Oh Really? DoT IG Thinks ATC Vulnerable To Hackers | Aero-News Network
Aero-News Network
RSS icon RSS feed
podcast icon MP3 podcast
Subscribe Aero-News e-mail Newsletter Subscribe

Airborne Unlimited -- Most Recent Daily Episodes

Episode Date

Airborne-Monday

Airborne-Tuesday

Airborne-Wednesday Airborne-Thursday

Airborne-Friday

Airborne On YouTube

Airborne-Unlimited-04.29.24

Airborne-Unlimited-04.23.24

Airborne-Unlimited-04.24.24 Airborne-FltTraining-04.25.24

Airborne-Unlimited-04.26.24

Thu, May 07, 2009

Oh Really? DoT IG Thinks ATC Vulnerable To Hackers

OK, In This Day And Age... Who Isn't?

A report (FI-2009-049) from the Department of Transportation's office of the Inspector General is raising the alarm over the potential vulnerabilities of the nations air traffic system to damage and interference by hackers.

The IG's Office claims that, "we issued our report on Federal Aviation Administration (FAA) web applications security and intrusion detection in air traffic control (ATC) systems, requested by the Ranking Minority Members of the full House Transportation and Infrastructure Committee and its Aviation Subcommittee. The objectives of this performance audit were to determine whether (1) web applications used in supporting ATC operations were properly secured to prevent unauthorized access to ATC systems, and (2) FAA’s network intrusion–detection capability was effective in monitoring ATC cyber–security incidents."

The IG adds that, "We found that web applications used in supporting ATC systems operations were not properly secured to prevent attacks or unauthorized access. During the audit, our staff gained unauthorized access to information stored on web application computers and an ATC system, and confirmed system vulnerability to malicious code attacks. In addition, FAA had not established adequate intrusion–detection capability to monitor and detect potential cyber security incidents at ATC facilities. The intrusion–detection system has been deployed to only 11 (out of hundreds of) ATC facilities. Also, cyber incidents detected were not remediated in a timely manner."

The report explains a bit more about their concerns by stating that 'The need to protect ATC systems from cyber attacks requires enhanced attention because the Federal Aviation Administration (FAA) has increasingly turned toward the use of commercial software and Internet Protocol (IP)1-based technologies to modernize ATC systems. While use of commercial IP products, such as Web applications,2 has enabled FAA to efficiently collect and disseminate information to facilitate ATC services, it inevitably poses a higher security risk to ATC systems than when they were developed primarily with proprietary software. Now, attackers can take advantage of software vulnerabilities in commercial IP products to exploit ATC systems, which is especially worrisome at a time when the Nation is facing increased threats from sophisticated nation-state-sponsored cyber attacks.'

FMI: www.oig.dot.gov/StreamFile?file=/data/pdfdocs/ATC_Web_Report.pdf

Advertisement

More News

ANN's Daily Aero-Term (04.26.24): DETRESFA (Distress Phrase)

DETRESFA (Distress Phrase) The code word used to designate an emergency phase wherein there is reasonable certainty that an aircraft and its occupants are threatened by grave and i>[...]

Aero-News: Quote of the Day (04.26.24)

"General aviation is at the forefront of developing and introducing innovative technologies that will transform the entire aviation industry..." Source: Kyle Martin, Vice President>[...]

ANN's Daily Aero-Term (04.27.24): Direct

Direct Straight line flight between two navigational aids, fixes, points, or any combination thereof. When used by pilots in describing off-airway routes, points defining direct ro>[...]

ANN's Daily Aero-Linx (04.27.24)

Aero Linx: Women in Corporate Aviation Women in Corporate Aviation support individuals seeking career advancement and professional development in the business aviation industry. Me>[...]

Aero-News: Quote of the Day (04.27.24)

“We would like to thank the many volunteers that help throughout the year to pull off the event, as well as the several reviewers, judges, and SURVICE staff that provide team>[...]

blog comments powered by Disqus



Advertisement

Advertisement

Podcasts

Advertisement

© 2007 - 2024 Web Development & Design by Pauli Systems, LC