RF Attacks on Aviation's Defense Against Mid-Air Collisions

G. Longo, V. Lenders

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

In an era of increasingly complex air traffic and millions of flights annually, the integrity of aviation's safety systems is paramount. This DEF CON 32 presentation, delivered by cybersecurity researchers Vincent Lenders and Giacomo Longo, delves into critical radio frequency (RF) vulnerabilities within the Traffic Alert and Collision Avoidance System (TCAS) – a technology recognized as the aviation industry's last line of defense against mid-air collisions. The speakers present compelling experimental evidence demonstrating the feasibility of launching sophisticated attacks against TCAS, challenging the long-held belief that the system's inherent timing requirements provided sufficient security.

Watch on YouTube

Visual summary for RF Attacks on Aviation's Defense Against Mid-Air Collisions by G. Longo, V. Lenders
Visual summary for RF Attacks on Aviation's Defense Against Mid-Air Collisions by G. Longo, V. Lenders

Key moments

  1. 0:00 Introduction to RF attacks on aviation's TCAS
  2. 2:00 SSR, ADSB, and TCAS technologies explained
  3. 4:00 TCAS: Aviation's critical last line of defense
  4. 5:55 Understanding TCAS core functions: Surveillance, TA, RA
  5. 6:50 Review of existing TCAS security research and risks
  6. 8:00 Transition to experimental analysis of TCAS attacks

RF Attacks on Aviation's Defense Against Mid-Air Collisions

Speakers: G. Longo; V. Lenders

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=p1H6-0clP7U

Overview

In an era of increasingly complex air traffic and millions of flights annually, the integrity of aviation's safety systems is paramount. This DEF CON 32 presentation, delivered by cybersecurity researchers Vincent Lenders and Giacomo Longo, delves into critical radio frequency (RF) vulnerabilities within the Traffic Alert and Collision Avoidance System (TCAS) – a technology recognized as the aviation industry's last line of defense against mid-air collisions. The speakers present compelling experimental evidence demonstrating the feasibility of launching sophisticated attacks against TCAS, challenging the long-held belief that the system's inherent timing requirements provided sufficient security.

The talk highlights the worrying reality that despite prior warnings and simulations, a definitive scientific methodology and experimental proof of concept for TCAS attacks using commercial, certified hardware has been conspicuously absent. Lenders and Longo's research addresses this gap directly, showcasing how an attacker can induce false collision warnings, manipulate resolution advisories, and even remotely disable TCAS functionality on aircraft. Their findings underscore a fundamental insecurity in a system vital for human life, demanding urgent attention from aviation authorities and security professionals alike.

The implications of this research are profound. With the potential for catastrophic loss of life and significant disruption to air travel, understanding and mitigating these RF vulnerabilities in TCAS is not merely an academic exercise but a critical imperative. The presentation not only exposes these weaknesses but also establishes a much-needed framework for rigorously testing and evaluating the security posture of such crucial aviation systems.

Background

▶ Watch: Introduction to RF attacks on aviation's TCAS (0:00)

The global air traffic management system is a highly intricate infrastructure, facilitating over 30 million flights per year. Its primary objectives include optimizing air traffic flow, providing situational awareness to ground controllers and pilots, and, most critically, preventing mid-air collisions. To achieve this, modern aviation relies on a suite of technologies, predominantly based on the Mode S data frame format, which enables wireless communication between aircraft and ground stations.

Three key Mode S-based technologies form the backbone of air traffic control and collision avoidance:

  1. Secondary Surveillance Radar (SSR): This is the oldest of the three, relying on ground-based radar stations to interrogate aircraft. Radars transmit on a 1030 MHz uplink, and aircraft respond on a 1090 MHz downlink. These messages, though small (56 or 112 bits), convey vital information like velocity, altitude, and heading. SSR is mandatory in airspaces worldwide.
  2. Automatic Dependent Surveillance-Broadcast (ADS-B): A more recent and precise technology, ADS-B mandates aircraft to determine their own position using Global Navigation Satellite Systems (GNSS), such as GPS. This positional data is then continuously broadcast on the 1090 MHz downlink to surrounding aircraft and ground stations. ADS-B offers significantly higher precision (a few meters accuracy) compared to SSR's hundreds of meters, allowing for reduced separation between aircraft.
  3. Traffic Alert and Collision Avoidance System (TCAS): The central focus of this presentation, TCAS is unique in that it operates as a direct protocol between aircraft. It employs a request-reply ranging mechanism, also utilizing the 1030 MHz uplink for interrogations and the 1090 MHz downlink for responses. TCAS is designed to detect potential collision threats and provide guidance to pilots to avert them. Its importance cannot be overstated, as it serves as the last line of defense against mid-air collisions, activating when other separation systems like SSR or ADS-B have failed. Introduced in 1987 in response to several catastrophic mid-air collisions in the 1970s and 80s, TCAS is now mandatory for aircraft exceeding certain size and passenger capacities in many airspaces.

TCAS operates through three core functions:

  • Surveillance: This involves periodically detecting and tracking surrounding aircraft, acquiring their range, altitude, and capabilities, which are then displayed to the pilot.
  • Traffic Advisory (TA): If the system identifies a potential collision threat, it issues an audible and visual alarm (TA) in the cockpit, alerting the pilot to the presence of conflicting traffic.
  • Resolution Advisory (RA): If the collision threat persists and intensifies, TCAS II, the most common version, issues a direct command to the pilot. This command, typically instructing one aircraft to climb and the other to descend, is designed to resolve the conflict and prevent a collision.

The security of TCAS has been a subject of concern for some time. Prior research, including risk assessments, theoretical analyses, and even simulations involving pilots in flight simulators (some conducted by Vincent Lenders himself), have highlighted potential vulnerabilities and explored how pilots might react to spoofed TCAS advisories. However, a significant gap remained: a lack of convincing experimental and scientific evidence demonstrating the practical feasibility of these attacks using commercial and certified hardware, along with an established methodology for such testing. This critical absence of real-world proof fueled the motivation behind Lenders and Longo's groundbreaking work.

Key Findings

▶ Watch: TCAS: Aviation's critical last line of defense (4:00)

The research presented by Lenders and Longo at DEF CON 32 delivers several critical findings that fundamentally alter the understanding of TCAS security. The overarching revelation is that TCAS, despite its vital role, is inherently insecure by design, lacking fundamental cybersecurity protections such as encryption, public key infrastructure (PKI), or robust authentication mechanisms. Its collaborative, clear-text communication protocol makes it susceptible to various RF-based attacks.

The most significant contribution of this work is the provision of the first convincing experimental and scientific evidence that sophisticated TCAS attacks are indeed feasible. Unlike previous theoretical studies or simulations, this research demonstrates the capability to trigger both Traffic Advisories (TAs) and Resolution Advisories (RAs) on commercial, certified TCAS hardware. This achievement debunks the informal notion that the protocol's stringent timing requirements served as an effective security barrier against all but the most advanced adversaries.

Specifically, the speakers identified and experimentally demonstrated the feasibility of three distinct attack vectors:

  1. Inducing a Traffic Advisory (TA): An attacker can spoof an aircraft's presence and behavior to trigger a false TA in a target aircraft's cockpit, creating unnecessary alarms and potentially distracting pilots.
  2. Triggering a Resolution Advisory (RA): Building upon a TA, an attacker can escalate the spoofed threat to generate a false RA. Crucially, by exploiting a specific design flaw in the TCAS conflict resolution algorithm (where the aircraft with the lowest Mode S address "wins" a negotiation), an attacker can dictate the evasive maneuver (climb or descend) for the target aircraft.
  3. Disabling TCAS Sensitivity: Perhaps the most alarming finding, the researchers demonstrated that an attacker can remotely send unauthenticated commands to an aircraft, instructing its TCAS system to reduce or entirely disable its collision avoidance sensitivity. This effectively blinds the aircraft's last line of defense, leaving it vulnerable to mid-air collisions without the pilot's explicit knowledge or consent.

A pivotal aspect of their success lies in overcoming the extremely tight timing constraints of the Mode S protocol, specifically the 128-microsecond turnaround time required for replies. This precise timing, previously considered a deterrent for low-skilled attackers, was successfully managed, showcasing the capabilities now available to determined adversaries. By establishing a rigorous methodology for testing these attacks, Lenders and Longo have not only exposed critical vulnerabilities but also provided a framework for future security evaluations of aviation systems.

Technical Deep Dive

▶ Watch: Understanding TCAS core functions: Surveillance, TA, RA (5:55)

The core of TCAS communication relies on the Mode S protocol, a standardized data frame format for wireless communication between aircraft and ground stations, operating on specific radio frequencies. TCAS utilizes a request-reply ranging protocol: aircraft interrogate each other on the 1030 MHz uplink and respond on the 1090 MHz downlink. The messages exchanged are remarkably small, either 56 or 112 bits, yet they carry essential information about an aircraft's identity, altitude, and capabilities.

A critical technical detail for TCAS operation and the success of these attacks is the precise calculation of relative distance. TCAS estimates the range between aircraft by measuring the Time of Flight (ToF) of these request-reply cycles. From this ToF, a fixed value of 128 microseconds is subtracted. This 128 µs represents the nominal internal processing delay (turnaround time) within a TCAS transponder. This extremely short time window for receiving, processing, and transmitting a reply has historically acted as a significant barrier for attackers, as typical operating system schedulers operate at timescales thousands of times slower. The researchers successfully navigated this precise timing challenge, which was key to their experimental success.

The presented attacks leverage this understanding of the Mode S protocol and TCAS operational logic:

Attack 1: Inducing a Traffic Advisory (TA)

To trigger a false TA, an attacker must convincingly impersonate a non-existent aircraft. This requires adhering to the complex TCAS standards, which the speaker humorously noted spans "1,300 pages of standards." The attacker's system must:

  1. Broadcast its presence: Announce itself as a legitimate aircraft within the target aircraft's surveillance range.
  2. Reply to interrogations properly: Accurately respond to the target TCAS's 1030 MHz interrogations on the 1090 MHz downlink, providing consistent and believable altitude and position data.
  3. Maintain a consistent identity: Utilize a unique and persistent Mode S address and associated parameters to appear as a single, continuous threat.

By fulfilling these conditions, the attacker can make the target TCAS system believe a conflicting aircraft is approaching, thus triggering a TA alarm in the cockpit.

Attack 2: Triggering a Resolution Advisory (RA)

An RA is a more severe alert, commanding the pilot to take evasive action. This attack builds upon a successful TA. Once a TA is triggered, the two TCAS systems (the legitimate one and the spoofed one) enter a "negotiation" phase to determine the appropriate evasive maneuvers. The vulnerability here lies in the conflict resolution algorithm used by TCAS II: the aircraft with the lowest Mode S address always wins the negotiation.

An attacker can exploit this by:

  1. Discovering the target aircraft's Mode S address: This information is openly broadcast and easily observable.
  2. Crafting a spoofed Mode S address: The attacker can choose a Mode S address lower than the target's.
  3. Manipulating negotiation responses: During the RA negotiation, the attacker can consistently send replies that force the target aircraft to perform a specific maneuver (e.g., climb or descend), effectively dictating the evasive action. This could potentially lead to a dangerous maneuver or even steer the aircraft into another legitimate, non-conflicting flight path.

Attack 3: Disabling TCAS Sensitivity

This attack targets the TCAS system's sensitivity level. TCAS adjusts its protected airspace (sensitivity) based on factors like altitude. For instance, near busy airports with closely spaced runways (like Las Vegas), ground stations can command aircraft to reduce their TCAS sensitivity to prevent nuisance advisories. The critical vulnerability identified is that these commands from ground stations are unauthenticated.

An attacker can leverage this by:

  1. Emulating a legitimate ground station: Transmitting a Mode S message on the 1030 MHz uplink designed to mimic a ground station command.
  2. Sending a TCAS sensitivity reduction/disablement command: Because there is no authentication, any aircraft within range that receives this command will comply, reducing or entirely disabling its TCAS functionality. This could effectively blind an aircraft to genuine collision threats, leaving it without its crucial last line of defense.

The technical challenge of achieving these attacks, particularly the precise timing required for Mode S replies, was a key aspect the researchers overcame. The 128 microsecond window is not just a nominal delay; it represents the time from the start of the received interrogation to the start of the transmitted reply, requiring extremely low-latency hardware and highly optimized software to process the incoming signal, interpret the message, generate the correct response, and transmit it with microsecond precision. The success of this research indicates that such capabilities are now within reach of determined adversaries.

Demo / Proof of Concept

▶ Watch: Review of existing TCAS security research and risks (6:50)

While the provided transcript details the mechanisms of the attacks and the experimental conditions necessary for their success, it does not provide a visual or step-by-step account of a live demonstration. However, the speakers explicitly state that their motivation was to provide "convincing experimental and scientific evidence that this T-CAS attacks may work. Actually they they may trigger for example resolution advisories using commercial and certified hardware." This confirms that the researchers successfully built a testbed and performed these attacks, thereby validating their feasibility.

The experimental setup, while not explicitly detailed in the transcript, would necessarily involve specialized Software-Defined Radio (SDR) hardware capable of operating on the 1030 MHz and 1090 MHz frequencies with the required sub-microsecond timing precision. This hardware, coupled with custom software implementing the complex Mode S and TCAS protocols, allowed the researchers to:

  • Accurately spoof aircraft presence and behavior.
  • Generate correctly timed and formatted Mode S interrogations and replies.
  • Monitor the responses of real, certified TCAS equipment under test.

The success of their experiments means they were able to:

  • Observe a target TCAS system generate a Traffic Advisory (TA) in response to a simulated threat.
  • Further escalate the spoofed threat to trigger a Resolution Advisory (RA), demonstrating the ability to manipulate the target's evasive maneuver.
  • Successfully send an unauthenticated ground station command that resulted in the target TCAS system reducing or disabling its collision avoidance sensitivity.

These achievements, though not visually described in the transcript, represent a significant proof of concept. They move the discussion of TCAS vulnerabilities from theoretical concerns and simulations to demonstrated, real-world exploitability using readily available (albeit specialized) commercial hardware. The implication is clear: the attacks described are not hypothetical but practically achievable.

Defensive Implications

▶ Watch: Transition to experimental analysis of TCAS attacks (8:00)

The findings presented by Vincent Lenders and Giacomo Longo expose profound defensive implications for the aviation industry, particularly concerning the inherent vulnerabilities of the TCAS system. The most immediate and critical takeaway for defenders is that TCAS, as currently implemented, is fundamentally insecure by design due to its reliance on unauthenticated, unencrypted, and clear-text communication. This architectural flaw makes it susceptible to spoofing and manipulation.

Defenders must recognize that aircraft systems cannot implicitly trust all incoming RF signals. A multi-layered defense strategy is essential. This includes:

  1. Enhanced Situational Awareness for Pilots: While TCAS is designed to be the "last line of defense," pilots should be trained and equipped to cross-reference TCAS advisories with other available information sources, such as visual observation, ADS-B data, and directives from Air Traffic Control (ATC). However, this is a complex challenge, as TCAS RAs are designed to be immediate and mandatory.
  2. Robust Authentication for Ground-to-Air Commands: The demonstrated ability to remotely disable TCAS sensitivity via unauthenticated ground station commands is an extreme vulnerability. Any command that can alter critical safety system parameters on an aircraft must be secured with strong cryptographic authentication. This requires a fundamental re-evaluation and potential redesign of how such commands are transmitted and processed.
  3. Resilience Against Spoofing: Aircraft avionics, including TCAS transponders, need to be made more resilient to spoofed or malicious signals. This could involve incorporating anomaly detection algorithms that identify inconsistent or impossible flight parameters from perceived threats, or cross-referencing data with other onboard sensors.
  4. Security-by-Design for Future Protocols: The issues highlighted in TCAS underscore a broader need for security-by-design principles in the development of all future aviation communication protocols. This means integrating authentication, encryption, and integrity checks from the outset, rather than attempting to retrofit them onto legacy systems.
  5. Standardized Vulnerability Testing: The research establishes a methodology for experimentally testing TCAS attacks. Aviation authorities and manufacturers should adopt and standardize such rigorous testing methodologies to proactively identify and mitigate vulnerabilities in critical safety systems before they can be exploited in real-world scenarios. This includes regular "red teaming" exercises against operational systems in controlled environments.
  6. Supply Chain Security: The reliance on commercial and certified hardware for these attacks highlights the importance of securing the avionics supply chain. Ensuring the integrity of components and software used in critical systems is paramount to prevent the introduction of backdoors or vulnerabilities.

In the short term, mitigating these vulnerabilities will be challenging due to the inherent difficulty of retrofitting security features into widely deployed legacy systems and the extensive certification processes required for aviation hardware. However, the catastrophic potential of mid-air collisions demands that these defensive implications be addressed with the utmost urgency, prioritizing research into secure alternatives and robust countermeasures for the aviation ecosystem.

Key Takeaways

  • TCAS is Fundamentally Insecure: Aviation's last line of defense against mid-air collisions, the Traffic Alert and Collision Avoidance System (TCAS), lacks basic security measures like encryption, authentication, or PKI, making it inherently vulnerable to RF attacks.
  • Experimental Feasibility Confirmed: Researchers have provided the first convincing experimental and scientific evidence that TCAS attacks, including inducing Traffic Advisories (TAs) and triggering Resolution Advisories (RAs), are practically feasible using commercial and certified hardware.
  • Timing Barrier Overcome: The critical 128-microsecond timing requirement for Mode S replies, previously considered a significant deterrent, can now be overcome by determined attackers using specialized RF hardware and software.
  • Remote TCAS Disablement Risk: An alarming vulnerability allows attackers to send unauthenticated ground station commands to aircraft, instructing their TCAS systems to reduce or entirely disable collision avoidance sensitivity, effectively blinding the aircraft to threats.
  • Urgent Need for Protocol Security: The discovered vulnerabilities underscore a critical need for the aviation industry to prioritize the security review and potential redesign of its communication protocols, integrating strong authentication, encryption, and integrity checks.
  • Standardized Testing Methodology Required: The research establishes a crucial methodology for experimentally testing TCAS vulnerabilities, which should be adopted and standardized by aviation authorities to proactively identify and mitigate risks in critical safety systems.

About the Speaker(s)

Vincent Lenders is a highly experienced cybersecurity researcher with over two decades of expertise. His work primarily focuses on the security of wireless networks, a field directly relevant to the vulnerabilities discussed in this presentation. Beyond his research, Lenders holds a leadership position as the Director of the Cyber Defense Campus in Switzerland, indicating his significant influence and contribution to national cybersecurity efforts and defense.

Giacomo Longo is a third-year PhD student based at the University of Genoa in Italy. His academic and research pursuits are centered on the radio security of critical transportation systems, specifically aviation and maritime systems. His collaboration with Vincent Lenders on this TCAS research highlights his emerging expertise in a highly specialized and impactful area of cybersecurity.

All talks from DEF CON 32 Creator Stage