Next Article in Journal
Multi-UAV Cooperative Pursuit of a Fast-Moving Target UAV Based on the GM-TD3 Algorithm
Previous Article in Journal
Enhancing Turbidity Predictions in Coastal Environments by Removing Obstructions from Unmanned Aerial Vehicle Multispectral Imagery Using Inpainting Techniques
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Risk Assessment of UAV Cyber Range Based on Bayesian–Nash Equilibrium

1
School of Cybersecurity, Northwestern Polytechnical University, Xi’an 710129, China
2
School of Automation, Northwestern Polytechnical University, Xi’an 710129, China
*
Author to whom correspondence should be addressed.
Drones 2024, 8(10), 556; https://doi.org/10.3390/drones8100556
Submission received: 5 September 2024 / Revised: 24 September 2024 / Accepted: 5 October 2024 / Published: 8 October 2024

Abstract

:
In order to analyze the choice of the optimal strategy of cyber security attack and defense in the unmanned aerial vehicles’ (UAVs) cyber range, a game model-based UAV cyber range risk assessment method is constructed. Through the attack and defense tree model, the risk assessment method is calculated. The model of attack and defense game with incomplete information is established and the Bayesian–Nash equilibrium of mixed strategy is calculated. The model and method focus on the mutual influence of the actions of both sides and the dynamic change in the confrontation process. According to the calculation methods of different benefits of different strategies selected in the offensive and defensive game, the risk assessment and calculation of the UAV cyber range are carried out based on the probability distribution of the defender’s benefits and the attacker’s optimal strategy selection. An example is given to prove the feasibility and effectiveness of this method.

1. Introduction

Cyber attacks pose a threat to UAV systems, making these a significant real-world issue that is currently receiving attention in the global field of cyber security [1]. As UAVs become more autonomous and intelligent, their security issues face numerous challenges as well [2]. The security issues brought about by UAVs can be divided into the following two categories:
  • Security risk to UAVs themselves, as shown in Figure 1. Modern UAVs are gradually shifting their communication protocols to universal internet protocols, and their business systems are becoming increasingly interconnected with other information systems. There is a possibility that UAV could be attacked by hackers. On the one hand [3], the information security of UAV devices is threatened. The user information carried in the UAV is a security risk, because once the attacker obtains access to the camera or storage system, the user’s personal information will be stolen or maliciously used. On the other hand [4], if attackers take control of the UAV, ground station personnel will lose effective control over the UAV, leading to the loss of the UAV or accidents such as collisions and crashes.
  • The security hazards posed by UAVs, as illustrated in Figure 2, encompass a broad spectrum of concerns. Given their agile nature and ease of operation, a UAV presents a significant risk of being weaponized by malefactors for nefarious purposes such as personal assaults, illicit surveillance, and unauthorized incursions [5]. The challenge of controlling their flight domains within shared airspace has escalated, posing unprecedented threats to public security and privacy. Recent high-profile incidents underscore the severity of this issue. The White House in the United States was subjected to unwarranted aerial surveillance by a DJI UAV [6], an intrusion that raised serious questions about national security and the protection of sensitive sites. Similarly, Kuala Lumpur International Airport in Malaysia experienced an illegal overflight by an unpermitted UAV [7], disrupting air traffic and highlighting vulnerabilities in airport security protocols. Most alarmingly, the office of the Japanese Prime Minister was breached by a UAV carrying radioactive material [8], an act that not only endangered lives but also exposed the potential for UAV to be used as tools of terror. These incidents serve as stark reminders that cyber threats extend beyond digital realms, impacting physical security and operational integrity. They pose direct challenges to national security and demand urgent attention and action from policymakers, technologists, and law enforcement agencies alike. The multifaceted security issues associated with UAVs necessitate robust regulatory frameworks, advanced detection systems, and stringent enforcement mechanisms to safeguard against misuse and ensure the responsible integration of UAVs into our airspace.
Since many UAV systems are seriously flawed in design, numerous studies and experiments have shown that the information security of current UAV systems mainly faces the following threats:
Deception. The structure and flight controller of multi-rotor UAV models were analyzed, and many shortcomings were found, which are related to serial port connections and UAV telemetry data connections, especially due to its weak communication properties, and the fact that encryption is not used in most cases [9]. The experiments [10] show that it is easy to capture, modify or inject information by means of GPS deception interference. Hackers can intercept and deceive using this vulnerability in the data link, thereby achieving complete control over the UAV.
A malware infection in UAV systems poses significant risks, particularly when considering the internal communication protocols that facilitate user control through wireless devices like tablets, laptops, and smartphones. Unfortunately, recent studies have highlighted vulnerabilities in these technologies [11], revealing that they can be exploited by malicious actors. Hackers have devised sophisticated methods to compromise UAV security by leveraging weaknesses in the transmission protocols. Specifically, they can create a reverse shell using a TCP payload, which they subsequently inject into the UAV’s memory. This intrusion allows for the clandestine installation of malicious software onto the system that runs the ground station, effectively giving the attacker unauthorized access and control over the UAV. The consequences of such an attack can range from data theft and privacy violations to complete loss of UAV functionality, endangering both the operator and bystanders. It is therefore imperative for manufacturers and users alike to prioritize cybersecurity measures, including regular updates, robust encryption, and rigorous testing of communication channels, to mitigate these risks and ensure the safe operation of UAV.
Data interference and interception. The UAV uses wireless communication and transmits information through open, non-secure wireless channels [12], making it vulnerable to various threats such as data interception, malicious data injection, and altering pre-set flight paths. This allows the UAV and GCS to be maliciously installed and injected with many infected digital files, such as videos and images [13].
Wi-Fi interference. Attackers can hijack the UAV’s communication by installing and configuring a Raspberry-pi [14] and sending an access instruction between authentication processes, such as interfering with the expected UAV frequency and luring the UAV to connect to the hacker’s Wi-Fi.
From the foregoing analysis, it is evident that cyber intrusions can incapacitate a UAV’s control system, rendering it unresponsive to legitimate commands and thereby facilitating its unauthorized commandeering. This phenomenon, where UAVs fall prey to cyber hijacks, has escalated into a critical concern, jeopardizing national security on multiple fronts.
At present, there are more studies on the physical security of UAV, but less on the information security of UAVs, because a UAV is a special CPS system, and the security research of CPS system mainly includes the directions of defense in depth, intrusion detection, and risk assessment. Among them, risk assessment can help managers judge the security level of UAV, and deploy targeted defense measures, which is of profound significance.
Many researchers at home and abroad have studied the threat assessment methods of a CPS system based on various theories. Based on fuzzy Analytic Hierarchy Process (AHP), the authors of [15] conducted hierarchical modeling of CPS system devices and attack behaviors, evaluated the threat value of each device in the system, and then deployed more effective defense measures. Based on the attack map and the quantitative vulnerability index of the system, the study analyzes the vulnerability of all possible attack paths, and obtains the best attack path for threat analysis. The paper uses an attack tree to model the industrial control system, uses fuzzy number to calculate node interval probability, and obtains the probability of each attack path in the system. The study uses an attack tree to assess the information security vulnerability of CPS system.
The above research methods mainly carry out risk assessment from the aspects of CPS system structure or attackers, etc. In this paper, the risk assessment methods of common information systems are transferred to the UAV cyber range, and the impact of the defense strategy and offensive and defensive confrontation of the UAV cyber range on the UAV security is considered. The authors of [16] proposed an information risk assessment method of CPS system based on offensive and defensive game, and established a complete information static game model for threat assessment and analysis. However, there is information uncertainty between attack and defense; so, the practicability of the complete information game model is very limited.
In view of the shortcomings of the above research, for equipment with high vulnerability in the UAV range, it is important to consider how to cost-effectively deploy defensive measures for the equipment. Considering how to deploy defense measures to UAV cyber range in combination with capital investment in order to obtain the highest return on investment, and how to find a balance between UAV information security risk and security investment, we are faced with the decision problem of making reasonable defense strategy choices by using limited resources. The game theory in economics can be used for reference to study the selection of security strategies of UAV cyber range.
The contribution of this paper is a common information system risk evaluation method that will be migrated to the UAV cyber range, and it considers the defensive strategy of UAV range and attack–defense confrontation and the influence on UAV risk, providing a new perspective and method for the UAV cyber range risk evaluation. By constructing an attack and defense tree model for the UAV cyber range, the attack and defense strategy sets of attackers and defenders are analyzed, and the attack and defense revenue function is calculated.
Therefore, this paper proposes a method of UAV range risk assessment based on an incomplete-information static attack and a defense game model. The main innovation of this method lies in two aspects. On the one hand, it combines the static game model of incomplete information and considers the information asymmetry that may be encountered in practical work. It is assumed that the risk management personnel of the UAV cyber range cannot accurately grasp the situation of the attackers, can only know that the attackers are two types of high threat and low threat according to experience, and know their respective alternative strategies and revenue functions, but they cannot accurately judge which type of attackers they will face. So, we need to use the relevant methods of an incomplete-information static game to solve it. On the other hand, it is an economical and effective defense strategy choice. On the basis of the economic indicators of the attack–defense tree model, the return on investment (DPF) and the return on attack (APF) of the attacker, the attack–defense tree model for the UAV cyber range is constructed. According to the attack and defense tree model, the attack and defense strategy sets of attackers and defenders in UAV cyber range are analyzed, and the attack and defense revenue function is calculated. A static Bayesian game model for attack and defense is established, and an offensive and defense game tree is established by analyzing the static game model of incomplete information and the benefits of both sides, and a mixed strategy Bayesian–Nash equilibrium is calculated.

2. Related Research Work

At present, the research work on the risk assessment of UAVs, UAV attack and defense security analysis, UAV system risk assessment and the application of game theory in the security field are still in the initial stage, and no systematic theoretical methods have been developed. The main research work can be summarized in the following four aspects.

2.1. Risk Assessment of UAV

UAVs typically rely on radio communications to transmit data and control commands. SDR technology [17] can be used to simulate and analyze signals in UAV cyber communication to identify potential vulnerabilities and threats. On the one hand, with SDR equipment, it is possible to simulate malicious attacks, test the defense mechanisms of the UAV cyber range, and assess its ability to withstand attacks. On the other hand, SDR equipment can be used to create complex communication scenarios to test the performance of the UAV cyber range in multiple situations. UAV cyber communication is not limited to Wi-Fi protocol, as it may also involve other communication protocols such as LoRa, UAV-to-UAV direct communication, etc. SDR technology has irreplaceable applications in the identification and analysis of Wi-Fi, LTE, UAV-to-UAV communication risk.
Feng Dengguo et al. [18] analyzed the current situation of information security risk assessment at home and abroad, assessment system models, assessment standards, assessment methods, and assessment process, discussed the assessment systems at home and abroad, pointed out the problems to be solved in the current information security risk assessment ‚ and looked forward to the development prospect of information security risk assessment. Lin Chuang et al. [19] introduced the research status and progress of stochastic models and evaluation techniques of cyber security ‚ and summarized several research methods and evaluation techniques of stochastic models of cyber security. As regards the attack tree, Schneier [20] proposed the method of using an attack tree to describe system security in a formal and systematic way to model a single-vulnerability threat. Moore [21] elaborated that the attack tree, which expresses the attack change in a recursive or progressive way, can more directly reflect the steps of the attacker to implement the attack. As regards the privilege graph, Dacier et al. [22] put forward the concept of the privilege graph to express the changes in the attackers’ control permissions on the system caused by system vulnerabilities and to evaluate the security of the system. A metric is defined for vulnerability to express the probability of success of an attack on the vulnerability. Ortalo et al. [23] proposed a cyber risk evaluation experimental model framework based on the idea of the privilege graph. In terms of attack graphs, Phillips and Swiler proposed the graph-based cyber vulnerability analysis method [24]. This method can test all possible results after a successful attack‚ and it indicates the attack paths with high probability of success that an attacker can take to obtain different risks faced by cyber information assets. As regards model checking‚ Ramakrishnan et al. [25] firstly put forward the application of the model-checking method to the comprehensive analysis of host weaknesses‚ and implemented a vulnerability analysis tool under UNIX system. Ritchey and Ammann [26] extended the application of model checking to the evaluation of cyber systems. Zhang Yongzheng et al. [27] proposed a risk communication model composed of risk cyber and risk communication algorithm. The risk cyber describes the access relationship structure and risk situation of the cyber system, and the risk communication algorithm gives the movement rules of risks. We not only focus on the vulnerability of Wi-Fi communications, but also look at other wireless communication protocols and control mechanisms such as Bluetooth [28], ZigBee [29], 5G [30], and satellite communications [31]. We provide an in-depth analysis of the security of these wireless technologies, including their encryption strength, authentication mechanisms, and anti-jamming capabilities.
In addition to cyber security, in the research work exploring UAV Physical Layer Security (PLS), such as the rate-split multiple access technology that supports IoT in satellite and aerial integrated cyber communication proposed in [32], we can explore how to apply this access method to the UAV cyber range to improve the data transmission rate and reliability. At the same time, [33] provides a secure energy efficient hybrid beamforming technique for satellite-integrated Earth cyber range, which provides us with the possibility to achieve simultaneous transmission and confidentiality of signals in UAV communications. In addition, the self-powered absorbable reconfigurable smart surface technology proposed by [34] provides a new perspective for enhancing the physical layer security of the UAV cyber range, especially in countering malicious interference and cyber-attacks. Finally, the covert mmwave communication technology in [35] can maintain the concealment of communication even in the face of space random monitors under the condition of finite block length, which is of great significance for covert communication of UAVs in complex environments. Taken together, our research efforts will integrate these advanced technologies to develop a comprehensive set of UAV physical layer security solutions designed to improve the communication performance and security of the UAV cyber range while ensuring robustness in the face of a variety of threats.
Although the existing studies have discussed the security of physical layer and wireless control mechanism of UAVs, the risk of the UAV cyber range is often ignored, which provides opportunities for potential attackers. Existing assessment methods and technologies may not be sufficient to fully cover the security risks of drones.

2.2. UAV Attack and Defense Security Analysis

The research on UAV attack and protection mainly focuses on UAV communication and sensors. This paper mainly discusses the attack and protection of UAV communication.
  • WiFi cracking attack. Before turning off the UAV controller, SkyJet uses aircrack-ng to detect nearby wireless cyber and clients. This task is carried out when connecting the attacker with the UAV, allowing for full control of the victim’s UAV. This type of attack is divided into three stages [36]. In the first step, a wireless sniffing tool, such as airodump, is used to discover WEP-enabled and WPA-2-enabled cyber ranges, as well as an open cyber network. The second step is to use an injection tool, such as “airplay”, to increase and modify the communication transmission traffic. The third step, “aircrack-ng,” allows an attacker to launch a counter-authentication attack that can interrupt a Wi-Fi connection protected by WPA2 encryption.
  • Denial-of-service DoS attack. After authentication, the airdump-ng command is used to evaluate the cyber security of the UAV. The aircrack-ng command is then used to disconnect any connected devices, or the aircrack-ng command to disconnect any secure UAV. The use of Kali-Linux as a platform for WiFi interference causes the UAV to crash [37].
  • ARP cache poisoning. A malicious script called Scapy is continuously executed through the computer using the Python library until the UAV disconnects from the connected device [38].
  • To solve the intrusion problem of UAV, Pleban et al. [39] proposed to use ground stations as access points and WPA/WPA2 to encrypt WiFi links. Pigatto [40] et al. built a security system model for the application scenarios of unmanned equipment such as UAV and unmanned vehicles, and designed a lightweight authentication protocol by using elliptic curve encryption algorithm. Won et al. [41] designed a certificateless signature label key encapsulation protocol to realize key negotiation between UAV and other intelligent terminal mobile terminals, taking into account the identity anonymity and data privacy of UAV. The UAV monitoring system designed by Birnbaum [42] et al. uses the regression least squares method to achieve real-time prediction of fuselage and control parameters, and determines the security state of the UAV by analyzing the abnormal state of parameters. Reyes [43] et al. proposed the design of a UAV cyber security transmission mechanism based on cognitive radio, providing a new solution for UAV cyber security protection and fault recovery. Sedjelmaci [44] used Bayesian game theory to realize UAV cyber intrusion detection, effectively balancing the calculation cost of UAV cyber nodes in the intrusion detection process and the correlation between the detection accuracy rates.

2.3. Unmanned Aircraft System Risk Assessment

Firstly, the threats faced by UAVs, their own risk and UAV assets are analyzed, and then the probability of occurrence of security risk, the severity of risk of UAVs, and the value of UAV assets are evaluated so as to obtain the occurrence and possibility of security incidents and the possible losses caused by security incidents, and finally the overall security value of UAV.
Risk assessment methods can be roughly divided into two categories: qualitative assessment and quantitative assessment, and their development trend is shown in the figure below. Therefore, the following is an analysis of the current research status of UAV system risk assessment from these two aspects.
  • Qualitative assessment
Qualitative assessment is to make use of security knowledge and experience to conduct a holistic assessment of the security status of a system [45]. In the IT field, typical qualitative information risk evaluation methods include OCTAVE, CORAS, Delphi method, the Analytic Hierarchy Process (AHP), and so on. In the field of industrial control, Byres et al. proposed a risk assessment method of industrial control system based on an attack tree. This method uses the attack tree model to provide a structured view for the industrial control system of the Modbus communication protocol, describes a series of events leading to attacks, and helps security experts take defensive measures.
Since qualitative risk assessment can only give a rough or overall description of the security of unmanned aerial systems, it is difficult to accurately display the security details of unmanned aerial systems, and it is difficult to customize appropriate protection strategies according to the security status of unmanned aerial systems. Therefore, qualitative assessment is often used as a basis for quantitative assessment, or applied to scenarios where the accuracy of risk assessment is less required.
  • Quantitative evaluation
Quantitative analysis mainly uses mathematical tools such as probability analysis to quantify the security value, and its main advantage is accuracy. At present, many scholars have studied the information risk evaluation of the industrial control system, but few have paid attention to the information risk evaluation of the UAV system.
The risk assessment method of the UAV information space is mainly based on the mature theoretical basis of information risk assessment in the field of industrial control. Gertman et al. [46] proposed a risk assessment method for an industrial control information system based on attack scenarios. Industrial control security experts assessed system vulnerabilities and threats, formulated possible attack paths and the success probability of attackers, and finally calculated the security risk value. Henry et al. [47] used the directed graph model to model the attack process of the industrial control system and calculate the security value. This method also required security experts to specify parameters in the model. Hewett et al. [48] applied game theory to the risk evaluation of industrial control systems, established a non-cooperative game model between attackers and defenders, and finally realized quantitative evaluation by quantifying the benefits of confidentiality, integrity and availability.
To sum up, if quantitative evaluation is adopted, there are two typical approaches to the evaluation of UAV information security. The first approach is to evaluate UAV from the perspective of traditional functional security evaluation by using a fault tree, Petri net, transfer function and other commonly used functional security research methods. The second is from the perspective of information risk assessment of the IT cyber range, using common risk assessment techniques in the IT field, including attack graph, Bayesian cyber range, game theory and other methods to carry out risk assessment of UAV. Considering that in the UAV system, the cyber-attack is often carried out from an external cyber network through the UAV information management layer to penetrate the operation control layer, and then interfere with the UAV mission execution, and cause security accidents or other losses. At present, this paper evaluates the risk of UAV based on game theory. In the future, we will combine the intersection of information risk assessment and functional risk assessment to realize the quantitative assessment from the information management level to the operational control level of unmanned aerial systems.
Generally speaking, a security assessment is a comprehensive examination of a system or organization’s security measures and procedures to determine its ability to withstand attacks and threats. It includes a comprehensive evaluation of physical security, cyber security, data security and human resource security. Risk assessment is the process of identifying and analyzing potential security risk and the impact these threats may have on a system or organization. It aims to quantify the likelihood of a threat occurring and the potential extent of damage, thereby providing a basis for risk management and decision making. Vulnerability assessment is the identification of weaknesses in a system, network, or application that could be exploited by a threat to cause damage. It focuses on flaws at the technical level, such as misconfiguration, software bugs, or insecure designs. In this paper, the approach we propose focuses on the scope of risk assessment, in particular, assessing the level of risk in UAV networks by quantifying potential threats and system vulnerabilities. Our approach not only identifies possible security risk, but also assesses the likelihood of these threats exploiting system vulnerabilities and their potential consequences.

2.4. Application of Game Theory in the Field of Security

Game theory is a decision analysis theory based on advance. Due to its value in understanding and modeling conflict, game theory has been recently applied to information warfare and computer cyber security. Syverson [49] proposed the idea of rational analysis of normal and malicious nodes in a cyber network by using a random game. Burke [50] proposed to use repeated games with incomplete information to model the behavior of attackers and defenders in information warfare. Lye and Wing [51] analyzed the Nash equilibrium of the defender and the attacker and their respective optimal strategies using the form of stochastic game. Xu [52] designed and analyzed the DDoS defense system based on the static game with complete information and optimized the performance of the system. Liu [53] proposed intrusion intent and strategy reasoning models based on game theory, which contributed to the further development of the security field.
This paper draws on the related research results above, but it is also different from the research work above. The details are as follows: First, this paper presents a defense graph model for the risk assessment of UAV cyber range attack and defense, and calculates the attack and defense benefits. Secondly, an offensive and defensive game model with incomplete information is established to calculate the mixed strategy Bayesian–Nash equilibrium. Finally, according to the defender’s benefit and the attacker’s optimal strategy, the probability distribution is selected as the basis for the UAV range risk assessment calculation.

3. Application of Attack–Defense Tree Model in UAV Cyber Range

3.1. Attack–Defense Tree Model with Economic Indicators

In recent years, in the field of computer cyber security, some scholars have begun to apply game theory to analyze the problem of offensive and defensive confrontation and offensive and defensive strategy of cyber security. However, the UAV system is different from the traditional information system; so, it cannot blindly learn from the strategy selection method applied in the field of computer cyber security. In the course of establishing the game model of attack and defense of the UAV cyber range, the determination of the income function is very important.
In traditional computer cyber security game analysis, the three attributes of information confidentiality, integrity and availability are used as basic evaluation indexes to construct the income function matrix for analysis. The method proposed in this paper is different from the revenue function construction method in the traditional computer cyber system, but based on the traditional attack and defense tree model, considering the economic cost and benefit of attack and defense, DPF and APF represent the defense benefits and attack benefits of both sides of the UAV range, and construct the revenue matrix. Then, the relevant game theory knowledge is used to build a game model for predictive analysis.
The attack tree describes the many ways in which a UAV range can be attacked. It uses a tree structure to represent various attack behaviors against UAV. Based on the basic attack tree model, each attack node is attached to one or more defense measures to obtain an attack–defense tree.
The defense side of the UAV range decides to adopt two strategies of defense and non-defense against the target UAV cyber, and the attacker decides whether to attack the target UAV cyber range or not. In order to simulate and deal with the problem of offensive and defensive game strategy of the UAV cyber range, virtual player “0” is introduced according to Harsanyi’s idea, that is, “nature”. “Nature” first selects the type of defense, where the defense mainly refers to the defense cost.
In the game of attack and defense of UAV cyber range, regardless of whether it is attack or defense, it is costly. By introducing a virtual player, “nature”, this player does not have to consider his own gains and losses; its only role is to give the type vector θ = θ 1 , θ 2 , , θ n of each player in the attack and defense game of the UAV cyber range, where θ i Θ i the feasible type space and Θ i is a complete description of the characteristics of the player i .
In the actual combat of cyber-attack and -defense of the UAV range, there are generally two types of attackers: adventurous attackers and conservative attackers. The attacker does not want the defender to know which type he belongs to. Obviously, with different types, the attack strategy chosen by the attacker and the effect of the attack are different. Since the attacker makes the decision in advance, the result of its choice will be understood by the defender and the decision will be made.
In order to facilitate the analysis of offensive and defensive game by using the attack and defense tree model of UAV cyber range, two important economic indicators, namely DPF and APF, are introduced, which are important bases for the subsequent analysis and calculation of the return matrix of offensive and defensive game. The meanings and calculation methods of both are discussed below.

3.2. Quantification of Strategic Benefits of Both Sides

3.2.1. Attack Payoff Function

An important attribute, Attack Payoff Function (APF), is assigned to each attack event that attacks the defense tree. It indicates that during the attack and defense game between the attacker and the defender, after the defender has deployed targeted defensive measures, the attacker will be able to perform the following operations. The benefits obtained from successful attack can still be calculated using the formula shown in the following figure.
A P F = G × 1 R M c o s t a + c o s t u a v c o s t a + c o s t u a v
where G indicates the profit that the attacker expects to obtain from a successful attack. c o s t a represents the cost of the attacker to carry out the attack. The rate R M at which the risk of an attack on a UAV system is reduced due to the deployment of a defensive measure at a UAV range ranges from 0 to 1. c o s t u a v means that after the defender has deployed targeted defense measures, the attacker has to increase the attack cost in order to continue to breach these defense measures.

3.2.2. Defense Payoff Function

An important attribute is assigned to each defense measure of the attack–defense tree, defense payoff function (DPF), which represents the expected income after spending a certain cost on a specific attack event and deploying corresponding defense measures during the offensive and defense game in the UAV cyber range, as shown in the following formula.
D P F = A L E u a v × R M C C
where A L E u a v indicates the economic loss that may be caused by the potential information security risk of the UAV cyber range, which is related to the asset value, the percentage of asset value loss after the threat is generated, and other factors. The rate R M at which the risk of an attack on a UAV system is reduced due to the deployment of a defensive measure at a UAV range ranges from 0 to 1. C represents the cost of deploying a defensive measure. Specifically, the formula symbols are expressed in Table 1.

4. Construct the Game Model of Attack and Defense of UAV Cyber Range with Incomplete Information Static

Game theory [54] is an important mathematical theory for the study of confrontation or competition in the economic field. Based on game model analysis, it can infer the strategic choices of participants. In the UAV cyber range, the attacker attacks the risk of the UAV, and the defender deploys defense strategies for the possible threats of the UAV, forming an offensive and defensive game between the two. Based on the attack and defense game of UAV cyber range, this paper constructs a static game model of incomplete information to evaluate UAV security, considering the uncertainty of information between attack and defense. The content expressed by the formula symbol is shown in Table 2.

4.1. Model Assumption

Hypothesis 1. 
The rationality hypothesis. Both, as rational participants, hope that the strategy they adopt is the optimal strategy for the other side, and the participants derive the maximum benefits at this time. Therefore, in order to ensure the maximum benefit to the participants, neither will change the strategy at this time.
Hypothesis 2. 
Type hypothesis. In the process of attack and defense of the actual UAV range, on the one hand, due to the hidden attack technology itself and the complexity of the defense system, the UAV cyber attackers and defenders often cannot fully grasp the strategic benefits of each other; On the other hand, analysis methods such as backtracking of security incidents by both sides can summarize their relevant laws and provide certain basis and guidance for determining each other’s benefits. Therefore, assuming that the uncertainty of each other’s strategy returns is caused by the uncertainty of the other’s type, the two sides have a rough judgment of each other’s type probability distribution. It is an important means to solve the problem of incomplete information to convert the uncertainty of participants’ information into uncertainty of their types, but to judge the probability distribution of their types. Both sides can be divided into multiple types according to the uncertainty factors.
Hypothesis 3. 
Income hypothesis. In the process of attack and defense of UAV cyber range, it is assumed that the attack benefit is mainly measured by the economic benefit obtained by adopting the attack strategy, while the defense benefit is mainly measured by the economic benefit of protecting information resources by adopting defense strategy. In the process of attack and defense, attackers mainly select different attack strategies to obtain effective information resources so as to maximize attack benefits. Defenders mainly choose different defense strategies to protect the security of their own information resources so as to maximize their own benefits. In this process, both the offensive and defensive sides aim to maximize the benefits, and choose their own offensive and defensive strategies in the process of offensive and defensive confrontation of the UAV range. Therefore, the economic benefits brought by information resources can be used to measure the benefits of both sides.

4.2. Establish UAV Range Defense Model Based on Bayesian Static Game

The Bayesian–Nash equilibrium is constructed by using the attack–defense tree model AGM = A , S , D , where A = a 1 , a 2 , a 6 represents the set of atomic attacks of the attacker, and the attack income is represented by the value after atomic attacks. Each attack path consists of multiple atomic attacks; S = s 1 , s 2 , s 8 represents a status node; D = d 1 , d 2 , d 3 represents a collection of defense behaviors, represented by the name of the defense behavior and the defense income.
Static Bayesian game is a static game model with incomplete information, which represents a game in which participants act simultaneously with incomplete information. In this paper, a static Bayesian offensive and defensive game model is constructed that conforms to the actual offensive and defensive environment of the UAV cyber range. The participants U A V A D M = N A , N D , T A , T D , B A , B D , P A , P D , U A , U D include attackers and defenders, that is, the number of participants n = 2 .
The static Bayesian offensive and defensive game model for the offensive and defensive environment of UAV cyber range can be expressed as a quintuple, where:
(1)
N = N A , N D represents the set of participants in the offensive and defensive game model. N A and N D represent attackers and defenders in the UAV range, respectively.
(2)
T = T A , T D represents the type set of participants in the offensive and defensive game model. Where T A = t 1 A , t 2 A , , t n 1 A represents the set of types of attackers N A , such as internal attacks, external attacks, and spies; T D = t 1 D , t 2 D , , t n 2 D represents a set of types of defenders N D , such as security experts, security analysts, and security operations personnel. In the actual UAV range, one side of the offense and defense does not fully understand the benefits of the other side. Therefore, when analyzing the static Bayesian offensive and defensive game model, the method of “Harsanyi transformation” is used to assume a fictitious player, and the fictitious player first decides the different types of other players, and replaces the uncertainty of information with the uncertainty of type.
(3)
B = B A , B D represents the action set of players in the game model. It represents a collection of actions by different types of attackers N A , such as DoS, backdoors, fuzzers; and a set of actions B D = b 1 D , b 2 D , , b m 2 D that represent different types of defenders, such as authentication, transmission encryption, and intrusion detection.
(4)
P = P A , P D represents the prior probability set of players in the offensive and defensive game model. Where P A = P t D | t A represents the probability that the attacker judges the type t A of the defender in the case of type t D ; P D = P t A | t D indicates the probability that the defender determines the type t D of the attacker in the case of type t A .
(5)
U = U A , U D represents the income function set of participants in the offensive and defensive game model. b A B A , b D B D , t A T A , t D T D , U A b A , b D , t A represents the revenue function of the attacker when the attacker is of the type t A , the attacker takes action b A , and the defender takes action b D ; U D b A , b D , t D represents the revenue function of the defender when the defender is of the type t D , when the attacker takes action b A , and when the defender takes action b D . According to the above, in order to better analyze the attack and defense game model of the UAV cyber range, the quantitative calculation method of attack and defense benefits is given. The profit function of the attacker can be expressed as U A b A , b D , t A = A P F b A , b D , t A , and the profit function of the defender can be expressed as U D b A , b D , t D = D P F b A , b D , t D .

4.3. Solving Bayesian Equilibrium of Attack and Defense Game Model of UAV Cyber Range

Game equilibrium analysis is the key content of game theory research. Thinking from the perspective of UAV target range managers, the prediction of attackers’ strategy selection can help managers deploy the best defense measures and improve the defense capability of UAV systems. From this, two important concepts are given below.

4.3.1. Mixed Strategies in Bayesian Games

Mixed policy U A V A D M is the pure policy set S A t A = S 1 A t A , S 2 A t A , , S n A t A of the attacker under the type t A T A . If the pure policy S m A t A of the attacker is selected by probability f m A t A , F A t A = f 1 A t A , f 2 A t A , , f n 1 A t A is called a mixed policy of the attacker under the type t A , and it is abbreviated as F A t A = f 1 A , f 2 A , , f n 1 A ; similarly, the mixed policy of the defender can be obtained as F D t D = f 1 D t D , f 2 D t D , , f n 2 D t D , and it is abbreviated as F D t D = f 1 D , f 2 D , , f n 2 D .

4.3.2. Mixed Strategy Bayesian–Nash Equilibrium

Given the U A V A D M = N A , N D , T A , T D , B A , B D , P A , P D , U A , U D mixed strategy Bayesian–Nash equilibrium, F A t A = f 1 A t A , f 2 A t A , , f n 1 A t A represents the probability distribution of mixed strategies for attackers and the probability distribution of mixed strategies for defenders F D t D = f 1 D t D , f 2 D t D , , f n 2 D t D . If the following conditions (3) and (4) are met at the same time, the mixed strategy F A * t A , F D * t D is called a Bayesian–Nash equilibrium.
t D T D P A t D | t A U F A * t A , F D * t D , t A t D T D P A t D | t A U F A t A , F D * t D , t A
t A T A P D t A | t D U F A * t A , F D * t D , t D t A T A P D t A | t D U F A t A , F D * t D , t D
Based on the attack and defense game of UAV cyber range, the static Bayesian attack and defense game model constructed must have the following two mixed strategies F A * t A = f 1 A * t A , f 2 A * t A , , f n 1 A * t A and F D * t D = f 1 D * t D , f 2 D * t D , , f n 2 D * t D , so that both attack and defense can obtain the maximum benefits at the same time. According to the rational assumption, both sides will not change their strategy when the benefits are maximum. Therefore, both attack and defense will adopt the strategy of the best return situation so as to achieve the game equilibrium. In this case, the probability distribution of the attack behavior F A * t A = f 1 A * t A , f 2 A * t A , , f n 1 A * t A is represented by the defender’s prediction of the attacker’s strategy, which is used as the basis for risk evaluation.

5. Design of UAV Cyber Range Risk Assessment Method

The game-theory-based approach to UAV range risk assessment, combined with NIST SP 800-30’s risk assessment framework, during the risk analysis phase, is designed to identify threats, vulnerabilities, and assets that may affect an organization’s objectives and assess the impact of these factors on the organization. By analyzing the game between attackers and defenders, the overall risk of a UAV range can be assessed. The overall risk includes not only the direct threat to assets from attackers, but also the possible cost and impact of defensive measures taken by defenders. Through a game-theory-based approach, the risk assessment of a UAV range is able to more fully consider the game between attackers and defenders, and how this game affects overall risk.
Common information system risk assessment methods calculate the threat value based on the three elements of assets, threats and vulnerabilities. The calculation formula is as follows:
R = A , V , T = R L A , V , P V , T
where R indicates threat value; A represents assets; V represents asset risk; T indicates threat type; L indicates loss due to threat; P indicates the likelihood of a threat.
The commonality of information system risk assessment and UAV cyber range risk assessment is analyzed. Based on the security risk calculation formula of information system, the threat value is calculated based on the possibility of UAV security risk occurrence P V , T and the loss caused by the threat L A , V .
In this paper, the attack and defense game strategy model of the UAV cyber range is constructed by calculating the formulas of attack income and defense income in Section 3. By analyzing the historical data of attack and defense of UAV range, the prior probability of defender to attacker P D = P t A | t D and the prior probability of attacker to defender P A = P t D | t A are obtained, respectively. The benefits of both offense and defense are input into the model U A V A D M , and the game equilibrium F A * t A , F D * t D is calculated. According to the rational assumption of the offensive and defense game model, the defender and the attacker will choose the optimal strategy and keep it the same. Therefore, the prediction of the attack strategy of the defender to the attacker in the UAV cyber range can be represented by the mixed strategy Bayesian–Nash equilibrium of the offensive and defense game model F A * t A = f 1 A * t A , f 2 A * t A , , f n 1 A * t A , which is the possibility of threat occurrence F A * t A . Threats cause losses for defense gains.
According to [55,56], the defense measures deployed by the defender in the threat assessment process are determined by the manager. It is assumed that the determined defender strategy b 1 D is as follows: the threat value of the unmanned aerial vehicle (UAV) system in the UAV cyber range can be expressed in a formula R i . The manager conducts risk assessment and analysis of the UAV system according to different defense strategies and calculates the threat value of the UAV system. The UAV security risk level is determined and the optimal defense strategy is deployed.
R i = i 2 = 1 n P t A | t D i 1 = 1 m f i A * t A U D b A , b D , t D U D max b A , b D , t D
Considering that a UAV consists of multiple subsystems such as navigation control, communication, perception and obstacle avoidance, ground station control and mission load, the weight of each subsystem’s threat value in the overall UAV security risk value should be considered during the overall UAV risk assessment. The weight vector is represented by W = W 1 , W 2 , , W n , and the subsystem threat value is represented by R = R 1 , R 2 , , R n . The overall security risk value formula of UAV is as follows:
R a l l = i = 1 n R i W i
The flow of Algorithm 1 is as follows.
Algorithm 1 Static game risk evaluation algorithm of incomplete information
Input: U A V A D M
Output: UAV security risk value
BEGIN
1. Initialize()
2. Establish a set of attack and defense types T = T A , T D
3. Establish both offensive and defensive action sets B = B A , B D
4. For all S i A t A S A t A
5. Calculate attack income APF and defense income DPF, respectively
6. t D T D P A t D | t A U F A * t A , F D * t D , t A t D T D P A t D | t A U F A t A , F D * t D , t A
7. t A T A P D t A | t D U F A * t A , F D * t D , t D t A T A P D t A | t D U F A t A , F D * t D , t D
8. Get a mixed Bayesian equilibrium, F A * t A = f 1 A * t A , f 2 A * t A , , f n 1 A * t A
9. R i = i 2 = 1 n P t A | t D i 1 = 1 m f i A * t A U D b A , b D , t D U D max b A , b D , t D
10. Invoke algorithm 2 to calculate the weight of the UAV subsystem.
11. R a l l = i = 1 n R i W i
12. Return R a l l
END
The weight of the UAV subsystem can be calculated by various methods. In this paper, the fuzzy Analytic Hierarchy Process is used to calculate the subsystem weight. A number of experts assign importance to each subsystem, construct a judgment matrix, and according to r i and f i j , complete the consistency transformation; the judgment matrix is transformed into a fuzzy judgment matrix that meets the consistency conditions, and finally the subsystem weight W i is obtained.
r i = m = 1 n r i m
f i j = r i r j 2 + 0.5
W i = 1 n 1 2 α + 1 n α × j = 1 n f i j
The flow of Algorithm 2 is as follows.
Algorithm 2 UAV subsystem weight calculation algorithm.
Input: UAV subsystem fuzzy judgment matrix
Output: UAV subsystem weight
BEGIN
1. Initialize()
2. Use formula r i = m = 1 n r i m and f i j = r i r j 2 + 0.5 to complete consistency transformation
3. W i = 1 n 1 2 α + 1 n α × j = 1 n f i j
4. Return W i
END

6. Application and Analysis

The UAV range can collect the on-site work data of the UAV logistics and transportation cyber range in real time, monitor the operation status of the UAV logistics and transportation cyber range, and control the UAV execution site to deliver goods safely and effectively. According to the monitoring data, the UAV ground station generates control commands and issues them to the UAV. The UAV accepts the control commands issued by the ground station to control its own task process, such as flight height and motor speed adjustment. However, the UAV data transmission protocol is complex and diverse, and faces some information security risks, including illegal access risk, the UAV cyber protocol’s openness risk, the unencrypted data transmission risk, and the UAV cyber structure’s risk. The status data of an unmanned aerial system face the great threat of being tampered by criminals in the cyber network, and there may be a series of serious attacks on unmanned aerial systems.
Specifically, unmanned aerial vehicle systems and ground stations are two important pieces of equipment of the unmanned aerial vehicle range, and the communication between them mostly adopts the MavLink protocol, but it mainly has security problems such as lack of authentication in the communication process and a lack of programmability of information verification and protocol. This means that an attacker could exploit a programmability flaw in the MavLink protocol to inject malicious code into a flight control unit or ground station. Therefore, once the ground station or UAV of the UAV range is subjected to information attack, it will cause serious consequences.
For example, the ground station is a commonly used equipment in the UAV range, and its working flow must be limited to a certain range to protect the ground station from damaging the equipment due to excessive flow impact. When the UAV range is subjected to an information attack, it can damage the equipment. If the ground station is subjected to information attacks, malicious attackers will access the ground station, illegally send forged data from the ground station, issue wrong instructions to make the UAV fly out of the reasonable inspection range, and then destroy the normal work of public facilities and cause losses. On the other hand, viruses targeting UAV systems, such as the malUAV backdoor virus, can enter the UAV communication system through various ways and change the behavior of the UAV by modifying the protocol package information, such as executing suicide behaviors and endangering the security of society.
In view of this possible attack situation, take this as an example to analyze. First, the attack–defense tree is established based on specific attack behavior and defense measures, and then the UAV range risk evaluation method proposed in this paper is analyzed to illustrate the specific application of this method, that is, how to help UAV range information security managers choose defense strategies based on the Bayesian–Nash equilibrium solution.
In this paper, the UAV communication system in the UAV cyber range is taken as an example, and the method proposed in this paper is used for risk assessment and analysis. As shown in Figure 3, the UAV communication system is mainly composed of the UAV range server, attacker, terminal equipment and UAV.
According to the analysis of attack information by the range manager, the attacker strategies are classified into two types, which are represented by t A = {adventurous attacker, conservative attacker}. The specific information is shown in Table 3, where different atomic attack combinations represent different types of attack strategies, and the attack behavior is uncertain; so, the attacker’s information is also uncertain. According to the cost of defense strategies, the impact of the UAV range and the experience of managers, defender strategies can also be divided into two categories, represented by t D = {high level defender, low level defender}, and the specific information is shown in Table 4.
According to the action strategies adopted by both attack and defense, the attack–defense tree of the UAV cyber range is constructed. The following is an example of the attack–defense tree as shown in Figure 4, aiming at the two kinds of attack events that the ground station and the UAV communication system may suffer.
The defense benefits and attack benefits are calculated based on that shown in 3.2. In the attack–defense tree, if it is able to resist and attack events at the same time, the current analysis of the situation is that attack events may be initiated by adventurous attackers, but may also be initiated by conservative attackers, and unmanned aerial range information security managers can not accurately judge which is the case. Therefore, it is necessary to calculate the respective benefits of both sides when the defender faces the adventurous attacker and the conservative attacker. Table 5, Table 6, Table 7 and Table 8 list the calculation results.
Based on the calculation results of the above tables, the income matrix of both sides of the UAV cyber range can be obtained, as shown in Table 9 and Table 10.
It needs to be explained here that the relationship between the data economic loss ALE and the attack income G used in the calculation of DPF and APF is not necessarily equal, that is, the attack income of the attacker is not necessarily equal to the economic loss caused by the defender, which should be analyzed according to the specific situation. In fact, if the benefit of the attack is greater than the financial loss of the defender, this is the preferred effect of the attacker. Therefore, based on this consideration, in the calculation example analysis in this section, the ALE value and G value in the table are set to be equal and the latter is greater than the former so as to carry out a more comprehensive data analysis.
After determining the strategy set of the participants and obtaining the basic data of the attack–defense tree model, the proposed method is applied to establish the game model and solve the Nash equilibrium so as to deduce the strategy choice preferences of the attacker and the defender considering the capital cost and economic benefit. The formula in Section 3 is used to calculate the strategic gains of the participants, and the prior probability of the defenders against the types of attackers is obtained by combining the analysis of the attack history and defense history of the UAV cyber range: (adventurous attacker, conservative attacker) = (0.55, 0.45); the prior probability of the attacker on the type of defender: (high level defender, low level defender) = (0.6, 0.4). The mixed strategy Bayesian–Nash equilibrium is calculated by the equilibrium formula, and the calculation results are shown in Table 11.
According to the analysis of the actual situation, in the defense process of the UAV range, the defender’s strategy is determined. Therefore, assuming that the defender adopts the defense strategy b 1 D at this time, according to the calculated security risk value R i , we can obtain:
R i = i 2 = 1 2 P t A | t D i 1 = 1 2 f i 2 A * t A U D b A , b D , t D U D max b A , b D , t D = 0.648
The unmanned aerial vehicle’s navigation and control system, communication system and mission payload system are important subsystems in UAV range. This paper considers the impact of subsystem security risk on the overall threat of the UAV cyber range. Taking three subsystems as an example, the calculated security risk value of each subsystem is (R1, R2, R3) = (0.648, 0.591, 0.759). According to the importance evaluation of the three subsystems in the UAV cyber range by experts, the weight vector of the subsystem is calculated by using the fuzzy Analytic Hierarchy Process as (W1, W2, W3) = (0.528, 0.309, 0.261).
According to R a l l , the calculation of the overall threat value of UAV R a l l = 0.729 , the threat level is divided into five levels according to [57], and the threat level of this system is judged to be level 4.
Similarly, you can obtain the threat value when deploying other defense strategies. At the same time, this paper takes the absolute value of the revenue of the defense strategy and calculates the average value of the revenue of each defense strategy. In this case, the strategy with a small value is better, as shown in Figure 5.
It is evident that when UAV range administrators choose b 2 D for strategic defenses, the resultant security risk value is notably minimized, concurrently aligning with a relatively equitable defense income function. This confluence enables managers to judiciously select and enact the optimal defense strategy by comparing threat values against the income function, thereby fortifying the UAV’s security posture and curtailing potential security risks.
The methodology proposed herein demonstrates its practicality and efficacy through this analysis. Notably, we incorporate the principles of static game theory under conditions of incomplete information, meticulously accounting for the dynamic interplay between offensive and defensive maneuvers, alongside the inherent uncertainties that pervade their interactions. This approach yields a more authentic reflection of real-world applications, as it encapsulates the complexity and unpredictability intrinsic to risk landscapes.
Considering the influence of different risk evaluation methods on the results, this paper analyzes the FAHP, Minimax Theorem, Nash equilibrium and Bayesian equilibrium. In the experimental environment, the Intel Xeon Gold 6230 20 core CPU is selected, Ubuntu 18.04 version is selected as the operating system, Pycharm is used as the development tool, and Python 3.6 version is adopted.
The specific comparison of cyber security assessment in the UAV cyber range is shown in Figure 6, where (a) is the method of this paper, (b) FAHP [58], (c) Minimax Theorem [59], and (d) Nash equilibrium [60]. K indicates the change in information requirements of both sides. K = 4 indicates that an attacker and a defender possess 100% of each other’s information. Similarly, K = 1 indicates that an attacker and a defender possess 25% of each other’s information. It can be seen that in the scenario of random protection of security targets, in the Bayesian equilibrium method of the incomplete-information game introduced in this paper, when the information demand of both sides expands to 4, the security benefit can be maintained at a high level close to 1 when the attack benefit is lower than the investment cost. Different from the conservative and adventurous attackers of FAHP, the change in security benefit is less than 0.1 with the increase in information requirements of both sides. In the case of a system completely without Minimax Theorem and Nash equilibrium of information, the increase in security benefit is about 0.2 with the increase in information requirements of both sides. In the Bayesian equilibrium method of the incomplete-information game introduced in this paper, the UAV cyber security’s benefits can be greatly improved by about 70% only when the information demand of both sides is expanded from 1 to 2. However, when the information demand is further expanded, the security benefit is only improved by about 10% at most.
In this paper, the uncertainty of information between attack and defense is increased, and the incomplete-information game is adopted to be closer to the actual UAV application scenario. FAHP can deal with the risk assessment of complex systems, especially in the multi-criteria decision problems. It allows decision-makers to consider the impact of multiple factors and is able to deal with ambiguous and uncertain information. Compared with the Minimax Theorem and Nash equilibrium, the attack time cost is higher. The Minimax Theorem can deal with the decision problem under incomplete information, and provides a framework for decision making under an uncertain environment. However, compared with FAHP, Nash equilibrium and the method in this paper, it is too conservative in decision-making and misses potential opportunities. Nash equilibrium is too idealized and may not exist or be difficult to achieve in actual situations. Therefore, this method introduces an incomplete-information game, optimizes Nash equilibrium method, and provides a specific threat value calculation formula and threat assessment algorithm steps, which can better complete UAV risk assessment.
In this experiment, the attacker launched 20 attacks on the UAV flight system in the UAV cyber range, counted the results of the security benefit changes in the 20 attacks and defense games, and compared the security benefit results of the traditional method and the Bayesian game method with incomplete information. As can be seen from Figure 7, using the risk evaluation algorithm based on an incomplete-information game, the security benefits obtained by the UAV system and the attacker after 17 attacks are greatly improved, and the bargaining process of the attack and defense parties is simulated to better demonstrate the interaction between the attack and defense parties.

7. Conclusions

In this paper, the existing common information system risk assessment method based on the game model is transferred to the UAV cyber range, and the incomplete-information model is adopted, which is more in line with the actual application of UAV risk assessment. A static Bayesian attack and defense game model is established, and the game model is used to calculate a mixed strategy Bayesian–Nash equilibrium and predict the attacker behavior. The improvement observed with the fuzzy Analytic Hierarchy Process and the Minimax Theorem is relatively small, 2.67% and 5.38%, respectively. The improvement observed with the proposed method is higher than that with FAHP and the Minimax Theorem. It is 21.43%, and achieved a good, expected effect. The research results show that the application of the static Bayesian offensive and defensive game model on the UAV cyber range can enable the defenders to predict the intention of the attacker and formulate effective defense strategies even though they lack the basic information of the attacker in the initial stage of the offensive and defensive game, and provide help for the UAV cyber range managers to deploy the optimal defense measures. However, this method is only suitable for phased threat assessment, and it is difficult to carry out a dynamic risk assessment of UAV. Therefore, two issues need to be considered in future work combining actual UAV attack and defense requirements. One is to propose an attack effectiveness prediction method based on the analysis of attack stages to describe attack capabilities in multiple dimensions to ensure the quantification of attack strategies and damage; the other is to improve the accuracy of UAV range security risk prediction through feedback iterative optimization.

Author Contributions

Conceptualization, S.M.; methodology, S.M. and Q.P.; validation, S.M. and Q.P.; investigation, S.M. and Q.P.; resources, S.M.; data curation, S.M. and Q.P.; writing—original draft preparation, S.M. and Q.P.; writing—review and editing, S.M. and Q.P.; visualization, S.M.; supervision, S.M.; project administration, S.M.; funding acquisition, S.M. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

Not applicable.

Informed Consent Statement

Not applicable.

Data Availability Statement

The data presented in this study are available on request from the corresponding author.

Conflicts of Interest

The authors declare no conflicts of interest.

References

  1. Qu, Y.; Dai, H.; Zhuang, Y.; Chen, J.; Dong, C.; Wu, F.; Guo, S. Decentralized Federated Learning for UAV Networks: Architecture, Challenges, and Opportunities. IEEE Netw. 2021, 35, 156–162. [Google Scholar] [CrossRef]
  2. Wazid, M.; Bera, B.; Das, A.K.; Garg, S.; Niyato, D.; Hossain, M.S. Secure Communication Framework for Blockchain-Based Internet of UAVs-Enabled Aerial Computing Deployment. IEEE Internet Things Mag. 2021, 4, 120–126. [Google Scholar] [CrossRef]
  3. Guo, W.; Zhang, Z.; Chang, L.; Song, Y.; Yin, L. A DDoS Tracking Scheme Utilizing Adaptive Beam Search with Unmanned Aerial Vehicles in Smart Grid. Drones 2024, 8, 437. [Google Scholar] [CrossRef]
  4. Khan, M.A.; Nasralla, M.M.; Umar, M.M.; Rehman, G.U.; Khan, S.; Choudhury, N. An Efficient Multilevel Probabilistic Model for Abnormal Traffic Detection in Wireless Sensor Networks. Sensors 2022, 22, 410. [Google Scholar] [CrossRef]
  5. Sharma, N.; Yadav, N.S.; Sharma, S. Classification of UNSW-NB15 Dataset Using Exploratory Data Analysis with Ensemble Learning. EAI Endorsed Trans. Ind. Netw. Intell. Syst. 2021, 8, 171319. [Google Scholar] [CrossRef]
  6. Wang, K.L.; Li, H.M. A Method with Multi-Channel CNN-BiGRU and Multi-Feature Fusion. Microelectron. Comput. 2022, 39, 41–49. [Google Scholar]
  7. Basan, E.; Basan, A.; Nekrasov, A.; Fidge, C.; Abramov, E.; Basyuk, A. A Data Normalization Technique for Detecting Cyber Attacks on UAVs. Drones 2022, 6, 245. [Google Scholar] [CrossRef]
  8. Lei, T.; Zhang, Y.; Wang, S.I.; Dai, H.; Artzi, Y. Simple Recurrent Units for Highly Parallelizable Recurrence. In Proceedings of the 2018 Conference on Empirical Methods in Natural Language Processing, Brussels, Belgium, 31 October–4 November 2018; ACL: New York, NY, USA, 2018; pp. 4470–4481. [Google Scholar]
  9. Ramachandran, P.; Zoph, B.; Le, Q.V. Searching for Activation Functions. In Workshop Track, Proceedings of the 6th International Conference on Learning Representations, Vancouver, BC, Canada, 30 April–3 May 2018; ICLR: San Diego, CA, USA, 2018. [Google Scholar]
  10. Zhao, P.; Fan, Z.J.; Cao, Z.W.; Li, X. Intrusion Detection Model Using Temporal Convolutional Network Blended into Attention Mechanism. Int. J. Inf. Secur. Priv. 2022, 16, 1–20. [Google Scholar] [CrossRef]
  11. Sihag, V.; Choudhary, G.; Choudhary, P.; Dragoni, N. Cyber4UAV: A Systematic Review of Cyber Security and Forensics in Next-Generation UAVs. Drones 2023, 7, 430. [Google Scholar] [CrossRef]
  12. Dong, N.; Cheng, X.R.; Zhang, M.Q. Intrusion Detection System with Dynamic Weight Loss Function Based on Internet of Things Platform. J. Comput. Appl. 2022, 42, 2118–2124. [Google Scholar]
  13. Shafique, A.; Mehmood, A.; Elhadef, M. Survey of Security Protocols and Vulnerabilities in Unmanned Aerial Vehicles. IEEE Access 2021, 9, 46927–46948. [Google Scholar] [CrossRef]
  14. Tian, G.F.; Shan, Z.L.; Liao, Z.H.; Wang, Y.L. Network Intrusion Detection Model Based on Faster R-CNN Deep Learning. J. Nanjing Univ. Sci. Technol. 2021, 45, 56–62. [Google Scholar]
  15. Khan, N.A.; Brohi, S.N.; Jhanjhi, N. UAV’s Applications, Architecture, Security Issues and Attack Scenarios: A Survey. In Intelligent Computing and Innovation on Data Science; Springer: Singapore, 2020; pp. 753–760. [Google Scholar]
  16. Fu, Y.F.; Du, Y.S.; Cao, Z.J.; Li, Q.; Xiang, W. A Deep Learning Model for Network Intrusion Detection with Imbalanced Data. Electronics 2022, 11, 898. [Google Scholar] [CrossRef]
  17. Li, H.; Ge, H.J.; Yang, H.Q.; Yan, J.; Sang, Y. An abnormal traffic detection model combined BiIndRNN with global attention. IEEE Access 2022, 10, 30899–30912. [Google Scholar] [CrossRef]
  18. Bin Mohammad Fadilah, M.S.; Balachandran, V.; Loh, P.; Chua, M. DRAT: A UAV Attack Tool for Risk Assessment. In Proceedings of the Tenth ACM Conference on Data and Application Security and Privacy, New Orleans, LA, USA, 16–18 March 2020; pp. 153–155. [Google Scholar]
  19. Leonardi, M.; Strohmeier, M.; Lenders, V. On Jamming Attacks in Crowdsourced Air Traffic Surveillance. IEEE Aerosp. Electron. Syst. Mag. 2021, 36, 44–54. [Google Scholar] [CrossRef]
  20. Li, T.; Zhang, J.; Obaidat, M.S.; Lin, C.; Lin, Y.; Shen, Y.; Ma, J. Energy-Efficient and Secure Communication towards UAVs Networks. IEEE Internet Things J. 2022, 9, 10061–10076. [Google Scholar] [CrossRef]
  21. Terven, J.; Córdova-Esparza, D.M.; Romero-González, J.A. A Comprehensive Review of YOLO Architectures in Computer Vision: From YOLOv1 to YOLOv8 and YOLO-NAS. Mach. Learn. Knowl. Extr. 2023, 5, 1680–1716. [Google Scholar] [CrossRef]
  22. Wang, C.Y.; Bochkovskiy, A.; Liao, H.Y. YOLOv7: Trainable Bag-of-Freebies Sets New State-of-the-Art for Real-Time Object Detectors. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, Vancouver, BC, Canada, 17–24 June 2023; pp. 7464–7475. [Google Scholar]
  23. Liu, Z.; Gao, X.; Wan, Y.; Wang, J.; Lyu, H. An Improved YOLOv5 Method for Small Object Detection in UAV Capture Scenes. IEEE Access 2023, 11, 14365–14374. [Google Scholar] [CrossRef]
  24. Koubaa, A.; Ammar, A.; Abdelkader, M.; Alhabashi, Y.; Ghouti, L. AERO: AI-Enabled Remote Sensing Observation with Onboard Edge Computing in UAVs. Remote Sens. 2023, 15, 1873. [Google Scholar] [CrossRef]
  25. Huang, H.; Zhao, G.; Bo, Y.; Yu, J.; Liang, L.; Yang, Y.; Ou, K. Railway Intrusion Detection Based on Refined Spatial and Temporal Features for UAV Surveillance Scene. Measurement 2023, 211, 112602. [Google Scholar] [CrossRef]
  26. Hu, X.; Li, T.; Wu, Z.; Gao, X.; Wang, Z. Research and Application of Intelligent Intrusion Detection System with Accuracy Analysis Methodology. Infrared Phys. Technol. 2018, 88, 245–253. [Google Scholar] [CrossRef]
  27. Fu, C.H.; Tsao, M.W.; Chi, L.P.; Zhuang, Z.Y. On the Dominant Factors of Civilian-Use UAVs: A Thorough Study and Analysis of Cross-Group Opinions Using a Triple Helix Model (THM) with the Analytic Hierarchy Process (AHP). Drones 2021, 5, 46. [Google Scholar] [CrossRef]
  28. Bouafif, H.; Kamoun, F.; Iqbal, F.; Marrington, A. UAV Forensics: Challenges and New Insights. In Proceedings of the 2018 9th IFIP International Conference on New Technologies, Mobility and Security (NTMS), Paris, France, 26–28 February 2018; IEEE: New York, NY, USA, 2018; pp. 1–6. [Google Scholar]
  29. Salamh, F.E.; Karabiyik, U.; Rogers, M. A constructive DIREST security threat modeling for UAV as a service. J. Digit. Forensics Secur. Law 2021, 16, 121–137. [Google Scholar] [CrossRef]
  30. Citroni, R.; Di Paolo, F.; Livreri, P. A novel energy harvester for powering small UAVs: Performance analysis, model validation and flight results. Sensors 2019, 19, 1771. [Google Scholar] [CrossRef]
  31. Hartmann, K.; Steup, C. The vulnerability of UAVs to cyber attacks—An approach to the risk assessment. In Proceedings of the 2013 5th International Conference on Cyber Conflict (CYCON 2013), Tallinn, Estonia, 4–7 June 2013; pp. 1–23. [Google Scholar]
  32. Lin, Z.; Lin, M.; Wang, J.-B. Supporting IoT with rate-splitting multiple access in satellite and aerial-integrated networks. IEEE Internet Things J. 2021, 8, 11123–11134. [Google Scholar] [CrossRef]
  33. Lin, Z.; Lin, M.; Champagne, B.; Zhu, W.; Al-Dhahir, N. Secrecy-energy efficient hybrid beamforming for satellite-terrestrial integrated networks. IEEE Trans. Commun. 2021, 69, 6345–6360. [Google Scholar] [CrossRef]
  34. Liang, Z.; Xing, G. Self-powered absorptive reconfigurable intelligent surfaces for securing satellite-terrestrial integrated networks. China Commun. 2024, 21, 276–291. [Google Scholar]
  35. Ma, R.Q.; Yang, W.W.; Guan, X.R. Covert mmWave communications with finite blocklength against spatially random wardens. IEEE Internet Things J. 2024, 11, 3402–3416. [Google Scholar] [CrossRef]
  36. Gülataş, İ.; Baktır, S. Unmanned aerial vehicle digital forensic investigation framework. J. Navig. Mar. Sci. 2018, 14, 32–53. [Google Scholar]
  37. Salamh, F.E.; Mirza, M.M.; Karabiyik, U. UAV forensic analysis and software tools assessment: DJI Phantom 4 and Matrice 210 as case studies. Electronics 2021, 10, 733. [Google Scholar] [CrossRef]
  38. Yahuza, M.; Idris, M.Y.I.; Ahmedy, I.B.; Wahab, A.W.A.; Nandy, T.; Noor, N.M.; Bala, A. Internet of UAVs security and privacy issues: Taxonomy and open challenges. IEEE Access 2021, 9, 57243–57270. [Google Scholar] [CrossRef]
  39. Salamh, F.E.; Karabiyik, U.; Rogers, M.K. RPAS forensic validation analysis towards a technical investigation process: A case study of Yuneec Typhoon H. Sensors 2019, 19, 3246. [Google Scholar] [CrossRef] [PubMed]
  40. Rana, T.; Shankar, A.; Sultan, M.K.; Patan, R.; Balusamy, B. An intelligent approach for UAV and UAV privacy security using blockchain methodology. In Proceedings of the 2019 9th International Conference on Cloud Computing, Data Science Engineering (Confluence), Noida, India, 10–11 January 2019; pp. 162–167. [Google Scholar] [CrossRef]
  41. Yaacoub, J.P.; Noura, H.; Salman, O.; Chehab, A. Security analysis of UAVs systems: Attacks, limitations, and recommendations. Internet Things 2020, 11, 100262. [Google Scholar] [CrossRef] [PubMed]
  42. Al-Room, K.; Iqbal, F.; Baker, T.; Shah, B.; Yankson, B.; MacDermott, A.; Hung, P.C. UAV Forensics: A Case Study of Digital Forensic Investigations Conducted on Common UAV Models. Int. J. Digit. Crime Forensics 2021, 13, 1–25. [Google Scholar] [CrossRef]
  43. Nassi, B.; Bitton, R.; Masuoka, R.; Shabtai, A.; Elovici, Y. SoK: Security and privacy in the age of commercial UAVs. In Proceedings of the 2021 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 24–27 May 2021; pp. 73–90. [Google Scholar]
  44. Bouafif, H.; Kamoun, F.; Iqbal, F. Towards a better understanding of UAV forensics: A case study of Parrot AR UAV 2.0. Int. J. Digit. Crime Forensics 2020, 12, 35–57. [Google Scholar] [CrossRef]
  45. Altawy, R.; Youssef, A.M. Security, privacy, and safety aspects of civilian UAVs: A survey. ACM Trans. Cyber-Phys. Syst. 2016, 1, 1–25. [Google Scholar] [CrossRef]
  46. Ghosh, T.; Rasheed, I.; Toorchi, N.; Hu, F. UA V Security Threats, Requirements and Solutions. In UAV Swarm Networks; CRC Press: Boca Raton, FL, USA, 2020; pp. 193–206. [Google Scholar]
  47. Zhang, X.M.; Han, Q.L.; Ge, X.; Ding, D.; Ding, L.; Yue, D.; Peng, C. Networked control systems: A survey of trends and techniques. IEEE/CAA J. Autom. Sin. 2020, 7, 1–17. [Google Scholar] [CrossRef]
  48. Hassija, V.; Chamola, V.; Agrawal, A.; Goyal, A.; Luong, N.C.; Niyato, D.; Yu, F.R.; Guizani, M. Fast, reliable, and secure UAV communication: A comprehensive survey. IEEE Commun. Surv. Tutor. 2021, 23, 2802–2832. [Google Scholar] [CrossRef]
  49. Chiper, F.L.; Martian, A.; Vladeanu, C.; Marghescu, I.; Craciunescu, R.; Fratu, O. UAV detection and defense systems: Survey and a software-defined radio-based solution. Sensors 2022, 22, 1453. [Google Scholar] [CrossRef]
  50. Pojsomphong, N.; Visoottiviseth, V.; Sawangphol, W.; Khurat, A.; Kashihara, S.; Fall, D. Investigation of UAV Vulnerability and its Countermeasure. In Proceedings of the 2020 IEEE 10th Symposium on Computer Applications & Industrial Electronics (ISCAIE), Penang, Malaysia, 18–19 April 2020; IEEE: New York, NY, USA, 2020; pp. 251–255. [Google Scholar]
  51. Park, S.; Kim, H.T.; Lee, S.; Joo, H.; Kim, H. Survey on Anti-UAV Systems: Components, Designs, and Challenges. IEEE Access 2021, 9, 42635–42659. [Google Scholar] [CrossRef]
  52. Hosseinzadeh, M.; Sinopoli, B. Active Attack Detection and Control in Constrained Cyber-Physical Systems Under Prevented Actuation Attack. In Proceedings of the 2021 American Control Conference (ACC), New Orleans, LA, USA, 25–28 May 2021; IEEE: New York, NY, USA, 2021; pp. 3242–3247. [Google Scholar]
  53. Nisa, C.; Sudarsono, A.; Yuliana, M. Zero Knowledge Authentication Modification for UAV and Server Communication Security. J. Mantik. 2021, 5, 1019–1029. [Google Scholar]
  54. Samland, F.; Fruth, J.; Hildebrandt, M.; Hoppe, T.; Dittmann, J.A.R. UAV: Security threat analysis and exemplary attack to track persons. Intell. Robot. Comput. Vis. XXIX Algorithms Tech. 2012, 8301, 158–172. [Google Scholar]
  55. Sciancalepore, S.; Ibrahim, O.A.; Oligeri, G.; Di Pietro, R. Detecting UAVs Status via Encrypted Traffic Analysis. In Proceedings of the ACM Workshop on Wireless Security and Machine Learning, Miami, FL, USA, 15–17 May 2019; pp. 67–72. [Google Scholar]
  56. Bisio, I.; Garibotto, C.; Lavagetto, F.; Sciarrone, A.; Zappatore, S. Unauthorized Amateur UAV Detection Based on WiFi Statistical Fingerprint Analysis. IEEE Commun. Mag. 2018, 56, 106–111. [Google Scholar] [CrossRef]
  57. Munari, S.; Palazzi, C.E.; Quadrio, G.; Ronzani, D. Network Traffic Analysis of a Small Quadcopter. In Proceedings of the 3rd Workshop on Micro Aerial Vehicle Networks, Systems, and Applications, Niagara Falls, NY, USA, 23 June 2017; pp. 31–36. [Google Scholar]
  58. Hoang, T.M.; Nguyen, N.M.; Duong, T.Q. Detection of Eavesdropping Attack in UAV-Aided Wireless Systems: Unsupervised Learning with One-Class SVM and k-Means Clustering. IEEE Wirel. Commun. Lett. 2019, 9, 139–142. [Google Scholar] [CrossRef]
  59. Iqbal, F.; Yankson, B.; AlYammahi, M.A.; AlMansoori, N.; Qayed, S.M.; Shah, B.; Baker, T. UAV forensics: Examination and analysis. Int. J. Electron. Secur. Digit. Forensics 2019, 11, 245–264. [Google Scholar] [CrossRef]
  60. Alladi, T.; Bansal, G.; Chamola, V.; Guizani, M. SecAuthUAV: A Novel Authentication Scheme for UAV-Ground Station and UAV-UAV Communication. IEEE Trans. Veh. Technol. 2020, 69, 15068–15077. [Google Scholar] [CrossRef]
Figure 1. A schematic illustration of the security risks of UAVs.
Figure 1. A schematic illustration of the security risks of UAVs.
Drones 08 00556 g001
Figure 2. Examples of UAV information security incidents.
Figure 2. Examples of UAV information security incidents.
Drones 08 00556 g002
Figure 3. UAV communication topology.
Figure 3. UAV communication topology.
Drones 08 00556 g003
Figure 4. An example of an attack–defense tree at a UAV range.
Figure 4. An example of an attack–defense tree at a UAV range.
Drones 08 00556 g004
Figure 5. Defense policy income average and threat value.
Figure 5. Defense policy income average and threat value.
Drones 08 00556 g005
Figure 6. Comparison of methods.
Figure 6. Comparison of methods.
Drones 08 00556 g006
Figure 7. Attack and defense game experiment.
Figure 7. Attack and defense game experiment.
Drones 08 00556 g007
Table 1. Meaning of offensive and defensive strategy formula.
Table 1. Meaning of offensive and defensive strategy formula.
SymbolContent
APFAttack payoff function
GThe gain an attacker expects from a successful attack
c o s t a The cost to the attacker to carry out the attack
R M The rate at which the risk of an attack on a drone system is reduced due to the deployment of a defensive measure at the drone range
c o s t u a v After defenders deploy targeted defenses, attackers have to incur additional attack costs in order to continue to breach those defenses
DPFDefense payoff function
A L E u a v The potential information security risk of UAV cyber range may lead to economic losses
C The cost of deploying a defensive measure
Table 2. The meaning of game strategy model formula.
Table 2. The meaning of game strategy model formula.
SymbolContent
A Attacker atomic attack set
D Defense behavior set
N A Attackers at the UAV range
N D Defenders at the UAV range
T A A collection of attack types, such as internal attacks, external attacks, and espionage
T D A collection of defense types, such as security experts, security analysts, and security operations personnel
B A Aggressive behavior of game players, such as DoS, backdoors, fuzzers
B D Defensive behavior of game participants, such as identity authentication, transmission encryption, intrusion detection
P A In the case of type t A , the attacker determines the probability of the defender’s type t D
P D In the case of type t D , the defender determines the probability of the attacker’s type t A
U A The attacker’s payoff function
U D The defender’s revenue function
S A t A The attacker’s pure policy set under the type t A T A
F D t D Defender mixed strategy probability distribution
F A t A Probability distribution of attacker mixed strategy
S m A t A The attacker’s pure strategy
R i The threat value of unmanned aerial systems inside the UAV range
R a l l The overall security risk value of drones
W Weight vector
Table 3. Description of attacker actions.
Table 3. Description of attacker actions.
ClassificationBase AttackDescriptionAdventurous AttackerConservative Attacker
b 1 A b 2 A b 3 A b 4 A
Root a 1
Information collection
UAV model, operating system, communication protocol and other basic information
a 2
Communication link interference
Using radio-jamming equipment to block the UAV’s communication with the ground station
a 3
Software exploit
Exploit known vulnerabilities in UAV software to gain initial access
User a 4
Privilege promotion
By exploiting the risk, the user’s permission is upgraded from the common user to the root user
a 5
Data tampering
Tampering with a UAV’s mission data to influence its flight behavior
a 6
Implant malware
Building back doors into UAV systems to maintain long-term control
Data a 7
Theft of sensitive data
Stealing flight logs and mission data from unmanned aerial systems
a 8
Control system hijacking
Access control systems through malware to hijack flight control of UAV
DoS a 9
Launch a DoS attack
A UDP flood attack disables the UAV’s communication system
a 10
Physical failure
If the attacker is able to gain sufficient access, it may send a self-destruct command or directly operate the UAV to perform physical damage
Table 4. Description of defender actions.
Table 4. Description of defender actions.
Defensive StrategyHigh DefenderJunior Defender
b 1 D b 2 D b 3 D b 4 D
Information protection
Communication encryption
Update regularly
Authority management
Data integrity check
Malware protection
Data encryption
Control system hardening
Cyber monitoring
Table 5. DPF calculation results (defender vs. conservative attacker).
Table 5. DPF calculation results (defender vs. conservative attacker).
Attack A L E u a v DefenseRMCDPF
b 1 A 1000 b 2 D 0.12400−0.7
b 3 D 0.25700−0.64
b 2 A 800 b 2 D 0.25600−0.67
b 3 D 0.3600−0.6
Table 6. APF calculation results (defender vs. conservative attacker).
Table 6. APF calculation results (defender vs. conservative attacker).
AttackG c o s t a Defense c o s t u a v APF
b 1 A 1000123 b 2 D 304.2
b 3 D 1201.59
b 2 A 800200 b 2 D 303.9
b 3 D 2051.57
Table 7. DPF calculation results (defender vs. adventurous attacker).
Table 7. DPF calculation results (defender vs. adventurous attacker).
Attack A L E u a v DefenseRMCDPF
b 1 A 1000 b 2 D 0.11400−0.725
b 3 D 0.15700−0.79
b 2 A 800 b 2 D 0.18600−0.76
b 3 D 0.20600−0.74
Table 8. APF calculation results (defender vs. adventurous attacker).
Table 8. APF calculation results (defender vs. adventurous attacker).
AttackG c o s t a Defense c o s t u a v APF
b 1 A 1000123 b 2 D 304.16
b 3 D 1202.1
b 2 A 1600200 b 2 D 304.5
b 3 D 2052.02
Table 9. Payoff matrix (defender vs. conservative attacker).
Table 9. Payoff matrix (defender vs. conservative attacker).
b 1 A b 2 A
b 2 D −0.7, 4.2−0.67, 3.9
b 3 D −0.64, 1.59−0.6, 1.57
Table 10. Payoff matrix (defender vs. adventurous attacker).
Table 10. Payoff matrix (defender vs. adventurous attacker).
b 1 A b 2 A
b 2 D −0.725, 4.16−0.76, 4.5
b 3 D −0.79, 2.1−0.74, 2.02
Table 11. Mixed strategy Bayesian Nash equilibrium.
Table 11. Mixed strategy Bayesian Nash equilibrium.
Mixed Strategy EqualizationType of Attacker/DefenderMixed Strategy Bayesian–Nash Equilibrium Probability Distribution
F A * t A Adventurous attacker F 1 A * t A , F 2 A * t A = 0.475 , 0.524
Conservative attacker F 3 A * t A , F 4 A * t A = 0.256 , 0.648
F D * t D High-level defender F 1 D * t D , F 2 D * t D = 0.603 , 0.327
Primary defender F 3 D * t D , F 4 D * t D = 0.421 , 0.583
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Miao, S.; Pan, Q. Risk Assessment of UAV Cyber Range Based on Bayesian–Nash Equilibrium. Drones 2024, 8, 556. https://doi.org/10.3390/drones8100556

AMA Style

Miao S, Pan Q. Risk Assessment of UAV Cyber Range Based on Bayesian–Nash Equilibrium. Drones. 2024; 8(10):556. https://doi.org/10.3390/drones8100556

Chicago/Turabian Style

Miao, Shangting, and Quan Pan. 2024. "Risk Assessment of UAV Cyber Range Based on Bayesian–Nash Equilibrium" Drones 8, no. 10: 556. https://doi.org/10.3390/drones8100556

APA Style

Miao, S., & Pan, Q. (2024). Risk Assessment of UAV Cyber Range Based on Bayesian–Nash Equilibrium. Drones, 8(10), 556. https://doi.org/10.3390/drones8100556

Article Metrics

Back to TopTop