# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 30 June 2013 |
| Platform | Quiet Systems |
| Series | DKSR-M-2013-06 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

The first NATO CCDCOE / CyCon paper scores military and consumer UAVs on the same cyber-physical factors. Reaper C2, AR.Drone open Wi-Fi, and RQ-170 lost-link are treated as one risk class — assessment, not a new product CVE.

### Key judgments

1. **[Assessment — High confidence]** Hartmann and Steup, CyCon 2013, Tallinn, 4–7 June 2013. NATO CCDCOE / IEEE proceedings.
2. **[Assessment — High confidence]** Risk scheme applied to MQ-9 Reaper and Parrot AR.Drone; RQ-170 discussed. Synthesizes Creech 2011, RQ-170 2011, and AR.Drone — no new defect ID.
3. **[Inference — Moderate confidence]** This is the first in-window NATO-venue statement that the consumer open-Wi-Fi class and military C2 belong on the same tracker.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. Hartmann and Steup: UAV cyber-risk assessment

*Event / publication dates: 5th International Conference on Cyber Conflict (CyCon 2013), Tallinn, 4–7 June 2013.*

| Field | Value |
| --- | --- |
| Component | software / firmware / hardware |
| Product | Risk scheme applied to MQ-9 Reaper and Parrot AR.Drone; RQ-170 discussed |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | none public |

**Verified record — [Fact — A1]** Kim Hartmann, Christoph Steup, “The Vulnerability of UAVs to Cyber Attacks - An Approach to the Risk Assessment,” CyCon 2013. https://ccdcoe.org/uploads/2018/10/26_d3r2s2_hartmann.pdf · https://ieeexplore.ieee.org/document/6568373 · conference dates https://ccdcoe.org/cycon/

**Exposure.** Communications, storage, sensors, fault handling. C2, Sense, and lost-link as scored factors.

**Intelligence assessment.** [Assessment — High confidence] First NATO CCDCOE / CyCon paper on this class. [Uncertainty] Assessment paper; no new product bug.

**Opportunity.** Do not invent a CWE for a risk scheme. Watch SkyJack (December 2013) as fielded automation of the AR.Drone half.

**LRRK relevance.** Watch. Campaign (military and consumer on one sheet).

**Confidence.** High on the paper. Moderate as a case.

## Forward indicators

1. SkyJack (December 2013) — automation of the AR.Drone half this paper already scores.
2. A CyCon or ICS follow-on that names a SKU CVE (none in this window).

> **Collection integrity.** One assessment paper synthesizing prior cases. No taxonomy (policy/assessment). Not padded. Public sources only. No invented CVEs. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
