Please select your home edition
Edition
Cyclops Marine 2023 November - LEADERBOARD

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable SW
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

ETNZ-STORE-728X90 one B BOTTOMCyclops Marine 2023 November - FOOTERRS Sailing 2021 - FOOTER

Related Articles

Last Chance for 2024 Olympic Qualification
Starting this weekend at the Semaine Olympique Française The Last Chance Regatta, held during the 55th edition of Semaine Olympique Française (Franch Olympic Week) from 20-27 April in Hyères, France, is as it says – the last chance.
Posted today at 5:42 am
35th Antigua Classic Yacht Regatta Day 1
Easy start to an exciting week The 35th Antigua Classic Yacht Regatta got off to a slow start today with unusual calm southerly winds which prompted the race committee to shorten the Old Road course.
Posted today at 3:49 am
5.5 Metre Alpen Cup at Fraglia Vela Riva Day 1
Cold start but hot racing on Lake Garda, Italy The Jean Genie (GBR 43, Peter Morton, Andrew Palfrey, Ruairidh Scott) won two out of three races on the opening day of the 2024 5.5 Metre Alpen Cup, on Thursday, which is being hosted by the first time by Fraglia Vela Riva.
Posted on 18 Apr
New and familiar faces set for 2024 Resolute Cup
There's no set formula for evaluating the entry list for an invitational event There's no set formula for evaluating the entry list for an invitational event. But among the critical criteria would be a healthy number of former champions, geographic diversity and a handful of new entries.
Posted on 18 Apr
First six OGR finishers all Whitbread veterans
Whitbread yacht Outlaw AU (08) crosses the finish line at 13:39 UTC to claim the Adelaide Cup Former Whitbread yacht Outlaw AU (08) crosses the Royal Yacht Squadron, Cowes finish line at 13:39 UTC, 18th April after 43 days at sea ranking 6th in line honours and IRC for Leg 4.
Posted on 18 Apr
76th N2E Yacht Race - One week to go
Newcomers and veterans make N2E a sailing institution The 76th Newport to Ensenada International Yacht Race will depart from its multi-line start. A multitude of racers and 145 boats that keep N2E a Southern California yacht racing favorite, will take to the 125mn course bound for the Hotel Coral and Marina.
Posted on 18 Apr
Clipper Race fleet set to arrive in Seattle
After taking on the North Pacific Ocean Over 170 non-professional sailors, including 25 Americans, are on board a fleet of eleven Clipper Race yachts currently battling it out in a race across the world's biggest ocean and heading for the Finish Line in Seattle.
Posted on 18 Apr
Alegre leads the search for every small gain
Going into 2024 52 Super Series season The first of the two new Botin Partners designed TP52s to be built for this 52 Super Series season, Andy Soriano's Alegre, is on course to make its racing debut at 52 Super Series Palma Vela Sailing Week.
Posted on 18 Apr
Trust A+T: Best in Class
Positive feedback from this Caribbean racing season Hugh Agnew recently sailed with SY Adela under Captain Greg Perkins in the Antigua Superyacht Challenge. They went on to win the Gosnell's Trophy - a great result.
Posted on 18 Apr
10 years of growth and international success
J/70 celebrates its 10th anniversary With nearly 1,900 hulls built and National Class Associations in 25 countries, the J/70 is the largest modern sport keelboat fleet in the world.
Posted on 18 Apr