Please select your home edition
Edition
Mariners Museum 728x90

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable SW
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

Naiad/Oracle SupplierProtector - 660 x 82C-Tech Emirates TNZ

Related Articles

Int Moth Worlds - Zhik returns to its spiritual home at 2017 Worlds
Zhik is returning to its roots as the official clothing sponsor of the 2017 McDougall McConaghy Moth World Championships Zhik, the innovative sailing apparel specialist, is returning to its roots as the official clothing sponsor of the 2017 McDougall McConaghy Moth World Championships. And, ten years on, the Moths are returning to their spiritual home on Lake Garda. Zhik and the International Moth class are virtually synonymous with each other.
Posted on 20 Jul
Cheeki Rafiki - Douglas Innes to face retrial over manslaughter
Douglas Innes to face retrial over manslaughter The Director of Stormforce Coaching, the company that ran Cheeki Rafiki, is set to face retrial for manslaughter over the deaths of the four crew. They were 700nm from Nova Scotia, returning to Southampton after racing in Antigua when the keel feel off. It is said that previous groundings had weakened the keel bolts....
Posted on 17 Jul
Rytov continues to defend lead at 2017 Melges 20 European Championship
On the eve of final day at Melges 20 European Championship Russia's Igor Rytov & his Russian Bogatyrs remains in command On the eve of the final day at the 2017 Melges 20 European Championship, Russia's Igor Rytov and his Russian Bogatyrs remains in command. Thanks to a very consistent performance thus far, they are inching ever closer to capturing the top European title and trophy.
Posted on 15 Jul
Get better wave forecasts from PredictWind and ECMWF
Predictwind is well-known for accurate wind forecasts but now leads the way with accurate wave forecasts PredictWind is well known for its world leading accurate wind forecasts, but did you know Predictwind also leads the way with accurate wave forecasts?
Posted on 12 Jul
Centennial Transat builds bridge to a flying future
The Queen Mary 2 won its battle with the four 30-meter trimarans, as expected, in upwind conditions for the sailboats The race was timed to mark a hundred years since American troops arrived on the shores of France in WW1, and it also brought together all of the fastest Ultimate trimarans for the first time as the class begins to take flight.
Posted on 7 Jul
X-Yachts announce the new X49 as the latest member of the 'X' range
In 2016, X-Yachts launched the new pure ‘X’ range which included the X4³ and the X65.  In 2016, X-Yachts launched the new pure ‘X’ range, which included the X43 and the X65. This range was exceptionally well received by both press and clients, with more than 50 yachts sold in the first year. The ‘X’ range incorporates the best elements from both the Xcruising range and the Xperformance range into one beautifully designed performance cruiser
Posted on 6 Jul
Sailors for the Sea named an Environmental Innovator of the Year
Green Sports Alliance presented annual Environmental Leadership Award and Environmental Innovators of the Year Awards The Green Sports Alliance presented their annual Environmental Leadership Award and Environmental Innovators of the Year Awards, the highlight of their annual Green Sports Celebration on Wednesday, June 28th at the Green Sports Alliance Summit in Sacramento, CA.
Posted on 5 Jul
The Bridge – Colville nurses boat and crewman to third place finish
Arriving in New York on Independence Day will be some consolation for finishing lower on the podium than Colville wanted Sodebo Ultim’ finished five hours nine minutes and 52 seconds after second-placed IDEC Sport and 15 hours 47 minutes and 35 seconds after the winner Macif.
Posted on 4 Jul
The Bridge – Francis takes second but not passing the flame on yet
Joyon and his crew of Alex Pella, Gwénolé Gahinet, Sébastien Picault and Quentin Ponroy exchanged the lead with Macif IDEC Sport remained in the hunt, 30-50 miles behind, and Joyon used all his nous to make it quickly through transition zones and keep a boat 10 years older and several tonnes heavier in contention.
Posted on 4 Jul
François Gabart and Macif win The Bridge – Centennial Transat
François Gabart and his five-man crew on Macif have won The Bridge – Centennial Transat trimaran race François Gabart and his five-man crew on Macif have won The Bridge – Centennial Transat trimaran race, crossing the finish line under the Verrazano-Narrows Bridge in New York, on Monday, July 3 at 13:31:20 (local time), 08 days, 00 hours 31 minutes and 20 seconds after leaving from under the Saint-Nazaire Bridge. Macif sailed 3,582.13 nautical miles at an average speed of 18.61 knots.
Posted on 4 Jul