TY - JOUR
T1 - Mission-preserving protocol defense
T2 - An in-situ MAVLink honeypot with benchmark-calibrated thresholds and constant-space logging
AU - Chen, Zigang
AU - Cao, Zheng
AU - Yu, Fulin
AU - Yuan, Xiaochen
AU - Zhu, Haihua
N1 - Publisher Copyright:
© 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.
PY - 2026/8/1
Y1 - 2026/8/1
N2 - Modern UAVs increasingly prioritize onboard compute for mission-critical tasks such as real-time control, SLAM, and AI navigation, leaving little tolerance for security mechanisms that impose a noticeable compute-tax. Meanwhile, the MAVLink control/telemetry protocol remains a prominent attack surface, where protocol-layer abuses can rapidly escalate into command injection or denial of service. This paper presents an in-situ, protocol-level MAVLink honeypot that provides active defensive deception and behavior-driven mitigation while maintaining a small and predictable runtime footprint. The honeypot emulates essential MAVLink behaviors to lure and discriminate adversarial interactions, and adopts three key mechanisms for deployability: (i) a startup micro-benchmark to calibrate a platform-specific flooding threshold (set as 60% of the measured UDP receive peak within a fixed 1 s window), (ii) per-IP sliding windows that trigger brief sleeps or temporary blacklisting under abnormal request patterns, and (iii) constant-space logging with ring-buffer semantics to sustain long-lived operation. Evaluation in a containerized embedded-like setting (0.5 CPU core, 100 MiB RAM) shows stable memory usage of 16-19 MiB, peak CPU below 2.5% of a single core under attack, sub-second detection/mitigation latency across representative MAVLink abuse scenarios (heartbeat flooding, parameter enumeration, dangerous command injection, and UDP flooding), and log size converging to a constant after 1000 entries. Overall, the results demonstrate that protocol-layer defensive deception can be integrated onboard with minimal interference to primary mission compute, providing a practical security enhancement path for MAVLink-based UAV systems.
AB - Modern UAVs increasingly prioritize onboard compute for mission-critical tasks such as real-time control, SLAM, and AI navigation, leaving little tolerance for security mechanisms that impose a noticeable compute-tax. Meanwhile, the MAVLink control/telemetry protocol remains a prominent attack surface, where protocol-layer abuses can rapidly escalate into command injection or denial of service. This paper presents an in-situ, protocol-level MAVLink honeypot that provides active defensive deception and behavior-driven mitigation while maintaining a small and predictable runtime footprint. The honeypot emulates essential MAVLink behaviors to lure and discriminate adversarial interactions, and adopts three key mechanisms for deployability: (i) a startup micro-benchmark to calibrate a platform-specific flooding threshold (set as 60% of the measured UDP receive peak within a fixed 1 s window), (ii) per-IP sliding windows that trigger brief sleeps or temporary blacklisting under abnormal request patterns, and (iii) constant-space logging with ring-buffer semantics to sustain long-lived operation. Evaluation in a containerized embedded-like setting (0.5 CPU core, 100 MiB RAM) shows stable memory usage of 16-19 MiB, peak CPU below 2.5% of a single core under attack, sub-second detection/mitigation latency across representative MAVLink abuse scenarios (heartbeat flooding, parameter enumeration, dangerous command injection, and UDP flooding), and log size converging to a constant after 1000 entries. Overall, the results demonstrate that protocol-layer defensive deception can be integrated onboard with minimal interference to primary mission compute, providing a practical security enhancement path for MAVLink-based UAV systems.
KW - High-efficiency onboard systems
KW - Honeypots and defensive deception
KW - MAVLink
KW - Protocol-layer security
KW - Unmanned aerial vehicles (UAVs)
UR - https://www.scopus.com/pages/publications/105043491681
U2 - 10.1016/j.comcom.2026.108613
DO - 10.1016/j.comcom.2026.108613
M3 - Article
AN - SCOPUS:105043491681
SN - 0140-3664
VL - 257
JO - Computer Communications
JF - Computer Communications
M1 - 108613
ER -