18
Transport Security

New realities in aviation security remotely gaining control of aircraft systems

Embed Size (px)

DESCRIPTION

New realities in aviation security remotely gaining control of aircraft systems

Citation preview

Page 1: New realities in aviation security remotely gaining control of aircraft systems

Transport Security

Page 2: New realities in aviation security remotely gaining control of aircraft systems

AIR TRANSPORT● 2.8 billion

– People flown in 2011.

● 38 million

– Number of flights in 2011

MARITIME TRANSPORT● 30,936

– Transport ships in 2011

● 8,7 billion tons

– Seaborne trade on 2012

Page 3: New realities in aviation security remotely gaining control of aircraft systems

Safety is NOT Security

Page 4: New realities in aviation security remotely gaining control of aircraft systems

New technologies, new threats......new requirements:

● IT Security profile– New systems– Automation

● Aviation profile– Specific knowledge– Own technologies– Standards

Page 5: New realities in aviation security remotely gaining control of aircraft systems

Part I– Traditional technologies

Part II– New risks and attack vectors

Agenda

Page 6: New realities in aviation security remotely gaining control of aircraft systems

Traditional technologies

Good old days

Page 7: New realities in aviation security remotely gaining control of aircraft systems

Older technologiesPrimary Surveillance

Radars (PSR)

✈ Detects presence of planes via the reflection of radio waves by the planes.

Secondary Surveillance Radars (SSR)

✈ Detects and measures the position of aircrafts, requests additional information from them.

Page 8: New realities in aviation security remotely gaining control of aircraft systems

Legacy systems Glass cockpit

Older technologies

Page 9: New realities in aviation security remotely gaining control of aircraft systems

New technologies

Risks and attacks

Page 10: New realities in aviation security remotely gaining control of aircraft systems

Attack overview

DISCOVERY

✈ ADS-B

GATHERING

✈ ACARS

EXPLOITATION

✈ Systems

Page 11: New realities in aviation security remotely gaining control of aircraft systems

THE TARGET

SOFTWARE

Page 12: New realities in aviation security remotely gaining control of aircraft systems

DISCOVERY - ADS-B

Automatic Dependent Surveillance-Broadcast

✈ Radar substitute

✈ Position, velocity, identification

Page 13: New realities in aviation security remotely gaining control of aircraft systems

GATHERING - ACARS

Aircraft Communications Addressing and Reporting System

✈ Digital data link for transmission of messages between aircraft and ground stations

Page 14: New realities in aviation security remotely gaining control of aircraft systems

EXPLOITATION - FMS✈Flight Management System– Typically consists of two units:

» A computer unit

» A control display unit

✈Control Display Unit (CDU or MCDU) provides the primary human/machine interface for data entry and information display.

✈FMS provides:

» Navigation

» Flight planning

» Trajectory prediction

» Performance computations

» Guidance

Page 15: New realities in aviation security remotely gaining control of aircraft systems

EXPLOITATION - Attack deliveryGround Service providers

● The “glue” of the aviation ecosystem

house

Software Defined Radio● A radio communication

system where hardware components are implemented by means of software.

Page 16: New realities in aviation security remotely gaining control of aircraft systems

Unmanned Aircraft Systems

COMMUNICATIONS– SATCOM

● Iridium● Ku-Band● C/S-Band

– VHF● :-)

NON-SEGREGATED AIRSPACE

● Civil aviation systems– COTS/MOTS– Vulnerable:

● Protocols● Systems

Page 17: New realities in aviation security remotely gaining control of aircraft systems

RemediationWhere to start from?

– ✈ NextGen Security● On-board systems security

audit

– ✈ Who is affected?● Manufacturers● Ground Service Providers● Airlines/Operators

Page 18: New realities in aviation security remotely gaining control of aircraft systems

Remember: Safety is NOT Security

[email protected]

Additional resources

– RootedCon 2012● Slides: http://x90.es/7e4● Video: http://x90.es/7e5

– HITB 2013● Slides: http://x90.es/7e6● Video: http://x90.es/7e7