Computer hackers 'could bring rail network to a standstill' warns security expert - but would we even notice?
New switching systems are vulnerable to attack
Simplest form of cyber attack could paralyse network
'Could not cause crashes' says expert - but could cause delays
By ROB WAUGH
Mail Online
Last updated at 4:13 PM on 28th December 2011
Railway systems have become vulnerable to the simplest form of cyber attack - one that can easily be mastered by relatively unskilled teenage hackers.
Anyone who knows how to unleash a 'denial of service' attack could bring train services to a standstill, a German security expert said this week.
The vulnerability is due to mobile phone signals used to link railway switching systems together - and would allow hackers to cause massive service disruption.
'Denial of service' campaigns are one of the simplest forms of cyber attack - where hackers recruit large numbers of computers to overwhelm the targeted system with Internet traffic.
The attacks require far less skill than penetrating a computer network or writing malicious software.
Hackers have used the approach to attack sites of government agencies around the world and sites of businesses.
Stefan Katzenbeisser, professor at Technische Universität Darmstadt in Germany, said switching systems were at risk of 'denial of service' attacks, which could cause long disruptions to rail services.
'Trains could not crash, but service could be disrupted for quite some time,' said Katzenbeisser.
Train switching systems, which enable trains to be guided from one track to another at a railway junction, have historically been separate from the online world, but communication between trains and switches is handled increasingly using wireless technology.
The use of 'connected' systems renders them vulnerable to cyber attack.
Train networks have become more vulnerable in recent years as separate switching systems have become connected via wireless signals.
Katzenbeisser said GSM-R - standing for GSM-railway - a mobile technology used for train communications, is more secure than the usual GSM, used in phones.
But it's still vulnerable to hackers who manage to lay hands on one security key.
'Probably we will be safe on that side in coming years. The main problem I see is a process of changing security keys. This will be a big issue in the future, how to manage these keys safely,' Katzenbeisser said.
The software encryption ‘keys’, which are needed for securing the communication between trains and switching systems, are downloaded to physical media like USB sticks and then sent to offices to be installed - raising the risk of them ending up in the wrong hands.
If one of the keys was lost, hackers could then attack and overwhelm a railway network's switching system.
Computer hackers 'could bring rail network to a standstill'
Moderator: John Ashworth
- John Ashworth
- Site Admin
- Posts: 23606
- Joined: 24 Jan 2007, 14:38
- Location: Nairobi, Kenya
- Contact:
- John Ashworth
- Site Admin
- Posts: 23606
- Joined: 24 Jan 2007, 14:38
- Location: Nairobi, Kenya
- Contact:
Re: Computer hackers 'could bring rail network to a standsti
BBC 28 December 2011 Last updated at 15:40 GMT
Train-switching technology 'poses hacking threat'
A shift to a mobile communications technology could expose rail networks to hackers, according to a security expert.
Prof Stefan Katzenbeisser made the claim at the Chaos Communication Congress in Berlin.
The professor said that the systems which switch trains from one line to another could be shut down if encryption keys went astray.
He stressed that trains would not be in danger, but there could be delays.
Train-switching systems have historically been controlled by proprietary analogue systems.
At the end of the last century, more than 35 incompatible systems were used for railway communications across Europe.
GSM-R roll-out
A group of manufacturers met to address this and decided to switch to a single digital standard to ensure they could source replacement parts and make different companies' systems interoperable.
They developed GSM-Railway (GSM-R), a more secure version of the 2G wireless standard used by mobile phones.
It allows traffic controllers and train drivers to talk to each other, and for data to be transmitted recording the vehicle's speed and location. The control centre then uses the data to give the train permission to enter the next part of the track, theoretically making trackside signals unnecessary.
The technology is already being used in parts of Europe, Africa and Asia. Network Rail is rolling it out in the UK and aims to cover all Britain's rail lines by the end of 2014.
USB sticks
Prof Katzenbeisser believes the system is relatively secure from hackers under normal circumstances. However, the computer science expert from Technische Universitat Darmstadt warns that encryption keys, used to protect the communications, could pose risks.
"The main problem I see is a process of changing... keys. This will be a big issue in the future, how to manages these keys safely," he told Reuters news agency at the conference.
The news agency said the keys are downloaded to physical media such as USB sticks before being distributed for installation.
It said the risk would occur if one of them fell into the wrong hands. This could allow hackers to mount a denial of service attack by overwhelming the signals system with traffic, forcing it to shut down.
"Trains could not crash, but services could be disrupted for some time," the professor said.
However, a spokesman for Network Rail played down the risk.
"GSM-R is a robust and secure system and Network Rail does not comment in detail on security," PJ Taylor, head of national news at Network Rail, told the BBC.
Train-switching technology 'poses hacking threat'
A shift to a mobile communications technology could expose rail networks to hackers, according to a security expert.
Prof Stefan Katzenbeisser made the claim at the Chaos Communication Congress in Berlin.
The professor said that the systems which switch trains from one line to another could be shut down if encryption keys went astray.
He stressed that trains would not be in danger, but there could be delays.
Train-switching systems have historically been controlled by proprietary analogue systems.
At the end of the last century, more than 35 incompatible systems were used for railway communications across Europe.
GSM-R roll-out
A group of manufacturers met to address this and decided to switch to a single digital standard to ensure they could source replacement parts and make different companies' systems interoperable.
They developed GSM-Railway (GSM-R), a more secure version of the 2G wireless standard used by mobile phones.
It allows traffic controllers and train drivers to talk to each other, and for data to be transmitted recording the vehicle's speed and location. The control centre then uses the data to give the train permission to enter the next part of the track, theoretically making trackside signals unnecessary.
The technology is already being used in parts of Europe, Africa and Asia. Network Rail is rolling it out in the UK and aims to cover all Britain's rail lines by the end of 2014.
USB sticks
Prof Katzenbeisser believes the system is relatively secure from hackers under normal circumstances. However, the computer science expert from Technische Universitat Darmstadt warns that encryption keys, used to protect the communications, could pose risks.
"The main problem I see is a process of changing... keys. This will be a big issue in the future, how to manages these keys safely," he told Reuters news agency at the conference.
The news agency said the keys are downloaded to physical media such as USB sticks before being distributed for installation.
It said the risk would occur if one of them fell into the wrong hands. This could allow hackers to mount a denial of service attack by overwhelming the signals system with traffic, forcing it to shut down.
"Trains could not crash, but services could be disrupted for some time," the professor said.
However, a spokesman for Network Rail played down the risk.
"GSM-R is a robust and secure system and Network Rail does not comment in detail on security," PJ Taylor, head of national news at Network Rail, told the BBC.