硬币大小的设备可入侵波音737飞机
Coin-sized device can hack a Boeing 737

原始链接: https://www.wired.com/story/this-coin-sized-device-can-hack-a-boeing-737/

研究人员在波音 737 的航空电子系统中发现了一个关键漏洞,证明了具备物理接触权限的攻击者可以利用维护端口篡改飞行数据。通过注入错误信息(例如不准确的温度或重量数值,或进行细微的导航调整),攻击者可能危及飞行安全,导致飞行员困惑或使飞机偏离航线。 尽管经验丰富的飞行员理论上可以通过切换至手动控制来化解风险,但研究人员警告称,这些隐蔽的攻击手段极易在紧急情况下导致飞行员误判或反应迟缓。安全专家强调,这种威胁发生的可能性很高,因为攻击者可以在日常维护期间安装微型硬件设备。 研究团队提出了多种缓解措施,包括使用环氧树脂物理加固易受攻击的端口、实施更好的电气隔离,以及为系统通信增加加密认证。这一发现为航空业敲响了警钟,凸显了更新 20 世纪安全模型以防御现代复杂网络物理威胁的紧迫性。专家们一致认为,随着技术的进步,航空业必须改进其安全标准,以确保关键系统能够抵御高水平对手的攻击。

这篇 Hacker News 讨论聚焦于《连线》杂志的一篇报道,该报道详细介绍了一种硬币大小的设备,它能通过外部维护端口入侵波音 737 客机。 评论者们大多淡化了标题的“恐慌因素”,将其与汽车使用的 OBDII 扫描仪相提并论。共识是物理接触才是主要障碍;一旦有人能够物理接触到飞机的敏感内部系统,传统的安全性便“毫无意义”了。许多用户指出,授权的维护人员本就拥有对航空电子设备和线路的完全访问权限,因此该设备与其说是一个新的威胁,不如说是一种对现有物理脆弱性的演示。 讨论帖还强调了对机场安全的更广泛担忧,例如围栏防线不够严密以及内部威胁的风险。尽管波音公司坚称现有的设计层和运行环境能降低这些风险,但怀疑论者认为这只是业内“我们不认为黑客能搞定它”的托辞。参与者还讨论了分享付费内容的相关伦理,并呼吁在平台上采取更好的存档做法。
相关文章

原文

Trick the pilot into thinking the outside air was colder—or the plane's load of passengers and cargo was lighter—than in reality, and the 737 might not achieve the necessary speed for takeoff before running out of runway. Mess with the flight plan, and you could cause the autopilot to change the plane's heading to make it enter another country's airspace, where it could be commandeered by that country's air force. A sudden navigation change could potentially crash a plane into a mountain, or a slow one could send a transoceanic flight in the wrong direction until it ran out of fuel over water. “It could be something as subtle as, you're in the Pacific, you see blue everywhere, and this diverts you 3 degrees off course, and now you're in the middle of nowhere,” Schulman says.

The researchers note that a careful pilot would be able to recover from almost any of the attacks they've imagined: Taking manual control of the plane overrides its autopilot, and even if the Multipurpose Control Display Unit were hacked, the correct values would show up on a different screen in the cockpit. But even in this scenario, Schulman says, the pilot “would see that this is not lining up, but they would have no idea why, and it would be very confusing and probably lead them toward an uncertain conclusion about what to do next.” In a less optimistic scenario—or if the hacker implements a more subtle change—Schulman says a pilot might not notice until it was too late.

In their paper, the researchers outline a range of fixes for the vulnerability they've uncovered, starting with removing the connector in the vulnerable port altogether, or plugging it with epoxy. More long-term, though, they suggest planes' systems could be updated to include defenses in their software that detect their Bus Driver hacking technique, or that better electrically isolate systems, as in some military aircraft, or even add cryptographic authentication to prevent spoofing of signals among the plane's systems.

Calling for these kinds of updates—not just for Boeing, but across the aviation industry—is far from alarmist given the practicality of the attack the researchers describe, says Beau Woods, a cybersecurity consultant who has served as an adviser to the Cybersecurity and Infrastructure Security Agency and as a member of Boeing's Industry Cyber Technical Council. “It is entirely possible to have someone who is on staff go up to an airplane when it's on the ground, going through maintenance, and put this type of thing in there,” says Woods, who read the researchers' work ahead of publication. The paper, he says, “looks like solid empirical evidence about some realistic scenarios for high-capability adversaries.”

The researchers' technique, he says, shows how the “threat model” for any highly sensitive system has to change as potential attackers' technology advances—in this case, as it became possible to fit an entire hardware setup capable of connecting to a plane's Wi-Fi and relaying commands to its systems onto a tiny disc hidden inside the dust cap of an obscure plug.

“Now that the research has been published, it can be understood and recognized that the reality has changed,” Woods says. “Threat models from the 20th century rarely survive contact with 21st-century tools and techniques.”

Update: 8/12/2026, 11:20 am EDT: A misspelling of Sam Crow's name has been corrected.

联系我们 contact @ memedata.com