Sea Control - Sea Control 335 - Sea-Hacking from Land with Dr. Chris Demchak
Episode Date: April 10, 2022Links1. "Can't Sail Away from Cyber Attacks. 'Sea-Hacking' from Land," by Chris C. Demchak and Michael L. Thomas, War on the Rocks, October 15, 2021.2. "North Korean Jams GPS Signals to Fishing Boats:... South," by Ian Wood and Stella Kim, NBC News, April 1, 2016.3. "Ships fooled in GPS spoofing attack suggest Russian cyberweapon," by David Hambling, NewScientist, August 10, 2017.4. "Iran's secret cyber files," by Deborah Haynes, SkyNews.
Transcript
Discussion (0)
Hey folks, Sherrod here. Dr. Chris Demchak joined me to discuss her War on the Rocks article with
Michael L. Thomas on hacking at sea. As a reminder, all opinions you hear in this episode are our own
and not reflective of any institution with which we might be otherwise associated. This episode was
edited and produced by Jonathan Selling. We are still looking for audio editors to add to our
team, so if you're interested, please email us at seacontrol at simsec.org with your resume.
Finally, I want to take the opportunity to recommend our partners in the SimSec Podcast
Network, The Bilge Pumps. You can find Alex, Jamie, Drack, and a pile of iron brew bottles
wherever you download your podcasts. And on that note, I'll turn it over to Kimbersman.
You're listening to Sea Control, posted by the Center for International Maritime Security.
Hello, housemates, and welcome back aboard Sea Control. My guest today is Dr. Chris Demchak,
and we'll be discussing her article for War on the Rocks, Can't Sail Away from Cyberattacks,
Sea Hacking from Land. So Dr. Demchak, welcome. Would you mind introducing yourself to our
listeners, please? Hi there. My name is Chris Demchak. I am the Hopper Chair of Cybersecurity
at the U.S. Naval War College in the Cyber and Innovation Policy Institute in Newport, Rhode
Island. Well, thank you. And as a reminder, all opinions are our own and not representative of
any institution with which we may be otherwise associated. So you start your article with a
vignette from the Maritime Hacking Village at the August 2021 Cybersecurity Conference in DEF CON.
So can you tell us a little bit more about what is DEF CON? What was the Maritime Hacking Village?
DEF CON started in 1993, ironically, as a goodbye party for a fellow hacker by Jeff Moss
that was to be held in Las Vegas, I guess by accident in August. And it grew so popular
by other hackers that, by the time, the last number I could find is for 2019, 30,000 people
attended. Hackers who come, they adopt aliases, and what they do there is they engage in talks
and competitions amongst each other and networking, etc. It's widely and openly attended by
governments, you know, representatives and other commercial folk, and anybody who can participate
attend and network um and the convention space is divided into villages each supporting a topic
with its own displays contest talks now one of these topics is the cyber security of and around
the ocean as one pundit put it um ships are huge iot collections that's internet of things
collections these days they're all connected to the internet and they offer also opportunities
for exploitation, for ransom, political leverage, the usual reasons that hackers would hack.
And the Maritime Village, called Hack the Sea, responds to that particular area of concern.
It offers contests, equipment displays, talks, networking opportunities related to ships
in the maritime environment.
So the Sea Hacking Challenge was called CTF, which is a play on words for Commander Task
force, but what equipment was being used for CTF Hacking Challenge and what was it supposed to
simulate? So CTF is one of these competitions and it's a capture the flag format in which
three to five individuals per team can hands-on attempt to hack a sort of real maritime hardware
in a controlled environment. And what they did is they used Fathom 5's Grace Maritime Cybersecurity
test bed. And that is a relatively accurate facsimile of equipment typically in use on
board the bridge of a midsize container vessel. And in this particular contest, the teams focused
on gaining control through their hacking in and gaining control of steering or propulsion
or navigation, or preferably all three of them. I'm going to ask you one of those dread follow-up
questions that we discussed in the in the pre-brief for this but when you say capture the
flight format obviously i'm familiar with what that means from the pre-teens running around in
the woods uh perspective but what does that mean for a for a cyber event like this well for a cyber
event uh it it literally means there's a an an outcome that you have to achieve so have i gained
control of um propulsion and turned off the engines yes boom i've captured that flag that's
what that means and they usually keep leaderboards too showing who is making which flags as they move
along it's a very very common phenomenon in cyber ranges that are open to competitions okay um what
systems were the hackers able to access and then what did they do once they had acquired that access
now you touched on this a little bit in your previous answer but i do want to see it's
interesting me what they chose to do once they've acquired that control well they used you know
these are realistic looking components and of course the protocols and so they succeeded in
penetrating you know different maritime subsystems which in this particular case was navigation
firefighting and steering systems and one of the flags to capture which they did was to get in and
jam the rudder suddenly hard right and you override the physical controls of the bridge
And you basically force a critical failure. Now, the one last year, 2021 DEF CON, they used wired connections to their laptops.
But in 2022, the intent is to have this hack occur over a wireless environment.
In this case, they succeeded. They got in. They did what they needed to do.
You mentioned that the winning team had no experience in the virtual environment that they were using and then no real experience with maritime hacking either.
So who actually participated?
Well, this is this is also interesting is the contest is open to anyone who's interested.
And in this particular context, people go by aliases. Right.
So those that won said they knew nothing about the maritime environment, never tried a hackership and just decided to try the contest.
But what they found is what we've discussed in other venues, that the land-oriented systems have migrated onto the ships.
And so they were presented with the same vulnerabilities that were well-known in hacking.
It's a question of following through.
You mentioned a 2017 incident in which hackers seized control of a German-owned ship transiting from Cyprus to Djibouti.
What happened in that instance, and how was it ultimately resolved?
Ah, yes.
Well, in February of 2017, basically pirates off the shores of Djibouti hacked into the controls of a container vessel.
And the apparent intent was to steer it into an area where they could easily overwhelm the crew and board it.
Now, details are actually limited, but what we know from the open source is that the hack succeeded for 10 hours.
that for 10 hours, they could not control their own navigation.
The owners of the likely vessel have never admitted that it happened.
But we do know from others, from the reports by others,
that IT experts were brought in,
and they were finally able to get the navigation system working again.
And this time, of course, in hindsight,
installed some tougher protections for the maritime environment.
we know this is possible right and in spring of 2021 last year as well um we had a team of
doctoral students compete in enable x hack the machine exercise um using the same equipment
that they used in hack the sea at the defcon but they hacked remotely and successfully into the
simulated bridge so the fact that you're wired or not wired it's absolutely possible if you're
close enough and you're connected to the internet for some of the hacking to your vessel.
You've outlined sort of the possibilities, but the so what is really what the hackers can do
with that access. So what is the quote unquote worst case scenario for maritime hacking?
Well, so what depends on what losses are associated with that loss of control. So you
can imagine a ship with crude oil suddenly ramming another similar vessel in a narrow sea
lanes near ecologically sensitive fishing areas. You can imagine a huge container ship suddenly
turning into the midsection of a passing aircraft carrier. And even though the crew is able to
respond to the calls of the aircraft carrier, they're unable to regain control of steering
or propulsion sufficiently to stop the forward momentum of their vessel. And these vessels are
enormous. And you can also imagine the economic costs of just repeatedly groundings or erratic
behavior of enormous container ships, again, across these narrow maritime passageways or
choke points like the Suez Canal, the Straits of Molucca. Now, last year, we had the Ever Given
grounding in the Suez Canal, right? The Suez Canal carries 30% of the world's shipping container
volume and about 12% of global trade. Blocking the canal, as the Ever Given did, for six days alone,
just six days sparked such fears of oil shipment delays it raised the price of oil four percent
globally at least by one estimate imagine this happening not just once but in multiple
choke points in the maritime environment imagine just erratic behaviors of vessels carrying
critical goods to russia right now think about this in this crisis environment where maybe not
Not even people in favor of Ukraine have suddenly decided that they're going to attack Russian vessels because they're convenient, or Russian-bound vessels, because they're convenient, or maybe just near a war zone.
I mean, one of the concerns we would have is the paranoia of Mr. Putin would hardly interpret that behavior as anything but an attack by Western allies.
The so what is enormous.
Yeah, and as you mentioned that, so I should mention that we are recording this on March 6. So I don't know what date exactly this will go up, but we're still in kind of early stages of the Russia-Ukraine war that's going on following the Russian invasion.
So just to frame where we are in the timeline as we have this discussion, and correct me if I'm wrong, but there are actually anonymous hackers that are conducting cyber attacks in Russia right now, unless I'm mistaken.
So to my knowledge, I haven't heard them targeting anything at sea. But your points about the worst case scenario ever given strikes me. But in reality, every single port in the world effectively has a choke point across the front of it.
I mean, that narrow entrance to a port creates a protected anchorage, creates a protected burst for the ship.
So every single port in the world, with a few exceptions, I think, has some sort of choke point associated with it.
Absolutely. And if you can, and you know, this is something that, of course, the U.S. Navy thinks about all the time.
And what would happen if ships were someone attempted to bottle up naval vessels in port X or Y by using container ships?
So what are the most common shipboard vulnerabilities and how can shipping companies start to address those?
Well, here, you know, my co-author and I are going to defer to the experts, you know, in particular, because these are folks that are trying to help the shipping companies.
You know, the newer ships tend to have rudimentary protections with firewalls,
but most of the existing maritime fleet shipboard systems are networked with absolutely insufficient security.
Often the networks are not segregated.
If you get access, then generally you can roam relatively freely throughout other operational elements.
Quite often the newer technologies are simply connected onto older legacy systems with limited security.
i was astonished to find out how often windows nt was still you know in the base of these
shipboard systems and communications in general becomes a target um you can have poison updates
remote administration efforts to add control they they get phishing emails directed at members
who were on the bridge or in the engine room or whatever um and of course the data flows inward
and outward, it's classic. It's completely consistent with what you see on the land side
as well. And the other thing is, you know, we have to keep in mind, we think of ships underway,
but ships and ports are vulnerable as well with, you know, the possibility the results aren't
going to be realized until they are underway. And then there's satellites. You know, communications
with satellites can be particularly problematical. The vessel has to communicate externally to chart
its course. Inputs can be spoofed and the actual satellite terminals themselves can be hacked
to gain access. One researcher said that electronic charting systems pretty much never
have antivirus. You don't think of satellites as giving you a virus. And we've had the antivirus
industry for at least 30 years. But at the same time, we have not seen the ship building community
that have been launched with complex computer architectures
containing more than basic cyber protection.
And so this is something where investment and resources
are simply necessary for the shipping companies.
It's not enough to have insurance.
And unfortunately, that's often the choice they make.
Your piece started with small teams acting in isolation,
but you eventually got into what we're seeing
from some of the state actors.
So what are Russia, China and North Korea and Iran doing in the maritime cyber realm?
And what does that pretend for any future military campaigns?
Well, the major or what we call tier six actors, of course, include China and Russia in general.
But the other two play above their weight often enough.
The most publicly discussed and blatant state based attack on maritime commerce was the Russian spoofing of GPS in the Black Sea.
affecting about 1,300 commercial vessels, and I love this number, 1,300 vessels at least 7,900
times between 2016 and 2019. I mean, you could have had it more than once. And then, of course,
we have, you know, the Russian cyber attacks on Ukraine in 2017, which bled far beyond Ukraine
and led, not a target, but led to a devastating NotPetya attack, crippling the large, extraordinarily large Maersk shipping line, right, far from Ukraine.
So we have this bleed over that happens as well as anything that they might have directed themselves.
Now, in 2017, we also saw the North Koreans had learned how to play in this game.
So the North Koreans, in 2017 particularly, their navigation jamming was said to be behind the forced return of hundreds of South Korean fishing vessels, obviously operating in their proper economic zones.
and just this last year and i haven't seen verified in public press but sky news reported
that they had acquired documents that were said to originate from an iranian offensive cyber unit
which is part of the islamic revolutionary guard you know cyber command they have their own cyber
command and the documents were you know educational how to sink a cargo ship using cyber techniques
And, you know, how to hack into a satellite communication system that is used by the global shipping industry.
You can see how that would be something they'd want their folks to know how to do, given where they are in the world.
And then we have the growing hacking from space.
OK, so the satellites weren't built with this idea that someone could hack into them.
people are scrambling and you know backfitting how to protect them um that's where you often
also get the discussion of how to secure communications from satellite using quantized
communications there is a lot of talk about using older functional radio wave technology
right it's more secure it's you can't hack it the same way um but you know these discussions are
really not very far along. And it's pretty questionable how widely these alternatives,
one of them called E-Loran, assuming that's how they pronounce it, will spread. This takes a lot
of money and a sense of urgency on the shipbuilding firms and the shipping lines to accomplish this.
Now, how does this affect future military campaigns? Well, obviously, this adds an element
of uncertainty you are in lock and straits you everyone knows where they're supposed to be
how they're supposed to be sailing you know what their azimuth is and and so on but around you
are these passing large container ships and so one of the things it does in peacetime is it
requires that you spend a lot more time being extremely attentive to the variation in the
behaviors of these other ships particularly ships that go offline in a sense they they're there but
then you can't find out where they went these are ships you start tracking just as one used to try
and track of you know adversaries submarines and ships you have to start tracking everything around
you. And for military campaigns, well, we don't know yet exactly the effects it's going to have,
but to put it mildly, it massively raises the uncertainty about any crowded environment into
which you have to inject military forces by sea. When you closed with the recommendation for the
U.S. maritime industry, what was that recommendation and why? Well, we feel pretty strongly that there
efforts being made to improve the situation, working with like-minded allies, particularly
with allies. I do think the U.S. maritime industry needs to work and extend and embrace
the 2020 National Maritime Cybersecurity Plan and all the relevant and related proposed bills that
are actually in current negotiations in the Congress, such as the Shipyard Act.
You have to go beyond ports, though. One of the keys to a lot of these acts is they're focused on
U.S. ports. You have to go beyond ports. You really have to start making requirements on
the ships themselves, far beyond what we currently require in customs and
in our own Coast Guard requirements.
And it has to be done pretty urgently.
You're going to need policies that require proof of
and also proof of funding for cybersecurity upgrades
in container ships if they are delivering cargo to U.S. ports, right?
And this strategic response should, in principle,
be done cooperatively and implemented by other very established seafaring nations.
Ports are often forgotten.
There's a term that is now being, I'm pleased to say,
widely explored in the U.S. Department of Defense,
and that's contested logistics.
So the problem is that a lot of the ports,
that the ships coming to us going forward encounter, for them and for the ports,
cybersecurity is situational.
It's ad hoc.
It's driven by, you know, profit margins and perhaps the experience of one operating officer
where some ship got hacked and then they care about it more.
Of course, and, you know, fears of inefficiency in the operations.
you know the U.S. government can strongly influence what's considered normal but is
currently grossly inadequate and even in terms of the construction of the ships although we don't do
a large percentage of the ship construction in the world but we can certainly influence
in with our allies how they operate and we can certainly influence something that we've just
seen happen the insurance of the worldwide maritime fleet again um as you've pointed out
we are what seven days i think or something like that into the uh russo-ukrainian war
and insurance companies around the world are withdrawing their coverage for any ships that
serve or pick up goods or deliver goods to russia doesn't have an effect right away but it has an
effect on any planning going forward so the u.s is in its alleys are major stakeholders in the
global maritime socio-technical economic system and we need to step up our game to start to clean
it up because it's the same system that our major adversary is absolutely intending to dominate
not only with the numbers of ships it produces with the ports it owns it's um it's companies
owned, with its volumes, and of course, its tendency for political and personal coercion.
Lately, military, I call it saber rattling. And of course, just command of the technologies as
they go forward. Any of these cyber vulnerabilities we leave in the maritime industry, basically feed
the lead of the adversaries, allows them to get ahead of us and outpace us. So we have to do
something about this we have to do it now and we have to do it collectively with the private sector
with our maritime industry before it costs us all extraordinary in resources disruption to our
economies and of course in you know lives well unfortunately that's all that we have time for
today i'd like to thank my guest dr chris demchak so chris where can we find you online and what are
you working on next? So I am, I'm at the other end of the U.S. Naval War College, chris.demchak
at usnwc.edu. And with my colleagues, I am continuing to work on how the U.S. and allies
can collectively defend with cyber and emerging technologies in the maritime and the greater
global environment. Happy to talk to you. Well, thank you again for joining us. To the listeners,
thanks for tuning in. We'll see you next time.
We'll be right back.
We'll be right back.
