The Federal Aviation Administration (FAA) lacks “key practices that are necessary to carry out a risk-based cybersecurity oversight program” with regards to avionics, according to the Government Accountability Office (GAO).
“While FAA recognizes avionics cybersecurity as a potential safety issue for modern commercial airplanes, it has not fully implemented key practices that are necessary to carry out a risk-based cybersecurity oversight program” — GAO report
On Friday, the GAO issued its assessment of the FAA’s cybersecurity efforts and found that while airplane and avionics manufacturers “have undertaken extensive measures” to thwart cyberattacks, the FAA is lacking a comprehensive, risk-based avionics cybersecurity oversight program.
Specifically, the GAO found that the FAA has not:
The good news is that “to date, there have been no reports of successful cyberattacks on an airplane’s avionics systems.”
However, without a comprehensive cybersecurity oversight system in place, “the evolving cyber threat landscape, combined with the increasing use of internal networks on airplanes and the increasing connections between airplanes and external sources, could lead to increasing risks for future flight safety.”
The 55-page report gives a full list of vulnerabilities to avionics, and here we have highlighted the main bullet points:
According to the GAO report, bad actors looking to exploit vulnerabilities in flight safety include:
Spoofing is one such area of flight operation disruption in which bad actors could compromise an airplane’s navigational system in ways that “could make the airplane seem to disappear from the skies” or even create “the appearance of nearby ‘ghost’ airplanes, which could cause a pilot to alter an airplane’s course.”
“Someone with authorized access could intentionally or unintentionally misuse flight data, commercial components within avionics systems could contain vulnerabilities that enable cyberattacks, and malevolent hackers could seek to disrupt flight operations with various types of attacks on navigational data” — GAO report
The GAO report summarizes that “critical data used by cockpit systems could be altered, someone with authorized access could intentionally or unintentionally misuse flight data, commercial components within avionics systems could contain vulnerabilities that enable cyberattacks, and malevolent hackers could seek to disrupt flight operations with various types of attacks on navigational data.”
Other vulnerabilities lie in the integrity of supply chains themselves. According to report:
Without adequately assessing the security practices of manufacturers and thoroughly testing electronic components, cybersecurity vulnerabilities can be introduced to avionics systems at multiple points within insecure supply chains. This could potentially result in a range of impacts, from allowing an adversary to take control of a system to decreasing the availability of materials needed to develop a system.
Within commercial airplanes, software and hardware compromised by malware could enable malicious persons to perpetrate exploits after the compromised parts are installed on the airplane. Additionally, supply chain failures could create exploitable defects. Airplanes feature electronic hardware components known as line replaceable units, which could be compromised and adversely affect flight operations. It is also possible that counterfeit line replaceable units containing malware or other security vulnerabilities could be inadvertently installed.
The GAO concluded that while the FAA has taken steps to coordinate cybersecurity issues, the “FAA has not conducted an overall assessment of the cybersecurity risks to avionics systems, and it has not developed policies and procedures for overseeing the implementation of avionics cybersecurity controls based on such an assessment.”
“To date, there have been no reports of successful cyberattacks on an airplane’s avionics systems” — GAO report
In order to strengthen its avionics cybersecurity oversight program, the GAO recommended that the FAA complete the following six steps:
According to the GAO, “FAA concurred with five out of six GAO recommendations, but it did not concur with the recommendation to consider revising its policies and procedures for periodic independent testing.
“The GAO clarified this recommendation to emphasize that FAA safely conduct such testing as part of its ongoing monitoring of airplane safety.”
Jeanna Liu’s love for nature is rooted in her childhood. As a young girl, Liu…
The arrival of generative artificial intelligence (genAI) into the mainstream at the end of 2022…
Data analytics and machine learning models deliver the most powerful results when they have access…
I’ve been on the road for almost a year now. Chasing freedom, adventure, and purpose.…
As technological use increases, so may the cost of innovation due to the global movement…
Have you ever asked yourself why some people are amazing at picking gifts, while others…