USENIX Security2026Top-tier venue
Design and Implementation of a Physical Implant Attack on the Boeing 737
Sam Crow, Stephen Checkoway, Patrick Mercier, Pat Pannuto, Stefan Savage, Aaron Schulman
Abstract
We explore a new kind of threat model for aviation cybersecurity—one in which an adversary has temporary physical access to an airframe. We argue why such attacks are practically feasible and explain how the design of existing avionics systems, their interconnects, and their maintenance architecture make such threats of particular concern. Using the Boeing 737 as an example, we develop and demonstrate a small, programmable hardware implant that can be quickly inserted into an existing maintenance socket with roughly 60 seconds of access on the ground. By carefully manipulating physical ARINC 429 bus signals, this device can create an undetected "attacker-in-the-middle" (AITM) capability between the aircraft's flight management computer (FMC) and multipurpose control display unit (MCDU). We explore the options for addressing this class of attack and, in particular, show why transformer-coupled buses such as MIL-STD-1553, are far more challenging to manipulate in this manner.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 290ccdc1-054c-4b9f-b438-d9a49aaf28e1Builds on3
- Error Handling of In-vehicle Networks Makes Them VulnerableKyong-Tak Cho, Kang G. ShinCCS 2016 · 238 citations
- Viden: Attacker Identification on In-Vehicle NetworksKyong-Tak Cho, Kang G. ShinCCS 2017 · 218 citations
- On a Collision Course: Unveiling Wireless Attacks to the Aircraft Traffic Collision Avoidance System (TCAS)Giacomo Longo, Martin Strohmeier, Enrico Russo, Alessio Merlo et al.USENIX Security 2024 · 8 citations
Related papers
- A View from the Cockpit: Exploring Pilot Reactions to Attacks on Avionic SystemsMatthew Smith, Martin Strohmeier, Jon Harman, Vincent Lenders et al.NDSS 2020
- Physical-Layer Attacks Against Pulse Width Modulation-Controlled ActuatorsGökçen Yilmaz Dayanikli, Sourav Sinha, Devaprakash Muniraj, Ryan M. Gerdes et al.USENIX Security 2022
- Trust the Crowd: Wireless Witnessing to Detect Attacks on ADS-B-Based Air-Traffic SurveillanceKai Jansen, Liang Niu, Nian Xue, Ivan Martinovic et al.NDSS 2021
- SoK: Security of Cyber-physical Systems Under Intentional Electromagnetic Interference AttacksQinhong Jiang, Yan Long, Youqian Zhang, Chen Yan et al.USENIX Security 2026
- A Bus Authentication and Anti-Probing Architecture Extending Hardware Trusted Computing Base Off CPU Chips and BeyondZhenyu Xu, Thomas Mauldin, Zheyi Yao, Shuyi Pei et al.ISCA 2020 · 23 citations
