Homeland Security Issues Alert For Potential Small Aircraft Threat | Aero-News Network
Aero-News Network
RSS icon RSS feed
podcast icon MP3 podcast
Subscribe Aero-News e-mail Newsletter Subscribe

Airborne Unlimited -- Most Recent Daily Episodes

Episode Date

Airborne-Monday

Airborne-Tuesday

Airborne-Wednesday Airborne-Thursday

Airborne-Friday

Airborne On YouTube

Airborne-Unlimited-04.29.24

Airborne-Unlimited-04.23.24

Airborne-Unlimited-04.24.24 Airborne-FltTraining-04.25.24

Airborne-Unlimited-04.26.24

Fri, Aug 02, 2019

Homeland Security Issues Alert For Potential Small Aircraft Threat

An Attacker With Access To An Airplane Could Inject False Data Into A System, Leading To Loss Of Control

The Department of Homeland Security has issued an alert warning that some modern flight systems installed in small airplanes can be vulnerable to cyber attacks, particularly if the aircraft are in an accessible area.

The alert was issued by the DHS Cybersecurity and Infrastructure Security Agency. According to the alert, a public report of insecure implementation of CAN (Controller Area Network) bus networks affecting aircraft. According to this report, the CAN bus networks are exploitable when an attacker has unsupervised physical access to the aircraft. CISA is issuing this alert to provide early notice of the report.

The report from the security firm Rapid7 indicates that an attacker with physical access to the aircraft could attach a device to an avionics CAN bus that could be used to inject false data, resulting in incorrect readings in avionic equipment. The researchers have outlined that engine telemetry readings, compass and attitude data, altitude, airspeeds, and angle of attack could all be manipulated to provide false measurements to the pilot. The researchers have further outlined that a pilot relying on instrument readings would be unable to distinguish between false and legitimate readings, which could result in loss of control of the affected aircraft.

The Associated Press reports that Rapid7 focused on systems installed in small airplanes because they are more readily available for testing, and systems installed on larger airplanes, such as airliners, use more complex systems and are subject to more stringent security requirements.

While airport access is restricted by federal law, the Rapid7 lead researcher Patrick Kiley said that such security measures can be bypassed by "someone with five minutes and a set of lock picks." Kiley said that the systems can then be fairly easy to access through the engine compartment of the airplane.

The alert does not apply to older aircraft that still use mechanical instruments, according to DHS.

FMI: Alert
Source report

Advertisement

More News

ANN's Daily Aero-Term (04.30.24): Runway Centerline Lighting

Runway Centerline Lighting Flush centerline lights spaced at 50-foot intervals beginning 75 feet from the landing threshold and extending to within 75 feet of the opposite end of t>[...]

ANN's Daily Aero-Linx (04.30.24)

Aero Linx: Air Force Global Strike Command Air Force Global Strike Command, activated August 7, 2009, is a major command with headquarters at Barksdale Air Force Base, Louisiana, i>[...]

Airborne 04.24.24: INTEGRAL E, Elixir USA, M700 RVSM

Also: Viasat-uAvionix, UL94 Fuel Investigation, AF Materiel Command, NTSB Safety Alert Norges Luftsportforbund chose Aura Aero's little 2-seater in electric trim for their next gli>[...]

Airborne 04.29.24: EAA B-25 Rides, Textron 2024, G700 Deliveries

Also: USCG Retires MH-65 Dolphins, Irish Aviation Authority, NATCA Warns FAA, Diamond DA42 AD This summer, history enthusiasts will have a unique opportunity to experience World Wa>[...]

Airborne-NextGen 04.23.24: UAVOS UVH 170, magni650 Engine, World eVTOL Directory

Also: Moya Delivery Drone, USMC Drone Pilot, Inversion RAY Reentry Vehicle, RapidFlight UAVOS has recently achieved a significant milestone in public safety and emergency services >[...]

blog comments powered by Disqus



Advertisement

Advertisement

Podcasts

Advertisement

© 2007 - 2024 Web Development & Design by Pauli Systems, LC