While much of aviation cybersecurity focuses on network-based threats, researchers just showed that a physical attack on an airplane may require surprisingly little time or money.
Researchers at the University of California San Diego and Oberlin College built a small, coin-sized device that can take over communications between two key flight computers on Boeing 737 aircraft.
The prototype costs less than $100 to build and can be plugged into a maintenance port inside an electronics bay underneath the plane’s nose. The bay can be accessed from the ground through an exterior hatch that is not locked and is routinely accessible to maintenance workers and other airport staff.
The researchers estimate that an attacker would only need 60 seconds to intall the device.
The protoype they built is Wi-Fi enabled, which the researchers say could theoretically allow it to connect to the plane’s in-flight Wi-Fi and be controlled remotely over the internet.
“Our goal with this research is to alert the aviation community to this class of risks, so they may be appropriately mitigated well before they become dangerous,” the researchers wrote in a paper presented this week at the USENIX Security Symposium in Baltimore.
How the hack works
Once intalled, the device can interfere with communications between the aircraft’s Flight Management Computer, which manages its flight plan and provides important information used during takeoff, and the Multipurpose Control Display Unit pilots use to control it.
That gives the device the ability to secretly change a plane’s flight plan while preventing those changes from appearing on the pilot’s display. The researchers described scenarios in which hackers could cause the autopilot to divert the aircraft into another country’s airspace or just send it off course.
The researchers also demonstrated that the device could manipulate information about the plane’s weight, balance and outside temperature, making a takeoff unsafe.
“We believe we have made a strong case that time-limited physical access (e.g., 60 seconds) represents a realistic goal for a motivated attacker and that the consequences of even such short access can