待翻译:Coin size device can hack Boeing airplanes
AI 服务暂时不可用,以下为来源摘要,待恢复后补全翻译:Researchers have found it took only a coin-sized device and less than 60 seconds to hijack critical features in Boeing 737 airplanes, which could allow hackers to cause a flight to be redirected, overshoot the runway, o…
AI 服务暂时不可用,以下为来源正文,待恢复后补全翻译。
Researchers have found it took only a coin-sized device and less than 60 seconds to hijack critical features in Boeing 737 airplanes, which could allow hackers to cause a flight to be redirected, overshoot the runway, or even crash. Discovered by a team of computer scientists at the University of California San Diego (UCSD) and Oberlin College, the exploit involved making false representations about crucial flight data via display devices which usually sit in the cockpit. Though the attack method would theoretically require a nefarious insider or unauthorised access to an airport gate or hangar, the researchers estimated that simply plugging the device into the plane’s belly would take less than 60 seconds. As discovered by former UCSD student Sam Crow, the implant can effectively drive enough electrical current to override legitimate transmissions with its own. Once attached, researchers warned hackers could re-route a plane in flight, or modify data about weight, balance, and temperature to potentially sabotage a take-off. The vulnerability has been replicated on a testbed using Boeing 737 components, but the researchers believe their findings are relevant to the broader aviation industry. “The authors of this paper routinely travel on Boeing 737 aircraft and expect to continue doing so,” said Aaron Schulman, cybersecurity researcher at UCSD. “Our goal with this research is to alert the aviation community to this class of risks, so they may be appropriately mitigated well before they become dangerous.” The Boeing 737 is one of the world’s most common commercial aircrafts with approximately 8,000 vessels in service at the time of writing. Boeing collaborated on the research after being alerted to the vulnerability in 2020, and has since listed members of the research team in its “security hall of fame”. A Boeing spokesperson told Information Age the company has evaluated its security architectures against the potential threat and determined the research "does not impose a threat to ongoing operational safety". “We are grateful for UCSD’s responsible disclosure and collaboration. Their professionalism throughout our engagements is commendable," they said. "Safety is the foundation of everything we do, and we take threats to our products seriously." How does the hack work? In a video (below) demonstrating the hack, Schulman pointed out how the hack could be used to take over communications between two critical on-board computers. From a desk in his lab, Schulman housed a ‘multipurpose control display unit’ which is typically used to display critical flight data and flight path information to pilots in the cockpit. He explained this display unit is also used to configure planes for flight, with pilots inputting take-off, approach, and cruise or fuel-consumption parameters via its keyboard controls. The other module – a ‘Flight Management Computer’ – takes these provided parameters to compute and execute a flight plan accordingly. Rather than being stored in the cockpit, however, this device is stored in an ‘Electronic and Equipment’ (E and E) bay below the airplane. Though not accessible to the public, Schulman explained that someone with ground-crew access would be able to “reach up and get in there”. “There’s a plug deep in the ‘E and E’ bay,” Schulman said. “If you open the door and get inside, you can then touch [it] from the ground. “If you attach something to that plug, it actually gives you full control over this entire flight management computer.” From here, a hacker could conduct a “very covert and inconspicuous” attack where commands are illegitimately given to the flight management computer. Any resulting system values are then misrepresented to appear normal on the display unit shown in the cockpit. “The pilot doesn’t have any knowledge that something is going on,” Schulman said. A unique threat Given the amount of planning needed to conduct the exploit, researchers conceded attackers could simply mount other physical attacks, such as planting explosives, instead of inserting the hacking implant. Though true, the paper detailed that the covert device could also support non-destructive attacks, such as redirecting a flight so a country can detain a specific passenger. Researchers also found the implant method could allow a measure of deniability by making accidents (such as those caused by fuel shortages) seem like a pilot’s fault. Though the exploit could theoretically cause significant harm, the researchers emphasised pilots could override illegitimate system changes if they manage to detect that a compromise has occurred. “We note that complex industrial systems such as transport aircraft are frequently seen as outside the practical scope of all but the most well-funded and resourced attackers,” they wrote. “We hope our results, primarily the product of a single graduate student with modest financial resources, help people reconsider this assumption as well.”