Physical
access to an aircraft has not typically been considered a cybersecurity
risk—but it should be, according to a team of computer scientists at the
University of California San Diego. In a paper presented Aug. 13 at the USENIX Security Symposium in Baltimore, Maryland, former UC San Diego
Ph.D. student Sam Crow showed that physical access to an aircraft, even for a
brief period, would allow an attacker equipped with a custom-made hardware
device to take over communications between two key onboard computers.
The device needs to be plugged into a
port inside the plane's belly—an action that the researchers estimate would
take less than 60 seconds. This would require access to the aircraft either
when it is parked at a gate or in an airport hangar during regular maintenance.
Access to these areas is carefully controlled but not always successfully, the
computer scientists note in the new paper.
The researchers successfully
demonstrated the attack on a test bed made of actual Boeing 737 airplane parts
and software. The proof-of-concept attack allowed researchers to change the
plane's flight path and alter data that could make takeoff conditions unsafe.
But they are careful to note that the attack requires someone to do significant
planning and engineering work ahead of time. The research team communicated
closely with Boeing, disclosed the vulnerability in 2020, and further tested
and validated its findings in Boeing's own lab.
Of note, the Boeing 737 is one of the
most commonly used aircraft in commercial aviation, with 8,000 in service
today. It makes up about 25% of Delta's existing fleet, 38% of American's, 53%
of United's and all of Southwest Airlines' fleet. However, while the team's
implementation is designed specifically for the Boeing 737, the researchers
believe their findings are relevant to the aviation industry more generally.
"Our goal with this research is to
alert the aviation community to this class of risks, so they may be
appropriately mitigated well before they become dangerous. All of the authors
of this paper routinely travel on Boeing 737 aircraft and expect to continue
doing so," said UC San Diego computer scientist and cybersecurity expert
Aaron Schulman, one of the senior authors of the work.
The research team was led by Schulman
and Stefan Savage, both professors in the UC San Diego Department of Computer
Science and Engineering.
How does the attack work?
The researchers discovered an
unused maintenance port in the plane's Electronics and Equipment Bay, which
houses key electronic systems. This bay is located just under the plane's nose,
can be reached from the ground and is not locked. The maintenance port provides
access to data transmitted between two critical onboard computers.
One computer
is the flight management computer, which controls the plane's flight path and
approach path before landing and supplies critical information during takeoff.
The other is the computer that displays this flight path information, along
with other critical flight data, for the pilots in the cockpit. Information and
instructions to and from these two computers are carried by hardwired
communication systems known as buses—in this case, two ARINC 429 buses, which
were invented in 1977.
Buses, like the ARINC 429, convey data via current flowing through two wires and a set of resistors. Because the system is decades old, it does not have data security features, such as message authentication.
The
researchers designed, built and programmed a small hardware device that acts as
a third-party entity and takes over these buses. It does so by driving more
current, allowing it to override any legitimate transmissions with its own.
This approach allows the device to covertly transmit new instructions to the
flight management computer while suppressing indications that changes have been
made.
Using their proof-of-concept
demonstration, the researchers showed that their implant could reroute a plane
in flight or modify data about weight, balance and temperature, which could
lead to an unsafe takeoff. While pilots could override such changes, they would
need to detect that a compromise had occurred.
"We believe we have made a strong case that time-limited physical access (e.g., 60 seconds) represents a realistic goal for a motivated attacker and that the consequences of even such short access can be significant (and hence worthy of attention)," the researchers write.
Source: Brief physical access may let attackers alter Boeing 737 flight instructions



No comments:
Post a Comment