Please select your home edition
Edition
Southern Spars

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable .. .
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

Related Articles

Shape of next Volvo Ocean Race revealed at Southern Spars - Part 1
Southern Spars has been confirmed as the supplier of spars for the 2017-18 Volvo Ocean Race. In mid-April, Race Director, Jack Lloyd and Stopover Manager Richard Mason outlined the changes expected for the 40,000nm Race during a tour of Southern Spars 10,000sq metre specialist spar construction facility. A total of up to seven boats is expected to enter, but time is running out for the construction of any new boats.
Posted on 3 May
Sailing in the Olympics beyond 2016 - A double Olympic medalist's view
Bruce Kendall takes a look at what he believes Sailing needs to do to survive beyond the 2016 Olympics. Gold and Bronze medalist and multiple world boardsailing/windsurfer champion, Bruce Kendall takes a look at what he believes Sailing needs to do to survive beyond the 2016 Olympics. A key driver is the signalled intention by the International Olympic Committee to select a basket of events that will be contested.
Posted on 29 Apr
From Olympic flag to Olympic Gold and maybe another
The Sydney Olympics was a Sailing double 470 Gold event for Australia. Having won the 420 World Championship in 2000, the feeder class to the 470, while still at school in Australia young Matt Belcher was given the honour of carrying the Olympic flag during the closing ceremony of the Sydney 2000 Olympics.
Posted on 28 Apr
The Road to Rio now 99 days short
The Road to Rio 2016 still has a few curves, bumps and potholes for teams battling to win. The Road to Rio 2016 still has a few curves, bumps and potholes for teams battling to win in Hyeres, at some World championship events and Weymouth World Cup but for many crews: 'It's 106 miles to Chicago we got a full tank of gas, half a pack of cigarettes, it's dark and we're wearing sunglasses.' Whoops wrong movie.
Posted on 28 Apr
America's Cup - Oracle Racing win in Court but with collateral damage
Oracle Racing have had another claim against them by a former crew member dismissed. Oracle Racing have had another claim against them by a former crew member dismissed. Mitchell focussed largely on the circumstances of the matter and introduced into the public arena some interesting documents to support his claims.
Posted on 23 Apr
Thou doth protest too much, me thinks
And no, we’re not off to analyse Hamlet right away. There’ll be no surtitles popping up on the top of your screen And no, we’re not off to analyse Hamlet right away. There’ll be no surtitles popping up on the top of your screen about now. At any rate, it is simply an adaptation of Lady Gertrude’s original line. We merely seek to use it as a way to demonstrate that when there is a lot of brouhaha going on, the smoke screen ultimately ends up as a lovely, colourful flag as to the real intent behind it.
Posted on 18 Apr
An interview with Jake Beattie about the 2016 Race to Alaska
In 2014, Jake Beattie and a few friends envisioned the Race to Alaska. Now, it’s time this wild race’s second edition. In 2014, Jake Beattie-the executive director of the Northwest Maritime Center in Port Townsend, Washington, and a few friends hatched the bold idea of a human-powered race to Ketchikan, Alaska, took flight. They decided that their human-powered race would start in Port Townsend, Washington and run to Ketchikan, by way of the inside passage between Vancouver Island and British Columbia.
Posted on 14 Apr
Children of the Internet, Rio and Hong Kong
I have four daughters, the youngest, who in her mid 20's is a true child of the Internet. I have four daughters, the youngest, who in her mid 20's is a true child of the Internet. The kind of conversations I have with her run along these lines.... In the olden days we did not have television until I left school and they had a thing called print magazines, that reported events between two weeks and four months after they happened. And her sceptical response... Hoh! Daddy, Hoh!
Posted on 14 Apr
Go fast girls - 49er FX sailors Paris Henken and Helena Scutt
Paris Henken and Helena Scutt will be representing the USA at the Rio 2016 Olympics, which will be their first Olympiad. American’s Paris Henken (20) and Helena Scutt (23) recently won a berth to represent the USA at the Rio 2016 Olympics in the high-performance 49er FX skiff, a goal that the team has been working on for almost three years. While this is their first Games, writing them off as Olympic newbies would require ignoring their recent results and their strong teamwork.
Posted on 13 Apr
World Sailing Cup V3 - A Dead Rat in a Shoe or Spring Daffodils?
While a host of major sailing events go from strength to strength, the Sailing World Cup has very major issues. Last night my Irish better half was sitting beside me on the sofa watching an Australian version of the popular TV Cooking Program My Kitchen Rules on a tablet with her headphones while I was watching Diehard II for the seventeenth time (it’s a boy thing) on TV. She suddenly spluttered and laughed, took off her headphones and motioned for me to mute Diehard. (Seriously!!)
Posted on 9 Apr
T Clewring One DesignNaiadBakewell-White Yacht Design