<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">gumrf</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник Государственного университета морского и речного флота имени адмирала С. О. Макарова</journal-title><trans-title-group xml:lang="en"><trans-title>Vestnik Gosudarstvennogo universiteta morskogo i rechnogo flota imeni admirala S. O. Makarova</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2309-5180</issn><issn pub-type="epub">2500-0551</issn><publisher><publisher-name>ФГБОУ ВО «Государственный университет морского и речного флота имени адмирала С.О. Макарова»</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.21821/2309-5180-2025-17-5-641-652</article-id><article-id custom-type="edn" pub-id-type="custom">DKQYLH</article-id><article-id custom-type="elpub" pub-id-type="custom">gumrf-634</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>ЭКСПЛУАТАЦИЯ ВОДНОГО ТРАНСПОРТА, ВОДНЫЕ ПУТИ СООБЩЕНИЯ И ГИДРОГРАФИЯ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>OPERATION OF WATER TRANSPORT, WATERWAYS AND HYDROGRAPHY</subject></subj-group></article-categories><title-group><article-title>Модели кибератак на сеть автоматической идентификационной системы</article-title><trans-title-group xml:lang="en"><trans-title>Models of cyberattacks on the automatic identification system network</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Волков</surname><given-names>В. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Volkov</surname><given-names>V. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Волков Василий Владимирович — ведущий инженер-разработчик.</p><p>198035, Санкт-Петербург, ул. Двинская, д. 12</p></bio><bio xml:lang="en"><p>Vasily V Volkov — Lead Design Engineer, Scientific and Production Firm “Marinek” LLC.</p><p>12 Dvinskaya Str., St. Petersburg 198035</p></bio><email xlink:type="simple">vasekama160599@yandex.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Ольховик</surname><given-names>Е. О.</given-names></name><name name-style="western" xml:lang="en"><surname>Ol’khovik</surname><given-names>E. O.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Ольховик Евгений Олегович — доктор технических наук, профессор.</p><p>198035, Санкт-Петербург, ул. Двинская, 5/7</p></bio><bio xml:lang="en"><p>Evgeniy O. Ol’khovik — Grand PhD in Technical Sciences, professor Admiral Makarov State University of Maritime and Inland Shipping.</p><p>5/7 Dvinskaya Str., St. Petersburg 198035</p></bio><email xlink:type="simple">olhovikeo@gumrf.ru</email><xref ref-type="aff" rid="aff-2"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Федосенко</surname><given-names>Ю. С.</given-names></name><name name-style="western" xml:lang="en"><surname>Fedosenko</surname><given-names>Yu. S.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Федосенко Юрий Семенович — доктор технических наук, профессор, заведующий кафедрой «Систем информационной безопасности, управления и телекоммуникаций».</p><p>603950, Нижний Новгород, ул. Нестерова, 5а</p></bio><bio xml:lang="en"><p>Yuriy S. Fedosenko — Grand PhD in Technical Sciences, Professor, Head of the Department «Systems of Information Security Systems, Control and Telecommunications»” Volga State University of Water Transport.</p><p>Nesterova St., 5а, Nizhniy Novgorod, 603950</p></bio><email xlink:type="simple">fds1707@mail.ru</email><xref ref-type="aff" rid="aff-3"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>ОО «НПФ Маринэк»</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Scientific and Production Firm «Marinek» LLC</institution><country>Russian Federation</country></aff></aff-alternatives><aff-alternatives id="aff-2"><aff xml:lang="ru"><institution>ФГБОУ ВО «ГУМРФ имени адмирала С.О. Макарова»</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Admiral Makarov State University of Maritime and Inland Shipping</institution><country>Russian Federation</country></aff></aff-alternatives><aff-alternatives id="aff-3"><aff xml:lang="ru"><institution>ГБОУ ВО «Волжский государственный университет водного транспорта»</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Volga State University of Water Transport</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2025</year></pub-date><pub-date pub-type="epub"><day>06</day><month>12</month><year>2025</year></pub-date><volume>17</volume><issue>5</issue><fpage>641</fpage><lpage>652</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Волков В.В., Ольховик Е.О., Федосенко Ю.С., 2025</copyright-statement><copyright-year>2025</copyright-year><copyright-holder xml:lang="ru">Волков В.В., Ольховик Е.О., Федосенко Ю.С.</copyright-holder><copyright-holder xml:lang="en">Volkov V.V., Ol’khovik E.O., Fedosenko Y.S.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://journal.gumrf.ru/jour/article/view/634">https://journal.gumrf.ru/jour/article/view/634</self-uri><abstract><p>В исследовании рассмотрены случаи киберугроз в сети морской автоматической идентификационной системы. Обзор данных о выявленных уязвимостях автоматической идентификационной системы показал отсутствие качественно формализованного описания и классификации угроз, так как в настоящее время предлагаемые сценарные модели атак не покрывают весь их возможный спектр, а подходы к обеспечению кибербезопасности АИС (организационные и технические меры) сводятся к сценариям информационной безопасности непосредственно на судне. Предложено пять независимых моделей внешних атак на АИС — типовые уровни киберугрозы от низкого (единичная подделка сигнала) до высокого (комбинированная многоэтапная атака с использованием нескольких методов). Помимо внешних угроз в ходе исследования рассмотрены внутренние угрозы, связанные с проникновением в компьютерную сеть судна с последующим негативным воздействием. Эти результаты вынесены на отдельное обсуждение, поскольку требуют особого подхода и проработки. Предложены новые подходы и рекомендации к защите. Отмечается, что противодействие киберугрозам для АИС требует сочетания организационных и технических мер. Условно они разделены на программно-алгоритмические и аппаратно-архитектурные. К первым относятся методы, улучшающие протокол и программное обеспечение: аутентификация и шифрование АИС-сообщений, фильтрация аномалий, системы обнаружения атак. Обращается внимание на то, что альтернативным направлением является разработка алгоритмов выявления поддельных данных АИС, предусматривающая предварительное создание дополнительных систем мониторинга, которые могут непрерывно анализировать поступающие данные признаков аномалий: отсутствие предыдущего маршрута движения, нелогичные маневры, дублирование, рассинхронизацию с радиолокацией и т. п. Дан прогноз обеспечения кибербезопасности сетей АИС, предусматривающий создание более подробных правил и руководств классификационных обществ, а также разработку дополнительного программного обеспечения и технических средств как непосредственно на судне, так и в береговых центрах (например, в системах управления движением судов).</p></abstract><trans-abstract xml:lang="en"><p>The study examines cyber threats within the network of the maritime Automatic Identification System (AIS). A review of available data on identified AIS vulnerabilities has shown a lack of a well-structured formal description and classification of threats. At present, the existing scenario-based attack models do not encompass the full spectrum of possible threats, while most approaches to AIS cybersecurity — both organizational and technical — are limited to information-security measures implemented directly on board the vessel. Five independent models of external attacks on AIS are proposed, representing typical levels of cyber threats ranging from low (single-signal spoofing) to high (combined multistage attacks employing several methods). In addition to external threats, the study also considers internal threats related to unauthorized penetration into the ship’s computer network followed by destructive actions. These cases are discussed separately, as they require specific methods of analysis and mitigation. New approaches and recommendations for AIS protection are proposed. Counteracting cyber threats requires a balanced combination of organizational and technical measures, conventionally divided into software-algorithmic and hardware-architectural categories. The former includes methods for improving the AIS protocol and software, such as message authentication and encryption, anomaly filtering, and intrusion detection systems. Another important direction involves the development of algorithms for detecting falsified AIS data. This requires the creation of additional monitoring systems capable of continuously analyzing incoming information for signs of anomalies, such as the absence of a previous route, illogical maneuvers, data duplication, or desynchronization with radar observations. Future AIS cybersecurity is expected to rely on more detailed regulations and guidelines issued by classification societies, as well as on enhanced software and hardware solutions implemented both on board vessels and in shore-based centers, such as Vessel Traffic Management Systems (VTMS).</p></trans-abstract><kwd-group xml:lang="ru"><kwd>автоматическая идентификационная система</kwd><kwd>кибербезопасность</kwd><kwd>киберугрозы</kwd><kwd>модели угроз</kwd><kwd>безопасность судоходства</kwd><kwd>морской терроризм</kwd><kwd>идентификация судов</kwd><kwd>шифрование сообщений</kwd><kwd>киберриски</kwd><kwd>спуфинг</kwd></kwd-group><kwd-group xml:lang="en"><kwd>Automatic Identification System (AIS)</kwd><kwd>cybersecurity</kwd><kwd>cyber threats</kwd><kwd>threat modeling</kwd><kwd>maritime safety</kwd><kwd>maritime terrorism</kwd><kwd>vessel identification</kwd><kwd>message encryption</kwd><kwd>cyber risks</kwd><kwd>spoofing</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">IMO. Resolution MSC.428(98). Maritime Cyber Risk Management in Safety Management Systems. 2017. [Электронный ресурс]. — Режим доступа: https://wwwcdn.imo.org/localresources/en/OurWork/Security/Documents/Resolution%20MSC.428(98).pdf (дата обращения: 27.08.2025).</mixed-citation><mixed-citation xml:lang="en">IMO. Resolution MSC.428(98). Maritime Cyber Risk Management in Safety Management Systems. 2017. Web. 27 Aug. 2025 https://wwwcdn.imo.org/localresources/en/OurWork/Security/Documents/Resolution%20MSC.428(98).pdf.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">IALA. Guideline 1082 — An Overview of АИС, Ed. 2.0. Saint-Germain-en-Laye, France: IALA, June 2016. [Электронный ресурс]. — Режим доступа: https://navcen.uscg.gov/sites/default/files/pdf/IALA_Guideline_1082_An_Overview_of_АИС.pdf (дата обращения: 27.08.2025).</mixed-citation><mixed-citation xml:lang="en">IALA. Guideline 1082 — An Overview of АИС, Ed. 2.0. Saint-Germain-en-Laye, France: IALA, June 2016. Web. 27 Aug. 2025 https://navcen.uscg.gov/sites/default/files/pdf/IALA_Guideline_1082_An_Overview_of_АИС.pdf.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">IEC. International Standard IEC 61162–450:2018. Maritime navigation and radiocommunication equipment and systems — Digital interfaces — Part 450: Multiple talkers and multiple listeners — Ethernet interconnection (Lightweight Ethernet). — Geneva: IEC, 2018. — 84 p.</mixed-citation><mixed-citation xml:lang="en">IEC. International Standard IEC 61162–450:2018. Maritime navigation and radiocommunication equipment and systems — Digital interfaces — Part 450: Multiple talkers and multiple listeners — Ethernet interconnection (Lightweight Ethernet). Geneva: IEC, 2018.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">IEC. International Standard IEC 61162–460:2015. Maritime navigation and radiocommunication equipment and systems — Digital interfaces — Part 460: Multiple talkers and multiple listeners — Ethernet interconnection — Safety and Security (Security gateway). — Geneva: IEC, 2015. — 62 p.</mixed-citation><mixed-citation xml:lang="en">IEC. International Standard IEC 61162–460:2015. Maritime navigation and radiocommunication equipment and systems — Digital interfaces — Part 460: Multiple talkers and multiple listeners — Ethernet interconnection — Safety and Security (Security gateway). Geneva: IEC, 2015.</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Storm D. Hack in the Box: Researchers attack ship tracking systems for fun and profit [Электронный ресурс]. — Режим доступа: https://www.computerworld.com/article/2500102/hack-in-the-box—researchers-attack-ship-tracking-systems-for-fun-and-profit.html (дата обращения: 27.08.2025).</mixed-citation><mixed-citation xml:lang="en">Storm D. Hack in the Box: Researchers attack ship tracking systems for fun and profit Web. 27 Aug. 2025 https://www.computerworld.com/article/2500102/hack-in-the-box—researchers-attack-ship-tracking-systems-for-fun-and-profit.html.</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Семёнов С. А. Сетевая угроза: как защитить морские суда от кибератак? // Транспортная безопасность и технологии. — 2018. — № 2(53). — С. 86–91.</mixed-citation><mixed-citation xml:lang="en">Semyonov, S.A. “Setevaya ugroza: kak zashchitit’ morskie suda ot kiberatak? “ Transportnaya bezopasnost’ i tekhnologii 2(53). (2018): 86–91.</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Антипов А. Возможные угрозы для морского судоходства, исходящие от взломанной системы АИС SecurityLab. [Электронный ресурс]. — Режим доступа: https://www.securitylab.ru/analytics/497745.php (дата обращения: 27.08.2025).</mixed-citation><mixed-citation xml:lang="en">Antipov A. Vozmozhnye ugrozy dlya morskogo sudohodstva, iskhodyashchie ot vzlomannoj sistemy AIS. SecurityLab. Web. 27 Aug. 2025 https://www.securitylab.ru/analytics/497745.php.</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Kessler G. C. AIS Spoofing: A Tutorial for Researchers / G. C. Kessler, D. M. Zorri // 2024 IEEE 49th Conference on Local Computer Networks (LCN) — 2024. — С. 1–7. DOI: 10.1109/LCN60385.2024.10639747.</mixed-citation><mixed-citation xml:lang="en">Kessler, G. C. and D. M. Zorri. “AIS Spoofing: A Tutorial for Researchers.” 2024 IEEE 49th Conference on Local Computer Networks (LCN) — 2024: 1–7. DOI: 10.1109/LCN60385.2024.10639747.</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Oruc A. Perspectives on the Cybersecurity of the Integrated Navigation System / A. Oruc, G. Kavallieratos, V. Gkioulos, S. Katsikas // Journal of Marine Science and Engineering. — 2025. — Vol. 13. — Is. 6. — P. 1087. DOI: 10.3390/jmse13061087.</mixed-citation><mixed-citation xml:lang="en">Oruc, A., G. Kavallieratos, V. Gkioulos and S. Katsikas. “Perspectives on the Cybersecurity of the Integrated Navigation System.” Journal of Marine Science and Engineering 13.6 (2025): 1087. DOI: 10.3390/jmse13061087.</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Munro K. Ships can’t be hacked. Wrong. Pen Test Partners Blog. [Электронный ресурс]. Режим доступа: https://www.pentestpartners.com/security-blog/ships-cant-be-hacked-wrong/ (дата обращения: 27.08.2025).</mixed-citation><mixed-citation xml:lang="en">Munro K. Ships can’t be hacked. Wrong. Pen Test Partners Blog. Web. 27 Aug. 2025 https://www.pen-testpartners.com/security-blog/ships-cant-be-hacked-wrong/.</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Hemminghaus C. BRAT: a BRIDGe attack tool for cyber security assessments of maritime systems / C. Hemminghaus, J. Bauer, E. Padilla // TransNav the International Journal on Marine Navigation and Safety of Sea Transportation. — 2021. — Т. 15. — № 1. — С. 35–44. DOI: 10.12716/1001.15.01.02.</mixed-citation><mixed-citation xml:lang="en">Hemminghaus, C., J. Bauer and E. Padilla. “BRAT: a BRIDGe attack tool for cyber security assessments of maritime systems.” TransNav the International Journal on Marine Navigation and Safety of Sea Transportation 15.1 (2021): 35–44. DOI: 10.12716/1001.15.01.02.</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Harish A. V. Literature review of maritime cyber security: The first decade / A. V. Harish, K. Tam, K. Jones // Maritime Technology and Research. — 2024. — Vol. 7. — Is. 2. — Pp. 273805. DOI: 10.33175/mtr.2025.273805.</mixed-citation><mixed-citation xml:lang="en">Harish, A. V., K. Tam and K. Jones. “Literature review of maritime cyber security: The first decade.” Maritime Technology and Research 7.2 (2024): 273805. DOI: 10.33175/mtr.2025.273805.</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">Смоленцев С. В. Проблемы использования сообщений автоматической идентификационной системы в задаче прогнозирования траекторий движения судов / С. В. Смоленцев, Д. В. Исаков, М. Б. Солодовниченко // Вестник государственного университета морского и речного флота имени адмирала С. О. Макарова. — 2025. — Т. 17. — № 2. — С. 163–174. DOI: 10.21821/2309-5180-2025-17-2-163-174. — EDN AYBTLM.</mixed-citation><mixed-citation xml:lang="en">Smolentsev, S. V., D. V. Isakov and M. B. Solodovnichenko. “Problems of using automatic identification system messages in the task of forecasting vessel movement trajectories.” Vestnik gosudarstvennogo universiteta morskogo i rechnogo flota im. admirala S. O. Makarova 17.2 (2025): 163–174. DOI: 10.21821/2309-5180-2025-17-2-163-174.</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">Smolentsev S. V. Algorithm for analyzing the automatic identification system data to identify typical scenarios for vessel divergence and testing the systems of autonomous shipping / S. V. Smolentsev, A. A. Butsanets, S. F. Shakhnov, A. P. Nyrkov, E. O. Ol’khovik // T-Comm. — 2024. — Vol. 18. — Is. 3. — Pp. 50–59. DOI: 10.36724/2072-8735-2024-18-3-50-59.</mixed-citation><mixed-citation xml:lang="en">Smolentsev, S. V., E. O. Ol’khovik, et al. “ Algorithm for analyzing the automatic identification system data to identify typical scenarios for vessel divergence and testing the systems of autonomous shipping.” T-Comm 18.3 (2024): 50–59. DOI: 10.36724/2072-8735-2024-18-3-50-59.</mixed-citation></citation-alternatives></ref><ref id="cit15"><label>15</label><citation-alternatives><mixed-citation xml:lang="ru">Ol’khovik E. Assessment of the Possibility of Using a Waterway for Operation of Autonomous Ships / E. Ol’khovik, A. Butsanets, A. Zhidkova // Transportation Research Procedia. — 2023. — Vol. 68. — Pp. 383–388. DOI: 10.1016/j.trpro.2023.02.051.</mixed-citation><mixed-citation xml:lang="en">Ol’khovik, E., A. Butsanets and A. Zhidkova. “Assessment of the Possibility of Using a Waterway for Operation of Autonomous Ships.” Transportation Research Procedia 68 (2023): 383–388. DOI: 10.1016/j.trpro.2023.02.051.</mixed-citation></citation-alternatives></ref><ref id="cit16"><label>16</label><citation-alternatives><mixed-citation xml:lang="ru">The Guidelines for Formal Safety Assessment (FSA) for use in the IMO rule-making process. London: IMO, 2018 — 71 p.</mixed-citation><mixed-citation xml:lang="en">The Guidelines for Formal Safety Assessment (FSA) for use in the IMO rule-making process. London: IMO, 2018.</mixed-citation></citation-alternatives></ref><ref id="cit17"><label>17</label><citation-alternatives><mixed-citation xml:lang="ru">Руководство по обеспечению кибербезопасности. НД № 2–030101–040. — Санкт-Петербург: ФАУ «Российский морской регистр судоходства», 2021. — 46 c.</mixed-citation><mixed-citation xml:lang="en">Rukovodstvo po obespecheniyu kiberbezopasnosti. ND № 2–030101–040. Saint-Petersburg: FAU «Rossijskij morskoj registr sudohodstva», 2021.</mixed-citation></citation-alternatives></ref><ref id="cit18"><label>18</label><citation-alternatives><mixed-citation xml:lang="ru">Правила классификации и постройки морских судов, часть XXI: Киберустойчивость. НД № 2–020101–174. — Санкт-Петербург: ФАУ «Российский морской регистр судоходства», 2025. — 74 c.</mixed-citation><mixed-citation xml:lang="en">Pravila klassifikacii i postrojki morskih sudov, chast’ XXI «Kiberustojchivost’». ND № 2–020101–174. Saint-Petersburg: FAU «Rossijskij morskoj registr sudohodstva», 2025.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
