Feeds

US air traffic faces 'serious harm' from cyber attackers

When. Not if

Protecting against web application threats using SSL

The United States' air traffic control system is vulnerable to serious cyber attack, according to a watchdog report that detailed several recent security breaches that could have been used to sabotage mission-critical networks.

One of the most serious attacks came last August, when hackers took control of Federal Aviation Administration computers in Alaska. By exploiting the administration's interconnected networks, the miscreants then stole an administrator's password and finally took control of a domain controller in the Western Pacific region. That gave them access to more than 40,000 login credentials used to control part of the FAA's mission-support network.

Two separate attacks in 2006 hit the FAA's remote maintenance monitoring system and its air traffic control systems. The latter forced the FAA to shut down a portion of ATC systems in Alaska.

"These web vulnerabilities occurred because (1) web applications were not adequately configured to prevent unauthorized access and (2) web application software with known vulnerabilities was not corrected in a timely manner by installing readily available security software patches released to the public by software vendors," the report, which was prepared by Assistant Inspector General Rebecca Leng, concluded.

In addition to reviewing recent security breaches, the report also analyzed 70 web applications that support ATC systems and conducted penetration tests into them. The results weren't encouraging.

Auditors identified 763 vulnerabilities rated "high-risk," meaning they could provide attackers with "immediate access into a computer systems, such as allowing execution of remote commands." They also found weak passwords and unprotected critical file folders.

The report went on to fault the FAA for employing woefully inadequate IDS, or intrusion detection systems. While ATC computers are located at hundreds of airport control towers, radar controls and other locations, IDS sensors are installed in only 11 ATC facilities, the report said. What's more, none of the IDS sensors monitor mission critical ATC operation systems.

"In our opinion, unless effective action is taken quickly, it is likely to be a matter of when, not if, ATC systems encounter attacks that do serious harm to ATC operations," the report warned (its emphasis).

The report offers five recommendations for the FAA's acting chief information officer, including ensuring all web apps are configured in compliance with governmental security standards and taking immediate action to correct high-risk vulnerabilities.

In a separate portion of the report, FAA managers said they "will treat vulnerabilities in this report with the utmost diligence." A PDF version of the report is available here. ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Critical Adobe Reader and Acrobat patches FINALLY make it out
Eight vulns healed, including XSS and DoS paths
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.