Ethical Considerations in Maritime Cybersecurity Research

الاعتبارات الأخلاقية في أبحاث الأمن السيبراني البحري

👤 A. Oruc 📄 TransNav, Vol. 16, No. 2, 2022 🔗 10.12716/1001.16.02.14 ✓ CC BY 4.0

الملخص

النقل البحري، وهو عنصر أساسي في التجارة العالمية، يتم بواسطة السفن المعاصرة. على الرغم من التحسينات التي جلبتها التطورات السريعة في التكنولوجيا إلى كفاءة السفن التشغيلية وقدرتها على الملاحة الآمنة، إلا أن المخاطر السيبرانية المرتبطة بالأنظمة الحديثة تزايدت بنفس الوتيرة. أثارت الدعاية الواسعة النطاق بشأن الحوادث السيبرانية على متن السفن أبحاثاً مكثفة من قبل الجامعات والصناعة والمنظمات الحكومية سعياً لفهم المخاطر السيبرانية. ونتيجة لذلك، اكتشف الباحثون وكشفوا عدداً متزايداً من التهديدات والثغرات في هذا السياق، مما يوفر معلومات قد تشكل في حد ذاتها تهديداً عندما يطلع عليها أطراف غير مرغوب فيهم. وبالتالي، تهدف هذه الورقة إلى زيادة وعي الباحثين بالمخاوف الأخلاقية وتقديم إرشادات لاتخاذ القرارات السليمة في المجالات التي يجب فيها التعامل مع عملية البحث بحذر لتجنب الضرر. لهذه الغاية، تقدم هذه الورقة مراجعة أدبية تستكشف القضايا الأخلاقية المتعلقة بأبحاث الأمن السيبراني البحري وتقدم أمثلة محددة لتعزيز الفهم. تتم مناقشة ستة مبادئ أخلاقية وأربع فئات من المعضلات الأخلاقية. وأخيراً، تقدم الورقة توصيات يمكن أن توجه الباحثين في التعامل مع أي صراعات أخلاقية قد تنشأ أثناء دراسة الأمن السيبراني البحري.

1. المقدمة

يُعتبر النقل بنية تحتية حيوية في نظر العديد من الدول، بما في ذلك الولايات المتحدة [1] والاتحاد الأوروبي [2] والنرويج [3]. أحد وسائط النقل تشمل الممرات المائية وتعتمد حصراً على السفن [4]. في الواقع، تنفذ سفن الشحن أكثر من 80٪ من التجارة العالمية من حيث الحجم [5]. بالإضافة إلى نقل البضائع حول العالم، تخدم السفن أغراضاً أخرى كالتدريب والبحث والصيد [6]. تبحر حالياً أكثر من 620,000 سفينة لأغراض مختلفة، وهي مجهزة بالعديد من أنظمة تكنولوجيا المعلومات (IT) والتكنولوجيا التشغيلية (OT) لأغراض متنوعة مثل الملاحة والدفع والاتصالات ومناولة البضائع والسلامة والأمن.

ومع ذلك، فإن أحد العيوب الرئيسية للتكنولوجيا المتقدمة هو المخاطر السيبرانية. تم الكشف عن العديد من الحوادث السيبرانية التي تؤثر على السفن حتى الآن [7،8]. علاوة على ذلك، كشفت الكثير من الأبحاث عن الثغرات السيبرانية في الأنظمة المحوسبة للسفن الحديثة.

تمثل الأخلاق المعتقدات المجتمعية؛ وعلى هذا النحو، يُوصف السلوك الأخلاقي عموماً بأنه المعايير المقبولة والعالمية [9]. أخلاقيات البحث هي تطبيق المبادئ الأخلاقية على الأنشطة البحثية، بما في ذلك تنظيم البحث وتصميمه وتنفيذه، واحترام المجتمع، واستخدام الموارد، والمخرجات [10]. تعمل اللجان الأخلاقية للأنشطة البحثية في العالم (مثل اللجان النرويجية الوطنية لأخلاقيات البحث) على توفير الوعي وتشجيع تنفيذ المبادئ الأخلاقية المقبولة عموماً [11]. علاوة على ذلك، أصدرت جمعيات مختلفة (مثل الجمعية الطبية العالمية) إعلانات للمبادئ الأخلاقية في مجالات بحثية محددة [12]. والأهم من ذلك، حتى لو كانت المعايير الأخلاقية قد ترتبط بالتشريعات، فإن التشريع لا يُغني عن الأخلاق [13]. وبناءً عليه، يجب أن يكون الباحثون على دراية كاملة بالمبادئ التوجيهية الأخلاقية والمقبولية الأخلاقية لنيتهم الاستقصائية قبل إجراء الدراسة [14].

تختلف أبحاث الأمن السيبراني البحري ومعاييرها الأخلاقية عن مجالات البحث السيبراني الأخرى في عدة أبعاد. فبينما يكون كل باحث مسؤولاً بشكل عام عن توقع العيوب المحتملة التي قد تنشأ عن بحثه، فإن الباحثين في مجال الأمن السيبراني البحري ملزمون بالنظر في الآثار والتداعيات المحتملة لأبحاثهم من منظور أوسع. النقل البحري هو عادة وسيلة نقل دولية يقوم بها طاقم متعدد الجنسيات. قد تؤثر عملية البحث سلباً على العديد من السفن التي ترفع أعلام دول مختلفة وأفراد طاقم من العديد من البلدان. ونتيجة لذلك، قد تنشأ صراعات دولية أثناء البحث أو بعده.

نظراً لأن الأمن السيبراني البحري مجال بحثي جديد نسبياً، لم يتم بعد تحديد أي معايير أخلاقية توجيهية. شهد المجال زيادة في اتجاهات البحث، وتوفر مناصب أكاديمية إضافية، ومشاريع بحثية تركز بشكل خاص على الأمن السيبراني البحري. يشير هذا النمو إلى الحاجة للباحثين والسلطات المسؤولة لمناقشة القضايا الأخلاقية من أجل وضع المعايير التوجيهية الأخلاقية واتباعها في النهاية. وبناءً عليه، تتناول هذه الدراسة المبادئ الأخلاقية والمعضلات المحتملة في أبحاث الأمن السيبراني البحري وتقدم أمثلة محددة لتوضيح النقاط المطروحة فيها. وبالتالي، ستساعد نتائج الدراسة الباحثين والسلطات المسؤولة في حالة وجود أي صراعات أخلاقية تتعلق بدراسات الأمن السيبراني البحري. قد تثبت النتائج فائدتها للباحثين والمعاهد العاملة بالتعاون مع الصناعة أيضاً. الدراسة منظمة على النحو التالي. يعرض القسم الثاني مراجعة للأدبيات ذات الصلة، يتبعها مناقشة المنهجية المستخدمة في الدراسة في القسم الثالث. في القسم الرابع، يتم تحديد المبادئ الأخلاقية والمعضلات في دراسات الأمن السيبراني البحري. وبالتالي، يقدم القسم الخامس ملخصاً ويقترح مواضيع بحثية إضافية للتحقيق المستقبلي.

2. الأعمال ذات الصلة

يتألف كتاب "أخلاقيات الأمن السيبراني" [15] من ثلاثة أجزاء: الأسس والمشكلات والتوصيات. يقدم قسم الأساسيات مقدمة للأمن السيبراني والموضوعات ذات الصلة، مثل التهديدات والدفاعات من حيث أمن البرمجيات وأمن الشبكات وأمن البيانات. بعد ذلك، يعرض الكتاب مناقشة للمشكلات المرتبطة بالموضوع. تشمل الأمثلة المأخوذة من الكتاب المفارقة الأخلاقية، وحرية التواصل السياسي، والقرصنة الأخلاقية وغير الأخلاقية. وأخيراً، تُقترح توصيات مثل المعايير للدول العاملة في الفضاء الإلكتروني وإطار للدفاع السيبراني الأخلاقي للشركات.

في ورقة بيضاء تمثيلية [16]، يوضح المؤلفون الخطاب الأخلاقي وصراعات الأمن السيبراني في ثلاثة مجالات (الصحة والأعمال والأمن القومي)، منظمة في أربعة جوانب (الشخصية الأخلاقية، ملخص مراجعة الأدبيات، تحديد القضايا الأخلاقية، وتوصيف القيم الخاصة بالمجال). كما تشرح الاختلافات بين المجالات. وأخيراً، تقدم الورقة تحليلاً ببليومترياً للمنشورات.

يصف مؤلفو [17] المعايير الأخلاقية للبحث العلمي. تُقسم المبادئ الأخلاقية في الدراسة إلى ثلاث فئات، تشمل الاستقصاء العلمي الأخلاقي، والسلوك الأخلاقي للباحثين، والمعاملة الأخلاقية للمشاركين في البحث. تُطابق هذه الفئات مع المبادئ الأخلاقية للواجب تجاه المجتمع، والإحسان، وتضارب المصالح، والموافقة المستنيرة، والنزاهة، وعدم التمييز، وعدم الاستغلال، والخصوصية والسرية، والكفاءة المهنية، والانضباط المهني.

يركز مؤلفو كتاب "الأخلاقيات والسياسات للعمليات السيبرانية" [18] على القضايا الأخلاقية المحيطة بالهجمات السيبرانية المنسوبة إلى دول. يقدم أحد الفصول ملخصاً لورشة عمل مركز التعاون السيبراني لحلف الناتو حول أخلاقيات وسياسات الحرب السيبرانية في عام 2014. من النتائج الحاسمة لهذه الورشة أن اللوائح المتعلقة بالحرب السيبرانية غير كافية وتحتاج إلى تعريف محدد بسبب المخاوف الأخلاقية.

يركز كتاب آخر [9] على جانبين من أخلاقيات تكنولوجيا المعلومات. يشرح المؤلف أهمية الأخلاقيات في تكنولوجيا المعلومات بلغة بسيطة. وثانياً، يهدف الكتاب إلى مساعدة المديرين في قطاع تكنولوجيا المعلومات على خلق بيئة عمل تُتبع فيها القواعد الأخلاقية. يقدم الكتاب نظرة شاملة للأخلاقيات في تكنولوجيا المعلومات من خلال مناقشة جوانب مختلفة مثل تطوير البرمجيات والملكية الفكرية.

يحقق مؤلفو [20] في الأخلاقيات في أبحاث الأمن السيبراني من خلال فحص حالتين. تناقش هذه الورقة أيضاً المعضلات الأخلاقية وتوصي بتطوير مدونة قواعد سلوك لأبحاث الأمن السيبراني للتغلب على هذه المعضلات. قد تحمي مثل هذه المدونة الباحثين من المطالبات القانونية وتساعدهم على التصرف في مواجهة العوائق الأخلاقية في مجال بحثهم. في النهاية، على الرغم من توفر أوراق وكتب مختلفة تركز على الأخلاقيات في أبحاث الأمن السيبراني، إلا أن أياً منها لا يتناول على وجه التحديد أبحاث الأمن السيبراني البحري. وبالتالي، تسعى هذه الورقة إلى سد هذه الفجوة في المجال.

3. المواد والطرق

تشكل مراجعة الأدبيات أساس هذه الدراسة. تم البحث في قواعد البيانات العلمية بما في ذلك Springer Link و Science Direct و Taylor & Francis Online. كما تم البحث في Google Scholar و ResearchGate و Academia.edu و Web of Science للعثور على منشورات إضافية ذات صلة. تم النظر في الكتب والمقالات الصحفية وأوراق المؤتمرات باللغة الإنجليزية. تم النظر فقط في المنشورات المتعلقة بأخلاقيات البحث - وبشكل خاص، أخلاقيات البحث في الأمن السيبراني. تم تصنيف المبادئ الأخلاقية والمعضلات المكتشفة والتحقيق فيها بالتفصيل. تم استخدام برنامج Citavi [24] لاستخراج البيانات من المقالات وإدارة المعرفة المكتسبة. في الخطوة التالية، تم استبعاد المبادئ والمعضلات غير ذات الصلة بأبحاث الأمن السيبراني البحري. أخيراً، تم إثراء الورقة بحالات وأمثلة من الأمن السيبراني البحري.

بالإضافة إلى ذلك، تم استخدام قاعدتي بيانات IMODOCS و IMO-Vega لاكتشاف الأنشطة المتعلقة بالأمن السيبراني في المنظمة البحرية الدولية (IMO). قاعدة بيانات IMO-Vega، التي تم تطويرها بالاشتراك بين IMO و DNV، تحتفظ بالبيانات التاريخية وتوفر متطلبات IMO المحدثة [25]. IMODOCS هي المنصة الرسمية على الويب التي تقدمها IMO لجعل وثائق IMO متاحة للحكومات الأعضاء والوكالات الحكومية الدولية والمنظمات [26]. تم قبول المؤلف عبر برنامج التدريب الداخلي في IMO، المصمم لطلاب الماجستير والدكتوراه [27]. هذه الحالة سمحت للمؤلف بالوصول إلى IMODOCS بصلاحية أمانة IMO، مما يعني أن المؤلف يمكنه الوصول إلى وثائق وسجلات IMO غير المتاحة للجمهور العام.

4. أخلاقيات البحث في الأمن السيبراني البحري

على مدى العقد الماضي، تزايد الاهتمام بالأمن السيبراني البحري كل عام، كما يمكن رؤيته في نتائج البحث في خدمات مثل Google Trends [28]. يقدم Google Trends قيماً على شكل رسم بياني استناداً إلى مصطلحات البحث والأطر الزمنية التي يحددها المستخدم. تتراوح هذه القيم من 0 إلى 100. يعرض الشكل 1 نتائج بحث عالمي عن كلمة "الأمن السيبراني البحري" للفترة من 1 يناير 2012 إلى 31 ديسمبر 2021. أصبحت بيانات هذا المصطلح قابلة للكشف أول مرة في Google Trends عام 2015. ومع ذلك، بدءاً من عام 2017، تظهر نتائج Google Trends اتجاهاً متزايداً لهذا المصطلح كل عام. قد يكون هذا الارتفاع مرتبطاً بإصدار قرار MSC.428(98) من IMO في 16 يونيو 2017، والذي فرض متطلبات مختلفة على الشركات البحرية بعد 1 يناير 2021 [32]. منذ عام 2014، واكبت IMO التطورات في الأمن السيبراني البحري. في السنوات الأخيرة، ركزت العديد من المشاريع البحثية على الأمن السيبراني في القطاع البحري، مثل MarCy [34] و CySiMS-SE [35] و Cyber-MAR [36] و CyberShip [37]. بالإضافة إلى ذلك، أنشأت الجامعات والمنظمات الحكومية وغير الحكومية مراكز للأمن السيبراني البحري [46-48]. يؤدي النظر الدقيق في أنشطة IMO الحالية والتطورات والاتجاهات البحثية إلى الاستنتاج المنطقي بأن البحث في الأمن السيبراني البحري سيستمر بنشاط في المستقبل. وبناءً عليه، يفرض الحذر ضرورة تحديد المبادئ الأخلاقية ومناقشة المعضلات الأخلاقية.

4.1 المبادئ الأخلاقية في أبحاث الأمن السيبراني البحري

يجب أن تفي أبحاث الأمن السيبراني البحري بستة مبادئ أخلاقية، والتي تشمل النزاهة، المسؤولية المهنية، المساءلة، السرية، القانونية، والانفتاح.

4.1.1 النزاهة

تشير النزاهة إلى صدق الباحث وأمانته [17]. هناك ثلاثة عناصر يجب على الباحث تجنبها بدقة وهي الاختلاق والتزوير والانتحال [49]. الاختلاق يشير إلى اختراع البيانات أو حالة [50]. التزوير يعني التحريف المتعمد للبيانات أو النتائج [50]. الانتحال يعني نسخ الأفكار أو البيانات أو العبارات دون استشهاد [50]. يجب تسمية الأفراد الذين يساهمون في المخطوطة بشكل كبير فقط كمؤلفين. التأليف الوهمي أو التأليف الهدية غير مقبول في الأوساط الأكاديمية. يجب أن يكون الباحث صادقاً فيما يتعلق بالبيانات والنتائج والهدف البحثي في تفسير نتائج البحث. يجب شرح النتائج بالكامل وتجنب التحيز والآراء الشخصية.

4.1.2 المسؤولية المهنية

نظراً لأن الأمن السيبراني البحري مجال بحثي جديد نسبياً، فإن عدد الباحثين المتاحين في هذا المجال أقل مقارنة بمجالات الأمن السيبراني الأخرى. يعتمد تحسين مجال بحثي على باحثين مؤهلين تأهيلاً عالياً. يجب على الباحثين في هذا المجال تثقيف وتدريب وتشجيع العلماء الآخرين في مراحل مبكرة من مسيرتهم المهنية لتوسيع وتحسين مجال البحث. يجب على الباحثين أيضاً السعي لجذب الشباب من خلفيات مختلفة مثل الهندسة الكهربائية وعلوم الكمبيوتر والملاحة البحرية.

يجب اختيار الباحثين وفقاً لمؤهلاتهم، بما في ذلك الخدمة البحرية والخبرة الساحلية والحماس والإنتاجية البحثية والمعرفة. يجب تجاهل الخصائص الشخصية الأخرى مثل الجنس والتوجه الجنسي والجنسية والرأي السياسي والمعتقد الديني. يجب أن يكون الباحثون الرئيسيون عادلين ويعاملون جميع أعضاء مجموعة البحث بالتساوي. يجب على الباحثين السعي للتعرف على الثقافة البحرية الوطنية والدولية، بما في ذلك الهيكل الهرمي، خاصة إذا كان البحث يُجرى على متن السفينة مع البحارة.

4.1.3 القانونية

كل باحث مسؤول عن الامتثال للقواعد واللوائح المحلية، مثل جميع الأفراد الآخرين. قد يؤدي بعض الأبحاث في الأمن السيبراني إلى صراع مع التشريعات. العديد من المكونات على متن السفن تستخدم بروتوكولات الاتصال اللاسلكي، مثل الاتصالات عبر الأقمار الصناعية أو التردد العالي جداً (VHF). أحد هذه المكونات هو نظام تحديد المواقع العالمي (GPS). يمكن أن يتأثر جهاز استقبال GPS بشكل ضار بهجمات التشويش [52]. يتوفر حالياً عدة أنواع من أجهزة تشويش GPS في السوق [53]. ومع ذلك، قد تحظر السلطات القانونية للدول استخدام هذه الأجهزة [54]. لذلك، يجب أن يكون الباحثون على دراية كاملة بالقضايا القانونية قبل بدء الدراسة.

يجب اتباع جميع المتطلبات المنصوص عليها في الاتفاقيات الموقعة. على سبيل المثال، تستخدم العديد من الصناعات اتفاقيات عدم الإفشاء (NDAs) [55]. قد تتضمن مشاريع البحث المتعلقة بالأمن السيبراني البحري شركاء صناعيين. قد يتم اكتشاف ثغرات سيبرانية مختلفة في منتجات الشركاء أثناء الدراسة. في هذه الحالة، يجب أن يتبع أي إجراء يتم اتخاذه الاتفاقيات الموقعة. يجب على الباحث ألا يستغل أو يسمح لأي شخص آخر باستغلال ثغرة مكتشفة.

4.1.4 المساءلة

الباحثون مسؤولون أيضاً عن اتخاذ جميع الإجراءات الوقائية الممكنة قبل بدء الدراسة. يجب أن تقلل منهجية الدراسة من جميع الأضرار المحتملة (للأصول أو المكونات أو البيئة) ومخاطر السلامة. أثناء الدراسة، يجب على الباحث الاعتناء بالمكونات على متن السفينة وتجنب التلف. أي ضرر لمكون مثل ECDIS أو البوصلة الجيروسكوبية أو AIS يمكن أن يؤدي إلى فقدان صلاحية السفينة للإبحار. قد يُمنع إبحار السفينة من قبل السلطات البحرية حتى يتم إصلاح المكونات التالفة.

قد يؤثر مشروع بحثي على أكثر من سفينة واحدة، بل ربما العديد من السفن في منطقة محددة. على سبيل المثال، قد يؤثر البحث المتعلق بـ GNSS على أنظمة GNSS للعديد من السفن في المنطقة، مما قد يؤدي إلى حادث بحري محتمل. وبالتالي، قبل بدء الدراسة، يجب على الباحثين وضع الأساس المناسب بسبب مساءلتهم للنظر في العديد من الجوانب المختلفة مثل حركة السفن وظروف البحر والطقس والرحلات واتفاقيات تأجير السفن وقيمة الأصول. كل باحث مسؤول بشكل كامل عن مساهمته في البحث.

4.1.5 السرية

قد تتجنب الشركات البحرية الكشف عن الحوادث السيبرانية على متن سفنها بسبب المخاوف التجارية. بالإضافة إلى السفن التجارية، يمكن للسفن الحربية أيضاً أن تواجه حوادث سيبرانية؛ ومع ذلك، تتجنب القوات البحرية للدول نشر مثل هذه الحوادث بسبب مخاوف الأمن القومي. وبناءً عليه، لا ينبغي مشاركة الحوادث دون إذن الأطراف المعنية.

يجوز للباحثين إجراء دراسات بالتعاون مع عناصر من الصناعة البحرية. على سبيل المثال، يمكن استخدام السفن العاملة لإجراء اختبارات الاختراق [56،57]. لا ينبغي أن تكون نتائج اختبار الاختراق متاحة لأي شخص، بما في ذلك الطاقم على متن السفينة، غير الموظفين المعينين في الشركات البحرية، ولا ينبغي نشرها في أي بيئة دون إذن الشركة البحرية. للدراسة القدرة على اكتشاف الثغرات السيبرانية في أي من الأنظمة على متن السفينة، والتي قد تعرض الملاحة الآمنة للخطر [52،58]. يجب على الباحثين الأخلاقيين، قبل الكشف عن الثغرات في المعدات، إبلاغ الشركات المصنعة مع السماح لهم بالوقت لإزالة الثغرات في منتجاتهم.

يجب حماية البيانات الشخصية للطاقم والركاب والموظفين المرتبطين بالبحث بشكل صارم. تحافظ مراكز بحثية مختلفة على بيانات البحث، مثل المركز النرويجي لبيانات البحث (NSD) في النرويج، الذي يقدم تخزيناً آمناً لبيانات البحث مع حماية خصوصية الأفراد والمنظمات.

4.1.6 الانفتاح

يجب على الباحثين دائماً مراعاة رفاهية الصناعة البحرية مع جميع أصحاب المصلحة، مثل IMO والبحارة وشركات الشحن وهيئات التصنيف والدول المصنعة والمنظمات الحكومية وغير الحكومية الأخرى. يجب تعظيم فائدة البحث، بما في ذلك المعلومات التي ينبغي نشرها وكيفية القيام بذلك. يجب مشاركة نتائج البحث مع أصحاب المصلحة بلغة مناسبة للمستوى الفني للجمهور المستهدف.

الانفتاح يحسن المصداقية والثقة. يجب أن يصف تقرير البحث بوضوح الطريقة المنفذة وجميع الأدوات المستخدمة ونتائج البحث. علاوة على ذلك، ينبغي مشاركة مجموعة البيانات والأدوات المطورة المستخدمة في الدراسة عبر منصات (مثل GitHub) إذا لم تكن هناك قيود مطلوبة. بهذه الطريقة، سيكون الباحثون الآخرون قادرين على تكرار البحث باستخدام نفس البيانات والطريقة لتأكيد دقة النتائج التي تم الحصول عليها. يجب أن يكون الباحثون دائماً منفتحين على النقد.

4.2 المعضلات الأخلاقية في أبحاث الأمن السيبراني البحري

مجال الأمن السيبراني البحري، مثل العديد من مجالات البحث، يشمل معضلات أخلاقية متنوعة. وبالتالي، فإن وجود لجنة أخلاقية في منظمة أو بدلاً من ذلك، لجنة أخلاقية خارجية، يمكن أن يكون مفيداً في التعامل مع مثل هذه المعضلات الأخلاقية [59]. يشرح هذا القسم المعضلات الأخلاقية المتعلقة بدراسات الأمن السيبراني البحري.

4.2.1 البحث في الهجمات السيبرانية التي ترعاها الدول

الأمن السيبراني للدول هو جانب آخر من الأمن القومي. قد تُنفذ الهجمات السيبرانية لأغراض مختلفة مثل التجسس السيبراني والمراقبة وتعطيل الأنظمة المستهدفة [60]. علاوة على ذلك، قد يتأثر المدنيون، بما في ذلك مواطني الدول المهاجمة، بالهجمات السيبرانية التي ترعاها الدول [15]. تُشغَّل السفن المدنية لأغراض متنوعة بما في ذلك التدريب والتجارة والبحث والإنقاذ. ومع ذلك، بسبب أبحاث الدفاع الوطني، تتأثر العديد من السفن المدنية بهجمات سيبرانية ترعاها الدول [8]. أصدرت منظمة C4ADS تقريراً يفيد بأن 1,311 سفينة مدنية تأثرت على مدى عامين بهجمات انتحال GNSS الروسية [8].

كما أوضح هذا النقاش، فإن السفن المدنية والصناعة البحرية الخاصة هي أهداف محتملة للهجمات التي ترعاها الدول. وبالتالي، يطرح السؤال حول ما إذا كان البحث الذي يدعم تطوير أساليب هجوم سيبراني جديدة لصالح بلد الباحث هو أمر أخلاقي أصلاً.

4.2.2 تطوير الخدمات والأدوات

الخدمات والأدوات التي تُطور للتقييم الأمني قد تكون متاحة لأي شخص. ومع ذلك، يمكن لهذه الخدمات والأدوات أن تساعد الجهات الخبيثة، بالإضافة إلى مسؤولي الأنظمة، في اكتشاف الأنظمة غير الآمنة. وبالتالي، فإن تطوير وإطلاق هذه الخدمات يؤدي إلى معضلات أخلاقية [63]. تتوفر خدمات الإنترنت التي تسمح بالمراقبة المستمرة، مثل Shodan.io و Censys.io، لدعم مسؤولي الأنظمة. يمكن للمستخدمين الحصول على النتائج التي يحتاجونها من خلال البحث بالنص الكامل. يمكن للجهات الخبيثة استغلال النتائج التي تنشرها هذه الخدمات [65].

أدوات اكتشاف الثغرات مفيدة لمحللي الأمن الذين يمكنهم اتخاذ الاحتياطات ضد المخاطر السيبرانية. ومع ذلك، فإن هذه الأدوات توفر أسلحة فعالة بنفس القدر للمهاجمين، على الرغم من أنها لا تشكل برامج ضارة بحد ذاتها. يمكن تطوير أدوات للدراسة وتوزيعها على منصات عامة (مثل GitHub) كجزء من النشر العلمي. تم تطوير أدوات متنوعة للتقييم الأمني للأنظمة البحرية بشكل خاص، مثل أداة BRAT [66]. في دراسة أخرى، شارك الباحثون المعلومات جزئياً فقط في GitHub حول الأدوات المستخدمة في تسليح AIS [58،67].

4.2.3 مشاركة تفاصيل الحوادث السيبرانية الفعلية

يمكن أن تكون مشاركة المعلومات حول الحوادث السيبرانية الفعلية مثمرة لتعزيز الوعي وتقليل الثغرات وإدارة المخاطر وتحسين المرونة السيبرانية [68]. يمكن لأصحاب المصلحة في الصناعة البحرية اتخاذ موقف ضد الهجمات السيبرانية المحتملة أو المساهمة في التخفيف منها. على النقيض من ذلك، يمكن للجهات الخبيثة أيضاً إدراك الثغرات وربما مهاجمة ضحايا محتملين آخرين في الصناعة من خلال استغلال الثغرة المكشوفة. تتكون تقارير الحوادث السيبرانية من أنواع مختلفة من المعلومات مثل التهديدات والثغرات والتدابير والتوصيات والتحليل [69].

في إحدى الحالات، سيطر جهة خبيثة بشكل كامل على نظام الملاحة لسفينة حاويات لمدة 10 ساعات [7]. لا تتوفر تفاصيل فنية عن هذا الحادث في الأدبيات المفتوحة. ومع ذلك، نظراً لأن العديد من السفن قد يكون لديها ثغرات مماثلة، فإن نفس نوع الهجوم يشكل خطراً على ملاحتها الآمنة. كان الكشف عن التفاصيل سيجبر شركات أخرى في الصناعة البحرية على اتخاذ إجراءات تصحيحية. على النقيض من ذلك، يحمل الكشف عن تفاصيل الهجوم خطر جذب مهاجمين محتملين آخرين، والذين يمكنهم استخدام هذه التفاصيل لاستغلال الثغرات المكشوفة.

4.2.4 معضلات أخرى

كما ذكر سابقاً، قد يتم تنفيذ مشروع بحثي بالتعاون مع مطوري المنتجات. قد يطلب أحد أصحاب المصلحة في مثل هذا المشروع تحليل ثغرات لمكون بحري محدد لا يستخدمونه أو ينتجونه. من المحتمل جداً أن يكون هذا المنتج مرتبطاً بمنافس. نظراً لأن الباحث لا يمكنه ضمان كيف سيستخدم صاحب المصلحة ثغرة محتملة يتم اكتشافها، فإن قبول أو رفض مثل هذا الطلب من قبل الباحث يمثل صراعاً [70].

أثناء التحقيق البحثي، قد يكتشف الباحثون ثغرة حرجة في أحد المكونات. حتى عندما يمنح الباحثون البائعين الوقت لتصحيح المشكلة، قد لا يقوم المصنعون بإصلاح المشكلة أو الكشف عنها لأسباب مختلفة، مثل الخوف من فقدان السمعة أو التأثير المالي السلبي على الشركة. قد تفتح هذه الثغرة المحتملة إمكانية وقوع حوادث بحرية، مما يؤدي إلى إلحاق الضرر بالبحارة أو السفن أو البيئة. في حالة وجود اتفاقية بين الأطراف (مثل NDA)، قد تعيق الاتفاقية القدرة على إعلام المجتمع البحري بالثغرات المحتملة.

أحد أهم الصراعات في الأمن السيبراني هو بين الخصوصية الشخصية والأمن [71،72]. على سبيل المثال، جعلت تقنية VSAT الإنترنت أكثر سهولة للبحارة اليوم. قد تجعل أبحاث الأمن السيبراني على شبكة سفينة حية بيانات البحارة الحساسة أكثر سهولة للوصول إليها من قبل الباحثين. على وجه التحديد، قد يتضمن هذا البحث تسجيل ومراقبة وتحليل أنشطة البحارة في الشبكة، بما في ذلك نشاطهم على الإنترنت.

5. الخاتمة

اجتذب الأمن السيبراني البحري اهتماماً متزايداً، وتسارع في السنوات الأخيرة، كما يتضح من النمو المشار إليه بواسطة Google Trends حول هذا الموضوع. ناقشت هذه الورقة المبادئ الأخلاقية الستة الأساسية التي يجب أن توجه أبحاث الأمن السيبراني البحري: النزاهة، المسؤولية المهنية، القانونية، المساءلة، السرية، والانفتاح. كما تم تحديد أربع فئات من المعضلات الأخلاقية التي قد يواجهها الباحثون وتقديم أمثلة واقعية: البحث في الهجمات السيبرانية التي ترعاها الدول، تطوير الخدمات والأدوات، مشاركة تفاصيل الحوادث السيبرانية الفعلية، ومعضلات أخرى. لكل معضلة، تمت مناقشة الاعتبارات ذات الصلة لتسليط الضوء على الطبيعة المزدوجة المحتملة لهذه القضايا. قدمت الورقة أيضاً توصيات عملية لمساعدة الباحثين على تجنب الأذى أو التخفيف منه في دراساتهم واقترحت مجالات للتحقيق المستقبلي. في الختام، يجب أن يكون الباحثون في الأمن السيبراني البحري على دراية كاملة بالآثار الأخلاقية لأعمالهم وأن يسعوا جاهدين لتحقيق أعلى معايير النزاهة الأكاديمية والمسؤولية المهنية لحماية جميع أصحاب المصلحة في النظام البيئي البحري. من خلال الالتزام بهذه المبادئ التوجيهية الأخلاقية، يمكن لمجتمع أبحاث الأمن السيبراني البحري ضمان مساهمة عملهم بشكل إيجابي في سلامة وأمن النقل البحري مع تقليل الضرر المحتمل.

المراجع

قائمة المراجع الكاملة (72 مصدراً) متاحة في الملف الأصلي للPDF.

Abstract

Maritime transportation, an essential component of world trade, is performed by contemporary vessels. Despite the improvements that rapid advances in technology have brought to vessels' operational efficiency and capability for safe navigation, the cyber risks associated with modern systems have increased apace. Widespread publicity regarding cyber incidents onboard ships has sparked extensive research on the part of universities, industry, and governmental organisations seeking to understand cyber risks. Consequently, researchers have discovered and disclosed an increasing number of threats and vulnerabilities in this context, providing information that in itself may pose a threat when accessed by the wrong parties. Thus, this paper aims to raise researchers' awareness of ethical concerns and provide guidance for sound decision-making in areas where the research process must be handled carefully to avoid harm. To this end, this paper presents a literature review that explores the ethical issues involved in maritime cybersecurity research and provides specific examples to promote further understanding. Six ethical principles and four categories of ethical dilemmas are discussed. Finally, the paper offers recommendations that can guide researchers in dealing with any ethical conflicts that may arise while studying maritime cybersecurity.

1. Introduction

Transportation is accepted as a critical infrastructure in the view of many countries, including the USA [1], the EU [2] and Norway [3]. One transportation mode involves waterways and relies exclusively on vessels [4]. In fact, cargo vessels execute over 80% of world trade by volume [5]. Besides carrying cargo around the world, vessels serve other purposes, as well. Today, over 620,000 vessels sail for different purposes, not only transporting cargo but supporting a variety of other endeavours, such as training, research, and fishing [6]. Modern vessels are equipped with many information technology (IT) and operational technology (OT) systems for various purposes, such as navigation, propulsion, communication, cargo handling, safety, and security.

However, a major drawback of advancing technology is cyber risks. Numerous cyber incidents affecting onboard ships have been disclosed to date [7,8]. Moreover, much research has revealed the cyber vulnerabilities of modern vessels' computerised systems.

Ethics represent societal beliefs; along these lines, ethical behaviour is generally described as accepted and universal norms [9]. Research ethics is the implementation of ethical principles in application of ethical principles to research activities, including the regulation of research, design and implementation of research, respect for society, the use of resources, and outputs [10]. Ethical committees for research activities in the world (e.g. Norwegian National Research Ethics Committees) operate to provide awareness and encourage the implementation of generally accepted ethical principles [11]. Moreover, various associations (e.g. World Medical Association (WMA)) have issued proclamations of ethical principles in specific research fields [12]. Importantly, even though ethical norms may be linked with legislation, legislation is no substitute for morality [13]. Accordingly, researchers should be fully aware of ethical guidelines and the ethical acceptability of their investigative intent before performing a study [14].

Maritime cybersecurity research and its ethical norms differ from other areas of cyber research in several dimensions. While, in general, each researcher is responsible for anticipating the potential drawbacks that may arise from their research, in the area of maritime cybersecurity, researchers are obligated to consider the implications and potential repercussions of their research from a wider perspective. Maritime transportation is typically an international mode of transportation performed by a multinational crew. The research process may impact negatively many vessels operating under the flags of different states and crew members from many countries. As a result, international conflicts may arise during or after research.

Given that maritime cybersecurity is a relatively new research field, any guiding ethical norms have not yet been defined. The field has seen an increase in research trends, additional academic positions becoming available, and research projects focused specifically on maritime cybersecurity. Such growth points to the need for researchers and responsible authorities to discuss ethical issues in order to establish and ultimately follow ethical guidelines. Accordingly, this study addresses ethical principles and potential dilemmas in maritime cybersecurity research and provides specific examples to illustrate the points made herein. Thus, the study findings will assist researchers and responsible authorities in the case of any ethical conflicts regarding maritime cybersecurity studies. The study findings may prove useful for researchers and institutes working in collaboration with industry, as well. The study is organised as follows. Section two presents a review of the related literature, followed by a discussion of methodology used in the study in section three. In section four, ethical principles and dilemmas in maritime cybersecurity studies are identified. Consequently, section five offers a summary and suggests additional research topics for further investigation.

2. Related Work

The book Ethics of Cybersecurity [15] comprises three parts: foundations, problems, and recommendations. The foundation section provides an introduction to cybersecurity and relevant topics, such as threats and defences in terms of software security, network security, and data security. Next, the book presents a discussion of problems associated with the topic. Examples taken from the book include the ethical paradox, freedom of political communication, and ethical and unethical hacking. Finally, recommendations are proposed, such as norms for states engaging in cyberspace and a framework for ethical cyber defence for companies.

In a representative white paper [16], the authors outline ethical discourse and conflicts of cybersecurity in three domains (health, business, and national security), organised into four aspects (moral character, a literature review summary, identification of ethical issues, and domain-specific value characterisation). The differences between domains are also explained. Lastly, the paper provides a bibliometric analysis of publications, including the number of papers published per year and per domain, the geographic origin of various papers, funding, and citation patterns.

The authors of [17] describe ethical norms of scientific research. Ethical principles in the study are divided into three categories, which comprise ethical scientific inquiry, ethical conduct and behaviours of researchers, and ethical treatment of research participants. Such categories are matched with ethical principles of duty to society, beneficence, conflict of interest, informed consent, integrity, nondiscrimination, nonexploitation, privacy and confidentiality, professional competence, and professional discipline. The book also addresses emerging ethics topics, such as big data, open data, and open science.

The authors of the book Ethics and Policies for Cyber Operations [18] focus on the ethical issues surrounding accused state-sponsored cyberattacks. One chapter in particular presents a summary of the NATO Cooperative Cyber Defence Centre of Excellence (NATO CCDCOE) workshop on Ethics and Policies for Cyber Warfare in 2014. A crucial finding of this workshop is that regulations for cyber warfare are inadequate and require specific definition because of ethical concerns.

Another book [9] focuses on two aspects of IT ethics. First, the author explains in layman's terms the importance of ethics in IT. Second, the book aims to help managers in the IT sector create a work environment where ethical rules are followed. The book provides a comprehensive view of ethics in IT through its discussion of different aspects, such as software development, intellectual property, ethics for IT workers and IT users, and the ethics of IT organisations. Along similar lines, [13] describes the ethical responsibilities of cybersecurity professionals and organisations.

The authors of [20] investigate ethics in cybersecurity research through an examination of two cases. This paper also discusses ethical dilemmas and recommends developing a code of conduct for cybersecurity research to overcome these dilemmas. Such a code may protect researchers against legal claims and assist them in acting in the face of ethical barriers in their research field. Ultimately, while various papers and books focused on ethics in cybersecurity research are currently available, none of these addresses specifically to maritime cybersecurity research. Thus, this paper seeks to fill this gap in the field.

3. Materials and Methods

A literature review forms the foundation of this study. Scientific databases, including Springer Link, Science Direct, and Taylor & Francis Online, were searched. Google Scholar, ResearchGate, Academia.edu, and Web of Science were also searched to seek out additional relevant publications. Books, journal articles, and conference papers in English were considered. Only publications concerning research ethics – in particular, research ethics in cybersecurity – were considered. The discovered ethical principles and dilemmas were classified and investigated in detail. Citavi software [24] was used to extract data from the articles and manage the acquired knowledge. In the next step, irrelevant principles and dilemmas in relation to maritime cybersecurity research were eliminated. Finally, the paper was enriched with cases and examples of maritime cybersecurity.

Additionally, the IMODOCS and IMO-Vega Database were used to discover cybersecurity-related activities in the IMO. The IMO-Vega Database, developed jointly by the IMO and DNV, maintains historical data and provides up-to-date IMO requirements [25]. The IMODOCS is the official web platform offered by the IMO to make IMO documents available for IMO member governments, intergovernmental agencies, and organisations in consultative status with the IMO [26]. The author was accepted via the IMO Internship Programme, which is designed for master students and Ph.D. candidates [27]. This status allowed the author to access the IMODOCS with the membership authority of the IMO Secretariat (Maritime Knowledge Centre), meaning that the author could access more IMO documents and records not available to the general public.

4. Research Ethics in Maritime Cybersecurity

Over the past decade, interest in maritime cybersecurity has been increasing every year, as can be seen in the results found by searching services such as the Google Trends website [28]. Google Trends presents values in the form of a graph based on user-specified search terms and time frames, ranging from 0 to 100. Figure 1 displays the results of a worldwide search for the keyword maritime cybersecurity for the period spanning 1 January 2012 to 31 December 2021. Data for the term first became detectable by Google Trends in 2015. However, starting in 2017, the Google Trends results demonstrate an increasing trend for this term every year. This increase may be connected to the issuance of IMO Resolution MSC.428(98) on 16 June 2017, which imposed various requirements on maritime companies after 1 January 2021 [32]. Since 2014, the IMO has kept up-to-date on maritime cyber security. In recent years, numerous research projects have focused on cybersecurity in the maritime sector, such as MarCy [34], CySiMS-SE [35], Cyber-MAR [36], and CyberShip [37]. Moreover, maritime cybersecurity centres have been established by universities as well as governmental or non-governmental organisations [46–48]. Careful consideration of current IMO activities, research advances and tendencies leads to the logical conclusion that research on maritime cybersecurity will actively continue in the future. Accordingly, prudence dictates the necessity to identify ethical principles and discuss ethical dilemmas.

4.1 Ethical Principles in Maritime Cybersecurity Research

Maritime cybersecurity research should meet six ethical principles, which include integrity, professional responsibility, accountability, confidentiality, legality, and openness.

4.1.1 Integrity

Integrity refers to researchers' truthfulness and honesty [17]. Three elements that a researcher must strictly avoid are fabrication, falsification, and plagiarism [49]. Fabrication refers to the invention of data or a case [50]. Falsification denotes the intentional distortion of data or results [50]. Plagiarism means the copying of ideas, data, or statements without citation [50]. Only individuals who contribute to the manuscript significantly should be named as authors. Ghost or gift authorships are not acceptable in academia. The researcher must be honest regarding the data, results, and research objective in interpreting the research results. Findings should be explained fully. Bias and personal opinions must be avoided.

4.1.2 Professional Responsibility

Given that maritime cybersecurity is a relatively new research field, fewer researchers are available in the field compared to other cybersecurity-oriented fields of study. The improvement of a research field depends on highly qualified researchers. Researchers in the field should educate, train, recommend, support, and encourage other scholars who are at an early point in their careers to extend and improve the research field. The researchers should also strive to attract young people from different backgrounds, such as electrical engineering, computer science, and maritime.

Researchers should be selected according to their qualifications, including sea service, shore experience, enthusiasm, research productivity, and knowledge. Other personal characteristics should be disregarded, such as gender, sexual orientation, nationality, political view, and religious belief. The lead researchers should be fair and treat all members of the research group equally. Researchers should endeavour to familiarise themselves with national and international maritime culture, including hierarchical structure, especially if the research is performed onboard with seafarers.

4.1.3 Legality

Each researcher is responsible for obeying local rules and regulations, like all other individuals. Some cybersecurity research could lead to a conflict with legislation. Several types of components onboard ships use wireless communication protocols, such as satellite or very high frequency (VHF) communications. One such component is the Global Positioning System (GPS). A GPS receiver can be adversely affected by jamming attacks [52]. Thus, several types of GPS jamming devices are currently available on the market [53]. However, the use of such devices may be prohibited by legal authorities of states like in the USA [54]. Therefore, researchers must be fully familiar with legal issues before beginning a study.

All requirements that are stipulated in signed agreements must be followed. For example, many industries employ non-disclosure agreements (NDAs) [55]. Furthermore, maritime cybersecurity-related research projects may involve industry partners. Various cyber vulnerabilities in the products developed by partners might be detected during a study. In such a case, any action taken must follow the signed agreements. A researcher should neither exploit nor allow any other person to exploit a detected vulnerability.

4.1.4 Accountability

Researchers are also accountable to take all possible protective actions before starting a study. The study methodology should minimise all potential (asset, component, or environmental) damage and safety hazards. During a study, the researcher should care for the components onboard a ship and avoid damage. Any damage to a component, such as ECDIS, gyro compass, and AIS, can lead to a loss of the vessel's seaworthiness. Thus, the sailing of the vessel could be forbidden by maritime authorities until the damaged components are fixed.

A research project may affect more than a single vessel, possibly even many vessels in a specific zone. For instance, research concerning GNSS may affect the GNSS systems of many vessels in the zone, potentially precipitating a marine accident. Thus, before starting a study, researchers must lay the appropriate groundwork due to their accountability to consider many different aspects involved, such as vessel traffic, sea and weather conditions, voyages, charter party agreements, and asset value. Each researcher is totally accountable for his own contribution to the research.

4.1.5 Confidentiality

Maritime companies might avoid disclosing the onboard cyber incidents their vessels have encountered because of commercial concerns. Besides commercial vessels, warships can also experience cyber incidents; however, nations' naval forces avoid publicising such incidents because of national security concerns. Accordingly, incidents should not be shared without the permission of the related parties.

Scholars may conduct studies in collaboration with elements of the maritime industry. For instance, vessels in service can be used to conduct pen tests [56,57]. The results of such a pen test should not be available to anyone, including the crew on board, other than nominated staff in maritime companies and should not be published in any environment without the permission of the maritime company. A study has the potential to discover cyber vulnerabilities in any onboard systems, which may endanger the safe navigation of the vessel [52,58]. Therefore, before disclosing vulnerabilities in equipment, ethical researchers should inform the manufacturers while also allowing them time to eliminate the vulnerabilities in their products.

The personal data of crew, passengers, and office staff associated with research should be strictly protected. Various research centres maintain research data, such as the Norsk Senter for Forskningsdata (NSD – Norwegian Centre for Research Data) in Norway, which offers secure storage of research data while protecting the privacy of individuals and organisations.

4.1.6 Openness

Researchers should always consider the well-being of the maritime industry with all stakeholders, such as IMO, seafarers, cadets, shipping companies, class societies, flag states, manufacturers, and any other governmental and non-governmental organisations. Moreover, researchers should maximise the research benefit, including what information should be disseminated, as well as how this should be done, as a significant topic. Research results should be shared with stakeholders using language that is suited to the appropriate technical level for the intended audience.

Openness improves credibility and trust. A research report should clearly describe the implemented method as well as all tools used and the research findings. Moreover, the data set and developed tools used in the study should be shared through platforms (e.g. GitHub) if no restrictions are required. In this way, other researchers will be able to replicate the research using the same data and method to confirm the accuracy of the obtained results. Researchers should always be open to critique.

4.2 Ethical Dilemmas in Maritime Cybersecurity Research

The field of maritime cybersecurity, like many research fields, includes various ethical dilemmas. Thus, an ethical committee in an organisation or, alternatively, an external ethical committee could be beneficial in coping with such ethical dilemmas [59]. Hence, this section explains ethical dilemmas relating to maritime cybersecurity studies.

4.2.1 Research on State-Sponsored Cyberattacks

Cybersecurity for states is another facet of national security. Cyberattacks may be performed for different purposes, such as cyber espionage, surveillance, and disruption of the target systems [60]. Furthermore, civilians, including the attacking states' own citizens, may be affected by state-sponsored cyberattacks [15]. Civilian vessels are operated for a variety of purposes, including training, commercial, research, rescue, and so on. However, because of national defence research, many civilian vessels are affected by state-sponsored cyberattacks [8]. In 2019, C4ADS released a report entitled Above Us Only Stars, according to which 1,311 civilian vessels were affected over a two-year period by Russian GNSS spoofing attacks [8].

As this discussion has shown, civilian vessels and the private marine industry are potential targets of state-sponsored attacks. Thus, the question arises as to whether research supporting the development of novel cyberattack methods for the benefit of the researcher's own country is even ethical.

4.2.2 Developing Services and Tools

Services and tools that are developed for security assessment may be accessible to anyone. However, such services and tools can help malicious actors, in addition to system administrators, detect insecure systems. Thus, developing and launching these services leads to ethical dilemmas [63]. Internet services that allow for continuous monitoring, such as Shodan.io and Censys.io, are available to support system administrators. Users of these services can obtain the results they need through a full-text search. Malicious actors may exploit the results that these services publish [65].

Vulnerability detection tools are useful for security analysts who can take precautions against cyber risks. However, the tools offer equally effective weapons for attackers, even though they do not constitute harmful software on their own. Tools can be developed for a study and distributed on public platforms (e.g. GitHub) as part of a scientific publication. Various tools have been developed for security assessment of marine systems in particular, such as the BRidge Attack Tool (BRAT) [66]. In another study, the researchers only partially shared information in GitHub about tools used in AIS weaponisation [58,67].

4.2.3 Sharing Details of Actual Cyber Incidents

Information sharing about actual cyber incidents can be fruitful to enhance awareness, decrease vulnerabilities, manage risk, and improve cyber resilience [68]. Stakeholders in the maritime industry may take a position against potential cyberattacks or contribute to mitigation. Contrariwise, malicious actors can also realise the vulnerability and possibly attack other potential victims in the industry by exploiting the disclosed vulnerability. Cyber incident reports consist of various information types, such as threats, vulnerabilities, measures, recommendations, and analysis [69].

In one case, a malicious actor took full control of the navigation system of a container vessel for 10 hours [7]. No technical details from this incident are available in the open literature. Nevertheless, because many vessels might have similar vulnerabilities, the same type of attack is also a danger to their safe navigation. Disclosing the details would have compelled other companies in the maritime industry to take corrective action. Contrariwise, disclosing the attack details bears the risk of attracting other potential attackers, who could use such details to exploit the exposed vulnerabilities.

4.2.4 Other Dilemmas

As previously mentioned, a research project might be performed with the collaboration of product developers. A stakeholder in such a project may request a vulnerability analysis for a specific marine component that they neither use nor produce. It is highly possible that such a product could be related to a competitor. Because a researcher cannot ensure how the stakeholder will use a possible vulnerability that is detected, accepting or rejecting such a request by the researcher represents a conflict [70].

During a research investigation, the researchers may detect a critical vulnerability in a component. Even when researchers allow the vendors time to correct the problem, the manufacturers might not fix the issue or disclose it for various reasons, such as fear of loss of reputation or a negative financial impact on the company. Such a potential vulnerability may open the possibility for marine incidents to occur, leading to harm to seafarers, vessels, or the environment. In the event of an agreement between the parties (e.g. an NDA), the agreement might hamper the ability to inform the maritime community about potential vulnerabilities.

One of the foremost conflicts in cybersecurity is situated between personal privacy and security [71,72]. For example, VSAT technology has made the internet more accessible to seafarers today. Cybersecurity research on a live ship network may make seafarers' sensitive data more accessible to researchers. Specifically, such research may involve logging, monitoring, and analysing seafarers' activities in the network, including their internet activity.

5. Conclusion

Maritime cybersecurity has attracted increasing attention, accelerating in recent years, as illustrated by the growth indicated by Google Trends on this topic. This paper discussed the six key ethical principles that should guide maritime cybersecurity research: integrity, professional responsibility, legality, accountability, confidentiality, and openness. Four categories of ethical dilemmas that researchers may face were also identified and illustrated with real-world examples: research on state-sponsored cyberattacks, developing services and tools, sharing details of actual cyber incidents, and other dilemmas. For each dilemma, the relevant considerations were discussed to highlight the potentially dual-use nature of these issues. The paper also offered practical recommendations to aid researchers in avoiding or mitigating harm in their studies and suggested areas for future investigation. In conclusion, researchers in maritime cybersecurity must be fully aware of the ethical implications of their work and strive to uphold the highest standards of academic integrity and professional responsibility to protect all stakeholders in the maritime ecosystem. By adhering to these ethical guidelines, the maritime cybersecurity research community can ensure that their work contributes positively to the safety and security of maritime transportation while minimising potential harm.

References

Full reference list (72 sources) available in the original PDF.