Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Researchers Hijack Botnet Gain Insight to Bots and Their Victims | Main | SQL Injection Attacks in Content Management Systems »

Hacking Air Traffic Control Systems

The Wall Street Journal is reporting air traffic control networks have been attacked on multiple occasions in the past several years. The FAA doesn't agree with all the findings of the Transportation Department's inspector general who issued the report but the undisputed facts are troubling enough.

For example, an attack led to a partial shutdown air traffic systems in Alaska at one point. A modernization effort is underway. More intrusion detection is clearly needed:

The report warned that the FAA isn't well equipped to detect intrusions into its computer system, noting that it has detection sensors at only 11 of its 734 facilities across the country. All of those detectors are placed on administration or "mission support" systems, with no detectors on any of its operational systems, giving it little visibility into potential problems with operational networks, the report said.

It would be hard to overestimate the complexity of the air traffic control system and its links to administrative systems. This kind of complexity is itself part of the problem. Monolithic, centralized control systems can only get so complex before the weight of the complexity undermines their ability to function and adapt. A more fundamental redesign may be in order here.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/1042

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net