Hackers can fake radio signals to 'hijack' aircraft landing systems
computing.co.uk
computing.co.uk
Basically they come down to, if you learn how a system works, or how something is made, you can learn to implement or influence that system and/or build that thing. Back in the 60's the click bait was "kid learns how to build an atomic bomb!" This was pretty eye catching but really it is just physics, material science, and a bit of math.
That said, so many people rarely look past the surface of things, seeing something like a cell phone as an opaque magical brick that can do wondrous things. And yet all that the phone does, and how it does it, are knowable if someone chooses to invest the time. (admittedly it is a lot of time if you don't have the basics).
The headline, "People who know how radios work can affect systems that are based on radio." is so much less scary.
If, for example, simply transmitting in the clear on the right frequency can get the airliner to try to land on a virtual runway that is 20 feet below the real one - that is interesting.
Much easier would be to put the runway where it doesn't exist, such as at the foot of a cluster of tall buildings or hillside that is a mile from the actual location. A strong transmitter and directional antenna would be effective. It would be a once-only attack, because the FCC, FAA, FBI would all be on maximum alert after that. There's also a good chance it wouldn't work because the airliner is cross checking its position with GPS, ATC is cross checking with radar, and there's a good chance either the pilot or ATC will abort due to confusion over position.
Ideally the pilot would notice and correct, but in poor visibility, maybe they wouldn't have time.
It's a lot easier to buy an SDR than a SAM -- even ignoring the cost differential. I don't know the black market cost of a man portable SAM, but the SDR described in the article is less than $1000 and you can buy it commercially.
If you're caught with an SDR in your suitcase, no one will likely know what it is "I use it to listen to shortwave, here, I'll demo", while if you're caught with a SAM, you'll likely end up in jail.
No one is going to build a SAM in their hotel room, but it doesn't take much specialized skill to solder together a radio jammer using schematics transferred to you over the internet.
And finally, you can use the radio jammer from a backpack and no one will know it's there, but the SAM will leave a trail leading back to you.
Building an SDR which can output a signal strong enough to overpower the ILS array is not going to be cheap, subtle, or particularly easy. ILS is glitchy and pilots are trained to deal with the glitches — a localizer can be disrupted merely by having a plane (or any other large metal object) nearby.
For example it was both inspiring and utterly brilliant in the way that Alan Turing broke the Enigma cipher with his Bombe machine, but today anyone who knew how Enigma worked (which England did at the time) with a modern laptop could exhaustively search the keyspace and 'crack' messages in real time.
Software radios have made it possible for curious people to have "read/write" access to the entire spectrum between half a megahertz and six gigahertz. That will continue to be a problem for people who designed systems that depended on how "difficult" it was to build a radio at their particular frequency.
That isn't the case for Aircraft navigation. Anyone who can pass the Amateur "General' class exam in the US has the necessary knowledge for interfering, potentially destructively, with aircraft navigation. I normally would consider that a non-issue except that Asian Airlines flew a plane into the runway at SFO. Is that a system problem? Or one where the pilot should be better trained? Arguments can probably made along those lines. But that interfering with navigation is possible with pretty much "off the shelf" components? Not really a new thing and certainly not something that is an imminent threat to passenger safety.
And it depends on the direction of the answers too.
For example I think most autoland still require some amount of visibility a few seconds before touchdown, and the pilots are supposed to go around if they do not have it. Plus, I believe planes also use a radio altimeter while landing. But I don't believe they use GPS for the final approach.
So you might put a plane in a difficult position with that kind of attack, but not necessarily making it crash. And there are probably more easy ways to do more damage.
However, ALL instrument approaches have minimum visual altitudes, and the lowest I'm aware of is 200 ft above the ground. If you can't see the airport by the time you get down to the minimum altitude you execute a missed approach procedure- basically you climb and navigate to another waypoint to restart the approach or to hold. Additionally, all aircraft must have barometric altimeters as required equipment- no amount of radio spoofing can fool them.
So in an ideal world an attack would go like this: the pilot follows the malicious approach, notices that they are at the minimum altitude, looks for the airport but doesn't see it (or sees it a few miles away), then executes a missed approach- no crash. There aren't too many tight approaches that could make you crash by being off by a mile.
To get around this you would need to spoof either the pitot-static (pressure sensing) system, or the pilot's altimeter setting. You could only spoof the pitot-static system by sabatoge on the ground, and you can only realistically spoof the altimeter setting by pretending to be ATC on the radio- at which point the real ATC would correct whatever you said and get real suspicious.
Of course, given that instrument landings are the highest workload portion of a flight, pilots get distracted. Even if they would normally catch on to the fact that they aren't on the correct approach, you might cause a few crashes by pilots that aren't on top of their game.
Edit to add one more thing: Your plane is tracked by airborne surveillance as well, and if you claim to be at a waypoint and that doesn't match what ATC has on their scope they will warn you. So you'd have to also spoof a surveillance signal at the correct location while blocking the real planes signal to keep ATC from noticing.
https://en.wikipedia.org/wiki/Instrument_landing_system#ILS_... claims "<50 ft" decision height for CAT IIIb.
I never even considered the possibility of a CAT IIIc where you can land in zero visibility, probably because I'll never fly an airplane with suitable equipment. I've never briefed flying a CAT III approach, and wouldn't even consider landing at those airports in the light planes that I fly. In my local area around KDEN the general consensus is that while it's technically legal to land a light plane at KDEN you would probably have to declare an emergency to get clearance from ATC, and even then they'd strongly encourage you to land somewhere nearby (like KFTG) if possible.
The best response is probably jamming (seduction) detection, through good data fusion algorithms. Hard to do directive jamming without sidelobe leakage that could be detected on the ground.
Transmitting a signed (AEAD) bitstream should be possible by publishing a public key in the NOTAM. The cost decrease in DRFMs (SDRs) also means that deploying radio receivers with upgradable waveforms is also much cheaper.
https://en.wikipedia.org/wiki/Instrument_landing_system and https://aviation.stackexchange.com/a/2661, compare https://en.wikipedia.org/wiki/Battle_of_the_Beams
No need to actually read this one. Thanks guys.
No, it is not. Nobody should be able to influence air traffic in that way just because she/he understands the transport layer.
After spending a night with a friend who just returned from a security audit (lots of cocktails were involved too) 15 years ago, I am convinced that the only reason we have not seen major disruptions yet is because of a pretty strict adherence to hacker ethics: one of the global "airport tech players" was deploying systems that used UDP for ground traffic control.... Having a bus or lorry use an active runway is just a single, malicious UDP packet away...
There are multiple safeguards in place to avoid single points of failure, such as runway crossing procedures with mandatory call to air traffic control unit for explicit permission before entering a runway. Many ATC recordings on VASAviation Youtube channel show that even rescue services (during emergencies) adhere to that.
Taxiways leading to runways are marked with holding positions that may not be crossed without authorization: https://i.imgur.com/dCF8lFi.jpg For extra visibility in poor weather, many airports are also equipped with runway guard lights paved into the ground or blinking on either side of the taxiway: https://i.imgur.com/dbix1Aw.png
Surface movement radars and transponder-based systems have also become widespread. They trigger alerts when a vehicle is about to enter an active runway: https://i.imgur.com/sJQ94zq.jpg
Remember in San Fransisco where a plane almost landed on a taxi way instead of the runway? It's worth reading the complex situation with the off-line runway and the way ILS was setup with those runways being so close together, but what prevented the disaster was a pilot in the Taxi line of aircraft getting on the radio and saying, "Where is this guy going?!" and everyone suddenly realizing they were lined up for the Taxi way!
Real people, being aware, looking and reacting prevented that accident. That's why human checks and cross-checks are so important.
Because it is a pain.
Every pilot has to learn to do visual approaches.
I think it just makes one thing apparent though. If we go to fully automated flying then there must ALSO be a visual check. In fact we can make it better than humans because we should make sure that the plane can see through fog. But key point is that there is always some redundancy built in.
I don't think a visual check is needed (otherwise you would be much more limited in where/when you can land), but cross-checking some other data is. Turns out we're already there, and in an ILS approach the pilots should already be checking other instruments.
I hear you. But it is the reality of the world. There comes a time when everyone realizes that the boundary between civilized behavior and uncivilized behavior is just a convention. I think of it as the final stage of moving from childhood into adulthood.
For example, you could go into the hardware store and buy a couple of bags of fertilizer, some stump remover, a bag of charcoal for the grill, some food for the roses, and six quarts of motor oil. Are you going to do some gardening and grilling over the weekend or going to blow up someone's house? The materials work for either activity. Maybe you rent a moving van over the holiday weekend. Helping a buddy move? Or mowing down tourists at a crowded venue?
People who choose to be evil will be evil. There isn't anything you can do about them but you can build defense in depth on various other ways.
In the case of air navigation you have a pilot in the cockpit who is supposed to be paying attention. They can takeoff, navigate, and land with nothing more than their eyeballs, a compass, and some paper charts. All the other gizmos help certainly but they aren't essential[1]. When people actively interfere with the other gizmos, whether it is intentionally by transmitting on restricted frequencies, or unintentionally like the delivery truck that shut down Newark Airport because the driver used a GPS jammer to keep the home office from seeing they were taking a break while he watched the planes, it has effects. The rest of the system reacts to minimize damage and risk and the actions themselves bring attention to the people involved.
It is fortunate in my experience that that 90+% of the people in the world are too lazy or simply not wired to be curious about how things work the way they do. You may have noticed from the article that they didn't say how you would interfere with navigation with a "$600 SDR", they just said that you could. Most people reading that will say, "Oh dear that's dreadful! Oh look here's a picture of a funny puppy on the next page."
As I get older and meet more people, it amazes me how rare genuine curiosity really is. The persistence to follow that curiosity in order to develop understanding is rarer still. Life doesn't have a safety net, and trying to give it one to eliminate danger completely is pretty futile.
[1] Ok the pilots in the group are going to jump up and say, without an artificial horizon, an airspeed indicator, and working altimeter and you'll be sorry but even without those you can do pretty well.
Given that one wouldn't care about spectrum purity, the required budget becomes minimal, with a trivial hardware component resulting in components easily obtainable with an anonymous visit to a swap meet, if one were to visit the right swap meet. After that, it's a simple matter of programming.
I've found that a lot of people are so defined by their job that they have no idea what happens above or below them. The "I deal with packet filters" person can't explain basic networking, nor do they have any idea what the overall configuration of the (enterprise) network is like, to cite an example.
Sure, that and the redundancy and procedure built into an ILS approach. Keep in mind that even airplanes on the wrong part of the tarmac can fuck with the localizer. ILS is imperfect and that's already well known and worked around[1].
1: https://www.pprune.org/rumours-news/616082-air-india-b788-de...
That is impossible to prevent. If not anything, it is usually not that difficult to overwhelm any electromagnetic communication with your own powerful signal. Preventing communication is at least as destructive as manipulating communication without avoiding detection.
Nonsense. It all depends on what is implemented on top of UDP.
It reminds me of when the Army's drone was diverted and captured because someone spoofed GPS... It probably isn't possible to capture a drone in the same way anymore because I'm sure that they fixed this flaw.
It's like the HTTP vs HTTPS problem ... but anyone can MITM attack because the signal is wireless (and not encrypted and/or signed).
In this case, the user can be sure that the site uses encryption of personal data to increase protection and security. However, it must be understood that obtaining a certificate can be a daunting task (which accounts for the additional weight of this factor when ranking).
When a site requests a certificate, the organization that issued the certificate becomes a trusted third party to read more here https://sitechecker.pro/http-vs-https/ and check it. When your browser accesses a site that uses the secure HTTPS protocol, it uses the information contained in the certificate to authenticate the site. A user who understands the difference between HTTP and HTTPS, can safely make purchases, and not be afraid that his data will be stolen.
"Tests of the ILS system began in 1929 in the United States."
It's really just a radio beam. It's no wonder it can be mucked with.
The glideslope signal (vertical deviation indication) would be easier to spoof. Set that up 1/2 mile short of the runway and aligned to intercept the proper glideslope shortly before the true glideslope intercept point (Maltese cross on the chart). That has a chance of working and going undetected. If you're able to get an aircraft onto the rogue glideslope lobe, even when ATC gets a low altitude alert, the crew is likely to report they're perfectly on glideslope. I'm not sure this is as practical an attack as simply firing on an aircraft on approach, of course.
Trolling flightradar24 and like services would be easy.
Wireless systems without AAA and encryption and signing are effectively fucked.
I've seen these articles pop up a few times in the past couple days but everyone in aviation already knows that there isn't any security on this stuff. People even jam ATC for giggles sometimes[1]. There's enough redundancy that nothing bad has happened as a result so everyone goes on with life. I think this is just low hanging defcon fruit targeting non aviation-aware readers.
This is not to say it's impossible, but with the current stuff on the market and required software investment I'd put it at an order of magnitude or two higher execution complexity than grabbing a VHF radio and messing with ILS beams.
https://www.cnet.com/news/truck-driver-has-gps-jammer-accide... (Truck driver has GPS jammer, accidentally jams Newark airport)
Why dont I? Its illegal and its ethically wrong, and its not my focus of study.
Generating the requisite signal is easy to do with opensource code and just $200 or so of equipment.
I bet the drone didn't use the military encrypted GPS because they didn't want encryption keys to fall into the wrong hands (they're global), or just because the effort to load the new GPS keys every week was too much, The attackers just jammed and then spoofed GPS, and by providing a very strong signal, any kalman filters designed to merge signals from inertial units would be fooled.
Of course none of the DoD's version of events explains why then Iran has a mostly intact RQ-170...
The Islamic Republic of Iran, by definition, has state level resources. In addition to their own resources, they have close ties with Russia and China. I agree with your ballpark of an order of magnitude higher complexity than messing with ILS, but that's well within Iran's capabilities.
Even introducing an error into the system can cause disastrous effects [2]
[0] https://arstechnica.com/information-technology/2018/07/a-225...
[1] https://radionavlab.ae.utexas.edu/images/stories/files/paper...
[2] https://blog.themistrading.com/2012/07/could-gps-spoofing-ca...
Ars technica cited a researcher at Northwestern that said GPS isn't necessarily a perfect fallback
> One reason: the types of runway misalignments that would be effective in a spoofing attack typically range from about 32 feet to 50 feet, since pilots or air traffic controllers will visually detect anything bigger. It’s extremely difficult for GPS to detect malicious offsets that small. A second reason is that GPS spoofing attacks are relatively easy to carry out.
https://arstechnica.com/information-technology/2019/05/the-r...
Or impersonate. One of my pilot friends was planning a trip across the CA Central Valley, and he reported with some bemusement that there was at active NOTAM (NOtice To Air Men) to be on guard about some guy in the Fresno area that was impersonating ATC. Apparently it had been happening for months and nothing much by way of investigation had taken place.
At this point I pretty much concluded that bad Part 15 devices or PG&E power line noise h0rk1ng over my ham radio reception was not going to get any attention, ever, if the FCC can't be bothered to find an ATC impersonator. I mean really, there are hams that do hidden transmitter hunts purely for sport. A posse of them could find that clown easily on any random Saturday morning and not be late for lunch.
So why don't they?
One of my ham friends deals with the FCC often, because he works in spectrum management at the NTIA. The stories he tells make me never want to set foot in D.C. except to visit all the museums that my taxes fund.
What stops them from finding who's transmitting and then filing a civil suit?
Whenever I hear something like this it reminds me of the favorite talks I attended. The Iridium hacking talk at HOPE XI[1].
"When they talk about security they mainly talk about 'hey this is so complex, no one is able to do this, maybe a state or something like that'. So they say 'it will probably be beyond the reach of all but the most determined attackers.' We went well ok, we are determined."
But that would reveal your position. Presumably the above could be executed without even being present: just leave behind the equipment.
You’d probably have to engineer the flight path to go through a building, power line, or other obstacle, but that in and of itself seems like a difficult proposition since flight paths leading into an airport with this type of system wouldn’t have 100ft obstacles anywhere near the approach direction. You’d have to spoof the localizer to be offset to the side of the runway to accomplish this, but doing it too far will cause instruments to disagree (GPS, VOR) and ATC to yell at you.
Maybe you could aim it at a nearby taxiway, but to do so (per my understanding of the physics of ILS) you’d have to have your equipment in-line with the taxiway. All of this just seems really hard to pull off in practice.
One of the many conspiracy theories associated with this incident is that Russia deliberately created the physical and electronic conditions necessary for this crash to take place.
The cockpit records suggest there were more obvious causes in this instance, but it seems very likely a state actor would be able to engineer a successful attack using a variety of means - not just ILS, but other forms of physical and electronic spoofing.
I agree it’s not a practical attack.
I'd hope that the pilot would notice something is off and abort the landing before that. (Eg: visually be like "oh there is something on the runway I thought I was cleared on)
Theoretically even if cleared for landing they should keep an eye out and abort if, say, an errant baggage cart was in the way.
For the rest, usually below 10.000 feet, there van never be "two heads up", so one pilot is always watching the instruments. Any deviation from expected parameters (airspeed, verticale speed, ils deviation, radio altitude) Will result in an unstabilised approach and thus the execution of missed approach procedures (a go-around).
As mentioned elsewhere, everyone in aviation knows these systems are as insecure as can be.
Edit: forgot to finish a sentence..
Frankly aviation is ripe for cyber attack. The problem is not simple to solve, mainly because introducing crypto into critical navigation systems will also introduce failures where legitimate service is interrupted due to system glitches. It will take crashing a jet before the industry decides to take this seriously, and it is entirely possible that a terrorist group or state actor will use this weakness. Government and industry can and would respond, but it would take money and time.
I would not place blame with a pilot who is cleared for landing, and fails to see something on the runway. Even if they are making a good faith effort to scan the runway, it's hard to see things from the sky with your eyes.
>It will take crashing a jet before the industry decides to take this seriously, and it is entirely possible that a terrorist group or state actor will use this weakness.
I agree it's an issue that should be worked on, but I think it's much more likely (as a parent pointed out) someone will simply fly a drone into the airspace.
After all, bird strike incidents are a major cause of crashes:
>The Federal Aviation Administration (FAA) estimates bird strikes cost US aviation 400 million dollars annually and have resulted in over 200 worldwide deaths since 1988.[56] In the United Kingdom, the Central Science Laboratory estimates[8] that worldwide, the cost of birdstrikes to airlines is around US$1.2 billion annually. This cost includes direct repair cost and lost revenue opportunities while the damaged aircraft is out of service. Estimating that 80% of bird strikes are unreported, there were 4,300 bird strikes listed by the United States Air Force and 5,900 by US civil aircraft in 2003.
In any other condition, the pilot would see the runway well before the aircraft was at an altitude low enough to touch the ground in any sort of bank or turn.
A commercial airplane operating under Cat IIIa ILS at a Cat IIIa Airport could operate on autoland to the touchdown point
If you could potentially cause a wing strike, why wouldn't you just trick the plane into landing on the taxiway, for maximum chaos?
Def Con in 2012 https://www.youtube.com/watch?v=e1QAjCH_1oU
EDIT: (Since I can’t reply because HN for whatever reason prevents me from posting more than 2-3 replies per day): To clarify, yes I’m arguing that this is not newsworthy.
Only if you get caught. How do they catch you if you set up the transmitters and then fled the scene?
What? You can't "trace a transmitter" like this. You could triangulate someone's location while transmitting.
> purchase records tied to serial numbers on the transmitters
Yeah, I'm sure second hand sales would update this information if it exists in the first place at all, and even if it did, it's not like transmitter transmits that information.
So.. don't do it? If anyone with rudimentary SDR knowledge can build a system to interfere with aircraft landing, and they can get away with it by taking basic precautions (don't stay at the scene and don't brag), that's still pretty terrifying.
Anyone without rudimentary opsec will likely be caught between the "shits and giggles" phase of experimentation and the "domestic terrorism" phase of doing something extremely stupid near an airport. This person will likely ask questions on a forum site that are sketchy enough that the regular hobbyists report the suspicious user. This is a pattern that repeats often: stupid criminal gets caught by talking about doing crimes, or by showing criminal behavior to non-criminals. Any crime large enough to require a conspiracy is also large enough to have a secret informant.
The biggest threat is someone with a legitimate interest in SDR, and enough skill to devise an attack unassisted, who experiences a psychological stress powerful enough to make them break, and turn against the civil order. That is extremely low probability, but still theoretically possible. People that decide to pick up a weapon and fight are likely to use what is at hand, and the expertise they already have, to attack. Everyone else in the field has a very strong interest in making sure that no one does anything overtly stupid with SDR, because even accidental missteps could ruin the profession/hobby for everyone, entire countries at a time.
If that is in fact what you're asking, then there are a great many societal functions that you should be worrying about the stability of at a much higher priority than flight radio.
This, specifically is a feature, and why voice is still done over AM. It allows all planes to be heard by ATC, regardless of their transmission strength relative to other planes. AM signals "add" whereas FM tends to have a "capture" effect, and only receive the strongest signal (or most equally strong signals) at a time.
> ILS, VORs
Slightly OT, but I love the simplicity of design in these systems. They've actually inspired me to go, finally, take my HAM license exam. (Probably early next month due to scheduling.)
I sometimes feel like many systems built are just much to over-engineered and don't even attempt to exploit physics to do their job. On the other hand, as this article points out, VORs and ILS aren't authentication.
I still can't believe that there wasn't designed with some kind of authentication built into the ADS-B system. It's newer and deals with transmitting arbitrary data.
PAPI lights are my favourite example of this.
For those that don't know the system, PAPI lights are installed next to runway touchdown point and give visual feedback of vertical approach path: are you too low, too high or just fine.
Photo: https://i.imgur.com/Da8p3Uk.jpg Diagram: https://i.imgur.com/XSrUeD1.jpg
It needs no moving parts and no electronic control.
Each light has a filter that splits the beam into white and red sectors. Red is shown below a certain angle, white above. Each light is at a different elevation angle.
Photo: https://i.imgur.com/D0GvPHA.png Diagram: https://i.imgur.com/o2SRGE8.jpg (red lines are red/white sector boundary for each light)
Viewing from a very low angle, all four lights look red. Slightly above that, one of them turns white. At standard approach angle, two are white and two are red. A bit above approach path, the third one becomes white. At very high angles, the whole row is white.
PAPI lights become more precise as the aicraft gets closer. The system can serve any number of aircraft at the same time, does not have to track them, and does not require receivers/transmitters or any other on-board equipment.
(Fictional, but widely believed to be true, at least for a time)
Ended when Germany moved the radio gear in preparation for invading Russia.
Such monitoring systems date back to 1960s: https://sci-hub.tw/10.1049/ree.1967.0009
"Hacking" is a bit of a heavy handed word here, too.
Although as others have mentioned, if you're trying to crash a plane or cause a disruption at the airport there's easier ways. Including just flying the drone over the runway (to close an airport).
I don't think anyone has forgotten about MCAS