The NMEA 2000 Bus: Insecure by Design

▶ Watch (4:43)

The NMEA 2000 protocol uses Controller Area Network with two wires, CAN high and CAN low. It uses dominant and recessive bits terminated by two resistors. CAN interfaces are not authenticated. They are built into almost everything, from excavators to GPS head units. The bus is a public forum where any device can talk. NMEA 2000 is based on ISO 11783 and compatible with J1939. Despite widespread use, published research on the protocol is scarce. Hardware remains expensive, limiting academic access.

Building a Deterministic Fingerprint

▶ Watch (7:22)

The team built a physical test system with three devices and five nodes: a wind sensor, weather station, Maratron head unit, and Garmin chart plotter. They used a Saleae logic analyzer to collect CAN frames. Anissa created a software pipeline that extracts the Parameter Group Number from the CAN header by parsing the reserve bit, data page bit, PDU field, and PDU specific. The pipeline converts hex headers to binary, applies bitshifts for PDU specific above 240, and outputs a decimal PGN. Source address is extracted similarly.

The Dashboard and Anomaly Detection

▶ Watch (18:16)

The dashboard displays a system map, device inventory, PGN frequency per device, and a PGN monitor. After baselining, a new run triggers alerts. Unknown devices appear in a block. New PGNs and device combinations are listed. Frequency anomalies are flagged when the measured frequency deviates more than 85% from the baseline. The team demonstrated with a pre-recorded analysis showing new PGNs, unknown devices, and frequency changes. The dashboard provides a deterministic way to detect deviations from normal bus behavior.

Next Steps: Analog Analysis and Inline Protection

▶ Watch (21:10)

Constantine outlined next steps: performing analog analysis on the electrical characteristics of CAN bits. The analog data is 2,000 times larger than the digital data. Changes in bus voltage levels could indicate tampering. After baselining, they aim to detect anomalies and then implement inline protection. The goal is to prevent bad packets from reaching the bus. They also discussed enabling out-of-band communication and encryption as a future add-on to the unauthenticated CAN bus.

Q&A

Can the fingerprinting system be installed as a drop-in device? Yes, initially as a passive listener, later an inline device that can block or modify traffic. ▶ 23:34

Has there been any suspicion into the need for unauthenticated unencrypted? The team considers the bus a public forum and plans to enable out-of-band encryption as a future add-on. ▶ 24:13

Notable Quotes

It is not authenticated. It is uh built into almost everything. Constantine Macris · ▶ 5:06

there’s not a lot of published research on this Constantine Macris · ▶ 6:54

the measurement for the depth under your keel could be a problem Constantine Macris · ▶ 10:14

we will be able to say, hey, this network is now different Constantine Macris · ▶ 22:20

Key Takeaways

  • Deterministic fingerprinting uses device inventory, PGN frequency, and topology.
  • Unknown devices or PGNs trigger alerts with an 85% frequency change threshold.
  • Future work includes analog signal analysis and inline protection for the CAN bus.

About the Speaker(s)

Constantine Macris is a Connecticut native and pursuing a PhD at the URI. He is a reserve CDR in the Navy, industry expert in OT and network security and CISO at Dispel.