Navigation Data Anomaly Analysis and Detection

تحليل وكشف الشذوذ في بيانات الملاحة

👤 Ahmed Amro, Aybars Oruc, Vasileios Gkioulos, Sokratis Katsikas 📄 Information 2022, 13(3), 104 🔗 10.3390/info13030104 ✓ CC BY 4.0

الملخص

أدت عدة هجمات تخريبية ضد شركات في الصناعة البحرية إلى دفع الخبراء لاعتبار الخطر المتزايد الناجم عن التهديدات السيبرانية عقبة رئيسية أمام التحول الرقمي. تتجه الصناعة نحو زيادة الأتمتة والاتصال، مما يؤدي إلى تقليل المشاركة البشرية في وظائف الملاحة المختلفة وزيادة الاعتماد على بيانات الاستشعار والبرمجيات لأنماط التشغيل الأكثر استقلالية. لتحقيق أهداف الأتمتة المتزايدة في ظل التهديد بالهجمات السيبرانية، يجب إعداد وحدات البرمجيات المختلفة المتوقعة في وظائف الملاحة المختلفة لكشف مثل هذه الهجمات باستخدام تقنيات الكشف المناسبة. لذلك، نقترح نهجاً منهجياً لتحليل رسائل NMEA الملاحية التي تحمل بيانات المستشعرات المختلفة، والشذوذ المحتمل فيها، والأسباب الخبيثة لهذه الشذوذات بالإضافة إلى خوارزميات الكشف المناسبة. تم تقييم النهج المقترح من خلال حالتين استخدام، نظام الملاحة المتكامل (INS) التقليدي وسفينة الركاب المستقلة (APS). تعكس النتائج فائدة الكشف القائم على المواصفات والتردد في كشف الشذوذات المحددة بثقة عالية. علاوة على ذلك، وُجد أن التحليل يسهل توصيل التهديدات من خلال الإشارة إلى الأثر المحتمل للشذوذات المحددة على عمليات الملاحة. كما قمنا بتطوير بيئة اختبار تسهل إجراء التحليل. تتضمن البيئة أداة مطورة، NMEA-Manipulator، التي تمكن من استدعاء الشذوذات المحددة من خلال مجموعة من الهجمات السيبرانية على بيانات المستشعرات. يمهد عملنا الطريق للعمل المستقبلي في تحليل شذوذات NMEA نحو تطوير نظام كشف اختراق NMEA.

1. المقدمة

يشهد المجال البحري تحولاً رقمياً كبيراً، مما يؤدي إلى تغييرات جوهرية في نماذج الأعمال والعمليات والتكنولوجيا [1]. يتم نشر نظام الملاحة المتكامل (INS) على السفن التقليدية اليوم لدعم الملاحة الآمنة نتيجة لهذا التحول الرقمي. ومع ذلك، فإن التقدم التكنولوجي سيغير خصائص السفن بشكل كبير في المستقبل القريب. مؤخراً، تم اقتراح مشاريع جديدة لزيادة الاستقلالية في المجال البحري. يشمل ذلك أتمتة الأنظمة والخدمات البحرية حتى تتمكن هذه الأنظمة من الوصول إلى التشغيل المستقل في البحر بحلول عام 2035 [2]. أدت هذه المشاريع إلى اقتراح فئة سفن جديدة تدعى السفينة السطحية المستقلة البحرية (MASS) كما حددتها المنظمة البحرية الدولية (IMO) [3]. من بين هذه المشاريع الجديدة مشروع العبارة المستقلة (Autoferry) [4]. يهدف المشروع إلى تطوير سفينة ركاب مستقلة (APS) أو عبارة لنقل الركاب عبر قناة مدينة تروندهايم في النرويج. من المتوقع أن تتم مراقبة APS عن بعد والتحكم فيها عند الضرورة من مركز بعيد.

أثرت حداثة مشروع Autoferry على نموذج المخاطر السيبرانية وأدت إلى أهداف وتقنيات هجوم فريدة. العوامل الرئيسية التي أدت إلى ذلك هي نمط التشغيل الآلي عن بعد وكذلك حقيقة أن الركاب سيكونون على متن السفينة بدون طاقم. أدى نمط التشغيل الآلي عن بعد إلى نواقل هجوم سيبراني جديدة وأوسع بسبب الاتصال عن بعد، والاعتماد على الخدمات الآلية، وانخفاض الدفاعات البشرية، والاعتماد على التقنيات الرقمية للمشغل عن بعد للتدخل. علاوة على ذلك، فإن وجود الركاب يفرض عامل خطر يتعلق بالسلامة يحفز أنواعاً مختلفة من الجهات الفاعلة المهددة لإيذائهم من خلال الهجمات السيبرانية. من بين نواقل الهجوم المحددة في Autoferry معلومات الملاحة التي يتم تبادلها بين المكونات البحرية المختلفة.

حددت الجمعية الوطنية للإلكترونيات البحرية (NMEA) مجموعة من المواصفات الإلكترونية ومواصفات البيانات للاتصال بين أنظمة الإلكترونيات البحرية المختلفة. تجلت هذه المواصفات في سلسلة من المعايير. أحدث الإصدارات هي NMEA0183 [5] وNMEA2000 [6]. تحكم هذه المعايير بنية وطريقة اتصال الرسائل بين الأجهزة المختلفة. تُستخدم رسائل NMEA بشكل رئيسي في المجال البحري. ومع ذلك، فقد وجدت معلومات تحديد المواقع التي توفرها تطبيقاتها في مجالات أخرى مثل تلك التي تتطلب تتبع الموقع للأمن الشخصي [7،8]، وكشف سرقة السيارات [9]. بينما توفر هذه الرسائل وفرة من المعلومات المستخدمة في مهام ووظائف ملاحية مختلفة، فقد تم فحص أمنها ووجد أنها تفتقر إلى أي ضوابط مثل المصادقة والتشفير والتحقق [10]. وهذا يجعلها عرضة لمجموعة واسعة من الهجمات السيبرانية.

تهدف هذه الورقة إلى تحسين أمان رسائل NMEA من خلال تحديد واقتراح الأساليب المناسبة لمعالجة ومراقبة المخاطر المرتبطة بها. يتم النظر في معيار NMEA0183 في هذه الورقة، مع خطط مستقبلية لتوسيع العمل ليشمل معيار NMEA2000. لذلك، نقترح نهجاً منهجياً لتحليل رسائل NMEA، وشذوذاتها، والأسباب الخبيثة لهذه الشذوذات (أي الهجمات) بالإضافة إلى خوارزميات الكشف المناسبة.

نستخدم حالتين استخدام بحريتين طوال هذه الورقة لتسهيل وصف نهجنا. حالات الاستخدام هي APS والسفن التقليدية المجهزة بنظام INS. بهذه الطريقة، اغتنمنا فرصة لإثبات أهمية دراستنا ليس فقط لسفن اليوم ولكن أيضاً للسفن المحتملة في المستقبل. نجادل بأن نهجنا يمكن أن يساعد في تطوير أنظمة ملاحة مرنة يتم تطويرها وتشغيلها مع مراعاة السلوك العدائي.

مساهمة الورقة هي كما يلي:

• نقترح نهجاً منهجياً جديداً لكشف الشذوذ في رسائل NMEA.

• نقدم تحليلاً للشذوذات المحتملة في رسائل NMEA وعلاقتها السببية بمجموعة من الهجمات السيبرانية.

• نقترح طريقة لإنشاء مجموعات بيانات تركيبية تحتوي على رسائل NMEA عادية ومُخترقة بشكل ضار، ونقوم بتنفيذ واستخدام حزمة برمجية لإنشاء مجموعات البيانات التجريبية هذه.

• نستخدم مجموعات البيانات في سياق حالتين استخدام لتقييم أداء طرق كشف الشذوذ المصممة خصيصاً لهذا الغرض.

تم تنظيم بقية الورقة على النحو التالي: في القسم 2، نقدم الخلفية الضرورية ونستعرض الأدبيات ذات الصلة. في القسم 3، نقدم طريقتنا المقترحة للتحليل المنهجي متعدد الأبعاد للشذوذات في رسائل NMEA. في القسم 4، نناقش كيفية تطبيق طريقتنا المقترحة على حالات استخدام INS وAPS. في القسم 5، نقدم نتائج تجاربنا مع الأساليب المقترحة، نحو تقييم فائدتها في تطوير نظام كشف اختراق لرسائل NMEA. في القسم 6، نقيم ونناقش النتائج والنتائج التي توصلنا إليها من التجارب، وفي القسم 7 نقدم خيارات نشر نظام IDS لـ NMEA. أخيراً، يلخص القسم 8 استنتاجاتنا ويقترح اتجاهات للبحث المستقبلي.

2. الخلفية والأعمال ذات الصلة

تتوفر العديد من المنشورات التي تشير إلى المخاطر السيبرانية للسفن المستقلة في الأدبيات. قدم كافاليراتوس وآخرون [11] نتائج تقييم المخاطر السيبرانية للسفن التي يتم التحكم فيها عن بعد والمستقلة. تم إجراء تقييم المخاطر باستخدام منهجية نمذجة التهديدات STRIDE. وفقاً للنتائج، فإن نظام التعريف التلقائي (AIS)، ونظام عرض الخرائط الإلكترونية والمعلومات (ECDIS)، والنظام العالمي للاستغاثة والسلامة البحرية (GMDSS)، على وجه الخصوص، تتضمن مخاطر عالية مختلفة. ناقش فينيم وأوتني [12] إمكانية استخدام السفن المستقلة لإلحاق الضرر بالصناعة البحرية. قد يتسبب الهجوم السيبراني في اصطدام سفينة مستقلة بمنصة بحرية في البحر، عن قصد أو عن غير قصد. تقترح الورقة أيضاً العديد من تدابير التخفيف. يُقال إن الاحتفاظ بعدد قليل من أفراد الطاقم على متن السفينة هو الإجراء الوقائي الأكثر فعالية ضد المخاطر السيبرانية وفقاً للمؤلفين.

ليس فقط السفن المستقلة ولكن أيضاً السفن التقليدية التي تبحر في البحر اليوم يمكن أن تتعرض للهجمات السيبرانية. كشف سفيلسيتش وآخرون [13] عن نقاط الضعف السيبرانية لنظام INS على متن السفينة. حصل المؤلفون على ما مجموعه 27 معلومة، وأربع نقاط ضعف باستخدام ماسح ضوئي للثغرات. تم الإبلاغ عن إحدى نقاط الضعف المكتشفة في INS على أنها "حرجة". علاوة على ذلك، قدم لوكاس وآخرون [14] مسحاً لكشف الاختراق في المركبات، بما في ذلك السفن البحرية. ناقش المؤلفون العديد من الأعمال التي تستهدف انتحال GPS وAIS والتلاعب بهما. ومع ذلك، لم يتم الإشارة إلى بروتوكول NMEA.

بدافع من التهديدات المحددة في الصناعة البحرية والتركيز على بروتوكول NMEA كناقل تهديد محتمل، قمنا بمسح أحدث ما توصلت إليه أبحاث أمان NMEA. شرح كريلي وآخرون [15] شبكة INS على متن السفينة، بما في ذلك وصف تفصيلي لمعايير NMEA 0183 و2000. يركز المؤلفون على NMEA 2000 بشكل خاص في جوانب مختلفة، مثل مكونات شبكة NMEA 2000، ومقارنة الإيثرنت وشبكة منطقة التحكم (CAN)، ووظائف CAN. علاوة على ذلك، يناقش المؤلفون برامج NMEA، بما في ذلك Sail Soft NMEA Studio وMaretron N2K Analyzer وN2K Meter. بالإضافة إلى ذلك، تمت ملاحظة العديد من تطبيقات رسائل NMEA في الأدلة الجنائية الرقمية [16،17]، والأمن الشخصي [7،8]، وكشف سرقة السيارات [9]، وكذلك استخدام رسائل NMEA في كشف انتحال نظام GNSS [18]. ومع ذلك، لم تناقش هذه الأعمال أمان رسائل NMEA نفسها. جادلت بعض الأعمال بأن أمان NMEA يعتمد حالياً على أمان الشبكة والمضيف [19،20]. ومع ذلك، تناول سيونغ وكيم [21] الأمن السيبراني لرسائل NMEA باستخدام دوال التجزئة الآمنة عند تخزين رسائل NMEA في مسجل بيانات الرحلة على متن السفن. يُقال إن هذا يحسن أصالة رسائل NMEA المخزنة.

بالإضافة إلى ذلك، اقترح بوديهين وآخرون [22] نهجاً للتعلم الآلي لكشف هجمات GPS. يبث جهاز GPS رسائل NMEA 0183 إلى شبكة السفينة. يمكن لبرنامج التعلم الآلي الذي طوره المؤلفون على Raspberry Pi 3B+ كشف تشويش GPS وانتحاله بنجاح. بهذه الطريقة، يمكن إخطار ضابط المراقبة على جسر القيادة بهجوم GPS محتمل. يمكن أيضاً استخدام التعلم الآلي لكشف الأنشطة الخبيثة في شبكة السفينة [23]. علاوة على ذلك، قدم هيمينغهاوس وآخرون [24] أداة هجوم على الجسر تسمى BRAT تستهدف رسائل NMEA بمجموعة واسعة من الهجمات من أجل تقييم أمان الأنظمة البحرية. ناقش المؤلفون الافتقار إلى الأمان في الأنظمة البحرية، خاصة تلك التي تستخدم بروتوكول NMEA. ثم قدموا بنية الأداة وقيموها مقابل برنامج OpenCPN مفتوح المصدر لرسم الخرائط الملاحية.

تم العثور على تطبيق آخر لبروتوكول NMEA في نظام AIS. تم تجهيز السفن بنظام AIS لتحسين سلامة وكفاءة الملاحة وحماية البيئة البحرية [25]. إنه مكون إلزامي للسفن في ظل ظروف محددة موصوفة في اتفاقية SOLAS [26]. يرسل جهاز إرسال واستقبال AIS معلومات ثابتة وديناميكية ومتعلقة بالرحلة بالإضافة إلى رسائل متعلقة بالسلامة باستخدام تنسيق رسائل NMEA [25،27]. تناولت العديد من الأعمال كشف الشذوذ في AIS. اقترح إيفار وآخرون [28] تقييماً لسلامة رسائل AIS من منظور جودة البيانات. استهدف المؤلفون رسائل AIS لتقييم جودة البيانات وأجروا العديد من وظائف التلاعب على رسائل AIS لاستدعاء الشذوذ في البيانات. ثم اقترحوا نهج كشف قائم على القواعد. في عمل آخر، استخدم بلاوكامب وآخرون [29] التعلم الآلي لكشف الشذوذ في حركة المرور المستنتجة من رسائل AIS. على الرغم من أن المؤلفين لم يستهدفوا الأمن السيبراني، إلا أن الهجمات السيبرانية هي من بين الدوافع الرئيسية لبحثهم. على الرغم من أن رسائل NMEA وAIS لها تنسيق متشابه نسبياً، إلا أن رسائل AIS تتضمن حمولة ثنائية مشفرة بدلاً من حمولة نصية في NMEA-0183. علاوة على ذلك، تحمل رسائل AIS معلومات مختلفة عن رسائل NMEA، مثل رسائل المرور من السفن الأخرى. حفزت هذه الاختلافات العمل في هذه الورقة للتحقيق في أساليب تحليل وكشف الشذوذ المناسبة.

أصل NMEA يأتي من بروتوكول CAN أو ناقل CAN، وهو بروتوكول قائم على الرسائل يتيح الاتصال بين الأجهزة في السيارات [30]. تناولت العديد من الأعمال في الأدبيات كشف الشذوذ في ناقل CAN. نهدف إلى استنتاج القطع الأثرية ذات الصلة من مجال كشف الشذوذ في ناقل CAN واستخدامها لكشف شذوذ NMEA. في هذه الورقة، نعتمد على أحدث أنظمة كشف الاختراق (IDS) لناقل CAN في مجال السيارات والتي تم توثيقها بواسطة لوكمان وآخرون [31]. ناقش المؤلفون عدة جوانب، وهي استراتيجيات النشر، وطرق الكشف، وتقنيات الهجوم، والتحديات التقنية المتعلقة بالمجال. نظراً لأوجه التشابه بين NMEA وناقل CAN، تم العثور على العديد من القطع الأثرية ذات الصلة بعملنا وسيتم مناقشتها طوال هذه الورقة.

يتأثر التحليل المنهجي للشذوذ في رسائل NMEA المقترح في هذه الورقة بنموذج الخطوات الست الذي اقترحه سابالياوسكايت وآخرون [32]. اقترح المؤلفون ست خطوات لإجراء عملية تحليل مشتركة لمخاطر السلامة والأمن باستخدام ستة أبعاد، وهي الوظائف والبنية والإخفاقات والهجمات والتدابير المضادة للسلامة والتدابير المضادة للأمن. وفقاً لذلك، يتكون تحليل الشذوذ في هذه الورقة من ست خطوات؛ كل خطوة تحلل بعداً مختلفاً متعلقاً بكشف شذوذ NMEA، وهي وظائف الملاحة والرسائل والحقول والشذوذ والهجمات وطرق الكشف. أثرت الطبيعة المنهجية ومتعددة الأبعاد للتحليل في نموذج الخطوات الست على اقتراحنا. بالإضافة إلى ذلك، يتأثر تحليل رسائل NMEA وشذوذاتها بعملية تحليل AIS التي أجراها إيفار وآخرون [28] (مزيد من التفاصيل في القسم 4.4).

تتأثر إجراءات الهجوم في عملنا بالمعلومات الخاصة بالمجال المقدمة في عمل هاريد وآخرون [33]. ناقش المؤلفون في [33] سلسلة القتل السيبراني في المجال البحري نحو زيادة استعداد الملاحين ضد الهجمات السيبرانية. على وجه التحديد، قاموا بهجوم سياقي يستهدف معلومات الملاحة المستلمة في ECDIS. علاوة على ذلك، اعتمدنا على إطار ATT&CK [34] لوصف تقنيات الهجوم المنفذة في سيناريوهات الهجوم. تم اختيار إطار ATT&CK بسبب نموذج التهديد الشامل الخاص به في وصف السلوك العدائي.

3. المنهجية

تركز هذه الورقة على كشف الشذوذ في رسائل NMEA التي يمكن أن تسببها جهات فاعلة خبيثة. يوضح الشكل 1 النموذج الوصفي المقترح لنظام كشف شذوذ NMEA. تدعم عدة أنواع من رسائل NMEA عدة وظائف ملاحية. تتكون كل رسالة من عدة حقول، يحمل كل منها معلومات محددة. يقوم المهاجمون بإجراءات هجومية للتأثير على وظائف الملاحة من خلال استهداف أنواع الرسائل أو الحقول. ينفذ المدافعون خوارزميات كشف لحماية وظائف الملاحة من خلال مراقبة أنواع الرسائل والحقول لكشف إجراءات الهجوم. النموذج الوصفي عام بطبيعته؛ وبالتالي، فهو مناسب لأي حالة استخدام تستخدم بيانات استشعار يتم تبادلها في رسائل NMEA لوظائف الملاحة.

نقترح طريقة للتحليل المنهجي ومتعدد الأبعاد للشذوذ في رسائل NMEA نحو تطوير حل لكشف شذوذ يركز على NMEA. تحليل الشذوذ، كما هو محدد في مجال جودة البيانات، هو عملية لتحليل القيم في مجموعة بيانات تجريبياً، بحثاً عن سلوك غير متوقع [35]. في هذه العملية، يتم تحليل رسائل NMEA لتحديد الشذوذات المحتملة وتأثيرها وطرق استدعائها وكشفها. يتم تقديم وصف تفصيلي للطريقة المقترحة أدناه:

3.1. الخطوة 1—وظائف الملاحة (أي المهام)

تحديد وظائف الملاحة التي تعتمد على رسائل NMEA. يتم تعريف هذه الوظائف لنظام INS بواسطة IMO وللسفن المستقلة بواسطة هيئات التصنيف التي تصف المهام المختلفة التي تقوم بها الأنظمة البحرية أو الأفراد مثل مراقبة الطريق وتجنب الاصطدام ومراقبة المحرك والتحكم فيه وغيرها. يمكن استخدام هذه المعلومات لاحقاً في تحليل المخاطر، وتحديداً تقييم الأثر.

3.2. الخطوة 2—أنواع الرسائل

تحديد أنواع الرسائل المستهدفة، وتصنيفها وفقاً للسمات ذات الصلة مثل وظائفها الملاحية (مثل مراقبة المحرك) والمصدر (مثل المحرك). تحدد هذه الخطوة نطاق الرسائل التي تم تحليلها ومن المتوقع أن تكون معتمدة على النظام، حيث يدعم كل نظام قائمة محددة من الرسائل.

3.3. الخطوة 3—حقول الرسائل

تحديد حقول الرسائل ذات الصلة، وتحديد نوع المعلومات التي تحملها (مثل السرعة والاتجاه وما إلى ذلك)، وتنسيق كل حقل. نوع المعلومات مفيد لتحديد حقول الرسائل ذات الصلة ضمن نفس الرسالة وعبر أنواع الرسائل المختلفة. المعلومات مفيدة لكل من أنشطة الهجوم والكشف. من المتوقع أن يعكس المهاجم المتطور عرضاً معدلاً بالكامل، بينما يمكن للمدافع اكتشاف الشذوذ من خلال مراقبة الحقول ذات الصلة بحثاً عن التناقضات. من ناحية أخرى، فإن التنسيق والجوانب الأخرى مثل نطاق كل حقل مفيدة لتطوير طرق كشف الشذوذ.

تعتمد الخطوتان 2 و3 بشكل كبير على تنسيق الرسائل التي تم تحليلها. يوضح الشكل 2 تنسيق رسالة NMEA-0183. بعد محدد البداية ($)، يتم إرفاق معرف المتحدث NMEA المكون من حرفين (مثل GP لنظام GPS) بمعرف الرسالة المكون من 3 أحرف الذي يحدد نوع الرسالة (مثل DTM وRMC وما إلى ذلك). ثم تحتوي كل رسالة NMEA على عدة حقول، كل منها يتوافق مع معلومة معينة، مثل الوقت وخط الطول والسرعة فوق الأرض (SOG) وما إلى ذلك. ثم يتم فصل رقمين سداسي عشري يمثلان مجموع اختباري للجملة المحسوبة عن قيمة الحقل الأخير باستخدام محدد المجموع الاختباري (*). أخيراً، يحدد حرفا إرجاع carriage return وتغذية سطر نهاية كل رسالة.

3.4. الخطوة 4—الشذوذات

تحديد الأنماط الشاذة (مثل القيم والأحداث غير المعتادة) التي قد تظهر أثناء العمليات. خلال هذه الخطوة، يتم تحليل جميع الرسائل ضمن النطاق وحقولها لتحديد الأنماط الشاذة بناءً على بعض التصنيفات للشذوذات.

3.5. الخطوة 5—تقنيات الهجوم

تحديد تقنيات الهجوم التي يمكن تنفيذها لاستدعاء أنماط شاذة في أنواع الرسائل المحددة وحقول رسائلها.

3.6. الخطوة 6—خوارزميات الكشف

تحديد خوارزميات الكشف المناسبة لكشف الأنماط الشاذة الناتجة عن تقنيات الهجوم المنفذة ضد رسائل NMEA. ترتبط هذه الخطوة ارتباطاً وثيقاً بالخطوة السابقة حيث يتم تحدي خوارزمية الكشف باستمرار وتعزيزها بتقنيات هجوم محسنة حتى يتم تحقيق مستوى كفاءة كافٍ.

4. تحليل NMEA المنهجي بالنظر إلى حالتي استخدام APS وINS

في هذا القسم، نناقش الأنشطة والقطع الأثرية ونتائج نهج تحليل NMEA المقترح المعروض في القسم 3، مع مراعاة كل من حالتي استخدام INS وAPS. يهدف هذا إلى إظهار فائدة عملية تحليل الشذوذ المقترحة بالإضافة إلى تطوير حل مناسب لكشف الشذوذ.

4.1. الخطوة 1—المهام والوظائف الملاحية

تم تحديد المهام والوظائف لحالتي استخدام INS وAPS. تم تعريف مهام INS في القرار MSC.252(83) "اعتماد معايير الأداء المنقحة لنظام الملاحة المتكامل (INS)" من قبل IMO [36]. من ناحية أخرى، تم تعريف وظائف APS بواسطة أمرو وآخرون [37].

4.1.1. المهام الملاحية لنظام INS

تم تطوير مفهوم INS لتعزيز الملاحة الآمنة للسفن بوظائف متكاملة ومعززة. يتكون INS من ست مهام ملاحية [36]، على النحو التالي:

• مراقبة الطريق (INS-RM): المراقبة المستمرة للسفينة الخاصة وفقاً للمسار المخطط [38].

• تخطيط الطريق (INS-RP): القدرة على تخطيط الطريق (مثل التخزين والتحميل والاستيراد والتصدير والتوثيق)، والتحقق من الطريق بناءً على الحد الأدنى من الخلوص تحت العارضة، وصياغة وتحسين خطة الطريق مقابل المعلومات الجوية [36].

• تجنب الاصطدام (INS-CA): كشف ورسم السفن والأجسام الأخرى في الجوار لمنع الاصطدامات [38].

• بيانات التحكم في الملاحة (INS-NCD): توفير البيانات لمحطة المهام للتحكم اليدوي والآلي في السفينة [38].

• عرض الحالة الملاحية والبيانات (INS-NSDD): عرض العديد من المعلومات (مثل بيانات AIS ورسائل معلومات السلامة البحرية (MSI) وتكوين INS)، وتوفير وظائف الإدارة [36].

• إدارة التنبيهات (INS-AM): إدارة التنبيهات المركزية على الجسر لمراقبة ومعالجة وتوزيع وعرض التنبيهات [38].

يسهل INS أداء المهام الملاحية المذكورة أعلاه. مهام "مراقبة الطريق" و"تجنب الاصطدام" إلزامية وفقاً للوائح IMO [38]. علاوة على ذلك، يجب استيفاء متطلبات "عرض بيانات التحكم في الملاحة للتحكم اليدوي" لمهمة بيانات التحكم في الملاحة و"الوحدة C" لمهمة إدارة التنبيهات [36]. نظراً لأن عدم وجود بعض المهام والمتطلبات الملاحية في INS قد يزيد من مخاطر الملاحة الآمنة للسفينة، فقد تم تصنيفها على أنها إلزامية من قبل IMO. على سبيل المثال، بينما "تجنب الاصطدام" و"مراقبة الطريق" هما مهمتان ملاحيتان إلزاميتان لنظام INS، فإن "تخطيط الطريق" و"عرض الحالة الملاحية والبيانات" تُترك اختيارية من قبل IMO [36]. في الخطوة التالية، يتم تحديد رسائل NMEA ذات الصلة بكل مهمة ملاحية. يتيح لنا هذا المطابقة فهم مستوى مخاطر شذوذات NMEA المحتملة من خلال النظر في المهام الملاحية الإلزامية والاختيارية التي تحددها IMO.

4.1.2. وظائف APS

لا يوجد إطار تنظيمي أو إرشادات مقبولة عالمياً تحدد وظائف APS. ومع ذلك، في عملنا السابق [37]، قمنا بتجميع مجموعة من وظائف APS المتوقعة بناءً على مجموعة من الأعمال ذات الصلة بما في ذلك عمل رادسيث وآخرون [39] في مشروع "الملاحة البحرية غير المأهولة من خلال الذكاء في الشبكات (MUNIN)" بالإضافة إلى إرشادات الفئة للسفن المستقلة والمشغلة عن بعد من DNV [40]. ملخص موجز لوظائف APS المتوقعة تمت مناقشته أدناه (راجع [37] لمزيد من التفاصيل):

• وظائف مراقبة المحرك والتحكم فيه: مراقبة والتحكم في محرك APS. يمكن إجراؤها بواسطة APS نفسه (APS-AEMC)، أو مركز التحكم عن بعد (RCC) (APS-REMC)، أو فريق التحكم في الطوارئ (ECT) (APS-EEMC).

• وظائف الملاحة: إنشاء الوعي الظرفي. يمكن إجراؤها بواسطة APS نفسه بناءً على بيانات المستشعر (APS-AN)، أو في RCC بناءً على بيانات المستشعر المرسلة من APS (APS-RN)، أو بواسطة ECT بناءً على بيانات المستشعر المرسلة من APS (APS-EN).

قد يتسبب التأثير على هذه الوظائف من خلال الهجمات السيبرانية في عواقب تتعلق بالسلامة والمالية والتشغيل وفقاً لتقييم المخاطر الذي تم إجراؤه سابقاً [41].

4.2. الخطوة 2—أنواع الرسائل

هناك العديد من رسائل NMEA (أي الجمل) المحددة في معيار IEC 61162-1 [42]. في هذه الورقة، سنقتصر تحليلنا على رسائل NMEA التي تبثها محاكي Bridge Command (https://www.bridgecommand.co.uk/ (تم الوصول في 16 فبراير 2022)) من أجل تقييم عملية التحليل المقترحة. تم فحص الرسائل باستخدام دليل معيار IEC 61162-1 [42] المتوافق مع NMEA 0183. الرسائل بالإضافة إلى أوصافها موضحة في الجدول 1.

بعد تحديد رسائل NMEA المستهدفة للتحليل، يتم تحليل مشاركتها في وظائف الملاحة. يمكن أن يعكس هذا التحليل وظيفة الملاحة المتأثرة لكل رسالة NMEA التي تتعرض لهجوم. يوضح الجدول 2 العلاقة المحددة بين الرسائل ووظائف APS وINS. تعتبر الرسالة ذات صلة بوظيفة إذا كانت توفر معلومة تؤثر على أداء الوظيفة. على سبيل المثال، تعتمد وظيفة APS-AN على معلومات الموقع (أي الإحداثيات) التي يتم تبادلها في إحدى رسائل GGA أو GLL أو RMC لتخطيط الطريق. فيما يتعلق بحالة استخدام INS، فإن رسائل NMEA المستهدفة تشارك في جميع وظائف INS باستثناء "إدارة التنبيهات" باستخدام القرار MSC.252(83) [36]. من ناحية أخرى، نظراً لأن حالة استخدام APS في مراحل التطوير المبكرة، فقد نظرنا في المشاركة المحتملة لكل رسالة في وظائف الملاحة في APS بناءً على التصاميم والمفاهيم المنقولة في الأدبيات. يشير تحليلنا إلى أن جميع الرسائل المدروسة من المتوقع أن تشارك في وظائف الملاحة باستثناء رسائل RPM، والتي من المتوقع أن تشارك في وظائف مراقبة المحرك والتحكم فيه.

4.3. الخطوة 3—حقول الرسائل

خلال هذه الخطوة من تحليلنا، قمنا بتحليل حقول جميع الرسائل المحددة أثناء الخطوة 2 (القسم 4.2). الهدف من هذا التحليل هو فهم فائدة وتنسيق المعلومة الموضحة في كل حقل. يسهل هذا الفهم الأنشطة التي سيتم إجراؤها في الخطوات القادمة. علاوة على ذلك، تم تحديد رسائل NMEA ذات الصلة وتوضيحها في الجدول A1 في الملحق B. تعتبر رسالتان مترابطتين إذا كان التغيير في المعلومات الواردة في رسالة واحدة الذي يحدث في ظل الظروف العادية، سيغير (تأثير مباشر) أو قد يغير (تأثير غير مباشر) المعلومات في الرسالة الأخرى. يمكن ملاحظة مثال على التأثير غير المباشر في العلاقة بين رسالتي RMC وRPM: التغييرات في السرعة فوق الأرض (SOG) في رسالة RMC قد تعكس سرعة محرك مختلفة يتم التقاطها في حقل عدد الدورات في الدقيقة ضمن رسالة RPM. من ناحية أخرى، تمت ملاحظة مثال على التأثير المباشر في معلومات الموقع (أي خط الطول وخط العرض) التي يتم تبادلها في ثلاث رسائل، وهي GGA وGLL وRMC. إذا تغيرت أي قيمة في أي رسالة، فيجب أن تنعكس في الرسائل الأخرى. هذه المعلومات قيمة لكل من أنشطة الهجوم والكشف.

4.4. الخطوة 4—الأنماط الشاذة

في هذه الخطوة، يتم تحديد الشذوذات المحتملة التي يمكن ملاحظتها في رسائل NMEA. اقترح إيفار وآخرون [28] 13 نمطاً شاذاً محتملاً في رسائل AIS، التي تتبع نفس معيار NMEA مع بعض الاختلافات في تنسيق الرسالة وكذلك في المحتوى. ومع ذلك، فإنها تشترك في نفس التجريد لأنواع الرسائل، كل منها يتكون من عدة حقول رسائل. في هذه الورقة، نعتمد الشذوذات ذات الصلة ونتجاهل تلك غير ذات الصلة برسائل NMEA. تم تحديد سبعة أنماط شاذة رئيسية؛ هذه، مع أوصاف موجزة، موضحة في الجدول 3.

لقد قمنا بتحليل جميع الشذوذات المذكورة أعلاه مقابل جميع أنواع الرسائل وحقولها المقابلة وسجلنا نتائجنا للخطوات التالية. بعض الأمثلة على الشذوذات المحددة معروضة في الجدول 4 بينما يتم توفير قائمة بجميع الشذوذات المحددة في الجدول A2 في الملحق C.

4.5. الخطوة 5—تقنيات الهجوم

في هذا القسم، نناقش الأنشطة التي تم إجراؤها خلال الخطوة الخامسة في التحليل فيما يتعلق بتقنيات الهجوم المتوقع أن تستدعي واحداً أو أكثر من الشذوذات المحددة أثناء الخطوة 4. في هذا الاتجاه، نقترح تطبيق إطار ATT&CK [34] لنمذجة التهديدات بسبب طبيعته الشاملة ومستوى التجريد المناسب [41]. ومع ذلك، لا يزال من الممكن تطبيق طرق نمذجة التهديدات الأخرى إذا كانت تقترح تقنيات هجوم يمكن تحقيقها تقنياً. يأخذ نهج نمذجة التهديدات في الاعتبار كلاً من الهجمات البسيطة والهجمات المتطورة. ناقش لوكمان وآخرون [31] عدة أنواع من الهجمات ضد ناقل CAN، وهي إدراج الحزمة، والمحو، وإعادة الإرسال، وتعديل الحمولة. في إطار ATT&CK، قد يندرج الإدراج وإعادة الإرسال وتعديل الحمولة تحت تقنية هجوم التلاعب بالعرض (MoV) [43] بينما قد يندرج محو الحزمة تحت تقنية هجوم حرمان العرض (DoV) [44]. يتم توفير وصف موجز لكل تقنية أدناه:

• هجمات DoV تتضمن حرمان الملاحين أو الأنظمة المعتمدة من القدرة على تقديم تصور حي للبيئة المادية. يتم تحقيق ذلك بإسقاط رسالة NMEA واحدة أو أكثر لإعاقة وظائف الملاحة ذات الصلة.

• هجمات MoV تتضمن تعديل التصور الحي للبيئة المادية. يمكن القيام بذلك بعدة طرق:

• ثابت: يقوم المهاجم بتعديل القيم في رسائل NMEA الأصلية إلى قيم ثابتة محددة. على سبيل المثال، بغض النظر عن السرعة الحقيقية، يعكس قيمة سرعة ثابتة أخرى. هذا يحاكي جهة تهديد بسيطة تستخدم قواعد بسيطة للهجوم من النوع الوسيط (MitM).

• هجمات السياق: يتلاعب المهاجم بالرسائل بناءً على القيم التي تمت ملاحظتها في الرسائل الأصلية لإنشاء تغيير تدريجي. هذا يحاكي جهة تهديد أكثر تقدماً تستخدم قواعد MitM أكثر تطوراً. تجنب الكشف هو من بين أهداف المهاجم.

• هجمات الارتباك: يرسل المهاجم رسائل مصنوعة أو مكررة بالإضافة إلى الرسائل الأصلية.

• هجمات إعادة الإرسال: يعيد المهاجم إرسال مجموعة ثابتة من الرسائل بدلاً من التدفق الأصلي للرسائل.

لقد قمنا بتحليل الشذوذات والهجمات المحتملة التي يمكن أن تستدعيها. يتم تحديد العلاقة بين الشذوذ والهجوم إذا كان الهجوم، بناءً على تعريفه، قد يؤدي إلى استدعاء الشذوذ. تُظهر العلاقات المحددة في الجدول 5. يمكن قراءة الجدول على النحو التالي: من المتوقع أن هجوم DoV يستدعي فقط شذوذ "نقص الإبلاغ"، بينما من المتوقع أن هجوم MoV من نوع الارتباك يستدعي جميع الشذوذات المحتملة باستثناء "نقص الإبلاغ".

لتحقيق تقنيات الهجوم هذه، قمنا بتطوير نظام يسمى NMEA-Manipulator لتسهيل عملية استدعاء شذوذات NMEA المحددة. يعترض NMEA-Manipulator تدفق رسائل NMEA ويتحكم فيه باتباع مجموعة من القواعد (وصف مفصل في القسم 5.1).

4.6. الخطوة 6—خوارزميات الكشف

ناقش لوكمان وآخرون [31] العديد من خوارزميات الكشف لكشف الهجمات ضد رسائل ناقل CAN. تمت ملاحظة ثلاثة طرق كشف رئيسية في الأدبيات، الكشف القائم على التوقيع، والكشف القائم على الشذوذ، والكشف القائم على المواصفات. يتم توفير وصف موجز لكل طريقة أدناه بالإضافة إلى مبررنا لفائدتها في تحليلنا:

• الكشف القائم على التوقيع يشير إلى استخدام توقيع أو حدث محدد لكشف نشاط خبيث معين [45]. سيتطلب هذا هجمات موثقة ضد رسائل NMEA لتوليد توقيعات مناسبة.

• الكشف القائم على الشذوذ يشير إلى مراقبة الأنشطة في الوقت الحقيقي في النظام ومقارنتها بالسلوك العادي وإطلاق إنذار عند ملاحظة انحراف عن السلوك العادي [46]. يشمل هذا النهج التعلم الآلي والتردد والإحصاء والنهج الهجينة. نجادل بأن نهج التعلم الآلي والإحصاء تتطلب مجموعة كبيرة من البيانات لتدريب نماذج قوية بشكل فعال، وبالتالي، فهي حالياً ليست خيارات قابلة للتطبيق في حالتنا. توصلنا إلى هذا الاستنتاج بعد تجربة آلة المتجهات الداعمة أحادية الفئة وأشجار القرار لكشف الشذوذ. أظهر تقييم النموذج أداءً ضعيفاً يرتبط بشكل أساسي بحجم مجموعة البيانات المحدود. نظراً لعدم وجود مجموعة بيانات متاحة للعامة لرسائل NMEA ضمن نطاق تحليلنا، لم نتابع النهج القائمة على التعلم الآلي والإحصاء أكثر من ذلك. من ناحية أخرى، وجد أن الكشف القائم على التردد، مع الأخذ في الاعتبار تردد وصول الرسائل، مناسب ويتم النظر فيه بشكل أكبر للتقييم.

• الكشف القائم على المواصفات يشير إلى تطبيق الحدود والقواعد المناسبة لوصف السلوك المعروف للمكون [47]. نجادل بأن هذا النهج هو الأكثر ملاءمة في نطاق تحليلنا لأنه لا يتطلب كمية كبيرة من البيانات للتعلم. علاوة على ذلك، بالنظر إلى الطبيعة الديناميكية، التي يمكن التنبؤ بها إلى حد ما، لرسائل NMEA، فقد يكون سلوكها محصوراً ضمن مجموعة من القواعد والحدود (أي المواصفات). لقد حددنا عدة فئات من المواصفات، وهي المواصفات الفيزيائية والنظام والبروتوكول والبيئة. يتم توفير وصف موجز لكل فئة أدناه:

• المواصفات الفيزيائية تقيد الطريقة التي تتغير بها القيم بمرور الوقت بين الرسائل المتتالية (مثل أقصى تغيير في المسافة). هذا مرتبط بالبيئة المادية التي تهدف رسائل NMEA إلى عكسها.

• مواصفات النظام تقيد القيم في حقول NMEA وتطورها بمرور الوقت لكل نظام (مثل أقصى عدد دورات RPM في الدقيقة، وتسارع SOG، وما إلى ذلك). يجب تعريف هذا لكل نظام مستهدف.

• مواصفات البروتوكول تقيد تنسيق رسائل NMEA وحقولها (مثل تنسيق UTC في حقل UTC لرسائل GGA وGGL وRMC). يجب تعريف هذا لكل بروتوكول مستهدف؛ في تحليلنا، يتم استخدام NMEA0183.

• مواصفات البيئة تقيد نطاق القيم المتعلقة ببيئة التشغيل. يشمل ذلك الوقت والتاريخ وخط الطول وخط العرض ورمز المسند وغيرها.

لقد قمنا بتحليل الشذوذات المحددة من خلال النظر في طرق الكشف المفيدة المتوقعة. يتم تحديد العلاقة بين الشذوذ وطريقة الكشف إذا كان الشذوذ يمكن أن يخالف مواصفات أو حداً معيناً في طريقة الكشف المقابلة، بناءً على تعريفاتها. على سبيل المثال، التغيير المفاجئ غير المتوقع في أي قيمة حقل، ضمن التنسيق والنطاق المحددين مسبقاً، لا يخالف مواصفات البروتوكول لذلك الحقل. علاوة على ذلك، ليس من المتوقع أن يؤدي تغيير قيم الحقول وحدها إلى تغيير تردد وصول الرسالة. لذلك، ليس من المتوقع أن تكون مواصفات البروتوكول والكشف القائم على التردد مفيدة لكشف هذا النوع من الشذوذ. ومع ذلك، فإن التغيير المفاجئ في بعض الحقول المتعلقة بمعايير النظام أو الفيزيائية أو البيئية مثل السرعة والوقت والمسافة، سينتهك المواصفات المقابلة. يوضح الجدول 6 نتائج تحليلنا. يشير تحليلنا إلى أن الكشف القائم على التردد قد يكون مناسباً فقط لشذوذات نقص وزيادة الإبلاغ. من ناحية أخرى، يمكن استخدام النهج القائم على المواصفات لأنواع الشذوذ المتبقية، باستخدام فئات مواصفات مختلفة.

فيما يلي، نحلل طرق الكشف المختلفة مقابل الرسائل وحقولها لتحديد قواعد المواصفات المطلوبة للكشف.

5. توليد البيانات وإعدادها

في هذا القسم، نقدم نتائج تجاربنا طوال تحليلنا من أجل تقييم فائدتها في تطوير حل لكشف الاختراق. بدأنا بتوليد البيانات، وإعدادها، وإثرائها لتسهيل التحليل. بعد ذلك استخدمنا البيانات المولدة لتحديد المواصفات والقواعد المرشحة لكشف الشذوذ. تم إجراء الأنشطة في هذه العملية باستخدام منصة الاختبار السيبراني ذات الطابع البحري التي طورناها، والتي اقترحناها وقدمناها في عملنا السابق [48]. تتضمن المنصة عدة مكونات تدعم تطوير حل كشف الشذوذ.

5.1. توليد البيانات

يتم تسهيل عملية توليد البيانات من خلال توفر برنامج محاكاة أو جهاز يولد رسائل NMEA. هناك العديد من برامج محاكاة NMEA، مثل BridgeCommand (https://www.bridgecommand.co.uk/) ومحاكي NMEA (https://github.com/panaaj/nmeasimulator). تم استخدام برنامج BridgeCommand في هذه الورقة لأنه يسمح بسيناريوهات مخصصة. يشمل التخصيص المنطقة الملاحية وفئة السفينة والطقس والوقت وخيارات التقنيات المضمنة على متن السفينة.

بالإضافة إلى ذلك، يتم دعم عملية توليد البيانات بقدرات إجراء سيناريوهات هجوم متنوعة من أجل استدعاء الشذوذات المختلفة التي تم تحليلها. لهذا السبب، قمنا بتطوير نظام يسمى NMEA-Manipulator. على غرار أداة التقييم BRAT المقترحة سابقاً [24]، يتيح NMEA-Manipulator إجراء مجموعة واسعة من الهجمات ضد حركة مرور NMEA. ومع ذلك، فإن هدف التصميم الرئيسي له ليس تقييم أمان الأنظمة البحرية، بل تسهيل تحليل شذوذات NMEA نحو تطوير أنظمة كشف الاختراق. يتم استخدام NMEA-Manipulator في خطوتين، وهما الخطوة 5 من عملية تحليل شذوذ NMEA لملاحظة تأثير تقنيات الهجوم المقترحة، ويستخدم أيضاً في خطوة توليد البيانات لتقييم خوارزميات الكشف المختلفة. يظهر نظرة عامة على NMEA-Manipulator في الشكل 3.

يجب استضافة NMEA-Manipulator في جهاز متصل بنفس LAN الذي يربط المتحدث والمستمع الأصليين لـ NMEA. علاوة على ذلك، يتطلب NMEA-Manipulator عنصرين إضافيين غير تطويريين (NDI)، وهما أداة MitM مثل Ettercap وأداة استنشاق شبكة مثل tshark. توفر أداة MitM القدرة على الوصول إلى حركة مرور LAN والتحكم فيها، بينما تسمح أداة الاستنشاق بتسجيل رسائل NMEA الأصلية في ملف رسائل NMEA (NMF). بالإضافة إلى ذلك، يتطلب NMEA-Manipulator قواعد هجوم لتنظيم سلوكه. يتم إدراج قواعد الهجوم في ملف قواعد الهجوم (ARF). يحتوي ARF على عدة أسطر، كل منها يتوافق مع سيناريو هجوم معين (أي شذوذ مستدعى). تأمر قواعد الهجوم NMEA-Manipulator بأداء واحدة أو أكثر من تقنيات الهجوم التي تمت مناقشتها في القسم 4.5.

يتضمن NMEA-Manipulator ستة مكونات فرعية رئيسية (أي وحدات)، محلل، وكاشف جلسة، ومعدل ومُسقِط، ومُدرِج، ومرسل، ومُبلّغ. يقرأ المحلل رسائل NMEA من NMF ويستدعي المُعدِّل والمُسقِط في حالة ملاحظة رسالة جديدة. يطبق المُعدِّل والمُسقِط بعد ذلك قواعد الهجوم النشطة المحددة في ARF بينما يطبق المُدرِج قواعد هجوم الإدراج النشطة بالإضافة إلى هجمات إعادة الإرسال والارتباك. يحدد كاشف الجلسة عنوان IP لمستمع NMEA من حركة المرور المستنشقة ويُمرره إلى المرسل الذي يرسل الرسائل المعدلة والمُدرجة إلى المستمع. أخيراً، يُنشئ المُبلّغ ملف سجل بخصوص قواعد الهجوم المُفعّلة والمُعطّلة والمُعدّلة لتسهيل الخطوات اللاحقة من التحليل.

في هذا الاتجاه، استخدمنا NMEA-Manipulator أثناء عملية توليد البيانات من خلال إجراء ثلاث تجارب. تتكون كل تجربة من عدة سيناريوهات هجوم تعمل بالتزامن مع سيناريو ملاحة عادي. تم اختيار سيناريوهات الهجوم لتكون شاملة بحيث تستدعي مجموعة واسعة من الشذوذات المحددة. تضمنت جميع التمارين سيناريو ملاحة عادي يتمثل في اتباع مسار محدد مسبقاً في منطقة بالقرب من المملكة المتحدة باستخدام سفينة كبيرة مزودة برادار (RADAR) ونظام تحديد المواقع العالمي (GPS). ملخص موجز للتجارب التي تم إجراؤها معروض أدناه:

1. تم إجراء مزيج من هجمات MoV المختلفة، وهي الهجمات الثابتة وهجمات السياق، في محاولة لاستدعاء خمس شذوذات، وهي التغيير المفاجئ غير المتوقع، والقيمة غير الموجودة، والقيمة غير المتوقعة، والقيمة غير الصحيحة، وتطور حقل البيانات. استهدفت سيناريوهات الهجوم عدة رسائل وحقول رسائل مثل العودة بالزمن إلى الوراء يوماً واحداً عن طريق تغيير حقول UTC في رسائل GGA وGLL. مثال آخر هو زيادة مسافة أهداف الرادار بالإضافة إلى حقول أخرى في رسالة TTM، لإنشاء سيناريو تصادم.

2. تم إجراء العديد من هجمات MoV السياقية وهجمات DoV لاستدعاء شذوذ تطور حقل البيانات ونقص الإبلاغ، على التوالي.

3. تم إجراء مزيج من هجمات MoV المختلفة، وهي الهجمات الثابتة والارتباك وإعادة الإرسال. الهدف هو استدعاء عدة شذوذات، بما في ذلك مشكلات المطابقة وزيادة الإبلاغ.

يمكن العثور على مزيد من التفاصيل حول التجارب التي تم إجراؤها في الجدول A3 في الملحق D.

بيئة الاختبار المستخدمة لتحقيق السيناريوهات المختلفة موضحة في الشكل 4. يتم إنتاج عرض السفينة باستخدام محاكي BridgeCommand، الذي يُستخدم كمرسل NMEA. يتضمن المحاكي جهاز GPS محاكياً يرسل رسائل NMEA عبر UDP إلى المستمع. من ناحية أخرى، يتم إنتاج عرض مخطط الرحلة بواسطة برنامج OpenCPN لرسم الخرائط الملاحية، الذي يُستخدم كمستمع NMEA. علاوة على ذلك، يتم استخدام برنامج Wireshark [49] لالتقاط حركة مرور الشبكة عند عقدة الاستقبال. تشغل عقدة المهاجم نظام التشغيل Kali Linux مع نظام NMEA-Manipulator.

يتم إنشاء قطعتين أثريتين من كل تجربة، سجل تجربة والتقاط حزمة لحركة المرور الواصلة إلى مستقبل NMEA. يُستخدم السجل لتسهيل تصنيف رسائل NMEA (مثل مهاجمة أو عادية) ويدعم تتبع الأحداث التي وقعت أثناء التجارب. من ناحية أخرى، يُستخدم التقاط الحزمة للخطوات اللاحقة في تقييم طرق كشف الشذوذ المختلفة. أخيراً، تم إجراء تجارب إضافية لالتقاط رسائل NMEA في العمليات العادية للمساعدة في جهود تحديد المواصفات والقواعد المناسبة لكشف الشذوذ.

في هذه التجارب، كان مرسل ومستقبل NMEA فقط قيد التشغيل بينما تم إبقاء عقدة المهاجم خاملة.

5.2. إعداد البيانات وإثرائها

تم استخدام حركة مرور الشبكة الملتقطة من التجارب التي تم إجراؤها كمدخل في هذه الخطوة. تم استخدام Tshark، واجهة سطر الأوامر لـ Wireshark، لاستخراج رسائل NMEA مع وقت الملاحظة المرتبط بكل رسالة. هناك حاجة إلى معلومات الوقت لأن بعض رسائل NMEA لا تحتوي على مثل هذه المعلومات. ثم يتم إجراء تنظيف البيانات لإصلاح بعض المشكلات في الرسائل مثل فصل الرسائل المتسلسلة وإزالة أحرف carriage return. بعد ذلك، يتم تحويل الرسائل مع معلومات التوقيت إلى متجهات ميزات. علاوة على ذلك، يتم تصنيف الرسائل على أنها "عادية" أو "هجوم" بالرجوع إلى وثائق التجربة. على سبيل المثال، خلال التجارب المختلفة، لم تكن بعض أنواع رسائل NMEA أهدافاً للهجمات، مما يؤدي إلى تصنيف "عادي" لهذه الرسائل وتصنيف "هجوم" لأنواع الرسائل المستهدفة خلال فترة نشاط قواعد الهجوم. تتم إضافة حقول إضافية لإثراء البيانات الملتقطة، مثل المسافة من آخر موقع، ومعدل وصول الرسائل، وما إلى ذلك. هذا يهدف إلى تسهيل تحليل المواصفات والشذوذات. أخيراً، يتم تصدير متجهات الميزات الناتجة مع الرؤوس والتسميات إلى تنسيق CSV. نظراً لاختلاف الميزات لكل نوع من رسائل NMEA، فقد اعتُبر من الضروري تقييم المواصفات لكل نوع على حدة. لهذا السبب، فإن المخرجات من الخطوة السابقة هي مجموعة من ملفات CSV، واحد لكل نوع رسالة. يحتوي كل ملف على جميع الرسائل من نوع رسالة واحد تم توليدها في تجربة واحدة. جميع الأنشطة التي تم إجراؤها خلال هذه المرحلة باستثناء التصنيف اليدوي لبعض متجهات الميزات تتم آلياً باستخدام نصوص Python.

6. التقييم والنقاش

لقد قمنا بتحليل البيانات المولدة والمعالجة لتقييم طرق الكشف المقترحة. يتم تسليط الضوء على مجموعة مختارة من النتائج أدناه.

6.1. الكشف القائم على المواصفات

نتائج تقييم فئات الكشف القائم على المواصفات المقترحة المختلفة معروضة في هذا القسم، وهي مواصفات البيئة والفيزياء والنظام والبروتوكول.

6.1.1. مواصفات البروتوكول

يتم تنفيذ النهج من خلال عملية تحقق لكل رسالة للتحقق من امتثال حقولها لمواصفات البروتوكول. بالنظر إلى البنية والتنسيق المعروفين لكل نوع رسالة، يمكن لهذا النهج كشف مشكلات المطابقة بثقة عالية. على سبيل المثال، تم تنفيذ سيناريو هجوم أثناء التجربة 3 (الجدول A3) للتلاعب بالعرض فيما يتعلق بعدد الأقمار الصناعية التي قد تُستخدم لتثبيت الموقع. يتم تنفيذ الهجوم بتعديل قيمة العدد الصحيح المتوقعة الأصلية بالحرف "x". لوحظ تأثير الهجوم على برنامج مخطط الرحلة حيث تغير مؤشر عدد الأقمار الصناعية إلى اللون الأحمر، مما يعكس إشارة ضعيفة، ومع ذلك، كانت القيمة الحقيقية 13. تم تنفيذ قاعدة كشف لهذا الهجوم للتحقق مما إذا كان تنسيق الحقل متوافقاً أم لا وتعكس النتائج كشفاً صحيحاً.

6.1.2. مواصفات البيئة

تقييم هذا النهج لم يتم تنفيذه، بل تم تقييمه نظرياً في القسم. هذا بسبب أن هذه الفئة من المواصفات تعتمد على مصادر حقيقية للمعلومات المرجعية، مثل الوقت الصحيح ورمز المسند لنطاقات الإحداثيات. يعتمد المحاكي المستخدم على ملفات تعريف سيناريو ثابتة. يتم تعريف وقت كل تجربة محاكاة يدوياً. الاعتماد على وقت النظام الحقيقي لكشف عدم الاتساق يولد نتائج إيجابية خاطئة. لذلك، نجادل أنه في التنفيذ المباشر، إذا تلقت أنظمة السفينة معلومات الوقت من مصدر غير إشارات GPS، فإن كشف أي تعديلات على معلومات الوقت يكون مباشراً.

6.1.3. مواصفات النظام

يتم ترميز هذه الفئة من المواصفات في ملف لكل سفينة لاستضافة حل كشف الشذوذ. يملي هذا الملف على برنامج الكشف مواصفات الأنظمة المختلفة على متن السفينة لتحديد الشذوذ بسبب وجود قيم لا يُفترض ملاحظتها في النظام المضيف.

يوضح الشكل 5 تصوراً لنوع الشذوذ "القيمة غير الموجودة" الذي تم استدعاؤه بواسطة هجوم MoV أثناء التجربة 1 (الجدول A3). يعكس الشكل ملاحظتين، الجزء الأيسر يعكس كشف رسالة RSA لقراءة مستشعر تستقبل من مستشعر دفة الميناء. ومع ذلك، فإن ملف المواصفات للنظام المحاكى يملي أنه يحتوي فقط على مستشعر دفة الميمنة، مما يعني مستشعر دفة واحد. في الجزء الأيمن من الشكل، تم كشف شذوذ مماثل في رسالة RPM عند ملاحظة عمود جديد (أي رقم المصدر 4) غير موجود ضمن مواصفات النظام التي تحتوي فقط على عمودين (أي رقمي المصدر 1 و2). يتم كشف هذين الشذوذين وما شابههما بثقة عالية بسبب الطبيعة الثابتة للأنظمة في السفن. علاوة على ذلك، يمكن كشف الشذوذات الناتجة عن التغييرات المفاجئة باستخدام مواصفات النظام. على سبيل المثال، التغييرات المحتملة في عدد الدورات في الدقيقة (rpm) في رسالة RPM في أحد نماذج السفن في المحاكي تكون في النطاق (25 إلى 2000 rpm) بينما النطاق لنموذج آخر هو (1 إلى 100). تمت صياغة قواعد كشف لكل منها لكشف أي تغييرات في rpm خارج النطاق المناسب. ستعيد هذه القواعد شذوذات بثقة عالية. ومع ذلك، إذا حافظ المهاجمون على تغيير في قيم rpm ضمن مواصفات النظام، فلن يتم كشف أفعالهم باستخدام هذا النهج بناءً على قيمة rpm كميزة. تشمل الشذوذات الأخرى التي يمكن كشفها باستخدام هذا النهج القيم غير المتوقعة وتطور حقل البيانات. يمكن ملاحظة مثال على قيمة غير متوقعة في قيمة معدل الدوران (ROT) في رسالة ROT. لكل سفينة حد متوقع معين يمكن للسفينة أن تدور ضمنه في الدقيقة. على سبيل المثال، يمكن أن يتغير الفرق في قيمة ROT بين رسالتين متتاليتين في نموذج سفينة واحد في المحاكي ضمن النطاق (-100 إلى 100). يُظهر هجوم أثناء التجربة 2 هذا التأثير بزيادة قيمة ROT بمئة بينما كان الفرق الحقيقي 11.2، مما أدى إلى فرق إجمالي قدره 111.2 مما سمح بتحديد الشذوذ. ومع ذلك، وبالمثل للشذوذ السابق، يمكن للمهاجم البقاء غير مكتشف إذا كان التغيير الناتج ضمن مواصفات النظام.

6.1.4. المواصفات الفيزيائية

سنوضح الفائدة والتحديات المحددة في هذا النهج في مجموعة مختارة من الرسائل، وهي RMC وRPM وHDT، لكشف التغيير المفاجئ غير المتوقع وشذوذ تطور حقل البيانات. يمكن استدعاء مثال على تغيير مفاجئ غير متوقع من خلال هجوم MoV ليعكس تغييراً في الموقع بطريقة غريبة. تم تنفيذ عرض توضيحي لهذا أثناء التجربة 1 (الجدول A3). يمكن ملاحظة تأثير هذا الهجوم بوضوح عند تصور الفرق بين كل قيمتي خط عرض وخط طول متتاليتين، كما هو موضح في الشكل 6.

يمكن استدعاء نوع شذوذ تطور حقل البيانات من خلال تغيير حقلي SOG وCOG تدريجياً في رسالة RMC لتعكس سرعة وتفاصيل اتجاه مختلفة. مثال على هذا الهجوم تم توضيحه أثناء التجربة 2 (الجدول A3). تتغير قيم SOG وCOG في الظروف العادية بطريقة محددة. لا يمكن لقيمة SOG بين رسالتين RMC متتاليتين أن تتغير فيزيائياً خارج نطاق معين. ومع ذلك، يظهر تصور شذوذ حقل البيانات في الشكل 7أ. يمكن كشف هذا الشذوذ من خلال تعريف قاعدة تحدد النطاق الذي يمكن أن يتغير فيه SOG خلال فترة زمنية معينة. ثم أي تغيير خارج هذه القاعدة سيشير إلى شذوذ بثقة عالية. يوضح الشكل 7ب الطريقة التي يتصرف بها الفرق بين قيم SOG المتتالية في الظروف العادية وظروف الهجوم. تأثير الهجوم مرئي بوضوح ويمكن استنتاجه من الشكل. يمكن وصف سلوك المهاجم على أنه تقليل قيمة SOG بمقدار 1 عدة مرات في إطار زمني معين ثم إعادة القيمة إلى قيمتها الطبيعية، مما يؤدي إلى زيادة مفاجئة. وبالمثل، لا يُتوقع من COG في الظروف العادية أن يكون لديه اختلافات كبيرة بين الرسائل المتتالية إلا إذا كانت القيمة تصل إلى الحدود في النطاق (-360 إلى 360)؛ عندها فقط يكون التغيير الكبير طبيعياً. في هذه الورقة، تم تحديد عتبة الفرق الطبيعي بناءً على أكبر فرق محسوب في القيمة بين نفس الحقل في رسالتين متتاليتين في حركة المرور العادية المسجلة. سيتطلب تحديد عتبة أكثر دقة مجموعة بيانات أكبر من رسائل NMEA من أنظمة حقيقية.

لقد ذكرنا سابقاً أننا نأخذ في الاعتبار الجهات الفاعلة التهديدية البسيطة والمتقدمة. لهذا السبب، اقترحنا عملية تحديد رسائل وحقول NMEA ذات الصلة أثناء الخطوة 3 (القسم 3.3). إذا قام المهاجمون بصياغة رسائل بفروق ضمن النطاق الطبيعي، فإن ربط الحقول ذات الصلة في الرسائل الأخرى يمكن استخدامه لزيادة الثقة في الكشف. يمكن أن يوفر الارتباط بين حقل COG في رسالة RMC وحقل الاتجاه بالدرجات في رسالة HDT دليلاً على الشذوذ في كلتا الرسالتين بشرط أن تكون واحدة منهما فقط عرضة للهجوم في وقت معين. يبدو الشكلان 8أ و8ب متشابهين جداً؛ وهذا يصور الارتباط المباشر بين الحقلين في رسالتين مختلفتين. لتقييم قدرة الكشف بناءً على ارتباط حقول الرسائل، تم إجراء سيناريوهين هجوم في أوقات مختلفة أثناء التجربة 2 (الجدول A3). استهدف هجوم واحد حقل COG من خلال زيادة قيمة COG تدريجياً عدة مرات على مدى فترة من الزمن ثم إعادتها لاحقاً إلى القيمة الطبيعية. يمكن ملاحظة تأثير هذا الهجوم في الشكل 8ج. خلال نفس الإطار الزمني، لا تعكس الاختلافات في حقل الاتجاه سلوكاً مماثلاً؛ وهذا مؤشر قوي على وجود شذوذ. وبالمثل، استهدف الهجوم الآخر حقل الاتجاه في HDT، مما تسبب في تأثير مماثل لوحظ في الشكل 8د. يمكن أن يوفر هذا أيضاً مؤشراً قوياً على وجود شذوذ. ومن الجدير بالملاحظة أنه يُلاحظ أحياناً تأخير بسيط قبل أن تتطابق قيم COG والاتجاه مع بعضها البعض. يشكل استيعاب هذا تحدياً لخوارزمية الكشف وسيتم النظر فيه في العمل المستقبلي.

6.2. الكشف القائم على التردد

تم اقتراح هذه الفئة من المواصفات حصراً لكشف شذوذات نقص وزيادة الإبلاغ. المبرر وراء ذلك هو أنه في الظروف العادية، رسائل NMEA من كل نوع لها كمية محددة من الرسائل أو الحزم التي تصل إلى النظام المستهدف في فترة محددة. نشير إلى هذا المقياس بمعدل الوصول. هجمات DoV ستُسقط بعضاً أو كل الرسائل؛ سيؤدي هذا إلى انخفاض في معدل الوصول مما يشير إلى نقص الإبلاغ. علاوة على ذلك، فإن هجمات MoV من نوع إعادة الإرسال التي يعيد خلالها المهاجمون إرسال الرسائل بمعدل إرسال منخفض (TR) ستسبب أيضاً شذوذ نقص الإبلاغ. من ناحية أخرى، إذا زاد المهاجمون معدل الإرسال ليتجاوز الطبيعي، سيزيد معدل الوصول، مما يشير إلى زيادة الإبلاغ. وبالمثل، يمكن أن تسبب هجمات MoV من نوع الارتباك نقصاً أو زيادة في الإبلاغ بناءً على معدل الإرسال الذي يتحكم فيه المهاجم. لتقييم الكشف المقترح لهذه الشذوذات، نستخدم Wireshark لرسم عدد الحزم في الثانية في حركة المرور المسجلة للتجارب ذات الصلة.

تحتوي حركة المرور على رسالة NMEA واحدة لكل حزمة باستثناء رسائل RPM؛ حيث يتم ضم كل زوج في حزمة واحدة. يوضح الشكلان 9أ و9ب معدل الوصول لحركة المرور المسجلة في التجربتين 2 و3 (الجدول A3)، على التوالي. تأثير هجمات DoV مرئي بوضوح في الشكل 9أ. خلال هذا الهجوم، تم إسقاط جميع الرسائل، ثم استئنافها، ثم إسقاطها مرة أخرى. الانخفاض الثالث المرئي في الرسم البياني يرجع إلى التبديل من حركة المرور المولدة عبر NMEA-Manipulator إلى حركة المرور العادية. يوضح الشكل 9ب معدل الوصول أثناء هجمات مختلفة بمعدلات إرسال مختلفة. بعد البدء بحركة مرور عادية، سيطر NMEA-Manipulator على حركة المرور وطبق عدة هجمات MoV ثابتة، والتي كان لها تأثير محدود على معدل الوصول. ثم بدأ هجوم MoV من نوع الارتباك بإرسال رسائل عادية مسجلة مسبقاً بمعدل إرسال رسالة واحدة كل 0.5 ثانية بالإضافة إلى حركة المرور العادية. بعد ذلك، تم زيادة معدل الإرسال لإرسال رسالة واحدة كل 0.1 ثانية باستخدام رسائل عادية مسجلة ورسائل مزورة مسجلة بالتناوب. أخيراً، تم زيادة معدل الإرسال إلى رسالة واحدة كل 0.05 ثانية، على غرار التكرار الأخير، باستخدام رسائل عادية ومزورة مسجلة. تأثير هجمات الارتباك وإعادة الإرسال باستخدام معدلات إرسال مختلفة مرئي بوضوح في الشكل 9ب حيث ينحرف معدل وصولها بطريقة واضحة عن معدل الوصول العادي. ومع ذلك، إذا استهدف المهاجمون أنواعاً قليلة فقط من الرسائل، فإن النظر في معدل الوصول لحركة المرور بأكملها قد يفوت الهجوم المستهدف. لذلك، نقترح مراقبة معدل وصول مخصص لكل نوع رسالة على حدة. هذا مناسب بشكل خاص في أنظمة السفن الحقيقية حيث رسائل NMEA المختلفة لها معدلات وصول مختلفة. من أجل تجنب الكشف باستخدام الكشف القائم على التردد، يحتاج المهاجمون إلى ضبط TR بشكل مناسب أثناء هجماتهم، مما يعقد مهمتهم.

6.3. توصيل المخاطر المرتبطة بالكشف

يهدف تحليلنا المقترح إلى تطوير حل لكشف الشذوذ مُثرى بالسياق التشغيلي لرسائل NMEA المرتبطة بالوظائف المختلفة. عندما يتم كشف شذوذ باستخدام آليات الكشف المختلفة لرسالة معينة أو مجموعة رسائل، فإن الوظائف المتأثرة تكون معروفة. وبالتالي، يتم تسهيل التوصيل متعدد المستويات للمخاطر من المستوى التقني إلى المستوى التشغيلي. مثال على ذلك كما يلي: إذا تم كشف الشذوذ الموضح في الشكل 8د ضد رسالة HDT، فإن ما يلي معروف:

• تم تحديد عدم اتساق بواسطة مواصفة فيزيائية تتعلق بمعلومات الاتجاه في رسائل HDT؛ هذا بسبب الخطوتين 6 و3. في الخطوة 3 تم تعيين حقل الاتجاه لتحديد الشذوذات والهجمات وطرق الكشف ذات الصلة. في الخطوة 6 تم اقتراح طرق الكشف لحقل الاتجاه.

• الرسائل الشاذة قادمة من البوصلة الجيروسكوبية؛ هذا معروف من خلال معرف المتحدث المحدد في الخطوة 2.

• قد يشير هذا إلى شذوذ تطور حقل البيانات؛ تم تحديده في الخطوة 4.

• قد يكون هذا نتيجة لهجوم MoV؛ العلاقة بين الشذوذ والهجوم الذي قد يسببه تم تحديدها في الخطوة 5 (انظر الجدول 5).

• قد يؤثر هذا على وظائف مراقبة الطريق وبيانات التحكم في الملاحة وعرض الحالة الملاحية والبيانات في INS مما قد يسبب خسائر تتعلق بالسلامة والمالية والسمعة وضرراً بيئياً؛ تم تحديد العلاقات بين الرسالة المستهدفة والوظائف ذات الصلة في الخطوة 1 (انظر الجدول 2).

6.4. القيود المحددة

سلطت التجارب الضوء على بعض القيود المحتملة في طرق كشف الشذوذ المختلفة. ملخص القيود المحددة معروض أدناه:

• النتائج الإيجابية الكاذبة: المواصفات ضعيفة التكوين يمكن أن تولد تنبيهات إيجابية كاذبة. على سبيل المثال، مواصفة نظام لسفينة محاكاة واحدة هي نطاق لتغيير RPM بمقدار 100 بين رسالتين RPM متتاليتين. استخدام نفس المواصفة في سفينة أخرى بنطاق تغيير RPM مختلف سيولد نتيجة إيجابية كاذبة. لذلك، يُشجع بشدة على ضبط مواصفات النظام بدقة لكل نظام مستهدف. جانب آخر يجب مراعاته هو خطأ المستشعر أو الضوضاء. قد تستدعي الضوضاء في المستشعر شذوذاً ومؤشراً خاطئاً على سلوك خبيث. لوحظت حالة من هذه المشكلة في إحدى التجارب. تسبب خلل في المحاكي في تغير سرعة السفينة بشكل غير طبيعي بسبب انخفاض عمق الماء. لوحظ شذوذ في البيانات ليس بسبب سلوك خبيث. يجب مراعاة هذه المشكلات أثناء تطوير نظام كشف الشذوذ.

• النتائج السلبية الكاذبة: السلوك الخبيث الذي يعمل ضمن الحدود المحددة في المواصفات لن يتم كشفه ولكن لا يزال يمكن أن يسبب تأثيراً. على سبيل المثال، تقليل قيمة RPM بمقدار 50 بينما حد التغيير هو 100 لن يولد تنبيهاً، ولكن قيمة السرعة ستظهر أقل من المتوقع، مما قد يتسبب في أمر بزيادة السرعة والذي بدوره يمكن أن يسبب مشكلة في الملاحة الآمنة.

علاوة على ذلك، تم ذكر قيود أخرى في تحليلنا فيما يلي:

• عدد الرسائل التي تم تحليلها محدود بتلك المدعومة من قبل المحاكي المتاح. ومع ذلك، فإن أربعة أنواع من الرسائل، وهي GLL وRMC وGGA وZDA، هي من بين أفضل 10 رسائل NMEA تمت ملاحظتها على الإنترنت أثناء مسح Shodan [50]. يجب أن يركز العمل المستقبلي على المزيد من أنواع الرسائل.

• تضمن تحليلنا فقط NMEA0183. يتم دمج بروتوكولات أخرى في الأنظمة البحرية بما في ذلك NMEA2000 [6] وOneNet [51]. ومع ذلك، لا يزال NMEA0183 مستخدماً في الصناعة البحرية كما لوحظ في الأدبيات ومسح Shodan على الإنترنت [50].

• يأخذ تحليلنا في الاعتبار فقط الهجمات ذات الأهداف التي تؤثر على المهام الملاحية من خلال حرمان وتعديل العرض الذي يتم تقديمه باستخدام رسائل NMEA. يمكن التحقيق في تقنيات هجوم أخرى يمكن أن تسبب شذوذاً في العمل المستقبلي.

• استخدمنا إطار ATT&CK لنمذجة التهديدات. قد يؤدي استخدام تقنيات نمذجة تهديدات أخرى إلى تحديد هجمات أخرى. ومع ذلك، فإن هجماتنا المدروسة تتماشى مع الهجمات التي تمت مناقشتها في الأدبيات.

• استخدمنا فئات معينة من الشذوذات أثناء تحليلنا بناءً على الشذوذات الملاحظة في الأدبيات. يمكن أن توجد شذوذات أخرى. إذا تم تحديد شذوذات جديدة في المستقبل، فسيتطلب هذا تكراراً آخر لعملية التحليل للنظر في الرسائل والحقول والهجمات وطرق الكشف ذات الصلة.

7. خيارات النشر

ناقش لوكمان وآخرون [31] استراتيجيات النشر الملاحظة لأنظمة IDS لناقل CAN. لوحظ أن أنظمة IDS لناقل CAN توضع إما في العقد المركزية أو النهائية أو داخل شبكة CAN. من المتوقع أن يكون لأنظمة IDS لـ NMEA نفس الخيارات. ومع ذلك، فإن اختيار الموقع حساس لحالة الاستخدام. ومع ذلك، نناقش هنا الوضع المحتمل لأنظمة IDS لـ NMEA في الأنظمة البحرية. تم ملاحظة فئتين رئيسيتين من أنظمة IDS في الأدبيات، وهما IDS القائم على المضيف (HIDS) وIDS القائم على الشبكة (NIDS). ناقش جاك وآخرون [52] مفهوم الوعي الظرفي في الأنظمة البحرية وأشاروا إلى التحدي في تطبيق HIDS بسبب الاضطرابات المحتملة في الضمان. من ناحية أخرى، فإن NIDS هو خيار نشر أكثر ملاءمة، حيث يمكن إضافته إلى الشبكات لمراقبة حركة مرور NMEA وكشف الشذوذ. ومع ذلك، نجادل أنه إذا تمكن المهاجمون من استهداف شبكة السفينة وتنفيذ الهجمات المقدمة في هذه الورقة بنجاح، فقد يتم استهداف NIDS أيضاً باستخدام تقنيات هجوم مماثلة، لتجنب الكشف. لذلك، نجادل بأن التنفيذ الأمثل يمكن تحقيقه من خلال دمج حل كشف الشذوذ داخل عقدة مستقبل NMEA، كجزء من البرنامج الذي يستهلك رسائل NMEA. ومع ذلك، بالنظر إلى أن هذا الحل سيسمح بكشف الشذوذ في الوقت الحقيقي، فإن تقييم الأداء ضروري للتحقق من أن الحل لا يعيق وظائف الملاحة. يمكن أن يستهدف العمل المستقبلي تنفيذ إثبات المفهوم من خلال تطوير IDS لـ NMEA ودمجه مع برنامج OpenCPN.

8. الاستنتاجات

الرقمنة المستمرة في المجال البحري تؤدي إلى أنماط تشغيل جديدة. يتم تحويل عمليات الشحن تدريجياً إلى مواقع ساحلية بعيدة، بالاعتماد على بيانات المستشعرات المنقولة من السفن. نمط التشغيل هذا يجعل عمليات الشحن عرضة لمجموعة واسعة من الهجمات السيبرانية بما في ذلك التلاعب بالعرض وحرمانه، مما يعيق الملاحة الآمنة لاحقاً. استهدفت هذه الورقة كشف الشذوذ في رسائل NMEA الناتجة عن جهات فاعلة خبيثة. تحمل رسائل NMEA معلومات حاسمة للعديد من وظائف الملاحة، مثل تجنب الاصطدام. يمكن أن تتسبب عواقب استهدافها في هجمات سيبرانية في عواقب تتعلق بالسلامة والتشغيل والمالية.

بداية، تم اقتراح تحليل منهجي لرسائل NMEA. يهدف التحليل إلى تحديد الشذوذات في رسائل NMEA وسببها وطرق الكشف الممكنة. بعد ذلك، تم استدعاء العديد من الشذوذات المحددة باستخدام بعض الهجمات المحددة في بيئة اختبار ضد مجموعة من رسائل NMEA المحاكاة. ثم تم تقييم طرق الكشف المحددة.

يشير تحليلنا إلى رسائل وحقول NMEA ذات الصلة التي أظهرت فائدة لكشف التناقضات. علاوة على ذلك، يوفر التحليل المنهجي نظرة عامة متعددة المستويات للمخاطر المرتبطة بالشذوذات المكتشفة. عندما يتم كشف شذوذ على المستوى التقني، يمكن استنتاج معلومات على المستوى التقني، مثل الجهاز المصدر وتقنية الهجوم المرشحة والرسائل ذات الصلة للتحقيق. علاوة على ذلك، يتم استخدام معلومات المخاطر على المستوى التشغيلي أو مستوى المهمة فيما يتعلق بالخطر المحتمل للشذوذ المكتشف ضد الوظائف ذات الصلة. تعكس تقنيات الهجوم المستخدمة العديد من الجهات الفاعلة التهديدية المحتملة بدرجات متفاوتة من التعقيد؛ وهذا يشكل تغطية جيدة للتهديدات المحتملة ضد رسائل NMEA ضمن النطاق. سيتم النظر في تقنيات هجوم أخرى لتحقيق أهداف أخرى غير التأثير على وظائف الملاحة في العمل المستقبلي.

تم إثبات أن الكشف القائم على المواصفات والتردد يوفر قدرة على الكشف باستخدام أساليب مختلفة. يمكن أن توفر مواصفات البروتوكول مؤشراً واثقاً لمشكلات المطابقة في رسائل NMEA. علاوة على ذلك، يمكن أن توفر مواصفات النظام مؤشراً واثقاً للشذوذات الخاصة بالنظام المتعلقة ببعض القيم والأحداث غير المتوقعة في نظام معين. ومع ذلك، فإن كفاءة هذا النهج تعتمد على قوة المواصفات المحددة لكل نظام مضيف. لا يزال من الممكن للهجمات المتقدمة تجنب الكشف. بالإضافة إلى ذلك، يمكن أن توفر المواصفات الفيزيائية مؤشرات للشذوذ، لكنها تتطلب تطويراً دقيقاً للمواصفات. لقد أوضحنا فائدة تحديد العلاقات بين بعض رسائل NMEA وحقولها في تحديد شذوذات تطور حقل البيانات. يمكن أن توفر العلاقات مؤشرات قوية على الأنماط الشاذة. ومع ذلك، فإن التحليل الشامل لجميع العلاقات المحددة مطلوب لتعميم النتائج. علاوة على ذلك، يمكن أن يوفر الكشف القائم على التردد مؤشراً قوياً على شذوذات نقص وزيادة الإبلاغ. ومع ذلك، يمكن للمهاجمين المتقدمين تجنب الكشف من خلال الحفاظ على معدل إرسال يتوافق مع حركة المرور العادية.

يمكن أن يستخدم العمل المستقبلي نتائج تحليلنا لتطوير وتنفيذ وتقييم حل كشف شذوذ NMEA مناسب للنشر على متن السفن. علاوة على ذلك، يمكن أن يستخدم اتجاه آخر تنويعة من بيئة الاختبار الخاصة بنا بتضمين محاكيات NMEA أخرى أو مصدر NMEA مادي (مثل GPS أو AIS)؛ وهذا سيشمل رسائل وحقول NMEA أخرى. بالإضافة إلى ذلك، استهدفت هذه الورقة تقنيات هجوم يمكن أن تسبب تأثيراً على وظائف الملاحة. يمكن أن يستكشف العمل المستقبلي تقنيات هجوم مختلفة لا تهدف إلى التأثير على وظائف الملاحة ويمكن أن تستدعي شذوذاً مثل استخراج البيانات أو القيادة والتحكم. علاوة على ذلك، حددنا تطبيقاً محتملاً لتقنيات التعلم الآلي في كشف شذوذ NMEA. ومع ذلك، كانت كمية البيانات المحدودة تحدياً يمكن استهدافه في العمل المستقبلي. أخيراً، يمكن أن يكون اتجاه آخر للعمل المستقبلي هو استخراج المواصفات الفيزيائية ومواصفات النظام من كمية كبيرة من رسائل NMEA المسجلة في العديد من الأنظمة، لتحسين قواعد المواصفات.

المراجع

قائمة المراجع الكاملة (52 مصدرًا) متاحة في الملف الأصلي للPDF.

Abstract

Several disruptive attacks against companies in the maritime industry have led experts to consider the increased risk imposed by cyber threats as a major obstacle to undergoing digitization. The industry is heading toward increased automation and connectivity, leading to reduced human involvement in the different navigational functions and increased reliance on sensor data and software for more autonomous modes of operations. To meet the objectives of increased automation under the threat of cyber attacks, the different software modules that are expected to be involved in different navigational functions need to be prepared to detect such attacks utilizing suitable detection techniques. Therefore, we propose a systematic approach for analyzing the navigational NMEA messages carrying the data of the different sensors, their possible anomalies, malicious causes of such anomalies as well as the appropriate detection algorithms. The proposed approach is evaluated through two use cases, traditional Integrated Navigation System (INS) and Autonomous Passenger Ship (APS). The results reflect the utility of specification and frequency-based detection in detecting the identified anomalies with high confidence. Furthermore, the analysis is found to facilitate the communication of threats through indicating the possible impact of the identified anomalies against the navigational operations. Moreover, we have developed a testing environment that facilitates conducting the analysis. The environment includes a developed tool, NMEA-Manipulator that enables the invocation of the identified anomalies through a group of cyber attacks on sensor data. Our work paves the way for future work in the analysis of NMEA anomalies toward the development of an NMEA intrusion detection system.

1. Introduction

The maritime domain is undergoing a major digital transformation, leading to substantial changes in the business models, processes, and technology [1]. The Integrated Navigation System (INS) on conventional vessels of today is deployed to support safe navigation as a result of such digital transformation. However, technological advancements would change the characteristic of vessels dramatically in the near future. Recently, new projects have been proposed to increase autonomy in maritime. This includes automating maritime systems and services until such systems can reach sea-going autonomous operation by the year 2035 [2]. These projects have led to the proposition of a new ship class named Maritime Autonomous Surface Ship (MASS) as defined by the International Maritime Organization (IMO) [3]. Among these new projects is the Autonomous Ferry (Autoferry) project [4]. The project aims to develop an Autonomous Passenger Ship (APS) or ferry for carrying passengers across the Trondheim city canal in Norway. The APS is expected to be remotely monitored and controlled when necessary from a remote center.

The novelty of the Autoferry project influenced the cyber risk paradigm and led to unique attack objectives and techniques. The main factors that have led to this are the auto-remote operational mode as well as the fact that passengers will be on board without a crew. The auto-remote operational mode has led to novel and broader cyber attack vectors due to remote connectivity, dependency on automated services, reduced human defenses, and the dependency on digital technologies for the remote operator for intervention. Furthermore, the presence of passengers imposes a safety risk factor motivating different types of threat actors to cause them harm through cyber attacks. Among the identified attack vectors in Autoferry is the navigational information which is communicated among the different marine components.

The National Marine Electronics Association (NMEA) defined a group of electronic and data specifications for the communication between different marine electronic systems. These specifications have manifested into a series of standards. The latest versions are NMEA0183 [5] and NMEA2000 [6]. These standards govern the structure and the manner in which messages are communicated among the different devices. NMEA messages are mainly utilized in the maritime domain. However, the positioning information provided by them has found their application in other domains such as those with requirements for location tracking for personal security [7,8], and car theft detection [9]. While these messages provide an abundance of information utilized in different navigational tasks and functions, their security has been investigated and found to be lacking any controls such as authentication, encryption, and validation [10]. This makes them susceptible to a wide range of cyber-attacks.

This paper aims to improve the security of NMEA messages by identifying and proposing relevant approaches for the treatment and monitoring of the risks associated with them. The NMEA0183 standard is considered in this paper, with future plans to extend the work to include the NMEA2000 standard. Therefore, we propose a systematic approach for analyzing NMEA messages, their anomalies, malicious causes of such anomalies (i.e., attacks) as well as the appropriate detection algorithms.

We utilize two maritime use cases throughout this paper to facilitate the description of our approach. The use cases are the APS and conventional vessels equipped with an INS. In this way, we caught an opportunity to prove the importance of our study not only for today's vessels but also for potential vessels of the future. We argue that our approach can aid in the development of resilient navigation systems that are developed and operated under the consideration of adversarial behavior.

The contribution of the paper is as follows:

• We propose a novel systematic approach for anomaly detection in NMEA messages.

• We present an analysis of possible anomalies in NMEA messages and their cause-and-effect relationship with a range of cyber-attacks.

• We propose a method for creating synthetic datasets with both normal and maliciously tampered with NMEA messages, and we implement and use a software package to create such experimental datasets.

• We use the datasets within the context of two use cases to evaluate the performance of anomaly detection approaches specifically designed for the purpose.

The remainder of the paper is structured as follows: In Section 2, we provide the necessary background and we review the relevant literature. In Section 3, we present our proposed method for systematic, multidimensional analysis of anomalies in NMEA messages. In Section 4, we discuss how our proposed method applies to the INS and the APS use cases. In Section 5, we present results of our experimentation with the proposed approaches, towards assessing its usefulness in developing an intrusion detection system for NMEA messages. In Section 6, we evaluate and discuss the results and findings of the experimentation, and in Section 7 we present deployment options of an NMEA IDS. Finally, Section 8 summarizes our conclusions and proposes directions for future research.

2. Background and Related Work

Several publications which point out cyber risks of autonomous ships are available in the literature. Kavallieratos et al. [11] presented the results of cyber risks assessment of remotely controlled and autonomous ships. The risk assessment was performed using the STRIDE threat modeling methodology. According to the results, the Automatic Identification System (AIS), Electronic Chart Display and Information System (ECDIS), and Global Maritime Distress Safety System (GMDSS), in particular, include various high risks. Vinnem and Utne [12] discussed the possibility of using autonomous ships for damaging the offshore industry. A cyber attack may cause the collision of an autonomous ship and an offshore platform at sea, intentionally or unintentionally. The paper also suggests several mitigation measures. Keeping a small number of crew onboard is argued to be the most effective preventive measure against cyber risk according to the authors.

Not only autonomous ships but also conventional vessels sailing at sea today could be exposed to cyber attacks. Svilicic et al. [13] unveiled the cyber vulnerabilities of an INS onboard ship. The authors acquired a total of 27 pieces of information, and four vulnerabilities using a vulnerability scanner. One of the detected vulnerabilities in the INS was reported as "Critical". Moreover, a survey of intrusion detection in vehicles, including maritime vessels, is presented by Loukas et al. [14]. The authors discussed several works targeting Global Positioning System (GPS) and AIS spoofing and manipulation. However, no reference is made to the NMEA protocol.

Motivated by the identified threats in the maritime industry and focusing on the NMEA protocol as a possible threat vector, we surveyed the current state-of-the-art of NMEA security. Krile et al. [15] explained the network of an INS onboard ship, including a detailed description of the NMEA 0183 and 2000 standards. The authors focus on NMEA 2000 in particular in different aspects, such as components of an NMEA 2000 network, comparison of ethernet and Controller Area Network (CAN), and the functions of CAN. Moreover, the authors discuss NMEA software, including Sail Soft NMEA Studio, Maretron N2K Analyzer, and N2K Meter. Additionally, several applications of NMEA messages have been observed in digital forensics [16,17], personal security [7,8], car theft detection [9], as well as utilizing NMEA messages in detection Global Navigation Satellite System (GNSS) Spoofing [18]. Nevertheless, these works did not discuss the security of NMEA messages themselves. Some works have argued that NMEA security currently depends on the network and host security [19,20]. However, Seong and Kim [21] addressed the cybersecurity of NMEA messages by utilizing secure hash functions when storing NMEA messages in the voyage data recorder onboard vessels. This is argued to improve the authenticity of stored NMEA messages.

Additionally, Boudehenn et al. [22] proposed a machine learning approach to detect GPS attacks. The GPS device broadcasts NMEA 0183 messages to the ship network. Machine learning software developed by the authors in a Raspberry Pi 3B+ could detect GPS jamming and spoofing attacks successfully. In this way, the officer of the watch on the bridge may be notified about a potential GPS attack. Machine learning could be also used to detect malicious activities in the ship network [23]. Moreover, Hemminghaus et al. [24] have presented a bridge attack tool named BRidge Attack Tool (BRAT) that targets NMEA messages with a wide range of attacks in order to assess the security of maritime systems. The authors discussed the lack of security in marine systems, particularly the ones utilizing the NMEA protocol. Then, they presented the architecture of the tools and evaluated it against the open-source OpenCPN chart plotter.

Another application of the NMEA protocol is found in AIS. The vessels are equipped with an AIS to improve the safety and efficiency of navigation and to protect the marine environment [25]. It is a compulsory component for vessels under specific conditions described in the Safety of Life at Sea (SOLAS) Convention [26]. An AIS transceiver transmits static, dynamic, and voyage related information as well as safety related messages using the format of NMEA messages [25,27]. Several works have addressed anomaly detection in AIS. Iphar et al. [28] proposed an integrity assessment of AIS messages from a data quality perspective. The authors targeted AIS messages for data quality assessment and conducted several manipulation functions on AIS messages to invoke anomalies in the data. Then they proposed a rule-based detection approach. In another work, Blauwkamp et al. [29] utilized machine learning for detecting anomalies in traffic inferred from AIS messages. Although the authors did not target cybersecurity, cyber attacks are among the main motivations of their research. Although NMEA and AIS messages have a relatively similar format, AIS messages include encoded binary payload instead of a textual payload in the NMEA-0183. Furthermore, AIS messages carry different information than NMEA messages, such as traffic messages from other ships. These differences motivated the work in this paper to investigate suitable anomaly analysis and detection approaches.

The origin of NMEA comes from the CAN protocol or CAN bus, a message-based protocol that enables communication among devices in automobiles [30]. Several works in the literature have addressed anomaly detection in CAN bus. We aim to infer relevant artifacts from the domain of CAN bus anomaly detection and utilize them for NMEA anomaly detection. In this paper, we rely on the state-of-the-art Intrusion Detection Systems (IDS) for CAN bus in the automotive domain which was captured by Lokman et al. [31]. The authors discussed several aspects, namely deployment strategies, detection approaches, attacking techniques, and technical challenges related to the field. Due to the similarities between NMEA and CAN bus, several artifacts were found relevant to our work and they will be discussed throughout this paper.

The systematic anomaly analysis of NMEA messages proposed in this paper is influenced by the Six-Step Model proposed by Sabaliauskaite et al. [32]. The authors proposed six steps for conducting joint safety and security risk analysis process utilizing six dimensions, namely, functions, structure, failures, attacks, safety countermeasures, and security countermeasures. Accordingly, the anomaly analysis in this paper consists of six steps; each step analyzes a different dimension related to NMEA anomaly detection, namely, navigational functions, messages, fields, anomalies, attacks, and detection methods. The systematic and multidimensional nature of the analysis in the Six-Step model has influenced our proposition. Additionally, the analysis of NMEA messages and their anomalies is influenced by the AIS analysis process conducted by Iphar et al. [28] (more details in Section 4.4).

The attack procedures in our work are influenced by the domain-specific information provided in the work of Hareide et al. [33]. The authors in [33] have discussed a cyber kill chain in maritime toward increasing the navigators' preparedness against cyber attacks. Specifically, they have conducted a contextual attack targeting navigational information received at the ECDIS. Moreover, we relied on the ATT&CK framework [34] to describe the conducted attack techniques in the attack scenarios. The ATT&CK framework was chosen due to its comprehensive threat model in describing adversarial behavior.

3. Methodology

This paper focuses on the detection of anomalies in NMEA messages that can be caused by malicious actors. Figure 1 depicts the proposed meta-model of the NMEA anomaly detection system. Several NMEA message types support several navigational functions. Each message consists of several fields, each holding specific information. Attackers conduct attack procedures to impact navigational functions by targeting message types or fields. Defenders implement detection algorithms to protect the navigational functions by monitoring message types and fields to detect attack procedures. The meta-model is general in nature; as such, it is relevant to any use case that utilizes sensor data communicated in NMEA messages for navigational functions.

We propose a method for systematic and multidimensional anomaly analysis of NMEA messages toward the development of an NMEA-focused anomaly detection solution. Anomaly analysis, as defined in the data quality domain, is a process for analyzing the values in a data set empirically, looking for unexpected behavior [35]. In this process, NMEA messages are analyzed for identifying possible anomalies, their impact, and ways in which they can be invoked and detected. A detailed description of the proposed method is provided hereafter:

3.1. Step 1—Navigational Functions (i.e., Tasks)

The identification of the navigational functions which rely on NMEA messages. These functions are defined for an INS by the IMO and for autonomous ships by classification societies describing the different tasks to be carried by marine systems or personnel such as route monitoring, collision avoidance, engine monitoring and control, and others. This information can later be utilized in risk analysis and, specifically, impact assessment.

3.2. Step 2—Message Types

The identification of targeted message types, and categorizing them according to relevant attributes such as their navigational functions (e.g., engine monitoring) and source (e.g., engine). This step specifies the scope of the analyzed messages and is expected to be system-dependent, since each system supports a specific list of messages.

3.3. Step 3—Message Fields

The identification of relevant message fields, the identification of the type of information they hold (e.g., speed, heading, etc.), and the format of each field. The type of information is useful for the identification of related message fields within the same message and across different message types. The information is useful for both attack and detection activities. A sophisticated attacker is expected to reflect a completely modified view, while the defender can detect anomalies by observing relevant fields for inconsistencies. On the other hand, the format and other aspects such as the range of each field are useful for the development of anomaly detection methods.

Steps 2 and 3 rely heavily on the format of the analyzed messages. The format of an NMEA-0183 message is depicted in Figure 2. After the starting delimiter ($), a 2-letter NMEA talker ID (e.g., GP for GPS) is attached to a 3-letter message ID specifying the message type (e.g., DTM, RMC, etc.). Then, each NMEA message has several fields, each corresponding to a certain piece of information, such as time, longitude, Speed Over Ground (SOG) etc. Then, a 2-digit in hexadecimal format that represents the calculated sentence checksum is separated from the last field value using the checksum delimiter (*). Finally, a carriage return and a line feed specify the end of each message.

3.4. Step 4—Anomalies

The identification of anomalous patterns (e.g., unusual values and events) that may appear during operations. During this step, all messages within the scope and their fields are analyzed to identify anomalous patterns based on some categorization of anomalies.

3.5. Step 5—Attack Techniques

The identification of attack techniques that can be carried out to invoke anomalous patterns in the selected message types and their message fields.

3.6. Step 6—Detection Algorithms

The identification of suitable detection algorithms for detecting anomalous patterns caused by attack techniques carried against NMEA messages. This step is tightly coupled with the previous step as the detection algorithm is continuously challenged and enhanced with improved attack techniques until a sufficient efficiency level is achieved.

4. Systematic NMEA Analysis Considering APS and INS Use Cases

In this section, we discuss the activities, artifacts, and results of our proposed NMEA analysis approach presented in Section 3, considering both the INS and the APS use cases. This is aimed to demonstrate the utility of the proposed anomaly analysis process in addition to the development of a suitable anomaly detection solution.

4.1. Step 1—Navigational Tasks and Functions

The tasks and functions for the INS and APS use cases were identified. The tasks of the INS were defined in the Resolution MSC.252(83) "Adoption of the revised performance standards for Integrated Navigation System (INS)" by the IMO [36]. On the other hand, the functions for the APS are defined by Amro et al. [37].

4.1.1. Navigational Tasks of the INS

The concept of the INS was developed to enhance the safe navigation of vessels with integrated and augmented functions. The INS consists of six navigational tasks [36], as follows:

• Route Monitoring (INS-RM): continuous monitoring of the own vessel as per the planned route [38].

• Route planning (INS-RP): capability of route planning (e.g., store and load, import, export, documentation), route checking based on minimum under keel clearance, drafting and refining the route plan against meteorological information [36].

• Collision Avoidance (INS-CA): detecting and plotting other ships and objects in the vicinity in order to prevent collisions [38].

• Navigation Control Data (INS-NCD): providing data to the task station for the manual and automatic control of the ship [38].

• Navigational Status and Data Display (INS-NSDD): displaying several information (e.g., AIS data, Maritime Safety Information (MSI) messages, INS configuration), and providing management functions [36].

• Alert management (INS-AM): centralized alert management on the bridge for the monitoring, handling, distribution, and presentation [38].

The INS facilitates the performing of the aforementioned navigational tasks. The tasks of "route monitoring" and "collision avoidance" are mandatory as per the IMO's regulations [38]. Moreover, the requirements of "presentation of navigation control data for manual control" of the navigation control data task and "Module C" of the alert management task should be fulfilled [36]. Given that the lack of some navigational tasks and requirements in the INS may increase risks in the safe navigation of the vessel, they are classified as mandatory by the IMO. For instance, while "collision avoidance" and "route monitoring" are mandatory navigational tasks for an INS, the "route planning" and "navigational status and data display" are left optional by the IMO [36]. In the next step, the relevant NMEA messages to each navigational task is identified. Such a matching enables us to understand the risk level of potential NMEA anomalies by considering mandatory and optional navigational tasks defined by the IMO.

4.1.2. The Functions of the APS

There exists no regulatory framework or globally accepted guidelines that define the functions of an APS. Nevertheless, in our previous work [37], we have compiled a group of expected APS functions based on a group of relevant works including the work of Rødseth et al. [39] in the "Maritime Unmanned Navigation through Intelligence in Networks (MUNIN)" project as well as class guidelines for autonomous and remotely operated vessels by DNV [40]. A brief summary of the expected APS functions is discussed below (refer to [37] for more details):

• Engine Monitoring and Control functions: the monitoring and control of APS engine. They can be conducted by the APS itself (APS-AEMC), a Remote Control Center (RCC) (APS-REMC), or an Emergency Control Team (ECT) (APS-EEMC).

• Navigation Functions: establishing situational awareness. They can be conducted by the APS itself based on the sensor data (APS-AN), at the RCC based on the sensor data transmitted from the APS (APS-RN), or by the ECT based on the sensor data transmitted from the APS (APS-EN).

Impacting these functions through cyber attacks could cause safety, financial, and operational consequences according to a previously conducted risk assessment [41].

4.2. Step 2—Message Types

There are many NMEA messages (i.e., sentences) defined in the IEC 61162-1 standard [42]. In this paper, we will restrict our analysis on the NMEA messages broadcasted by the Bridge Command simulator (https://www.bridgecommand.co.uk/ (accessed on 16 February 2022)) in order to evaluate the proposed analysis process. The messages were investigated using the guideline of the IEC 61162-1 standard [42] which is compatible with NMEA 0183. The messages in addition to their descriptions are shown in Table 1.

After identifying the targeted NMEA messages for analysis, their involvement in the navigational functions is analyzed. This analysis can reflect the impacted navigational function for each NMEA message that is a subject of an attack. Table 2 depicts the identified relevance between messages and the APS and INS functions. A message is considered relevant to a function if it provides a piece of information that influences performing the function. For instance, the APS-AN function relies on the location information (i.e., coordinates) communicated in either one of the GGA, GLL, or RMC messages for route planning. Regarding the INS use case, the targeted NMEA messages are involved in all the INS functions except "Alert Management" using Resolution MSC.252(83) [36]. On the other hand, as the APS use case is in its early development stages, we considered the possible involvement of each message in the APS navigational functions based on the designs and concepts communicated in the literature. Our analysis suggests that all considered messages are expected to be involved in the navigation functions except for the RPM messages, which are expected to be involved in the engine monitoring and control functions.

4.3. Step 3—Message Fields

During this step of our analysis, we have analyzed the fields of all the messages identified during step 2 (Section 4.2). The goal of this analysis is to understand the utility, and format of the piece of information depicted in each field. This understanding facilitates the activities to be conducted in the upcoming steps. Furthermore, the related NMEA messages are identified and depicted in Table A1 in Appendix B. Two messages are considered to be correlated if a change in information contained in one message that occurs under normal circumstances, will (direct effect) or might (indirect effect) change information in the other message. An example of an indirect effect can be observed in the relation between the RMC and RPM messages: changes in the Speed over Ground (SOG) in the RMC message might reflect different engine speed which is captured in the revolutions per minute field within the RPM message. On the other hand, an example of a direct effect has been observed in the location information (i.e., longitude and latitude) that is communicated in three messages, namely, GGA, GLL, and RMC. If any value changes in any message, it should be reflected in the other messages. Such information is valuable for both attack and detection activities.

4.4. Step 4—Anomalous Patterns

In this step, the possible anomalies that can be observed in NMEA messages are identified. Iphar et al. [28] proposed 13 possible anomalous patterns in AIS messages, that follow the same standard as NMEA with some differences in the message format as well as in content. However, they have the same abstraction of message types, each consisting of several message fields. In this paper, we adopt the relevant anomalies and neglect those that are not relevant to NMEA messages. Seven main anomalous patterns have been identified; these, along with brief descriptions are shown in Table 3.

We have analyzed all the aforementioned anomalies against all message types and their corresponding fields and recorded our results for the next steps. Some examples of the identified anomalies are presented in Table 4 while a list of all the identified anomalies is provided in Table A2 in Appendix C.

4.5. Step 5—Attack Techniques

In this section, we discuss the activities performed during the fifth step in the analysis concerning attack techniques that are expected to invoke one or several of the anomalies identified during step 4. In this direction, we propose the application of the ATT&CK framework [34] for threat modeling due to its comprehensive nature and suitable level of abstraction [41]. However, other threat modeling methods can still be applied if they propose attack techniques that can be technically achieved. The threat modeling approach considers both simple attacks as well as sophisticated attacks. Lokman et al. [31] discussed several attack types against the CAN bus, namely, packet insertion, erasure, reply, and payload modification. In the ATT&CK framework, insertion, reply, and payload modification may fall under the Manipulation of View (MoV) attack technique [43] while packet erasure may fall under Denial of View (DoV) attack technique [44]. A brief description of each technique is provided below:

• DoV attacks entail denying the seafarers or the depending systems the ability to render a live perception of the physical environment. This is achieved by dropping one or several NMEA messages to hinder the relevant navigational functions.

• MoV attacks entail the modification of the live perception of the physical environment. This can be done in several ways:

• Fixed: the attacker modifies the values in original NMEA messages to specific fixed values. For example, no matter what is the real speed reflects another fixed speed value. This emulates a simple threat actor using simple Man-in-the-Middle (MitM) attack rules (i.e., filters).

• Context attacks: the attacker manipulates the messages based on the values observed in the original messages to create a gradual change. This emulates a more advanced threat actor using more sophisticated MitM attack rules. Avoiding detection is among the attacker's objectives.

• Confusion attacks: the attacker sends crafted or repeated messages in addition to the original messages.

• Replay attacks: the attacker replays a fixed set of messages instead of the original stream of messages.

We have analyzed the anomalies and the possible attacks that can invoke them. A mapping between an anomaly and an attack is identified if the attack, based on its definition, may result in invoking the anomaly. The identified relations are depicted in Table 5. The table can be read as follows: a DoV attack is expected to only invoke an "Under Reporting" anomaly, while a confusion MoV attack is expected to invoke all possible anomalies except "Under Reporting".

To realize such attack techniques, we have developed a system called NMEA-Manipulator to facilitate the process of invoking the identified NMEA anomalies. NMEA-Manipulator intercepts and controls the flow of NMEA messages following a set of rules (detailed description in Section 5.1).

4.6. Step 6—Detection Algorithms

Lokman et al. [31] discussed several detection algorithms for detecting attacks against CAN bus messages. Three main detection approaches have been observed in the literature, signature-based, anomaly-based detection, and specification-based. A brief description of each approach is provided below in addition to our rationale for its utility in our analysis:

• Signature-based detection refers to the utilization of a specific signature or event for the detection of a specific malicious activity [45]. This would require documented attacks against NMEA messages to generate suitable signatures.

• Anomaly-based detection refers to the observing of real-time activities in a system and comparing them to normal behavior and raising an alarm when a deviation of normal behavior is observed [46]. This approach includes machine learning, frequency, statistical, and hybrid-based approaches. We argue that the machine learning and statistical approaches require a large set of data to effectively train robust models and, consequently, they are currently not viable options in our case. We have reached this conclusion after experimenting with a one-class support vector machine, and decision trees for detecting anomalies. The model evaluation has reflected poor performance mostly associated with the limited size of the data set. Since there exists no publicly available data set for the NMEA messages in the scope of our analysis, we have not pursued machine learning and statistical based approaches any further. On the other hand, frequency-based detection, considering message arrival frequency, was found relevant and is further considered for evaluation.

• Specification-based detection refers to the application of suitable thresholds and rules for describing the well-known behavior of a component [47]. We argue that this approach is the most suitable in the scope of our analysis because it does not require a large amount of data for learning. Moreover, considering the dynamic, yet predictable nature of NMEA messages, their behavior might be confined within a set of rules and thresholds (i.e., specifications). We have identified several categories of specifications, namely, physical, system, protocol, and environment specifications. A brief description of each category is provided below:

• Physical specifications restrict the manner in which the values change over time among consecutive messages (e.g., maximum change in distance). This is related to the physical environment the NMEA messages are intended to reflect.

• System specifications restrict the values in the NMEA fields and their evolution over time for each system (e.g., maximum engine rpm, SOG acceleration, etc.). This needs to be defined for each target system.

• Protocol specifications restrict the format of the NMEA messages and their fields (e.g., UTC format in the UTC field of GGA, GGL, and RMC). This needs to be defined for each target protocol; in our analysis, NMEA0183 is utilized.

• Environment specifications restrict a range of values that are related to the operational environment. This includes time, date, longitude, latitude, datum code, and others.

We have analyzed the identified anomalies by considering the expected useful detection methods. A mapping between an anomaly and a detection method is identified if the anomaly can violate a certain specification or threshold in the corresponding detection method, based on their definitions. For instance, a sudden unexpected change in any field value, within the predefined format and range, does not violate the protocol specification of that field. Furthermore, changing the field values alone is not expected to change the frequency of message arrival. Therefore, protocol specifications and frequency-based detection are not expected to be useful for detecting this type of anomaly. However, a sudden change in certain fields related to system, physical or environmental parameters such as speed, time, and distance, would violate the corresponding specifications. Table 6 depicts the results of our analysis. Our analysis suggests that frequency-based anomaly detection might only be suitable for under and over reporting anomalies. On the other hand, the specification-based approach can be used for the remaining anomaly types, using different specification categories.

In the sequel, we analyze the different detection methods against the messages and their fields to identify the required specification rules for detection.

5. Data Generation and Preparation

In this section, we present the results of our experiments throughout our analysis in order to evaluate its usefulness in the development of an intrusion detection solution. Initially we generated data, prepared it, and enriched it to facilitate the analysis. Afterwards we utilized the generated data for the identification of candidate specifications and rules for detecting anomalies. The activities in this process have been conducted using our developed maritime-themed cybersecurity testbed, which we proposed and presented in our earlier work [48]. The testbed includes several components that support the development of the anomaly detection solution.

5.1. Data Generation

The data generation process is facilitated by the availability of a simulator software or a device that generates NMEA messages. There are several NMEA simulator software, such as BridgeCommand simulator (https://www.bridgecommand.co.uk/) and NMEA simulator (https://github.com/panaaj/nmeasimulator). The BridgeCommand simulator software was utilized in this paper since it allows for customized scenarios. The customization includes the navigational area, ship class, weather, time, and options for the included technologies on board.

Additionally, the data generation process is supported by capabilities for conducting various attack scenarios in order to invoke the different analyzed anomalies. For this reason, we have developed a system called NMEA-Manipulator. Similar to the previously proposed BRAT assessment tool [24] NMEA-Manipulator enables conducting a wide range of attacks against NMEA traffic. However, the main design goal of it is not to assess the security of marine systems, rather to facilitate the analysis of NMEA anomalies toward the development of intrusion detection systems. NMEA-Manipulator is utilized in two steps, namely, step 5 of the NMEA anomaly analysis process to observe the impact of the suggested attack techniques, and it is utilized as well in the data generation step for evaluating the different detection algorithms. An overview of NMEA-Manipulator is depicted in Figure 3.

The NMEA-Manipulator must be hosted in a device that is connected to the same LAN that connects the original NMEA speaker and listener. Furthermore, the NMEA-Manipulator requires two additional Non-Developmental Items (NDI), namely, a MitM tool such as Ettercap and a network sniffer tool such as tshark. The MitM tool provides the ability to access and control the LAN traffic, while the sniffer tool allows the recording of the original NMEA messages into an NMEA Messages File (NMF). Additionally, NMEA-Manipulator requires attack rules to govern its behavior. The attack rules are inserted into an Attack Rules File (ARF). The ARF contains multiple lines, each corresponding to a certain attack scenario (i.e., invoked anomaly). The attack rules command the NMEA-Manipulator to perform one or more of the attack techniques discussed in Section 4.5.

The NMEA-Manipulator includes six main subcomponents (i.e., modules), a parser, a session detector, a modifier and dropper, an inserter, a sender, and a reporter. The parser reads the NMEA messages from the NMF and invokes the modifier and dropper in case a new message is observed. The modifier and dropper then apply the activated attack rules specified in the ARF while the inserter applies the activated insertion attack rules as well as the replay and confusion attacks. The session detector identifies the IP address of the NMEA listener from the sniffed traffic and forwards it to the sender which sends the modified and inserted messages to the listener. Finally, the reporter generates a log file regarding the activated, deactivated, and modified attack rules to facilitate the later steps of the analysis.

In this direction, we utilized NMEA-Manipulator during the data generation process by conducting three experiments. Each experiment consists of several attack scenarios running in conjunction with a normal navigational scenario. The attack scenarios were chosen to be comprehensive so that they invoke a wide range of the identified anomalies. All the exercises included a normal navigational scenario which is following a predefined path in an area near the UK using a large ship equipped with a RADAR and a GPS. A brief summary of the conducted experiments is presented below:

1. A combination of different MoV attacks, namely, fixed and context attacks was conducted in an attempt to invoke five anomalies, namely sudden unexpected change, nonexistent value, unexpected value, incorrect value, and data field evolution. The attack scenarios targeted several messages and message fields such as going back in time 1 day by changing UTC fields in GGA and GLL messages. Another example is increasing the distance of RADAR targets as well as other fields in the TTM message, to create a collision scenario.

2. Several MoV context attacks and DoV attacks were conducted to invoke data field evolution and under reporting anomalies, respectively.

3. A combination of different MoV attacks was conducted, namely fixed, confusion and replay attacks. The goal is to invoke several anomalies, including conformity issues and over reporting.

More details regarding the conducted experiments can be found in Table A3 in Appendix D.

The testing environment used to realize the different scenarios is depicted in Figure 4. The ship view is produced using the bridge command simulator, which is utilized as the NMEA sender. The simulator includes a simulated GPS device sending NMEA messages over UDP to the listener. On the other hand, the chart plotter view is produced by the OpenCPN chart plotter software, which is utilized as the NMEA listener. Moreover, the Wireshark software [49] is utilized for capturing the network traffic at the receiving node. The attacker node operates the Kali Linux operating system with the NMEA-Manipulator system.

Two artifacts are generated from each experiment, an experiment log and a packet capture of the traffic arriving at the NMEA receiver. The log is utilized to facilitate the labeling of NMEA messages (e.g., attacked or normal) and to support traceability of the events occurred during the experiments. The packet capture on the other hand is utilized for later steps in evaluating the different anomaly detection methods. Finally, additional experiments were conducted to capture NMEA messages in normal operations to aid the efforts in the identification of suitable specifications and rules for detecting anomalies.

In these experiments, only the NMEA sender and receiver were operational while the attacker node was kept idle.

5.2. Preparation and Enrichment of Data

The captured network traffic from the conducted experiments was utilized as input in this step. Tshark, the command-line interface of Wireshark, was utilized for extracting the NMEA messages with the associated time of observation of each message. The time information is needed since some NMEA messages do not contain such information. Then, data cleaning is conducted to fix some issues in the messages such as splitting concatenated messages and removing carriage return characters. Afterwards, the messages with the timing information are transformed into feature vectors. Moreover, the messages are labeled as "Normal" or "Attack" by referring to the experiment documentation. For instance, during the different experiments, some NMEA message types were not targets of attacks, which leads to a "Normal" classification of such messages and an "Attack" classification of the targeted message types during the period of activity of the attack rules. Additional fields are added for the enrichment of the captured data, such as distance from the last position, rate of message arrival etc. This is intended to facilitate the analysis of the specifications and anomalies. Finally, the output feature vectors with the headers and labels are exported into Comma-Separated Value (CSV) format. Due to different features for each NMEA message type, it has been deemed necessary to evaluate the specifications for each type separately. For this reason, the output from the previous step is a group of CSV files, one for each message type. Each file holds all the messages of a single message type that were generated in a single experiment. All activities performed during this stage except for the manual labeling of some feature vectors are automated using python scripts.

6. Evaluation and Discussion

We have analyzed the generated and processed data to evaluate the proposed detection approaches. A selected group of results is highlighted hereafter.

6.1. Specification-Based Detection

The results of the evaluation of the different proposed specification-based detection categories are presented in this section, namely, environment, physical, system, and protocol specifications.

6.1.1. Protocol Specifications

The approach is implemented through a validation process for each message to check the compliance of its fields with the protocol specifications. Considering the known structure and format for each message type, this approach can detect conformity issues with high confidence. For instance, an attack scenario was carried during experiment 3 (Table A3) to manipulate the view regarding the number of satellites that may be utilized for position fixing. The attack is carried by modifying the original expected integer value with the character "x". The impact of the attack was observed on the chart plotter software as the indicator of the number of satellites was changed to red, reflecting a bad signal, however, the true value was 13. A detection rule for this attack is implemented to check if the field format is in compliance or not and the results reflect correct detection.

6.1.2. Environment Specifications

The evaluation of this approach is not implemented, rather it is conceptually evaluated in the section. This is due to the rationale that such category of specification relies on true sources for reference information, such as correct time and datum code for coordinate ranges. The utilized simulator relies on static scenario definition files. The time of each simulation experiment is manually defined. Relying on the true system time to detect inconsistency generates false positives. Therefore, we argue that in a live implementation, if the ship systems receive time information from a source other than GPS signals, detecting any modifications of the time information is straightforward.

6.1.3. System Specifications

This category of specifications is encoded in a file for each ship to host the anomaly detection solution. This file dictates to the detection software the specifications for the different systems on board to identify anomalies due to the existence of values that are not supposed to be observed in the host system.

Figure 5 depicts a visualization of the anomaly type "Non existent value" that is invoked by an MoV attack during experiment 1 (Table A3). The figure reflects two observations, the left part reflects detection of the RSA message of a sensor reading receiving from a port rudder sensor. However, the specification file of the simulated system dictates that it only has a starboard rudder sensor, which means a single rudder sensor. On the right part of the figure, a similar anomaly is detected in the RPM message when observing a new shaft (i.e., source number 4) that is not within the system specifications which is only having two shafts (i.e., source numbers 1 and 2). These two anomalies and similar ones are detected with high confidence due to the static nature of systems in ships. Furthermore, anomalies due to sudden changes can be detected using system specifications. For instance, the possible changes in the revolutions per minute (rpm) in the RPM message in one of the ship models in the simulator is in the range (25 to 2000 rpm) while the range for another model is (1 to 100). Detection rules for each one is formulated to detect any rpm changes outside the appropriate range. These rules will return anomalies with high confidence. However, if the attackers maintained a change in the rpm values that is within the system specifications, their actions will not be detected using this approach based on the rpm value as a feature. Other anomalies that can be detected using this approach are unexpected values and data field evolution. An example of an unexpected value can be observed in the rate of turn (ROT) value in the ROT message. Each ship has a certain expected limit within which the ship can turn in a minute. For instance, the difference in ROT value between two consecutive messages in one ship model in the simulator can change within the range (-100 to 100). An attack during experiment 2 demonstrates this effect by increasing the ROT value by a hundred while the true difference was 11.2, leading to a total difference of 111.2 which allowed the identification of the anomaly. However, similarly to the previous anomaly, an attacker can stay undetected if the resulted change is within the system specifications.

6.1.4. Physical Specifications

We will demonstrate the utility and identified challenges in this approach in a selected group of messages, namely, RMC, RPM, and HDT, for detecting sudden unexpected change and data field evolution anomalies. An example of a sudden unexpected change can be invoked through an MoV attack to reflect a position change in a strange manner. A demonstration of this was carried out during experiment 1 (Table A3). The impact of this attack can be observed clearly when visualizing the difference between each two consecutive latitude and longitude values, as depicted in Figure 6.

A data field evolution type of anomaly can be invoked through gradually changing the SOG and Course Over Ground (COG) fields in the RMC message to reflect a different speed and heading details. An example of this attack is demonstrated during experiment 2 (Table A3). The SOG and COG values under normal conditions change in a specific manner. The SOG value between two consecutive RMC messages cannot physically change outside a certain range. Still, a visualization of a data field anomaly is depicted in Figure 7a. This anomaly can be detected by defining a rule specifying the range in which the SOG can change over a certain period of time. Then, any change outside this rule would suggest an anomaly with high confidence. Figure 7b depicts the manner in which the difference between consecutive SOG values behaves under normal and attack conditions. The impact of the attack is clearly visible and can be deduced from the figure. The behavior of the attacker can be described as reducing the SOG value by 1 several times in some time frame then returning the value to its normal value, which leads to a sudden increase. Similarly, the COG is not expected under normal conditions to have large differences between consecutive messages except if the value is reaching the limits in the range (-360 to 360); only then a large change is normal. In this paper, the threshold for a normal difference was determined based on the largest calculated difference in value between the same field in two consecutive messages in the normal recorded traffic. The determination of a more accurate threshold would require a larger data set of NMEA messages from real systems.

We have mentioned previously that we are considering simple and advanced threat actors. For this reason, we have proposed the process of identifying the relevant NMEA messages and fields during step 3 (Section 3.3). If attackers crafted messages with differences within the normal range, correlating the relevant fields in other messages can be utilized to increase the confidence in the detection. A correlation between the COG field in the RMC message and the heading in the degrees field in the HDT message can provide evidence of anomalies in both messages under the condition that only one of them is subject to attack at a certain time. Figure 8a,b look very similar; this depicts the direct correlation between the two fields in two different messages. To evaluate the ability of detection based on the correlation of message fields, two attack scenarios were conducted at different times during experiment 2 (Table A3). One attack targeted the COG field by gradually increasing the COG value several times over a period of time and later returning it to normal value. The effect of this attack can be observed in Figure 8c. During the same time frame, the differences in the heading field do not reflect similar behavior; this is strong indication of an anomaly. Similarly, the other attack targeted the heading field in the HDT, causing a similar effect which is observed in Figure 8d. This also can provide strong indication of an anomaly. Notably, minor delay is sometimes observed before the COG and heading values match each other. Accommodating this constitutes a challenge for the detection algorithm and will be considered in future work.

6.2. Frequency-Based Detection

This category of specifications is solely suggested for detecting over and under reporting anomalies. The rationale behind it is that under normal conditions NMEA messages of each type have a specific amount of messages or packets arriving at the target system in a specific period. We refer to this metric as arrival rate. DoV attacks will drop some or all messages; this will lead to a decrease in the arrival rate which suggests under reporting. Furthermore, replay MoV attacks during which attackers replay messages at a reduced Transmission Rate (TR) will also cause an under reporting anomaly. On the other hand, if attackers increased the transmission rate to go beyond normal, the arrival rate will increase, which suggests over reporting. Similarly, confusion MoV can cause over or under reporting based on the transmission rate controlled by the attacker. To evaluate the proposed detection for these anomalies, we utilize Wireshark to graph the number of packets per second in the recorded traffic of the relevant experiments.

The traffic contains one NMEA message per packet except for RPM messages; each pair is joined in one packet. Figure 9a,b depict the arrival rate for the recorded traffic in experiments 2 and 3 (Table A3), respectively. The impact of the DoV attacks is clearly visible in Figure 9a. During this attack, all messages were dropped, resumed, then dropped again. The third visible drop in the graph is due to the switching from the traffic generated through the NMEA-Manipulator and normal traffic. Figure 9b depicts the arrival rate during different attacks with different employed TRs. After starting with normal traffic, NMEA-Manipulator controlled the traffic and applied several fixed MoV attacks, which had a limited impact on the arrival rate. Then, a confusion MoV attack started by sending pre-recorded normal messages at TR of 1 message every 0.5 s in addition to the normal traffic. After that, the transmission rate was increased to send 1 message every 0.1 s using alternately recorded normal messages and recorded forged messages. Finally, the transmission rate was increased to 1 message every 0.05 s, similar to the last iteration, by using normal and forged recorded messages. The impact of confusion and replay attacks using different TR is clearly visible in Figure 9b as their arrival rate deviates in a clear manner from the normal arrival rate. However, if attackers targeted only a few message types, considering the arrival rate for the entire traffic might miss the targeted attack. Therefore, we propose that a dedicated arrival rate for each message type be monitored separately. This is particularly suitable in real ship systems in which different NMEA messages have different arrival rates. In order to avoid detection using frequency-based detection, attackers need to appropriately adjust the TR during their attacks, which complicates their task.

6.3. Communication of Risk Associated with Detection

Our proposed analysis aims to develop an anomaly detection solution that is enriched with the operational context of the NMEA messages that are associated with the different functions. When an anomaly is detected using the different detection mechanisms for a specific message or a group of messages, the impacted functions are known. Consequently, the multi-tier communication of the risk from the technical level to the operational level is facilitated. An example of this is as follows: if the anomaly depicted in Figure 8d against the HDT message is detected, the following is known:

• An inconsistency is identified by a physical-based specification concerning the heading information in HDT messages; this is due to steps 6 and 3. In step 3 the heading field was designated for identifying relevant anomalies, attacks, and detection methods. In step 6 the detection methods for the heading field were proposed.

• The anomalous messages are arriving from the gyro compass; this is known through the TalkerID identified in step 2.

• This might indicate a data field evolution anomaly; identified in step 4.

• This might be a result of a MoV attack; the relationship between the anomaly and the attack that possibly causes it is identified in step 5 (see Table 5).

• This could impact the Route Monitoring, Navigation control data and Navigational status and data display functions in the INS which might cause safety, financial and reputation loss and environmental damage; the relationships between the targeted message and the relevant functions are identified in step 1 (see Table 2).

6.4. Identified Limitations

The experiments have highlighted some possible limitations in the different anomaly detection approaches. A summary of the identified limitations is provided below:

• False positives: weakly configured specifications can generate false positive alerts. For instance, a system specification for one simulated ship is a range for RPM change of 100 between two consecutive RPM messages. Using the same specification in another ship with a different RPM change range would generate a false positive. Therefore, it is highly encouraged to fine-tune the system specifications for each target system. Another aspect to consider is the sensor error or noise. A noise in the sensor might invoke an anomaly and a false indication of malicious behavior. An instance of this issue has been observed in one of the experiments. A glitch in the simulator caused the speed of the vessel to abnormally change due to low water depth. An anomaly in the data is observed which is not caused by malicious behavior. These issues need to be considered during the development of the anomaly detection system.

• False negatives: malicious behavior operating within the thresholds defined in the specifications will not be detected but still can cause an impact. For instance, reducing the RPM value by 50 while the change threshold is 100 will not generate an alert, but, the speed value will appear less than what is expected, this can cause a speed increase command which in turn can cause an issue in safe navigation.

Moreover, other limitations in our analysis are mentioned hereafter:

• The number of analyzed messages is limited to those supported by the available simulator. Still, four message types, namely, GLL, RMC, GGA, ZDA are among the top 10 NMEA messages observed on the internet during a scan in Shodan [50]. Future work should focus on more message types.

• Our analysis included only NMEA0183. Other protocols are being integrated into the maritime systems including NMEA2000 [6] and OneNet [51]. Yet, NMEA0183 is still utilized in the maritime industry as observed in the literature and the internet-wide Shodan scan [50].

• Our analysis only considers attacks with objectives to impact navigational tasks by denying and manipulating the view that is rendered using the NMEA messages. Other attack techniques that can cause anomalies can be investigated in future work.

• We utilized the ATT&CK framework for the threat modeling. Using other threat modeling techniques might identify other attacks. Still, our considered attacks are in line with the attacks discussed in the literature.

• We utilized certain categories of anomalies during our analysis based on the observed anomalies in the literature. Other anomalies can exist. If new anomalies are identified in the future, this would require another iteration of the analysis process to consider relevant messages, fields, attacks, and detection methods.

7. Deployment Options

Lokman et al. [31] discussed the observed deployment strategies of IDS for CAN bus. It has been observed that CAN bus IDSs are placed either in the central or end nodes or within the CAN network. NMEA IDSs are expected to have the same options. However, the choice of placement is sensitive to the use case. Still, we discuss here the possible placement of NMEA IDSs in marine systems. Two main categories of IDS are observed in the literature, namely Host-based IDS (HIDS) and Network-based IDS (NIDS). Jacq et al. [52] have discussed the concept of situational awareness in naval systems and indicated the challenge in the application of HIDS due to possible warranty disruptions. On the other hand, NIDS is a more suitable deployment option, as it can be added to the networks for monitoring NMEA traffic and detecting anomalies. However, we argue that if attackers are able to target the ship network and successfully carry the attacks presented in this paper, NIDS might also be targeted using similar attack techniques, to avoid detection. Therefore, we argue that the optimal implementation can be achieved through the integration of the anomaly detection solution within the NMEA receiver node, as part of the software that consumes NMEA messages. Still, considering that this solution would allow real-time anomaly detection, a performance evaluation is crucial to validate that the solution does not hinder the navigation functions. Future work can target a proof-of-concept implementation through the development of an NMEA IDS and integrate it with the OpenCPN software.

8. Conclusions

The ongoing digitization in maritime is leading to new operational modes. The shipping operations are being gradually transferred to remote shore locations, relying on sensor data transmitted from the vessels. This mode of operation makes the shipping operations susceptible to a wide range of cyber-attacks including manipulation and denial of view, which subsequently hinders safe navigation. This paper targeted the detection of anomalies in NMEA messages caused by malicious actors. NMEA messages carry information that is crucial for several navigational functions, such as collision avoidance. The consequences of targeting them in cyber attacks could cause safety, operational and financial consequences.

Initially, a systematic analysis of NMEA messages was proposed. The analysis aims to identify anomalies in NMEA messages, their cause, and possible detection methods. Afterwards, several of the identified anomalies were invoked using some of the identified attacks in a testing environment against a group of simulated NMEA messages. Then the identified detection methods were evaluated.

Our analysis suggests relevant NMEA messages and fields which have demonstrated utility for detecting inconsistencies. Moreover, the systematic analysis provides a multi-tier overview of the risks associated with the detected anomalies. When an anomaly is detected at the technical tier, technical-level information can be induced, such as source device, candidate attack technique, and relevant messages for investigation. Furthermore, risk information is utilized at the operational or mission tier regarding the possible risk of the detected anomaly against the relevant functions. The employed attack techniques reflect several possible threat actors with varying degrees of complexity; this constitutes a good coverage of possible threats against the NMEA messages within scope. Other attack techniques to achieve other objectives than impacting the navigational functions will be considered in future work.

Specification-based and frequency-based detection has been demonstrated to provide detection capability using different approaches. Protocol specifications can provide a confident indication of conformity issues in the NMEA messages. Furthermore, system specifications can provide a confident indication of system-specific anomalies related to some values and events that are not expected in a specific system. However, the efficiency of this approach relies on the strength of the defined specifications for each host system. Advanced attacks can still avoid detection. Additionally, physical specifications can provide indicators of anomalies, yet they require careful development of the specifications. We have demonstrated the utility of identifying relationships among some NMEA messages and their fields in the identification of data field evolution anomalies. The relationships can provide strong indications of anomalous patterns. Still, a comprehensive analysis of all the identified relationships is required to generalize the findings. Moreover, frequency-based detection can provide a strong indication of over and under reporting anomalies. However, advanced attackers can avoid detection by maintaining a transmission rate that is consistent with normal traffic.

Future work can utilize the results of our analysis to develop, implement, and evaluate an NMEA anomaly detection solution that is suitable for deployment onboard vessels. Furthermore, another direction could utilize a variation of our testing environment by including other NMEA simulators or a physical NMEA source (e.g., GPS or AIS); this would include other NMEA messages and fields. Additionally, this paper targeted attack techniques that can cause an impact on navigational functions. Future work can explore different attack techniques that do not aim to impact the navigational functions and can still invoke anomalies such as ex-filtration or command and control. Moreover, we have identified a possible application of machine learning techniques in NMEA anomaly detection. Yet, the limited amount of data was a challenge that can be targeted in future work. Finally, another direction for future work can be the extraction of physical and system specifications from a large amount of NMEA messages recorded in several systems, to improve the specification rules.

References

Full reference list (52 sources) available in the original PDF.