Search This Blog

Showing posts with label vulnerable systems. Show all posts
Showing posts with label vulnerable systems. Show all posts

Wednesday, 13 May 2015

Cybercrime at 10,000 feet and above

As we were updating this article FBI today (29.04.2015) sent a warning to airlines to check for any suspicious activities where passengers are connecting unknown cables or wires to the inflight entertainment, or they have been advised to check inflight system logs frequently for any suspicious behavioural access.
All this action from world top investigative agency stemmed out of an recent event when a security researcher was offloaded a plane on 19th April 2015 from an United Airlines flight because the airlines thought he could probably hack into the aviation systems and disturb its inflight systems including EICAS (Engine-Indicating and Crew Alerting System), he tweeted something like this, “find myself on a 737/800, lets see Box-IFE-ICE-SATCOM,? Shall we start playing with EICAS messages? “PASS OXYGEN ON” Anyone? :) 
FBI had already seen his tweet and by the time his plane landed after he tweeted the above message he was escorted away and was questioned for few hours, now the point is whether or not he tweeting something as sensitive as aircraft information and claiming to hack is dumb/or was totally unnecessary but, it all points back to one key element here, that is anything and everything with an IP address connected to the all-knowing internet is vulnerable for cybercrime attack.
Airplanes are increasingly fitted with state of the art gadgetry so that passengers wouldn’t be deprived of the earthly connectivity options when they are above 10,000 ft and more. Most American airlines today provide Wi-Fi at a nominal cost and passengers have an option and wide array of choice to stream media, or to connect to internet to update their status on social media like Facebook or Twitter in real time. This combination of entertainment on the usual computer networks and an ever growing ambition to make everything connected might have just put the aircrafts flying above the ground susceptible to attacks by organizations which may have completely sinister motives which would also include threats to a national security and safety of passengers. Though the experts say this is theoretically possible might be difficult to achieve technically as of now.
The security experts also warn that there are weak encryption algorithms or insecure protocols in SATCOM technologies manufactured by some of the world’s largest manufacturers of these equipments who supply the same to airlines to be fitted in those aircrafts.
Technically though inflight systems and aircraft navigation is usually separated there usually will be a network communication which could be potentially breached by would be cyber criminals with advance knowledge of avionics systems and most modern aircrafts today have this combination of passenger systems and in aircraft controls on the same network.
In January 2008, Boeing responded to reports about FAA concerns regarding the protection of the 787’s computer networks from possible intentional or unintentional passenger access by stating that various hardware and software solutions are employed to protect the airplane systems. These included air gaps for the physical separation of the networks, and firewalls for their software separation. These measures prevent data transfer from the passenger internet system to the maintenance or navigation systems.
Aircrafts usually have a device called NED or Network Extension Device, though the way this device handles information is unique in nature, there is a slight possibility that in the future cyber criminals might come up with techniques which could probably bypass security boundaries between passenger network and the in aircraft systems.
As an example the geo position that you see on the entertainment screens comes from this devices where inflight systems transmit position frequently to the screens in front but this is usually one way communication and it has been stated that communication back to aircraft systems may be very difficult to achieve though new techniques might emerge.
This recent incident has only shown that new age technology not only affects the way you would do business on the ground but it could also affect the personal safety of people in today’s modern transport systems or endanger national safety if it falls into wrong hands.
Though the recent findings or warnings have been largely based on theoretical possibilities, Airlines and Aircraft manufacturers now have an increased pressure not only to ensure the in flight systems are safe and time tested but also they would need to imbibe state of the art cyber security controls to keep the Pilot/air traffic control systems safe from falling prey to criminals or terrorist groups.

Security – Growing Threats, and vulnerability

March 27, 2013, was a red letter day in the history of cyber security in the civilized world. We saw for the first time, an actual Cyber war. The ammo used jammed the World Wide Web highway almost to a halt. The open hostilities between ‘spam-fighters’ at SpamHaus and the free thinking Dutch Web-hosting company Cyberbunker gave a new meaning to the word ‘security outage.
It was a DDOS(distributed Denial of Service), attack on unprotected Domain Name System (DNS) servers which were flooded with big amounts of useless information, jamming up bandwidth and processing time bringing down almost half of the infrastructure on the London Internet Exchange, and triggering similar shutdowns in many banks worldwide. The losses were not disclosed, but the fact that the Internet is so vulnerable, is scary. Then there are persistent targeted attacks on institutions as well as individuals. They could come in the form of phishing, or spear phishing, hacking, poisoning of websites, malware injection. These are just a handful of different ways of attacking individual or enterprises.
Over USD 60 billion was spent in 2012 to fight security threats, according to Gartner. The spending is slated to grow to USD 86 billion to 2016, and the global security software sales that grew to $20.4 billion in 2012, is expected to grow 7.9% to $24 billion in 2014.
Open security threats to vulnerable systems across industries are stuff IT nightmares are made of. Airline outages involving millions of passengers and hours of flight time, easier to bust ATMs or ability to siphon money by exploiting IT vulnerabilities, to bring down utility infrastructure or hacking into the extensive network of oil and gas pipelines (the Iranian Stuxnet attack), even the tweet war declared on the Whitehouse that effected the stock market globally – the list is endless, it is cyber terrorism.
Today, the digital world has come to a stage where there is no telling where the next attack will come from. Hacking and breach strategies are changing every day, enterprises need to have a constant surveillance on whether they are falling in the high risk category, specially where there is money, data or market standing involved. Banks, financial institutions and other institutions that deal with finances, are the most effected, as are organisations dealing with direct consumer data.
Threats come in many guises – networking, the human connectivity with machine and the worldwide web. Then there is the threat brought in by emerging technologies such as Cloud and enterprise mobility and the most controversial one – about employee freedom to use varied devices for company uses – the Bring Your Own Device (BYOD) arguments.
As we get more connected, more tech dependent for our business needs, as data becomes more and more valuable, so will our security risks increase, our vulnerabilities rise and our threat detection will need to be more streamlined, much, much more effective than it is now.
Thoughts, what is the best way to fight this increasing scare???