From Click to Sink: Utilizing AIS for Command and Control in Maritime Cyber Attacks

被引:14
作者
Ahmed, Amro [1 ]
Gkioulos, Vasileios [1 ]
机构
[1] Norwegian Univ Sci & Technol, Gjovik, Norway
来源
COMPUTER SECURITY - ESORICS 2022, PT III | 2022年 / 13556卷
关键词
Maritime; Cybersecurity; Automatic Identification System (AIS); Cover channel; ATT&CK; AUTHENTICATION;
D O I
10.1007/978-3-031-17143-7_26
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The maritime domain is among the critical sectors of our way of life. It is undergoing a major digital transformation introducing changes to its operations and technology. The International Maritime Organization urged the maritime community to introduce cyber risk management into their systems. This includes the continuous identification and analysis of the threat landscape. This paper investigates a novel threat against the maritime infrastructure that utilizes a prominent maritime system that is the Automatic Identification System (AIS) for establishing covert channels. We provide empirical evidence regarding its feasibility and applicability to existing and future maritime systems as well as discuss mitigation measures against it. Additionally, we demonstrate the utility of the covert channels by introducing two realistic cyber attacks against an Autonomous Passenger Ship (APS) emulated in a testing environment. Our findings confirm that AIS can be utilized for establishing covert channels for communicating Command & Control (C&C) messages and transferring small files for updating the cyber arsenal without internet access. Also, the establishment and utilization of the covert channels have been found to be possible using existing attack vectors and technologies related to a wide range of maritime systems. We hope that our findings further motivate the maritime community to increase their efforts for integrating cyber security practices into their systems.
引用
收藏
页码:535 / 553
页数:19
相关论文
共 60 条
[1]  
Amro A., 2021, NORSK IKT KONF FORSK, V3
[2]   Navigation Data Anomaly Analysis and Detection [J].
Amro, Ahmed ;
Oruc, Aybars ;
Gkioulos, Vasileios ;
Katsikas, Sokratis .
INFORMATION, 2022, 13 (03)
[3]   Communication and Cybersecurity Testbed for Autonomous Passenger Ship [J].
Amro, Ahmed ;
Gkioulos, Vasileios .
COMPUTER SECURITY: ESORICS 2021 INTERNATIONAL WORKSHOPS, 2022, 13106 :5-22
[4]   Communication architecture for autonomous passenger ship [J].
Amro, Ahmed ;
Gkioulos, Vasileios ;
Katsikas, Sokratis .
PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART O-JOURNAL OF RISK AND RELIABILITY, 2023, 237 (02) :459-484
[5]  
[Anonymous], 2021, ENHANCING MITRE
[6]  
[Anonymous], AIVDM AIVDO PROTOCOL
[7]  
[Anonymous], 2019, TRANSPORT MODES
[8]  
[Anonymous], 2017, Consultation on CIS Liquidity Risk Management Recommendations
[9]  
[Anonymous], 2021, ENCRYPTED CHANNEL
[10]  
[Anonymous], 2021, TRANSIENT CYBER ASSE