This Coin-Sized Device Can Hack a Boeing 737
Even as the digital components of so many life-critical systems have proven susceptible to cybersabotageācars, medical devices, even water utilities and power gridsāthe computer systems
Even as the digital components of so many life-critical systems have proven susceptible to cybersabotageācars, medical devices, even water utilities and power gridsāthe computer systems of airplanes have, thankfully, remained uniquely inaccessible to hackers. But one group of academic researchers has spent years testing a different, devious approach to aviation cybersecurity. Perhaps, they suggest, a plane could be hacked the same way that spies and saboteurs have targeted other high-value, offline computers: by surreptitiously gaining physical access to one and plugging in a device designed to silently run the attackers' malicious code. Tomorrow at the Usenix Cybersecurity Conference, researchers from the University of California at San Diego and Oberlin College will present a hacking technique capable of commandeering the autopilot of a Boeing 737 to redirect its navigation or silently altering key values in the plane's takeoff and fuel calculations while spoofing the results on the pilot's screenāsubtle changes the researchers say could potentially cause anything from runway overruns on takeoff to diversions to a different country's airspace to catastrophic crashes.
To carry out that hacking, they've built a roughly coin-sized, Wi-Fi-enabled prototype device that costs less than $100. In less than a minute, that hardware implant can be fitted into a port accessible via a hatch on the exterior of the plane, one that's routinely within reach of maintenance workers or other airport and airline staff between flights. Once it's in place, the device can send electrical signals on one of the 737's internal networks to spoof commands to sensitive computer systems that guide its autopilot and show the pilot variables like the plane's total weight and outside air temperature, which play a critical role in a 737's takeoff calculations. The researchers' hacking device, next to a quarter for scale.
Photograph Courtesy of UCSD By proving the viability of that technique, the result of a process that stretched over more than a decade and entailed buying tens of thousands of dollarsā worth of plane components for testing, they hope to show that this sort of physical access hacking represents a practical threat in the hands of well-resourced saboteurs and a significant blind spot in aircraft security. Compared to the traditional threat of simply planting a bomb on a plane, they argue, it's also an approach that would offer an attacker more control, stealth, and deniability. āIf you could get 60 seconds with an airplane, what could you do?ā asks Stefan Savage, one of the UCSD computer science professors who led the project, describing the question that first motivated their line of research.
