The radio navigation systems used by airplanes for safe landings are unsafe and vulnerable to hacking.

The signal that aircraft use to locate the runway can be spoofed using a radio for $600.

The radio navigation systems used by airplanes for safe landings are unsafe and vulnerable to hacking.
Aircraft in a demonstration of an attack on the radio due to fake signals. ILS lands to the right of the runway.

Virtually any aircraft that has taken to the skies in the last 50 years – whether it be a single-engine Cessna or a giant airliner with 600 seats – has relied on radio stations for a safe landing at airports. These Instrument Landing Systems (ILS) are considered precision approach systems, as opposed to GPS and other navigation methods, providing crucial real-time information about the aircraft's horizontal position relative to the runway and the vertical descent angle. In many conditions – especially during landings in fog or rain at night – this radio navigation remains the primary means of ensuring that the aircraft touches down at the beginning and right in the middle of the runway.

Like many other technologies created in the past, ILS does not account for security against hacking. Radio signals are unencrypted, and their authenticity is not verified. Pilots simply assume that the audio signals received by their systems on a frequency assigned for the airport are the real signals transmitted by the airport operator. For many years, this lack of security did not concern anyone, mainly because the cost and complexity of spoofing signals made attacks pointless.

But now researchers have developed a low-cost hacking method that raises questions about the safety of ILS used in virtually every commercial airport in the industrialized world. Using a $600 radio, researchers can spoof airport signals such that the pilot's navigation instruments will indicate that the aircraft is off course. According to training, the pilot must correct the descent rate or orientation of the aircraft, thereby creating a potential incident. programmatic control, researchers can spoof airport signals so that the pilot's navigation instruments indicate that the aircraft has veered off course. According to training, the pilot must adjust the descent rate or the vessel's orientation, thereby creating a risk of an incident.

One attack technique involves fake signals indicating that the descent angle is less than it actually is. The forged message contains a so-called 'descend to land' signal, instructing the pilot to increase the descent angle, which could result in the aircraft touching down before reaching the runway.

The video shows a different type of fake signal that could pose a threat to an aircraft on approach for landing. The attacker can send a signal informing the pilot that their aircraft is to the left of the centerline of the runway, while in reality, the aircraft is centered. The pilot may react by steering the aircraft to the right, ultimately leading to a displacement.

Play video

Researchers from Northeastern University in Boston consulted with a pilot and a safety expert and cautiously note that such signal forgery is unlikely to lead to an accident in most cases. Failures in ADS-B operation are a known safety threat, and experienced pilots undergo extensive training on how to respond. In clear weather, a pilot will easily notice if the aircraft is not aligned with the runway centerline, allowing them to go around.

Another reason for reasonable skepticism is the complexity of carrying out such an attack. In addition to a programmable radio station, directed antennas and amplifiers are required. All this equipment would be quite difficult to smuggle onto an aircraft if a hacker aims to conduct an attack from onboard. If they decide to attack from the ground, a lot of work will be needed to align the equipment with the runway without attracting attention. Moreover, airports typically monitor for interference on critical frequencies, which may lead to the attack being halted shortly after it begins.

In 2012, researcher Brad Haynes, known by the callsign Renderman, revealed vulnerabilities in the ADS-B (Automatic Dependent Surveillance-Broadcast) system that aircraft use to determine their location and transmit data to other aircraft. He summarized the challenges of real signal forging as follows:

If everything aligns – the location, hidden equipment, bad weather conditions, a suitable target, a well-motivated, smart attacker with financial means – what will happen? In the worst case, the plane lands on grass, injuries or fatalities may occur; however, the safe design of aircraft and rapid response teams significantly reduce the likelihood of a catastrophic fire resulting in total loss of the aircraft. In such cases, the landing will be aborted, and the attacker will not be able to repeat this action. In the best-case scenario, the pilot will notice the discrepancy, soil their pants, gain altitude, circle around again, and report that something is wrong with the ILS – the airport will begin an investigation, which means the attacker will no longer want to remain nearby.

So, if everything comes together, the outcome will be minimal. Compare this to the ratio of outcomes to investments and the economic effect from the incident when one goat with a drone flew around Heathrow Airport for $1000 over two days. The drone was certainly a more effective and viable option than such an attack.

Yet, researchers say that risks exist. Aircraft that do not land on the glide path – the imaginary line that an aircraft follows for a perfect landing – are much harder to detect even in good weather. Moreover, some busy airports, to avoid delays, instruct aircraft not to rush into a go-around even in poor visibility conditions. Instructions The landing guidelines from the Federal Aviation Administration (FAA) followed by many airports in the US state that such decisions should be made at an altitude of just 15 meters. Similar instructions are in place in Europe. They leave the pilot very little time to safely abort the landing if the visual surrounding conditions do not match the data from the ILS.

"Detection and recovery in case of failure of any instruments during critical landing procedures is one of the most challenging tasks in modern aviation," researchers wrote in their work titled "Wireless Attacks on Aircraft ILS Systems," accepted at the 28th USENIX Security Symposium"Given how much pilots rely on the ILS and tools in general, failures and malicious interference can lead to catastrophic consequences, especially during autonomous approaches and flights."

What Happens with ILS Failures

Several landings that nearly resulted in disaster demonstrate the dangers of ILS failures. In 2011, Singapore Airlines Flight SQ327, with 143 passengers and 15 crew members on board, unexpectedly tilted left while just 10 meters above the runway at Munich Airport in Germany. After landing, the Boeing 777-300 veered to the left, then turned right, crossed the centerline, and stopped with its landing gear in the grass to the right of the runway.

The radio navigation systems used by airplanes for safe landings are unsafe and vulnerable to hacking.

The radio navigation systems used by airplanes for safe landings are unsafe and vulnerable to hacking.

In report on the incident, published by the German Federal Bureau of Aircraft Accident Investigation, states that the aircraft missed the landing point by 500 meters. Investigators noted that one of the contributing factors to the incident was the distortion of the glide slope signals by an ascending aircraft. Although no injuries were reported, this event highlighted the severity of ILS system failures. Among other incidents involving ILS failures that nearly ended tragically are New Zealand Flight NZ 60 in 2000 and Ryanair Flight FR3531 in 2013. A video explains what went wrong in the latter case.

Play video

Vaibhav Sharma heads a safety company based in Silicon Valley, operating globally, and has been flying small aircraft since 2006. He also holds an amateur radio operator license and volunteers in the Civil Air Patrol, where he has been trained as a rescuer and radio operator. He operates an aircraft in the X-Plane simulator, demonstrating an attack with signal spoofing that causes the aircraft to land to the right of the runway.

Sharma told us:

Such an attack on the ILS is realistic, but its effectiveness will depend on a combination of factors, including the attacker's knowledge of air navigation systems and the conditions during approach. If used properly, the attacker could steer the aircraft towards obstacles surrounding the airport, and if this is done in poor visibility conditions, it will be very difficult for the pilots to detect deviations and respond.

He stated that the attacks have the potential to threaten both small planes and large jets, albeit for different reasons. Small aircraft move at slower speeds, giving pilots time to react. Large jets, on the other hand, have more crew members capable of responding to adverse events, and the pilots of such aircraft are typically trained more frequently and thoroughly.

He mentioned that the most important factor for both large and small aircraft will be assessing the surrounding conditions, particularly the weather, during landing.

"Such an attack would likely be more effective when pilots have to rely more on instruments for a successful landing," Sharma said. "This could involve night landings in poor visibility conditions, or a combination of adverse conditions with congested airspace, putting greater demands on pilots and making them heavily dependent on automation."

Aandjan Ranganathan, a researcher from Northeastern University who helped develop the attack, told us that relying on GPS in case of ILS failure is almost out of the question. Deviations from the runway during an effective spoofing attack would range from 10 to 15 meters, as any greater deviation would be noticed by pilots and air traffic controllers. GPS would struggle to detect such deviations. The second reason is that spoofing GPS signals is very easy.

"I can spoof GPS in parallel with spoofing the ILS," Ranganathan said. "The entire question comes down to the level of motivation of the attacker."

Predecessor to the ILS

Tests of the ILS began back in 1929, with the first operational system deployed in 1932 at the Berlin-Tempelhof airport in Germany.

The ILS remains one of the most effective landing systems. Other approaches, for instance, Omnidirectional azimuthal radio beacon, a directional radio beacon, global positioning system, and similar satellite navigation systems are considered inaccurate, as they only provide horizontal or transverse orientation. The KGS is considered an accurate approach system because it provides both horizontal and vertical (glideslope) orientation. In recent years, inaccurate systems have been used less often. The KGS has increasingly been associated with autopilots and automatic landing systems.

The radio navigation systems used by airplanes for safe landings are unsafe and vulnerable to hacking.
How the KGS works: course landing radio beacon [localizer], glideslope [glideslope], and marker beacons [marker beacon]

The KGS has two key components. The course landing radio beacon informs the pilot whether the aircraft is deviating left or right from the centerline of the runway, while the glideslope indicates whether the descent angle is too steep, which could cause the aircraft to miss the beginning of the runway. The third component is the marker beacons, which serve as landmarks to help the pilot gauge the distance to the runway. Over the years, they have increasingly been replaced by GPS and other technologies.

The course landing radio beacon uses two sets of antennas, broadcasting two different frequencies of sound—one at 90 Hz and the other at 150 Hz—assigned to one of the runways. The antenna arrays are positioned on either side of the runway, typically beyond the takeoff point, arranged so that the sounds cancel each other out when the landing aircraft is directly above the centerline of the runway. The deviation indicator shows a vertical line in the center.

If the aircraft deviates to the right, the 150 Hz sound becomes increasingly audible, causing the deviation indicator to move left from the center. If the aircraft deviates to the left, the 90 Hz sound becomes more prominent, and the indicator moves to the right. The course landing radio beacon cannot fully replace visual control of the aircraft's position, but it provides a critical and very intuitive means of orientation. Pilots simply need to keep the indicator centered to ensure the aircraft is precisely over the centerline.

The radio navigation systems used by airplanes for safe landings are unsafe and vulnerable to hacking.

The glide slope operates in a similar way, showing the aircraft's descent angle relative to the beginning of the runway. When the aircraft's angle is too shallow, a sound at 90 Hz becomes audible, and instruments indicate that the aircraft needs to descend. If the descent is too steep, a signal at 150 Hz indicates that the aircraft needs to climb higher. When the aircraft maintains the prescribed glide slope angle of about three degrees, the signals cancel each other out. Two glide slope antennas are located on a tower at a specific height determined by the glide slope angle suitable for a particular airport. The tower is typically positioned near the runway's touchdown zone.

The radio navigation systems used by airplanes for safe landings are unsafe and vulnerable to hacking.

Flawless counterfeit

The attack by researchers from Northeastern University uses commercially available software radio transmitters. These devices, sold for $400-$600, transmit signals that mimic genuine signals sent by the airport’s ILS. The attacker’s transmitter can be either onboard the target aircraft or on the ground, up to 5 km away from the airport. As long as the attacker’s signal is stronger than the real signal, the ILS receiver will perceive the attacking signal and display its orientation relative to the vertical and horizontal flight paths planned by the attacker.

The radio navigation systems used by airplanes for safe landings are unsafe and vulnerable to hacking.

The radio navigation systems used by airplanes for safe landings are unsafe and vulnerable to hacking.

If the spoofing is poorly done, the pilot will witness sudden or erratic changes on the instrument readings, which he will interpret as a malfunction of the ILS. To make the spoofing harder to detect, the attacker can determine the precise location of the aircraft using GNSS, a system that transmits the aircraft's location via GPS, altitude, ground speed, and other data to ground stations and other aircraft every second.

Using this information, the attacker can initiate the signal spoofing when the approaching aircraft shifts left or right relative to the runway and send it a signal indicating that the aircraft is on course. The optimal time for the attack would be when the aircraft has just passed a waypoint, as demonstrated in the video at the beginning of the article.

Then, the attacker can apply a real-time correction and signal generation algorithm that will continuously adjust the malicious signal to ensure that the offset from the correct path corresponds to all movements of the aircraft. Even if the attacker lacks the skills to create a flawless fake signal, they can confuse the ILS enough that the pilot cannot rely on it during landing.

The radio navigation systems used by airplanes for safe landings are unsafe and vulnerable to hacking.

One method of signal spoofing is known as a 'jamming attack.' The attacker sends specially prepared signals with power greater than that of the airport's transmitter. Typically, the attacker would need to send signals at a power of around 20 watts. Jamming attacks make it easier to carry out a convincing signal substitution.

The radio navigation systems used by airplanes for safe landings are unsafe and vulnerable to hacking.
Jamming attack

The second method of signal substitution is known as a 'tone attack.' Its advantage is that it is possible to send a single frequency sound with a lower power than that of the airport's ILS. However, it has several drawbacks, such as the attacker needing to know the specifics of the aircraft—such as the location of its ILS antennas.

The radio navigation systems used by airplanes for safe landings are unsafe and vulnerable to hacking.
Tone attack

Lack of easy solutions

Researchers say there are currently no ways to eliminate the threat of spoofing attacks. Alternative navigation technologies—including omnidirectional azimuthal beacons, radio beacons, global positioning systems, and similar satellite navigation systems—represent wireless signals that lack authentication mechanisms and are therefore susceptible to spoofing attacks. Furthermore, only ILS and GPS can provide information on the horizontal and vertical approach trajectory.

In their work, the researchers write:

Most security issues facing technologies such as GNSS, ACARS and TCAS, can be addressed by implementing cryptography. However, cryptography alone will be insufficient to prevent localization attacks. For example, GPS signal encryption, similar to military navigation technology, can prevent spoofing to a certain extent. Nonetheless, an attacker could still redirect GPS signals with the desired time delays to achieve location or timing spoofing. Inspiration can be drawn from existing literature on preventing GPS spoofing attacks and creating similar systems on the receiver side. An alternative may be to implement a large-scale secure localization system based on distance bounding and secure proximity confirmation techniques. However, this would require bidirectional communication, and this option necessitates further research regarding its scalability, feasibility, and more.

The Federal Aviation Administration (FAA) in the United States has stated that they do not have sufficient information regarding the demonstration conducted by researchers to comment on it.

This attack and the significant amount of research conducted are impressive, but the main question in the paper remains unanswered — how likely is it that someone would actually go through the effort to execute such an attack? Other types of vulnerabilities, for example, that allow hackers to remotely install malware on users' computers or bypass popular encryption systems, are easy to monetize. The GPS spoofing attack is not like that. It also includes life-threatening attacks on pacemakers and other medical devices.

And although it is harder to see the motivation for such attacks, it would be a mistake to dismiss their possibility. In report, published in May by C4ADS, a non-profit organization focused on global conflict and interstate security issues, it noted that the Russian Federation has frequently engaged in large-scale testing of GPS disruption, resulting in navigational systems on ships being mislocated by 65 miles or more [The report actually states that during the opening of the Crimean Bridge (that is, not "often", but just once), a transmitter located on this bridge interfered with the global navigation system, and its effects were felt even near Anapa, which is located 65 km (and not miles) from that location. "But everything else is correct" (c) / note from the translator.].

"The Russian Federation has a relative advantage in using and developing capabilities to deceive global navigation systems," warns the report. "However, the low cost, availability in open sale, and ease of use of such technologies provide not only states but also insurgents, terrorists, and criminals with broad opportunities to destabilize both state and non-state networks."

And although substituting GPS seems esoteric in 2019, it is unlikely to be such a fantastic assumption that in the coming years it will become a more common occurrence as attack technologies become clearer and software-controlled radio transmitters become more widespread. Attacks on GPS do not necessarily need to be conducted to cause accidents. They can be carried out to disrupt airport operations, just like illegal drones led to the closure of Gatwick Airport in London last December, just days before Christmas, and three weeks later, Heathrow Airport.

"Money is one motivation, and demonstrating power is another," said Ranganathan. "From a security perspective, these attacks are quite critical. This needs to be taken care of, as there will be enough people in this world who would want to demonstrate power."

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers đŸ”„ Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster