Please select your home edition
Edition
Selden 2020 - LEADERBOARD

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable SW
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

Selden 2020 - FOOTERVetus-Maxwell 2021 v2 FOOTERAllen Dynamic 40 Footer

Related Articles

The X-Yachts Gold Cup Experience
A celebration of sailing, of X-Yachts and, most importantly of all, people Having just returned from Haderslev, Denmark - which is the home of X-Yachts and played host to the X-Yachts Gold Cup 2025 - I was left wondering if this was a racing event, a rally or a social celebration amongst close friends.
Posted on 10 Jun
Three Rivers Race bridge mast drop compilation!
Horning Sailing Club's event is iconic for many reasons The Yachtmaster Insurance Three Rivers Race at Horning Sailing Club is an iconic event for many reasons. The most unique scenes are at the bridges, where the sailors have to drop their masts and row underneath, often leaving it to the very last minute.
Posted on 10 Jun
2025 IRC National Championships preview
This year's event has teams racing from all over the world The 2025 IRC National Championship, part of the Royal Thames Yacht Club's 250th Anniversary Regatta, will bring together over 50 IRC-rated boats for three days of competitive inshore racing in the Solent.
Posted on 10 Jun
Loro Piana Giraglia Day 3: Capricorno rising
Upset on day three of the inshore racing The pecking order at maxi events is typically well defined with the largest, fastest yachts coming home first. However this was nearly upset on day three of the inshore racing at Loro Piana Giraglia, organised by the Yacht Club Italiano
Posted on 9 Jun
Freestyle Pro Tour Sardinia day 4
Caers, Huvermann and Pezetti win in full-power freestyle conditons Day 4 at FPT Sardinia delivered a full dose of high-wind freestyle, with Juniors, Women, and Men's fleets all completing full eliminations under the blasting winds.
Posted on 9 Jun
5.5 Metre World Championship Day 1
Strong winds delay the start of racing in Sopot No racing was possible on the opening day of the 2025 5.5 Metre World Championship in Sopot, Poland, with winds of 30 knots across the bay for most of the day.
Posted on 9 Jun
Black Foils into top three for SailGP Season 5
The Black Foils have moved into third place in the season long Rolex SailGP Championship The Black Foils have moved into third place in the season long Rolex SailGP Championship after a second place at the Mubadala New York Sail Grand Prix.
Posted on 9 Jun
Prize Round the Island Race for 84-year-old Peter
Taking line honours on the helm of his old boat Peter Cunningham hailed the Round the Island Race after taking line honours on the helm of his old boat. Peter, who was first to finish the 2021 race with his PowerPlay Racing Team, repeated the feat on the multihull MOD70, now Zoulou.
Posted on 9 Jun
Registration now open for GKA Youth events
Germany and Spain events will have U14, U16 and U19 divisions Registration is now open for the two upcoming GKA Youth events of the 2025 season. First up is the GKA Youth Big Air Kite World Championship in St. Peter Ording, Germany.
Posted on 9 Jun
Celebrating 50 Years of the Vintage Yacht Regatta
QCYC will host the event in July at Shorncliffe The Queensland Cruising Yacht Club (QCYC) will host the 50th Vintage Yacht Regatta from 18 to 20 July 2025 at Shorncliffe, celebrating five decades of timber yachts, traditional seamanship and spirited racing on Moreton Bay.
Posted on 9 Jun