Please select your home edition
Edition
Pantaenius - All Risk

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable .. .
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

Sail Exchange 660x82 New SailsX-Yachts AUS X4 - 660 - 1Beneteau SAIL Oceanis 35.1 37.1 41.1 660x82 1

Related Articles

2017 Jeanneau Rendezvous at the inaugural Sail Peninsula Regatta
Some photos taken by LaFoto at the 2017 Jeanneau Rendezvous which was part of the inaugural Sail Peninsula Regatta. The 2017 Jeanneau Rendezvous was part of the inaugural Sail Peninsula Regatta from Martha Cove on Victoria's Mornington Peninsula. It was a great regatta with a stern chaser race held on the Friday night, followed by a long distance race to Blairgowrie on Saturday in a glamorous five to ten knots, then finally an awesome medium distance race off Safety Beach in 25-35 knots...
Posted on 21 Feb
Super Series Sailing Spectacular
News arrived of at least one Australian outfit going for a new build 52. Someone had to entertain Beau Geste and SMB During the week, news arrived of at least one Australian outfit going for a new build 52. Someone had to keep Beau Geste and SMB entertained at the sharp end of the 52 bracket. Two other camps were linked to other former 52 Super Series craft, Phoenix and Spookie, but the one touted as going after Phoenix has denied it, saying that Hasso (SAP) Plattner of Germany has bought her.
Posted on 20 Feb
More marina space and exciting firsts for GC Boat Show and Marine Expo
More marina space and exciting additions to an impressive Fleet of Firsts have set scene for a colossal marine showcase More marina space and even more exciting additions to an already impressive Fleet of Firsts have set the scene for a colossal marine showcase both on water and on land on Queensland’s Gold Coast from 17-19 March.
Posted on 17 Feb
Tenth blog from on board Perie Banou II
The irrepressible, charismatic and yarn-spinning record-breaker known as Jon Sanders is back sailing the oceans The sailor who cannot garden; the irrepressible, charismatic and yarn-spinning record-breaker known as Jon Sanders is back sailing the oceans he knows so well. After his ribs episode on the quay in Cape Town, and making more friends everywhere he goes, Jon is now making for St Helena. So here, in his typical rapid-fire style are his latest exploits...
Posted on 17 Feb
B&G adds enhanced Navionic functionality to Zeus and Vulcan range
B&G® announces the latest updates will bring PredictWind weather services direct to Zeus and Vulcan chartplotter range. B&G®, the world’s leading sailing navigation and instrument specialist, is pleased to announce the latest in its software updates will bring PredictWind weather services direct to its Zeus and Vulcan chartplotter range.
Posted on 16 Feb
Beneteau Open Day at Cruising Yacht Club of Australia
The Beneteau Team will be exhibiting three new Beneteau models at the CYCA this Saturday. The Beneteau Team will be exhibiting three new Beneteau models at the CYCA this Saturday.
Posted on 16 Feb
Lisa Blair enjoys a sunrise crossing of International Date Line
At sea for 20 days, Lisa Blair, 32 reached a key milestone in her attempt to circumnavigate Antarctica solo At sea for 20 days, 13 hours, 4 minutes and 39 seconds, sailor and adventurer Lisa Blair, 32 reached a key milestone in her attempt to circumnavigate Antarctica solo and unassisted crossing the International Dateline at 16:25:39 UTC (05:25:39 local time) on 11 February 2017.
Posted on 11 Feb
Six weeks to go to 2017’s Gold Coast International Boat Show
Come and see over 600 boats for sale on water and on the land as well as engines, accessories and electronics. Come and see over 600 boats for sale on water and on the land as well as engines, accessories and electronics, live entertainment and boating education every 15 minutes across a giant 3km display circuit.
Posted on 10 Feb
On board interview with Lisa Blair - solo Antartica circumnavigation
So far, Lisa is tracking very well in her attempt to become the first woman to sail solo around Antartica. So far, Lisa is tracking very well in her attempt to become the first woman to sail solo around Antartica. After the setbacks of a delayed departure due to gremlins in the electronics, we are delighted to have these answers from her on board. She is well and enjoying her time. Climate Action Now, her Hick 50, left Albany in Western Australia on January 22, 2017.
Posted on 8 Feb
Growing Fleet of Firsts for Queensland’s biggest GC Intl Marine Expo
A very impressive Fleet of Firsts is taking shape even more world-leading marine brands/businesses step aboard this week A very impressive Fleet of Firsts is taking shape as even more world-leading marine brands and businesses step aboard this week with first releases at Australia’s first major boat show of 2017 – the Gold Coast International Boat Show and Marine Expo in March.
Posted on 2 Feb