DEF CON 32 - An adversarial approach to Airline Revenue Management Proving Ground - Craig Lester

DEF CON 32 - An adversarial approach to Airline Revenue Management Proving Ground - Craig Lester

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 42:38

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

[BLUF with citation]
The video explores how airline revenue management systems and electronic flight bags (EFBs) are vulnerable to exploitation due to poor cybersecurity practices, flawed software design, and inadequate integrity checks—highlighting risks such as incorrect performance calculations, data tampering, and potential flight safety failures 24:00.

Key Takeaways:
• Airline revenue systems face complex pricing and inventory challenges, with dynamic pricing influenced by rules, slots, and market conditions [3:52–4:48].
• EFBs—used by pilots for performance calculations—contain critical vulnerabilities, including data integrity issues that could lead to unsafe takeoffs or landings [32:01–33:03].
• A Boeing performance tool bug allowed runway data to be tampered with, leading to incorrect V-speeds; fixing it took years due to aviation certification requirements [32:01–33:03].
• An Airbus EFB flaw was nearly ignored by engineering teams, who claimed it was a "product improvement," prompting regulator intervention to resolve it [35:50–37:15].
• A Fly Smart Plus app had ATS disabled, enabling man-in-the-middle attacks on updates via Wi-Fi, a risk amplified by pilot habits and fixed layover hotels [38:11–38:41].
• A charting app (eOT Manual) used a predictable integrity key, allowing tampering with approach plates that could result in unsafe descent paths [39:01–40:00].

[Closing statement]
These vulnerabilities demonstrate systemic weaknesses in aviation software and cybersecurity, emphasizing the need for stronger integrity checks, pilot training, and regulatory oversight.

Sources:

  • 3:52 Discusses airline revenue management, pricing rules, and dynamic inventory.
  • 24:00 Introduces EFBs and their role in flight operations.
  • 32:01 Details a

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

good morning ah there we go good morning everyone uh I am Lillian ashbaker I represent the Aerospace Village I do the speaker cfp process the Aerospace Village is in conjunction with the Creator stage team is pleased to introduce Craig he is presenting on an adversarial approach to Airline Revenue management so please welcome Craig to the stage can hold it that we hold it with anything there's no way well hey everyone uh I'm Craig uh a little about me I uh I first moved into state for work about 15 years ago and started flying a lot since then um by trade I'm uh I work with Splunk and seam tools now but my um background was uh Cisco and carrier sort of networking stuff but yeah s so firstly what what's this talk not about so it's I'm not all about uh these big uh clickbait you know sort of…