In the 21st century, the industry of drones, also known as Unmanned Aerial Vehicles (UAVs), has witnessed a rapid increase with its large number of airspace users. The tremendous benefits of this technology in civilian applications such as hostage rescue and parcel delivery will integrate smart cities in the future. Nowadays, the affordability of commercial drones expands its usage at a large scale. However, the development of drone technology is associated with vulnerabilities and threats due to the lack of efficient security implementations. Moreover, the complexity of UAVs in software and hardware triggers potential security and privacy issues. Thus, posing significant challenges for the industry, academia, and governments. In this paper, we extensively survey the security and privacy issues of UAVs by providing a systematic classification at four levels: Hardware-level, Software-level, Communication-level, and Sensor-level. In particular, for each level, we thoroughly investigate (1) common vulnerabilities affecting UAVs for potential attacks from malicious actors, (2) existing threats that are jeopardizing the civilian application of UAVs, (3) active and passive attacks performed by the adversaries to compromise the security and privacy of UAVs, (4) possible countermeasures and mitigation techniques to protect UAVs from such malicious activities. In addition, we summarize the takeaways that highlight lessons learned about UAVs' security and privacy issues. Finally, we conclude our survey by presenting the critical pitfalls and suggesting promising future research directions for security and privacy of UAVs.
翻译:21世纪,无人驾驶飞机行业,又称无人驾驶航空飞行器(无人驾驶飞行器),随着大量空域用户的增多,无人驾驶飞机行业出现了快速增长,这种技术在人质救援和包裹交付等民用应用方面的巨大好处将在未来纳入智能城市。如今,商业无人驾驶飞机的可负担性扩大了其大规模使用。然而,无人驾驶飞机技术的发展与脆弱性和威胁相关联,因为缺乏有效的安全执行效率。此外,软件和硬件中无人驾驶航空器的复杂性引发了潜在的安全和隐私问题。因此,对业界、学术界和政府提出了重大挑战。在本文件中,我们广泛调查无人驾驶航空器在民用应用中的安全和隐私问题,在四个层次上提供系统分类:硬件层面、软件层面、通信层面和传感器层面。特别是,我们深入调查:(1) 由于恶意行为者可能发动袭击而影响到无人驾驶航空器的常见脆弱性;(2) 现有威胁正在危及无人驾驶航空器的民用应用,(3) 消极方为损害无人驾驶航空器的安全和隐私提出了重大挑战而进行积极和被动攻击。我们最后要总结我们从恶意安全调查中了解和减轻风险的技术。