Cloud Computing: Navigating Cyber Threats, Uncertainty and Doubt
Share
APEX Insight: Cybersecurity is top of the mind for flyers and aviation experts, and in the complex ecosystem of the connected aircraft, separating fact from hack-fiction is key.
Earlier this year a security researcher with One World Labs made headlines after claiming to be able to hack an in-flight entertainment system and commandeer a United Airlines flight. In the ensuing high-profile FBI investigation, Chris Roberts claimed to have identified security vulnerabilities with Thales and Panasonic IFE systems on Boeing 737-800, 737-900 and Airbus A-320 aircraft, hacking into them with modified cables and his laptop 15-20 times between 2011-2014.
Despite widespread doubt of Roberts’ claims, amply expressed by aviation industry experts, the incident reinforced cybersecurity fears amongst the public and has stirred a debate within security communities. “However misguided it was, at least it brought this subject into the public,” says Andy Beers, director of Aeronautical Sales for the Americas, Cobham SATCOM at the Global Connected Aircraft Summit (GCAS) in Washington, DC. “I’m glad it started a conversation. We’re taking cyber threats very seriously… and are already being proactive in developing systems and practices to address security threats in the future,” he adds.
Yet, as Bob Gourley, publisher for CTOVision.com and Threatbrief.com explains, “In cybersecurity you see FUD – elaborate digital scenarios intended to provoke Fear, Uncertainty and Doubt – too frequently.” Not only is FUD leveraged to exploit connected businesses but the tactic also has the potential to perpetuate misnomers. “Everyone has already perceived threats on the Internet, and as uneducated passengers, we’re imagining things that can happen on an aircraft,” explains Axel Jahn, managing director, VP Business Development Connectivity, Zodiac Aerospace. “We need to educate our passengers and have explanations ready when things like this come to the press,” he adds.
“As security practitioners, you have to be really good risk managers.” – Vinit Duggal, Intelsat
FUD aside, the airline industry does face and needs to address regular cyber threats. Separating fact from fiction is a first step, but as Vinit Duggal, director and chief information security officer, Intelsat, points out: “FUD can also be Fact, Uncertainty and Doubt… As security practitioners, you have to be really good risk managers.” And within the incredibly complex aircraft and broader airline networks – risk management is no small order. “[In aviation] there are really complex systems that you need to deal with,” Jahn explains, adding that securing against threats needs to be approached on both a holistic and system-by-system basis.
Take for instance, the digitization of the flight bag. During the GCAS panel a United 767 pilot shared some of his concerns about the airline’s transition to a paperless, iPad-equipped flight deck. “As I take these Wi-Fi enabled devices into the cockpit and I use them to download a flight bag, am I now going to be at risk for hacks of this type of data?” he asks. Security, in this case is a multi-tiered prong: While the devices can be managed very efficiently by the airline, Duggal says, the integrity of the data is another issue.
“There are so many different aspects of security… and there are many systems in the chain,” Jahn remarks. And because many systems are fundamentally designed to operate separately from other connected parts, such as passenger entertainment, securing the entire environment requires high-level cooperation between all involved vendors. “Visibility is huge,” says Duggal. “How do you bring all of that data together under one view, and who’s the owner of that data?”
The answer, along with the question of what systems should be open or proprietary, remains to be seen; but Gourley, Duggal, Beers and Jahn are optimistic. “We need to work together as an industry, and there are a lot of good things out there,” Beers says, citing the RTCA SC-216 Aeronautical Systems Security committee formed in 2006 and ARINC 71 Attachment A. He adds: “There are things that are already in place today that make hacking quite difficult… and we look forward to helping make sure that these cyberthreats are contained.”
To continue the dialogue on cybersecurity an the connected aircraft, read “Hacking the Sky,” from The Technology Issue or thoughts from the Spring 2015 APEX TECH Conference, here.
