Delta Incident Puts Aviation Cybersecurity into Sharp Focus

A Delta Airlines Airbus A330-323E. Photo: Wikimedia.
A Delta Airlines Airbus A330-323E. Photo: Wikimedia.

In-flight connectivity (IFC) has a been a huge topic in satellite circles for well over a decade now, as airlines roll out these services improving both passenger experience and operations. However, increased connectivity also lends itself to a larger attack surface.

Aviation cybersecurity came into sharp focus with the incident earlier this month on Delta flight 591 from Las Vegas to Atlanta where an unauthorized Wi-Fi network appeared for a short time. This incident gained coverage across the cyber world over the last two weeks.

This kind of ‘evil twin’ attack could be an airline’s worst nightmare. Even though the incident was relatively short-lived, it bought the topic of airline cybersecurity back into the mainstream. Given most airlines are using satellite to provide connectivity, it has sparked an interesting debate.

Delta said in a statement that the safety of flight was never in question and no aircraft operating systems were affected. It added, “We are fully investigating to gather a complete set of facts, which will take time. We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated.”

Delta said there was no hack of any Delta system including the in-flight Wi-Fi. The airline’s initial finding was one unauthorized Wi-Fi network, which was not provided, operated, or supplied by Delta. The cabin crew deactivated the aircraft’s Wi-Fi functionality for approximately 30 minutes. The flight had 199 customers and six crew members.

Eliran Almog, CEO, Cyviation, an Israeli aviation cybersecurity company, told S3 that this incident was a clear example of a cyber threat the aviation industry has known about for some time: a rogue, or so-called ‘evil twin’ Wi-Fi network that impersonates a legitimate network and tries to convince passengers to connect.

Almog said Cyviation has been warning about this type of attack for years. The company recently published an article examining practical aviation cyberattack frameworks. Interestingly, this article describes this attack scenario: how a relatively small, accessible device can impersonate an aircraft’s legitimate Wi-Fi network and potentially convince passengers to connect to an attacker-controlled network.

In terms of this specific attack, the context was particularly interesting.

“Many of the passengers on that flight were returning from DEFCON, one of the largest hacking conferences in the world, which had just wrapped in Las Vegas. It illustrates the point better than anything I could argue in the abstract — the knowledge and tools required to pull off an attack like this are now common enough to be sitting on a commercial flight home from a conference, not locked away in a nation-state’s toolkit. What matters about Delta Flight 591 is that something the cybersecurity community has discussed for years suddenly became visible to the aviation industry and the traveling public,” Almog said.

While there was no suggestion that the safety of the flight was compromised, Almog believes this incident should be a wake-up call for the aviation industry.

“An unknown Wi-Fi network appearing inside an aircraft should not be treated as an IT inconvenience. It is an unauthorized digital asset operating inside a highly controlled environment. The positive aspect of the Delta incident is that the crew identified that something was wrong and responded. But our objective as an industry should be to provide airlines and crews with the technology and procedures to detect these situations systematically rather than depending on somebody noticing a suspicious SSID,” he said.

Almog says having better understanding here of these types of attacks is an industry-wide challenge. Almog said that any airline offering wireless connectivity potentially faces this problem because radio signals do not respect the logical security boundaries we create inside an aircraft. What matters now is how the industry responds.

“Aviation safety has become extraordinarily successful because we investigate incidents, share lessons, and build additional layers of protection. Cybersecurity needs to develop the same culture.

Delta Flight 591 should become a case study, not simply a headline,” he added.

What Happens Next

In terms of what lessons can be learned here, Almog said airlines should make the identity of their legitimate onboard networks extremely clear to passengers and crews.

Second, Almog believes airlines should examine the ability to detect rogue wireless networks operating onboard. Wireless intrusion detection and monitoring technologies already exist in other industries. The aviation industry needs solutions adapted to the unique aircraft environment.

Thirdly, he said crews need procedures. Detecting an unexpected wireless network should trigger a defined response and reporting process, not improvisation. After this, Almog said airlines need to understand their complete aircraft digital environment: the IFC system, passenger networks, connected devices, electronic flight bags, maintenance interfaces, and the boundaries between those systems. After doing all this, Almog believes this information needs to become part of the airline’s cybersecurity risk-management process.

Bob Gourley, CEO of OODA and a member of the CyberSat advisory board blasted the people behind the attack.

“This type of attack against Wi-Fi does not require any special skill. This was not hacking in any sense. All it takes to do this is a desire to cause trouble for others, either for kicks or an attempt at financial gain. No commercial Wi-Fi is immune from this type of attack. The result of their childish behavior is that an entire flight of people had their Wi-Fi access disrupted, and so many of us have grown accustomed to using it for entertainment or work while we are in the air. Some may have put sensitive info into a system controlled by one of the miscreants.”

In terms of potential next steps Gourley said there are some steps that airlines can take to mitigate this threat. “Wireless intrusion detection systems and cryptographic methods can be used to ensure malicious devices cannot take advantage of trivial spoofing like what occurred here. It is sad that airlines will have to take those steps, but these immature actors have shown that others may do the same in the future, making these steps prudent for all airlines,” he said. “Airlines can provide information to passengers to ensure they only connect to the correct Wi-Fi, and they can instal wireless intrusion detection capabilities on their in-flight Wi-Fi. Most major vendors have offerings that can render this type of basic issue moot.”

Gourley was particularly disappointed that the incident took place just after DEFCON.

“This is the most famous hacking conference in the world. I attend every year to stay current and catch up with friends. This is a gathering of some of the greatest, most welcoming and kind people on the planet, they gather to learn, teach, share and enjoy each other’s company. It appears that a couple people who attended this conference decided to do something bad. It infuriates me that these people did what they did,” he said.

However, this incident shows that we could see more of these types of incidents in the future. Almog cautioned that the tools needed to carry out cyberattacks are becoming cheaper and easier to use.

“An attacker does not necessarily need deep aviation knowledge to create a rogue Wi-Fi network. Flight 591 makes that point almost literally — a plane full of people with exactly that knowledge, on a completely ordinary domestic route,” said Almog. “So I expect we will see more cyber events involving aviation.”

He expects to see more attacks in the future targeting airlines, passengers, the aviation supply chain, and attacks that exploit the unique visibility that comes from doing something malicious aboard an aircraft.

“The industry cannot assume these events will not happen,” Almog said. “It must detect them early, understand their potential impact, and be prepared to respond.”