DEF CON 32 - RF Attacks on Aviation's Defense Against Mid-Air Collisions - G. Longo, V. Lenders

DEF CON 32 - RF Attacks on Aviation's Defense Against Mid-Air Collisions - G. Longo, V. Lenders

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 26:24

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video demonstrates that the Traffic Collision Avoidance System (TCAS) is vulnerable to realistic, executable attacks using off-the-shelf hardware and software, threatening aviation safety. 0:00

Key Takeaways:
• TCAS lacks encryption and relies on time-of-flight calculations, enabling spoofing attacks with sub-100 microsecond latency 2:43-2:55.
• An attacker can trigger a Traffic Advisory (TA) by mimicking aircraft signals with precise timing, placing a fake aircraft directly in front of a real one 19:00-19:40.
• A ground-based attacker can disable TCAS by commanding a reduced sensitivity level, effectively deactivating collision avoidance 12:05-12:20.
• Attacks achieve a 98% success rate, inducing resolution advisories and causing TCAS shutdown due to prolonged proximity 21:26-21:42.
• The attack requires only ~$10,000 in hardware and a skilled developer, with successful lab demonstration using software-defined radio (SDR) 17:40-18:24.

These findings confirm that TCAS remains fundamentally insecure against real-world attacks, with no current standard providing adequate protection. 25:32-25:45

Sources:

  • 0:00 Introduction to TCAS and its role in aviation safety.
  • 2:43-2:55 Explanation of TCAS's lack of encryption and security flaws.
  • 12:05-12:20 Ground-based attack to disable TCAS via sensitivity manipulation.
  • 19:00-19:40 Technical implementation of

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

hello everybody so welcome to our presentation on the radio frequency attacks on the aviation's last line of uh defense against media coalitions it will be a talk on the attacks on the traffic collision avoiding system in aviation the so-called tcas so my name is Vincent lenders I'm a cyber security researcher for more more than 20 years focusing on uh the security of wireless networks and I'm also the director of the Cyber defense campus in Switzerland I'll be giving this talk together with jao I'm jao I'm a thirdd PhD student from Italy the University of Genoa and I work also on radio security avionics and Maritime systems as well so but go on wion so the air traffic control um is a key infrastructure um for safe uh air travel today with more than 30 Millions um flights per year worldwid…