Please select your home edition
Edition
North Sails Performance 2023 - LEADERBOARD

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable SW
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

RS Sailing 2021 - FOOTER2024 fill-in (bottom)Pantaenius 2022 - SAIL & POWER 2 FOOTER AUS

Related Articles

2024 52 Super Series PalmaVela Sailing Week Day 3
1,2,3... the new Alegre tops the leaderboard After three good races today on the Bay of Palma - each with a different winner - Andy Soriano's brand new Alegre leads the 52 SUPER SERIES PalmaVela Sailing Week, but only on tie break ahead of Doug DeVos's Quantum Racing powered by American Magic.
Posted on 30 Apr
New Vaikobi lifestyle apparel collection
Your go to for everything off the water The NEW Vaikobi lifestyle apparel collection will be your go to for everything off the water.
Posted on 30 Apr
Grabbing chances with both hands
Can bad weather actually lead to more sailing? There's been no getting away from the fact that it's been a pretty miserable start to 2024 weather-wise in the UK. February saw record rainfall (yes, I know we're famed for our rain over here), it's been seriously windy and generally chilly.
Posted on 30 Apr
IMOCA skippers in The Transat CIC
Sam Goodchild: This Transatlantic's going to be far from normal The IMOCA skippers in The Transat CIC from Lorient to New York could get away without much upwind sailing over the next few days, as they head west across the Atlantic, according to Sam Goodchild, the Vulnerable skipper who is sitting out this race.
Posted on 30 Apr
Transat CIC day 3
Bracing for the low pressure system, Dalin and Lipinski still leading After passing through an earlier front yesterday with winds in excess of 30 knots and heavy seas, the fleet, which has left the south coast of Ireland behind and is now sailing on the open ocean, is gearing up for the second complex weather situation.
Posted on 30 Apr
worldmarine.media news update
Transat CIC, Congressional Cup, Last Chance Regatta News from The Transat CIC from Lorient to New York, the 59th Congressional Cup where Chris Poole and Ian Williams contested the final and the Last Chance Regatta, where the final qualifiers for Paris 2024 were decided.
Posted on 30 Apr
The BFD: Not just another TLA
The brightest, biggest, and toughest full-colour marine display available Roald Dahl created the BFG and in the seminal game Doom, one of the sought-after weapons also shared that TLA (three-lettered acronym), but A+T have their own similar acronym for an anything but ordinary product... the BFD - the sailor's weapon of choice.
Posted on 30 Apr
Youth in the limelight at Antigua Sailing Week
Axxess Marine Youth 2 Keel Race Day The breeze was on the up for the second day of Antigua Sailing Week, celebrating youth sailing on Axxess Marine Youth 2 Keel Race Day. The 10-knot easterly breeze piped up during the day, gusting up to 15 knots.
Posted on 30 Apr
America's Cup: Shoeby on that Splash and Sail
It was nice to tick all that off in one day.” Kevin Shoebridge on ETNZ's Day 1 Splash and Sail We thought, 'We've got a bit of time. We'll pull the mainsail up'. Then we ended up going for a sail [and fitting in three dry foiling tacks]. It was nice to tick all that off in one day.” Kevin Shoebridge on ETNZ's Day 1 Splash and Sail.
Posted on 30 Apr
100 entries and counting
For Ocean Dynamics and Mount Gay Airlie Beach Race Week Entries for Ocean Dynamics and Mount Gay Airlie Beach Race Week 2024 have already touched 100 and continue to grow as organiser, Whitsunday Sailing Club (WSC), announces a new Regatta Director, Jenni Birdsall.
Posted on 30 Apr