small plane flying

Department of Homeland Security Issues Cybersecurity Warning for Small Planes

Planes using networked communication systems are particularly vulnerable to cyberattacks, according to a flaw discovered by researchers.

The Department of Homeland Security issued a security alert for operators of small planes on Tuesday, advising plane owners that their flight systems are vulnerable to hacking if someone gains unauthorized physical access to their planes.

Plane owners should ensure that they are restricting physical access until the industry develops safeguards to address the problem, the DHS critical infrastructure computer emergency response team said. According to the Associated Press, the issue was originally discovered by Rapid7, a cybersecurity firm based in Boston that reported the bugs to the federal government.

The firm found that an attacker could disrupt and manipulate electronic messages across a small plane’s network by attaching a small device to its wiring. Those messages could include crucial information like engine readings, compass data and altitude.

Aircraft systems, like their automotive counterparts, are becoming more reliant on networked communication systems, the AP reported. Auto companies have already had to address several vulnerabilities exposed in their own systems.

Rapid7’s research focused on small planes because data was easier to acquire and large aircraft typically have more complex systems that must meet additional security regulations, according to the AP. Older small planes with mechanical control systems are also not included in the alert issued by the government.

Lamar Bailey, the senior director of security research at security firm Tripwire, said that organizations often worry about external attacks without realizing the lingering dangers of physical access.

“The ability to directly connect to a system allows the attacker to bypass many of the layers of security in place for remote defense,” Bailey said. “Insider threat is still one of the most dangerous and hardest to defend against.”

The Federal Aviation Administration, which oversees air traffic control operations across the U.S., has also been facing its own set of challenges when it comes to security.

In a Department of Transportation inspector general’s report earlier this year, the FAA was reprimanded for not having a “comprehensive, strategy policy framework to identify and mitigate cybersecurity risks.” The agency responded by vowing to have a plan in place by the end of September, the AP reported.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Integration Imagination: The Future of Connected Operations

    Security teams that collaborate cross-functionally and apply imagination and creativity to envision and design their ideal integrated ecosystem will have the biggest upside to corporate security and operational benefits. Read Now

  • Smarter Access Starts with Flexibility

    Today’s workplaces are undergoing a rapid evolution, driven by hybrid work models, emerging smart technologies, and flexible work schedules. To keep pace with growing workplace demands, buildings are becoming more dynamic – capable of adapting to how people move, work, and interact in real-time. Read Now

  • Trends Keeping an Eye on Business Decisions

    Today, AI continues to transform the way data is used to make important business decisions. AI and the cloud together are redefining how video surveillance systems are being used to simulate human intelligence by combining data analysis, prediction, and process automation with minimal human intervention. Many organizations are upgrading their surveillance systems to reap the benefits of technologies like AI and cloud applications. Read Now

  • The Future is Happening Outside the Cloud

    For years, the cloud has captivated the physical security industry. And for good reason. Remote access, elastic scalability and simplified maintenance reshaped how we think about deploying and managing systems. But as the number of cameras grows and resolutions push from HD to 4K and beyond, the cloud’s limits are becoming unavoidable. Bandwidth bottlenecks. Latency lags. Rising storage costs. These are not abstract concerns. Read Now

  • Right-Wing Activist Charlie Kirk Dies After Utah Valley University Shooting

    Charlie Kirk, a popular conservative activist and founder of Turning Point USA, died Wednesday after being shot during an on-campus event at Utah Valley University in Orem, Utah Read Now

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities