
DEF CON 32 - Analyzing the Security of Satellite Based Air Traffic Control -Martin Strohmeier
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 24:05
Satellite-based air traffic control, while improving airspace efficiency, lacks fundamental security measures like authentication, making it vulnerable to both passive and active attacks 2:53.
Key Takeaways:
• Satellite ADS-B signals can be passively intercepted and used for reconnaissance, enabling tracking of aircraft positions and routes 3:47.
• Active attackers can spoof aircraft positions or flood ground stations with emergency messages, disrupting air traffic control 18:33.
• A full ADC system can be exploited with simple, low-cost hardware—such as software-defined radios—allowing students or enthusiasts to build functional transmitters and inject fake data 22:04.
• The lack of authentication in ADC protocols means any entity within satellite coverage can potentially compromise data integrity or cause denial-of-service 23:15.
Despite its benefits, satellite-based air traffic control remains insecure and poses significant privacy and safety risks without proper security implementation.
Sources:
- 2:53 Overview of satellite-based air traffic control and lack of security.
- 3:47 Passive eavesdropping on ADS-B signals and reconnaissance capabilities.
- 18:33 Active spoofing and message flooding attacks on ADC downlinks.
- 22:04 Demonstration of real-world transmitter setup and injection of fake ADC messages.
- 23:15 Summary of security flaws and ease of exploitation in ADC protocols.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
um thanks and welcome to my talk on uh analyzing the security of satellite based air traffic control my name is Martin Schomer uh I work at the Cyber defense campus with which is uh part of the procurement agency and part of the Swiss Department of Defense so Defcon has and and other conferences has long range of talks about attacks on air traffic control it's obviously an interesting critical infrastructure um if you are able to attack something could have potentially catastrophic consequences this is an an overview of uh typical Technologies Communications protocols that are being used by uh commercial and and aircraft and other aircraft uh in Flight uh and basically since around the early 2010s a lot of practical attacks on pretty much all of these uh communication Technologies in aviat…