Marine Network Protocols and Security Risks
Abstract
:1. General Background
2. Security Considerations for Marine Network Protocols
2.1. Confidentiality
2.2. Integrity
2.3. Availability
2.4. Authentication
2.5. Authorization
2.6. Non-Repudiation
3. Privacy Considerations for Marine Network Protocols
4. Risk Analysis for Current Protocols
- TCP/IPv6: For data transmission via Internet.
- Controller Area Network (CAN) Bus/NMEA 2000: For vehicular and marine data transmission.
- NMEA 0183: For marine data transmission.
- Automated Identification System (AIS): For marine data transmission.
- NMEA OneNet: For marine data transmission.
- Denial of Service (DoS): Targets the availability of data.
- Spoofing: Targets the integrity of data.
- Packet sniffing: Targets the confidentiality of data.
- Replay/Man-in-the-Middle (MITM): Targets both confidentiality and integrity of data.
4.1. TCP/IPv6
4.1.1. Denial of Service
4.1.2. Spoofing
4.1.3. Packet Sniffing
4.1.4. Replay/Man-in-the-Middle
4.2. NMEA 2000
4.2.1. Denial of Service
4.2.2. Spoofing
4.2.3. Packet Sniffing
4.2.4. Replay/Man-in-the-Middle
4.3. NMEA 0183
4.3.1. Denial of Service
4.3.2. Spoofing/Packet Sniffing
4.3.3. Replay/Man-in-the-Middle
4.4. Automated Identification System (AIS)
4.4.1. Denial of Service
4.4.2. Spoofing
4.4.3. Packet Sniffing
4.4.4. Replay/Man-in-the-Middle
4.5. OneNet
4.5.1. Denial of Service
4.5.2. Spoofing
4.5.3. Packet Sniffing
4.5.4. Replay/Man-in-the-Middle
5. Challenges and Opportunities
5.1. Incorporating Ad-Hoc Security in Legacy Protocols
5.2. Adopting Existing Hardware into Current Protocols
5.3. Involving Network and Industry Researchers in Protocol Development
5.4. Shift towards Zero-Trust Network Protocol Paradigm
6. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
References
- Proc, J. The Story of Portishead Radio: Long Range Maritime Radio Communications: 1920–1995. 2001. Available online: http://jproc.ca/radiostor/portis1.html (accessed on 23 February 2021).
- National Oceanic And Atmospheric Administrator. History of the Program; National Oceanic And Atmospheric Administrator: Washington, DC, USA, 2021.
- Inmarsat Government. History of the Program; Inmarsat Government: Reston, VA, USA, 2021.
- National Marine Electronics Association. NMEA 0183–Standard for Interfacing Marine Electronic Devices; National Marine Electronics Association: Reston, VA, USA, 2002. [Google Scholar]
- National Marine Electronic Association. NMEA 2000® Interface Standard Standard for Serial-Data Networking of Marine Electronic Devices; National Marine Electronic Association: Reston, VA, USA, 2016. [Google Scholar]
- Marine and Coastguard Agency. Radio: Operational Guidance on the Use of VHF Radio and Automatic Identification Systems (AIS) at Sea; Marine and Coastguard Agency, 2016. Available online: https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/442648/MGN_324Corr.pdf (accessed on 12 April 2021).
- Shoab, M.; Jain, K.; Anulhaq, M.; Shashi, M. Development and implementation of NMEA interpreter for real time GPS data logging. In Proceedings of the 2013 3rd IEEE International Advance Computing Conference (IACC), Ghaziabad, India, 22–23 February 2013; pp. 143–146. [Google Scholar]
- Federal Communications Commission. Global Maritime Distress and Safety System (GMDSS); Federal Communications Commission: Washington, DC, USA, 2017.
- Xu, H.; Heijmans, J.; Visser, J. A Practical Model for Rating Software Security. In Proceedings of the 2013 IEEE Seventh International Conference on Software Security and Reliability Companion, Gaithersburg, MD, USA, 18–20 June 2013; pp. 231–232. [Google Scholar] [CrossRef] [Green Version]
- National Marine Electronic Association. Basic NMEA 2000® Installer Training; National Marine Electronic Association: Severna Park, MD, USA, 2021. [Google Scholar]
- Hester, P.; Highsmith, W. Method and Apparatus for Channel Allocation Integrity in a Communication Network. 1994. Available online: https://patentimages.storage.googleapis.com/pdfs/US5349580.pdf (accessed on 12 April 2021).
- Jo, Y.H.; Cha, Y.K. A Study on Cyber Security Requirements of Ship Using Threat Modeling. J. Korea Inst. Inf. Secur. Cryptol. 2019, 29, 657–673. [Google Scholar]
- Van Herrewege, A.; Singelee, D.; Verbauwhede, I. CANAuth-a simple, backward compatible broadcast authentication protocol for CAN bus. In Proceedings of the ECRYPT Workshop on Lightweight Cryptography, Louvain-la-Neuve, Belgium, 28–29 November 2011; p. 20. [Google Scholar]
- Siddiqui, A.S.; Gui, Y.; Plusquellic, J.; Saqib, F. Secure communication over CANBus. In Proceedings of the 2017 IEEE 60th International Midwest Symposium on Circuits and Systems (MWSCAS), Boston, MA, USA, 6–9 August 2017; pp. 1264–1267. [Google Scholar] [CrossRef]
- Samonas, S.; Coss, D. The CIA Strikes Back: Redefining Confidentiality, Integrity and Availability in Security. J. Inf. Syst. Secur. 2014, 10, 21–45. [Google Scholar]
- Trivedi, K.S.; Kim, D.S.; Roy, A.; Medhi, D. Dependability and security models. In Proceedings of the 2009 7th International Workshop on Design of Reliable Communication Networks, Washington, DC, USA, 25–28 October 2009; pp. 11–20. [Google Scholar] [CrossRef]
- Maple, C. Security and privacy in the internet of things. J. Cyber Policy 2017, 2, 155–184. [Google Scholar] [CrossRef]
- Niksefat, S.; Kaghazgaran, P.; Sadeghiyan, B. Privacy issues in intrusion detection systems: A taxonomy, survey and future directions. Comput. Sci. Rev. 2017, 25, 69–78. [Google Scholar] [CrossRef]
- Garmin. Boat Antennas and Sensors. 2021. Available online: https://buy.garmin.com/en-US/US/on-the-water/antennas_sensors/cOnTheWater-c10538-p1.html (accessed on 7 March 2021).
- Wullems, C.; Pozzobon, O.; Looi, M.; Kubik, K. Enhancing the Trust of Location Acquisition Systems for Critical Applications and Location-Based Security Services. In Proceedings of the 4th Australian Information Warfare & IT Security Conference, Enhancing Trust, Adelaide, Australia, 20–21 November 2003; pp. 391–406. [Google Scholar]
- Deering, S.R. Hinden Internet Protocol, Version6 (IPv6) Specification. RFC2460 1998. Available online: https://www.hjp.at/doc/rfc/rfc2460.html (accessed on 12 April 2021).
- Nikander, P. Denial-of-service, address ownership, and early authentication in the IPv6 world. In International Workshop on Security Protocols; Springer: Berlin/Heidelberg, Germany, 2001; pp. 12–21. [Google Scholar]
- Garcia-Martinez, A.; Bagnulo, M. An Integrated Approach to Prevent Address Spoofing in IPv6 Links. IEEE Commun. Lett. 2012, 16, 1900–1902. [Google Scholar] [CrossRef] [Green Version]
- Dawood, H. IPv6 security vulnerabilities. Int. J. Inf. Secur. Sci. 2012, 1, 100–105. [Google Scholar]
- Shue, C.A.; Gupta, M.; Myers, S.A. IPSec: Performance Analysis and Enhancements. In Proceedings of the 2007 IEEE International Conference on Communications, Glasgow, Scotland, 24–28 June 2007; pp. 1527–1532. [Google Scholar] [CrossRef] [Green Version]
- Schulz, M.; Klapper, P.; Hollick, M.; Tews, E.; Katzenbeisser, S. Trust The Wire, They Always Told Me! On Practical Non-Destructive Wire-Tap Attacks Against Ethernet. In Proceedings of the 9th ACM Conference on Security & Privacy in Wireless and Mobile Networks, Darmstadt, Germany, 18–20 July 2016; pp. 43–48. [Google Scholar] [CrossRef]
- Anbar, M.; Abdullah, R.; Saad, R.M.; Alomari, E.; Alsaleem, S. Review of security vulnerabilities in the IPv6 neighbor discovery protocol. In Information Science and Applications (ICISA) 2016; Springer: Berlin/Heidelberg, Germany, 2016; pp. 603–612. [Google Scholar]
- Voss, W. A Comprehensible Guide to Controller Area Network; Copperhill Media: Greenfield, MA, USA, 2008. [Google Scholar]
- Hou, C.; Jiang, H.; Yang, Y.; Rui, W.; Hu, L. Research on Implementing Real Time Ethernet for Ship Power System. In Proceedings of the 2010 2nd International Workshop on Intelligent Systems and Applications, Wuhan, China, 27 May 2010; pp. 1–4. [Google Scholar] [CrossRef]
- Furumoto, K.; Kolehmainen, A.; Silverajan, B.; Takahashi, T.; Inoue, D.; Nakao, K. Toward Automated Smart Ships: Designing Effective Cyber Risk Management. In Proceedings of the 2020 International Conferences on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData) and IEEE Congress on Cybermatics (Cybermatics), Rhodes, Greece, 2–6 November 2020; pp. 100–105. [Google Scholar] [CrossRef]
- Caprolu, M.; Pietro, R.D.; Raponi, S.; Sciancalepore, S.; Tedeschi, P. Vessels Cybersecurity: Issues, Challenges, and the Road Ahead. IEEE Commun. Mag. 2020, 58, 90–96. [Google Scholar] [CrossRef]
- Taylor, A.; Japkowicz, N.; Leblanc, S. Frequency-based anomaly detection for the automotive CAN bus. In Proceedings of the 2015 World Congress on Industrial Control Systems Security (WCICSS), London, UK, 14–16 December 2015; pp. 45–49. [Google Scholar] [CrossRef]
- Kim, J.; Yim, J.; Kang, Y.; Park, Y. Comparison of COTS inertial sensors for getting marine elevator’s platform tilt values. In Proceedings of the 2015 International Conference on Information and Communication Technology Convergence (ICTC), Jeju, Korea, 28–30 October 2015; pp. 989–992. [Google Scholar] [CrossRef]
- LabSat. LabSat 3. 2021. Available online: https://www.labsat.co.uk/index.php/en/products/labsat-3 (accessed on 23 February 2021).
- NMEAsoft. GPS Simulator. 2021. Available online: http://www.nmeasoft.com/product/gpssimulator/ (accessed on 23 February 2021).
- Lund, M.S.; Hareide, O.S.; Jøsok, O. An Attack on an Integrated Navigation System. Necesse 2018, 3, 149–163. [Google Scholar] [CrossRef]
- Balduzzi, M.; Pasta, A.; Wilhoit, K. A security evaluation of AIS automated identification system. In Proceedings of the 30th Annual Computer Security Applications Conference, New Orleans, LA, USA, 8–12 December 2014; pp. 436–445. [Google Scholar]
- Kessler, G. Protected AIS: A demonstration of capability scheme to provide authentication and message integrity. TransNav Int. J. Mar. Navig. Saf. Sea Transp. 2020, 14, 279–286. [Google Scholar] [CrossRef]
- Stewart, A.; Rice, E.; Safonov, P. Digital Authentication Strategies for the Automated Identification System. Available online: http://micsymposium.org/mics2018/proceedings/MICS_2018_paper_64.pdf (accessed on 12 April 2021).
- National Marine Electronics Association. OneNet Standard for IP Networking of Marine Electronic Devices; National Marine Electronics Association: Reston, VA, USA, 2021; Available online: https://www.nmea.org/content/STANDARDS/OneNet (accessed on 23 February 2021).
- Lázaro, F.; Raulefs, R.; Wang, W.; Clazzer, F.; Plass, S. VHF Data Exchange System (VDES): An enabling technology for maritime communications. CEAS Space J. 2019, 11, 55–63. [Google Scholar] [CrossRef] [Green Version]
- Ruan, N.; Hori, Y. DoS attack-tolerant TESLA-based broadcast authentication protocol in Internet of Things. In Proceedings of the 2012 International Conference on Selected Topics in Mobile and Wireless Networking, Avignon, France, 2–4 July 2012; pp. 60–65. [Google Scholar]
- Perrig, A.; Canetti, R.; Tygar, J.D.; Song, D. Efficient authentication and signing of multicast streams over lossy channels. In Proceedings of the 2000 IEEE Symposium on Security and Privacy (S P 2000), Berkeley, CA, USA, 14–17 May 2000; pp. 56–73. [Google Scholar] [CrossRef] [Green Version]
- Catak, F.O.; Mustacoglu, A.F. Distributed denial of service attack detection using autoencoder and deep neural networks. J. Intell. Fuzzy Syst. 2019, 37, 3969–3979. [Google Scholar] [CrossRef]
- Zhang, Z.; Li, X.; Wang, X.; Cheng, H. Decentralized Cyber-Physical Systems: A Paradigm for Cloud-Based Smart Factory of Industry 4.0. In Cybersecurity for Industry 4.0; Thames, L.S.D., Ed.; Springer: Cham, Switzerland, 2017; pp. 127–171. [Google Scholar]
- Luo, H.; Wu, K.; Guo, Z.; Gu, L.; Yang, Z.; Ni, L.M. SID: Ship Intrusion Detection with Wireless Sensor Networks. In Proceedings of the 2011 31st International Conference on Distributed Computing Systems, Minneapolis, MN, USA, 20–24 June 2011; pp. 879–888. [Google Scholar] [CrossRef]
- Watrobski, P.; Klosterman, J.; Barker, W.; Souppaya, M. Methodology for Characterizing Network Behavior of Internet of Things Devices (Draft); Technical Report; NIST: Gaithersburg, MD, USA, 2020.
Security Consideration | Primary Risk |
---|---|
Confidentiality | Access to private data |
Integrity | Modification of data |
Availability | Inability to access data or resource |
Authentication | Inability to confirm identity |
Authorization | Improper access to resource or data |
Non-repudiation | Inability to confirm an action made by an identity |
DoS | Spoofing | Packet Sniffing | Relay/Man in the Middle | |
---|---|---|---|---|
TCP/IPv6 | Medium | Medium | Medium | High |
CAN Bus/NMEA 2000 | High | High | High | High |
NMEA 0183 | High | High | High | High |
AIS | High | High | High | High |
OneNet | Medium | High | Low | Low/High |
Publisher’s Note: MDPI stays neutral with regard to jurisdictional claims in published maps and institutional affiliations. |
© 2021 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
Tran, K.; Keene, S.; Fretheim, E.; Tsikerdekis, M. Marine Network Protocols and Security Risks. J. Cybersecur. Priv. 2021, 1, 239-251. https://doi.org/10.3390/jcp1020013
Tran K, Keene S, Fretheim E, Tsikerdekis M. Marine Network Protocols and Security Risks. Journal of Cybersecurity and Privacy. 2021; 1(2):239-251. https://doi.org/10.3390/jcp1020013
Chicago/Turabian StyleTran, Ky, Sid Keene, Erik Fretheim, and Michail Tsikerdekis. 2021. "Marine Network Protocols and Security Risks" Journal of Cybersecurity and Privacy 1, no. 2: 239-251. https://doi.org/10.3390/jcp1020013