The Problem: Students Can’t See the Ship
Undergraduate cybersecurity students lack maritime domain knowledge. Without it, they cannot attack or defend a ship. Ship access is limited due to port security and insurance. Greer initiated a joint study with Unitest Marine to develop a virtual environment. UNC Wilmington has a center for cyber defense education and specialized maritime classes. The study aims to create a world-class platform for teaching maritime cyber security.
The Simulator: A Container Ship With 20 Subsystems
The Unitest X92 simulator models a container ship as an apex system with 20 subsystems. It includes a bridge, diesel generator, emergency main engine, and steering gear. The 3D model shows a Winther gas and diesel 10-cylinder two-cycle engine. The simulator has detailed deck plans and control diagrams. It is designed for training merchant seaman to STCW code standards. The simulator’s fault library contains no cyber-related faults.
Gaps: No Full Ship, No Network Diagrams, No Cyber Faults
Preliminary study results identified three functional gaps. First, the X92 is not a full ship simulator. A complete bridge and below-waterline systems are missing. Second, the control diagrams are useful but not practical for cyber security. A network diagram and digital logic controllers are needed. Third, the simulator fault library has no cyber-related items. These gaps affect all three use cases: domain knowledge, security by design, and incident response.
Phase Two: Bridging Synthetic and Physical Worlds
Phase two will integrate the Unitest X92 simulator with other systems. Greer plans to link it with a Nautis bridge simulator or other simulators to create a full ship environment. Alternatively, he can integrate the synthetic ship with physical test beds, including industrial controllers and network simulators. This will create a hybrid range. Completion is targeted for spring 2026. The people in Poland are excited for the results.
System Engineering Methods for Maritime Cyber Security
Greer advocates model-based system of systems engineering for cybersecurity. He developed six methods. The “eyebox” method draws an imaginary box around the vessel. Anything breaking the plane is an attack vector. System Operational Dependency Analysis (SODA) examines coupling mechanisms like network and software. Criticality analysis defines mission-critical systems. Cyber hazard loss analysis uses STPA adapted by Dr. William Young. This informs risk management strategy design.
Q&A
Will slides be available? Email Jeff Greer at greerj@uncw.edu for the slides. ▶ 21:10
How do you manage security integration across three network types? A holistic approach is needed because people often focus on single components. ▶ 21:39
Is it the manufacturer’s responsibility to build training devices? No, the simulators are separate; Greer is looking at simulators that parallel the work tools to make this all work. ▶ 22:23
Notable Quotes
Undergraduate students do not have a maritime uh domain knowledge. Jeff Greer · ▶ 0:35
It’s not a full ship simulator. Jeff Greer · ▶ 10:32
the simulator fault library does not include any cyber related items Jeff Greer · ▶ 11:25
Each ship has three different types of networks at least, right? Jeff Greer · ▶ 21:39
Key Takeaways
- Unitest X92 simulator lacks full ship coverage, network diagrams, and cyber faults for cybersecurity education.
- Greer’s phase two will integrate multiple simulators and physical test beds by spring 2026.
- Model-based system of systems engineering methods like SODA and eyebox analysis are essential for maritime cyber security.
About the Speaker(s)
Jeff Greer is an Assistant Professor of Practice in Cybersecurity at the University of North Carolina Wilmington. When not teaching he is reading, writing, and coding. The focus of his applied R&D work is the application of system-of-systems engineering practices to resolve maritime cybersecurity problems. Prior to retiring from corporate life, Jeff was an integral part of an executive team that built a mobile broadband business delivering internet services to ships at sea around the world. Jeff is a member of the USCG Sector 5 Area Maritime Security Council and the FBI Infragard program. Jeff holds an MS Degree in Cybersecurity Technology from the University of Maryland Global Campus.
Laavanya Rachakonda is an Assistant Professor in the Department of Computer Science at the University of North Carolina Wilmington since August 2021. She earned her Ph.D. and M.S. in Computer Science and Engineering under Dr. Saraju P. Mohanty at the University of North Texas in 2021. As Founder and Director of the Smart and Intelligent Physical Systems Laboratory (SIPS) at UNCW, she leads research in Machine Learning, AI, IoT, and IoMT for smart healthcare, agriculture, transportation, and smart living, with a focus on security and privacy.