This Coin-Sized Device Can Hack a Boeing 737

This Coin-Sized Device Can Hack a Boeing 737

这种硬币大小的设备可以入侵波音 737

Even as the digital components of so many life-critical systems have proven susceptible to cybersabotage—cars, medical devices, even water utilities and power grids—the computer systems of airplanes have, thankfully, remained uniquely inaccessible to hackers. But one group of academic researchers has spent years testing a different, devious approach to aviation cybersecurity. Perhaps, they suggest, a plane could be hacked the same way that spies and saboteurs have targeted other high-value, offline computers: by surreptitiously gaining physical access to one and plugging in a device designed to silently run the attackers’ malicious code.

尽管许多关键生命系统的数字组件已被证明容易受到网络破坏(如汽车、医疗设备,甚至是水务设施和电网),但值得庆幸的是,飞机的计算机系统一直以来都未被黑客攻破。然而,一组学术研究人员花费数年时间,测试了一种针对航空网络安全的不同且狡猾的方法。他们认为,飞机或许可以像间谍和破坏者针对其他高价值离线计算机那样被入侵:通过秘密获得物理访问权限,并插入一个旨在静默运行攻击者恶意代码的设备。

Tomorrow at the Usenix Cybersecurity Conference, researchers from the University of California at San Diego and Oberlin College will present a hacking technique capable of commandeering the autopilot of a Boeing 737 to redirect its navigation or silently altering key values in the plane’s takeoff and fuel calculations while spoofing the results on the pilot’s screen—subtle changes the researchers say could potentially cause anything from runway overruns on takeoff to diversions to a different country’s airspace to catastrophic crashes.

明天在 Usenix 网络安全会议上,来自加州大学圣地亚哥分校和欧柏林学院的研究人员将展示一种黑客技术,该技术能够接管波音 737 的自动驾驶仪以重定向导航,或在静默修改飞机起飞和燃油计算关键数值的同时,在飞行员屏幕上伪造结果。研究人员表示,这些细微的改动可能会导致从起飞跑道冲出、偏航至他国领空,甚至引发灾难性坠机等各种后果。

To carry out that hacking, they’ve built a roughly coin-sized, Wi-Fi-enabled prototype device that costs less than $100. In less than a minute, that hardware implant can be fitted into a port accessible via a hatch on the exterior of the plane, one that’s routinely within reach of maintenance workers or other airport and airline staff between flights. Once it’s in place, the device can send electrical signals on one of the 737’s internal networks to spoof commands to sensitive computer systems that guide its autopilot and show the pilot variables like the plane’s total weight and outside air temperature, which play a critical role in a 737’s takeoff calculations.

为了实施这种入侵,他们制造了一个大约硬币大小、支持 Wi-Fi 的原型设备,成本不到 100 美元。在不到一分钟的时间内,这种硬件植入物就可以安装到飞机外部舱门内的一个接口上,该接口在航班间隙通常处于维护人员或其他机场及航空公司员工的可触及范围内。一旦安装到位,该设备就可以在 737 的内部网络上发送电信号,向引导自动驾驶仪的敏感计算机系统发送伪造指令,并向飞行员显示诸如飞机总重量和外部气温等变量,这些变量在 737 的起飞计算中起着至关重要的作用。

By proving the viability of that technique, the result of a process that stretched over more than a decade and entailed buying tens of thousands of dollars’ worth of plane components for testing, they hope to show that this sort of physical access hacking represents a practical threat in the hands of well-resourced saboteurs and a significant blind spot in aircraft security. Compared to the traditional threat of simply planting a bomb on a plane, they argue, it’s also an approach that would offer an attacker more control, stealth, and deniability.

通过证明该技术的可行性——这一过程历时十多年,涉及购买价值数万美元的飞机组件进行测试——他们希望表明,这种物理访问入侵在资源充足的破坏者手中构成了实际威胁,也是航空安全中的一个重大盲点。他们认为,与在飞机上放置炸弹的传统威胁相比,这种方法还能为攻击者提供更多的控制权、隐蔽性和可否认性。

“If you could get 60 seconds with an airplane, what could you do?” asks Stefan Savage, one of the UCSD computer science professors who led the project, describing the question that first motivated their line of research. “Well, it turns out there’s a port that’s externally accessible. You can get to it with no special tools in about 15 seconds. And you can shove in a piece of electronics a little bigger than a quarter that lets you basically tell the autopilot what to do and lie to the pilot about changes to the flight plan.”

“如果你能接触飞机 60 秒,你能做什么?”领导该项目的加州大学圣地亚哥分校计算机科学教授 Stefan Savage 问道,他描述了最初激发他们研究方向的问题。“事实证明,有一个外部可访问的接口。你无需任何特殊工具,大约 15 秒就能接触到它。然后你可以插入一个比 25 美分硬币稍大的电子设备,它基本上能让你指挥自动驾驶仪,并向飞行员谎报飞行计划的变更。”

The researchers aren’t revealing which port they targeted on the 737, nor are they releasing some details of how their hacking device is able to spoof commands to the plane’s computers. They’ve worked closely with Boeing to share their findings, first disclosing elements of their research to the company more than six years ago, and going so far as to test out and demonstrate their attack in a Boeing facility’s test lab.

研究人员没有透露他们针对的是 737 上的哪个接口,也没有公布其黑客设备如何向飞机计算机伪造指令的某些细节。他们与波音公司密切合作分享了研究结果,早在六年前就首次向该公司披露了部分研究内容,甚至还在波音设施的测试实验室中测试并演示了他们的攻击。

When WIRED reached out to Boeing about the researchers’ work, it responded in a statement that it had carried out its own review of its components’ designs, installations, and interfaces in response to the researchers’ findings. But it downplayed the practical risk of their physical-access hacking technique. “Our technical experts are confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks,” the statement reads.

当《连线》(WIRED)就研究人员的工作联系波音公司时,波音在一份声明中回应称,针对研究人员的发现,公司已对组件的设计、安装和接口进行了审查。但波音淡化了这种物理访问入侵技术的实际风险。声明称:“我们的技术专家确信,飞机上现有的多层保护措施,包括系统设计和运行环境内的保护,提供了足够的缓解措施,能够显著限制现实世界攻击的可行性和风险。”

For their part, the researchers say, Boeing hasn’t told them about any technical fix for the vulnerabilities they’ve discovered—and they speculate that the company may not in fact implement any such update to their systems for years to come, given how rarely commercial airplanes are redesigned.

研究人员表示,波音公司并未告知他们针对所发现漏洞的任何技术修复方案——他们推测,考虑到商用飞机的重新设计频率极低,该公司未来几年内可能实际上不会对其系统实施任何此类更新。

That lack of an immediate security update for planes shouldn’t be cause for panic or grounding aircraft, they write in their paper. “All of the authors of this paper routinely travel on Boeing 737 aircraft and expect to continue doing so,” the introduction of the paper reads.

他们在论文中写道,飞机缺乏即时的安全更新不应引起恐慌或导致飞机停飞。“本文的所有作者都经常乘坐波音 737 飞机,并预计未来将继续这样做,”论文引言中写道。

Savage argues, though, that the research has demonstrated the need for long-term changes in both the cybersecurity of airplane components and, perhaps more immediately, the operational security measures that determine who can access a plane while it’s on the ground. Their simplest fix suggestion: Plug the port with epoxy, or remove it altogether.

不过,Savage 认为,这项研究表明,无论是飞机组件的网络安全,还是(或许更紧迫的)决定谁能在地面接触飞机的运营安全措施,都需要进行长期变革。他们最简单的修复建议是:用环氧树脂封堵接口,或者干脆将其彻底移除。

“This is something the aviation industry will want to plan to defend against,” Savage says. “I would not sleep on this one.”

“这是航空业需要计划防御的问题,”Savage 说。“我不会对此掉以轻心。”