أدى التحول الرقمي المتسارع في الصناعة البحرية، مدفوعًا بالاعتماد الواسع النطاق لأجهزة إنترنت الأشياء (IoT)، وأنظمة السفن المتكاملة، وعمليات الموانئ الآلية، إلى توسيع كبير في سطح الهجمات السيبرانية، مما جعلها عرضة بشكل متزايد للتهديدات المتطورة. تبحث هذه الدراسة في تطبيق الاستخبارات مفتوحة المصدر (OSINT) كمنهجية استباقية وقابلة للتطوير وفعالة من حيث التكلفة لتعزيز الأمن السيبراني البحري. نقدم إطارًا بحريًا متخصصًا للاستخبارات مفتوحة المصدر، يتألف من سير عمل منهجي من خمس مراحل (التحديد، الجمع، المعالجة، التحليل، النشر) مصمم خصيصًا ليناسب المشهد التشغيلي والتهديدات الفريدة للقطاع. يدعم الإطار تصنيف شامل للتهديدات السيبرانية البحرية ومجموعة أدوات منتقاة تضم أكثر من 100 مصدر استخباراتي مفتوح، تغطي تتبع السفن، والاستخبارات المؤسسية، والاستطلاع الرقمي، والمنصات التحليلية. من خلال دراسات حالة تطبيقية، نوضح كيف يمكن لهذا النهج تحديد الثغرات الأمنية الحرجة مثل كشف التكنولوجيا التشغيلية المكشوفة، وضعف روابط سلسلة التوريد البرمجية، والمخاطر البشرية المستمدة من البيانات المتاحة للعموم. تؤكد نتائجنا أن الاستخبارات مفتوحة المصدر البحرية توفر طبقة استخباراتية لا غنى عنها، مما يمكن الجهات المعنية من الانتقال من الوضع الأمني التفاعلي إلى إدارة المخاطر الاستباقية من خلال الكشف المبكر عن التهديدات، وتقييم الثغرات المستنير، وتعزيز الوعي الظرفي، مع الالتزام بالمبادئ التوجيهية الأخلاقية والقانونية المقترحة لجمع الاستخبارات المسؤول.
تشهد الصناعة البحرية رقمنة سريعة وواسعة النطاق عبر جميع جوانب القطاع. على الرغم من أن هذا التكامل التكنولوجي يعد بتعزيز الإنتاجية وتبسيط العمليات، إلا أنه في الوقت نفسه يوسع سطح الهجوم. مع اعتماد أكثر من 80% من التجارة الدولية على النقل البحري [1]، من الضروري تأمين وحماية مختلف جوانب القطاع من التحديات السيبرانية. لقد زادت الهجمات السيبرانية على الصناعة البحرية بنسبة مذهلة 900% في السنوات الأخيرة [2]. ومن المنطقي تنفيذ طبقات أمنية إضافية [3].
يشمل هذا التحول الرقمي الأتمتة في الموانئ، وتكامل أجهزة إنترنت الأشياء على السفن، وإنشاء أنظمة لوجستية مترابطة. لسوء الحظ، غالبًا ما تقدم السفينة الواحدة بيئة أمنية معقدة، حيث تعمل في وقت واحد بأحدث التقنيات جنبًا إلى جنب مع أنظمة قديمة جدًا، مما يزيد من تعقيد الامتثال للوائح المتطورة مثل توجيه شبكات وأنظمة المعلومات (NIS-2) (EU 2022/2555) [4]، الذي يفرض إدارة صارمة لمخاطر الأمن السيبراني على المشغلين البحريين، وقرار المنظمة البحرية الدولية (IMO) MSC.428(98) [5]، الذي يتطلب معالجة المخاطر السيبرانية بموجب المدونة الدولية لإدارة السلامة (ISM) [6]. تمثل المنظمات البحرية أهدافًا عالية القيمة لمختلف الجهات الفاعلة في التهديدات. غالبًا ما تكون الممارسات الأمنية الحالية تفاعلية، مما يؤكد الحاجة إلى قدرات استخباراتية استباقية، مثل الاستخبارات مفتوحة المصدر (OSINT)، لتوقع التهديدات والتخفيف من حدتها [7]، [8].
يمكن تسليح الاستخبارات مفتوحة المصدر من قبل الجهات الخبيثة لتخطيط وتنفيذ هجمات موجهة ضد الأصول البحرية من خلال استغلال البيانات نفسها المخصصة للسلامة والشفافية. من خلال التحليل المنهجي لمصادر الاستخبارات مفتوحة المصدر، يمكن للخصوم تحديد الأهداف عالية القيمة من خلال أنماط التوقف غير المبررة والشذوذ في المسار، والتي قد تشير إلى سفن تحمل شحنات حساسة أو تعمل تحت الإكراه.
على سبيل المثال، يمكن استغلال نظام التعريف الآلي (AIS)، وهو نظام تتبع قياسي يستخدم عالميًا لمراقبة مواقع السفن وطرقها وهوياتها في الوقت الفعلي، للكشف عن الفجوات المتعمدة في الإرسال أو التناقضات التي تشير إلى الانتحال. يمكن للمهاجمين تحديد السفن التي تحاول إخفاء تحركاتها، مما يجعلها عرضة للاعتراض أو القرصنة أو الهجمات السيبرانية-الفيزيائية. بالإضافة إلى ذلك، من خلال رسم أنماط المرور الأوسع داخل النقاط الاستراتيجية أو المناطق الحساسة سياسيًا، يمكن للجهات الخبيثة تحديد الأوقات والمواقع المثلى للكمائن أو عمليات التهريب أو الاختراقات السيبرانية المنسقة، مما يحول البيانات البحرية المتاحة للعموم إلى مخطط تكتيكي للتعطيل والاستغلال.
الهدف الأساسي من هذه الدراسة هو تمكين الجهات المعنية البحرية من خلال هذا الإطار المتخصص بقدرة استباقية وفعالة من حيث التكلفة للكشف المبكر عن التهديدات، وتحديد الثغرات، وتعزيز الوعي الظرفي، مما يتيح الانتقال من الوضع الأمني التفاعلي إلى إدارة المخاطر الوقائية. إلى جانب الإطار نفسه، تقدم هذه الدراسة مساهمات إضافية:
أولاً، تقدم نهجًا تحليليًا منظمًا يحول نتائج الاستخبارات مفتوحة المصدر الخام إلى استخبارات قابلة للتنفيذ من خلال تصنيف الثغرات، وترتيبها حسب الخطورة، وربطها بأطر عمل راسخة مثل MITRE ATT&CK [9].
ثانيًا، توفر إرشادات عملية للتبني المؤسسي من خلال نموذج تكامل متدرج يمكن الجهات المعنية البحرية من جميع الأحجام من تشغيل الاستخبارات مفتوحة المصدر ضمن هياكل الحوكمة الحالية وأطر الامتثال التنظيمي.
تتبع الدراسة إطارًا منهجيًا منظمًا مقسمًا إلى خمس مراحل رئيسية: التحديد، حيث يتم تحديد الأهداف الاستراتيجية؛ الجمع، حيث يتم جمع البيانات بشكل منهجي من المصادر العامة؛ المعالجة، حيث يتم تنظيف البيانات وتطبيعها؛ التحليل، حيث يتم فحص البيانات المعالجة لاستخراج الاستخبارات؛ والنشر، حيث يتم تجميع النتائج في تقارير قابلة للتنفيذ. هذا البحث هو في الأساس منهجي وتأطيري بطبيعته. بدلاً من تقديم نتائج تجريبية كمية، يقدم عملية منظمة وقابلة للتكرار لجمع وتحليل الاستخبارات البحرية مفتوحة المصدر، تم التحقق من صحتها من خلال دراسة حالة نوعية.
تبحث هذه الدراسة في إمكانات الاستخبارات مفتوحة المصدر لتعزيز الأمن السيبراني البحري، مع التركيز الأساسي على التدابير الوقائية. تكمن حداثة هذه الدراسة في تطوير إطار استخباراتي شامل وقابل للتنفيذ مصمم خصيصًا لسياق الأمن السيبراني البحري، وهي مساهمة تسد فجوة كبيرة في الأدبيات الحالية. بينما اعترفت الأبحاث السابقة بقيمة الاستخبارات مفتوحة المصدر، تقدم هذه الدراسة منهجية شاملة خطوة بخطوة لتنفيذها، كاملة مع تصنيف للتهديدات السيبرانية البحرية وعملية منهجية لجمع وتحليل البيانات من مصادر عامة متنوعة مثل AIS وShodan ووسائل التواصل الاجتماعي للطاقم.
يتم تنظيم بقية هذه الورقة على النحو التالي. يضع القسم الثاني الخلفية اللازمة من خلال تفصيل مبادئ الاستخبارات مفتوحة المصدر، ومشهد الأمن السيبراني البحري، والجهات الفاعلة الرئيسية في التهديدات، ونواقل الهجوم الشائعة. يستعرض القسم الثالث الأعمال ذات الصلة ويحدد موقع مساهمتنا ضمن الخطاب الأكاديمي الحالي. يقدم القسم الرابع جوهر بحثنا: منهجية مفصلة للاستخبارات مفتوحة المصدر البحرية، بما في ذلك سير عمل استخباراتي من خمس مراحل، ومناقشة عملية البحث وراء تجميع مجموعة أدوات مصنفة، وفحص نقدي للاعتبارات الأخلاقية والقانونية. يفصل القسم الخامس التصنيف الناتج لأدوات الاستخبارات مفتوحة المصدر البحرية. يوضح القسم السادس التطبيق العملي للإطار المقترح من خلال دراسة حالة، مما يتحقق من فائدته في تحديد الثغرات الواقعية. يناقش القسم السابع النتائج، مع التركيز على التكامل المؤسسي، وتطوير العمليات، والعوامل البشرية في الأمن السيبراني البحري. أخيرًا، يختتم القسم الثامن الورقة بتلخيص المساهمات الرئيسية وتحديد اتجاهات البحث المستقبلية.
يبدأ هذا القسم الخلفي بتأسيس الدور الأساسي للاستخبارات مفتوحة المصدر وإظهار كيف يمكن تسليح البصمة الرقمية الهائلة المتاحة للعموم للصناعة من قبل الجهات الفاعلة في التهديدات. ثم يتعمق في المنهجيات المحددة للاستخبارات مفتوحة المصدر السلبية والنشطة، مسلطًا الضوء على التهديد الناشئ للهجمات المعززة بالذكاء الاصطناعي التي تؤتمت التنميط والتصيد. يرسم هذا القسم بعد ذلك مشهد الأمن السيبراني البحري المعقد، مؤكدًا على تقارب تكنولوجيا المعلومات (IT) وتكنولوجيا التشغيل (OT) كثغرة رئيسية. أخيرًا، يصنف الجهات الفاعلة المختلفة في التهديدات ويحلل نواقل الهجوم الأساسية التي يستغلونها، من اختراقات الشبكة وانتهاكات الاتصالات عبر الأقمار الصناعية إلى الهندسة الاجتماعية وهجمات سلسلة التوريد. معًا، تؤطر هذه العناصر قطاعًا تحت ضغط متصاعد، حيث تزداد الرقمنة مع تهديدات سيبرانية متطورة ومتعددة الأوجه.
الاستخبارات مفتوحة المصدر (OSINT) هي ممارسة جمع وتحليل المعلومات التي يمكن الوصول إليها بحرية وقانونية للعموم لأغراض مثل تقييم التهديدات والأمن السيبراني. تلعب الاستخبارات مفتوحة المصدر دورًا حيويًا في البقاء على اطلاع والاستجابة بفعالية باستخدام الاستنتاجات المستمدة من البيانات المجمعة [10]، [11].
من الصور إلى مقاطع الفيديو إلى أشكال أخرى من الوسائط الرقمية، يشارك الأشخاص معلومات شخصية متزايدة عبر الإنترنت، وينطبق الشيء نفسه على المجال البحري. باستخدام الأدوات المناسبة ومهارات الهندسة الاجتماعية، يمكن للجهات الخبيثة الوصول إلى معلومات حساسة، مثل كلمات المرور، أو حتى ابتزاز الآخرين [11].
على سبيل المثال، يمكننا الحصول على الكثير من المعلومات المتعلقة بالقطاع البحري من السجلات العامة ومواقع الويب مثل MarineTraffic [12]. يمكننا العثور على رقم المنظمة البحرية الدولية (IMO) للسفينة، وهويات الخدمة المتنقلة البحرية (MMSI)، والأبعاد، والمالك، والموقع الحالي، وحتى موانئ المغادرة والوصول. بالنسبة لبعض السفن، قد تكون معلومات أفراد الطاقم السابقين متاحة أيضًا. يمكن الحصول على كل هذه المعلومات بمعرفة اسم السفينة. بمرور الوقت، يمكن للجهات الخبيثة بناء ملف شامل يحتوي على معلومات حاسمة كافية، ثم التخطيط لشن هجمات مختلفة وتنفيذها، تتراوح بين الاعتداءات الجسدية (مثل القرصنة والتهريب) والاختراقات السيبرانية المتطورة التي تستغل الثغرات في أنظمة السفن [13].
يتطور مشهد التهديدات السيبرانية في البيئات البحرية ويصبح أكثر تعقيدًا. تستهدف الجهات الفاعلة المختلفة ذات الدوافع المختلفة الأصول البحرية لأسباب استراتيجية أو اقتصادية أو أيديولوجية. تشمل هذه الفئات: الجهات المدعومة من الدول التي تستهدف الأصول ذات الأهمية الاستراتيجية والعسكرية؛ والمجموعات الإجرامية الإلكترونية التي تسعى لتحقيق مكاسب مالية من خلال برامج الفدية واختراق البريد الإلكتروني التجاري؛ والناشطون الذين يهاجمون لأسباب أيديولوجية؛ والتهديدات الداخلية من الموظفين الحاليين أو السابقين [27]–[35].
تهدد الهجمات السيبرانية العمليات البحرية من خلال نواقل هجوم متنوعة. تشمل الهجمات القائمة على الشبكات استهداف الأنظمة المترابطة داخل القطاع البحري، بما في ذلك شبكات الشركات ومنصات الاتصالات على السفن. يتعرض الاتصال عبر الأقمار الصناعية (VSAT) للخطر بسبب الثغرات في التشفير وبيانات الاعتماد الافتراضية. تستغل الهندسة الاجتماعية العامل البشري من خلال التصيد والاحتيال. تستهدف هجمات سلسلة التوريد الموردين والمقاولين الخارجيين. وأخيرًا، يستهدف استغلال تكنولوجيا التشغيل (OT) أنظمة التحكم الصناعية في السفن والموانئ [36]–[48].
هناك عدد قليل من الدراسات التي تستكشف تقاطع العمليات البحرية والاستخبارات مفتوحة المصدر. يدرس تانابي وآخرون [49] دورة الاستخبارات الكلاسيكية ويقترحون طريقة موحدة تدمج تقنيات OSINT. يبحث راجاماكي وآخرون [50] في تقاطع OSINT وتحليلات البيانات الضخمة في المراقبة البحرية، مع التركيز على خصوصية البيانات والامتثال للائحة العامة لحماية البيانات (GDPR). يقدم لوفيل وهيرينغ [51] تمرين نبتون، وهو برنامج تدريبي محاكي للأمن السيبراني البحري في جامعة تالين للتكنولوجيا. يستكشف سيج [52] استخدام OSINT كأداة عملية للحفاظ على الوعي الظرفي عند فشل أنظمة التتبع الإلكترونية مثل AIS. يعالج كانيلوبولوس [53] التهديدات السيبرانية المتزايدة في القطاع البحري ويؤكد على ضرورة استراتيجية استخباراتية مضادة استباقية.
يبني هذا البحث على هذه الأسس ليسد فجوة كبيرة في الأدبيات الحالية من خلال اقتراح إطار OSINT شامل ومنظم وقابل للتطبيق مباشرة مصمم خصيصًا للأمن السيبراني البحري.
تم تصميم المنهجية المقدمة في هذا القسم كإطار عملي لممارسي OSINT البحري. وهي ليست تصميمًا تجريبيًا يتطلب تحققًا كميًا، بل نهجًا نوعيًا منظمًا لجمع الاستخبارات يمكن تكييفه وتحسينه بناءً على السياق التشغيلي.
تم تجميع كتالوج الأدوات المقدم في هذا البحث من مجموعة من المصادر العامة لسد فجوة في الأدبيات. شمل ذلك مراجعة مدونات الممارسين، ومواد المؤتمرات الأمنية، والمنتديات الفنية حيث تتم مناقشة الأدوات وتقييمها بنشاط. تم تقييم الأدوات بناءً على ملاءمتها لتيارات البيانات البحرية الأساسية مثل AIS والصور الفضائية وسجلات السفن والسجلات المؤسسية [12]، [54].
يتكون سير عمل OSINT من خمس مراحل أساسية: التحديد، حيث يتم تحديد متطلبات الاستخبارات وبيئة المعلومات المستهدفة؛ الجمع، حيث يتم جمع البيانات بشكل منهجي من مصادر بحرية متنوعة؛ المعالجة، حيث يتم تنظيف البيانات وتطبيعها وهيكلتها؛ التحليل، حيث يتم تحويل المعلومات المعالجة إلى استخبارات قابلة للتنفيذ؛ والنشر، حيث يتم تقديم النتائج لأصحاب المصلحة [55]، [56].
عند إجراء عمليات OSINT البحرية، تعتبر الخصوصية أمرًا بالغ الأهمية. يعد تقليل البيانات والحد من الغرض من المبادئ الأساسية التي يجب الالتزام بها. كما يجب أن تلتزم عمليات OSINT بالأطر القانونية مثل اللائحة العامة لحماية البيانات (GDPR) وتوجيه NIS-2. تشمل المبادئ التوجيهية الأخلاقية: الغرض المشروع، والتناسب، والشفافية مع أصحاب المصلحة المعنيين [57]–[61].
يقدم هذا القسم مجموعة أدوات استقصائية شاملة لـ OSINT البحري، منظمة في إطار معياري من مجالات التحقيق المترابطة.
تشكل القدرة على مراقبة حركة السفن قدرة أساسية في OSINT البحري. المصدر الأساسي للبيانات هو نظام التعريف الآلي (AIS)، والذي يمكن وصفه بأنه إشارة تبث علنًا مصممة لتجنب الاصطدام والوعي بالمجال البحري [62]. من خلال تجميع هذه البيانات وتصورها، يمكن للمحققين إعادة بناء الأنشطة السابقة للسفينة وتحديد الانحرافات عن السلوك المتوقع.
تكمن القيمة الاستراتيجية لاستخبارات الشركات والسجلات الرسمية في قدرتها على استكشاف الزوايا القانونية والإدارية للمجال البحري. من خلال رسم خرائط للتسلسلات الهرمية للشركات، والتحقق من الملكية من خلال الوثائق الرسمية، وتقييم الامتثال المالي والتنظيمي، يمكن للمحققين تحويل معرف السفينة إلى ملف OSINT شامل.
تمثل منصات التوظيف البحري والتواصل المهني ناقلًا هامًا لتسرب المعلومات. يتم استغلال هذه الموارد بشكل روتيني من قبل الجهات الخبيثة لحصاد بيانات الأفراد، بما في ذلك هويات الطاقم والشهادات وتواريخ التوظيف وارتباطات السفن، لتسهيل الهندسة الاجتماعية المستهدفة وحملات التصيد.
بمجرد إنشاء موطئ قدم أولي على الأنظمة التكنولوجية للسفينة من خلال مسح الشبكة (Shodan، Censys)، يمكن للمحقق نشر مجموعة من أدوات OSINT الموجهة لتكنولوجيا المعلومات لتعميق صورة الاستخبارات. يشمل ذلك أدوات مثل Sherlock وHunter.io لجمع بيانات الطاقم، وقواعد بيانات الثغرات (CVE.org)، ومنصات استخبارات التهديدات (AlienVault OTX).
توظف المرحلة التحليلية النهائية أدوات متخصصة لتحويل بيانات OSINT الخام إلى استخبارات قابلة للتنفيذ. تعتبر منصات تحليل الروابط مثل Maltego حاسمة لتصور العلاقات المعقدة بين السفن والمالكين من الشركات والموانئ، وكشف هياكل الملكية الخفية. تقوم ماسحات الثغرات (Nmap، OpenVAS) بفحص سطح الهجوم الرقمي لأنظمة السفن والموانئ.
تطبق دراسة الحالة هذه إطار OSINT البحري لإجراء تقييم أمني استباقي لميناء تولوم، وهو ميناء متوسط الحجم خيالي في دولة إريون. الهدف هو توضيح كيف يمكن جمع المعلومات المتاحة للعموم وتحليلها بشكل منهجي لتحديد الثغرات المحتملة في طبقات الأمن المادية والرقمية والبشرية.
متطلبات الاستخبارات: "رسم البصمة الرقمية والإدارية لميناء تولوم لتحديد الثغرات المحتملة القابلة للاستغلال من قبل جهة فاعلة في التهديدات."
تم جمع البيانات من مصادر متعددة: تتبع حركة السفن عبر MarineTraffic؛ تحليل الموقع الإلكتروني للميناء واكتشاف أنماط البريد الإلكتروني؛ مسح البنية التحتية الرقمية عبر Shodan/Censys مما كشف عن أجهزة ICS مكشوفة وNAS غير محمي وخدمة RDP مكشوفة؛ والاستخبارات الجغرافية المكانية عبر خرائط Google.
تم تنظيم البيانات في جداول منظمة: قاعدة بيانات للأفراد (الأسماء والأدوار وروابط التواصل الاجتماعي)؛ وجرد للأصول (عناوين IP والمنافذ المفتوحة والخدمات والثغرات)؛ وخط زمني تشغيلي (مواعيد وصول ومغادرة السفن).
تم تصنيف النتائج إلى أربع فئات مواضيعية (البنية التحتية الرقمية، البشرية، التشغيلية، المادية) وتصنيفها حسب الخطورة. تم تحديد ثلاثة سيناريوهات هجوم رئيسية: هجوم برامج فدية مستهدف عبر التصيد الاحتيالي؛ تعطيل تشغيلي عبر التلاعب بأنظمة ICS؛ وسرقة بيانات الاعتماد وتسلل الشبكة. تم ربط النتائج بإطار MITRE ATT&CK [9].
تم إعداد تقرير تهديد مصنف لإدارة الميناء، يلخص المخاطر الحرجة (أجهزة ICS غير الآمنة، واجهات الإدارة المكشوفة) والمخاطر المتوسطة (تسرب معلومات الموظفين)، مع توصيات تشمل عزل شبكات OT عن الإنترنت العام وتفعيل المصادقة متعددة العوامل.
من خلال الجمع المنهجي وتحليل البيانات المتاحة للعموم، يمكن للمحللين الكشف عن الثغرات دون القيام بأنشطة اقتحامية. توفر أدوات مثل Shodan مراقبة فورية للبصمة الرقمية البحرية. عند دمج OSINT في مهام الصيد عن التهديدات الحالية، يصبح من الممكن الكشف المبكر عن الحالات الشاذة وأنماط السلوك المشبوهة.
يتطلب التنفيذ الفعال دمجًا سلسًا لممارسات OSINT في عمليات الأمن البحري الحالية. يجب أن تتعاون فرق اختبار الاختراق بشكل وثيق مع وحدات OSINT، باستخدام نتائج المصادر المفتوحة لمحاكاة الهجمات المستهدفة. يضمن دمج OSINT في العمليات الأمنية ترجمة الرؤى الاستخباراتية مباشرة إلى إجراءات أمنية قابلة للتنفيذ [70].
تساعد سير العمل المحددة جيدًا في ضمان الاتساق والانضباط المنهجي عبر جهود OSINT البحرية. يجب أن تشمل إدارة المتطلبات مراجعات منتظمة وأطرًا لتحديد الأولويات وحلقات تغذية راجعة لضمان توافق جهود الاستخبارات مع احتياجات الأمن التشغيلية [72].
لا يقتصر تشغيل OSINT البحري الفعال على امتلاك الأدوات المناسبة فحسب، بل يتطلب أشخاصًا يتمتعون بالمهارات المناسبة والمعرفة بالمجال [73]. التدريب المستمر ضروري لمواكبة التطور المستمر للتهديدات والتقنيات والديناميكيات الجيوسياسية المتغيرة [6].
تم الحصول على جميع المعلومات من المصادر المتاحة للعموم فقط. لم يتم الوصول إلى أي أنظمة دون إذن. التزم التمرين بالمبادئ التوجيهية الأخلاقية المحددة في القسم IV-C، مع الالتزام الصارم بمبادئ الحد من الغرض وتقليل البيانات.
تثبت دراسة الحالة أن OSINT يوفر طبقة استخباراتية منخفضة التكلفة وعالية القيمة يمكن الوصول إليها للموانئ والمؤسسات البحرية من جميع الأحجام، مما يمكن من تقييم المخاطر الاستباقي دون استثمار رأسمالي كبير. العامل البشري يظل الحلقة الأضعف في الأمن السيبراني البحري [75].
يجب أن يبدأ الدمج على مستوى الحوكمة، حيث يجب تأطير OSINT كأداة للوفاء بالالتزامات التنظيمية الحالية مثل قرار MSC.428(98) للمنظمة البحرية الدولية [5]، وتوجيه NIS-2 [73]، واللائحة العامة لحماية البيانات (GDPR). يقدم القسم نموذج تكامل متدرج: المستوى 1 (المشغلون الصغار) - تدقيق نصف سنوي للبصمة الرقمية؛ المستوى 2 (الشركات المتوسطة) - مراقبة مستمرة عبر MSOC؛ المستوى 3 (الموانئ الكبرى) - فريق استخبارات تهديدات مخصص [23]، [76]، [77].
تعتمد OSINT على البيانات المتاحة للعموم، والتي قد تكون قديمة أو غير كاملة أو مضللة عن قصد. يتطلب الإطار مستوى معينًا من النضج المؤسسي والموارد. قد تفتقر الكيانات البحرية الأصغر إلى الخبرة أو الميزانية لتنفيذ برنامج OSINT بشكل فعال. قد تتكيف الجهات الخبيثة مع منهجيات OSINT، مما يقلل فعاليتها بمرور الوقت.
لقد وسعت الرقمنة السريعة والواسعة النطاق للقطاع البحري سطح الهجوم السيبراني بشكل كبير. يؤكد هذا البحث على الحاجة الملحة لاستراتيجيات الأمن السيبراني الاستباقية. من خلال تطوير وتطبيق إطار OSINT بحري مخصص، توضح هذه الورقة كيف يمكن الاستفادة من المعلومات المتاحة للعموم بشكل منهجي لتحديد الثغرات واكتشاف التهديدات في مرحلة مبكرة وتعزيز الوعي الظرفي.
المساهمات الرئيسية تشمل: (1) منهجية OSINT منظمة قائمة على المراحل؛ (2) تصنيف شامل للتهديدات السيبرانية البحرية؛ (3) مجموعة أدوات منتقاة تضم أكثر من 100 مصدر OSINT؛ (4) إطار أخلاقي وقانوني؛ و(5) إرشادات عملية للتبني المؤسسي مع نموذج تكامل متدرج.
يجب أن تعطي الأبحاث المستقبلية الأولوية للتكامل مع الذكاء الاصطناعي والتعلم الآلي لأتمتة اكتشاف التهديدات، وتطوير منصات استشعار متقدمة تدمج AIS والصور الفضائية وبيانات IoT، واستكشاف أعمق للعامل البشري عبر التواصل الاجتماعي واختبارات الهندسة الاجتماعية المحاكاة.
The accelerating digital transformation of the maritime industry, driven by the widespread adoption of Internet of Things (IoT) devices, integrated vessel systems, and automated port operations, has significantly expanded its cyber-attack surface, rendering it increasingly vulnerable to sophisticated threats. This study investigates the application of Open-Source Intelligence (OSINT) as a proactive, scalable, and cost-effective methodology for enhancing maritime cybersecurity. We present a specialized maritime OSINT framework comprising a systematic five-phase workflow (Identification, Collection, Processing, Analysis and Dissemination) tailored to the sector's unique operational and threat landscape. The framework is supported by a comprehensive taxonomy of maritime cyber threats and a curated toolkit of over 100 OSINT resources, spanning vessel tracking, corporate intelligence, digital reconnaissance, and analytical platforms. Through applied case studies, we demonstrate how this approach can identify critical vulnerabilities such as exposed operational technology, weak software supply chain links, and human-factor risks derived from publicly accessible data. Our findings confirm that maritime OSINT provides an indispensable intelligence layer, enabling stakeholders to transition from reactive security postures to proactive risk management through early threat detection, informed vulnerability assessment, and enhanced situational awareness, while adhering to the proposed ethical and legal guidelines for responsible intelligence collection.
The maritime industry is undergoing rapid and extensive digitalization across all aspects of the domain. Although this technological integration promises enhanced productivity and streamlined operations, it simultaneously expands the attack surface. With over 80% of international trade relying on maritime transportation [1], it is crucial to secure and protect the different aspects of the sector from cybersecurity challenges. Cyberattacks on the maritime industry have increased by a staggering 900% in recent years [2]. It is sensible to implement additional security layers [3].
This digital transformation includes automation in ports, integration of IoT devices on vessels, and establishment of interconnected logistics systems. Unfortunately, a single vessel often presents a complex security environment, simultaneously operating cutting-edge technologies alongside very old legacy systems, further complicating compliance with evolving regulations such as the Network and Information Systems (NIS)-2 Directive (EU 2022/2555) [4], which mandates stringent cybersecurity risk management for maritime operators and the International Maritime Organization (IMO—the UN agency responsible for regulating shipping) resolution MSC.428(98) [5], requiring cyber risks to be addressed under the International Safety Management (ISM) Code (an international standard for the safe management and operation of ships) [6]. Maritime organizations are high-value targets for various threat actors. Current security practices are often reactive, stressing the need for proactive intelligence capabilities, such as Open-Source Intelligence (OSINT), to anticipate and mitigate threats [7], [8].
OSINT can be weaponized by malicious actors to plan and execute targeted attacks against maritime assets by exploiting the very data intended for safety and transparency. By systematically analyzing OSINT sources, adversaries can identify high-value targets through unexplained loitering patterns and route anomalies, which may signal vessels carrying sensitive cargo or operating under duress.
For example, the Automatic Identification System (AIS) is a standard tracking system used globally to monitor vessel positions, routes, and identities in real time, which can be utilized to detect deliberate gaps in transmission or inconsistencies that indicate spoofing. Attackers can pinpoint vessels attempting to conceal their movements, making them vulnerable to interception, piracy, or cyber-physical attacks. Additionally, by mapping broader traffic patterns within strategic chokepoints or politically sensitive areas, malicious actors can identify optimal times and locations for ambushes, smuggling operations, or coordinated cyber intrusions, turning publicly available maritime data into a tactical blueprint for disruption and exploitation.
The primary objective of this study is to leverage this specialized framework to empower maritime stakeholders with a proactive, cost-effective capability for early threat detection, vulnerability identification, and enhanced situational awareness, thereby enabling a shift from reactive security postures to preventive risk management. Beyond the framework itself, this study makes two additional contributions:
First, it introduces a structured analytical approach that transforms raw OSINT findings into actionable intelligence through vulnerability categorization, severity ranking, and mapping to established frameworks such as MITRE ATT&CK [9].
Second, it provides practical guidance for organizational adoption through a tiered integration model that enables maritime stakeholders of all sizes to operationalize OSINT within the existing governance structures and regulatory compliance frameworks.
The study follows a structured methodological framework organized into five key phases: identification, where strategic objectives are defined; collection, where data are systematically gathered from public sources; processing, where data are cleaned and normalized; analysis, where processed data are examined to extract intelligence; and dissemination, where findings are synthesized into actionable reports. Throughout this workflow, a variety of OSINT tools are utilized, each aligned with the goals of the corresponding phase. These tools were identified through a dedicated research process to assemble a practical toolkit tailored for the maritime domain. This research is primarily methodological and framework-oriented in nature. Rather than presenting quantitative experimental results, it offers a structured, repeatable process for maritime OSINT collection and analysis, validated through a qualitative case study.
This study investigates the potential of OSINT to enhance maritime cybersecurity, with a primary focus on preventive measures. The novelty of this study lies in the development of a comprehensive and actionable OSINT framework specifically tailored to the maritime cybersecurity context, a contribution that fills a significant gap in the existing literature. While prior research has acknowledged the value of OSINT, this study provides a holistic, step-by-step methodology for its implementation, complete with a taxonomy of maritime cyber threats and a systematic process for collecting and analyzing data from diverse public sources such as AIS, Shodan, and crew social media.
The remainder of this paper is organized as follows. Section II establishes the necessary background by detailing OSINT principles, the maritime cybersecurity landscape, key threat actors, and prevalent attack vectors. Section III reviews the related work and positions our contribution within the existing scholarly discourse. Section IV presents the core of our research: a detailed maritime OSINT methodology, including a five-phase intelligence workflow, a discussion of the research process behind the compilation of a categorized toolkit, and a critical examination of ethical and legal considerations. Section V details the resulting taxonomy of maritime OSINT tools. Section VI demonstrates the practical application of the proposed framework through a case study, validating its utility in identifying real-world vulnerabilities. Section VII discusses the findings, emphasizing organizational integration, process development, and human factors in maritime cybersecurity. Finally, Section VIII concludes the paper by summarizing the key contributions and outlining directions for future research.
This background section begins by establishing the fundamental role of OSINT and demonstrating how the vast, publicly accessible digital footprint of the industry can be weaponized by threat actors. It then delves into the specific methodologies of passive and active OSINT, highlighting the emerging threat of AI-enhanced attacks that automate profiling and phishing. This section subsequently maps the complex maritime cybersecurity landscape, emphasizing the convergence of Information Technology (IT) and Operational Technology (OT) as a key vulnerability. Finally, it categorizes diverse threat actors and analyzes the primary attack vectors they exploit, from network intrusions and satellite communication compromises to social engineering and supply chain attacks.
Open-Source Intelligence (OSINT) is the practice of gathering and analyzing information that is freely and legally accessible to the public for purposes such as threat assessment and cybersecurity. OSINT plays a vital role in staying informed and responding effectively using deductions derived from aggregated data [10], [11].
From pictures to videos to other forms of digital media, people are increasingly sharing personal information online, and the same applies to the maritime domain. With proper tools and social engineering skills, malicious actors can gain access to sensitive information, such as passwords, or even extort someone [11].
For example, we can obtain a lot of information related to the maritime sector from public records and websites such as MarineTraffic [12]. Namely, we can find the vessel's IMO number, Maritime Mobile Service Identity (MMSI) numbers, dimensions, owner, current location, and even its departure and destination ports. For some vessels, information about past crew members may also be accessible. All this information can be obtained by knowing the name of the vessel.
The cyber threat landscape in maritime environments is evolving and becoming increasingly complex. Various threat actors with different motivations and skill levels attempt to circumvent security defenses. Based on a retrospective analysis of past maritime cyber incidents and intelligence, we can categorize threat actors into: state-sponsored actors targeting maritime assets with strategic, economic, or military relevance; cybercriminal organizations and individuals targeting maritime operations for financial gain through ransomware, business email compromise, and cargo theft facilitation; hacktivists targeting maritime organizations for ideological reasons; and insider threats from current or former employees with access to operational maritime systems or sensitive data [27]–[35].
Cyberattacks threaten maritime operations through diverse attack vectors. Network-based attacks target interconnected systems within the maritime sector, including corporate networks, ship communication platforms, and port management infrastructure. Vessel operations relying on Very Small Aperture Terminals (VSAT) and other satellite systems are susceptible to cyberattacks due to inherent vulnerabilities in satellite communication. Social engineering preys on maritime personnel through tactics like phishing, pretexting, and business email compromise (BEC). Supply chain compromises exploit the intricate web of vendors, service providers, and contractors that support maritime operations. Finally, operational technology exploitation targets industrial control systems governing ship propulsion, navigation, and port cargo handling [36]–[48].
There are only a few studies that explore the intersection of maritime operations and OSINT, and each adopts a distinct methodology and focus. While existing research demonstrates the potential of OSINT for improving maritime situational awareness, cybersecurity, and operational integrity, these works often differ in scope—ranging from privacy and ethical considerations to simulation-based training and real-world case studies.
Tanabe et al. [49] situate OSINT within the broader intelligence cycle... Rajamäki et al. [50] examine the intersection of OSINT and Big Data Analytics (BDA) in maritime surveillance... Lovell and Heering [51] present Exercise Neptune, a simulator-based maritime cybersecurity training program...
The methodology presented in this section is designed as a practical framework for maritime OSINT practitioners. It is not intended as an experimental design requiring quantitative validation, but rather as a structured, qualitative approach to intelligence gathering that can be adapted and refined based on operational context.
The catalog of tools presented in this research was assembled from a range of public sources to address a gap in literature. This involved reviewing practitioner blogs, security conference materials, and technical forums where tools are actively discussed and evaluated. Tools were assessed based on their relevance to core maritime data streams like AIS, satellite imagery, vessel registries, and corporate records [12], [54].
OSINT workflow is structured around five core phases: Identification, where intelligence requirements and the target's information environment are defined; Collection, involving methodical gathering of data from maritime-specific sources; Processing, where raw data is cleaned, normalized, and structured; Analysis, where processed information is transformed into actionable intelligence; and Dissemination, where findings are communicated to relevant stakeholders [55], [56].
When conducting maritime OSINT operations, privacy is critical. Data minimization and purpose limitation are foundational principles. OSINT activities must also comply with legal frameworks such as GDPR, NIS-2 Directive, and data protection regulations. Ethical guidelines include legitimate purpose, proportionality, and transparency with relevant stakeholders [57]–[61].
This section presents a comprehensive OSINT investigative toolkit for maritime security, structured into a modular framework of interconnected investigative domains.
The ability to monitor vessel movements and maritime traffic constitutes a foundational capability within maritime OSINT. The primary data source is AIS, a publicly broadcast signal designed for collision avoidance and maritime domain awareness [62]. By aggregating and visualizing this data, investigators can reconstruct a vessel's past activities and identify deviations from expected behavior.
The strategic value of corporate and official registry intelligence lies in its ability to explore the legal and administrative corners of the maritime domain. By mapping corporate hierarchies, verifying ownership through official documents, and assessing financial and regulatory compliance, investigators can transform a vessel identifier into a comprehensive OSINT profile.
Platforms designed for crew recruitment and maritime networking represent a significant vector for information leakage. These resources are routinely exploited by malicious actors to harvest personnel data, including crew identities, certifications, employment histories, and vessel associations, to facilitate sophisticated social engineering and targeted phishing campaigns.
Once an initial foothold on a vessel's technological systems is established through network scanning (Shodan, Censys), an investigator can deploy a suite of IT-oriented OSINT approaches. This includes tools like Sherlock and Hunter.io for personnel data collection, vulnerability databases (CVE.org), and threat intelligence platforms (AlienVault OTX).
The final analytical phase employs specialized tools to transform raw maritime data into actionable intelligence. Link analysis platforms like Maltego are critical for visualizing complex relationships between vessels, corporate owners, and ports. Vulnerability scanners (Nmap, OpenVAS) probe the digital attack surface of shipboard and port systems.
Note: The case study presented in this section is based on a fictional port (the Port of Tulum) to avoid real-world targeting and ensure ethical compliance. It applies the maritime OSINT framework outlined in Section IV-B to conduct a proactive security assessment of the Port of Tulum, a fictional but representative mid-sized port in Erewhon.
Intelligence requirement: "Map the digital and administrative footprint of Tulum Port to identify potential vulnerabilities exploitable by a threat actor." Key focal points included publicly accessible IT/OT systems, personnel information, operational schedules, and physical layout.
Data was gathered from multiple open sources: vessel traffic tracking (MarineTraffic), website analysis revealing email patterns, digital infrastructure reconnaissance (Shodan/Censys) exposing multiple ICS devices and unprotected NAS, and geospatial intelligence (Google Maps).
Data was organized into structured tables: Personnel Database (names, roles, social links), Asset Inventory (IPs, open ports, services, vulnerabilities), and Operational Timeline (vessel arrivals/departures).
Findings were categorized into four thematic groups (Digital Infrastructure, Human/Personnel, Operational, Physical) and ranked by severity. Three main attack scenarios were identified: targeted ransomware attack via spear-phishing; operational disruption via ICS manipulation; and credential harvesting with network pivot. Findings were mapped to the MITRE ATT&CK framework [9].
A classified threat report was drafted for port management, summarizing critical risks (unsecured ICS devices, exposed management interfaces) and medium risks (employee information leakage), with recommendations including OT network segmentation and multi-factor authentication enforcement.
By systematically collecting and analyzing publicly available data, analysts can uncover vulnerabilities without engaging in intrusive activities. Tools like Shodan allow real-time monitoring of maritime digital footprints. When OSINT is integrated into existing threat hunting workflows, it enables early detection of anomalies and suspicious behavior patterns.
Effective implementation requires seamless integration of OSINT practices into existing maritime security operations. Penetration testing teams should collaborate closely with OSINT units, using open-source findings to simulate targeted attacks. Integrating OSINT into security operations ensures intelligence insights translate directly into actionable security measures [70].
Well-defined processes ensure consistency and methodological discipline across maritime OSINT efforts. Requirements management includes regular reviews, prioritization frameworks, and feedback loops to ensure intelligence efforts align with operational security needs [72].
Running effective maritime OSINT operations requires people with the right skills and domain knowledge, a requirement reinforced by NIS-2 Directive Article 21 [73] and IMO's ISM Code [6]. Continuous learning is essential to keep pace with evolving threats, technologies, and shifting geopolitical dynamics.
All information was obtained from publicly accessible sources only. No systems were accessed without authorization. The exercise adhered to the ethical guidelines in Section IV-C, with purpose limitation and data minimization strictly observed.
The case study validates that OSINT provides a low-cost, high-value layer of threat intelligence accessible to ports and maritime organizations of all sizes. Human factors remain the weakest link in maritime cybersecurity [75]. Continuous monitoring of an organization's own digital footprint is essential.
Integration begins at the governance level, framing OSINT as a tool for fulfilling regulatory obligations such as IMO Resolution MSC.428(98) [5], NIS-2 Directive [73], and GDPR. A tiered integration model is proposed: Tier 1 (small operators) — semi-annual digital footprint audit; Tier 2 (mid-sized companies) — continuous monitoring via MSOC; Tier 3 (large ports) — dedicated threat intelligence function [23], [76], [77].
OSINT relies on publicly accessible data, which may be outdated, incomplete, or intentionally misleading. The framework assumes a certain level of organizational maturity and resources. Smaller maritime entities may lack the expertise or budget to implement an OSINT program effectively. As OSINT methodologies become more widely adopted, threat actors may adapt to reduce their digital footprint.
The rapid and widespread digitalization of the maritime sector has dramatically expanded its cyber-attack surface. This research underscores the urgent need for proactive cybersecurity strategies. Through the development and application of a dedicated maritime OSINT framework, this paper demonstrates how publicly available information can be systematically leveraged to identify vulnerabilities, detect early-stage threats, and enhance situational awareness.
Key contributions include: (1) a structured, phase-based OSINT methodology tailored to maritime context; (2) a comprehensive taxonomy of maritime cyber threats; (3) a curated toolkit of over 100 OSINT resources; (4) an ethical and legal framework; and (5) practical guidance for organizational adoption with a tiered integration model.
Future research should prioritize integration with AI and machine learning to automate threat detection, the development of advanced sensor fusion platforms combining AIS, satellite imagery, and IoT data, and deeper exploration of human-centric OSINT including social media profiling and simulated social engineering attacks.