Device as small as a coin can attack Boeing 737 aircraft

According to Wired, a research team from the University of California San Diego and Oberlin University on August 13 described details of testing using hardware devices to take control of the autopilot system on a Boeing 737 aircraft at the Usenix Security Conference in Baltimore, Maryland, USA.
Through connection to the aircraft maintenance interface, this device allows attackers to manipulate cruise navigation information, silently change calculated values related to fuel or takeoff, and tamper with the results on the pilot's screen. Researchers say these subtle changes can cause a plane to overshoot the runway on takeoff, even enter another country's airspace, or cause a catastrophic accident.
The attack depended on access to the electronics compartment under the nose of the plane. To carry out the attack, the research team built a prototype of a coin-sized device that can connect to Wi-Fi and costs less than 100 USD. In less than a minute, the device can be attached to a gate through a hatch on the outside of the plane, where airport and airline employees often pass between flights. Once installed, the device can transmit electrical signals using the Boeing 737's internal network to send fake commands to the autopilot control computer system and display parameters such as the aircraft's total weight and outside air temperature, which play an important role in takeoff calculations.
The process of proving the feasibility of the hacking technique took more than 10 years and required tens of thousands of dollars to buy aircraft components for testing. Not only revealing blind spots in aviation security, the research team emphasized that compared to the threat of bombing, the new approach gives attackers high control and acts more discreetly.

According to Interesting Engineering, communications are vulnerable to transmission attacks according to the ARINC 429 standard that the aviation industry has used for decades. According to this standard, electronic devices on aircraft send and receive data running in one direction on each pair of wires. They do not have modern cybersecurity protections and lack mechanisms to verify message origin.
The team disclosed the security flaw to Boeing in 2020. They then tested and confirmed their findings in Boeing's labs. The study focused on the Boeing 737, one of the most widely operated commercial aircraft in the United States. Boeing 737 aircraft make up the majority of the fleets of major airlines such as Delta, United and Southwest.
Aaron Schulman, a computer scientist at the University of California San Diego and lead author of the study, emphasized that the test aims to help aviation companies address the threat of bad actors directly accessing hardware devices or servers in an increasingly sophisticated way.