Researchers have demonstrated how brief physical access to a Boeing 737 could give an attacker control over data moving between critical flight computers. The finding challenges a long-held assumption that aviation cybersecurity mainly concerns network-based threats. A team from the University of California San Diego presented the research Aug. 13 at the USENIX Security Symposium in Baltimore, Maryland. Their proof-of-concept used a custom hardware device connected to an aircraft maintenance interface. The researchers tested the system using Boeing 737 components and flight software. They showed that an attacker could manipulate information tied to the aircraft’s flight path. The demonstration also showed how altered flight data could affect critical takeoff calculations. Physical access creates risk The attack depends on reaching an electronics bay beneath the aircraft’s nose. Researchers found an unused maintenance interface that connects to communications carrying data between two important flight computers. Reaching the port would require access to a secured airport area. The team estimates that connecting the device could take less than a minute. That short window matters because aircraft maintenance areas and airport gates can see frequent activity. Security controls reduce the risk, but researchers argue that physical access deserves more attention. “Time-limited physical access” can still create serious consequences, the researchers wrote in their paper. They said a motivated attacker could potentially make such access a realistic objective. Legacy flight buses exposed The vulnerable communications rely on ARINC 429 data buses, a technology aviation has used for decades. These hardwired systems carry information between avionics components through electrical signals. Unlike modern networked systems, the buses were not designed around contemporary cybersecurity protections. They lack mechanisms that would authenticate messages and verify their source. Researchers built their device to impersonate a legitimate participant on the communication link. Their demonstration showed that the device could interfere with legitimate data and introduce its own messages. That capability could affect information displayed to pilots. It could also alter data used by flight management systems. The team demonstrated changes to the aircraft’s planned route during testing. It also manipulated information associated with weight, balance and temperature. Pilots could potentially detect and override some altered information. The researchers stressed that their scenario still requires extensive preparation and specialized engineering. Boeing worked with researchers The team disclosed the vulnerability to Boeing in 2020. Researchers later tested and validated their findings in a Boeing laboratory. The study focuses specifically on the 737, one of the most widely operated commercial aircraft in the United States. Researchers noted that the broader security issue extends beyond one aircraft family. Boeing 737 aircraft account for significant portions of major US airline fleets. The type represents roughly a quarter of Delta’s fleet, more than half of United’s and all of Southwest’s fleet, according to the researchers. Aaron Schulman, a UC San Diego computer scientist and senior researcher, said the work aims to help aviation companies address physical-access threats before they become dangerous.The researchers also stressed that their demonstration does not mean commercial aircraft face an imminent takeover threat. Instead, it exposes a class of vulnerabilities that could become more important as attackers gain access to increasingly sophisticated aviation systems.Get the latest in engineering, tech, space & science - delivered daily to your inbox.Aamir is a seasoned tech journalist with experience at Exhibit Magazine, Republic World, and PR Newswire. With a deep love for all things tech and science, he has spent years decoding the latest innovations and exploring how they shape industries, lifestyles, and the future of humanity.
Tiny device hacks Boeing 737 flight systems, alters routes in under 60 seconds
Full Article
Original Source
Read the full article at Interestingengineering →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.