أدت الرقمنة إلى تجهيز السفن بأنظمة حاسوبية أكثر. وعلى الرغم من أن هذا التحول حسّن السلامة الملاحية والكفاءة التشغيلية، إلا أنه أثار أيضًا مخاوف كبيرة تتعلق بالأمن السيبراني. لمعالجة هذه المخاوف، تقترح هذه الدراسة مفهوم مركز وطني للعمليات الأمنية السيبرانية البحرية (M-SOC)، بهدف حماية السفن من الهجمات السيبرانية. تم تطوير المفهوم المقترح باتباع إرشادات SOC التي نشرتها MITRE.随后، تم تقييم المسودة الأولية باستخدام تقنية المجموعة البؤرية (Focus Group). تم استخدام تحليل البيانات الموضوعية (Thematic Data Analysis) لتحليل ملاحظات الخبراء المتخصصين. من خلال النظر في مدخلات الخبراء، تم تحسين المفهوم الأولي. consequently، تساهم التوصيات الـ 11 المقدمة في الدراسة في تطوير مركز قادر على اكتشاف والاستجابة للتهديدات السيبرانية التي تستهدف السفن ضمن منطقة بحرية محددة. من المتوقع أن يعزز تشغيل مراكز M-SOC المرونة السيبرانية للنظام البيئي البحري على المستوى الوطني.
يسهل القطاع البحري أكثر من 80% من التجارة العالمية من حيث الحجم [1]. يتم هذا النقل بواسطة أسطول من 108,789 سفينة شحن [2]. ومع ذلك، لا تُشغَّل السفن لنقل البضائع فقط. إذ يخدم 836,342 سفينة في العالم أغراضًا مختلفة، بما في ذلك البحث والتدريب وصيد الأسماك والدفاع والنقل والأنشطة الترفيهية [3]. في هذه المقالة، يُعرّف مصطلح "السفينة" جميع أنواع المركبات المائية، مثل السفن التجارية والسفن الحربية والسفن ذات الأغراض الخاصة، وكلها مجهزة بأنظمة حاسوبية تدمج تكنولوجيا المعلومات (IT) مع تكنولوجيا التشغيل (OT). هذه الأنظمة ضرورية للتشغيل الآمن والفعال للسفن التقليدية اليوم والسفن التي تُتحكم عن بعد أو المستقلة في المستقبل.
في السنوات الأخيرة، استُهدفت السفن المعاصرة بشكل متكرر بالهجمات السيبرانية. وفقًا لتقدير "Above Us Only Stars"، تضرر ما مجموعه 1311 سفينة مدنية بسبب هجمات انتحال نظام GNSS التي نفذتها روسيا بين فبراير 2016 ونوفمبر 2018 [4]. بالإضافة إلى ذلك، ادعت كوريا الجنوبية أنه في عام 2017، اضطرت 280 من سفنها إلى العودة إلى الميناء بسبب هجوم تشويش على GPS نفذته كوريا الشمالية [5]. في عام 2022، تلاعبت مجموعة القراصنة Anonymous بنظام التعريف التلقائي (AIS) ليخت فلاديمير بوتين، وغيرت بياناته البحرية لإعادة تسمية السفينة وتصويرها على أنها تصطدم بجزيرة الأفعى في أوكرانيا [6]. في عام 2024، زُعم أن الولايات المتحدة مسؤولة عن هجوم سيبراني على السفينة البحرية الإيرانية M/V Behshad في البحر الأحمر وخليج عدن لتعطيل قدراتها على جمع المعلومات الاستخباراتية ومشاركتها [7]. تسلط هذه الحوادث الضوء على الضعف السيبراني المتزايد للسفن.
يجب معالجة مخاطر الأمن السيبراني بالتأكيد من أجل التشغيل الآمن للسفن. ومع ذلك، فإن الأمن السيبراني مجال معقد. يتطلب ضمان الأمن السيبراني الفعال الجمع بين مجالات الخبراء المختلفة وتنسيق العملية بشكل جيد. ضمن هذا الإطار، يتعاون الخبراء لأداء إجراءات حاسمة في الدفاع عن الفضاء السيبراني، مثل الحماية والاكتشاف والتوصيف والمواجهة والتخفيف والاستعادة [8]. لا يوجد مصطلح متفق عليه عالميًا لهذه الأدوار [9]. وبالتالي، تتوفر مفاهيم مختلفة لوصف مجموعات من المتخصصين في الأمن السيبراني، مثل فريق الاستجابة لحوادث أمن الحاسوب (CSIRT) وفريق الاستجابة للحوادث السيبرانية (CIRT) ومركز الاستجابة للحوادث الحاسوبية (CIRC) ومركز عمليات الأمن (SOC) ومركز عمليات الأمن السيبراني (CSOC) [9]. بناءً على هذه المفاهيم، تقدم هذه الدراسة مركز العمليات الأمنية السيبرانية البحرية (M-SOC). باختصار، M-SOC هو مركز متخصص يُشغَّل لتلبية احتياجات الأمن السيبراني الفريدة لأصحاب المصلحة البحريين.
تسببت الزيادة في تواتر وتعقيد الهجمات السيبرانية في القطاع البحري في إنشاء العديد من المنظمات الوطنية وغير الربحية. يعرض هذا القسم منظمات الأمن السيبراني البحرية الوطنية في الدنمارك وسنغافورة والولايات المتحدة. بالإضافة إلى ذلك، يتم تقديم المبادرات غير الربحية في فرنسا والنرويج. من خلال فحص هياكل وخدمات هذه المنظمات، يمكن اكتساب رؤى حول المبادرات العالمية.
على المستوى الوطني، أنشأت الدنمارك وحدة الأمن السيبراني البحري الدنماركية في يوليو 2018 تحت إدارة السلطة البحرية الدنماركية (DMA) [12]–[14]. في سنغافورة، تم إطلاق مركز عمليات الأمن السيبراني البحري (MSOC) من قبل سلطة الموانئ البحرية السنغافورية (MPA) في عام 2019 [16,17]، ومن المقرر توسيعه إلى مركز الضمان والعمليات السيبرانية البحرية (MCAOC) بحلول عام 2025 [18,19]. في الولايات المتحدة، تأسست قيادة الفضاء السيبراني لخفر السواحل (CGCYBER) لتحسين قدرات الأمن السيبراني لخفر السواحل [21]. تتولى CGCYBER حماية البنية التحتية الحيوية لنظام النقل البحري (MTS) وتضم فرقًا متخصصة بما في ذلك فرق الحماية السيبرانية (CPTs).
على صعيد المنظمات غير الربحية، تأسست France Cyber Maritime في 17 نوفمبر 2020 في فرنسا لتحسين المرونة السيبرانية للعمليات البحرية والموانئ [23]. تدير France Cyber Maritime فريق الاستجابة للطوارئ السيبرانية البحرية (M-CERT) [24]–[27]. في النرويج، تأسست NORMA Cyber في أواخر عام 2020 بمبادرة من اتحاد مالكي السفن النرويجي (NSA) [25]، وبدأت بتقديم خدمات مثل الاستخبارات السيبرانية وإدارة الحوادث والمراقبة الأمنية [28,29]. تتعاون NORMA Cyber مع الهيئة النرويجية للسواحل والمركز الوطني للأمن السيبراني (NCSC) لتنسيق جهود الاستجابة.
استكشفت ستة منشورات في الأدبيات قضايا التصميم والتنفيذ والتشغيل والتدريب لمراكز M-SOC. بحث Nganga وآخرون [30] في العوامل المؤثرة على فعالية عمليات M-SOC ووجدوا نقصًا في الموظفين المؤهلين ومحدودية استخبارات التهديدات السيبرانية (CTI) وضعف الاتصال بالإنترنت على متن السفن. اقترح Nganga وآخرون [31] نموذجًا لمشاركة CTI خاص بالصناعة البحرية [31]. حدد Nganga وآخرون [34] العوامل البشرية التي تؤثر على قدرات الاستجابة التكيفية لمحللي M-SOC. اقترح Jacq وآخرون [35] بنية M-SOC من ست وحدات لاكتشاف التهديدات السيبرانية والاستجابة لها، وتم اختبارها في سيناريوهات مختلفة. طور Raimondi وآخرون [36] برنامجًا تدريبيًا متخصصًا لمشغلي M-SOC باستخدام إطار عمل NICE والتوأم الرقمي. قدم Nikolov [37] مفهومًا لمركز عمليات وتدريب أمني (SOTC) في الأكاديمية البحرية نيكولا فابتساروف.
تسد أبحاثنا ثغرة مهمة في الأدبيات من خلال اقتراح مفهوم وطني لـ M-SOC. على عكس الدراسات السابقة، يقدم مفهومنا إطارًا قادرًا على دعم جميع السفن العاملة في منطقة بحرية محددة وتوفير الكشف المبكر. ينتقل هذا النهج من المراقبة الخاصة بالأصول إلى الوعي الظرفي على مستوى المنطقة.
تتكون المنهجية من ثلاث مراحل رئيسية. أولاً، تم تطوير مفهوم M-SOC باتباع استراتيجيات SOC التي نشرتها MITRE [9]. ثانيًا، تم تقييم مفهوم M-SOC المقترح من خلال تقنية المجموعة البؤرية (Focus Group)، والتي مكّنت من التحقق من صحته من قبل خبراء متخصصين. ثالثًا، تم تحليل المناقشات التي جرت خلال اجتماع المجموعة البؤرية لتحديد الأنماط والرؤى الرئيسية باستخدام تحليل البيانات الموضوعية (Thematic Data Analysis) [65]. بناءً على نتائج هذا التحليل، تم تحسين مفهوم M-SOC الأولي.
تم استخدام إرشادات MITRE [9] لأن MITRE منظمة معترف بها في مجال الأمن السيبراني لنزاهتها وخبرتها الفنية. نُشرت الاستراتيجيات العشر الأولى في عام 2014 [53]، ثم نُشرت طبعة ثانية تضم 11 استراتيجية في عام 2022 [9]. تم تكييف هذه الاستراتيجيات لتطوير M-SOC، مما أسفر عن 11 عنصرًا. تم استخدام تقنية المجموعة البؤرية لتقييم المفهوم. شارك 17 خبيرًا في مناقشة المجموعة البؤرية، بما في ذلك باحثين من 4 جامعات ومهنيين من 3 جمعيات تصنيف وشركات استشارية ومشغلي سفن ومنظمة حكومية دولية (IGO). تم استخدام برنامج QualCoder مفتوح المصدر [66] لتحليل البيانات النوعية.
يتكون مفهوم M-SOC الوطني المقترح من 11 عنصرًا. يعالج كل عنصر بُعدًا محددًا من أبعاد إنشاء وتشغيل M-SOC. يقدم هذا القسم شرحًا مفصلاً لكل عنصر، مما يوفر دليلاً مفيدًا لأصحاب المصلحة لتحسين الأمن السيبراني البحري الوطني.
العنصر 1: بناء الوعي الظرفي. الغرض هو فهم مهمة M-SOC، والمواقف الخطرة المحتملة، والبيئة على متن السفينة، ومشهد التهديدات، والبيئة التنظيمية، وسلوكيات الطاقم. تشمل المسؤوليات الرئيسية: تحديد المخاطر السيبرانية الحرجة، وتطوير خطط الاستجابة والتعافي، والتحقيق في الحوادث، ورفع الوعي، وتقديم المشورة للجهات التنظيمية، ومشاركة CTI.
العنصر 2: تمكين M-SOC. الهدف هو إضفاء الطابع الرسمي على سلطة M-SOC ونطاقه ومسؤولياته من خلال ميثاق معتمد [9]. يجب أن تشمل السلطات التواصل مع السفن، والمراقبة، وبدء الإجراءات، وتطوير الأدوات، وطلب الوثائق، وإجراء التحقيقات الجنائية، وإصدار التوجيهات. يجب توفير الدعم المالي الكافي من ميزانية الدولة.
العنصر 3: تصميم هيكل M-SOC مخصص. الغرض هو تصميم هيكل M-SOC يأخذ في الاعتبار التوافر المستمر للخدمة، والخبرة متعددة التخصصات، والتكامل مع البنى التحتية البحرية القائمة. يُقترح نموذج SOC وطني مركزي. يجب أن تعمل M-SOC على مدار الساعة بنظام المناوبات. قد تكون هناك حاجة إلى منشأة ثانوية للطوارئ.
العنصر 4: توظيف وتطوير قوى عاملة ماهرة. الهدف هو تحديد متطلبات التوظيف واستراتيجيات التوظيف وإطار التدريب. يوصى بوجود 10 محللين على الأقل للمراقبة المستمرة. يجب أن يجمع الفريق بين الخبرة في العمليات البحرية والأمن السيبراني والقانون البحري. البحارة السابقون مرشحون قيمون. يجب أن يتلقى الموظفون تدريبات السلامة الأساسية على متن السفن.
العنصر 5: وضع خطة للاستجابة للحوادث السيبرانية. الهدف هو تصميم خطة شاملة للاستجابة للحوادث وفقًا لإطار NIST المكون من أربع مراحل: (1) الإعداد، (2) الكشف والتحليل، (3) الاحتواء والاستئصال والتعافي، (4) النشاط بعد الحادث [87]. يجب أن تشمل الخطة قوائم الاتصالات والمكتبات المرجعية وآليات تحديد الأولويات.
العنصر 6: الاستفادة من استخبارات التهديدات السيبرانية (CTI). الهدف هو إنشاء عملية CTI شاملة مصممة خصيصًا للأمن السيبراني البحري [9]. تتكون دورة الاستخبارات الكلاسيكية من ست مراحل: التخطيط، الجمع، المعالجة، التحليل، النشر، والتقييم [94]. تتضمن مصادر البيانات OSINT ومقدمي CTI التجاريين والتنبيهات الحكومية.
العنصر 7: جمع البيانات ذات الصلة. الهدف هو جمع البيانات من خلال نهجين: جمع البيانات على متن السفينة (Shipboard Data Collection) والذي يتضمن صعود المحللين إلى السفينة لجمع بيانات OT/IT وسجلات VDR؛ وجمع البيانات البحرية (Seaborne Data Collection) والذي يشمل المراقبة عن بعد لحركة مرور AIS و GNSS و NAVTEX وخلاصات الكاميرات والرادار.
العنصر 8: تطوير أدوات M-SOC. الهدف هو توفير أدوات محددة لـ M-SOC لمراقبة مصادر البيانات واكتشاف الهجمات السيبرانية. لا توجد حلول كافية في السوق حاليًا. تشمل الأدوات المقترحة: أنظمة كشف التسلل (IDS) لحركة المرور الخاصة بالسفن، وكشف انتحال AIS، وكشف تشويش GNSS، وكشف السفن الوهمية عبر مقارنة الرادار مع AIS، والتحقق عبر صور الأقمار الصناعية.
العنصر 9: تعزيز التواصل. الغرض هو إنشاء آليات اتصال داخلية وخارجية للتعاون. يشمل التواصل الداخلي اجتماعات منتظمة موثقة. يشمل التواصل الخارجي أصحاب المصلحة مثل أطقم السفن والمشغلين وجمعيات التصنيف والسلطات البحرية وشركات التأمين والمصنعين. يجب استخدام لغة واضحة وتجنب المصطلحات التقنية المعقدة عند التواصل مع غير المتخصصين.
العنصر 10: قياس أداء M-SOC. الهدف هو تحديد مقاييس أداء محددة لتقييم الفعالية التشغيلية. تشمل المقاييس: تغطية المنطقة البحرية المراقبة، وكثافة حركة المرور، وملف الحوادث، وأنشطة التأهب (التدريبات والخطط)، وكفاءة الاستجابة التشغيلية (وقت الكشف، وقت التنبيه، وقت الاستجابة)، ومراجعة متعددة لأصحاب المصلحة.
العنصر 11: توسيع قدرات M-SOC. الهدف هو توسيع النطاق التشغيلي ليشمل جميع المرافق الحيوية للنظام البيئي البحري مثل الموانئ والمحطات وأحواض بناء السفن والسلطات البحرية، بالإضافة إلى السفن التي يتم التحكم فيها عن بعد والمركبات المستقلة.
تقترح هذه الدراسة مفهومًا شاملاً من 11 عنصرًا لإنشاء M-SOC وطني لمراقبة التهديدات السيبرانية واكتشافها والاستجابة لها ضد السفن في منطقة بحرية محددة. يمكن أن يحسن M-SOC الوطني بشكل كبير الأمن السيبراني للمنطقة من خلال توفير الوعي الظرفي المستمر وقدرات الإنذار المبكر. في هذا النموذج، تحتفظ السفن بالمسؤولية الأساسية عن الاستجابات التفاعلية، بينما يقدم M-SOC استجابات نشطة محدودة ودعمًا منسقًا من الشاطئ.
ناقش الخبراء عدة مواضيع رئيسية. فيما يتعلق بتقديم الخدمات من قبل M-SOC، تم مناقشة نموذج شراكة متبادلة المنفعة بدلاً من المنافسة مع القطاع الخاص. فيما يتعلق بانتشار M-SOCs، من المتوقع أن تصبح أكثر انتشارًا على المستوى الوطني في السنوات القادمة، مع وجود تحديات كبيرة لإنشاء M-SOC حكومي دولي. يجب هيكلة العلاقة بين M-SOCs الخاصة والوطنية بشكل صحيح. تشمل التحديات الرئيسية محدودية أدوات OT المتاحة، وطبيعة السفن المتنقلة، والحاجة إلى معرفة شاملة بالعمليات البحرية.
أشار الخبراء إلى أن SMCP (عبارات الاتصالات البحرية القياسية) الصادرة عن IMO لا تتضمن حاليًا عبارات متعلقة بالأمن السيبراني ويجب تنقيحها. كما تمت مناقشة الحاجة إلى منصة CTI بحرية محددة تديرها منظمات موثوقة.
يمتلك القطاع البحري مكانة حاسمة للتجارة العالمية والاستقرار الاقتصادي. السفن الحديثة مجهزة بأنظمة IT و OT معقدة. على الرغم من أن الأنظمة الحاسوبية تحسن الكفاءة التشغيلية والملاحة الآمنة للسفن، إلا أنها تثير أيضًا مخاوف بشأن التهديدات والثغرات السيبرانية. ينقل النقل الدولي المخاطر السيبرانية من بلد إلى آخر. لذلك، يجب على الدول اتخاذ الإجراءات التخفيفية المطلوبة للسفن التي تبحر في مياهها الإقليمية.
استجابة لهذه الحاجة، تقترح هذه الدراسة مفهومًا شاملاً لإنشاء M-SOC وطني، مصمم لمنع التهديدات السيبرانية التي تستهدف السفن في منطقة بحرية محددة. تم تصميم المفهوم الأولي باتباع إرشادات MITRE [9]، وتم تقييمه من قبل الخبراء باستخدام تقنية المجموعة البؤرية، وتم تحليله باستخدام تحليل البيانات الموضوعية. تخدم الدراسة أربعة أبعاد: الإنشاء والتشغيل، والمراقبة الآنية، والاستجابة للحوادث، والتواصل والتعاون. تم اقتراح 11 عنصرًا حاسمًا لتحقيق هذه الأبعاد.
تساهم هذه الدراسة في سد الفجوة في الأدبيات الحالية بين أفضل ممارسات SOC التقليدية والمتطلبات الفريدة لـ M-SOC. من خلال تقديم نهج منظم ومُقيَّم ومخصص للقطاع، توفر هذه الدراسة أساسًا لإنشاء M-SOC من قبل السلطات البحرية وصناع السياسات وأصحاب المصلحة في الصناعة. العمل المستقبلي الأكثر أهمية هو إنشاء M-SOC فعلي باتباع المفهوم المقترح، الأمر الذي سيتطلب تمويلًا كبيرًا ويوفر فرصة للتقديم على المنح.
قائمة المراجع الكاملة (168 مصدرًا) متاحة في الملف الأصلي للPDF.
Digitalization has resulted in ships being equipped with more computerized systems. Even though this transformation has improved navigational safety and operational efficiency, it has also raised cyber security concerns significantly. To address such concerns, this study proposes a national Maritime Cyber Security Operations Center (M-SOC) concept, aiming at protecting vessels against cyber-attacks. The proposed concept was developed by following a SOC-related guideline published by MITRE. Subsequently, the initial draft was evaluated through the Focus Group technique. Thematic Data Analysis was employed to analyze feedback from domain experts. By considering expert input, the draft concept was improved. Consequently, the 11-element recommendation presented in the study contributes to the development of a center capable of detecting and responding to cyber threats targeting ships within a designated sea zone. The operation of M-SOCs is expected to enhance the cyber resilience of the maritime ecosystem at the national level.
The maritime sector facilitates over 80% of global trade by volume [1]. This transportation is performed by a fleet of 108,789 cargo ships [2]. However, ships are not operated only for cargo transportation. A total of 836,342 ships in the world serve different purposes, including research, training, fishing, defense, transportation, and leisure activities [3]. In this article, the term "vessel" or "ship" defines all kinds of watercraft, such as commercial ships, warships, and special-purpose vessels, all with computerized systems that integrate Information Technology (IT) with Operational Technology (OT) systems. These systems are essential for the safe and efficient operation of conventional vessels today and remote-controlled or autonomous ships in the future.
In recent years, contemporary ships have been frequently targeted by cyber-attacks. According to the estimation of "Above Us Only Stars", a total of 1311 civilian vessels were damaged by GNSS spoofing attacks conducted by Russia between February 2016 and November 2018 [4]. Additionally, South Korea claimed that in 2017, 280 of their ships had to return to port because of a GPS jamming attack carried out by North Korea [5]. In 2022, the hacker group Anonymous manipulated the AIS of Vladimir Putin's yacht, changing its maritime data to rename the vessel and depict it as colliding with Snake Island in Ukraine [6]. In 2024, the USA was allegedly accountable for a cyber-attack on the Iranian naval vessel M/V Behshad in the Red Sea and the Gulf of Aden to disrupt its intelligence-gathering and sharing capabilities [7]. These incidents highlight the growing cyber vulnerability of vessels.
Cyber security risks should definitely be addressed for the safe operation of ships. However, cyber security is a complex field. Ensuring effective cyber security requires bringing together different areas of expertise and coordinating the process well. Within this framework, experts collaborate to perform critical actions in cyberspace defense, such as protecting, detecting, characterizing, countering, mitigating, and restoring [8]. There is no universally agreed-upon term for these roles [9]. Thus, various notions are available to describe groups of cyber security specialists, such as CSIRT, CIRT, CIRC, SOC, and CSOC [9]. Based on these notions, this study introduces the M-SOC. In summary, the M-SOC is a specialized center operated to meet the unique cyber security needs of maritime stakeholders.
The increasing frequency and complexity of cyber-attacks in the maritime sector have caused the establishment of various national and non-profit organizations. This section presents national maritime cyber security organizations in Denmark, Singapore, and the U.S. In addition, non-profit initiatives in France and Norway are introduced. By examining the structures and services provided by these organizations, insights into global initiatives can be gained.
At the national level, Denmark founded the Danish Maritime Cybersecurity Unit in July 2018 under the Danish Maritime Authority (DMA) [12]–[14]. In Singapore, the Maritime Cybersecurity Operations Centre (MSOC) was launched by the Maritime and Port Authority of Singapore (MPA) in 2019 [16,17], with plans to expand to the Maritime Cyber Assurance and Operations Centre (MCAOC) by 2025 [18,19]. In the USA, the Coast Guard Cyber Command (CGCYBER) was founded to improve cyber security capabilities [21] and protects the Maritime Transportation System (MTS) with specialized teams including Cyber Protection Teams (CPTs).
On the non-profit side, France Cyber Maritime was founded on 17 November 2020 in France to improve cyber resilience of marine and port operations [23] and operates the Maritime Cyber Emergency Response Team (M-CERT) [24]–[27]. In Norway, NORMA Cyber was founded in late 2020 by the Norwegian Shipowners' Association (NSA) [25], offering threat intelligence, incident management, and security monitoring services [28,29]. NORMA Cyber collaborates with the Norwegian Coastal Administration and the NCSC.
Six publications in the literature explore design, implementation, operations, and training aspects of M-SOCs. Nganga et al. [30] investigated factors impacting M-SOC operations and found a lack of qualified staff, limited CTI, and poor internet connectivity onboard ships. Nganga et al. [31] proposed a CTI sharing model for the maritime industry. Nganga et al. [34] identified human factors affecting adaptive response capabilities of M-SOC analysts. Jacq et al. [35] proposed a six-module M-SOC architecture to detect and respond to cyber threats. Raimondi et al. [36] developed a specialized training program for M-SOC operators using the NICE framework and digital twins. Nikolov [37] presented a concept for a Security Operations and Training Centre (SOTC) at the Nikola Vaptsarov Naval Academy.
Our research addresses an important deficiency in the literature by proposing a national M-SOC concept. Unlike previous studies, our concept introduces a framework capable of supporting all vessels operating in a designated sea zone with early detection capabilities. This approach transitions from asset-specific monitoring to zone-wide situational awareness.
The methodology consists of three main phases. First, the M-SOC concept was developed by following the SOC strategies published by MITRE [9]. Second, the proposed M-SOC concept was evaluated through the Focus Group technique, enabling validation by domain experts. Third, the discussions held during the Focus Group meeting were analyzed to identify key patterns and insights by employing Thematic Data Analysis [65]. Based on the outcomes of this analysis, the initial M-SOC concept was further improved.
MITRE's guidelines [9] were used because MITRE is a recognized organization for integrity, technical expertise, and innovation in cyber security. The original ten strategies were published in 2014 [53], and a second edition with 11 strategies was published in 2022 [9]. These were adapted to develop the M-SOC, resulting in 11 elements. The Focus Group technique was used to evaluate the concept. 17 experts participated in the Focus Group discussion, including researchers from 4 universities, professionals from 3 classification societies, consultancy firms, a ship operator, and an IGO. The open-source software QualCoder [66] was used for qualitative data analysis.
The proposed national M-SOC concept comprises 11 elements. Each element addresses a specific dimension of M-SOC establishment and operation. This section provides detailed explanation of each element, offering a useful guide for stakeholders to improve national maritime cyber security.
Element 1: Building Situational Awareness. The purpose is to understand the M-SOC's mission, potential hazardous situations, the shipboard environment, the threat landscape, the regulatory environment, and crew behaviors. Key responsibilities include: identifying critical cyber risks, developing response and recovery plans, conducting incident investigations, raising awareness, advising regulatory bodies, and sharing CTI.
Element 2: Empowering the M-SOC. The objective is to formalize the M-SOC's authority, scope, and responsibilities through an approved charter [9]. Authorities should include communicating with vessels, monitoring, initiating actions, developing tools, requesting documents, conducting forensic investigations, and issuing advisories. Sufficient financial support should be provided from the state budget.
Element 3: Designing a Tailored M-SOC Structure. The purpose is to design an M-SOC structure considering continuous service availability, interdisciplinary expertise, and integration with existing maritime infrastructures. A centralized national SOC model is proposed. The M-SOC should operate 24/7 with a shift-based schedule. A secondary facility may be required for emergencies.
Element 4: Recruiting and Developing a Skilled Workforce. The objective is to define staffing requirements, hiring strategies, and training framework. At least 10 analysts are recommended for continuous monitoring. The team should combine expertise in maritime operations, cyber security, and maritime law. Former seafarers are highly valuable candidates. Personnel should receive basic maritime safety training.
Element 5: Establishing a Cyber Incident Response Plan. The objective is to design a comprehensive incident response plan following NIST's four-phase framework: (1) Preparation, (2) Detection and Analysis, (3) Containment, Eradication, and Recovery, and (4) Post-Incident Activity [87]. Plans should include communication lists, reference libraries, and prioritization mechanisms.
Element 6: Leveraging Cyber Threat Intelligence. The objective is to establish a comprehensive CTI process specifically designed for maritime cyber security [9]. The classical intelligence cycle comprises six phases: Planning, Collection, Processing, Analysis, Dissemination, and Evaluation [94]. Data sources include OSINT, commercial CTI providers, government alerts, and industry-specific sources.
Element 7: Collecting Relevant Data. The objective is to collect data through two approaches: Shipboard Data Collection (analysts boarding vessels to collect OT/IT logs and VDR data) and Seaborne Data Collection (remote monitoring of AIS, GNSS, and NAVTEX traffic, camera feeds, and RADAR data).
Element 8: Developing M-SOC Tools. The objective is to provide M-SOC-specific tools for monitoring data sources and detecting cyber-attacks. Few commercial solutions exist. Proposed tools include: IDS for ship-specific traffic, AIS spoofing detection, GNSS jamming detection, ghost vessel detection via RADAR-AIS comparison, and satellite imagery verification.
Element 9: Fostering Communication. The purpose is to establish internal and external communication mechanisms for collaboration. Internal communication includes regular documented meetings. External communication involves stakeholders such as ship crews, operators, classification societies, maritime authorities, insurers, and manufacturers. Clear language should be used to avoid technical jargon.
Element 10: Measuring M-SOC Performance. The objective is to identify specific performance metrics for evaluating operational effectiveness. Metrics include: monitored sea zone coverage, traffic density, cyber incident occurrence profile, preparedness activities (drills, plans, training), operational response efficiency (detection time, alert time, response time), and multi-stakeholder review.
Element 11: Expanding M-SOC Capabilities. The objective is to expand the operational scope to cover all critical facilities of the maritime ecosystem, including ports, terminals, shipyards, and maritime authorities, as well as remote-controlled and autonomous vessels.
This study proposes a comprehensive concept consisting of 11 elements for the establishment of a national M-SOC to specifically monitor, detect, and respond to cyber threats against vessels in a designated sea zone. A national M-SOC can significantly improve the cyber security of the region by offering continuous situational awareness and early warning capabilities. In this model, vessels retain the primary responsibility for reactive responses, while the M-SOC provides limited active responses and coordinated support from the shore side.
Experts discussed several key topics. Regarding M-SOC services to private companies, a mutually beneficial partnership model was discussed rather than competition with the private sector. Regarding widespread M-SOCs, they are expected to become more prevalent at the national level in coming years, with significant challenges for establishing an intergovernmental M-SOC. The relationship between private and national M-SOCs should be properly structured. Key challenges include limited available OT tools, the mobile nature of ships, and the need for comprehensive knowledge of marine operations.
Experts noted that the IMO's SMCP currently does not include cyber security-related phrases and should be revised. The need for a maritime-specific CTI platform operated by credible organizations was also discussed.
The maritime sector has a critical place for global trade and economic stability. Modern ships are equipped with complex IT and OT systems. Even though computerized systems improve operational efficiency and safe navigation of ships, they also raise concerns regarding cyber threats and vulnerabilities. International transportation transfers cyber risks from one country to another. Therefore, states should take the required mitigation measures for ships sailing in their territorial waters.
In response to this need, this study proposes a comprehensive concept for the establishment of a national M-SOC, designed to prevent cyber threats targeting vessels in a designated sea zone. The initial concept was designed by following MITRE's guidelines [9], evaluated by experts through the Focus Group technique, and analyzed using Thematic Data Analysis. The study serves four dimensions: Establishment and Operation, Real-Time Monitoring, Incident Response, and Communication and Collaboration. Eleven critical elements are proposed to address these dimensions.
Our study addresses the gap between conventional SOC best practices and the unique requirements of the M-SOC. By offering a structured, evaluated, and sector-specific approach, this study provides a foundation for the establishment of an M-SOC by maritime authorities, policymakers, and industry stakeholders. The most significant future work is to establish an actual M-SOC by following the concept proposed, which would require substantial funding and provide an opportunity for grant applications.
Full reference list (168 sources) available in the original PDF.