LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 30 November 2013 | | Platform | Quiet Systems | | Series | DKSR-M-2013-11 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF IEEE HST treats the phone-as-GCS pattern as a kinematic C2 trust problem. Uncertified smartphone and tablet GCS apps — the AR.Drone commercial pattern, moving into military use — are a loss-of-control and data-exfil path. ### Key judgments 1. **[Assessment — High confidence]** Mansfield et al., 2013 IEEE HST, Waltham, 12–14 November 2013. 2. **[Assessment — High confidence]** Smartphone/tablet UAV GCS apps and their mobile/wireless backhaul (DoD and civilian). Not a single named app CVE. 3. **[Uncertainty]** Authors state DoD lacked a secure network, certification, and policy for these devices at time of writing — a policy gap, not a defect ID. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Mansfield et al.: smartphone UAV GCS threat model *Event / publication dates: 2013 IEEE Conference on Technologies for Homeland Security (HST), 12–14 November 2013, Waltham, MA.* | Field | Value | | --- | --- | | Component | software | | Product | Smartphone/tablet UAV GCS apps and mobile/wireless backhaul (DoD and civilian use) | | CVE / advisory | no CVE | | Patch | none | | Exploit status | none public | **Verified record — [Fact — A1]** Katrina Mansfield, Timothy Eveleigh, Thomas Holzer, Shahryar Sarkani, “Unmanned aerial vehicle smart device ground control station cyber security threat model,” 2013 IEEE HST, pp. 722–728. https://doi.org/10.1109/ths.2013.6699093 **Exposure.** GCS apps / mobile OS / wireless GCS hub. Control Fabric and Sense (who is on the phone). **Intelligence assessment.** [Assessment — High confidence] First IEEE HST paper on the phone-as-GCS pattern as kinematic C2. [Uncertainty] Threat model; no named app CVE. **Opportunity.** Watch SkyJack next month as the commercial pattern automated. Do not invent a CWE for a threat model. **LRRK relevance.** Watch. Control Fabric. Passport (app GCS). **Confidence.** High on the paper. Moderate as a case. ## Forward indicators 1. SkyJack (December 2013) — commercial phone-GCS pattern automated. 2. A named GCS-app CVE (none in this window). > **Collection integrity.** One threat-model paper. Taxonomy omitted (model / policy, not a mapped defect). Not padded. Public sources only. No invented CVEs. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>