Skip to main content

Traffic control systems ‘vulnerable to hacking’

Devices used by traffic control systems are vulnerable to being hacked, according to computer security specialist IOActive. Hackers could gain complete control of these devices and cause traffic issues for the cities in the US, UK, France, Australia, China and beyond.
May 1, 2014 Read time: 2 mins
Devices used by traffic control systems are vulnerable to being hacked, according to computer security specialist IOActive. Hackers could gain complete control of these devices and cause traffic issues for the cities in the US, UK, France, Australia, China and beyond.

IOActive researcher CESAR Cerrudo, who examined the systems, said the hackers would not target the traffic lights directly but rather magnetic sensors embedded in streets that feed data to traffic control systems.

Cerrudo found that the systems lack basic security protections, such as data encryption and authentication, allowing the data to be monitored, or, theoretically, replaced with false information. So, although an attacker can’t control traffic signals directly through the sensors, he might be able to fool the control systems into reading congested roadways as clear or free-running roadways as congested, causing traffic signals to respond accordingly.

By exploiting the vulnerabilities he found, Cerrudo feels an attacker could cause traffic jams and problems at intersections, on freeways, highways and other areas.

Depending on the configuration it is possible to make traffic lights stay green for more or less time, stay red and not change to green or flash. Electronic signs could display incorrect speed limits and instructions, while ramp meters could allow cars on the freeway faster or slower than needed.  

Although manual overrides and secondary controls can be used if anomalies are detected, Cerrudo said the possibility of a real attack shouldn’t be disregarded as launching an attack is simple. Making an attack have a bigger impact would be more complex but not impossible.

Cerrudo said the vendor had been contacted in September 2013 through the 1742 Department of Homeland Security’s ICS-CERT. “I was told by ICS-CERT that the vendor said they didn't think the issues were either critical or even important.”

Regarding one of the vulnerabilities, the unnamed vendor is reported to have said the devices were designed that way as customers (state/city governments) wanted them to work that way and they were working as designed, so there wasn't a security issue.
“Yes that was the answer, I couldn't believe it,” he said.

His findings will be presented to the forthcoming Infiltrate conference in Florida.

For more information on companies in this article

Related Content

  • Slow moving US road user charging programme
    July 18, 2012
    Bern Grush recently attended the Mileage-Based User Fee Conference in Austin Texas where the fledgling American landscape for Road User Charging is beginning to take shape. When I was a kid I liked to poke sticks into the ants' nests in sidewalk cracks. Ants would scatter in every conceivable direction. They ran in circles, they ran over and through each other. They screamed without logic. I was fascinated.
  • The great pay divide
    April 2, 2014
    Public acceptance is crucial for the acceptance of managed and express lanes as Jon Masters discovers. Lists of proposed highway expansion projects introducing variably priced toll lanes continue to lengthen. Managed lanes, or express lanes to some, are gaining support as a politically favourable way of adding capacity and reducing acute congestion on principal highways. In Florida, for example, the managed lanes on the 95 Express are claimed to have significantly increased average peak-time speeds on tolle
  • Minnesota DOT deploys GTT’s Canoga to curb intersection vehicle crashes
    September 3, 2014
    Minnesota Department of Transportation (MnDOT) is working toward making the state’s roads safer, using the Canoga traffic sensing solution from Global Traffic Technologies (GTT) to warn at-risk drivers when cross-traffic is approaching. Nearly 70 per cent of fatal vehicle collisions in Minnesota, as well as other states, occur on roads in rural communities, where higher speeds, varying terrain and inconsistent sightlines can put many drivers in danger. The MnDOT initiative is part of the nationwide Towards
  • Developing ‘next generation’ traffic control centre technology
    July 4, 2012
    The Rijkswaterstaat and Highways Agency have joined forces to investigate what the market can do to realise an idealistic vision for traffic control centre technology. Jon Masters reports One particular seminar session of the Intertraffic show in Amsterdam in March was notably over subscribed. So heavy was the press to attend that your author, making his way over late from another appointment, could not get in and found himself craning over other heads locked outside to overhear what was being said. The