Please select your home edition
Edition
Vetus-Maxwell 2021 v2 LEADERBOARD

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable SW
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

Trofeo Princesa Sofía Mallorca 2025Rolly Tasker Sails 2023 FOOTERMySail 2025

Related Articles

2025 Rolex Middle Sea Race preview
To date, yachts representing ten nations have confirmed their participation There has been an encouraging early wave of entries for the 46th edition of the Rolex Middle Sea Race, set to commence on Saturday, October 18, 2025.
Posted on 20 May
52 Super Series fleet is out into the Atlantic
11-strong fleet is now mustering in Galicia Following the successful shipping of most of the TP52s from Nice in the Mediterranean out into the Atlantic and to Vigo on rugged northwest of Spain, the race fleet is now mustering in Galicia ahead of the GALICIA 52 SUPER SERIES Royal Cup.
Posted on 20 May
Puget Sound sailing, Etchells, J/70s, Cup news
Seeking Goldilocks conditions on Puget Sound, Etchells NAs, J/70 U.S. Nationals, AC38 news As the saying goes, 'you don't know unless you go'. While I've mostly heard this phrase applied to climbing, skiing, and mountaineering, four late-winter and springtime races on Puget Sound this year exemplified the fact that this line.
Posted on 20 May
2025 edition of fivepointfive magazine published
5.5 Metre Class now off to Poland for the first time The 2025 edition of fivepointfive Magazine was launched during the recent Alpen Cup at Riva and is now available to read online and download.
Posted on 20 May
Henri-Lloyd supports Jazz Turner's challenge
GBR para-athlete overcomes fears in attempt to break record For a young woman with multiple and complex health issues, Jazz Turner is remarkable calm as she faces her imminent departure on her around Great Britain sailing challenge.
Posted on 20 May
A new IMOCA for Boris Herrmann's Team Malizia
Three teams have joined forces to build three new boats Boris Herrmann's Team Malizia announces the build of a new IMOCA racing yacht and with it, an unprecedented collaboration.
Posted on 20 May
Spotlight on the stars
Top 12 highlights at the 2025 Sanctuary Cove International Boat Show If you're looking to sample all the excitement of Australia's premiere marine lifestyle showcase, these star attractions are sure to draw the crowds.
Posted on 20 May
Newcomers enter Melbourne to Apollo Bay Yacht Race
The 52 nautical mile sprint is the final race of the ORCV summer sailing program Competitors in the 2025 Melbourne to Apollo Bay Yacht Race (M2AB) will start this final offshore event of the season under the eerie cover of darkness at 0400 hours on Saturday the 24th of May.
Posted on 20 May
VX One Class forms Int. Class Assoc.
Significant new chapter begins for VX One sailors with formation of an Int Class Assoc. A significant new chapter has just begun for VX One sailors worldwide with the formation of the VX One International Class Association
Posted on 20 May
Whitehead finish 9th at Formula Kite Europeans
A confident return to international competition in Urla, Türkiye Australia's Breiana Whitehead has made a confident return to international competition, finishing ninth overall at the 2025 Formula Kite European Championships in Urla, Türkiye.
Posted on 20 May