Maritime Comms Challenges and Vulnerabilities

▶ Watch (3:44)

Ships rely on AIS, GPS, VSAT, and ECIS plotting software. AIS has no built-in authentication. Attackers inject fake ship positions. GPS can be jammed or spoofed, dragging a vessel off course. VSAT systems ship with weak default credentials. ECIS, the bridge plotting software, is sometimes updated via IT networks, creating an entry point from non-bridge systems. These vulnerabilities compound with legacy hardware that cannot meet growing bandwidth demands from IoT and unmanned platforms.

SDR and SDN Advantages

▶ Watch (5:58)

Software-defined radios move signal processing from fixed hardware to software running on general-purpose CPUs or FPGAs. A single SDR board replaces a rack of single-purpose radios – HF, VHF, UHF, satellite modems, tactical receivers, even radar processors. This reduces physical footprint on submarines and unmanned platforms where real estate is tight. Software-defined networks decouple the control plane from the data plane. A central SDN controller handles routing, bandwidth allocation, and policy enforcement across all vessels.

Unified Framework: SDR + SDN + Satcom

▶ Watch (10:03)

The proposed framework combines SDR waveform agility, SDN network intelligence, and existing satellite infrastructure. SDR enables dynamic frequency tuning, adaptive modulation and coding, and cognitive spectrum sensing. SDN provides dynamic path selection, traffic prioritization, and centralized fleet-wide monitoring. Together they allow seamless link failover – for example, switching from a congested geosynchronous satellite to a low-earth-orbit satellite without dropping sessions.

Carrier Strike Group Use Case

▶ Watch (15:38)

In a typical carrier strike group each surface ship has its own satcom pipe – 200 to 500 kbps for small ships, 4 to 8 Mbps for the carrier. The SDN reroutes all traffic through the carrier, which caches frequently requested data (weather reports, situational updates) to avoid re-requests over satellite. Inter-vessel links use line-of-sight connections (25-30 km) with multi-hop routing. A geosynchronous satellite round-trip time is 552 ms. An inter-vessel link is 0.17 ms – over 3,000 times faster.

Security Mitigation and Conclusions

▶ Watch (22:15)

The SDN controller applies policies to filter AIS data that shows physically impossible tracks, preventing fake targets from reaching bridge repeaters. Multiple sensors reduce reliance on a single GPS signal. VSAT integrated into the SDN receives session authentication and encryption. Network segmentation isolates ECIS chart updates from administrative traffic. The speakers acknowledge this is theoretical and estimate a 10-year timeline for Navy adoption. Next steps are simulation-based evaluation, followed by a prototype testbed.

Notable Quotes

AIS doesn’t have any built-in authentication that lets people um inject phase targets or positions or or spoof things on that. AviNash Srinivasan · ▶ 3:52

the roundtrip time we are looking at is approximately 0.17 milliseconds AviNash Srinivasan · ▶ 18:51

it’s going to be like a 10-year program for the Navy to kind of move in this direction AviNash Srinivasan · ▶ 23:33

Key Takeaways

  • SDR and SDN can replace racks of single-purpose radios with a single programmable platform.
  • Inter-vessel links achieve 0.17 ms latency vs 552 ms for geosynchronous satcom.
  • SDN policy enforcement can mitigate AIS spoofing, GPS jamming, and VSAT default credential attacks.

About the Speaker(s)

Dr. Avinash Srinivasan is an Associate Professor in the Cyber Science department at the United States Naval Academy. He holds a Ph.D. and a Master’s in Computer Science, and a Bachelor’s in Industrial Engineering. His research interests span the broad areas of cybersecurity and forensics. In particular, his research focuses on network security and forensics, security and forensics in cyber physical systems, and critical infrastructure, steganography and information hiding, cloud computing forensics challenges, and privacy and anonymity. Dr. Srinivasan has administered several grants from agencies including DoD/Navy, NSF, DoJ, DHS, and DoEd. He has published 55 papers in prestigious refereed conferences and journals including IEEE Transactions on Information Forensics and Security, INFOCOM, ICDCS, and ACM SAC. Dr. Srinivasan also holds a patent (Patent number: 11210396). He currently serves on the editorial board for IEEE Transactions on Cognitive Communications and Networking as an Associate Editor. Dr. Srinivasan is a Certified Ethical Hacker (CEH) and Computer Hacking Forensics Investigator (CHFI). He has trained civilians as well as local and state law enforcement personnel in the areas of Macintosh Forensics and Network Forensics.