Security
Security Chiefs: Aircraft Need CAN Bus Cyber Safeguards
An IT Consultancy tested the ability to attach a device to a CAN bus to inject false data.
According to the DHS Cybersecurity and Infrastructure Security Agency, a device attached to an aircraft's avionics CAN bus could lead to incorrect engine telemetry readings, incorrect compass and attitude data, and incorrect altitude, airspeed, and angle of attack (AoA) data. (Photo: Chad Trautvetter/AIN)
According to the DHS Cybersecurity and Infrastructure Security Agency, a device attached to an aircraft's avionics CAN bus could lead to incorrect engine telemetry readings, incorrect compass and attitude data, and incorrect altitude, airspeed, and angle of attack (AoA) data. (Photo: Chad Trautvetter/AIN)

Certain controlled area network (CAN) bus systems aboard aircraft might be vulnerable to hacking when an attacker has “unsupervised physical access to the aircraft,"  the U.S. Department of Homeland Security's (DHS) Cybersecurity and Infrastructure Security Agency (CISA) warned yesterday in an alert (ICS-ALERT-19-211-01). It cited a report that an attacker with access to the aircraft could attach a device to an avionics CAN bus to “inject false data, resulting in incorrect readings in avionic equipment.”