new realities in aviation security remotely gaining control of aircraft systems

18
Transport Security

Upload: daveedwards12

Post on 18-Dec-2014

250 views

Category:

Business


0 download

DESCRIPTION

New realities in aviation security-Remotely gaining control of aircraft systems

TRANSCRIPT

Page 1: New realities in aviation security remotely gaining control of aircraft systems

Transport Security

Page 2: New realities in aviation security remotely gaining control of aircraft systems

AIR TRANSPORT● 2.8 billion

– People flown in 2011.

● 38 million

– Number of flights in 2011

MARITIME TRANSPORT● 30,936

– Transport ships in 2011

● 8,7 billion tons

– Seaborne trade on 2012

Page 3: New realities in aviation security remotely gaining control of aircraft systems

Safety is NOT Security

Page 4: New realities in aviation security remotely gaining control of aircraft systems

New technologies, new threats......new requirements:

● IT Security profile– New systems– Automation

● Aviation profile– Specific knowledge– Own technologies– Standards

Page 5: New realities in aviation security remotely gaining control of aircraft systems

Part I– Traditional technologies

Part II– New risks and attack vectors

Agenda

Page 6: New realities in aviation security remotely gaining control of aircraft systems

Traditional technologies

Good old days

Page 7: New realities in aviation security remotely gaining control of aircraft systems

Older technologiesPrimary Surveillance

Radars (PSR)

✈ Detects presence of planes via the reflection of radio waves by the planes.

Secondary Surveillance Radars (SSR)

✈ Detects and measures the position of aircrafts, requests additional information from them.

Page 8: New realities in aviation security remotely gaining control of aircraft systems

Legacy systems Glass cockpit

Older technologies

Page 9: New realities in aviation security remotely gaining control of aircraft systems

New technologies

Risks and attacks

Page 10: New realities in aviation security remotely gaining control of aircraft systems

Attack overview

DISCOVERY

✈ ADS-B

GATHERING

✈ ACARS

EXPLOITATION

✈ Systems

Page 11: New realities in aviation security remotely gaining control of aircraft systems

THE TARGET

SOFTWARE

Page 12: New realities in aviation security remotely gaining control of aircraft systems

DISCOVERY - ADS-B

Automatic Dependent Surveillance-Broadcast

✈ Radar substitute

✈ Position, velocity, identification

Page 13: New realities in aviation security remotely gaining control of aircraft systems

GATHERING - ACARS

Aircraft Communications Addressing and Reporting System

✈ Digital data link for transmission of messages between aircraft and ground stations

Page 14: New realities in aviation security remotely gaining control of aircraft systems

EXPLOITATION - FMS✈Flight Management System– Typically consists of two units:

» A computer unit

» A control display unit

✈Control Display Unit (CDU or MCDU) provides the primary human/machine interface for data entry and information display.

✈FMS provides:

» Navigation

» Flight planning

» Trajectory prediction

» Performance computations

» Guidance

Page 15: New realities in aviation security remotely gaining control of aircraft systems

EXPLOITATION - Attack deliveryGround Service providers

● The “glue” of the aviation ecosystem

house

Software Defined Radio● A radio communication

system where hardware components are implemented by means of software.

Page 16: New realities in aviation security remotely gaining control of aircraft systems

Unmanned Aircraft Systems

COMMUNICATIONS– SATCOM

● Iridium● Ku-Band● C/S-Band

– VHF● :-)

NON-SEGREGATED AIRSPACE

● Civil aviation systems– COTS/MOTS– Vulnerable:

● Protocols● Systems

Page 17: New realities in aviation security remotely gaining control of aircraft systems

RemediationWhere to start from?

– ✈ NextGen Security● On-board systems security

audit

– ✈ Who is affected?● Manufacturers● Ground Service Providers● Airlines/Operators

Page 18: New realities in aviation security remotely gaining control of aircraft systems

Remember: Safety is NOT Security

[email protected]

Additional resources

– RootedCon 2012● Slides: http://x90.es/7e4● Video: http://x90.es/7e5

– HITB 2013● Slides: http://x90.es/7e6● Video: http://x90.es/7e7