Please select your home edition
Edition
Zhik Yachting Range

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable .. .
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

T Clewring J-classInSunSport - NZSchaefer 2016 Ratchet 300x250

Related Articles

America's Cup - Arbitration Panel Hearing over Kiwi Qualifier for July
ACEA CEO, Russell Coutts has confirmed that the Arbitration Panel will hold its first Hearing in July. In a yet to be published interview in Sail-World, America’s Cup Events Authority CEO, Russell Coutts has confirmed that the Arbitration Panel will hold its first Hearing in July. This is the first official indication that the three person Arbitration Panel had even been formed, however Sail-World’s sources indicated that it had been empanelled since last January, possibly earlier.
Posted on 27 May
Rio 2016 - The Qualification Games - Part 2
Yachting NZ's refusal to nominate in three classes won in the first round of 2016 Olympic Qualification is unprecedented Yachting New Zealand's refusal to nominate in three classes won in the first round of 2016 Olympic Qualification is without precedent. Subject to Appeal, the Kiwis have signaled that they will reject 30% of the positions gained in the ISAF World Sailing Championships in Santander in 2014.
Posted on 22 May
Gladwell's Line - World Sailing changes tack after IOC windshift
Over the past year, we've given the International Sailing Federation (now re-badged as World Sailing) a bit of stick Over the past year, we've given the International Sailing Federation (now re-badged as World Sailing) a bit of stick. Every blow well earned over issues such as the pollution at Rio, the Israeli exclusion abomination plus a few more. But now World Sailing is getting it right.
Posted on 21 May
Rio 2016 - The Qualification Games - Part 1
Antipodean selection shenanigans aside, the Qualification system for the Rio Olympics appears to be achieving its goals Antipodean selection shenanigans aside, the Qualification system for the Rio Olympics appears to be achieving goals set in the Olympic Commission report of 2010. Around 64 countries are expected to be represented in Rio de Janeiro in August. That is a slight increase on Qingdao and Weymouth, but more importantly a full regional qualification system is now in place
Posted on 19 May
Taming the beast-a conversation with Stuart Meurer of Parker Hannifin
While AC72 cats were fast, they difficult to control, so Oracle partnered with Parker Hannifin to innovate a better way. If you watched videos of the AC72s racing in the 34th America’s Cup (2013), you’re familiar with the mind-boggling speeds that are possible when wingsail-powered catamarans switch from displacement sailing to foiling mode. While foiling is fast, there’s no disguising the platform’s inherent instability. Now, Oracle Team USA has teamed up with Parker Hannifin to innovate a better way.
Posted on 18 May
From foiling Moths to Olympic starting lines-a Q&A with Bora Gulari
Bora Gulari’s is representing the USA at the Rio 2016 Olympics in the Nacra 17 class, along with teammate Louisa Chafee. Bora Gulari (USA) has made a strong name for himself within high-performance sailing circles, with wins at the 2009 and 2013 Moth Worlds. In between, he broke the 30-knort barrier and was the 2009 US SAILING Rolex Yachtsman of the Year. His latest challenge is representing the USA at the Rio 2016 Olympics in the Nacra 17 class as skipper, along with his teammate Louisa Chafee.
Posted on 12 May
Concern for Zika at Rio Olympics is now deadly serious
Alphabet soup is one description that has thus far not been used for either Guanabara Bay, Alphabet soup is one description that has thus far not been used for either Guanabara Bay, or the Rio Olympics. Many others have, and they were apt, but things have changed. So here now we have a situation where one man, Associate Professor Amir Attaran, who does have a more than decent string of letters after his name, is bringing nearly as many facts to bear as references at the article's end
Posted on 12 May
Zhik - The brand born of a notion, not its history
here is probably every reason that ocean rhymes with notion. Zhik’s tagline is officially marketed as Made For Water There is probably every reason that ocean rhymes with notion. Zhik’s tagline has been officially marketed as Made For Water, and this is precisely what the company has done for the last eight years before the succinct and apt strapline came from out of R&D and into mainstream visibility.
Posted on 8 May
Shape of next Volvo Ocean Race revealed at Southern Spars - Part 1
Southern Spars has been confirmed as the supplier of spars for the 2017-18 Volvo Ocean Race. In mid-April, Race Director, Jack Lloyd and Stopover Manager Richard Mason outlined the changes expected for the 40,000nm Race during a tour of Southern Spars 10,000sq metre specialist spar construction facility. A total of up to seven boats is expected to enter, but time is running out for the construction of any new boats.
Posted on 3 May
Sailing in the Olympics beyond 2016 - A double Olympic medalist's view
Bruce Kendall takes a look at what he believes Sailing needs to do to survive beyond the 2016 Olympics. Gold and Bronze medalist and multiple world boardsailing/windsurfer champion, Bruce Kendall takes a look at what he believes Sailing needs to do to survive beyond the 2016 Olympics. A key driver is the signalled intention by the International Olympic Committee to select a basket of events that will be contested.
Posted on 29 Apr