Airborne WiFi: Rogue Waves in the Sky - m0nkeydrag0n
RF Village @ DEF CON 33 · Day 1 · RF Village
Overview
In "Airborne WiFi: Rogue Waves in the Sky," Monkey Dragon, a seasoned blue team operator, threat hunter, and forensics expert, delves into the often-overlooked security challenges posed by in-flight connectivity on commercial airlines. The talk illuminates the unique vulnerabilities that arise when passengers connect to Wi-Fi networks in the confined and complex environment of an aircraft, detailing the risks of evil twin and rogue access point (AP) attacks. Monkey Dragon emphasizes the critical need for vigilance, specialized detection strategies, and a deep understanding of on-wing infrastructure to combat these threats.

Key moments
- 0:00 Introduction, key terms, and talk context
- 2:00 The typical passenger's in-flight WiFi connection scenario
- 3:10 Understanding aircraft systems and the DER's role
- 4:00 IFC system components and blue team's security insights
- 6:00 Real-world evil twin attack incident on an airline
- 6:50 What to do when in-flight Wi-Fi feels suspicious
Airborne WiFi: Rogue Waves in the Sky
Speakers: Monkey Dragon, Blue Team Operator, Threat Hunter, Forensics, IR, War Driving Enthusiast
Conference: RF Village
YouTube: https://www.youtube.com/watch?v=9iXHZHwc2MY
Overview
In "Airborne WiFi: Rogue Waves in the Sky," Monkey Dragon, a seasoned blue team operator, threat hunter, and forensics expert, delves into the often-overlooked security challenges posed by in-flight connectivity on commercial airlines. The talk illuminates the unique vulnerabilities that arise when passengers connect to Wi-Fi networks in the confined and complex environment of an aircraft, detailing the risks of evil twin and rogue access point (AP) attacks. Monkey Dragon emphasizes the critical need for vigilance, specialized detection strategies, and a deep understanding of on-wing infrastructure to combat these threats.
This presentation is highly relevant for anyone involved in aviation security, incident response, or network defense, as it highlights a niche but significant attack surface. The speaker draws on real-world incidents, such as a documented evil twin attack on an Australian airline, to underscore the tangible risks to passenger data, operational integrity, and regulatory compliance. By blending practical threat hunting techniques with insights into the unique challenges of an airborne environment, Monkey Dragon provides a compelling case for proactive defense against wireless threats in the sky.
The talk is particularly important because it addresses a scenario where passengers, often in a hurry or seeking digital distraction, may lower their guard when connecting to what they perceive as legitimate airline Wi-Fi. The consequences of such compromises can range from data theft and privacy breaches to potential disruptions of on-board systems, making the detection and mitigation of these "rogue waves" a paramount concern for airlines and security professionals alike.
Background
▶ Watch: Introduction, key terms, and talk context (0:00)
The modern commercial aircraft, while primarily designed for safe transit, has evolved into a complex ecosystem of avionic systems and passenger-facing technologies, including In-Flight Connectivity (IFC) and In-Flight Entertainment (IFE). These systems provide passengers with Wi-Fi, texting, and various media services, allowing them to use their Portable Electronic Devices (PEDs) even at cruising altitude. Integrating these non-essential systems into an aircraft requires stringent oversight by a Designated Engineering Representative (DER), an FAA-approved authority responsible for ensuring that such additions do not compromise flight safety.
The problem of malicious Wi-Fi on aircraft stems from the inherent trust users place in ubiquitous Wi-Fi networks and the unique operational context of air travel. Passengers, often rushing to catch flights or eager to work, may connect to Wi-Fi networks without critical scrutiny. This haste can make them susceptible to evil twin attacks, where an attacker broadcasts an SSID (network name) that mimics a legitimate airline Wi-Fi network, luring unsuspecting users to connect. Once connected, the attacker can intercept traffic, harvest credentials through a fake captive portal, or perform other malicious activities. In contrast, rogue APs are unauthorized access points connected to the network, potentially by malicious actors or even inadvertently by "rogue IT," posing a different but equally significant threat to network integrity.
A notable incident highlighted in the talk involved an individual broadcasting evil twin networks on an airline in Australia. This attacker set up a deceptive captive portal, attempting to trick passengers into divulging personal information. This case, reportedly one of the first where an individual was apprehended for such an attack on an aircraft, starkly illustrates the real-world applicability and severity of this threat. The challenges are compounded by varying service models; some airlines offer gate-to-gate Wi-Fi, extending the attack window to densely populated airport terminals where more potential targets and opportunities for an attacker exist compared to the isolated environment at cruising altitude. Understanding the on-board infrastructure—typically comprising a server, modem, and multiple access points—is foundational for any blue team seeking to defend against these sophisticated and context-specific threats.
Key Findings
▶ Watch: Understanding aircraft systems and the DER's role (3:10)
Monkey Dragon's talk reveals several critical findings regarding the landscape of Wi-Fi security on commercial aircraft:
- Real-World Threat: Malicious Wi-Fi activity, specifically evil twin and rogue AP attacks, is not theoretical but a documented reality in the aviation sector, as evidenced by the incident on an Australian airline. This underscores the urgency for robust detection and response mechanisms.
- Infrastructure Understanding is Paramount: Effective threat hunting and incident response for airborne Wi-Fi require an intimate knowledge of the specific on-wing network infrastructure. Without this context, security teams are "blindly" sifting through logs, rendering generic detections largely ineffective.
- Unique Environmental Noise: The airport and airborne environment introduces significant noise into network logs. This includes cross-contamination from legitimate SSIDs broadcast by adjacent aircraft at gates, as well as benign but noisy phenomena like Apple Private Relays and ad-hoc networks. Detections must be highly tuned to filter this noise while identifying genuine threats.
- Creative Threat Hunting is Essential: Standard, "check-the-box" security processes often miss subtle indicators of compromise. The speaker emphasizes that "thinking outside of the box" and applying creativity, even by looking at seemingly benign events from a different angle, is crucial for uncovering hidden malicious activity ("the bones in the sand").
- Leveraging External and Open-Source Tools: Integrating data from external sources like Wiggle.net (a crowdsourced Wi-Fi mapping service) and ADSB (Automatic Dependent Surveillance-Broadcast) for flight tracking can provide invaluable context for investigations. In the Australian incident, Wiggle.net data helped identify the attacker's tradecraft.
- Importance of Detailed Documentation and Reporting: In the event of an incident, meticulous documentation, including screenshots, timelines, and comprehensive reports (executive summary, technical analysis, business impact, response/recovery approaches), is vital for effective communication with stakeholders and successful remediation.
Technical Deep Dive
▶ Watch: IFC system components and blue team's security insights (4:00)
Detecting and responding to malicious Wi-Fi on aircraft demands a nuanced technical approach, moving beyond generic network security practices. The core challenge lies in the unique environment of an airplane and airport, which generates a significant amount of "noise" that can obscure legitimate threats.
The on-wing infrastructure typically consists of an onboard server, a modem for external connectivity (terrestrial or satellite), and multiple access points (APs) distributed throughout the cabin. A blue team's first step is to thoroughly understand this architecture: the expected SSIDs, the legitimate BSSIDs (Basic Service Set Identifiers), and the normal operational patterns. Without this foundational knowledge, sifting through logs becomes a daunting and often fruitless exercise.
Detection Challenges and Strategies:
- Noise Filtering:
- Cross-Contamination: At airport gates, multiple aircraft from the same airline or alliance may be parked close together, leading to instances where one plane's Wi-Fi system detects the SSID of an adjacent, legitimate aircraft as a "rogue" or "impersonated" AP. This generates false positives.
- Benign Ad-Hoc Networks: Passengers might create personal hotspots or ad-hoc networks on their PEDs, which, while often benign, can trigger alerts.
- Apple Private Relay: Apple's privacy feature, which routes user traffic through a relay, can generate significant, legitimate network traffic that might look unusual to standard detections.
- Solution: Detections must be highly tuned to whitelist known legitimate networks and BSSIDs, filter out expected cross-contamination, and intelligently categorize benign ad-hoc networks and privacy features. This requires continuous adjustment of thresholds and careful analysis of event context.
- Specific Detections:
- Ad-Hoc Network Detection: While noisy, the presence of unexpected ad-hoc networks can be an initial indicator for further investigation.
- AP Impersonation: This is the primary detection for evil twin attacks. Systems should look for multiple APs broadcasting the same SSID but with different, unauthorized BSSIDs or MAC addresses.
- Rogue AP Events: Alerts for any unauthorized APs connected to the aircraft's network or attempting to mimic its services.
- MAC Address Analysis (OUI): A critical technique involves examining the Organizationally Unique Identifier (OUI) – the first three octets of a MAC address. The speaker highlighted an "Alpha" OUI in a simulated log as a suspicious indicator. Known malicious or frequently used hardware for rogue APs often share specific OUIs. Security teams can maintain blacklists or whitelists of OUIs to flag suspicious devices.
- Data Correlation and "Query Fu":
- Security Information and Event Management (SIEM) systems are central. The speaker emphasizes the importance of strong "query fu"—advanced querying skills—to correlate diverse data sources: syslog, authentication events, monetary transactions (if Wi-Fi is paid), and AP broadcast data.
- Building correlation tables from this data helps identify patterns and outliers, distinguishing legitimate traffic from malicious activity.
Leveraging External Data for Context:
- Wiggle.net: This crowdsourced database of wireless networks is an invaluable external resource. By mapping Wi-Fi networks globally, Wiggle.net can provide geographical context for detected SSIDs and BSSIDs. In the Australian incident, Wiggle.net data was instrumental in identifying the attacker's specific tradecraft and location, demonstrating its utility in post-incident analysis and even proactive threat intelligence.
- ADSB (Automatic Dependent Surveillance-Broadcast): This technology allows for the tracking of aircraft. Correlating network events with ADSB data can help confirm an aircraft's location and movement, adding another layer of context to Wi-Fi detections. For instance, if a rogue AP is detected, ADSB can help confirm which specific aircraft was in the vicinity at that time.
- FlightAware: Similar to ADSB, FlightAware provides flight tracking data that can assist in correlating detected Wi-Fi events with specific flights and routes.
Proactive Security and Continuous Improvement:
The talk stresses the importance of working closely with the engineers who design and build the on-wing systems—from modem firmware to client-facing software. Integrating security considerations early in the development lifecycle leads to stronger, more capable detections. Furthermore, security operations must adopt a cyclic process of continuously reviewing, tuning, and updating alerts and Indicators of Compromise (IoCs), adjusting thresholds as new data emerges or the threat landscape evolves. This iterative approach ensures that detections remain relevant and effective against evolving threats.
Demo / Proof of Concept
▶ Watch: Real-world evil twin attack incident on an airline (6:00)
While this talk did not feature a live demonstration or a hands-on proof-of-concept, the speaker effectively illustrated the detection process using simulated SIEM logs and real-world data from tools like Wiggle.net. Monkey Dragon presented hypothetical log entries from a "Hard Brigade SIM" that depicted warnings for "rogue AP" and "impersonated AP" events, highlighting how a suspicious OUI (specifically an "Alpha" OUI) in a BSSID could be a key indicator. The presentation also included screenshots from Wiggle.net, demonstrating the dense Wi-Fi landscape at an airport (San Diego), and how such external data could be correlated with internal findings to identify potential threats or confirm the nature of an event. These visual aids served to walk the audience through the analytical steps of identifying and investigating a malicious Wi-Fi event on an aircraft.
Defensive Implications
▶ Watch: What to do when in-flight Wi-Fi feels suspicious (6:50)
The insights from Monkey Dragon's presentation offer crucial defensive implications for airlines, aviation security teams, and blue team operators:
- Deep Infrastructure Knowledge is Non-Negotiable: Defenders must possess an intimate understanding of their specific on-wing Wi-Fi infrastructure, including all legitimate SSIDs, BSSIDs, MAC addresses (especially OUIs), and expected network behavior. This forms the baseline against which anomalies can be detected.
- Tailored Detection Engineering: Generic network security tools and out-of-the-box SIEM detections are insufficient. Security teams must develop and continuously tune custom detections specifically for the unique airborne and airport environment. This includes creating rules to filter out expected noise from adjacent aircraft, legitimate ad-hoc networks, and privacy features like Apple Private Relay.
- Proactive OUI Monitoring: Implement systems to monitor and flag unusual or blacklisted OUIs (the first three octets of a MAC address). While not definitive proof of malice, certain OUIs are associated with readily available consumer devices often repurposed for rogue APs, serving as strong indicators for further investigation.
- Robust Logging and Data Verbosity: Ensure that all on-wing Wi-Fi components are configured for verbose and useful logging. The quality and detail of log data directly impact the ability of analysts to correlate events, build timelines, and understand the full scope of an incident.
- Develop Comprehensive Incident Response Playbooks: Standardized, well-defined playbooks are essential for responding to Wi-Fi-related security incidents on aircraft. These playbooks should cover detection, analysis, containment, eradication, recovery, and post-incident reporting, tailored for the unique operational constraints of an airline.
- Cross-Functional Collaboration from Design Onward: Security teams should engage early and often with the engineers responsible for designing and building aircraft systems, including firmware and software developers. Embedding security considerations into the initial design phase can prevent vulnerabilities and enable more effective built-in detections.
- Leverage External Intelligence Sources: Integrate data from external tools like Wiggle.net and ADSB/FlightAware into threat hunting and incident response workflows. These resources can provide invaluable contextual information, helping to geolocate events, confirm aircraft movements, and even identify attacker tradecraft.
- Educate Cabin Crew and Passengers: Empower cabin crew to recognize and report suspicious Wi-Fi activity or passenger concerns. While not a technical control, passenger vigilance, if properly channeled, can be an early warning system. Remind passengers to be cautious about connecting to Wi-Fi, especially if it feels "off" or requires unusual information.
- Continuous Threat Hunting and Alert Tuning: Security is not a static state. Blue teams must actively engage in threat hunting, looking for "bones in the sand" that might be missed by automated alerts. This requires a cyclic process of reviewing existing alerts, adjusting thresholds, and developing new detections based on evolving threats and deeper environmental understanding.
Key Takeaways
- Malicious Wi-Fi activities, such as evil twin and rogue AP attacks, are a tangible and proven threat on commercial aircraft, requiring dedicated security measures.
- Effective detection and response are fundamentally dependent on a deep, contextual understanding of the specific on-wing Wi-Fi infrastructure and its normal operational patterns.
- Standard security tools and generic detections are often insufficient due to the unique "noise" of the airborne and airport environment, necessitating highly tuned and customized alerts.
- Creative, "outside-the-box" thinking in threat hunting, coupled with the intelligent use of external tools like Wiggle.net and ADSB, is crucial for uncovering subtle indicators of compromise.
- Robust logging, meticulous documentation, and comprehensive incident response playbooks are vital for successfully managing and mitigating Wi-Fi security incidents in the aviation sector.
- Proactive engagement with system engineers during the design phase and continuous tuning of detections are essential for building resilient airborne Wi-Fi security.
About the Speaker(s)
Monkey Dragon is a dedicated blue team operator with extensive experience in threat hunting, forensics, and incident response (IR). Beyond their professional role, they are an enthusiastic advocate and practitioner of war driving, a hobby that involves mapping Wi-Fi networks. This blend of professional expertise and personal passion for wireless technologies allows Monkey Dragon to approach network security challenges with a unique perspective, as demonstrated in their insightful analysis of airborne Wi-Fi threats. They are also associated with "Hard Brigade," though no further details about the organization were provided.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A niche, reasonably competent RF Village talk that applies standard wireless threat detection concepts to an underexplored attack surface — in-flight Wi-Fi. The Australian evil twin case gives it a real-world anchor, and the Wiggle.net/ADSB correlation angle is a genuinely clever operational detail, but the overall technical depth sits at 'blue team blog post' level rather than original research.
Heather Calloway (CISO) — WEAK
Technically credible niche work on a real but narrow attack surface. The defensive value exists for aviation blue teams, but the talk never climbs to the level of governance, regulatory accountability, or operator-facing decisions that would make it relevant beyond that sliver of the audience.