UAV Forensics and Analysis, What You Do After You Detect and Neutralize a Malicious UAV - Use Case Session - Kovar David, Founder/CEO, Kovar & Associates
are currently illegal to use domestically with very limited exceptions • Lots of pressure to enable full CUAS use for prisons, critical infrastructure, major public events • “Ok, you’ve shot it down, now what?”
in many sectors • Little understanding of inherent value • Little means to recognize value • You can start understanding the threat actors and their motivations even without CUAS
Payload operator via data link to UAV mission payload GPS signals Data uplink to cloud PIC to UAV FC via radio controller Telemetry to corporate network Each link, each component, leaves evidence and generates intelligence
the entire product, however, there is SN number for different components. So you could use one component SN number as the unique identifier such as Flight Controller SN number.” - DJI
Photograph the scene and the drone in situ • Remove the battery if safe to do so – May still be writing data – Engines may turn on – Greater chance of fire • Photograph all components, labels, barcodes
the law, or feel that ”the government” is infringing on their rights • Falling UAV can cause injury, prop strikes will cause injury. Remove props • LiPo batteries store lots of energy and can catch fire. Store in fire proof container
Telemetry • Flight Controls • Gimbal • Motor Status • Flight Status • Position • Battery Status • Battery Serial Number • Battery Voltage • Message Console • Message Config • Message ID • Message Misc • Lots of unknowns still
known for this aircraft? • Are any of the known locations for this aircraft at a residence or commercial facility? • How many aircraft have flown over our facility? • What types of aircraft have we seen? • Was the battery on this aircraft on any other aircraft? • Who else has seen this aircraft?
tell you a lot about the purpose of the flight LIDAR Optical NVIR Thermal WiFi • The sensor data and metadata will tell you a lot about where it has been, particularly since GPS data is critical for most types of missions
to take a picture, and EXIF data tells a story about the camera and where it was taking pictures. • Image Description : DCIM\100MEDIA\DJI_0030.JPG • Make : DJI • Camera Model Name : FC300S • Date/Time Original : 2016:03:27 10:15:57 • Create Date : 2016:03:27 10:15:57 • GPS Version ID : 3.2.0.0 • GPS Latitude Ref : North • GPS Longitude Ref : West • GPS Altitude Ref : Above Sea Level • Aperture : 2.8 • GPS Altitude : 74.6 m Above Sea Level • GPS Latitude : 40 deg 32' 15.84" N • GPS Longitude : 89 deg 30' 50.63" W • GPS Position : 40 deg 32' 15.84" N, 89 deg 30' 50.63" W DJI Phantoms do not did not record altitude in the EXIF data unfortunately.
Often a mobile device combined with a radio controller • Vendor applications and community developed • Looking for: – Default settings – Launch points, dates – Owner name, account Other Items • Spare removable media • Other UAVs • Laptops, cell phones, tablets
is sUAS – small unmanned aerial system. Take a system approach to security and investigations, do not treat the vehicle as a discreet or standalone element. • Law & Policy: • UAVehicle. Apply law and policy to the risk/threat posed by the sensors and services rather than by the delivery mechanism [email protected] - www.kovarllc.com