Skip to main content

NASA uncovered a network security flaw that could affect spacecraft

Researchers from the University of Michigan, University of Pennsylvania, and NASA have discovered a significant security flaw in networking technology used in spacecraft, airplanes, energy generation systems, and industrial control systems. 

UoM's news portal Michigan News reported the flaw abuses a network protocol and hardware system known as time-triggered ethernet, or TTE. 

This system allows mission-critical devices, such as life support systems, to coexist on the same network hardware as less important devices, such as passenger Wi-Fi, or data collection systems.

PCspooF

TTE was deemed safe for more than a decade, because the two types of network traffic were never allowed to interfere with one another on the same endpoint. It was originally established in a bid to reduce network costs while improving efficiency, the researchers said. 

However, the researchers have now managed to crack this barrier with an attack dubbed PCspooF, discussing it extensively as part of a paper titled "PCspooF: Compromising the Safety of Time-Triggered Ethernet".

The team illustrated the flaw by using real NASA hardware to simulate an Asteroid Redirection Test, specifically the stage where a capsule must dock with a spacecraft.

As the capsule would try to dock, the attack mashed vital and non-vital communication together, disrupting messages going through the system and creating a cascading effect. Eventually, the capsule veered off course and missed the dock entirely.

Baris Kasikci, the Morris Wellman Faculty Development Assistant Professor of Computer Science and Engineering, laid the risks bare. “If someone executed this attack in a real spaceflight mission, what would the damage be?”

However, in order to successfully pull off a PCSpooF attack, the attacker needs to plant a small, malicious device on the network, which means remote attacks are not possible.

Other good news is that the flaw can be fixed, relatively easily, by replacing copper Ethernet with fiber optic cables, or installing optical isolators between switches and untrusted devices. 

That would eliminate the risk of electromagnetic interference, although it would impact performance, according to researchers.



Source: TechRadar

Popular posts from this blog

iOS 14 Favorites Widget: How to Make a Replacement With Shortcuts

In iOS 14 , Apple overhauled widgets and introduced an option for adding ‌widgets‌ to the Home Screen , but in the process, a well-loved Favorites widget that existed in iOS 13 was removed. The Favorites widget let users set certain contacts and contact methods as favorites that were easily accessible, so you could, for example, add a favorite option for messaging Eric or calling Dan, with those actions executed with a tap. Why the Favorites widget was removed is a mystery and it could be a simple oversight with Apple planning to reintroduce it later, but for now, those who relied on the widget can recreate its functionality with Shortcuts. It takes some effort, but it may be worth the time investment if you often relied on your Favorites. Creating a Favorites Shortcut Making a shortcut that replicates the behavior of the Favorites widget isn't too tough, but if you want multiple favorite options, you'll need to create a separate shortcut for each one in the Shortcuts

The hidden cost of food delivery

Noah Lichtenstein Contributor Share on Twitter Noah Lichtenstein is the founder and managing partner of Crossover , a diversified private technology fund backed by institutional investors, technology execs and professional athletes and entertainers. More posts by this contributor What Studying Students Teaches Us About Great Apps I’ll admit it: When it comes to food, I’m lazy. There are dozens of great dining options within a few blocks of my home, yet I still end up ordering food through delivery apps four or five times per week. With the growing coronavirus pandemic closing restaurants and consumers self-isolating, it is likely we will see a spike in food delivery much like the 20% jump China reported during the peak of its crisis. With the food delivery sector rocketing toward a projected $365 billion by the end of the decade, I’m clearly not the only one turning to delivery apps even before the pandemic hit. Thanks to technology (and VC funding) we can get a ri

Amazon Takes Up to $200 Off M1 iPad Air With New Record Low Prices

Apple's previous generation M1 iPad Air has dropped further in price this week on Amazon, now available at $399.00 for the 64GB Wi-Fi model, down from $599.00. These price drops follow just one week after Apple unveiled the new M2 iPad Air. Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. You can also get the 256GB Wi-Fi M1 iPad Air on sale for $599.00, down from $749.00. Both of these deals are new all-time low prices on the 2022 tablet, and right now only Amazon has the discounts. $200 OFF 64GB Wi-Fi M1 iPad Air for $399.00 $150 OFF 256GB Wi-Fi M1 iPad Air for $599.00 Additionally, both cellular models are on sale right now on Amazon. The 64GB cellular model has hit $599.00 , down from $749.00, while the 256GB cellular model is available for $749.00 , down from $899.00. Stock on the cellular models is far more sparse compared to the Wi-Fi tablet

Apple Adds Support for Live Activities to Shazam

Apple today added support for Live Activities in Shazam, its free music discovery and identification app. Shazam's Live Activities keep the user updated when searching for music in the background, which is particularly useful when multitasking or identifying songs in other apps . The last significant update to Shazam arrived in January, allowing users to identify songs from other apps while listening with headphones. Apple acquired Shazam in 2018, and has been gradually bringing the app into closer alignment with ‌ Apple Music ‌ ever since, offering trials to the streaming service through the app and the ability to sync Shazams directly to ‌‌Apple Music‌‌. Shazam can be downloaded from the App Store for free . It can be accessed through the Control Center on ‌‌ iPhone ‌‌ and ‌‌ iPad ‌‌, through ‌ Siri ‌ commands, or on the Mac, as well as via widgets. Version 17.11 of Shazam is now available. Apple opened up its Live Activities API to third-party ‌iPhone‌ apps with the r