New McGill partnership targets cybersecurity risks in aerospace systems

Working with the Royal Military College of Canada, Queen’s University and CAE, researchers are using AI to monitor and detect threats across complex communication networks

A new collaboration involving McGill University is set to address the growing cybersecurity gap in space and aerospace systems, where long mission lifespans and reliance on legacy technologies prevent regular updates, even as cyberattacks grow increasingly sophisticated.

McGill, Queen’s University, the Royal Military College of Canada and CAE, an aviation training and simulation technology company headquartered in Montreal, are confronting this challenge by partnering to develop a novel AI-based Intrusion Detection System (IDS).

Steven Ding

The research team, led by Professor Steven Ding at McGill’s School of Information Studies, was recently awarded $500,000 in funding from the National Cybersecurity Consortium (NCC) to support this work. For its part, CAE is providing $47,762 of in-kind support.

“Many legacy satellite systems worldwide were designed before today’s highly interconnected operational environments became standard,” Ding explained. “The increasing use of networked tools and mobile devices across aerospace operations can introduce new categories of cyber risk. This project aims to improve understanding of how monitoring and mitigation strategies can be integrated into such environments.”

“With increased systems interconnectivity and links to the internet, many satellites and defence platforms are becoming exposed to threats they were never designed to handle,” added Eric Chung, an Engineering Manager for the CF-18 Mission Systems with CAE. “Moreover, with manufacturing spread across different suppliers, cybersecurity researchers and operators of defence platforms are interested in stopping malicious components before they enter the supply chain.”

The technology the team is developing also has civilian applications.

“On the civil side, airliners buy planes that they fly for decades. With updates like onboard internet, there are more vectors for cyber intrusion. We need systems to detect cyber anomalies, especially with platforms that were never designed for this in the first place,” Chung said.

 

Designed to adapt

Unlike existing technology, this IDS is adaptable to multiple communication systems, as the AI can teach itself how new systems work and automatically spot suspicious activity, without needing constant manual updates.

Ding likens it to standing in a crowded room where multiple languages are being spoken. Unless the listener – in this case, the AI – understands each language, it may not be able to identify a threat.

“The biggest challenge is that these systems rely on many different communication protocols,” Ding said. “As auditors, we want to listen in and identify any suspicious conversations, which is much harder when there isn’t just one language.”

The project has three main parts: the AI system, which learns how unfamiliar communication protocols work by analyzing raw data; an automated security tool that spots unusual activity and explains its findings in clear language; and a human-AI interface that lets users give feedback to improve accuracy over time.

The team said it plans to explore joint commercialization and further partnerships with industry.