Please select your home edition
Edition
U-DECK 2023 - No.2 728x90 TOP

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable SW
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

X-Yachts X4.3Zhik 2024 March - FOOTERSCIBS 2024 FOOTER

Related Articles

More flexible? More durable? More comfortable?
Next Gen FlexForce offer the ultimate in versatility, comfort, durability and stretch Our Next Gen FlexForce wetsuit tops and long johns offer the ultimate in versatility, comfort, durability and stretch.
Posted on 17 Apr
RS Venture Connect to carry Olympic Flame
Mare Inseme, an inclusive sailing association in Corsica, has been selected for the torch relay Mare Inseme, an inclusive sailing association in Corsica, has been selected to carry the Paris 2024 Olympic flame during the torch relay in the build up to the Olympic Games.
Posted on 17 Apr
Cup Spy Apr 16: Radical Swiss AC75 revealed
Alinghi Red Bull Racing was revealed in daylight - showing some very unique design features Alinghi Red Bull Racing was revealed in daylight on Tuesday in Barcelona - showing some very unique design features - and looking to leapfrog the other design teams, and make a two generation advance in AC75 design.
Posted on 17 Apr
Cup Spy April 16: Luna Rossa revealed
The first tow-run reached a boat speed of 20 knots before turning around for a second run The first tow-run reached a boat speed of 20 knots before turning around and proceeding with the second one at 25 knots and finally increasing to 30 knots.
Posted on 17 Apr
Who better than a J owner to talk about a J?
Chatting with Denis R., currently the owner of a J/99 and soon to be of a J/112E We asked some questions to Denis R., currently the owner of a J/99 and soon to be of a J/112E. He shares his feelings about why he chose the J/99 and why he is staying in the family with his next boat, the J/112E.
Posted on 17 Apr
Zhik Combined High Schools Championships Day 2
Two races held after a 2 hour delay waiting for the wind Day 2 of the Zhik Combined High Schools Sailing Championship saw competitors stranded on the shore as the forecast for breeze failed to materialise. After a two hour postponement, race officials were able to set a course in the light and variable breeze.
Posted on 17 Apr
The Globe40 bound for Valparaiso
Adding the stopover in Chile to its provisional schedule After several months of exchanges and a recent week on site, the GLOBE40 is thrilled to add a stopover in Valparaiso in Chile to its provisional schedule.
Posted on 17 Apr
The Ocean Race joins world leaders in Athens
Nature's Baton and the Relay4Nature connect at Our Ocean Conference The Ocean Race joined world leaders at the Our Ocean Conference 2024 at the Stavros Niarchos Foundation Cultural Center (SNFCC) in Athens, Greece on Tuesday, who had gathered to advance measures to protect and restore ocean health.
Posted on 17 Apr
America's Cup: Swiss launch a beauty of detail
Alinghi Red Bull Racing family came together to celebrate the first launch and another milestone Today was the official launch at the Swiss team's beautiful base in the heart of the Port Vell with Chiara Bertarelli, daughter of Ernesto, cracking the bottle on the foredeck and naming their new AC75 challenger.
Posted on 17 Apr
Zhik Combined High Schools Championships Day 1
Beashel makes a solid start to defend his title Beashel makes a solid start to defend his title on the opening day of the Zhik Combined High Schools (CHS) Sailing Championships.
Posted on 16 Apr