Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Boeing Model 777: Aircraft Electronic System Security Protection From Unauthorized Internal Access
www.federalregister.gov ^ | 11/18/2013 | FAA

Posted on 03/11/2014 10:28:03 AM PDT by Red Badger

FULL TITLE:

Special Conditions: Boeing Model 777-200, -300, and -300ER Series Airplanes; Aircraft Electronic System Security Protection From Unauthorized Internal Access

EXCERPT:

Discussion

The integrated network configurations in the Boeing Model 777-200, -300, and -300ER series airplanes may enable increased connectivity with external network sources and will have more interconnected networks and systems, such as passenger entertainment and information services than previous airplane models. This may enable the exploitation of network security vulnerabilities and increased risks potentially resulting in unsafe conditions for the airplanes and occupants. This potential exploitation of security vulnerabilities may result in intentional or unintentional destruction, disruption, degradation, or exploitation of data and systems critical to the safety and maintenance of the airplane. The existing regulations and guidance material did not anticipate these types of system architectures. Furthermore, 14 CFR regulations and current system safety assessment policy and techniques do not address potential security vulnerabilities which could be exploited by unauthorized access to airplane networks and servers. Therefore, these special conditions are being issued to ensure that the security (i.e., confidentiality, integrity, and availability) of airplane systems is not compromised by unauthorized wired or wireless electronic connections between the airplane information services domain, aircraft control domain, and the passenger entertainment services.

For the reasons discussed above, these special conditions contain the additional safety standards that the Administrator considers necessary to establish a level of safety equivalent to that established by the existing airworthiness standards.


TOPICS: Crime/Corruption; Culture/Society; Government; War on Terror
KEYWORDS: aerospace; boeing; iran; malaysia; mh370; waronterror
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-62 next last
To: Red Badger

Indonesia, most likely, from the looks of it.


41 posted on 03/11/2014 11:14:56 AM PDT by tcrlaf (Well, it is what the Sheeple voted for....)
[ Post Reply | Private Reply | To 38 | View Replies]

To: ilovesarah2012

Bill Clinton did along with our universities and hi-tech businesses hiring H1B goons.


42 posted on 03/11/2014 11:19:06 AM PDT by Resolute Conservative
[ Post Reply | Private Reply | To 8 | View Replies]

To: tcrlaf

The world’s most populous Muslim country?..........That would ignite a world war with the entire Muslim world..........oh, wait...........


43 posted on 03/11/2014 11:25:09 AM PDT by Red Badger (LIberal is an oxymoron......................)
[ Post Reply | Private Reply | To 41 | View Replies]

To: Sarah Barracuda

Why? Has that stopped China from killing their own people before?

But I agree with those that say China would simply buy a 777 if they wanted to reverse engineer it. And they probably have sufficient information anyway.


44 posted on 03/11/2014 11:34:53 AM PDT by DannyTN
[ Post Reply | Private Reply | To 23 | View Replies]

To: DannyTN

They can just buy one from Boeing if they want to.


45 posted on 03/11/2014 11:40:19 AM PDT by Georgia Girl 2 (The only purpose o f a pistol is to fight your way back to the rifle you should never have dropped.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Red Badger
Just pondering...We were on a DC 10 for our trip to Mexico. When the pilots got everything settled down and the plane was on auto pilot....the Captain walked down the aisle and spoke to each of us.

Now, since this is likely custom, it would be the best time to hijack a plane by grabbing the pilot with a knife to his throat cuz no one is going to jump the perp at this point.

The thing is somewhere. Any hostages are dead.

Sure is a puzzle...my guess is still a terrorist...with a suitcase.

46 posted on 03/11/2014 11:47:35 AM PDT by Sacajaweau
[ Post Reply | Private Reply | To 1 | View Replies]

To: DannyTN

Smells like a hijacking, but was the pilot and co-pilot in on it, and what did the hijackers do, kill all the passengers, throw them into the ocean, paint the plane a nice new color, fill it up with nukes and use it at a later date?


47 posted on 03/11/2014 11:54:38 AM PDT by Sarah Barracuda
[ Post Reply | Private Reply | To 44 | View Replies]

To: Red Badger

Perhaps not intentionally provided, but its there nonetheless.

There is a gent named Hugo Teso, a commercial pilot, who wondered whether you could treat a commercial heavy aircraft like you would a computer on the internet.

He’s part of a company called n.runs Professionals, and they do security research.

In April 2013 he gave a presentation for the BlackHat conference that not only shows you can do it, he did it, and he details the exact steps for doing it.

These aircraft use the Automatic Dependent Surveillance-Broadcast (ADS-B 101) which is a ‘radar substitute’. It has a data rate of 1Mbit/sec, and its used for locating and plotting large targets.

It can be exploited either for passive surveillance or you can do message jamming, replaying, or injection.

It has no security on it as late as April 2013.

Then there is ACARS 101 - the Aircraft Comms Addressing and Reporting System, which is a digital datalink for transmission of messages between aircraft and ground stations.

Monoalphabetic cyphers are as sophisticated as the security on that system gets. It can be accessed worldwide and you have access to detailed flight and aircraft info.

Then there is the FMS, the Flight Management System. This was the basis for the demo. n.runs bought an FMS off of e-bay. They bought an ACARS for around $10.00 used. They bought an FMS training package that uses actual aircraft codes for $90.

They then used a Software Defined Radio - works like a hardware radio except that the hardware components are implemented by means of software.

The Flight Management System is the link to Inertial Reference, Air Data, Nav Receivers, Engine and Fuel Systems, Surveillance Systems, Flight Controls, Aircraft Displays, the MCDU, and the air to ground data link. It’s bi-directional, meaning you can read from and send to all of those component flight systems.

So, if you understood none of that, the plane is as secure as the WiFi at Starbucks and you can read from and send data to any system connected to the FMS, including the autopilot.

That doesn’t mean this is what happened here, but it does mean that, currently, you average commercial heavy is as secure as a pallet of heroine in Detroit on Devil’s night.

www.48bits.com is where you can investigate Hugo Teso. I sourced this from his powerpoint preso from BlackHat.


48 posted on 03/11/2014 1:34:16 PM PDT by RinaseaofDs
[ Post Reply | Private Reply | To 12 | View Replies]

To: Sarah Barracuda

I agree its probably in Yemen now.


49 posted on 03/11/2014 1:34:41 PM PDT by ully2
[ Post Reply | Private Reply | To 47 | View Replies]

To: Red Badger
Has anyone yet debunked the claim that there were 20 employees of Freescale Semiconductor on board? I found this article from June 2013 Avionics Intelligence to be interesting in that it provides an overview of how Freescale Seminconductor plays a role in development of hardware for aviation electronics, including technologies related to combat and autonomous aviation.

I'm not arguing that the employees had anything to do with the mystery, I'm just curious whether this connection has already been explored (I have my single opening for conspiracy theories plenty occupied at the moment with other things). There is probably nothing to see here given that Freescale Semiconductor apparently has applications in a broad set of markets ,and I know of no one contending that these employees had anything to do specifically with the avionics applications/market.
50 posted on 03/11/2014 1:59:21 PM PDT by ecinkc (Onaka, Fukino, Okubo, Corley, Guthrie, Abercrombie, Nagamine, Romo and Malihi: The Usurper Cabal)
[ Post Reply | Private Reply | To 12 | View Replies]

To: RinaseaofDs

Believe me, I understood ALL of that...............and it’s terrifying............
As you say, it doesn’t mean that’s what happened in this case, but I would not rule it out. Clever, nefarious people with destruction on their minds is all it takes...........And if you and I know it, then it must be knowledge that is openly available to them............sickening............


51 posted on 03/11/2014 2:01:38 PM PDT by Red Badger (LIberal is an oxymoron......................)
[ Post Reply | Private Reply | To 48 | View Replies]

To: ecinkc

Not that I know of. Freescale used to be Motorola Semiconductor..............


52 posted on 03/11/2014 2:02:51 PM PDT by Red Badger (LIberal is an oxymoron......................)
[ Post Reply | Private Reply | To 50 | View Replies]

To: Red Badger
Well, it definitely appears to be official that the employees were on the plane. This is on the website of Freescale: http://media.freescale.com/phoenix.zhtml?c=196520&p=irol-newsArticle&ID=1907348.

I should have taken a minute to look it up before posting.
53 posted on 03/11/2014 2:07:07 PM PDT by ecinkc (Onaka, Fukino, Okubo, Corley, Guthrie, Abercrombie, Nagamine, Romo and Malihi: The Usurper Cabal)
[ Post Reply | Private Reply | To 52 | View Replies]

To: ecinkc; Army Air Corps; cripplecreek; DannyTN; Sarah Barracuda; ilovesarah2012; MrB; Sacajaweau; ...

READ post #48.....It will scare the heck out of you.............


54 posted on 03/11/2014 2:13:30 PM PDT by Red Badger (LIberal is an oxymoron......................)
[ Post Reply | Private Reply | To 50 | View Replies]

To: Red Badger

Jeepers.


55 posted on 03/11/2014 2:29:27 PM PDT by Army Air Corps (Four Fried Chickens and a Coke)
[ Post Reply | Private Reply | To 54 | View Replies]

To: Army Air Corps

SO, with a few clever programmers and a couple of hundred dollars of hardware and software, they can commandeer a jumbo jet and do with it as they may..........


56 posted on 03/11/2014 2:35:07 PM PDT by Red Badger (LIberal is an oxymoron......................)
[ Post Reply | Private Reply | To 55 | View Replies]

To: Red Badger

All this speculation on control of the aircraft is a pipe dream. Professional pilots monitor the heading and course constantly. If there is a deviation of any significance, the pilot can disconnect the autopilot and fly it manually, thus eliminating any outside manipulation of the airplane.


57 posted on 03/11/2014 4:24:42 PM PDT by aviator (Armored Pest Control)
[ Post Reply | Private Reply | To 56 | View Replies]

To: Red Badger

That appears to be the case.


58 posted on 03/11/2014 7:18:39 PM PDT by Army Air Corps (Four Fried Chickens and a Coke)
[ Post Reply | Private Reply | To 56 | View Replies]

To: Red Badger

Sounds like a modern version of Airport ‘77.

Wonder what was in the cargo hold (or carryon...diamonds?)...


59 posted on 03/11/2014 8:33:24 PM PDT by logi_cal869
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

The disquieting aspect of this sort of exploit is that it isn’t ‘special knowledge’. These are system components that are well understood internationally. They have to be, even in the third world.

In a way, it’s like placing a bank’s ATM machine on the ‘honor system’. “We don’t know who you are, but you look like a decent sort, since you have to be smart enough to know how a commercial heavy works and all . . . “

If 9/11 should have done ANYTHING, it should have shaken people to the realization that a plane SHOULD KNOW who is flying it, and who is giving it advice from the ground, and if it doesn’t, it should be smart enough to hold at an altitude. That a pilot lands at the wrong airport in this day and age is ridiculous, for example.

Put the three letter airport code into the FMS and that should address that issue, same as when the bitch in your GPS starts nagging you when you missed your turn 0.3 miles ago.

If we want guns that know who is holding and shooting them, shouldn’t that tech spring from the absolute certitude that we would want to know who is flying and landing a commercial heavy?


60 posted on 03/12/2014 4:20:43 AM PDT by RinaseaofDs
[ Post Reply | Private Reply | To 51 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-62 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson