USENIX Security2019Top-tier venue
Wireless Attacks on Aircraft Instrument Landing Systems
Harshad Sathaye, Domien Schepers, Aanjhan Ranganathan, Guevara Noubir
Abstract
Modern aircraft heavily rely on several wireless technologies for communications, control, and navigation. Researchers demonstrated vulnerabilities in many aviation systems. However, the resilience of the aircraft landing systems to adversarial wireless attacks have not yet been studied in the open literature, despite their criticality and the increasing availability of low-cost software-defined radio (SDR) platforms. In this paper, we investigate the vulnerability of aircraft instrument landing systems (ILS) to wireless attacks. We show the feasibility of spoofing ILS radio signals using commerciallyavailable SDR, causing last-minute go around decisions, and even missing the landing zone in low-visibility scenarios. We demonstrate on aviation-grade ILS receivers that it is possible to fully and in fine-grain control the course deviation indicator as displayed by the ILS receiver, in real-time. We analyze the potential of both an overshadowing attack and a lower-power single-tone attack. In order to evaluate the complete attack, we develop a tightly-controlled closed-loop ILS spoofer that adjusts the adversary's transmitted signals as a function of the aircraft GPS location, maintaining power and deviation consistent with the adversary's target position, causing an undetected off-runway landing. We systematically evaluate the performance of the attack against an FAA certified flight-simulator (X-Plane)'s AI-based autoland feature and demonstrate systematic success rate with offset touchdowns of 18 meters to over 50 meters.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d3ad68e1-e0ad-4ab8-a502-2145cadb8c81Cited by top-tier papers2
- Sliding into the Flight Deck's DMs: Practical Message Attacks on CPDLCMehdi Ziazi, Khalid Aleem, Harshad Sathaye, Martin StrohmeierUSENIX Security 2026
- Trust the Crowd: Wireless Witnessing to Detect Attacks on ADS-B-Based Air-Traffic SurveillanceKai Jansen, Liang Niu, Nian Xue, Ivan Martinovic et al.NDSS 2021
Builds on3
- All Your GPS Are Belong To Us: Towards Stealthy Manipulation of Road Navigation SystemsKexiong Curtis Zeng, Shinan Liu, Yuanchao Shu, Dong Wang et al.USENIX Security 2018 · 174 citations
- Crowd-GPS-Sec: Leveraging Crowdsourcing to Detect and Localize GPS Spoofing AttacksKai Jansen, Matthias Schäfer, Daniel Moser, Vincent Lenders et al.S&P 2018 · 135 citations
- Security of GPS/INS Based On-road Location Tracking SystemsSashank Narain, Aanjhan Ranganathan, Guevara NoubirS&P 2019 · 81 citations
Related papers
- A View from the Cockpit: Exploring Pilot Reactions to Attacks on Avionic SystemsMatthew Smith, Martin Strohmeier, Jon Harman, Vincent Lenders et al.NDSS 2020
- On a Collision Course: Unveiling Wireless Attacks to the Aircraft Traffic Collision Avoidance System (TCAS)Giacomo Longo, Martin Strohmeier, Enrico Russo, Alessio Merlo et al.USENIX Security 2024 · 8 citations
- Wireless Signal Injection Attacks on VSAT Satellite ModemsRobin Bisping, Johannes Willbold, Martin Strohmeier, Vincent LendersUSENIX Security 2024 · 11 citations
- SemperFi: Anti-spoofing GPS Receiver for UAVsHarshad Sathaye, Gerald LaMountain, Pau Closas, Aanjhan RanganathanNDSS 2022
- SDR receiver using commodity wifi via physical-layer signal reconstructionWoojae Jeong, Jinhwan Jung, Yuanda Wang, Shuai Wang et al.MobiCom 2020 · 27 citations
