Please select your home edition
Edition
SailX 728x90

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable .. .
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

Hamilton Island LuxuryWildwind 2016 660x82Barz Optics - Floaters

Related Articles

What to look for when buying a modern lifejacket
There is no doubt that modern lifejacket design has changed considerably. There is no doubt that modern lifejacket design has changed considerably and one of the biggest drivers of this change has been due to personal ownership. Rather than crew relying on lifejackets being on-board a boat, they want to own their own lifejacket as part of their kit bag.
Posted today at 7:12 am
The New Bavaria Cruiser 34 - you won't believe this is a 34' yacht!
The Sydney International Boat Show sees the World Premiere of the Bavaria Cruiser 34 - 2 Cabin version. The Sydney International Boat Show sees the World and Australian Premiere of the Bavaria Cruiser 34 - 2 Cabin version. The new Cruiser 34 offers more space and more comfort than ever before with a bigger cockpit, dual helms and ergonomically designed seating. This is the first time the entry level Bavaria cruiser has been offered in twin helm!
Posted on 19 Jul
Navathome Australia brings RYA Theory to your door
The RYA Cruising Syllabus has been built up over years of best practice development in Sail and Power Boat skippering. The Royal Yachting Association Cruising Syllabus has been built up over years of best practice development in Sail and Power Boat skippering. Split into a theory and practical syllabus the training modules take you in steps from a Start Yachting orientation through to Yachtmaster for either power or sail.
Posted on 5 Jul
Free $US3,000 Carbon Vang with SouthernFurl boom orders in July
Southern Spars is giving a free carbon vang - valued at US$3,000 - with SouthernFurl in-boom furlers ordered in July Southern Spars is giving away a free carbon vang - valued at US$3,000 - with all of their SouthernFurl in-boom furlers ordered in July. Carbon gas vangs make a great addition to the furling boom package, though if you’d prefer to keep your existing one, Southern Spars will offer you a 5% discount on the price of your boom instead.
Posted on 29 Jun
Newport Bermuda Race - High Noon takes honours
As the Newport Bermuda Race fleet rushed to the finish line on Monday in the wake of the first-to-finish boat, As the Newport Bermuda Race fleet rushed to the finish line on Monday in the wake of the first-to-finish boat, the powerful 100-foot grand prix Comanche, to the surprise of many they were led by an unusual boat and crew. High Noon, at 41 feet, is fully 59 feet shorter than Comanche and tens of feet shorter than many other entries.
Posted on 22 Jun
Platino recovery - Family confirms that tug has made rendezvous
Reports in social media say a salvage tug has made a rendezvous with the Platino earlier than expected. Reports in social media by family and friends of Nick Saull, the crew member killed during a catastrophic incident abroad the 66ft yacht Platino say the salvage tug which left on Tuesday night has made the rendezvous earlier than expected. The Facebook report says the tug, Sea Pelican, arrived on Friday morning, the weather in the area has eased and with a more favorable outlook.
Posted on 16 Jun
Royal Queensland Yacht Squadron to ban bottled water
Approval has been given to create a ban on bottled water that comes in plastic containers. The RQYS Management Committee has confirmed that approval has been given to create a ban on bottled water that comes in plastic containers. This will place the club as a leader in environmental impact management in Australia and around the world. The Royal Hong Kong Yacht Club earlier this year did likewise. Who’s next?
Posted on 16 Jun
Platino recovery operation well underway as crew arrive in Auckland
An ocean-going tug has left Whangarei to locate and attempt to salvage the luxury yacht Platino An ocean-going tug left Whangarei late on Tuesday night to locate and attempt to salvage the luxury yacht Platino which has been abandoned 550km NE of New Zealand. Weather dependent, we could reach Platino by Saturday and have the yacht and body of the person on board back in New Zealand early next week,” says Inspector Graham of the NZ Police.
Posted on 16 Jun
Search for Platino crew member lost in Pacific Ocean is suspended
Maritime New Zealand have advised that the Rescue Coordination Centre New Zealand (RCCNZ) has suspended the search for t Maritime New Zealand have advised that the Rescue Coordination Centre New Zealand (RCCNZ) has suspended the search for the sailor lost overboard from the yacht Platino on Monday morning, 550km north of New Zealand. Sail-World understands that a tug has left NZ to rendezvous with the boat. That boat is believed to have an NZ Police officer on board responsible for the recovery of the deceased.
Posted on 15 Jun
Platino survivors expected in Auckland on Thursday
Southern Lily, with three crew members from the 66ft yacht Platino aboard, is expected to arrive in Auckland on Thursday The container ship, Southern Lily, with three crew members from the 66ft yacht Platino aboard, is expected to arrive in Auckland on Thursday morning. The master of the Southern Lily, Shashi Prakash, said that seas in the region at the time of the rescue were 3 metres high making for a tricky operation to rendezvous with the dismasted yacht.
Posted on 15 Jun