Please select your home edition
Edition
Barz Optics - Floaters

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable .. .
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

upffront 660x82Safety at Sea - Baltic - 2Hall Spars - Boom

Related Articles

'The best day of my life' - Auckland On the Boat Show - Day 3
Despite the forecast of dicey weather, visitors to the Auckland On the Water Boat Show were rewarded with a good day Despite a less than optimist forecast of more inclement weather, visitors to the Auckland On the Water Boat Show were rewarded with a good day to be at the Show – overcast skies, but no rain and plenty to see and do. Held for the first time in the school holidays, the kids – who get free entry – had a great day.
Posted today at 4:55 am
Auckland on the Water Boat Show - Showers don't deter crowds on Day 2
A tsunami of boating fans of all persuasions swept through the gates of the Auckland On the Water Boat Show this morning A tsunami of boating fans of all persuasions swept through the gates of the Auckland On the Water Boat Show when they opened this morning. Whether it was a result of the morning weather forecast or Friday was just a convenient day - who knows?
Posted on 30 Sep
Auckland On the Water Boat Show opens full of the Joys of Spring
The Auckland On the Water Boat Show enjoyed a beautiful Spring day for its opening. Despite the inclement weather that has been the New Zealand's daily fare for too long, the Auckland On the Water Boat Show enjoyed a beautiful Spring day for its opening. Today was the first of the four-day show and is also the first time that the Show has been held in the school holidays.
Posted on 29 Sep
Knowing Harken takes years and years (Pt.II)
We looked at how Grant Pellew became the MD here in Australia, and how they rigorously go about testing their gear In Part One of getting to know Harken, we looked at how Grant Pellew became the MD here in Australia, and how they rigorously go about testing their gear. We also looked at some of the other brands Harken distributes in Australia and so we move on to the last category.
Posted on 25 Sep
Olympic Gold medalist and Volvo Ocean Race winner up for WS Board
Torben Grael (BRA) is amongst the 15 nominations for one of seven places on the Board of Directors of World Sailing Torben Grael (BRA) is amongst the 15 nominations for one of seven places on the Board of Directors of World Sailing in November. The five times Olympic medalist, Volvo Ocean Race winner and several times America's Cup competitor will bring a much needed sailing edge to the Board of World Sailing if he can navigate the politics of the controlling body of the sport.
Posted on 25 Sep
Amel - Do you fit the bill?
Perhaps it is equally as fascinating as the many features that go into either the Amel 55 or 64 It is certainly an interesting set of criterion. Perhaps it is equally as fascinating as the many features that go into either the Amel 55 or 64 and make them a definitive part of the quintessential bluewater cruiser armada. We’ll come to all of those in due course, but firstly we’ll tackle the hero image and why in so many ways, this explains, so, so much.
Posted on 21 Sep
Knowing Harken takes years and years (Pt.I)
You could imagine that being familiar with all that Harken produces and stands for is a lengthy process. You could imagine that being familiar with all that Harken produces and stands for is a lengthy process. So if you were going to be the person at the top in Australia, it would be best for you to have immersed yourself in sailing from an early age. When you grew up, being one of the technical service team would be more than a handy apprenticeship, as it were.
Posted on 19 Sep
Brookes and Gatehouse Videos with Knut Frostad
Navico, the parent company for Brookes and Gatehouse (B&G), Simrad and Lowrance have prepared some terrific videos Navico, the parent company for Brookes and Gatehouse (B&G), Simrad and Lowrance have prepared some terrific videos with Knut Frostad, the legendary Volvo Ocean Race sailor and former CEO. See him talk about sailing in general, the B&G product choices and placement he made for his own boat, and then why he loves his Outremer 5X.
Posted on 8 Sep
Boat Books of the Month - How to Read Water and False Flags
How to Read Water: Clues, Signs & Patterns from Puddles to Sea & False Flags: Disguised German Raiders of World War II. This month the Boatbooks Australia: Boat Books of the Month are How to Read Water: Clues, Signs & Patterns from Puddles to the Sea and False Flags: Disguised German Raiders of World War II.
Posted on 6 Sep
Soft Padeyes – light, strong and versatile
Several types of soft padeyes are now available and are proving increasingly popular over traditional stainless steel pa Several types of soft padeyes are now available on the market and are proving increasingly popular over traditional stainless steel padeyes. They all capitalise on the incredible strength to weight ratio and abrasion resistance of Dyneema® which offers a reliable, robust, flexible and safe termination.
Posted on 6 Sep