An insecure networking standard could allow a hacker with physical access to a small aircraft to trick the plane’s equipment into giving false readings of critical flight data, according to a warning from the Department of Homeland Security. The vulnerability, discovered by cybersecurity company Rapid7, is in the implementation of CAN bus, a popular networking standard that allows communication between microcontrollers in planes, cars and other machinery. A hacker would need physical access to carry out the hypothetical attack, which involves attaching a device to the plane’s CAN bus to insert false data. Engine readings, altitude and airspeed are among the data that could be manipulated, according to Rapid7 researcher Patrick Kiley. Kiley said the aviation sector is lagging in securing CAN bus networks because of an apparent reliance on physical security. Because the assumption is that hackers won’t get physical access to airplanes, “the increased perceived physical security of […]
The post DHS warns of vulnerability that could be used to alter flight data in small planes appeared first on CyberScoop.
Continue reading DHS warns of vulnerability that could be used to alter flight data in small planes→