Security Management
Published on Security Management (http://www.securitymanagement.com)
Dept. of Transportation: Air Traffic Control Systems Have Been Hacked
By Matthew Harwood
Created 05/08/2009 - 10:12



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
No
Date: 
05/08/2009
By Line: 
By Matthew Harwood
Teaser: 

Hackers have breached air traffic control (ATC) systems multiple times, a report conducted by the Department of Transportation [1]informed the Federal Aviation Administration.

Hackers have breached air traffic control (ATC) systems multiple times, a report conducted by the Department of Transportation [1]informed the Federal Aviation Administration.

Two attacks stand out.

In February, hackers breached an FAA public-facing Web site and gained unauthorized access to the personal information of 48,000 current and former FAA employees. In 2006, a Web-based viral attack infected ATC systems and ultimately led the agency to shutdown a portion of its ATC system in Alaska.

The vulnerabilities, according to the report prepared by Rebecca C. Leng, assistant inspector general for financial and information technology audits at the DOT, stem from the FAA's embrace of commercial software to modernize their operations.

While use of commercial IP [Internet Protocol-based] products, such as Web applications, has enabled FAA to efficiently collect and disseminate information to facilitate ATC services, it inevitably poses a higher security risk to ATC systems than when they were developed primarily with proprietary software.

Now, attackers can take advantage of software vulnerabilities in commercial IP products to exploit ATC systems, which is especially worrisome at a time when the Nation is facing increased threats from sophisticated nation-state-sponsored
cyber attacks.

Leng's report adds that Web applications are not properly secured to prevent attacks or unauthorized access and that the FAA does not have the adequate intrusion-detection capability to monitor and respond to breaches at ATC facilities.

According to PC World:

Penetration testers found 763 high-risk vulnerabilities in 70 Web applications used for functions such as distributing communications frequencies for pilots and controllers to the public and other applications used for internal air traffic control (ATC) systems within the U.S. Federal Aviation Administration (FAA), the report said.

A high-risk vulnerability is classified as one where an attacker could take control over a computer, modifying systems or stealing data. Testers also found 504 medium-risk and 2,590 low-risk vulnerabilities, such as the use of weak passwords and unprotected critical file folders, the report said.

FAA spokeswoman Laura Brown told The Wall Street Journal that the report's fear that hackers could wrest control of critical ATC operational systems [2] through its administrative systems were unfounded.

"It's not possible to use the administrative and mission support network to access the air-traffic control network," she said. "We have specific orders that prohibit them from being directly connected."

The report disagreed.

So far most attacks have primarily disrupted FAA’s ATC mission-support function. However, it is important to understand that attacks can spread from the mission-support network to the operational network—where real-time surveillance, communications, and flight information is processed to separate aircraft—because of network connections ...

The report also criticized the FAA's intrusion detection capabilities, noting that only 11 of 734 operational facilities have intrusion detection sensor systems in place.

The FAA agreed with all of the report's recommendations, including securely configuring its Web applications, patching security vulnerabilities identified in the report, and installing additional intrusion detection sensor systems.

Related Resources: 

"Cyberattacks from China and Russia Target U.S. Electrical Grid [3]," by Matthew Harwood, Daily Headlines, April 8, 2009

"Information Security Must Be a National Priority, Experts Say [4]," by Stephanie Berrong, Daily Headlines, March 13, 2009

"DHS Unfit to Run National Cybersecurity, Experts Say [5]," by Matthew Harwood, Daily Headlines, March 10, 2009

"Cyberattacks Against Government Networks Rise Dramatically in 2008 [6]," by Matthew Harwood, Daily Headlines, Feb. 17, 2009

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 38,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters, 1625 Prince Street, Alexandria, Virginia 22314-2818 U.S.A.
703.519.6200 | fax 703.519.6299 | www.asisonline.org

ASIS

© 2013 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/dept-transportation-air-traffic-control-systems-have-been-hacked-005617

Links:
[1] http://www.oig.dot.gov/StreamFile?file=/data/pdfdocs/ATC_Web_Report.pdf
[2] http://online.wsj.com/article/SB124165272826193727.html
[3] http://www.securitymanagement.com/../../../../../../news/cyberattacks-china-and-russia-target-us-electrical-grid-005468
[4] http://www.securitymanagement.com/../../../../../../news/information-security-must-be-national-priority-experts-say-005346
[5] http://www.securitymanagement.com/../../../../../../news/dhs-unfit-run-national-cybersecurity-experts-say-005318
[6] http://www.securitymanagement.com/../../../../../../news/cyberattacks-against-government-networks-rise-dramatically-2008-005210