论文标题

船只网络安全:问题,挑战和前方的道路

Vessels Cybersecurity: Issues, Challenges, and the Road Ahead

论文作者

Caprolu, Maurantonio, Di Pietro, Roberto, Raponi, Simone, Sciancalepore, Savio, Tedeschi, Pietro

论文摘要

由于最近对海上船只的几次袭击,船只网络安全最近正在增长。这些最近的袭击使海事领域杂乱无章,该领域被认为对网络威胁相对免疫。正如国际海事组织(IMO)发布的最新授权所证明的那样,引用的信念已经结束。根据这些法规,所有船只应成为网络安全风险分析的主题,应采用技术控制以减轻产生的风险。这项倡议是值得称赞的,因为尽管最近发生了事件,但影响现代船只的脆弱性和威胁对于运营实体仍不清楚,这使进一步攻击的可怕后果的潜力只是“何时”,而不是“如果”。在这项贡献中,我们调查并系统化影响现代船只采用的系统和通信技术的主要安全弱点。具体而言,我们描述了不同系统的架构和主要特征,指出了它们的主要安全问题,并指定了攻击者如何利用它们以造成服务中断和相关的财务损失。我们还确定了引入攻击的一些对策。最后,我们重点介绍了行业和学术界将要解决的一些研究挑战,以增强船舶安全性。

Vessels cybersecurity is recently gaining momentum, as a result of a few recent attacks to vessels at sea. These recent attacks have shacked the maritime domain, which was thought to be relatively immune to cyber threats. The cited belief is now over, as proved by recent mandates issued by the International Maritime Organization (IMO). According to these regulations, all vessels should be the subject of a cybersecurity risk analysis, and technical controls should be adopted to mitigate the resulting risks. This initiative is laudable since, despite the recent incidents, the vulnerabilities and threats affecting modern vessels are still unclear to operating entities, leaving the potential for dreadful consequences of further attacks just a matter of "when", not "if". In this contribution, we investigate and systematize the major security weaknesses affecting systems and communication technologies adopted in modern vessels. Specifically, we describe the architecture and main features of the different systems, pointing out their main security issues, and specifying how they were exploited by attackers to cause service disruption and relevant financial losses. We also identify a few countermeasures to the introduced attacks. Finally, we highlight a few research challenges to be addressed by industry and academia to strengthen vessels security.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源