Boeing 737's Maintenance Port Vulnerable to Minute-Long Hack
A recent study by security researchers has revealed that a Boeing 737's flight-management systems can be compromised in under a minute using a small hardware implant connected to an exposed maintenance port. The researchers, from the University of California, San Diego and Oberlin College, found that a brief physical access window to an externally reachable maintenance connector could allow the device to interfere with communications between the flight-management computer and a cockpit display unit.
The team built and tested a small hardware implant on a testbed made from genuine Boeing 737 components. They discovered that an attacker could open the hatch, insert the device, and close it again within roughly 60 seconds. The researchers stressed that this access window is short enough to be within the reach of ground personnel.
The attack, which they called 'Bus Driver,' targets the aircraft's ARINC 429 data buses. In their testbed, the implant was able to mediate communications between the flight-management computer and the multipurpose control and display unit. This allowed the researchers to manipulate flight-plan loading and execution as well as weight-and-balance data used to calculate take-off parameters.
Boeing has acknowledged the findings and stated that existing protections provide sufficient mitigation to limit the risk of real-world attacks. However, the researchers suggest restricting access to the connector as one possible mitigation, including sealing or removing it. The paper also found that alternative aircraft bus designs using transformer coupling are more resistant to the demonstrated attack technique.