber attacks - An approach to the risk assessment," in 5th Int. Conf. on Cyber Conflict (CYCON 2013), Tallinn, Estonia, IEEE, 2013, pp. 1–23.

[5] P. Gasti, G. Tsudik, E. Uzun, and L. Zhang, "DoS and DDoS in named data networking," in 2013 22nd Int. Conf. on Computer Communication and Networks (ICCCN), Nassau, Bahamas, IEEE, 2013, pp. 1–7. doi: 10.1109/ICCCN.2013.6614127.

[6] T.E. Humphreys, B.M. Ledvina, M.L. Psiaki, B.W. O'Hanlon, and P.M. Kintner, "Assessing the spoofing threat: Development of a portable GPS civilian spoofer," in Proc. 21st Int. Technical Meeting of the Satellite Division of ION (ION GNSS 2008), Savannah, GA, 2008, pp. 2314–2325.

[7] E. Yağdereli, C. Gemci, and A.Z. Aktaş, "A study on cyber-security of autonomous and unmanned vehicles," J. Def. Model. Simul., vol. 12, no. 4, pp. 369–381, 2015. doi: 10.1177/1548512915575803.

[8] J. David and C. Thomas, "Efficient DDoS flood attack detection using dynamic thresholding on flow-based network traffic," Comput. Secur., vol. 82, pp. 284–295, 2019. doi: 10.1016/j.cose.2019.01.002.

[9] A. Bettany and M. Halsey, "What is malware?" in Windows Virus and Malware Troubleshooting, Apress, 2017, pp. 1–8. doi: 10.1007/978-1-4842-2607-0_1.

[10] M. Mount and E. Quijano, "Iraqi insurgents hacked Predator drone feeds," CNN, 2009. Available: edition.cnn.com/2009/US/12/17/drone.video.hacked/index.html.

[11] N. Shachtman, "Computer virus hits U.S. drone fleet," 2011. Available: brookings.edu/opinions/computer-virus-hits-u-s-drone-fleet/.

[12] O.S.C. Kesavulu and P. Harini, "Enhanced packet delivery techniques using crypto-logic riddle on jamming attacks for wireless communication medium," Int. J. Latest Trends Eng. Technol., vol. 2, no. 4, pp. 469–478, 2013.

[13] D. Gaylor and E.G. Lightsey, "GPS/INS kalman filter design for spacecraft operating in the proximity of International Space Station," in AIAA Guidance, Navigation, and Control Conf., Austin, TX, 2003. doi: 10.2514/6.2003-5445.

[14] S. Ishibashi et al., "Accuracy improvement of an Inertial Navigation System brought about by the rotational motion," in OCEANS 2007 – Europe, Aberdeen, UK, IEEE, 2007, pp. 1–5. doi: 10.1109/OCEANSE.2007.4302282.

[15] W. Meiling et al., "Key technologies of GNSS/INS/VO deep integration for UGV navigation in urban canyon," in 11th Asian Control Conf. (ASCC), Gold Coast, Australia, IEEE, 2017, pp. 2546–2551. doi: 10.1109/ASCC.2017.8287576.

[16] G. Zhang and L.-T. Hsu, "Intelligent GNSS/INS integrated navigation system for a commercial UAV flight control system," Aerosp. Sci. Technol., vol. 80, pp. 368–380, 2018. doi: 10.1016/j.ast.2018.07.026.

[17] J. Seo and M. Kim, "eLoran in Korea – Current status and future plans," in European Navigation Conf., Vienna, Austria, 2013, pp. 23–25.

[18] S.-S. Jan and A.-L. Tao, "Comprehensive comparisons of satellite data, signals, and measurements between the BeiDou Navigation Satellite System and the Global Positioning System," Sensors, vol. 16, no. 5, p. 689, 2016. doi: 10.3390/s16050689.

[19] M.M. Moaiied and M.R. Mosavi, "Increasing accuracy of combined GPS and GLONASS positioning using fuzzy kalman filter," Iran. J. Electr. Electron. Eng., vol. 12, no. 1, pp. 21–28, 2016.

[20] D. Onori et al., "Coherent radar/lidar integrated architecture," in 2015 European Radar Conf. (EuRAD), Paris, France, IEEE, 2015, pp. 241–244. doi: 10.1109/EuRAD.2015.7346282.

[21] M. Lezoche and H. Panetto, "Cyber-physical systems, a new formal paradigm to model redundancy and resiliency," Enterp. Inf. Syst., vol. 14, no. 8, pp. 1150–1171, 2020. doi: 10.1080/17517575.2018.1536807.