Tech

Researchers Demonstrate Physical Cyberattack on Boeing 737 Using Coin-Sized Device

A prototype device costing under $100 can compromise autopilot and flight management systems within 60 seconds, prompting calls for immediate operational changes despite Boeing’s reassurances.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: WIRED · View original source
This Coin-Sized Device Can Hack a Boeing 737
Academic team from UC San Diego and Oberlin College reveals 'Bus Driver' vulnerability in aircraft systems

Academic researchers from the University of California at San Diego and Oberlin College have demonstrated a physical hacking technique capable of compromising a Boeing 737. Utilising a coin-sized, Wi-Fi-enabled device costing less than $100, the team showed they could access an exterior port within 60 seconds to spoof commands to the aircraft's autopilot and flight management systems. The attack, dubbed 'Bus Driver', can alter navigation waypoints and tamper with critical data such as aircraft weight and temperature, potentially causing runway overruns, diversions into foreign airspace, or catastrophic crashes.

The vulnerability involves a port protected by only a hatch without a lock, accessible via an exterior dust cap. Once the device is inserted, it sends electrical signals on the aircraft's internal bus with a higher current than legitimate commands, overriding the system to spoof data to the Flight Management Computer and Multipurpose Control Display Unit. This allows an attacker to redirect the flight plan or manipulate variables like outside air temperature, which are critical for takeoff calculations, while preventing those changes from appearing on the pilot's primary screen.

Boeing states its existing protections mitigate the risk, arguing that layers of protection within the system design and operating environment significantly limit the feasibility of real-world attacks. The manufacturer confirmed it conducted its own review of component designs and installations in response to the findings. However, the researchers argue the findings highlight a significant security blind spot, noting that Boeing has not provided a technical fix for the vulnerabilities discovered and may not implement software updates for years given the long lifecycle of commercial aircraft.

The research, which spanned more than a decade, involved acquiring tens of thousands of dollars worth of plane components to build an avionics test bed. The team alerted Boeing to their findings in spring 2020 and demonstrated the attack in a Boeing facility's test lab. While the researchers note that a careful pilot could potentially recover from such an attack by taking manual control, they warn that conflicting data could cause confusion or lead to delayed recognition of the threat until it is too late.

In their paper, the researchers call for immediate operational changes, such as sealing the port with epoxy or removing it altogether, alongside long-term software updates to include cryptographic authentication. They emphasise that the threat model for aviation security must evolve to account for the practicality of physical access attacks by well-resourced saboteurs, urging the industry to plan for these vulnerabilities rather than dismissing them as theoretical.

Continue reading

More from Tech

Read next: Google Pixel 11 review: A refined but incremental Android upgrade
Read next: ESA shelves Ariane 6 upgrades as cost pressures mount
Read next: RoboStore pivots to domestic robot manufacturing after FCC import ban