AIS Cybersecurity System for Reducing the Attack Surface of Voyage Networks

Abstract

U.S. Navy and commercial vessels use modern navigation technology consisting of computers and electronic systems that are highly interconnected and create a cyber terrain that is vulnerable to novel cyberattacks. Previous research proved that voyage networks are vulnerable to radio frequency attacks. One especially vulnerable component is the Automatic Identification System (AIS), a navigation and safety tool required on all vessels with a gross weight of 300 tons or greater. Previous security researchers were able to transmit data packets through the AIS receiver. The AIS blindly accepted packets as long as they followed ITU-R M.1371-5 standard protocol. This work aims to design a low-cost AIS data validation system that will reduce the attack surface of voyage networks. In this work, we leverage the NMEA-0183 and ITU-R M.1371-5 standards to implement two cybersecurity strategies, allow-listing and validating inputs, based on the quality dimensions of the data. The threat models that this security system attempts to address are contact spoofing attacks and arbitrary data injection attacks. We believe that a minimalist security system that is standalone, is not resource intensive, and can handle large volumes of AIS traffic is necessary for an effective design. The system proposed in this work fulfills these objectives. The resulting security system is implemented and validated using Python.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Dec 01, 2021
Accession Number
AD1165026

Entities

People

  • Jorge Jr Vasquez

Organizations

  • Naval Postgraduate School

Tags

Communities of Interest

  • Cyber
  • Energy and Power Technologies
  • Ground and Sea Platforms
  • Space

DTIC Thesaurus Topics

  • Central Processing Units
  • Coast Guard
  • Computer Networks
  • Computers
  • Cyber Warfare
  • Cyberattacks
  • Cybersecurity
  • Data Links
  • Databases
  • Detection
  • Detectors
  • Digital Communications
  • Identification Systems
  • Information Science
  • Machine Learning
  • Multiple Access
  • Network Protocols
  • Radio Frequency
  • Software Defined Radio
  • Warning Systems

Fields of Study

  • Computer science

Readers

  • Cybersecurity.
  • Distributed Systems and Data Platform Development
  • Radio communications and signal processing.

Technology Areas

  • Cyber
  • Microelectronics
  • Microelectronics - Microelectromechanical Systems