Ghosts in the Sky: Creating Phantom Aircraft with Mode-S Transponder Spoofing
Modern commercial aircraft constantly exchange information using Mode-S transponders, ADS-B broadcasts, and TCAS collision avoidance messages. These systems help keep aircraft safely separated, but were designed before authenticated wireless communications became a security concern.
This talk provides an introduction to the protocols that underpin airborne collision avoidance and investigates whether a phantom aircraft could be introduced into the ACAS surveillance process through maliciously crafted Mode-S transmissions.
This talk introduces the protocols that underpin modern airborne collision avoidance and explains how Aircraft Collision Avoidance Systems (ACAS) discover, track, and coordinate with nearby aircraft. Beginning with an overview of ADS-B, TCAS, and Mode S communications, I discuss how aircraft build situational awareness independently of ground-based air traffic control.
The talk then explores the security implications of unauthenticated aviation communications and reviews publicly known weaknesses in ADS-B and Mode-S. Building on this, I investigate whether a synthetic aircraft could be introduced into the ACAS surveillance process through maliciously crafted Mode S transmissions.
By examining how ACAS works and discussing its unique security challenges, this talk aims to leave attendees with an understanding of the current research surrounding aircraft collision avoidance and a practical example of how a spoofing attack could manifest using a simulated environment.
I'm a BSc Computer Science student at the University of Glasgow, entering my fourth and final year of study. Initially interning at BT as a software developer, I have since interned twice at Microsoft, with my primary area of interest being Windows kernel vulnerability research.
I have recently began researching topics in aviation security, specifically vulnerabilities in digital communication protocols used in commercial aviation.