Avionics News September 2014 - 35

Commentary

All in theory
Cybersecurity specialists have made headlines recently
showing, in theory, how avionics can be hacked. A 2013
European security conference presentation focused on
hacking a flight management system and taking over
a flight deck using ACARS (aircraft communications
addressing and reporting system). While it may be
technically possible, it isn't likely, according to some
experts.
"Airlines and GA operators routinely transfer flight
plans via ACARS and other similar methods every single
day without incident," Barber said. "The flight crew on
board the aircraft still has to examine a flight plan before
it is loaded into the FMS and made active for navigation.
This safety measure has been in place since flight plan
transfers first started, and also serves as a security
control."
Still, the risk is real, according to Chris Roberts, founder
and chief technology officer of One World Labs, a
cybersecurity firm based in Denver, Colorado.
"Several years ago, at the request of a client, we
breached a ground-based system that was connected
to a rather large airplane - a 190-ton-empty-weightsize plane," Roberts said. "We broke into the ground
computer with the passcode of '000000' and then
uploaded our own 'crate' to the main avionics and FADEC
system; we knew what and how to do this from simple
research on the Internet.
"We knew how to construct the package, how to
deploy it and a multitude of other factors thanks to
online manuals, patents and other data elements.
The net effect was if the plane had taken off, we could
have instructed the FADEC (full authority digital engine
control) controllers to shut down once the plane reached
a cruising altitude of 35,000 feet, and deploy the flaps.
We could have equally asked it to do many other things
simply by researching. So yes, you need to protect the
systems, protect the environments, and manage and
control those key and critical elements that are designed
to protect the plane both in flight and on the ground."

Balancing security
and technology
By Clay Barber, principal engineer, Garmin

Security as a topic should be taken most
seriously when it can affect safety. Many of
the safety measures that the aviation industry
has been practicing for a long time also help
address cybersecurity since these safety
measures are also effective security measures.
For example, we already maintain configuration
control of aircraft and systems. We already
show that aircraft and systems perform their
intended functions and don't have unintended
functions. Systems already perform validation
of data inputs from other connected devices,
databases and more.
Members of the aviation industry can
and should take common-sense steps to
maintain both safety and security while
striving to provide a good experience for our
customers. The rate of change in consumer
technology will always outpace that of
aviation. This can work to aviation's benefit,
as we can observe the issues created in
the consumer technology space and create
designs that avoid those issues.
Lawmakers and certification authorities
must concentrate on creating fact-based
policy and guidance that is not driven
by sensational anecdotes. Industry and
certification authorities should cooperate to
identify realistic threats and address those
that pose realistic risk to aviation. Policy
and guidance should be sized relative to the
risk. The Federal Aviation Administration
is already moving in this direction with
changes to the Part 23 small aircraft
certification regulations. q

Continued on following page

avionics news

*

september

2014

35



Table of Contents for the Digital Edition of Avionics News September 2014

Point of Communication
AEA Now
The View from Washington
International News and Regulatory Updates
Software Management
Member Profile
Keeping a business in the family
Are digital avionics secure?
A Conversation With...
Meet the AEA board of directors
Before & After
The Autonomous Navigation Systems AET Endorsement
Aviation Aces
Legal Ease
Business Basics
Member Profile
AEA members unveil new ADS-B solutions at AirVenture
What's New
Marketplace Classifieds
Avionics News September 2014 - Intro
Avionics News September 2014 - Cover1
Avionics News September 2014 - Cover2
Avionics News September 2014 - 1
Avionics News September 2014 - 2
Avionics News September 2014 - 3
Avionics News September 2014 - Point of Communication
Avionics News September 2014 - 5
Avionics News September 2014 - AEA Now
Avionics News September 2014 - 7
Avionics News September 2014 - 8
Avionics News September 2014 - 9
Avionics News September 2014 - 10
Avionics News September 2014 - 11
Avionics News September 2014 - 12
Avionics News September 2014 - 13
Avionics News September 2014 - The View from Washington
Avionics News September 2014 - 15
Avionics News September 2014 - International News and Regulatory Updates
Avionics News September 2014 - 17
Avionics News September 2014 - 18
Avionics News September 2014 - 19
Avionics News September 2014 - Software Management
Avionics News September 2014 - 21
Avionics News September 2014 - 22
Avionics News September 2014 - 23
Avionics News September 2014 - Member Profile
Avionics News September 2014 - 25
Avionics News September 2014 - 26
Avionics News September 2014 - 27
Avionics News September 2014 - Keeping a business in the family
Avionics News September 2014 - 29
Avionics News September 2014 - 30
Avionics News September 2014 - 31
Avionics News September 2014 - 32
Avionics News September 2014 - 33
Avionics News September 2014 - Are digital avionics secure?
Avionics News September 2014 - 35
Avionics News September 2014 - 36
Avionics News September 2014 - 37
Avionics News September 2014 - A Conversation With...
Avionics News September 2014 - 39
Avionics News September 2014 - Meet the AEA board of directors
Avionics News September 2014 - 41
Avionics News September 2014 - Before & After
Avionics News September 2014 - 43
Avionics News September 2014 - The Autonomous Navigation Systems AET Endorsement
Avionics News September 2014 - 45
Avionics News September 2014 - 46
Avionics News September 2014 - 47
Avionics News September 2014 - Aviation Aces
Avionics News September 2014 - 49
Avionics News September 2014 - 50
Avionics News September 2014 - 51
Avionics News September 2014 - Legal Ease
Avionics News September 2014 - 53
Avionics News September 2014 - 54
Avionics News September 2014 - 55
Avionics News September 2014 - 56
Avionics News September 2014 - 57
Avionics News September 2014 - Business Basics
Avionics News September 2014 - 59
Avionics News September 2014 - 60
Avionics News September 2014 - 61
Avionics News September 2014 - 62
Avionics News September 2014 - 63
Avionics News September 2014 - Member Profile
Avionics News September 2014 - 65
Avionics News September 2014 - AEA members unveil new ADS-B solutions at AirVenture
Avionics News September 2014 - 67
Avionics News September 2014 - 68
Avionics News September 2014 - 69
Avionics News September 2014 - 70
Avionics News September 2014 - 71
Avionics News September 2014 - What's New
Avionics News September 2014 - 73
Avionics News September 2014 - 74
Avionics News September 2014 - 75
Avionics News September 2014 - 76
Avionics News September 2014 - 77
Avionics News September 2014 - Marketplace Classifieds
Avionics News September 2014 - 79
Avionics News September 2014 - 80
Avionics News September 2014 - Cover3
Avionics News September 2014 - Cover4
http://www.brightcopy.net/allen/avne/56-10
http://www.brightcopy.net/allen/avne/56-9
http://www.brightcopy.net/allen/avne/56-8
http://www.brightcopy.net/allen/avne/56-7
http://www.brightcopy.net/allen/avne/56-6
http://www.brightcopy.net/allen/avne/56-5
http://www.brightcopy.net/allen/avne/56-4
http://www.brightcopy.net/allen/avne/56-3
http://www.brightcopy.net/allen/avne/56-2
http://www.brightcopy.net/allen/avne/56-1
http://www.brightcopy.net/allen/avne/55-12
http://www.brightcopy.net/allen/avne/55-11
http://www.brightcopy.net/allen/avne/55-10
http://www.brightcopy.net/allen/avne/55-9
http://www.brightcopy.net/allen/avne/55-8
http://www.brightcopy.net/allen/avne/55-7
http://www.brightcopy.net/allen/avne/55-6
http://www.brightcopy.net/allen/avne/55-5
http://www.brightcopy.net/allen/avne/55-4
http://www.brightcopy.net/allen/avne/55-3
http://www.brightcopy.net/allen/avne/55-02
http://www.brightcopy.net/allen/avne/55-01
http://www.brightcopy.net/allen/avne/54-12
http://www.brightcopy.net/allen/avne/54-11
http://www.brightcopy.net/allen/avne/54-10
http://www.brightcopy.net/allen/avne/54-9
http://www.brightcopy.net/allen/avne/54-8
http://www.brightcopy.net/allen/avne/54-7
http://www.brightcopy.net/allen/avne/54-6
http://www.brightcopy.net/allen/avne/54-5
http://www.brightcopy.net/allen/avne/54-4
http://www.brightcopy.net/allen/avne/54-3
http://www.brightcopy.net/allen/avne/54-2
http://www.brightcopy.net/allen/avne/54-1
http://www.brightcopy.net/allen/avne/53-12
http://www.brightcopy.net/allen/avne/53-11
http://www.brightcopy.net/allen/avne/53-10
http://www.brightcopy.net/allen/avne/53-9
http://www.brightcopy.net/allen/avne/53-8
http://www.brightcopy.net/allen/avne/53-7
http://www.brightcopy.net/allen/avne/53-6
http://www.brightcopy.net/allen/avne/53-5
http://www.brightcopy.net/allen/avne/53-4
http://www.brightcopy.net/allen/avne/53-3
http://www.brightcopy.net/allen/avne/53-2
http://www.brightcopy.net/allen/avne/53-1
http://www.brightcopy.net/allen/avne/52-12
http://www.brightcopy.net/allen/avne/52-11
http://www.brightcopy.net/allen/avne/52-10
http://www.brightcopy.net/allen/avne/52-9
http://www.brightcopy.net/allen/avne/52-8
http://www.nxtbook.com/allen/avne/52-7
http://www.nxtbook.com/allen/avne/52-6
http://www.nxtbook.com/allen/avne/52-5
http://www.nxtbook.com/allen/avne/52-4
http://www.nxtbook.com/allen/avne/52-3
http://www.nxtbook.com/allen/avne/52-2
http://www.nxtbook.com/allen/avne/52-1
http://www.nxtbook.com/allen/avne/51-12
http://www.nxtbook.com/allen/avne/51-11
http://www.nxtbook.com/allen/avne/51-10
http://www.nxtbook.com/allen/avne/51-9
http://www.nxtbook.com/allen/avne/51-8
http://www.nxtbook.com/allen/avne/51-7
http://www.nxtbook.com/allen/avne/51-6
http://www.nxtbook.com/allen/avne/51-5
http://www.nxtbook.com/allen/avne/51-4
http://www.nxtbook.com/allen/avne/51-3
http://www.nxtbook.com/allen/avne/51-2
http://www.nxtbook.com/allen/avne/51-1
http://www.nxtbook.com/allen/avne/50-12
http://www.nxtbook.com/allen/avne/50-11
http://www.nxtbook.com/allen/avne/50-10
http://www.nxtbook.com/allen/avne/50-9
http://www.nxtbook.com/allen/avne/50-8
http://www.nxtbook.com/allen/avne/50-7
http://www.nxtbook.com/allen/avne/50-6
http://www.nxtbook.com/allen/avne/50-5
http://www.nxtbook.com/allen/avne/50-4
http://www.nxtbook.com/allen/avne/50-3
http://www.nxtbook.com/allen/avne/50-2
http://www.nxtbook.com/allen/avne/50-1
http://www.nxtbook.com/allen/avne/49-12
http://www.nxtbook.com/allen/avne/49-11
http://www.nxtbook.com/allen/avne/49-10
http://www.nxtbook.com/allen/avne/49-9
http://www.nxtbook.com/allen/avne/49-8
http://www.nxtbook.com/allen/avne/49-7
http://www.nxtbook.com/allen/avne/49-6
http://www.nxtbook.com/allen/avne/49-5
http://www.nxtbook.com/allen/avne/49-4
http://www.nxtbook.com/allen/avne/49-3
http://www.nxtbook.com/allen/avne/49-2
http://www.nxtbook.com/allen/avne/49-1
http://www.nxtbook.com/allen/avne/48-12
http://www.nxtbook.com/allen/avne/48-11
http://www.nxtbookMEDIA.com