Shocking security flaw: A small device can hack into Boeing 737 aircraft systems and change flight paths in seconds

 

Researchers have discovered that a hacker may not need sophisticated hacking skills or complex cyberattacks to break into a Boeing 737; seconds of physical access is enough to tamper with its vital systems

Researchers have discovered that a hacker may not need sophisticated hacking skills or complex cyberattacks to break into a Boeing 737; seconds of physical access is enough to tamper with its vital systems.

A team from the University of California, San Diego, has demonstrated that brief physical access to a Boeing 737 could give an attacker the ability to manipulate data moving between vital navigation computers, in a discovery that challenges the prevailing belief that cyber threats in aviation are limited to network attacks.

Their tiny implant takes less than a minute to insert and could be placed by anyone with access to the plane on the ground. The result, they warn, could be runway overruns, flights silently commandeered into another country's airspace, or catastrophic crashes. pic.twitter.com/byySfwHki8

The team was able to hack into the aircraft's system via a small device connected to a hidden maintenance port in its front, exploiting a vulnerability in an old technology that lacked source verification mechanisms.

They presented this discovery on August 13 during the USENIX Security Symposium in Baltimore, where they designed a small device that can be connected to a hidden maintenance port in the front of the aircraft, to control vital data that travels between navigation computers, such as flight path information and critical takeoff data.

The problem lies in the presence of an unused maintenance port under the nose of the aircraft, which is connected to the internal communication systems between computers. Although accessing it requires entering the secure airport areas, connecting the device may take no more than a minute, which is sufficient time amidst the frequent activity in the maintenance areas.

This old system relies on a technology called ARINC 429, which consists of wires that transmit information between parts of the aircraft, but it lacks modern protection mechanisms that verify the identity of the sender or the validity of the messages, making it vulnerable to hacking.

The device designed by the researchers mimics a legitimate instrument on an aircraft and interferes with real data to transmit false information, such as changing the flight path or manipulating weight and balance data that pilots rely on for takeoff calculations. However, executing this attack requires advanced preparation and engineering expertise, and pilots might detect some of the alterations and evade them.

The researchers informed Boeing of this flaw in 2020, and tested it with the company in its laboratories. The study focuses on the 737 aircraft.

In conclusion, the researchers emphasize that this discovery does not mean that aircraft are threatened with immediate hijacking, but rather it is a warning about a new type of risk that may become more important as aviation systems develop. The goal is to help airlines develop plans to counter these physical threats before they become a reality.


 

Post a Comment

Previous Post Next Post