Please select your home edition
Edition
Selden 2020 - LEADERBOARD

AIS concern - serious vulnerability to hacking

by Tom Simonite, Technology Review/Sail-World on 20 Oct 2013
AIS data could be vulnerable SW
That AIS system you have such faith in may not be so secure after all. Hundreds of thousands of vessels, including many sailing boats worldwide, rely on the Automatic Identification System (AIS) for sharing vessel movements. Now the system has shown to be easily vulnerable to hacking.

Researchers have announced at a conference in Kuala Lumpur that they have found that it is possible to cause fake vessels to appear, real ones to disappear, and to issue false emergency alerts using cheap radio equipment.

Researchers with the computer security company Trend Micro discovered the problem, which stems from a lack of security controls in AIS, a system used by an estimated 400,000 vessels worldwide.

AIS is an easy target because the signals don’t currently have any authentication or encryption mechanism, making it simple to use software to craft a signal designed to do mischief, says Marco Balduzzi, Trend Micro researcher. 'All the ships out there are affected by this problem; it’s not tied to the hardware but to the protocol.'

International Maritime Organization rules make AIS mandatory on passenger vessels and on cargo ships over a certain size. Lighthouses, buoys, and other marine fixtures also transmit their location using the system.

'We were really able to compromise this system from the root level,' says Kyle Wilhoit, a researcher with Trend Micro’s Future Threat Research team. By purchasing a 700-euro piece of AIS equipment and connecting it to a computer in the vicinity of a port, the researchers could intercept signals from nearby craft and send out modified versions to make it appear to other AIS users that a vessel was somewhere it was not.

Using the same equipment and software, it is possible to force ships to stop broadcasting their movements using AIS by abusing a feature that lets authorities manage how nearby AIS transmitters operate. AIS transmissions could also be sent out that make fake vessels or structures such as lighthouses or navigational buoys appear, and to stage spoof emergencies such as a 'man in the water' alert or collision warning. No direct attacks were staged on any real vessels.

The researchers showed that their spoof signals were faithfully reproduced on the maps provided by online services that monitor AIS data.

One online service was fooled into showing a real tugboat disappearing from the Mississippi and reappearing on a Dallas lake, and (see photo left) depicting a fake vessel traveling off Italy on a course that spelled out the hacker term for a compromised system: 'pwned.'

Ships and marine authorities also use radar to detect other vessels and obstacles. But AIS was introduced as an easier and more powerful alternative, and people have come to rely on it, says Wilhoit. Balduzzi and Wilhoit collaborated on the research with independent Italian security researcher Alessandro Pasta, and presented their findings at the Hack In the Box security conference in Kuala Lumpur on Wednesday.

The researchers attempted to notify several international marine and communication authorities, but only received a response from the International Telecommunications Union, a United Nations agency that deals with global communications policy. 'They seem to be on board with changing the protocol,' says Wilhoit, 'but it’s one of those foundational problems that will take time to fix.' AIS equipment has the protocol built in, so rolling out an improved form of AIS requires replacing existing equipment.

Even deciding on how to update the AIS protocol and regulations could take some time. The International Maritime Organization, another U.N. agency, is the international authority most directly responsible for AIS design and use, but a spokesperson, Natasha Brown, told MIT Technology Review that she was not aware that any research on AIS security had been presented to the agency. 'This issue has not been formally raised at IMO, so there has been no [internal] discussion or IMO recommendations or guidance.'

Only a formal paper submitted via a government with IMO membership or an organization with consultative status would lead to any response, said Brown.

So if you were just about to upgrade your AIS system, it might be wise to wait until the protocol is changed - or at least until we find how long that will be...

Thanks to the www.oceancruisingclub.org!Ocean_Cruising_Club, the world-wide club for cruising sailors, for the notification about this news, and more information can be obtained about Trend Micro by http://www.trendmicro.com!clicking_here.

Marine Products Direct 2023 - Calypso FOOTERHyde Sails 2024 - One DesignCyclops Marine 2023 November - FOOTER

Related Articles

Video Interview: Onboard the Excess 14
At the Sanctuary Cove International Boat Show 2025 Excess have moved forward their designs with the Excess 13 and 14 cruising catamarans, so seeing the Excess 14 was high on the priority list, as well as talking to some exceptional high performance sailors on board to learn their thoughts.
Posted on 3 Jun
New Dynamic Range of T-Shirts and Shorts
Just the ticket at sea and on shore Packing for a weekend away on the water and having fun onshore has never been easier, thanks to the new range of Dynamic shorts and t-shirts from Henri-Lloyd.
Posted on 3 Jun
Rodkicker 50 - manual rigid vang for larger yachts
Specifically sized for yachts measuring between 50 and 55 feet A rigid vang is designed to enhance sail handling during reefing, preventing the boom from falling into the cockpit or onto the coach roof. Equipped with gas springs, it automatically elevates the boom upon release of the kicking strap.
Posted on 3 Jun
Jazz Turner sets off around the British Isles
Wheelchair cast aside for a gruelling fundraising voyage for Sailability We have been following Jazz Turner on a quest to become the first female wheelchair user to complete a solo, non-stop, unassisted circumnavigation of the British Isles. Today she left Brighton Marina, velcro-ed to the windward side on the epic voyage.
Posted on 2 Jun
RYA Southampton International Boat Show deal
Take advantage of an exclusive discounted £5 ticket Southampton International Boat Show, Britain's biggest festival of boating and watersports is back on 19th-28th September 2025 for its 56th edition and RYA members (aged 16+) can now take advantage of an exclusive discounted £5 ticket.
Posted on 31 May
Bulwarks and Bulldust – watch Episode Four
Episode Four - Mark Elkington, The Yacht Sales Co. - is now up and running Watch along as we speak with Mark Elkington from The Yacht Sales Co. about his transition from a West Australian crayfisherman to a global sales and support organisation par excellence.
Posted on 30 May
The Fastnet's centenary race is one for the books
Two Essentials You'll Want Onboard from Mantus and Revolve-Tec The countdown is on. On 26 July 2025, the 100th anniversary edition of the Rolex Fastnet Race sets sail from Cowes, a legendary 695-mile offshore challenge that finishes, once again, in Cherbourg-en-Cotentin, France.
Posted on 29 May
SAIL Amsterdam 2025 is just around the corner
Iconic 5-yearly event will welcome a spectacular fleet of tall ships and historic vessels From 20 to 24 August 2025, SAIL Amsterdam will once again bring the magic of maritime heritage to the heart of the Dutch capital.
Posted on 28 May
CNB Rendez-Vous a great success
In the stunning setting of Costa Smeralda with a fleet of 23 yachts CNB celebrated its annual Rendez-Vous in the stunning setting of Costa Smeralda with a fleet of 23 yachts converging in Porto Rotondo for a weekend of sailing, camaraderie, and elegance on and off the water.
Posted on 26 May
Dufour 48 first photos in Palma
Going further with the outdoor living experience The Dufour 48 truly embodies the new generation of Dufour yachts and goes further by offering an outdoor living experience and unprecedented comfort for a 48-footer.
Posted on 24 May