Sliding into the Flight Deck's DMs: Practical Message Attacks on CPDLC
Mehdi Ziazi, Khalid Aleem, Harshad Sathaye, Martin Strohmeier
摘要
This paper is currently under embargo, but the paper abstract is available now. The final paper PDF will be available on the first day of the conference. The Controller–Pilot Data Link Communications (CPDLC) system has become integral to modern air traffic management, particularly in high-density or oceanic airspace where voice communication is limited or unavailable. Designed to increase operational efficiency, CPDLC is an alternative to traditional VHF voice communication with standardized digital messages for altitude changes, heading adjustments, free-text messages, and frequency handovers. However, CPDLC does not implement encryption and relies primarily on protocol complexity and obscurity as a barrier to misuse. In this work, we present a full-stack security analysis of CPDLC and showcase several vulnerabilities that allow hijacking ATC-Pilot link with rogue ground station attacks and large-scale denial of service attacks that are capable of disabling CPDLC services for all aircraft in radio range. As a proof-of-concept, we also introduce cpdlc-gs, a first SDR based full-stack CPDLC ground-station implementation capable of injecting uplink messages to issue fake CPDLC flight instructions and effective denial of service attacks. Furthermore, to evaluate cpdlc-gs, together with air navigation service providers and avionics manufacturers, we develop a novel, fully-functional test environment with real, certifiable hardware from Universal Avionics. Through such a setup we conceptualize and validate several attacks and demonstrate that even isolated rogue stations can pose a substantial threat, especially when pilots are under high workload or in degraded communication scenarios. Overall, we argue that the heavy reliance and global adoption of CPDLC make it a high value target, and that the lagging aviation datalink security standard- ization process needs to be urgently addressed
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper4
- Crowd-GPS-Sec: Leveraging Crowdsourcing to Detect and Localize GPS Spoofing AttacksKai Jansen, Matthias Schäfer, Daniel Moser, Vincent Lenders 等S&P 2018 · 被引用 135 次
- Wireless Attacks on Aircraft Instrument Landing SystemsHarshad Sathaye, Domien Schepers, Aanjhan Ranganathan, Guevara NoubirUSENIX Security 2019 · 被引用 30 次
- On a Collision Course: Unveiling Wireless Attacks to the Aircraft Traffic Collision Avoidance System (TCAS)Giacomo Longo, Martin Strohmeier, Enrico Russo, Alessio Merlo 等USENIX Security 2024 · 被引用 8 次
- A View from the Cockpit: Exploring Pilot Reactions to Attacks on Avionic SystemsMatthew Smith, Martin Strohmeier, Jon Harman, Vincent Lenders 等NDSS 2020
相关 Paper
- Trust the Crowd: Wireless Witnessing to Detect Attacks on ADS-B-Based Air-Traffic SurveillanceKai Jansen, Liang Niu, Nian Xue, Ivan Martinovic 等NDSS 2021
- An Experimental Study of GPS Spoofing and Takeover Attacks on UAVsHarshad Sathaye, Martin Strohmeier, Vincent Lenders, Aanjhan RanganathanUSENIX Security 2022
- A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct LinkMilan Stute, Sashank Narain, Alex Mariotto, Alexander Heinrich 等USENIX Security 2019 · 被引用 59 次
- A Formal Security Analysis of CAN XLZhaozhou Tang, Khaled Serag, Z. Berkay Celik, Vijay Ganesh 等USENIX Security 2026
- Design and Implementation of a Physical Implant Attack on the Boeing 737Sam Crow, Stephen Checkoway, Patrick Mercier, Pat Pannuto 等USENIX Security 2026
