Detecting and Hunting Cyberthreats in a Maritime Environment: Specification and Experimentation of a Maritime Cybersecurity Operations Centre

被引:0
|
作者
Jacq, Olivier [1 ]
Boudvin, Xavier [1 ]
Brosset, David [1 ]
Kermarrec, Yvon [1 ,2 ]
Simonin, Jacques [1 ,2 ]
机构
[1] Ecole Navale, Chair Naval Cyber Def, F-29460 Lanveoc, France
[2] IMT Atlantique, Lab STICC, F-29238 Brest, France
关键词
ICS; SOC; maritime; cyber situation awareness;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The vast majority of worldwide goods exchanges are made by sea. In some parts of the world, the concurrence for dominance at sea is very high and definitely seen as a main military goal. Meanwhile, new generation ships highly rely on information systems for communication, navigation and platform management. This ever-spreading attack surface and permanent satellite links have grown a concern about the potential impact of cyberattacks on a ship at sea or on naval shore infrastructures. Therefore, on top of the usual cyberprotection measures taken for safety reasons, it is essential to implement an ongoing cyber monitoring of ships in order to detect, react accordingly, and stop any incoming threat. In this paper, we explain the specific constraints when trying to assess the cyber situation awareness of maritime information systems. As we will demonstrate, those systems combine physical and logical constraints which complexify their cyber monitoring process and architecture. Gathering valuable data while having a limited and controlled impact on the satellite bandwidth, maintaining a high level of integrity on remote systems in production are, for instance, thriving challenges for both civilian and military ships. We have designed and set up a research platform which fulfils those specifications to streamline the cyber monitoring process. We will then describe the architecture used to detect cyber-threats and collect potential Indices of Compromise from naval systems, as well as the results we have currently achieved.
引用
收藏
页数:8
相关论文
共 8 条
  • [1] Helicopter operations in the maritime environment
    Anon
    Aircraft Engineering and Aerospace Technology, 2001, 73 (04): : 386 - 391
  • [2] Training the Maritime Security Operations Centre Teams
    Raimondi, Marco
    Longo, Giacomo
    Merlo, Alessio
    Armando, Alessandro
    Russo, Enrico
    2022 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2022, : 388 - 393
  • [3] Hybrid Cybersecurity Research and Education Environment for Maritime Sector
    Visky, Gabor
    Siganov, Aleksei
    Rehman, Muaan Ur
    Vaarandi, Risto
    Bahsi, Hayretdin
    Tsiopoulos, Leonidas
    2024 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2024, : 644 - 651
  • [4] The CAN Bus in the Maritime Environment - Technical Overview and Cybersecurity Vulnerabilities
    Kessler, Gary C.
    TRANSNAV-INTERNATIONAL JOURNAL ON MARINE NAVIGATION AND SAFETY OF SEA TRANSPORTATION, 2021, 15 (03) : 531 - 540
  • [5] Learned linear models for detecting watercraft in a maritime environment
    Olson, C. C.
    Nichols, J. M.
    APPLIED OPTICS, 2020, 59 (25) : 7553 - 7559
  • [6] ISR Missions in Maritime Environment Using UAS - Contributions of the Portuguese Air Force Academy Research Centre
    Felix, Luis
    Oliveira, Tiago
    Cruz, Goncalo
    Silva, Diogo
    Agamyrzyansc, Anna
    Coelho, Vasco
    ROBOT 2023: SIXTH IBERIAN ROBOTICS CONFERENCE, VOL 2, 2024, 978 : 269 - 281
  • [7] Multi-Layer, Multi-Segment Iterative Optimization for Maritime Supply Chain Operations in a Dynamic Fuzzy Environment
    Sahin, Bekir
    Soylu, Ahmet
    IEEE ACCESS, 2020, 8 : 144993 - 145005
  • [8] Detecting Maritime Infrared Targets in Harsh Environment by Improved Visual Attention Model Preselector and Anti-Jitter Spatiotemporal Filter Discriminator
    Ma, Dongdong
    Dong, Lili
    Xu, Wenhai
    REMOTE SENSING, 2022, 14 (20)