Malware and the failure of aircraft systems
August 23rd, 2010 by Bow SineathOn August 20, 2008, a tragic accident occurred involving a Spanair MD-82 aircraft. The aircraft failed to gain altitude, rolled to the right, and crashed into the ground, killing 154 people. The investigation after the accident discovered that the pilots failed to extend the flaps and slats prior to takeoff, creating an improper takeoff configuration. This critical error is the primary cause of the accident and was a result of the pilots failing to follow the published pre-takeoff checklist. The investigation also noted that the takeoff warning system (TOWS) failed, which normally issues an audible warning to the pilots if the aircraft is departing in the improper takeoff configuration. This warning is meant to supplement the takeoff checklist procedures in the event the pilots inadvertently forgot one of the steps on the checklist. The combination of the failed TOWS alert and the pilots’ failure to follow the pre-takeoff checklist resulted in the aircraft attempting takeoff in an improper configuration.
Exactly two years later on August 20, 2010, a Spanish paper published the following article:
ELPAIS.com: The computer scoring Spanair aircraft failures had virus (English Translation by Google Translate)
The article reports that malware was installed on the TOWS system of the accident aircraft and implies that it may have been a contributing factor or the cause of the accident.
A TOWS failure is not uncommon to MD-80 series aircraft and has been blamed in other fatal accidents, including Northwest Flight 255 in 1987. As a result of Northwest Flight 255, McDonnell Douglas issued an update to their checklist procedures, including a change requiring pilots to check the TOWS system prior to takeoff. This change was published to all U.S. operators of MD-80 series aircraft, but was not available in the crashed Spanair aircraft. This omission is noted in a safety recommendation issued by the NTSB (National Transportation Safety Board):
http://www.ntsb.gov/recs/letters/2009/A09_67_71.pdf (PDF)
As noted by the NTSB, the Spanair MD-82 checklist included a daily check of the TOWS system, but not prior to every takeoff. This procedure differs from the checklist issued by McDonnell Douglas in 1988 and that is used by U.S. carriers.
As the Spanair flight was preparing for departure, the Ram Air Temperature (RAT) probe was reporting an abnormally high temperature. The aircraft returned to the gate and maintenance personnel discovered that the RAT probe heater, which is only supposed to be operated in the air, was incorrectly operating on the ground. The maintenance personnel pulled the circuit breaker for the RAT probe heater and cleared the aircraft for flight, not noting the reason the RAT heater was improperly operating on the ground.
The MD-80 series aircraft contain a relay that powers the TOWS system when the aircraft is on the ground and redirects that power to the RAT heater when the aircraft is in the air. The NTSB’s tests determined that a failure in this relay could cause a failure of the TOWS system with no warning. This means the TOWS system has a single point of failure. If there was a problem with this relay, it could potentially send power to the RAT probe heater instead of the TOWS.
Based on this evidence, I believe the malware discovered on the TOWS is irrelevant to the accident in every way. The finding is interesting and proves that malware can exist on these systems, but does not seem to be a contributing factor to the accident. When the ground crews disabled the RAT probe heater, they failed to detect the malfunctioning relay, which was sending power to the RAT probe heater instead of the TOWS. With no warning that the TOWS system was not receiving power and no check of the TOWS by the pilots, the aircraft began its takeoff roll in an improper configuration with no warning.
The investigation leaves the probable cause of the accident as human error. It is ultimately the responsibility of the pilot in command for a safe flight and, while these systems enhance safety, they are not responsible for operation of the aircraft. The failure of the TOWS can be considered a contributing factor to this tragedy, but in my opinion the malware is not relevant to the TOWS failure or the accident. The official report on the accident is due in December 2010, which will reveal the probable cause and contributing factors to the accident.
|
Share This Information | Malware and the failure of aircraft systems |
| Other SecureWorks Blog Categories: |
Black Hat/DEFCON 18 Conferences Recap (Part 2)
August 6th, 2010 by Hunter KingLast Tuesday, Dennis Dwyer blogged about his experiences at DEFCON 18, a computer security conference held in Las Vegas, Nevada. This event comes after the Black Hat computer security conference, which has more of a business and corporate feel. While I did not find this year’s conference as interesting as in years past, there were a number of interesting talks. Below is a quick summation of the talks I found were the most interesting.
Continue Reading "Black Hat/DEFCON 18 Conferences Recap (Part 2)" >>|
Share This Information | Black Hat/DEFCON 18 Conferences Recap (Part 2) |
| Other SecureWorks Blog Categories: |
DEFCON 18: Conference Recap (Part 1)
August 3rd, 2010 by Dennis DwyerI just returned from this year’s DEFCON conference held in Las Vegas. Overall, it was a great time and I enjoyed meeting everyone. This year was my first time attending DEFCON and I was surprised at the number of attendees. There were so many great presentations that I wasn’t able to attend them all. Here’s a brief recap of some of the talks I enjoyed:
Continue Reading "DEFCON 18: Conference Recap (Part 1)" >>|
Share This Information | DEFCON 18: Conference Recap (Part 1) |
| Other SecureWorks Blog Categories: |
Dedicate a Separate Computer for Online Safety
June 23rd, 2010 by Don JacksonSome of the advice regarding the adoption of live CDs targets those who have never used a Live CD and are interested in learning how. That is definitely not the average user. The average user is not going to use a live CD until it’s handed to them free of headaches, especially not as long as individual financial liability is as limited as it is or until after their identity is actually ruined.
Continue Reading "Dedicate a Separate Computer for Online Safety" >>|
Share This Information | Dedicate a Separate Computer for Online Safety |
| Other SecureWorks Blog Categories: |
Space weather’s role in return to Stone Age greatly exaggerated
June 22nd, 2010 by Don JacksonThe Space Weather Enterprise Forum was held on June 8, 2010, at the National Press Club in Washington, DC. NASA, The National Aeronautic and Space Administration (NASA) and the National Oceanic and Atmospheric Administration (NOAA) are the two U.S. agencies that track space weather in near-earth space and are the stars of this conference.
Continue Reading "Space weather’s role in return to Stone Age greatly exaggerated" >>|
Share This Information | Space weather’s role in return to Stone Age greatly exaggerated |
| Other SecureWorks Blog Categories: |
Cyber Security Preparedness for the 2010 G-20 Summit
June 18th, 2010 by Don JacksonCanada will soon host the G-20 summit in Toronto, Ontario. The G-20, short for the “Group of Twenty Finance Ministers and Central Bank Governors”, meets to discuss policy and issues affecting international financial stability that are larger in scope than any one member country’s area of responsibility.
Continue Reading "Cyber Security Preparedness for the 2010 G-20 Summit" >>|
Share This Information | Cyber Security Preparedness for the 2010 G-20 Summit |
| Other SecureWorks Blog Categories: |
Windows Help Center 0-day arbitrary command execution
June 10th, 2010 by Dennis DwyerThe SecureWorks CTU(SM) is closely monitoring a 0-day vulnerability in multiple Microsoft Windows operating system releases. The vulnerability lies in how Windows handles hcp:// URLs, used to access help documents. An attacker may create a malicious hcp:// URL and distribute it to victims via an HTML web page, e-mail message, document, or a variety of other attack vectors. Successful exploitation of this vulnerability may allow an attacker to execute arbitrary commands, which may result in total system compromise.
Continue Reading "Windows Help Center 0-day arbitrary command execution" >>|
Share This Information | Windows Help Center 0-day arbitrary command execution |
| Other SecureWorks Blog Categories: |
Don’t Panic: DNSSEC isn’t DO or Die
May 4th, 2010 by Nick ChapmanRecent rumors that the Internet is doomed are just as overblown as all the rest, except perhaps when AOL started letting its users onto the Internet – a fate from which the Internet never really recovered. The current rumor relates to DNSSEC (also known as Domain Name System Security Extensions), which cryptographically signs DNS results.
Continue Reading "Don’t Panic: DNSSEC isn’t DO or Die" >>|
Share This Information | Don’t Panic: DNSSEC isn’t DO or Die |
| Other SecureWorks Blog Categories: |
Effective new techniques for identifying BitTorrent users
April 30th, 2010 by Ben FeinsteinThis week we saw the proceedings of the 3rd USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET ‘10). Past years had seen the release of plenty of novel and groundbreaking research, so expectations were high. A group of researchers from I.N.R.I.A. in France published an impressive paper on new techniques for identifying and tracking users of the BitTorrent protocol titled, “Spying the World from Your Laptop: Identifying and Profiling Content Providers and Big Downloaders in BitTorrent”
Continue Reading "Effective new techniques for identifying BitTorrent users" >>|
Share This Information | Effective new techniques for identifying BitTorrent users |
| Other SecureWorks Blog Categories: |
Your Malware Settings May Have Changed
April 28th, 2010 by Nick ChapmanAn overview of a malicious script (Emold downloader trojan) that was delivered to many email addresses Tuesday evening and Wednesday morning.
Continue Reading "Your Malware Settings May Have Changed" >>|
Share This Information | Your Malware Settings May Have Changed |
| Other SecureWorks Blog Categories: |