Not the Drones You're Looking For

No ratings

Presented at No Hat 2024 by

In 2018, drones accessing the airspace created safety and security challenges, prompting Civil Aviation Authorities (CAAs) worldwide to initiate rule-making for Unmanned Aircraft Systems (UAS) Remote Identification (RID). UAS-RID policies, finalized in 2022, require drones to periodically broadcast telemetry information, enabling third-party entities to identify and locate drones and their operators. The need for quick and immediately actionable telemetry data led globally to the design of RID protocols where little emphasis was placed on security. Our research analyzed RID protocols' security, focusing on how ground stations receiving telemetry data can be abused by malicious users. We examined DroneID, the proprietary RID protocol from DJI, and Open Drone ID (ODID), the reference implementation of the ASTM F3411 standard used for RID regulations in the US and Europe. For both RID protocols, we reverse-engineered and analyzed the behavior of compliant ground station receivers, revealing novel vulnerabilities.We developed custom software - defined radio tools to perform signal injection with crafted data using the proprietary radio protocol OcuSync. Combining our findings with existing RID weaknesses, we created practical attack scenarios that enable attackers to forge fake drones and operators, spoof identities and locations, and disrupt RID functionalities, potentially causing false alarms in critical air spaces relying on these protocols for drone detection, or preventing real drones and operators from being identified. Recognizing the challenges of creating a universally accepted security solution for RID protocols, we developed mechanisms to detect these attacks, alleviating their impact on existing RID operations.