Trust the Command, Not Just the Connection: Monitoring and Managing the NTCIP Command Path to Traffic Signal Controllers and Dynamic Message Signs
Authors/Creators
Description
Intelligent Transportation Systems (ITS) govern physical roadway behavior through networked field devices, including actuated signal controllers, dynamic message signs (DMS), and roadside units. For the signal-controller and DMS standards examined here, the deployed command path has historically relied on Simple Network Management Protocol (SNMP) versions 1 and 2c. Those versions use shared community strings and do not provide the cryptographic message authentication, integrity protection, and replay resistance available in SNMPv3.
The result is a large installed base of transportation field devices that can act on commands based largely on network reachability and possession of a shared community string rather than on cryptographically verifiable command origin and integrity. This is not an outside critique: the NTCIP standards bodies published a formal assessment in 2021 concluding that the standards did not adequately address security. Nearly five years later, the SNMPv3 revision for signal controllers has not appeared on the published-standards register, and the base DMS object standard in force remains a 2014 publication that predates the assessment.
This paper examines the structural weakness in the NTCIP command path; reviews the public record of documented incidents and vulnerabilities across multiple vendors, spanning 2014 through a CISA advisory published three weeks before this writing; and argues that the case is sharpest precisely where agencies can least afford it — during incidents and emergencies, when signal timing and sign messaging are instruments of driver direction. We argue that agencies require monitoring and management applied to the command itself, inline and at the wire, rather than to the network connection alone. We then describe an inline, agentless enforcement approach implemented by PacketViper, explicitly state its limits, and conclude that command-path integrity is a reliability and public-safety requirement for ITS operations, not solely a cybersecurity control.
Other (English)
Competing interests: The author is affiliated with PacketViper, LLC, which develops the command-path enforcement approach described in Section 6. Review status: This technical preprint has not undergone formal peer review. No datasets were generated or analyzed for this paper. Source basis: Publicly available standards, advisories, CVE records, peer-reviewed research, and vendor disclosures were checked through 16 July 2026.
Files
Trama_2026_NTCIP_Command_Path_v3.0.md
Additional details
References
- REFERENCE 01 Federal Highway Administration, Office of Operations. Coordination of IT and TSMO: Cybersecurity Practices, FHWA-HOP-21-005, December 2021. https://ops.fhwa.dot.gov/publications/fhwahop21005/index.htm — one of five factsheets drawn from Principles and Strategies for Effective Coordination of IT and TSMO; source of the New Hampshire DOT "Cyber Yankee" National Guard exercise account, in which specialists uncovered the password and posted a message to a dynamic message sign. Verified 16 July 2026.
- REFERENCE 02 NTCIP Joint Committee (AASHTO / ITE / NEMA). About NTCIP. https://www.ntcip.org/about/
- REFERENCE 03 NTCIP 1203 v03, Object Definitions for Dynamic Message Signs (DMS), published September 2014. https://www.ntcip.org/file/2018/11/NTCIP1203v03f.pdf — see also DMS Working Group summary, https://www.ntcip.org/dynamic-message-signs/ (MULTI markup; dmsMessageMultiString).
- REFERENCE 04 NTCIP. Documents — Published Standards (document register). https://www.ntcip.org/document-numbers-and-status/ — current published NTCIP 1202 is v03b (October 2023); current published NTCIP 1203 is v03 (September 2014); NTCIP 9014 v01.20 published August 2021. Accessed 16 July 2026.
- REFERENCE 05 NTCIP 9014 v01.20, National Transportation Communications for ITS Protocol — Infrastructure Standards Security Assessment (ISSA), published August 2021. https://www.ntcip.org/file/2021/08/NTCIP9014v0120.pdf — contents and scope: https://www.nema.org/standards/view/national-transportation-communications-for-its-protocol-infrastructure-standards-security-assessment-(issa)
- REFERENCE 06 Institute of Transportation Engineers. Infrastructure Standards Security Implementation (ISSI). https://www.ite.org/technical-resources/standards/infrastructure-standard-security-implementation-issi/
- REFERENCE 07 ITE / NTCIP BSP2 Working Group. ISSI Project Overview presentation, 14 October 2022. https://www.ite.org/ITEORG/assets/File/Standards/ISSI%202022-10-14%20BSP2_PPT.pdf — lists NTCIP 1203 (DMS) among device standards pending SNMPv3 update.
- REFERENCE 08 Institute of Transportation Engineers. NTCIP 1202 v04 Actuated Signal Control (ASC). https://www.ite.org/technical-resources/topics/standards/ntcip-1202-v04-actuated-signal-control-asc/ — project materials state that previous versions used SNMPv1 and that v04 uses SNMPv3 without supporting SNMPv1. See also Notice of Intent to Adopt NTCIP 1202 v04 ASC, 30 September 2025: https://www.ite.org/ITEORG/assets/File/Standards/NOTICE%20OF%20INTENT%20TO%20ADOPT%201202%20V04%20ASC.pdf. As of 16 July 2026, v04 does not appear in the NTCIP published-standards register [4].
- REFERENCE 09 Cybersecurity and Infrastructure Security Agency (CISA). ICS Advisory ICSA-23-026-02, Econolite EOS (Update A), original release 26 January 2023. https://www.cisa.gov/news-events/ics-advisories/icsa-23-026-02 — CVE-2023-0451 (CVSS v3 7.5), CVE-2023-0452 (ICS-CERT CVSS v3 9.8).
- REFERENCE 10 National Vulnerability Database. CVE-2023-0452 Detail. https://nvd.nist.gov/vuln/detail/CVE-2023-0452 — CWE-328; NIST/NVD base score 5.3 (Medium), CNA (ICS-CERT) base score 9.8 (Critical); record carries a CNA/NVD score-mismatch indicator. Accessed 16 July 2026.
- REFERENCE 11 A. Lemon, Red Threat. Give Me the Green Light Part 1: Hacking Traffic Control Systems, 11 July 2024. https://www.redthreatsec.com/blog/greenlightspart1
- REFERENCE 12 CVE-2024-38944. https://nvd.nist.gov/vuln/detail/CVE-2024-38944 — see also GitHub Advisory GHSA-pr45-8j9c-76gc, https://github.com/advisories/GHSA-pr45-8j9c-76gc; Exploit-DB 52151, https://www.exploit-db.com/exploits/52151
- REFERENCE 13 A. Lemon, Red Threat. Give Me the Green Light Part 2: Dirty Little Secrets, 16 July 2024. https://www.redthreatsec.com/blog/give-me-the-green-light-part2-dirty-little-secrets — web interface as SNMP front end; Econolite values writable without authentication; Intelight web-security OID writable; credential OIDs .1.3.6.1.4.1.1206.3.36.1.6.10.2.0 / .10.3.0 returned in cleartext; Free the MIBs (https://www.freethemibs.org/).
- REFERENCE 14 B. Ghena, W. Beyer, A. Hillaker, J. Pevarnek, and J. A. Halderman. Green Lights Forever: Analyzing the Security of Traffic Infrastructure. 8th USENIX Workshop on Offensive Technologies (WOOT '14), San Diego, CA, August 2014. https://www.usenix.org/conference/woot14/workshop-program/presentation/ghena — full text: https://jhalderm.com/pub/papers/traffic-woot14.pdf
- REFERENCE 15 ICS-CERT / CISA. ICS-ALERT-14-155-01 Daktronics Vanguard Hardcoded Credentials, 4 June 2014, and ICS-ALERT-14-155-01A Daktronics Vanguard Default Credentials (Update A). https://www.cisa.gov/news-events/ics-alerts/ics-alert-14-155-01 — reported to ICS-CERT by the Federal Highway Administration; publicly available proof of concept.
- REFERENCE 16 Daktronics, Inc. Daktronics Responds to ICS-CERT Vanguard® Default Credentials Alert, 12 June 2014. https://investor.daktronics.com/news-releases/news-release-details/daktronics-responds-ics-cert-vanguardr-default-credentials-alert — confirms compromise of a small number of North Carolina DOT Vanguard signs.
- REFERENCE 17 Nextgov. Flaw Lets Hackers Control Electronic Highway Billboards, June 2014. https://www.nextgov.com/cybersecurity/2014/06/flaw-lets-hackers-control-electronic-highway-billboards/85849/ — North Carolina and California incidents; California sign privately owned, in use for event traffic control.
- REFERENCE 18 CISA. ICS Advisory ICSA-26-176-04, Daktronics Controller Firmware, 25 June 2026. https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-04 — VFC-DMP-5000 / DMP-5000 / DMP-8000; CVE-2026-28701, CVE-2026-31928 (CWE-798), CVE-2026-33560 (CWE-434); sectors include Emergency Services; reported by Thomas Jou, Princeton University.
- REFERENCE 19 CVE-2026-28701, Daktronics Controller Firmware Path Traversal. https://www.cve.org/CVERecord?id=CVE-2026-28701 — CWE-22; assigner ICS-CERT; CVE record scores CVSS v3.1 9.8 (Critical) AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and CVSS v4.0 9.3 (Critical); SSVC: exploitation none, automatable yes, technical impact total. Note the conflict with [22], which scores the same CVE 7.7 (High) with an AV:L local vector.
- REFERENCE 20 CVE-2026-33560, Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type. https://www.cve.org/CVERecord?id=CVE-2026-33560 — CWE-434; CVSS v3.1 7.1 (High) AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N, CVSS v4.0 8.4 (High). Requires authentication (PR:L).
- REFERENCE 21 CVE-2026-31928, Daktronics Controller Firmware Use of Hard-coded Credentials. https://www.cve.org/CVERecord?id=CVE-2026-31928 — CWE-798; CVSS v3.1 8.1 (High), CVSS v4.0 9.3 (Critical). Description: devices ship with a default administrative web account with weak authentication controls, not required to be changed during initial configuration or operation, providing full system access.
- REFERENCE 22 CISA. ICSA-26-176-04 CSAF machine-readable advisory (JSON), initial release 2026-06-25, TLP:WHITE. https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-04.json — authoritative advisory text and scoring; scores CVE-2026-28701 at CVSS v3.1 7.7 (High) AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N; records no known public exploitation at time of publication. Retrieved via CIRCL Vulnerability-Lookup, https://vulnerability.circl.lu/vuln/icsa-26-176-04, 16 July 2026.
- REFERENCE 23 SecurityWeek. New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking, June/July 2026. https://www.securityweek.com/new-controller-flaws-expose-highway-signs-and-billboards-to-remote-hacking/ — VINCE timeline (reported early January 2026, patched firmware ready around early March 2026); Daktronics statement confirming mitigation and customer notification, and that no active exploits have been reported to it; researcher's report of multiple internet-exposed controllers.
- REFERENCE 24 Federal Highway Administration, Office of Operations. Transportation Management Center Information Technology Security, FHWA-HOP-19-059, 2019. https://ops.fhwa.dot.gov/publications/fhwahop19059/fhwahop19059.pdf — technical guidance for TMCs mapped to the NIST Cybersecurity Framework and CIS Top 20 Controls v7.1; notes that TMCs and ITS devices no longer function as closed systems.
- REFERENCE 25 Federal Highway Administration. FHWA's Transportation Cybersecurity Strategic Plan, FHWA-HOP-23-T065. https://ops.fhwa.dot.gov/publications/fhwahop23T065/fhwahop23T065.pdf — background on FHWA cybersecurity capability strategy; not cited in the body, listed for the reader's onward reference.
- REFERENCE 26 Hackaday. Spoofing an Emergency Traffic Preemption Signal, 8 March 2026. https://hackaday.com/2026/03/08/spoofing-an-emergency-traffic-preemption-signal/ — Strobecom II EVP reverse engineering by [xssfox]; Arduino Nano and IR LED; precise timing and, in some systems, a valid vehicle ID required. Optical/IR surface — cited as out of scope, not as NTCIP command-path evidence.
- REFERENCE 27 U. Blumenthal and B. Wijnen. User-based Security Model (USM) for version 3 of the Simple Network Management Protocol (SNMPv3), RFC 3414, December 2002. https://www.rfc-editor.org/rfc/rfc3414