Air Traffic Control: Insecurity and ADS-B. Righter Kunkel, CISSP, CISA Security Researcher defcon 17



Similar documents
Cyber-hijacking Airplanes:

8-1 Chapter 8 Radio Operations: Aviation Spoken Here

IMPACT OF ADS-B ON CONTROLLER WORKLOAD: RESULTS FROM ALASKA S CAPSTONE PROGRAM

Appendice 1 al Regolamento ENAC ATSEP Basic training Shared

09 FLIGHT MANAGEMENT, NAVIGATION

Providing Safety and Reliability with PBN Guy Greider HUGHES PROPRIETARY

Volunteers Devoted to Kids and Aviation

With all of the new hype the

ADS-B is intended to transform air traffic control by providing more accurate and reliable tracking of airplanes in flight and on the ground.

11 Distress and Urgency

Aircraft Hacking Practical Aero Series

Communication, Navigation, Surveillance (CNS) engineers and executives of Airports Authority of India

Introduction. The Bricks and Bytes of Our Aviation Infrastructure

Transport Spectrum Tune-Up Aviation Spectrum Issues. Eddy D Amico, RF Spectrum Manager Airservices Australia. November 2009

S TEC. List of Effective Pages. Record of Revisions

International Civil Aviation Organization PERFORMANCE MONITORING OF ADS-B EQUPPED AIRCRAFTS IN INDIAN AIRSPACE

AIR FORCE INSTITUTE OF TECHNOLOGY

ILS Replacement. ACI World Safety Seminar November 2008 Kempinski Hotel Beijing Lufthansa Centre

Policy Regarding Datalink Communications Recording Requirements. AGENCY: Federal Aviation Administration (FAA), Department of Transportation (DOT).

LOG OF REVISIONS Revision Page FAA Date of Number Number(s) Description Approved Approval A All Initial Release K.

EASA Safety Information Bulletin

2014 NIFA CRM Contestant Briefing Guide San Diego, California

Air Traffic Controllers use StarCaster ATIS software to create, update and verify the contents of ATIS messages

Aircraft Tracking & Flight Data Recovery

Engineering Air Traffic

Air Traffic Management Solutions

Automatic Dependent Surveillance Broadcast (ADS-B)

The Rebirth of Aviation and Air Transportation in Ohio

INSTALLATION OF MODE 'A' / 'C' AND MODE S TRANSPONDERS.

SESAR Air Traffic Management Modernization. Honeywell Aerospace Advanced Technology June 2014

Communication Management Unit : Single Solution of Voice and Data Routing Unit

Rockwell Collins ARINC MultiLink SM flight tracking service

National Airspace System Security Cyber Architecture

Firewalls for small business

SYSTEM GLOBAL NAVIGATION SATELLITE SYSTEM LANDING TECHNOLOGY/PRODUCT DEVELOPMENT

Realities and Challenges of NextGen Air Traffic Management: The Case of ADS-B

Understanding Compliance with Automatic Dependent Surveillance Broadcast (ADS-B) Out

WIRELESS SECURITY. Information Security in Systems & Networks Public Development Program. Sanjay Goel University at Albany, SUNY Fall 2006

AOPA Comments to FAA Page 2 March 3, 2008

Chicago Center Fire Contingency Planning and Security Review

Science, Technology, Engineering and Math. The program also seeks to recruit and integrate students of diversity into the aviation industry.

Prevention of loss of communication. Air China

International Civil Aviation Organization. The Third Meeting of the Regional ATM Contingency Plan Task Force (RACP/TF/3)

AIRSPACE EXPLAINED. Separation of Traffic

ADS-B and Multilateration Integration in the U.S. The Role of the Integrator

ADS-B over Satellite Global Air Traffic Surveillance from Space

Mitigating the Impacts of Space Weather on Aviation Operations

Playing in a Satellite environment 1.2. Leonardo Nve Egea lnve@s21sec.com

FINAL REPORT. Investigation into the incident of aircraft B 777-2Q8ER, at LKPR on 18 April Prague October Ref. No 105/06/ZZ.

WHICH AIR TRAFFIC CONTROLLER TO CONTACT

Federal Aviation Administration ADS- B Installation Guidance

VDFP General Aviation Firefighting for Structural Firefighters

GREEN SHEET OV-10A AIRTACTICAL PLANE CRASH SEPTEMBER 6, 2006 MOUNTAIN FIRE INCIDENT NUMBER 06-CA-TUU

Safety Management Challenges for Aviation Cyber Physical Systems

FAA AIRCRAFT SYSTEMS INFORMATION SECURITY PROTECTION OVERVIEW. Abstract

AIRCRAFT RESCUE AND FIRE FIGHTING GUIDE REVISION 0. AA Flight Safety Department.4601 Hwy 360; MD 849 GSWFA.Fort Worth Texas Phone

ATCoach Radar Training Simulator

Air Traffic Control Modernization: FAA, NextGen, GNSS, and Avionics Equipage

b) Describe the concept of ERROR CHAIN in aviation.

50 Questions You Need To Ask When Preparing Crisis Coverage

INTRUSION DETECTION SYSTEM (IDS) D souza Adam Jerry Joseph I MCA

Automation at Odds. A 737 stalled when a radio altimeter malfunction caused the autothrottle and autopilot to diverge during an approach to Schiphol.

BOY SCOUTS OF AMERICA MERIT BADGE SERIES AVIATION

Security-related procedures and requirements are a fact of life for today's pilots, especially those who operate in the Washington, DC metropolitan

P/N 135A FAA Approved: 12/6/2007 Section 9 Initial Release Page 1 of 8

Global Positioning System Steering (GPSS) Converter Pilot s Operating Handbook

Briefing on the United Airlines System Operations Control Center and Crisis

INITIAL TEST RESULTS OF PATHPROX A RUNWAY INCURSION ALERTING SYSTEM

Air Traffic Management

Why it may be time to consider Certified Avionics for UAS (Unmanned Aerial Vehicles/Systems) White paper

Curriculum Map Bismarck Public Schools Aviation / High School (Bismarck Technical Center)

Evolution in Regional Aircraft Avionics

March 21, Dear Ranking Member Costello:

Required Surveillance Performance Accuracy to Support 3-Mile and 5-Mile Separation in the National Airspace System

Attacking Automatic Wireless Network Selection. Dino A. Dai Zovi and Shane A. Macaulay

Oral Preparation Questions

How To Secure An Rsa Authentication Agent

qualify for this license, applicants must be at least 18 years old and have at least 250 hours of flight experience.

AVIATION SAFETY. Proposals to Enhance Aircraft Tracking and Flight Data Recovery May Aid Accident Investigation, but Challenges Remain

Security and Risk Analysis of VoIP Networks

White Paper Mode S and the European Mandates

Low Level Windshear Alert System (LLWAS) An integral part of the U.S. FAA Wind-shear safety program

Chapter 15. Airports Authority of India Manual of Air Traffic Services Part EMERGENCY PROCEDURES

FACT SHEET UNMANNED AIRCRAFT SYSTEMS (UAS)

Trends in Aeronautical Information Management

Annual SERC Research Review (ASRR)

Secure communications Reference

PF3 ATC at its best Version History

MEMO AIRBUS A319/A320/A321. SOP / Flow Pattern

Who is Watching You? Video Conferencing Security

Challenges Facing the Implementation of FAA s Automatic Dependent Surveillance Broadcast Program

Civil Aviation and CyberSecurity Dr. Daniel P. Johnson Honeywell Aerospace Advanced Technology

Two-Year Academic Course Schedule - Fall 2015 through Summer Program Director: Dusty Mosness-Brailsford Campus Phone :

CAUSES OF AIRCRAFT ACCIDENTS

per day, air traffic controllers help a pilot by performing a

Revision Number Revision Date Insertion Date/Initials 1 st Edition February nd Edition March 05, 2002

Maryland State Firemen s Association Executive Committee Meeting December 5, 2009

Airspace. Chapter 14. Introduction

IN FLIGHT SECURITY INCIDENT MANAGEMENT

White Paper VoIP Crash Phone Systems

Transcription:

Air Traffic Control: Insecurity and ADS-B Righter Kunkel, CISSP, CISA Security Researcher defcon 17

Agenda Who am I? ATC Background DOS on a Tower State of Airline Security Where are we going? ADS-B defcon 17 Righter Kunkel 2

Who am I? Security Field for >12 years Worked with secure operating systems: B1, B2 Firewalls, proxies Trainer CISSP, CISA Ham Radio Private Pilot defcon 17 Righter Kunkel 3

First Is flying safe? YES Are planes going to fall out of the sky after this talk? NO Is flying safe after this talk? YES Is some of this talk illegal? YES Disclaimer: Don t do this! defcon 17 Righter Kunkel 4

Pilots? Is any one a pilot? defcon 17 Righter Kunkel 5

Our Focus We are not going to focus on: Airport physical security Cockpit door security X-Ray security Our focus: Computers used by ATC How airplanes report their position to ATC NexGen ATC defcon 17 Righter Kunkel 6

Why? ATC is busy moving planes through the air ATC not focused on network security of equipment being used Who would want to hack a radar scope? defcon 17 Righter Kunkel 7

Some ATC Background ATC VOR Transponders Flight Plans defcon 17 Righter Kunkel 8

ATC What is ATC? Source: GAO/T-AIMD AIMD-00 00-330 FAA Computer Security defcon 17 Righter Kunkel 9

VOR What are VOR s? VHF Omni-directional Radio Range Source: Wikipedia defcon 17 Righter Kunkel 10

Airplane Transponder Source: Wikipedia defcon 17 Righter Kunkel 11

Mode-S Transponders Primary Surveillance Radar (PSR) Paint the skin Secondary Surveillance Radar (SSR) Asks planes transponder to send out a signal and data, time based Get unconfirmed ALT from plane Source: Wikipedia defcon 17 Righter Kunkel 12

How do Flight Plans Work? Pilot submits a requested route Goes into a central computer Real flight plan gets printed out at ATC Source: Wikipedia defcon 17 Righter Kunkel 13

Some interesting attacks in the past D.B. Cooper 9/11 People trying to fake their own death defcon 17 Righter Kunkel 14

Who Was D.B. Cooper? Legendary Skyjacker $200,000 Parachuted out the back of a 727 in flight Never found Source: Wikipedia defcon 17 Righter Kunkel 15

9/11 I only want to focus on one fact: They turned the transponder off We have not developed anything to mitigate that attack country wide ADIZ in DC only defense defcon 17 Righter Kunkel 16

Faking Your Own Death A Pilot tried to bluff ATC about an emergency Set plane on autopilot Parachuted out of plane Plane intercepted by F16s Plane crashed Pilot got caught defcon 17 Righter Kunkel 17

Switching Gears My proposed attack: DOS on an ATC tower defcon 17 Righter Kunkel 18

A DOS on an ATC Tower 1. Get a fake ID (Of course this is illegal) 2. Get an aviation medical using fake id (also illegal) 3. Get issued a student pilot certificate with certificate number 4. Log into duat.com 5. Create multiple flight plans and submit 6. All flight plans get printed at tower defcon 17 Righter Kunkel 19

Medical Cert Source: Wikipedia defcon 17 Righter Kunkel 20

Web Sites Web based way to get weather briefings and enter flight plans Duat.com Duats.com defcon 17 Righter Kunkel 21

duat.com defcon 17 Righter Kunkel 22

duat.com defcon 17 Righter Kunkel 23

duat.com defcon 17 Righter Kunkel 24

duats.com defcon 17 Righter Kunkel 25

Telnet access to duats.com defcon 17 Righter Kunkel 26

Or Telephone Numbers Source: A/FD Source: A/FD defcon 17 Righter Kunkel 27

Or Radio Jam the ATC tower frequencies defcon 17 Righter Kunkel 28

State of Airline Insecurity I then stepped back and looked around. defcon 17 Righter Kunkel 29

FAA Insecurity A published report came out: ATC_Web_report.pdf Included on the CD defcon 17 Righter Kunkel 30

Test Results Wow! defcon 17 Righter Kunkel 31

FAA Network Infrastructure The connection that should never happen defcon 17 Righter Kunkel 32

IDS Sensors Who needs IDS defcon 17 Righter Kunkel 33

Leaked Data From Report ATC_Web_report.pdf I guess we now know what networks are vulnerable defcon 17 Righter Kunkel 34

Where are We Going? IDS by Feb. 2010 NextGen ATC ADS-B defcon 17 Righter Kunkel 35

NextGen ATC Converting from proprietary hardware to commercial off the shelf hardware Phasing out radar Airplanes transponder will report Lat., Long., and Alt. in clear txt ADS-B defcon 17 Righter Kunkel 36

ADS-B Insecurity Who am I and where am I in one unencrypted packet GPS will be the backbone of NextGen Oh, and GPS sats are failing faster than expected One could easily fake an ADS-B transmission No radar to verify true position defcon 17 Righter Kunkel 37

Call to Action Listen to ATC View ADS-B broadcasts Become a Pilot defcon 17 Righter Kunkel 38

Conclusion ATC Background DOS on a Tower State of Airline Security Where are we going? ADS-B defcon 17 Righter Kunkel 39

Questions? defcon 17 Righter Kunkel 40

References http://en.wikipedia.org/wiki/d._b._cooper http://www.oig.dot.gov/streamfile?file=/data/pdfdocs/atc_web_report.pdf http://www.airsport-corp.com/adsb2.htm http://online.wsj.com/article/sb124165272826193727.html# http://en.wikipedia.org/wiki/pilot_certification_in_the_united_states Airport/Facility Directory; FAA Product ID:AFDSW ; www.naco.faa.gov http://en.wikipedia.org/wiki/air_traffic_control_radar_beacon_system http://en.wikipedia.org/wiki/vhf_omnidirectional_range GAO, FAA COMPUTER SECURITY, GAO/T-AIMD-00-330 FAA Computer Security, Sept. 2000 defcon 17 Righter Kunkel 41