Design and Implementation of a Physical Implant Attack on the Boeing 737
Sam Crow, Stephen Checkoway, Patrick Mercier, Pat Pannuto, Stefan Savage, Aaron Schulman
摘要
We explore a new kind of threat model for aviation cybersecurity—one in which an adversary has temporary physical access to an airframe. We argue why such attacks are practically feasible and explain how the design of existing avionics systems, their interconnects, and their maintenance architecture make such threats of particular concern. Using the Boeing 737 as an example, we develop and demonstrate a small, programmable hardware implant that can be quickly inserted into an existing maintenance socket with roughly 60 seconds of access on the ground. By carefully manipulating physical ARINC 429 bus signals, this device can create an undetected "attacker-in-the-middle" (AITM) capability between the aircraft's flight management computer (FMC) and multipurpose control display unit (MCDU). We explore the options for addressing this class of attack and, in particular, show why transformer-coupled buses such as MIL-STD-1553, are far more challenging to manipulate in this manner.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper3
- Error Handling of In-vehicle Networks Makes Them VulnerableKyong-Tak Cho, Kang G. ShinCCS 2016 · 被引用 238 次
- Viden: Attacker Identification on In-Vehicle NetworksKyong-Tak Cho, Kang G. ShinCCS 2017 · 被引用 218 次
- On a Collision Course: Unveiling Wireless Attacks to the Aircraft Traffic Collision Avoidance System (TCAS)Giacomo Longo, Martin Strohmeier, Enrico Russo, Alessio Merlo 等USENIX Security 2024 · 被引用 8 次
相关 Paper
- A View from the Cockpit: Exploring Pilot Reactions to Attacks on Avionic SystemsMatthew Smith, Martin Strohmeier, Jon Harman, Vincent Lenders 等NDSS 2020
- Physical-Layer Attacks Against Pulse Width Modulation-Controlled ActuatorsGökçen Yilmaz Dayanikli, Sourav Sinha, Devaprakash Muniraj, Ryan M. Gerdes 等USENIX Security 2022
- Trust the Crowd: Wireless Witnessing to Detect Attacks on ADS-B-Based Air-Traffic SurveillanceKai Jansen, Liang Niu, Nian Xue, Ivan Martinovic 等NDSS 2021
- SoK: Security of Cyber-physical Systems Under Intentional Electromagnetic Interference AttacksQinhong Jiang, Yan Long, Youqian Zhang, Chen Yan 等USENIX Security 2026
- A Bus Authentication and Anti-Probing Architecture Extending Hardware Trusted Computing Base Off CPU Chips and BeyondZhenyu Xu, Thomas Mauldin, Zheyi Yao, Shuyi Pei 等ISCA 2020 · 被引用 23 次
