• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Claims that new signalling "could be hacked...."

Status
Not open for further replies.
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Baggypants

Member
Joined
24 Jul 2013
Messages
44
I refer you to:
http://www.railforums.co.uk/showthread.php?t=115293

To paraphrase; the code visible was NOT the access code.

Writing down logins and passwords for ANYTHING is a silly state of affairs. All that other thread means to me is they got away with it this time.

Don't forget the the original article that kicked it off was talking about a rogue insider. The fact stuff is taped to a screen, even if it's just their phone unlock code, points to poor security practice and opportunities for mischief.
 

Jamesb1974

Member
Joined
20 Mar 2006
Messages
596
So a guy from a bedroom in Hounslow is fighting extradition to USA charged with bringing down the American banking system but it's impossible/unlikely for anyone to hack into the UK signalling system?! I admit it's about as unlikely as a pilot choosing to deliberately crash his plane taking all his passengers and co-workers with him. Yes, right, think on. We're British, it can't possibly happen to us, being in denial is the national trait, among the English at least, hence UKIP.

Nice bit of topical comment and casual racism to kick things off. Moving on...

1) The 'guy in his bedroom in Hounslow', Navinder Singh Sarao also made a $40 million dollar profit on his trades (which he had legitimate access to via his work as a trader).

2) Andreas Lubitz had already mentioned that he wanted to do something "spectacular and unforgettable", again by his legitimate access to the cockpit. He killed 149 innocent people.

The common trends? Legitimate access plus minimum effort, maximum effect. Neither of those two mentioned had to do anything out of the ordinary to bring about their respective effects. Even a rogue insider would have to hack the system to defeat the inbuilt interlocking. But we are talking about outside influences hacking into a secure system to alter it for nefarious effect.

No one said that "it can't possibly happen to us" (and how is UKIP relevant by the way?) What was said that in the framework of terrorists or other groups wanting to cause mass casualties, it would be unlikely. Think about it. Hack into a secure computer system or ram a stolen HGV through some automatic half barriers as a train is approaching? A hacking attack has every chance of failure, not least because it would require (and I'll repeat myself for the hard of understanding) hacking at EVERY level of ERTMS. Not just the signalling station, but the train itself, plus everything else that goes with it. Not just a laptop attached to a cable somewhere, but the actual on train equipment, plus point operating equipment etc etc.

A HGV or other obstruction placed across the running line or for that matter, an explosive device placed on a train or station would have every chance of success. Why? Because it's simple and can't be planned for. When was the last time YOUR bag was checked getting on a train? Or when was the last time that the vehicle at the front of queue at a AHBC was checked by the police? In fact, when was the last time anyone other than a few spotters with cameras were stopped by police and/or security at a major railway station? Millions of people walk in and out of stations carrying bags, rucksacks, suitcases every single day. An attacker would just blend in unnoticed. Simple attacks like explosive devices or obstructions on the line would be far more likely than an expensive and potentially fail-worthy hacking attempt, purely because they are simple, difficult to disrupt and cause maximum devastation.

Terror groups want MASS casualties. They WANT to shock, to cause revulsion to (In Andreas Lubitz own words) cause something "spectacular and unforgettable". Fiddling with ERTMS so as to have the chance to cause an accident (not even a 100% chance as there are drivers on-board who can stop the trains, plus signallers in the signalling stations; someone still has to set the route the train is travelling over and they can send out emergency stop messages via GSMR or even the ERTMS itself) has so many flaws and pitfalls that I, personally would consider it unlikely to happen. Plus, its a one off event. The first time it gets hacked, the system gets redesigned or has its security enhanced so the attacker has to start again. While I'm sure that no computer system is infallible, I'm equally sure that the people who design and implement them may have thought about hacking access. ERTMS has been in development since 1990 http://www.ertms.net/?page_id=49 Do you think that at some point in it's 25 year development (a process that is still ongoing) the people at the sharp end may have considered the feasibility of external hacking, or did you think that they waited for good Professor to rock up on the BBC and suddenly think "Shiiiiiiiiiiiiiiiiiii*e! We hadn't thought of that! Back to the drawing board lads.."?

And, don't forget that modern passenger rolling stock is extremely crash worthy. Great Heck was the highest speed railway accident the UK has seen so far. Every one of the ten deaths in that crash will be sorely missed by their loved ones, but it is a credit to modern rolling stock design that more people weren't killed. As we saw on 7/7, you cannot prevent someone with an explosive device getting on-board a packed train (or bus for that matter). It is simple and sadly, deadly effective and one I think is far more likely to happen than some SPECTRE like agency pouring it's naughty resources into hacking ERTMS.
 
Last edited:

Busaholic

Veteran Member
Joined
7 Jun 2014
Messages
14,671
Nice bit of topical comment and casual racism to kick things off. Moving on...

1) The 'guy in his bedroom in Hounslow', Navinder Singh Sarao also made a $40 million dollar profit on his trades (which he had legitimate access to via his work as a trader).

2) Andreas Lubitz had already mentioned that he wanted to do something "spectacular and unforgettable", again by his legitimate access to the cockpit. He killed 149 innocent people.

The common trends? Legitimate access plus minimum effort, maximum effect. Neither of those two mentioned had to do anything out of the ordinary to bring about their respective effects. Even a rogue insider would have to hack the system to defeat the inbuilt interlocking. But we are talking about outside influences hacking into a secure system to alter it for nefarious effect.

No one said that "it can't possibly happen to us" (and how is UKIP relevant by the way?) What was said that in the framework of terrorists or other groups wanting to cause mass casualties, it would be unlikely. Think about it. Hack into a secure computer system or ram a stolen HGV through some automatic half barriers as a train is approaching? A hacking attack has every chance of failure, not least because it would require (and I'll repeat myself for the hard of understanding) hacking at EVERY level of ERTMS. Not just the signalling station, but the train itself, plus everything else that goes with it. Not just a laptop attached to a cable somewhere, but the actual on train equipment, plus point operating equipment etc etc.

A HGV or other obstruction placed across the running line or for that matter, an explosive device placed on a train or station would have every chance of success. Why? Because it's simple and can't be planned for. When was the last time YOUR bag was checked getting on a train? Or when was the last time that the vehicle at the front of queue at a AHBC was checked by the police? In fact, when was the last time anyone other than a few spotters with cameras were stopped by police and/or security at a major railway station? Millions of people walk in and out of stations carrying bags, rucksacks, suitcases every single day. An attacker would just blend in unnoticed. Simple attacks like explosive devices or obstructions on the line would be far more likely than an expensive and potentially fail-worthy hacking attempt, purely because they are simple, difficult to disrupt and cause maximum devastation.

Terror groups want MASS casualties. They WANT to shock, to cause revulsion to (In Andreas Lubitz own words) cause something "spectacular and unforgettable". Fiddling with ERTMS so as to have the chance to cause an accident (not even a 100% chance as there are drivers on-board who can stop the trains, plus signallers in the signalling stations; someone still has to set the route the train is travelling over and they can send out emergency stop messages via GSMR or even the ERTMS itself) has so many flaws and pitfalls that I, personally would consider it unlikely to happen. Plus, its a one off event. The first time it gets hacked, the system gets redesigned or has its security enhanced so the attacker has to start again. While I'm sure that no computer system is infallible, I'm equally sure that the people who design and implement them may have thought about hacking access. ERTMS has been in development since 1990 http://www.ertms.net/?page_id=49 Do you think that at some point in it's 25 year development (a process that is still ongoing) the people at the sharp end may have considered the feasibility of external hacking, or did you think that they waited for good Professor to rock up on the BBC and suddenly think "Shiiiiiiiiiiiiiiiiiii*e! We hadn't thought of that! Back to the drawing board lads.."?

And, don't forget that modern passenger rolling stock is extremely crash worthy. Great Heck was the highest speed railway accident the UK has seen so far. Every one of the ten deaths in that crash will be sorely missed by their loved ones, but it is a credit to modern rolling stock design that more people weren't killed. As we saw on 7/7, you cannot prevent someone with an explosive device getting on-board a packed train (or bus for that matter). It is simple and sadly, deadly effective and one I think is far more likely to happen than some SPECTRE like agency pouring it's naughty resources into hacking ERTMS.

The point of my provocative post was that complacency is a disease which has a grip in this country, never more so than at this endlessly-prolonged pre-election time when all the real issues are being ignored or brushed rapidly under the carpet e.g. how pensions or care for old people is going to be funded in this country, and what will happen when no ordinary person will be able to do internet banking any longer without taking all day over the simplest transaction and changing their password at the end of it. Give someone with basic computer skills and a motive (someone looking at him wrongly on the tube that morning, for instance) and the wherewithal granted by linking signalling systems together for standardisation, tidiness,etc (i.e. the customary mindset of the bureaucrat) and **** will happen, if you'll pardon my Hendyism. Why I said English (not sure one can be even casually racist about oneself) was because, though I would much regret Scotland gaining independence, the Scots are showing they can see through the veneer, and I expect the Welsh do to to a large extent, whereas England is expected to produce a majority of Tory seats with a lot of UKIP support too thus proving, to me at least, that some peoople really can be fooled all the time.
 

Pigeon

Member
Joined
8 Apr 2015
Messages
1,123
Nothing that has been said about ERTMS precludes the possibility of it being attacked.

It has been argued that abusing it to create a collision is very difficult, that's all. "Very difficult" has then been misinterpreted to mean "impossible", when what it actually means is "possible". And also "comparatively straightforward once you have the necessary information", which is all available if you're sufficiently determined to get hold of it.

Talk of terrorism and induced collisions is missing the point. Yes, it is far simpler to drive a Land Rover onto the track when two trains are about to cross at speed, but that doesn't mean there is no risk of ERTMS being attacked; it is just one of many reasons why that particular threat is very low on the scale.

You don't need to be able to produce an unavoidable collision. You just need to be able to present a credible threat of widespread disruption, which is much easier. Trying to attack multiple elements of a system to produce a specific outcome (collision at specific location/time) is a lot more difficult than attacking whichever element of the system is easiest to produce the very unspecific effect of simply being unable to rely on its safe operation.

A far more significant threat than terrorism is that of well-organised, well-resourced attacks by government black ops organisations. The US has done this, successfully, on various occasions: two that spring to mind are disabling the Iranian uranium enrichment plant (which was done by knowing the details and vulnerabilities of several different interacting systems, including bypassing air-gaps) and blowing up a gas pipeline in Russia (by supplying the Russians with crocked software which they were unable to adequately check).

China is well known to have a significant and sophisticated cyber-attack capability, and there is concern in various quarters over the possibility of massive disruption of Western telecommunications systems by China using back doors in Chinese-manufactured telecoms infrastructure hardware.

Although it is a railway-specific system under discussion, railway-specific knowledge is actually of little value outside picking nits over various highly specific individual attack modes which are in any case unlikely for several other reasons. The appropriate disciplines to assess and deal with the threat are computer security and military strategic asset protection.

There are also likely to be significant disciplinary-culture aspects which put the railway specialism at a disadvantage in evaluating the threat even where it is applicable. Railways have historically never had to consider external threats at all, and have been thoroughly useless at defending against internal threats because they habitually trust people not to try and beat the system - examples: Audenshaw Junction accident, where not only was the signalling equipment so poorly designed as to have exposed electrical contacts in the first place, but those contacts were so positioned as to make it trivial to defeat the interlocking by shorting them with any handy piece of metal, and correct safe operation relied on trusting people not to do this; the Connington South derailment, caused by an absolute tit of a signalman deliberately seeking "holes" in the interlocking which allowed him to move the points under the train; and the recent SPAD at Wootton Bassett, where the TPWS/AWS actuation valve had a readily-accessible handwheel to shut it off and correct safe operation relied on trusting people not to turn it, which demonstrates that the culture of designing systems on the assumption that they will not be abused is still alive and well.

From a computer security point of view, all three of these instances are examples of shockingly bad design of a kind that would be unacceptable even in non-safety-critical systems: if the possibility of someone using the system in an unintended manner exists at all, then you can be sure that sooner or later someone will do it, and it matters not at all that they're "not supposed to"; you don't rely on rules to prevent it, you rely on system design that does not present such possibilities in the first place. This is, of course, an exceedingly complex business, and one which - with few exceptions - the railways have avoided acknowledging, instead relying on rules-and-trust and never developing any better security.
 

tranzitjim

Member
Joined
4 Jun 2013
Messages
211
Location
Australia
Ok, I have some questions about this system.

Will you have one central server managing all traffic around the country?

How will the driver know he/she is facing a stop signal. Will it be in cab, or by trackside signal masts.

If it is 'in cab signalling', then how does the train cab get their signal communication?

How does the system detect where each train is, and how is that sent to the central server?
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,715
Location
Scotland
Ok, I have some questions about this system.

Will you have one central server managing all traffic around the country?

How will the driver know he/she is facing a stop signal. Will it be in cab, or by trackside signal masts.

If it is 'in cab signalling', then how does the train cab get their signal communication?

How does the system detect where each train is, and how is that sent to the central server?
A little light reading should answer your questions.
 

Llanigraham

On Moderation
Joined
23 Mar 2013
Messages
6,489
Location
Powys
There are too many people on here who have done NO research into ERTMS but are still making incorrect comments about it!!
 

martynbristow

Member
Joined
15 Jun 2005
Messages
426
Location
Birkenhead
Nothing that has been said about ERTMS precludes the possibility of it being attacked.

It has been argued that abusing it to create a collision is very difficult, that's all. "Very difficult" has then been misinterpreted to mean "impossible", when what it actually means is "possible". And also "comparatively straightforward once you have the necessary information", which is all available if you're sufficiently determined to get hold of it.

Talk of terrorism and induced collisions is missing the point. Yes, it is far simpler to drive a Land Rover onto the track when two trains are about to cross at speed, but that doesn't mean there is no risk of ERTMS being attacked; it is just one of many reasons why that particular threat is very low on the scale.

You don't need to be able to produce an unavoidable collision. You just need to be able to present a credible threat of widespread disruption, which is much easier. Trying to attack multiple elements of a system to produce a specific outcome (collision at specific location/time) is a lot more difficult than attacking whichever element of the system is easiest to produce the very unspecific effect of simply being unable to rely on its safe operation.

A far more significant threat than terrorism is that of well-organised, well-resourced attacks by government black ops organisations. The US has done this, successfully, on various occasions: two that spring to mind are disabling the Iranian uranium enrichment plant (which was done by knowing the details and vulnerabilities of several different interacting systems, including bypassing air-gaps) and blowing up a gas pipeline in Russia (by supplying the Russians with crocked software which they were unable to adequately check).

China is well known to have a significant and sophisticated cyber-attack capability, and there is concern in various quarters over the possibility of massive disruption of Western telecommunications systems by China using back doors in Chinese-manufactured telecoms infrastructure hardware.

Although it is a railway-specific system under discussion, railway-specific knowledge is actually of little value outside picking nits over various highly specific individual attack modes which are in any case unlikely for several other reasons. The appropriate disciplines to assess and deal with the threat are computer security and military strategic asset protection.

There are also likely to be significant disciplinary-culture aspects which put the railway specialism at a disadvantage in evaluating the threat even where it is applicable. Railways have historically never had to consider external threats at all, and have been thoroughly useless at defending against internal threats because they habitually trust people not to try and beat the system - examples: Audenshaw Junction accident, where not only was the signalling equipment so poorly designed as to have exposed electrical contacts in the first place, but those contacts were so positioned as to make it trivial to defeat the interlocking by shorting them with any handy piece of metal, and correct safe operation relied on trusting people not to do this; the Connington South derailment, caused by an absolute tit of a signalman deliberately seeking "holes" in the interlocking which allowed him to move the points under the train; and the recent SPAD at Wootton Bassett, where the TPWS/AWS actuation valve had a readily-accessible handwheel to shut it off and correct safe operation relied on trusting people not to turn it, which demonstrates that the culture of designing systems on the assumption that they will not be abused is still alive and well.

From a computer security point of view, all three of these instances are examples of shockingly bad design of a kind that would be unacceptable even in non-safety-critical systems: if the possibility of someone using the system in an unintended manner exists at all, then you can be sure that sooner or later someone will do it, and it matters not at all that they're "not supposed to"; you don't rely on rules to prevent it, you rely on system design that does not present such possibilities in the first place. This is, of course, an exceedingly complex business, and one which - with few exceptions - the railways have avoided acknowledging, instead relying on rules-and-trust and never developing any better security.
Yes that agreed, most point have been raised previously.
The issue is why bother! You can inflict similar damage in easier ways. The system relies on radio communication, this can be jammed or interfered with and you can still steal cables causing the same damage :/
With regards to black ops ... That's referred to as state sponsored terrorism effectively.
The conclusion of the initial report is it would need some knowledge from inside which is difficult.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,587
Location
Torbay
Nothing that has been said about ERTMS precludes the possibility of it being attacked.

It has been argued that abusing it to create a collision is very difficult, that's all. "Very difficult" has then been misinterpreted to mean "impossible", when what it actually means is "possible". And also "comparatively straightforward once you have the necessary information", which is all available if you're sufficiently determined to get hold of it . . .

. . . You don't need to be able to produce an unavoidable collision. You just need to be able to present a credible threat of widespread disruption, which is much easier. Trying to attack multiple elements of a system to produce a specific outcome (collision at specific location/time) is a lot more difficult than attacking whichever element of the system is easiest to produce the very unspecific effect of simply being unable to rely on its safe operation.

All of the above could apply equally to any existing and historic signalling methods whether miscreants were to use a simple battery to light the wrong lamp in a signal head as with the 1960s great train robbery, or were to stage a local signalbox takeover, St Trinians style.

The key trend in signalling since the beginning of railways has been greater centralisation. After railway policemen were removed from the trackside to the first signal boxes, mechanical installations at each end of a major station were combined, with track circuits substituting for direct visibility. Then relay interlockings and electric point machines were provided to combine further with the goods yard box a mile down the line, following which the development of affordable telemetry techniques in the 1960s led to much larger areas consolidated under large panel signalboxes.

Each time the control centres became larger, their physical security measures improved as befitted their more strategic wider areas of influence, and security and reliability of the new remote control links was ensured by routing them via railway owned trackside cables. The latest control consolidation strategy to concentrate all signalling control progressively to a small number of ROCs is merely a continuation of this historical trend. As a precursor to this, most railway remote control links from PSB to local interlocking and between central interlockings and trackside signalling sensors and actuators have migrated to the railway owned Fixed Telecommunications Network (FTN), a highly redundant dedicated nationwide system of trackside fibres and transmission hubs established by Network Rail that also carries safety critical voice communications between the local GSM-R cells and the control centres. This network is clearly not part of or connected in any way to the public internet.

So with a dedicated private network in order to attack the current signalling system virtually you actually still have to access railway assets or premises physically first.

ETCS level 2 and above changes this clearly. Whilst control centre commands and interlocking functionality will still be completely isolated from the internet and will continue to be confined entirely to the private FTN, the final link in the chain from local GSM-R cell to train will take place over a radio air gap which cannot be entirely isolated physically. Assuming some group had a suitable transceiver within close range of wherever they wanted to attack, they could theoretically set up a means to broadcast malicious messages. With all the encryption and other methods used by GSM and the ETCS computers to verify the message stream it is extremely unlikely a viable attack could result in false movement authority being interpreted, but a denial of service attack IS conceivable, where such a broadcast could swamp train computers into failing safely and stopping traffic. However just like attacking a railway policemen in the 1840s, the effects of this would be local, only affecting the local GSM-R cell concerned and the trains in its immediate area, although if a major junction was targeted that could cause significant knock-on disruption clearly. To do something similar on a much wider scale, a group would need a whole cell network of their own to mirror the railway controlled one.

ETCS has been in development by all of Europe's railway administrations and a group of manufacturers for around two decades now. Between them they have managed to achieve suitable safety accreditation for the system to be rolled out across the continent, and they have employed consultants and academics from many fields constantly to provide the kind of independent oversight needed, including in the security field. This is an ongoing process clearly, and whilst one standard system across Europe raises risks in itself, it also means the mitigation efforts can be tackled collectively.

. . . the recent SPAD at Wootton Bassett, where the TPWS/AWS actuation valve had a readily-accessible handwheel to shut it off and correct safe operation relied on trusting people not to turn it, which demonstrates that the culture of designing systems on the assumption that they will not be abused is still alive and well. . . examples of shockingly bad design of a kind that would be unacceptable even in non-safety-critical systems: if the possibility of someone using the system in an unintended manner exists at all, then you can be sure that sooner or later someone will do it, and it matters not at all that they're "not supposed to"; you don't rely on rules to prevent it, you rely on system design that does not present such possibilities in the first place. This is, of course, an exceedingly complex business, and one which - with few exceptions - the railways have avoided acknowledging, instead relying on rules-and-trust and never developing any better security.

Whilst I agree with some of those points, it is simply not true that systems are or were designed on the basis that abuses will not happen. That was the whole point of interlocking, as required along with block systems and continuous brakes from the 1870s, and whilst it is true in old mechanical boxes signallers could surreptitiously lift electric locks and the like with little fear of getting caught, modern systems are not nearly so easy to defeat. The steam SPAD incident is very unfortunate I agree but the particular vulnerability is probably a result of a fairly poor bespoke design for fitting these protection systems to steam traction and does not represent the state of the art with respect to any other traction. It is doubly unfortunate that lax procedures or training or discipline on the footplate then resulted in the incident, when the known shortcomings of older equipment, including the higher risk to these operator's own passengers in the Mk1 vehicles compared to more modern trains, should and must engender the very highest levels of vigilance, caution and skill on the part of the train crew.
 

carriageline

Established Member
Joined
11 Jan 2012
Messages
1,897
Plus, he says you should create safety by design, not by trusting people to behave.

But sorry, I can't see how that's possible. In the TPWS example you need to provide something to isolate the TPWS in case the system fails. Otherwise when it fails, the train will just sit there. How can you create a system that knows if it's failed or not?
 

anme

Established Member
Joined
8 Aug 2013
Messages
1,777
Nothing that has been said about ERTMS precludes the possibility of it being attacked.

It has been argued that abusing it to create a collision is very difficult, that's all. "Very difficult" has then been misinterpreted to mean "impossible", when what it actually means is "possible". And also "comparatively straightforward once you have the necessary information", which is all available if you're sufficiently determined to get hold of it.

I'm very interested in the statement in bold. Please could you elaborate? What exactly is this necessary information and where can it be found? How determined would someone have to be to get it?
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,587
Location
Torbay
Plus, he says you should create safety by design, not by trusting people to behave.

But sorry, I can't see how that's possible. In the TPWS example you need to provide something to isolate the TPWS in case the system fails. Otherwise when it fails, the train will just sit there. How can you create a system that knows if it's failed or not?

Agreed, but it shouldn't be so easy to override, or release brakes and take power again so quickly. I don't know for sure, but I would expect with modern traction when an isolation is made it wouldn't override the initial emergency brake application as appears to have occurred here. There was also a comment in the suspension notice about procedures associated with breakable seals on such devices, so it may be there wasn't a proper system in place for that by the operator generally or just on that particular locomotive.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,587
Location
Torbay
We manage it in aerospace! Slightly more incentive to do so there though...

At least on the railways if we are unsure in any way or if all else fails normally we can always slam on the brakes and come to a safe stand, knowing that any other trains nearby will also be able to stop clear of us. Unfortunately, that failed in this particular SPAD case and just goes to show how things can escalate if a primary safety system is defeated. At least in the air you have three dimensions in which to steer out of the way (if there's space clearly) whilst the one-dimensionality of rails tends to reinforce the inevitability of a bad outcome after the initiating event.
 

Stompehh

Member
Joined
5 Apr 2013
Messages
182
At least on the railways if we are unsure in any way or if all else fails normally we can always slam on the brakes and come to a safe stand, knowing that any other trains nearby will also be able to stop clear of us.

Indeed, that was the point I was trying to make. In the air, if something critical fails in an unsafe manner, there is only one way the aircraft is going to go, so systems are designed with very high levels of redundancy, dissimilarity and monitoring. However, developing to this level is EXTREMELY expensive.

In rail, if there is a failure you can, as you say, whack the anchors on (and for most failures this will happen automatically) and everything will be fine as you aren't going anywhere. To develop systems to the level of those in aerospace would be cost-prohibitive and entirely unnecessary.
 

Jamesb1974

Member
Joined
20 Mar 2006
Messages
596
It's great all this speculation, isn't it? If hacking computer systems is so easy, why is armed robbery still alive and well? Why not just hack the ATM's and get them to pour cash out? Very occasionally (ie, two or three times every few years) we see a news article about someone going to an ATM and it spewing money out, but that is due to a computer 'glitch' or some other gremlin. However, virtually every week we see a story about someone in a £3.99 mask hitting a security guard over the bonce with a stick and stealing the box the money is in. Why is this so? Because it is simple and effective. Nobody goes to the lengths of hacking ATM's because it simply isn't worth the risk/time to do it when a far simpler alternative is available.

Why is ERTMS suddenly flavour of the month when it comes to a security risk? Think of all the lonely signal boxes scattered around the network, where all the signaller has for company is his block bells and a kettle? Why not storm into one of them and 'arrange' a crash? That would be far simpler. Bump off the poor bobby and wreak havoc.

If and when ERTMS is hacked and a crash is arranged by some shadowy figure with a diabolical laugh, I will eat my own head wear live on the internet. Unless I get hacked that is..
 

martynbristow

Member
Joined
15 Jun 2005
Messages
426
Location
Birkenhead
It's great all this speculation, isn't it? If hacking computer systems is so easy, why is armed robbery still alive and well? Why not just hack the ATM's and get them to pour cash out? Very occasionally (ie, two or three times every few years) we see a news article about someone going to an ATM and it spewing money out, but that is due to a computer 'glitch' or some other gremlin. However, virtually every week we see a story about someone in a £3.99 mask hitting a security guard over the bonce with a stick and stealing the box the money is in. Why is this so? Because it is simple and effective. Nobody goes to the lengths of hacking ATM's because it simply isn't worth the risk/time to do it when a far simpler alternative is available.

Why is ERTMS suddenly flavour of the month when it comes to a security risk? Think of all the lonely signal boxes scattered around the network, where all the signaller has for company is his block bells and a kettle? Why not storm into one of them and 'arrange' a crash? That would be far simpler. Bump off the poor bobby and wreak havoc.

If and when ERTMS is hacked and a crash is arranged by some shadowy figure with a diabolical laugh, I will eat my own head wear live on the internet. Unless I get hacked that is..

Very good point.
With respect to the ATMs just watch Horizon 2013/4s defeating the hackers. Someone figured out how to dispense money.
Stealing money is very easy electronically it's getting away with it that's hard!
It comes down to expertise, hacking isn't easy, although everyone claims to be a computer whiz could they actually *hack* a protected system?
 

Pigeon

Member
Joined
8 Apr 2015
Messages
1,123
Why would someone bother to attack an ATM when it's easier, more lucrative, and less risky to create a virus that monitors keyboard input and collects bank/card details?

People do do it, sure, but for most people so inclined the money is not a motivation - not because they're rich, but because it's boring. They are more likely to ignore the money and instead change "insert card" to "insert penis" because it's funny.

Plus, he says you should create safety by design, not by trusting people to behave.

But sorry, I can't see how that's possible. In the TPWS example you need to provide something to isolate the TPWS in case the system fails. Otherwise when it fails, the train will just sit there. How can you create a system that knows if it's failed or not?

By numerous methods, depending on how you want it to respond in the case of failure. On an aircraft where you have to keep going no matter what it can get very complicated - multiple redundant systems and the like. On the railways where you can just bring everything to a halt until it's sorted out it can be very simple indeed, like weighting signal arms to return to danger if the wire breaks.

Certainly there is a need to be able to isolate TPWS in case it fails, but there are no circumstances in which it is either necessary or permissible to do it with the train in motion. Accordingly there is no need to locate the valve inside the cab. AFAICT they just do that because it's easier. Instead, it should be somewhere outside the cab, where it is only accessible with the train at a halt; and the standards to which one has to work when fitting a steam loco with TPWS should specify this.

...security and reliability of the new remote control links was ensured by routing them via railway owned trackside cables. ... ...the railway owned Fixed Telecommunications Network (FTN), a highly redundant dedicated nationwide system of trackside fibres and transmission hubs established by Network Rail that also carries safety critical voice communications between the local GSM-R cells and the control centres. This network is clearly not part of or connected in any way to the public internet.

So with a dedicated private network in order to attack the current signalling system virtually you actually still have to access railway assets or premises physically first.

Trackside cabling is not remotely secure. You've got all the hours of darkness to visit some bit of line in the middle of nowhere and do what you want at your leisure without anyone seeing you. Like stealing miles of it; AIUI a large part of the reason for moving to fibre is that it doesn't have the scrap value that copper does. Of course fibre is harder to tap than copper, but it is still possible, especially when you've got many hours to get it done. Having said all that, it's unlikely that anyone would bother.

ETCS level 2 and above changes this clearly. Whilst control centre commands and interlocking functionality will still be completely isolated from the internet and will continue to be confined entirely to the private FTN, the final link in the chain from local GSM-R cell to train will take place over a radio air gap which cannot be entirely isolated physically. Assuming some group had a suitable transceiver within close range of wherever they wanted to attack, they could theoretically set up a means to broadcast malicious messages. With all the encryption and other methods used by GSM and the ETCS computers to verify the message stream it is extremely unlikely a viable attack could result in false movement authority being interpreted, but a denial of service attack IS conceivable, where such a broadcast could swamp train computers into failing safely and stopping traffic. However just like attacking a railway policemen in the 1840s, the effects of this would be local, only affecting the local GSM-R cell concerned and the trains in its immediate area, although if a major junction was targeted that could cause significant knock-on disruption clearly. To do something similar on a much wider scale, a group would need a whole cell network of their own to mirror the railway controlled one.

Too complicated. As I said before the idea of someone aiming to bring about a collision is largely a red herring; it is merely necessary to present a credible threat of disruption. A DoS attack suffices, and neither knowledge of protocols nor a private cell network are required. You simply need to radiate enough power at the right frequency to overload the front end of the receiver. You don't need to do this continuously, either; intermittent short-duration bursts will do. A device to do this - remote-controlled for preference - can be made cheaply, easily, and small enough to be more or less impossible to find when it isn't transmitting. A group could make large numbers of these and deploy them at numerous random locations close to main lines and junctions to gain the ability to stop trains on any part of the network at will. Finding the devices would be a major operation and you could never be sure you'd got them all; preventing them being deployed is impossible.
 

martynbristow

Member
Joined
15 Jun 2005
Messages
426
Location
Birkenhead
Trackside cabling is not remotely secure. You've got all the hours of darkness to visit some bit of line in the middle of nowhere and do what you want at your leisure without anyone seeing you. Like stealing miles of it; AIUI a large part of the reason for moving to fibre is that it doesn't have the scrap value that copper does. Of course fibre is harder to tap than copper, but it is still possible, especially when you've got many hours to get it done. Having said all that, it's unlikely that anyone would bother.



Too complicated. As I said before the idea of someone aiming to bring about a collision is largely a red herring; it is merely necessary to present a credible threat of disruption. A DoS attack suffices, and neither knowledge of protocols nor a private cell network are required. You simply need to radiate enough power at the right frequency to overload the front end of the receiver. You don't need to do this continuously, either; intermittent short-duration bursts will do. A device to do this - remote-controlled for preference - can be made cheaply, easily, and small enough to be more or less impossible to find when it isn't transmitting. A group could make large numbers of these and deploy them at numerous random locations close to main lines and junctions to gain the ability to stop trains on any part of the network at will. Finding the devices would be a major operation and you could never be sure you'd got them all; preventing them being deployed is impossible.

Fibre optics can't be "tapped" they can be tampered with and you can use a relay etc. But you can't look into a fibre, unless you can defy laws of optics. In the short it requires extra equipment, tools and skill and will give an outage which a system should detect.

On the topic of a *DoS attack, its more of interference as your using the wrong protocol.
This could be mitigated by using large enough signal (broadcast power). To destroy this you would need to use the same the same exact frequency with a large enough noise. It becomes a balance. If its (ERTMS) built on the cheap (economic side) then this would be simple, but if the power was strong enough you would need a very large power source to override it, as digital communication is more resilient to interference and its binary in its nature. It wouldn't be hard to find such a power source or broadcast if you knew how to do it. Theoretically it would be very easy but I think in practise it could become cumbersome without expert planning.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,715
Location
Scotland
Fibre optics can't be "tapped" they can be tampered with and you can use a relay etc. But you can't look into a fibre, unless you can defy laws of optics. In the short it requires extra equipment, tools and skill and will give an outage which a system should detect.
In theory it is possible to tap fibre optics as there isn't 100% reflectance at the fibre wall and some photons will leak. Practically speaking, it would be extremely difficult to achieve but it isn't impossible.
 

JGR

Member
Joined
31 Jan 2012
Messages
147
Location
Ipswich
On the topic of a *DoS attack, its more of interference as your using the wrong protocol.
This could be mitigated by using large enough signal (broadcast power). To destroy this you would need to use the same the same exact frequency with a large enough noise. It becomes a balance. If its (ERTMS) built on the cheap (economic side) then this would be simple, but if the power was strong enough you would need a very large power source to override it, as digital communication is more resilient to interference and its binary in its nature. It wouldn't be hard to find such a power source or broadcast if you knew how to do it. Theoretically it would be very easy but I think in practise it could become cumbersome without expert planning.
Signal fading with distance lies (very roughly) between the square and the fourth power of distance. This depends on the level of obstacles, environmental conditions, etc.
This makes it very easy for a nearby unwanted transmitter on a particular frequency to totally swamp out reception of signals from another distant transmitter. You don't need a large power source or anything sophisticated in that common case.
Adaptive modulation schemes partially mitigate this, but even they won't save you from wideband noise across your whole communication band.

In theory it is possible to tap fibre optics as there isn't 100% reflectance at the fibre wall and some photons will leak. Practically speaking, it would be extremely difficult to achieve but it isn't impossible.
The whole point of fibre-optics is that photons don't leak, mainly due to Snell's law. To get around that you'd have to damage the fibre in some way or bend it very significantly. Given how finicky fibre couplers can be at the best of times, I don't rate your chances trying that. More likely you'd have to snip the whole bundle of fibres and insert your own electronics and/or beam splitters into the gap. I really can't see what would be worth snooping on signalling cables to justify that level of effort though.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,715
Location
Scotland
The whole point of fibre-optics is that photons don't leak, mainly due to Snell's law. To get around that you'd have to damage the fibre in some way or bend it very significantly. Given how finicky fibre couplers can be at the best of times, I don't rate your chances trying that. More likely you'd have to snip the whole bundle of fibres and insert your own electronics and/or beam splitters into the gap. I really can't see what would be worth snooping on signalling cables to justify that level of effort though.
There will always be some leakage as if there wasn't then there would be no need to boost the signal no matter how long the length of cable. However, it's so small a leakage that it's probably at the limit of what is possible with current technology.

I agree that it's not worth it for trying to interfere with signals, that level of technology is much more likely to be used by the intelligence services for keeping an eye on foreign powers.
 

dysonsphere

Member
Joined
22 Jan 2013
Messages
518
I would guess the easiest place to pick up fibre optics would be at a reapeter box where they maybe a data point to do tests.
 

JGR

Member
Joined
31 Jan 2012
Messages
147
Location
Ipswich
There will always be some leakage as if there wasn't then there would be no need to boost the signal no matter how long the length of cable. However, it's so small a leakage that it's probably at the limit of what is possible with current technology.
The glass is not perfectly transparent, so you get losses due to attenuation, you can use optical amplifiers to fix that though. The other problem is dispersion (pulses getting smeared in time) which needs more involved correction.
 

Hyphen

Member
Joined
17 Oct 2011
Messages
504
Location
Swansea (previously Nottingham/Sheffield)
The issue is why bother!

Ah yes. Why bother? It's obvious nobody's going to bother hacking this (because Land Rovers), so let's not bother with security models.

I think that's called Security by Obscurity, and quite a number of people have lost a lot of money assuming that was safe enough.

As a precursor to this, most railway remote control links from PSB to local interlocking and between central interlockings and trackside signalling sensors and actuators have migrated to the railway owned Fixed Telecommunications Network (FTN), a highly redundant dedicated nationwide system of trackside fibres and transmission hubs established by Network Rail that also carries safety critical voice communications between the local GSM-R cells and the control centres. This network is clearly not part of or connected in any way to the public internet.

I really hope you're not a developer of critical systems (though for the record, neither am I). Simply not being connected to the Internet really isn't enough.

The Iranian nuclear centrifuge control systems weren't connected to the Internet at all, but a fairly simple attack vector led to them being infected by Stuxnet - USB pen drive.
http://en.wikipedia.org/wiki/Stuxnet

So with a dedicated private network in order to attack the current signalling system virtually you actually still have to access railway assets or premises physically first.

Nope. As long as you can socially engineer someone to stick that pen drive in, you still don't need to ever go near the railway.

ETCS level 2 and above changes this clearly. Whilst control centre commands and interlocking functionality will still be completely isolated from the internet

Really, a lack of Internet access is not enough to make a system secure!

Also, these systems are connected to the Internet somewhere along the way - how else would the Open Data sites get details about realtime running? How would the berth data get to OpenTrainTimes so Poggs can produce his maps, if not from the signalling centre or another part of the signalling system?

With all the encryption and other methods used by GSM and the ETCS computers to verify the message stream it is extremely unlikely a viable attack could result in false movement authority being interpreted

Encryption in GSM was hacked many, many years ago. The particular cipher in question (A5/1) continues to be used for basic GSM (i.e. 2G) communications.
http://en.wikipedia.org/wiki/A5/1

New ciphers were of course introduced as 3G and LTE came along, but for backwards compatibility reasons they weren't introduced onto 2G.

I can't find anything stating which ciphers are used in GSM-R specifically, but it's interesting that the following document notes, on page 7, that GSM-R should be considered basically open from a safety standpoint.
http://www.bane.dk/db/filarkiv/5589/Boundaries between ETCS and the GSM-R network.pdf

Happily, they do seem to have taken security into account in designing ETCS, and as you note - they are running their own encryption on top (diagram on page 6).
 
Status
Not open for further replies.

Top