Analyzing the Security of Satellite Based Air Traffic Control

Martin Strohmeier

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

In this DEF CON 32 talk, Martin Strohmeier from the Cyber Defense Campus, part of the Swiss Department of Defense, presented a comprehensive analysis of the security vulnerabilities inherent in satellite-based air traffic control (ATC) systems. The presentation delved into two primary technologies: Satellite Automatic Dependent Surveillance-Broadcast (ADS-B) and the lesser-known Automatic Dependent Surveillance – Contract (ADS-C). Strohmeier highlighted that despite their critical role in modern aviation, particularly for surveillance over remote and oceanic regions, these systems suffer from a fundamental lack of security, primarily the absence of authentication.

Watch on YouTube

Visual summary for Analyzing the Security of Satellite Based Air Traffic Control by Martin Strohmeier
Visual summary for Analyzing the Security of Satellite Based Air Traffic Control by Martin Strohmeier

Key moments

  1. 0:00 Introduction to air traffic control security analysis
  2. 2:00 Shifting focus to satellite-based ATC technologies
  3. 4:00 Debunking 'unattackable' claims for Satellite ADSB signals
  4. 6:10 Introduction to Automatic Dependent Surveillance – Contract (ADC)
  5. 8:00 Explaining ADC's purpose for remote air traffic monitoring
  6. 9:59 Visualizing how ADC fills gaps in ADSB coverage

Analyzing the Security of Satellite Based Air Traffic Control

Speakers: Martin Strohmeier

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=vJWzTt2ANAQ

Overview

In this DEF CON 32 talk, Martin Strohmeier from the Cyber Defense Campus, part of the Swiss Department of Defense, presented a comprehensive analysis of the security vulnerabilities inherent in satellite-based air traffic control (ATC) systems. The presentation delved into two primary technologies: Satellite Automatic Dependent Surveillance-Broadcast (ADS-B) and the lesser-known Automatic Dependent Surveillance – Contract (ADS-C). Strohmeier highlighted that despite their critical role in modern aviation, particularly for surveillance over remote and oceanic regions, these systems suffer from a fundamental lack of security, primarily the absence of authentication.

The talk underscored a pervasive problem in aviation communication protocols: a historical disregard for security in favor of functionality and availability. While terrestrial ATC systems have been extensively studied and demonstrated to be vulnerable over the past decade, satellite-based counterparts have largely escaped scrutiny. Strohmeier's work reveals that the move to space-based systems has not inherently introduced security; instead, it has often extended existing vulnerabilities or introduced new ones without adequate safeguards. The implications are significant, ranging from the ability for passive attackers to eavesdrop on thousands of aircraft positions globally to active attackers disrupting critical air traffic management functions, potentially leading to catastrophic consequences in a critical infrastructure domain.

This research is particularly timely given the increasing reliance on satellite communications for enhancing airspace efficiency and safety in areas beyond the reach of terrestrial radar and radio. By exposing the ease with which these systems can be compromised, Strohmeier issues a stark warning to the aviation industry and calls for urgent action to integrate robust security measures, emphasizing that the resources required for such attacks are "straightforward or trivial" for determined adversaries.

Background

▶ Watch: Introduction to air traffic control security analysis (0:00)

The landscape of air traffic control security has been a focal point for researchers and ethical hackers for well over a decade. Since the early 2010s, numerous practical attacks have been demonstrated against nearly all conventional aviation communication technologies. Protocols such as terrestrial ADS-B, ACARS, and even Global Navigation Satellite System (GNSS) signals (like GPS) have been shown to be vulnerable to various forms of manipulation and denial-of-service attacks. The underlying issue across these systems is remarkably consistent: aviation standards, while publicly available, were designed without security, authentication, or integrity checks as primary considerations.

The methodology for these attacks typically involves implementing a receiver using readily available equipment like Software Defined Radios (SDRs), which is also popular among aviation enthusiasts and plane spotters for services like FlightRadar24 or FlightAware. Once reception is established, developing a transmitter to inject malicious signals becomes a relatively straightforward engineering task. This has led to demonstrations of "ghost aircraft" appearing on ATC screens, spoofing of aircraft positions, and other disruptive actions.

In response to the limitations of terrestrial surveillance, particularly over vast oceans and mountainous regions, new technologies emerged over the past decade that leverage satellites. These systems aimed to extend ATC coverage beyond the reach of ground-based infrastructure, enabling more efficient airspace utilization and reducing reliance on congested voice communication channels. However, a common misconception, particularly for satellite ADS-B, was that the sheer distance to space inherently provided a layer of security, making attacks impractical. Strohmeier's work directly challenges this assumption, drawing parallels to the established vulnerabilities of terrestrial systems and demonstrating that the shift to space-based platforms has not fundamentally addressed the underlying security deficits, but rather, in some cases, simply moved them to a higher altitude.

Key Findings

▶ Watch: Debunking 'unattackable' claims for Satellite ADSB signals (4:00)

Martin Strohmeier's research into satellite-based air traffic control systems uncovered several critical security findings, underscoring a significant vulnerability in modern aviation infrastructure:

  1. Satellite ADS-B Inherits Terrestrial Vulnerabilities: The presentation confirmed that Satellite ADS-B systems, which utilize constellations in Low Earth Orbit (LEO) to pick up standard terrestrial ADS-B signals, are just as vulnerable as their ground-based counterparts. Claims that the distance to space (e.g., "485 miles up in space") makes these signals unattackable were debunked, demonstrating that if satellites can receive these signals, an attacker with sufficient power can transmit them, including ghost aircraft signals.
  2. ADS-C Was Previously Unstudied for Security: The talk highlighted that Automatic Dependent Surveillance – Contract (ADS-C), a system crucial for aircraft monitoring in remote areas and less known than ADS-B, had not been subjected to any security analysis by the scientific or security community prior to this research. This represented a significant gap in understanding the attack surface of critical aviation systems.
  3. Ubiquitous Lack of Authentication: A central theme across both satellite ADS-B and ADS-C is the complete absence of authentication mechanisms. This fundamental flaw allows for both passive eavesdropping and active injection of malicious data without the ability for recipients (air traffic control) to verify the origin or integrity of the information.
  4. Widespread Passive Eavesdropping on ADS-C: A passive attacker can eavesdrop on ADS-C messages from thousands of aircraft across roughly half of the world using a single receiver. This enables the collection of sensitive aircraft information including position, altitude, speed, navigational intent, and meteorological data, revealing global air traffic patterns and individual flight paths.
  5. Active Attacks on ADS-C are Feasible: Despite regulatory constraints preventing a live demonstration of active attacks, the research postulated and analyzed the feasibility of such attacks. These include Denial of Service (DoS) attacks against the ADS-C logon handshake, which can prevent aircraft from establishing satellite connections, and spoofing attacks that can inject false position data for existing aircraft towards air traffic control.
  6. Trivial Resources for Attack: Strohmeier concluded that the resources required to conduct these passive and active attacks are "straightforward or trivial." This implies that the barrier to entry for adversaries is low, making these vulnerabilities highly concerning.

These findings collectively paint a picture of an aviation ecosystem that has prioritized operational efficiency and coverage over robust security, leaving critical components exposed to significant risks.

Technical Deep Dive

▶ Watch: Introduction to Automatic Dependent Surveillance – Contract (ADC) (6:10)

The technical core of Strohmeier's talk focused on dissecting the mechanisms and vulnerabilities of Satellite ADS-B and, in greater detail, ADS-C.

Satellite ADS-B: Extending Terrestrial Vulnerabilities to Orbit

The concept of Satellite ADS-B is deceptively simple: instead of relying solely on ground-based receivers, companies have launched constellations of LEO satellites that passively pick up the same 1090 MHz ADS-B signals transmitted by aircraft transponders. These signals, containing aircraft identification, position, altitude, and speed, are then relayed to Air Navigation Service Providers (ANSPs). This system is particularly useful for extending surveillance coverage over oceans or mountainous regions where terrestrial receivers are impractical.

The critical vulnerability here is that Satellite ADS-B does not introduce any new security features; it merely acts as a space-based relay for an already insecure protocol. As Strohmeier pointed out, industry claims that the distance (e.g., "485 miles up in space") makes the signal unattackable are "bullshit." If a satellite can receive a weak signal from an aircraft 485 miles below, then a ground-based attacker, with more powerful equipment, can certainly transmit a signal that reaches the satellite. This means all the well-documented ADS-B spoofing attacks, including the creation of ghost aircraft or the injection of false position data, are equally applicable to the satellite-based system. The primary difference is the increased power required for the uplink to reach the satellite.

Automatic Dependent Surveillance – Contract (ADS-C): A New Frontier of Insecurity

ADS-C is a more complex and less publicly understood system, but equally, if not more, critical for modern ATC. Developed in the late 1990s but gaining prominence over the last 5-10 years (partly due to incidents like MH370), ADS-C enables detailed aircraft monitoring in remote areas, significantly improving airspace efficiency by allowing reduced separation between aircraft and decreasing reliance on congested VHF/HF voice communications.

Operational Flow:

  1. Aircraft Position Source: Aircraft obtain their precise position data from GNSS/GPS services.
  2. Satellite Communication: This data is then transmitted from the Aircraft Earth Station (the aircraft) to satellites, typically geostationary satellites operated by providers like Inmarsat, though LEO constellations can also offer these services.
  3. Ground Relay: The satellites forward the data to Ground Earth Stations (referred to as Air Traffic Service Units (ATSUs)) located globally.
  4. ANSP Routing: From the ground stations, the information is routed to the relevant ANSPs who require the surveillance data.

Frequencies:

  • Aircraft Uplink (to satellite): 1.6 GHz
  • Satellite Downlink (to ground station): 3.6 GHz
  • Ground Uplink (to satellite): 6.5 GHz

Message Exchange:

  • Uplink (ATC to Aircraft): The air traffic controller always initiates the connection by requesting a "contract" from a specific aircraft.
  • Periodic Contracts: Request regular updates (e.g., every 10 minutes) on position, altitude, speed, and other meteorological or navigational data.
  • Event Contracts: Request reports triggered by specific events, such as a waypoint change.
  • Downlink (Aircraft to ATC): The aircraft responds with ADC reports. These reports contain crucial information including latitude, longitude, altitude, timestamp, and depending on the report type, additional navigational intent or meteorological data.

Threat Model and Attacker Capabilities:

Strohmeier identified three types of attackers:

  1. Passive Attacker (Eavesdropper):
  • Goal: Intercept ADS-C messages without detection.
  • Requirements: Needs to be within the footprint of the geostationary satellite beam.
  • Technical Challenge: In Europe, the 3.6 GHz downlink frequency conflicts with 5G cellular bands. To successfully eavesdrop on the weak satellite signals, the attacker needs to operate in a "5G-free zone" or use highly directional antennas and filtering to overcome local interference.
  • Impact: Can monitor thousands of aircraft simultaneously across half the world, gaining access to real-time position, altitude, speed, and navigational intent. This provides a comprehensive picture of global air traffic that is typically only available to ANSPs.
  1. Active Attacker (Denial of Service):
  • Goal: Disrupt the establishment or maintenance of ADS-C connections.
  • Mechanism: Attack the protocol handshake during the aircraft logon process (aircraft logs on, confirmed, acknowledged). By injecting malicious signals during this phase, an attacker could prevent the aircraft from successfully establishing an ADS-C contract.
  • Impact: Causes a Denial of Service for ADS-C, meaning ANSPs lose satellite-based surveillance for the affected aircraft. While other technologies (e.g., terrestrial radar, voice comms) might still be available, it degrades the efficiency and safety benefits of ADS-C, particularly in remote areas. This is not immediately safety-relevant in all cases but is certainly a disruptive attack.
  1. Active Attacker (Spoofing):
  • Goal: Inject false information into ADS-C reports.
  • Mechanism: Unlike terrestrial ADS-B where ghost aircraft can be easily injected, ADS-C requires the ATC to initiate a contract with a known aircraft. Therefore, an attacker cannot simply inject a "ghost" ADS-C aircraft that isn't already expected. However, an attacker can intercept and modify legitimate ADS-C reports from an existing aircraft or transmit false reports impersonating an existing aircraft with which ATC has an active contract.
  • Impact: Spoofing can lead to ANSPs receiving incorrect position, altitude, or navigational intent data for active flights. This could result in controllers issuing inappropriate instructions, misjudging separation distances, or being misled about an aircraft's true trajectory, with potentially severe safety implications.

The core vulnerability enabling all these attacks is the complete lack of authentication in the ADS-C protocol. There are no cryptographic signatures or integrity checks to verify the sender's identity or the data's authenticity, making it trivial for an attacker to either listen in or inject unverified information. The resources required for these attacks, primarily SDRs, antennas, and sufficient power, are described as "straightforward or trivial."

Demo / Proof of Concept

▶ Watch: Explaining ADC's purpose for remote air traffic monitoring (8:00)

The talk outlined the theoretical feasibility and requirements for both passive and active attacks on satellite-based air traffic control systems. For Satellite ADS-B, Martin Strohmeier stated that while they had postulated a theoretical attack, they had not performed a practical demonstration of sending signals to their satellites due to legal and regulatory reasons. He emphasized that it "would not be legal" but firmly asserted that it is "certainly not secure."

Regarding ADS-C, the research successfully demonstrated passive eavesdropping on live traffic, confirming the ability to intercept real-time aircraft data from thousands of flights globally. However, for active attacks such as Denial of Service or spoofing, the team similarly refrained from live demonstrations due to the critical nature of the infrastructure and the potential for regulatory and legal repercussions. The talk presented a detailed analysis of the protocol and the attack surface, establishing the technical feasibility of these active attacks without needing to execute them in practice. The focus was on demonstrating how such attacks could be conducted and the theoretical requirements, rather than performing them.

Defensive Implications

▶ Watch: Visualizing how ADC fills gaps in ADSB coverage (9:59)

The findings presented by Martin Strohmeier reveal significant security gaps in satellite-based air traffic control systems, demanding urgent attention from the aviation industry and regulatory bodies. The primary defensive implication is the absolute necessity to integrate robust security mechanisms into these protocols.

  1. Implement Strong Authentication: The most critical step is to introduce authentication into both ADS-B (where applicable for satellite relays) and ADS-C. This would ensure that only legitimate aircraft and ground stations can send or receive messages. Cryptographic signatures, linked to aircraft identities or established session keys, should be mandatory for all critical data transmissions. This would prevent unauthorized injection of ghost aircraft (for ADS-B) and spoofing of existing aircraft data (for ADS-C).
  2. Ensure Data Integrity: Beyond authentication, mechanisms for data integrity must be implemented. Even if a message is from an authenticated source, its content could be tampered with in transit. Cryptographic hash functions or Message Authentication Codes (MACs) should be used to verify that the position, altitude, speed, and navigational intent data received by ANSPs have not been altered.
  3. Enhance Anomaly Detection: ANSPs should deploy advanced anomaly detection systems that can identify suspicious patterns in aircraft reports. This includes impossible speeds or altitudes, sudden and illogical position changes, or deviations from expected flight paths, even if the reports appear to come from legitimate aircraft. Such systems could act as a secondary layer of defense, alerting controllers to potential spoofing attempts that might bypass current or future authentication schemes.
  4. Strengthen Protocol Handshakes: For ADS-C, specific countermeasures against Denial of Service (DoS) attacks targeting the logon handshake should be developed. This could involve more robust challenge-response mechanisms, rate limiting, or cryptographic session establishment to prevent attackers from disrupting the initial connection.
  5. Multi-Source Data Verification: Where possible, ANSPs should move towards a multi-source data verification strategy. Relying on a single data stream, especially from an unauthenticated satellite-based system, is inherently risky. Cross-referencing ADS-C data with other available surveillance methods (e.g., terrestrial radar, voice reports, other satellite systems) can help identify discrepancies and mitigate the impact of spoofing.
  6. Address RF Interference: The issue of 5G interference on the 3.6 GHz ADS-C downlink frequency highlights a need for better frequency planning and potentially more robust receiving equipment with advanced filtering capabilities to ensure reliable signal reception, even in congested radio environments.
  7. Raise Awareness and Training: Air traffic controllers and other operational personnel must be made aware of these vulnerabilities. Understanding the limitations and potential for malicious interference in satellite-based systems is crucial for making informed decisions, especially when faced with unusual or conflicting aircraft data.

In essence, the aviation industry must move beyond the assumption of inherent security through obscurity or distance and proactively embed security-by-design principles into all future and existing satellite communication protocols. The current reliance on unauthenticated data transmission in critical ATC functions presents an unacceptable level of risk.

Key Takeaways

  • Fundamental Security Lapses: Both Satellite ADS-B and ADS-C, crucial for modern air traffic control over remote areas, fundamentally lack authentication and integrity mechanisms, making them inherently insecure.
  • Distance is Not Security: The belief that space-based systems are inherently secure due to their distance from terrestrial attackers is a dangerous misconception; if satellites can receive signals, attackers can transmit them with sufficient power.
  • Widespread Passive Eavesdropping: A single passive receiver can monitor the real-time position, altitude, speed, and navigational intent of thousands of aircraft globally via ADS-C, exposing sensitive flight data across half the world.
  • Feasible Active Attacks: Active attackers can execute Denial of Service (DoS) attacks on ADS-C logon handshakes or spoof position data for existing aircraft, disrupting air traffic control operations and potentially compromising safety.
  • Low Barrier to Entry: The resources required for both passive eavesdropping and active attacks are described as "straightforward or trivial," indicating a low barrier for entry for malicious actors.
  • Urgent Need for Authentication: The aviation industry must urgently integrate robust authentication and data integrity checks into all satellite-based ATC protocols to mitigate these critical vulnerabilities and ensure the safety and reliability of global air travel.

About the Speaker(s)

Martin Strohmeier is a researcher at the Cyber Defense Campus. This campus is part of the procurement agency and falls under the Swiss Department of Defense. His work focuses on analyzing the security of critical infrastructure, particularly in the aviation and aerospace domains, as demonstrated by his extensive research into air traffic control systems.

All talks from DEF CON 32 Creator Stage