Transport Security
AIR TRANSPORT
●
2.8 billion
– People flown in 2011.
●
38 million
– Number of flights in 2011
MARITIME TRANSPORT
●
30,936
– Transport ships in 2011
●
8,7 billion tons
– Seaborne trade on 2012
Safety is NOT Security
New technologies, new threats...
...new requirements:
●
IT Security profile
– New systems
– Automation
●
Aviation profile
– Specific knowledge
– Own technologies
– Standards
Part I
– Traditional technologies
Part II
– New risks and attack vectors
Agenda
Traditional
technologies
Good old days
Older technologies
Primary Surveillance
Radars (PSR)
✈ Detects presence of
planes via the reflection of
radio waves by the planes.
Secondary Surveillance
Radars (SSR)
✈ Detects and measures the
position of aircrafts, requests
additional information from
them.
Legacy systems Glass cockpit
Older technologies
New
technologies
Risks and attacks
Attack overview
DISCOVERY
✈ ADS-B
GATHERING
✈ ACARS
EXPLOITATION
✈ Systems
THE TARGET
SOFTWARE
DISCOVERY - ADS-B
Automatic Dependent Surveillance-Broadcast
✈ Radar substitute
✈ Position, velocity, identification
GATHERING - ACARS
Aircraft Communications Addressing and
Reporting System
✈ Digital data link for transmission of messages
between aircraft and ground stations
EXPLOITATION - FMS
✈Flight Management System
– Typically consists of two units:
» A computer unit
» A control display unit
✈Control Display Unit (CDU or
MCDU) provides the primary
human/machine interface for data
entry and information display.
✈FMS provides:
» Navigation
» Flight planning
» Trajectory prediction
» Performance computations
» Guidance
EXPLOITATION - Attack delivery
Ground Service providers
●
The “glue” of the aviation
ecosystem
house
Software Defined Radio
●
A radio communication
system where hardware
components are
implemented by means
of software.
Unmanned Aircraft Systems
COMMUNICATIONS
– SATCOM
●
Iridium
●
Ku-Band
●
C/S-Band
– VHF
●
:-)
NON-SEGREGATED
AIRSPACE
●
Civil aviation systems
– COTS/MOTS
– Vulnerable:
●
Protocols
●
Systems
Remediation
Where to start from?
– ✈ NextGen Security
●
On-board systems security
audit
– ✈ Who is affected?
●
Manufacturers
●
Ground Service Providers
●
Airlines/Operators
Remember: Safety is NOT Security
hugo.teso@nruns.com
Additional resources
– RootedCon 2012
●
Slides: http://x90.es/7e4
●
Video: http://x90.es/7e5
– HITB 2013
●
Slides: http://x90.es/7e6
●
Video: http://x90.es/7e7

More Related Content

PDF
"Galileo-EGNOS as an Asset for UTM and Security", por Ángel Rodríguez - Unive...
PPTX
Euro hawk uav, germany death by certification
PPTX
Airport security – aviation security
PPT
General Aviation Security
PDF
The Aviation Security Service of NZ
PPT
Aviation security -_chpt1
PDF
Conflict Zones - ERA operations group 28.04.2015
PDF
Airport Security
"Galileo-EGNOS as an Asset for UTM and Security", por Ángel Rodríguez - Unive...
Euro hawk uav, germany death by certification
Airport security – aviation security
General Aviation Security
The Aviation Security Service of NZ
Aviation security -_chpt1
Conflict Zones - ERA operations group 28.04.2015
Airport Security

Viewers also liked (7)

PDF
Civil Aviation Security: Why we should pay attention to past and recent IED a...
PPTX
Surveillance
PPT
Surveillance Systems
PPTX
PPt Presentation on CNS (AAI)
PPT
AVIATION SECURITY PRESENTATION
PPTX
Safety & Security Airports
PPTX
Surveillance
Civil Aviation Security: Why we should pay attention to past and recent IED a...
Surveillance
Surveillance Systems
PPt Presentation on CNS (AAI)
AVIATION SECURITY PRESENTATION
Safety & Security Airports
Surveillance
Ad

Similar to New realities in aviation security remotely gaining control of aircraft systems (20)

PDF
RADAR, Mlat, ADS, Bird RADAR, Weather RADAR Guide
PDF
NACCDCA9P08 (1).pdf
PPT
Wind Profile CETC
PDF
_What is Drone Technology, How works and It’s Future.pdf
PPTX
Project01 atc
PPTX
Deepak
PPTX
Deepak
PDF
International Journal of Engineering and Science Invention (IJESI)
PDF
International Journal of Engineering and Science Invention (IJESI)
PPTX
Cyber security in_next_gen_air_transportation_system_wo_video
PDF
Global Defense Telemetry Market Size
PDF
Global Defense Telemetry Market Report
PDF
Global Defense Telemetry Market
PPTX
Seban ppt
DOC
A Brighter Future for the Black Box
PDF
ΕΛΙΣΜΕ ΓΕΕΘΑ 20181126 2.1 Κωνσταντίνος Μέλλος «Αντιμετωπίζοντας τις Σύγχρονες...
PDF
Global Defense Telemetry Market
PDF
Global Defense Telemetry Market Report
PDF
Global Defense Telemetry Market Report
PDF
Global Defense Telemetry Market Forecast
RADAR, Mlat, ADS, Bird RADAR, Weather RADAR Guide
NACCDCA9P08 (1).pdf
Wind Profile CETC
_What is Drone Technology, How works and It’s Future.pdf
Project01 atc
Deepak
Deepak
International Journal of Engineering and Science Invention (IJESI)
International Journal of Engineering and Science Invention (IJESI)
Cyber security in_next_gen_air_transportation_system_wo_video
Global Defense Telemetry Market Size
Global Defense Telemetry Market Report
Global Defense Telemetry Market
Seban ppt
A Brighter Future for the Black Box
ΕΛΙΣΜΕ ΓΕΕΘΑ 20181126 2.1 Κωνσταντίνος Μέλλος «Αντιμετωπίζοντας τις Σύγχρονες...
Global Defense Telemetry Market
Global Defense Telemetry Market Report
Global Defense Telemetry Market Report
Global Defense Telemetry Market Forecast
Ad

More from DaveEdwards12 (11)

PDF
Defcon 22-wesley-mc grew-instrumenting-point-of-sale-malware
PDF
A Journey to Protect Points of Sale (POS)
PPTX
Man in the Browser attacks on online banking transactions
PDF
New realities in aviation security remotely gaining control of aircraft systems
PPT
Insecurity in security products 2013
PPT
Why current security solutions fail
PPTX
Anatomy of business logic vulnerabilities
PPTX
Using 80 20 rule in application security management
PPTX
Top Application Security Trends of 2012
PPTX
Vulnerability in Security Products
PPTX
Insecurity in security products v1.5
Defcon 22-wesley-mc grew-instrumenting-point-of-sale-malware
A Journey to Protect Points of Sale (POS)
Man in the Browser attacks on online banking transactions
New realities in aviation security remotely gaining control of aircraft systems
Insecurity in security products 2013
Why current security solutions fail
Anatomy of business logic vulnerabilities
Using 80 20 rule in application security management
Top Application Security Trends of 2012
Vulnerability in Security Products
Insecurity in security products v1.5

Recently uploaded (20)

PDF
Shriram Finance, one of India's leading financial services companies, which o...
PDF
COVID-19 Primer for business case prep.pdf
PDF
Chembond Chemicals Limited Presentation 2025
PDF
Handouts for Housekeeping.pdfbababvsvvNnnh
PDF
Management Theories and Digitalization at Emirates Airline
PDF
IFRS Green Book_Part B for professional pdf
PDF
France's Top 5 Promising EdTech Companies to Watch in 2025.pdf
DOCX
“Strategic management process of a selected organization”.Nestle-docx.docx
PPTX
PPT Hafizullah Oria- Final Thesis Exam.pptx
DOCX
Handbook of entrepreneurship- Chapter 10 - Feasibility analysis by Subin K Mohan
PPTX
Business Research Methods- Secondary Data
PDF
The Relationship between Leadership Behaviourand Firm Performance in the Read...
PPTX
UNIT 3 INTERNATIONAL BUSINESS [Autosaved].pptx
PDF
BeMetals_Presentation_September_2025.pdf
PPTX
003 seven PARTS OF SPEECH english subject.pptx
PPTX
OS ALL UNITS MATxtdtc5ctc5cycgctERIAL.pptx
PPTX
PwC consulting Powerpoint Graphics 2014 templates
PDF
The Impact of Policy Changes on Legal Communication Strategies (www.kiu.ac.ug)
PDF
El futuro empresarial 2024 una vista gen
PPTX
Warehouse. B pptx
Shriram Finance, one of India's leading financial services companies, which o...
COVID-19 Primer for business case prep.pdf
Chembond Chemicals Limited Presentation 2025
Handouts for Housekeeping.pdfbababvsvvNnnh
Management Theories and Digitalization at Emirates Airline
IFRS Green Book_Part B for professional pdf
France's Top 5 Promising EdTech Companies to Watch in 2025.pdf
“Strategic management process of a selected organization”.Nestle-docx.docx
PPT Hafizullah Oria- Final Thesis Exam.pptx
Handbook of entrepreneurship- Chapter 10 - Feasibility analysis by Subin K Mohan
Business Research Methods- Secondary Data
The Relationship between Leadership Behaviourand Firm Performance in the Read...
UNIT 3 INTERNATIONAL BUSINESS [Autosaved].pptx
BeMetals_Presentation_September_2025.pdf
003 seven PARTS OF SPEECH english subject.pptx
OS ALL UNITS MATxtdtc5ctc5cycgctERIAL.pptx
PwC consulting Powerpoint Graphics 2014 templates
The Impact of Policy Changes on Legal Communication Strategies (www.kiu.ac.ug)
El futuro empresarial 2024 una vista gen
Warehouse. B pptx

New realities in aviation security remotely gaining control of aircraft systems

  • 2. AIR TRANSPORT ● 2.8 billion – People flown in 2011. ● 38 million – Number of flights in 2011 MARITIME TRANSPORT ● 30,936 – Transport ships in 2011 ● 8,7 billion tons – Seaborne trade on 2012
  • 3. Safety is NOT Security
  • 4. New technologies, new threats... ...new requirements: ● IT Security profile – New systems – Automation ● Aviation profile – Specific knowledge – Own technologies – Standards
  • 5. Part I – Traditional technologies Part II – New risks and attack vectors Agenda
  • 7. Older technologies Primary Surveillance Radars (PSR) ✈ Detects presence of planes via the reflection of radio waves by the planes. Secondary Surveillance Radars (SSR) ✈ Detects and measures the position of aircrafts, requests additional information from them.
  • 8. Legacy systems Glass cockpit Older technologies
  • 10. Attack overview DISCOVERY ✈ ADS-B GATHERING ✈ ACARS EXPLOITATION ✈ Systems
  • 12. DISCOVERY - ADS-B Automatic Dependent Surveillance-Broadcast ✈ Radar substitute ✈ Position, velocity, identification
  • 13. GATHERING - ACARS Aircraft Communications Addressing and Reporting System ✈ Digital data link for transmission of messages between aircraft and ground stations
  • 14. EXPLOITATION - FMS ✈Flight Management System – Typically consists of two units: » A computer unit » A control display unit ✈Control Display Unit (CDU or MCDU) provides the primary human/machine interface for data entry and information display. ✈FMS provides: » Navigation » Flight planning » Trajectory prediction » Performance computations » Guidance
  • 15. EXPLOITATION - Attack delivery Ground Service providers ● The “glue” of the aviation ecosystem house Software Defined Radio ● A radio communication system where hardware components are implemented by means of software.
  • 16. Unmanned Aircraft Systems COMMUNICATIONS – SATCOM ● Iridium ● Ku-Band ● C/S-Band – VHF ● :-) NON-SEGREGATED AIRSPACE ● Civil aviation systems – COTS/MOTS – Vulnerable: ● Protocols ● Systems
  • 17. Remediation Where to start from? – ✈ NextGen Security ● On-board systems security audit – ✈ Who is affected? ● Manufacturers ● Ground Service Providers ● Airlines/Operators
  • 18. Remember: Safety is NOT Security [email protected] Additional resources – RootedCon 2012 ● Slides: http://x90.es/7e4 ● Video: http://x90.es/7e5 – HITB 2013 ● Slides: http://x90.es/7e6 ● Video: http://x90.es/7e7