Micron Associates Health and Fitness: Why you shouldn't get used to in-flight entertainment

We might be looking at a future where we can no longer access the web and watch movies on demand -- while on a flight, that is.

In its recent report for the Federal Aviation Administration, the US Government Accountability Office presented the risks of in-flight WiFi and wireless entertainment systems when exploited by a capable attacker. The study highlights the vulnerability of web-based cockpit systems as the industry prepares to transition to the Next Generation Air Transportation System in 10 years.

But Micron Associates Health and Fitness is convinced that even though it's not an easy feat, attackers will now have a more accessible avenue to work on as FAA upgrades aircraft systems and flight tracking with a technology that relies heavily on the Internet.

The report highlights the air industry's capability to detect or prevent illegal access to the massive network that the FAA uses in tracking and processing flights worldwide. The airlines' reliance on firewalls to prevent unauthorized access makes it even more problematic -- firewalls can hardly be considered infallible as any other software can be easily hacked.

"Modern aircrafts are increasingly connected to the Internet. This interconnectedness can potentially provide unauthorized remote access to aircraft avionics systems," it says in the report.

FAA officials are also worried about the IP networks utilized by aircrafts as they can provide a path for outside threats to invisibly get on the system. And because an internet connection could serve as a direct link between the outside world and an aircraft's system, a malware-laden website is all it would take for an attacker to remotely access the system onboard.

The avionics system inside a plane's cockpit is a separate unit and is basically not connected to the system that powers the passengers Internet but as aircrafts upgrade their systems, it would not be unusual for passenger WiFi to have the same physical wirings.

The report also noted the risks of ever-increasing numbers of tablets and smartphones: "The presence of personal smartphones and tablets in the cockpit increases the risk of a system's being compromised by trusted insiders, both malicious and non-malicious, if these devices have the capability to transmit information to aircraft avionics systems."

However, Micron Associates Health and Fitness reported that the FAA is already taking steps to restructure its IT policies through a technical group working on a draft that's expected to be done in 6 months.

Although there has been no record yet of something like this happening in the real world, experts say it is totally plausible. The founder of a cybersecurity intel company who has discovered vulnerabilities in the in-flight entertainment systems said that we can "theorize on how to turn the engines off at 35,000 ft and not have any of those damn flashing lights go off in the cockpit".

In fact, during a conference in 2013, a security professional showed how he can hack into a plane's navigation systems and communicate with air traffic control, all with just the use of a smartphone. He took advantage of a loophole in the Automatic Dependent Surveillance-Broadcast system in order to reach the main flight management program. But since his demo has already been made known to the public, we could only assume that it's been solved.

 
harikaozan:

Im really questioning the wisdom of publishing this report for the whole world to see..i mean, they're practically pointing out the systems' weaknesses!

imo, it could be some sort of honeypot. but then again, they're doing it in the expense of worrying the whole riding public

 

The question is why aircraft systems would need wireless access. It's less reliable, more expensive, and more exploitable than the wired systems that have been used since the first modern aircraft.

There's no reason why Aircraft avionics should be anything other than hardwired.....with the obvious exception of radio systems, which utilize proprietary, coded signals that are only capable of carrying locational data.

 

Ea in nulla similique expedita laboriosam. Voluptatem sint et dolorem cumque aperiam.

Ut nemo eius ab doloribus ullam. Voluptas quasi quia non ut dicta ut. Quos sed quo qui ut est fugiat. Mollitia veritatis dolorem rerum autem. Repudiandae omnis debitis dicta dignissimos consectetur fugiat animi.

Career Advancement Opportunities

April 2024 Investment Banking

  • Jefferies & Company 02 99.4%
  • Goldman Sachs 19 98.8%
  • Harris Williams & Co. New 98.3%
  • Lazard Freres 02 97.7%
  • JPMorgan Chase 03 97.1%

Overall Employee Satisfaction

April 2024 Investment Banking

  • Harris Williams & Co. 18 99.4%
  • JPMorgan Chase 10 98.8%
  • Lazard Freres 05 98.3%
  • Morgan Stanley 07 97.7%
  • William Blair 03 97.1%

Professional Growth Opportunities

April 2024 Investment Banking

  • Lazard Freres 01 99.4%
  • Jefferies & Company 02 98.8%
  • Goldman Sachs 17 98.3%
  • Moelis & Company 07 97.7%
  • JPMorgan Chase 05 97.1%

Total Avg Compensation

April 2024 Investment Banking

  • Director/MD (5) $648
  • Vice President (19) $385
  • Associates (86) $261
  • 3rd+ Year Analyst (13) $181
  • Intern/Summer Associate (33) $170
  • 2nd Year Analyst (66) $168
  • 1st Year Analyst (205) $159
  • Intern/Summer Analyst (145) $101
notes
16 IB Interviews Notes

“... there’s no excuse to not take advantage of the resources out there available to you. Best value for your $ are the...”

Leaderboard

1
redever's picture
redever
99.2
2
Betsy Massar's picture
Betsy Massar
99.0
3
BankonBanking's picture
BankonBanking
99.0
4
Secyh62's picture
Secyh62
99.0
5
CompBanker's picture
CompBanker
98.9
6
dosk17's picture
dosk17
98.9
7
kanon's picture
kanon
98.9
8
GameTheory's picture
GameTheory
98.9
9
numi's picture
numi
98.8
10
bolo up's picture
bolo up
98.8
success
From 10 rejections to 1 dream investment banking internship

“... I believe it was the single biggest reason why I ended up with an offer...”