The
report (PDF), titled "Review of Web Applications Security and Intrusion Detection in Air Traffic Control Systems," summarizes the results of a security audit.
The audit was undertaken to see if the increasing use of commercial software and Web applications by the FAA -- mostly to provide public information -- is making its systems more vulnerable to cyber-attack.
Investigators also wanted to see if the systems' intrusion-detecting capabilities were effectively monitoring security incidents.
According to the report, the agency's systems failed on both counts.
The investigators managed to gain unauthorized access to air traffic control (ATC) systems in several places. They also found that intrusion detection sensors have been installed at only 11 operational facilities (out of hundreds).
So far, the incidents have mainly disrupted the ATC support systems, not the actual operational systems. The report's authors warn that attacks can easily bridge that gap.
"In our opinion, unless effective action is taken quickly, it is likely to be a matter of when, not if, ATC systems encounter attacks that do serious harm to ATC operations," reads the report.
The report concludes with several recommendations, which boil down to "do more, do it better, do it quicker."