Rough Draft Peer Review Submission

profilerevenant33
RohanLucas_5.4_ASCI_530_RoughDraft-1.docx

7

SECURITY THREATS DUE TO THE PROLIFERATION OF UAS

Key Requirements and Considerations for Mitigating Security

Threats Due to the Proliferation of Unmanned Aircraft Systems

ASCI 530 – Unmanned Aerospace Systems

Research Project

Embry-Riddle Aeronautical University-Worldwide

October 22, 2019

Abstract

This research project aims to holistically explore a wide range of security threats presented by Unmanned Aircraft Systems (UAS) to respective civilian and military entities as well as the potential consequences that could arise in case of negligence. Furthermore, the viability of the current traffic management system as well as potential loopholes within existing regulations and policies will be evaluated to identify whether any amendments to the current framework could be made. In addition, various technological solutions that could help enforce anti-UAS measures such as geofencing, radio-frequency signal jamming and use of predatory interceptors will also be rationalized as it is critical they are not only cost-effective but also do not create unintended safety hazards.

Keywords: Drones, Risk Mitigation, Security, Unmanned Aircraft Systems

Summary

Unmanned Aircraft Systems (UAS) present an expansive range of security threats within the overarching air transportation system that need to be effectively mitigated in order to ensure public safety and business continuity. In recent years, there have been several examples of rogue UAS being utilized in malicious and irresponsible ways resulting in severe safety and financial related consequences. Recent cases such as the major disruptions caused by rogue drones operating in restricted airspace at key airport hubs such as London Gatwick (LGW) not only resulted in unrealized revenues in excess of $20 million for operators such as easyJet, but also the cancellation of over 1,000 flights which impacted roughly 140,000 passengers in the region (Selinger, 2019). Other security threats in the form of terrorist attacks, cybersecurity, illegal surveillance, reconnaissance, smuggling, and mid-air collisions present further cause for concern for the relevant authorities (Sathyamoorthy, 2015).

Given the unique challenges presented by UAS and the relative infancy of the industry itself, an exploratory research design will be implemented to analyze the related threats and provide a deeper insight into the root causes and consequences of regulators not being adequately prepared for such risks. In addition, the research design fosters a platform for generation of new thinking and methodologies that will be pivotal in addressing future research problems in the domain. Given the global nature of these security concerns and the far-reaching effects not only on the entire aviation ecosystem but also on national safety, state authorities and militaries simply cannot afford to neglect this critical area (Sims, 2018). A variety of internal and external factors contribute to the complexity of the issue when it comes to mitigating the relevant threats while current controls in the form of contingency strategies and regulations in place are inadequate in solving these issues efficiently (Solodov, Williams, Hanaei and Goddard, 2018). Thus, it will take a collaborative industry-wide effort to transition beyond the current reactive measures in place to a more proactive system which has strategic contingencies for such extenuating circumstances.

Problem Statement

Several studies have highlighted the threat posed due to the proliferation of UAS and the resulting security related risks to society. With rapid technological advancement and economies of scale, UAS are now more affordable and accessible to the general public and their increasing functionality present a viable alternative for illegal purposes either due to irresponsible use or rogue actors. Card (2014) details the potential threats from a terrorist perspective to a highly developed country such as the United States and the need for government to utilize several strategies to address such a fast-emerging threat. Wiesbeck (2015) highlights the current technological solutions that can be applied to detect, track and control UAS from a regulatory perspective. However, depending on the situation, careful consideration needs to be given for each alternative to avoid spillover effects in the form of additional safety implications.

The specific problem is that there while there are several piecemeal solutions available to counter the security risks posed by UAS, there is a lack of a harmonized framework that enable authorities to employ contingency plans which systematically mitigate these threats in the safest, most proactive and efficient manner. In most cases, threats are identified too late and the risk for collateral damage is extremely high. These are highlighted by the recent UAS related security breaches in Europe and the Middle East (Solodov, Williams, Hanaei and Goddard, 2018). The findings of this research paper could provide the foundation for a formalized framework between regulators and help support future use cases and operational trials that aim to identify optimal response and mitigation strategies pertaining to UAS related threats.

Significance of the Problem Comment by Rohan Lucas: Rough draft version – to be expanded upon for final draft

Background

In recent years, several anonymous UAS security incidents have given state authorities some serious food for thought when it comes to the management and policing of rogue unmanned aircraft. This is an issue that is two-fold with the first issue being a severe lack of awareness and knowledge of how to safely operate UAS, particularly among recreational users. From smaller UAS that are operated in congested urban environments that could pose a risk to the general public in the form of collision or privacy invasion, to more serious incidents such as operation near airport terminals. Incidents in Dubai, London Gatwick and Heathrow airports have already resulted in losses in the tens of millions of dollars and consequently impacted hundreds of thousands of passengers. Airlines alone were reported to have suffered over $64.5 million from Gatwick’s 33-hour closure alone (Detrick, 2019) and aviation stakeholders risk losing much more if prevention measures are not put in place.

The second serious and more pressing issue is the intentional utilization of rogue UAS for terrorism and related criminal activities with several close calls already taking place in public events which draw huge crowds. Significant examples include UAS crash landings at campaign rallies in Germany held by Chancellor Angel Merkel and a University of Texas game in August 2014 where a unidentified drone hovered over nearly 100,000 football fans. Perhaps the most concerning incident was in January 2015 where a UAS was able to breach White House radar and surveillance systems before crash landing into a connected compound highlighting the ease at which a third party could penetrate a supposedly secure public vicinity with lives of the mass public at stake (Sathyamoorthy, 2015). In addition, drone strikes on nuclear facilities in France and more recently on Saudi Arabian oil facilities in September 2019 have raised concerns of international espionage and political agendas that aim to target opposition states as well. This supports the initial analysis carried out by Bhattacharjee (2015) who not only notes the increasing number of countries equipping for ‘modern warfare’ using UAS for counter terrorism but also the transition of malicious third parties gradually being able to replicate these systems for illegal purposes.

Related Research and Development

Although majority of related research and development has been mostly exploratory in nature given the recent proliferation of UAS, the underlying theme has centered on the steadily increasing number of security threats and the lack of a formalized contingency plan. Selinger (2019) acknowledged the need of several counter measures consisting of various systems and sensors to be seamlessly integrated in order to build a robust security framework that is capable of nullifying different types of threats. Despite several initiatives between regulators and corporate entities, the study came across similar limitations due to no industry consensus on what is the optimal strategy in mitigating UAS security threats.

Analysis by Sims (2018) concluded that militaries need to continue to dedicate resources in combating militant and espionage threats especially as non-state actors continue to refine their UAS capabilities. A potentially effective avenue to explore would be the possibility of coordination between military and commercial entities to delve further into research with the common objective of enhancing technological solutions geared to counter UAS. The author refers to previous research undertaken by The Defense Advanced Research Projects Agency who have investigated UAS counter measures for the US military with transferable use in complex urban environments. However, considering the confidentiality pertaining to military projects, sharing of information would be a major hurdle that would need to be overcome.

Technological Advancements Comment by Rohan Lucas: To be finalized for final draft including analysis of applicability, affordability and effectiveness of each solution

Technological advancements hold the key to ensuring contingency plans are robust enough to respond to unforeseen security threats posed by UAS. In this regard, technology-based solutions can be categorized based on their functionality of either detection, tracking or control. Additional analysis on studies such as those previously carried out by Wiesbeck (2015) cover a range of solutions including:

· Radio-frequency signal analyzer

· Location tracking of position link and GPS spoofing

· Audio/video detection

· Uncooperative radar (primary surveillance, holographic and multi-illuminators)

· Electro-optical tracking

· Dynamic Geofencing

· Radio-frequency signal jamming

· WLAN interruptions

· UAS predatory birds and interceptors

· UAS registry database for identification and tracking purposes

· Cybersecurity related measures

Alternative Actions Comment by Rohan Lucas: To be finalized for final draft. Further analysis including pros/cons will be added later

There is general consensus that a change to the current security framework is essential in order to accommodate the proliferation of UAS in the safest possible way. To address the challenges ahead, two alternative actions have been proposed in a hybrid approach to ensure adequate mitigation of security risks.

Amendments to Current Regulatory Framework and Future Mandates

Regulators need to integrate UAS security related measures into current policy and regulations to offset domestic and international threats. This includes mandates that aid regulators in detection, control and tracking of UAS via different initiatives such as drone registry databases for example. In addition, given the potential of international cross border UAS operations in the near future, building upon best practices, lessons learned and fostering a collaborative decision-making culture that aids information management will be key factors down the line.

Rationalization of Anti-UAS Technological Solutions

Given the the range of different threats, a technology agnostic approach should be taken to ensure the optimal solution is selected based on the specific conditions and environment as there is no one size fits all. By ensuring a clear cost benefit analysis along with guidance would enable the most cost effective, efficient solution that creates the least number of unintended safety hazards to be selected more often than not. In addition, an added benefit is that it would enable the relevant authorities to enforce manufacturers to follow certain requirements when it come to UAS design as well as the related security features that could be pre-installed as opposed to relying on generic commercial off-the-shelf (COTS) alternatives.

Recommendations Comment by Rohan Lucas: To be finalized for final draft

Based on the multi-faceted nature of UAS related security threats, a hybrid approach that extracts the best of the proposed alternative solutions appears to be the way forward. However, as UAS operations become increasingly globalized and sophisticated, it is paramount that security measures in place are harmonized and technological solutions are interoperable across different regions. While this will require a gradual transition due to the infrastructure limitations and resources available in different parts of the world, counter measures would not be as effective if governments opt to work in silos and implement fragmented policies to counter security threats.

Conclusion Comment by Rohan Lucas: To be finalized upon final completion of research draft and preceding sections

To be finalized upon final completion of research draft and preceding sections

References

Bhattacharjee, D. (2015, April 29). Unmanned Aerial Vehicles and Counter Terrorism Operations. Retrieved from https://www.researchgate.net/publication/314535499_Unmanned_Aerial_Vehicles_and_Counter_Terrorism_Operations.

Card, B. (2014, November 12). The Commercialization of UAVs: How Terrorists Will Be Able to Utilize UAVs to Attack the United State. Retrieved from https://www.utep.edu/liberalarts/nssi/_Files/docs/Capstone projects1/Card_Commercialization-of-UAVs.pdf.

Detrick, H. (2019, January 22). Gatwick's December Drone Closure Cost Airlines $64.5 million. Retrieved from https://fortune.com/2019/01/22/gatwick-drone-closure-cost/.

Humphreys, T. (2015, March 16). STATEMENT ON THE SECURITY THREAT POSED BY UNMANNED AERIAL SYSTEMS AND POSSIBLE COUNTERMEASURES. Retrieved from https://pdfs.semanticscholar.org/5452/8b7056e924a3cb368dc874fdc11a289d8edf.pdf.

International Air Transport Association. (2018). Key considerations when protecting manned aviation from drones. Key considerations when protecting manned aviation from drones. . International Air Transport Association. Retrieved from https://www.iata.org/whatwedo/ops-infra/air-traffic-management/Documents/11 June_Information IATA Position on Anti-Unmanned Aircraft System (Anti-UAS) Measures.pdf

Lester, E. and Weinert, A. "Three Quantitative Means to Remain Well Clear for Small UAS in the Terminal Area," 2019 Integrated Communications, Navigation and Surveillance Conference (ICNS), Herndon, VA, USA, 2019, pp. 1-17. doi: 10.1109/ICNSURV.2019.8735171 http://ieeexplore.ieee.org.ezproxy.libproxy.db.erau.edu/stamp/stamp.jsp?tp=&arnumber=8735171&isnumber=8735100

Rani, C., Modares, H., Sriram, R., Mikulski, D., & Lewis, F. L. (2016). Security of unmanned aerial vehicle systems against cyber-physical attacks. The Journal of Defense Modeling and Simulation, 13(3), 331–342. https://doi.org/ 10.1177/1548512915617252

Sathyamoorthy, D. (2015). A REVIEW OF SECURITY THREATS OF UNMANNED AERIAL VEHICLES AND MITIGATION STEPS. The Journal of Defence and Security, 6(1), 81-II. Retrieved from http://ezproxy.libproxy.db.erau.edu/login?url=https://search-proquest-com.ezproxy.libproxy.db.erau.edu/docview/1768942810?accountid=27203

Selinger, M. (May 2019). COUNTERDRONE CHALLENGES. Aerospace America. Retrieved from https://advance-lexis-com.ezproxy.libproxy.db.erau.edu/api/document?collection=news&id=urn:contentItem:5W63-XFJ1-DYRW-V4FB-00000-00&context=1516831.

Sims, A. (2018). The rising drone threat from terrorists. Georgetown Journal of International Affairs, 19, 97. Retrieved from http://ezproxy.libproxy.db.erau.edu/login?url=https://search-proquest-com.ezproxy.libproxy.db.erau.edu/docview/2164974307?accountid=27203

Solodov, A., Williams, A., Hanaei, S. A., & Goddard, B. (2018). Analyzing the threat of unmanned aerial vehicles (UAV) to nuclear facilities. Security Journal, 31(1), 305-324. doi:http://dx.doi.org.ezproxy.libproxy.db.erau.edu/10.1057/s41284-017-0102-5

Wiesbeck, W. (2015, June 17). Unmanned Aerial Vehicles – UAV, Drones Detection, Tracking, Control. Retrieved from http://www.terjin.com/dl/summit/Summit2015_10Wiesbeck.pdf.