Please select your home edition
Edition
A+T Instruments BFD 2024 Leaderboard

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable SW
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

V-DRY-XBarton Marine Pipe GlandsCyclops Marine 2023 November - FOOTER

Related Articles

Long Beach Olympic Classes Regatta overall
Wrapping up with World-Class podium performances The Long Beach Olympic Classes Regatta wrapped up with a full podium and high spirits, marking a thrilling conclusion to a week of elite racing in the iconic waters off Southern California.
Posted today at 5:41 am
WASZP Games 2025 Day 1
247 sailors across four fleets racing in Portland Harbour and Weymouth Bay "This race is live" — and with that, the 2025 WASZP Games were officially under way. With 247 sailors across four fleets, Portland Harbour and Weymouth Bay were transformed into a theatre of foiling.
Posted today at 4:56 am
Author and artist Alan Lucas OAM has passed away
He wrote nearly 40 successful books for boating enthusiasts Alan's importance to the sailing community cannot be understated, receiving an OAM for contributions to maritime literature and publishing nearly 40 books, with multiple editions.
Posted on 21 Jul
Eye on the Prize
The Contenders Chasing Admiral's Cup History For over half a century, the Admiral's Cup was considered the world championship of offshore racing. And then, in 2003, it was gone. Now, after a 22-year absence, the Cup is back.
Posted on 21 Jul
Paul Antrobus obituary
One of the outstanding figures of the era of great amateur sailors Sailors around the world will be sad to hear that British offshore sailing legend Paul Antrobus has crossed the bar. One of the "greats" of the IOR era of offshore racing, Paul had a distinguished career both afloat and ashore.
Posted on 21 Jul
Antigua launches high-energy racing spin-off
The Antigua Racing Cup is an event for racing purists The Ministry of Tourism, Civil Aviation and Investment is pleased to announce that a new vision for yachting in Antigua and Barbuda is beginning to take shape, building on the long-established brand of Antigua Sailing Week.
Posted on 21 Jul
Record MOCRA turn-out for the Rolex Fastnet Race
This year there are 20 multihulls racing for the Crystal Trophy While the four Ultims maxi-trimarans and nine Ocean Fiftys have their own classes in this Saturday's centenary Rolex Fastnet Race, the remaining multihulls convene in the MOCRA class.
Posted on 21 Jul
How to follow the Admiral's Cup inshore racing
Scheduled to start on Tuesday, concluding on Thursday The Admiral's Cup Inshore Racing is scheduled to start on Tuesday 22 July with three days of racing concluding on Thursday 24 July.
Posted on 21 Jul
A Day at the Races
What's it like to attend a SailGP event? On Sunday I went to the Emirates Great Britain Sail Grand Prix in Portsmouth, sitting in the grandstand and filming with the usual camera I use for interviews to try and give you a taste of the action and atmosphere from the shoreside.
Posted on 21 Jul
WASZP Games 2025 Women's Sprint Champs Overall
A thrilling showdown with five high-octane slalom races in Portland Harbour The final day of the WASZP Women's Sprint Championship delivered a thrilling showdown with five high-octane slalom races, pushing sailors to their limits in fast, tactical conditions.
Posted on 21 Jul