Physics-aware targeted attacks against maritime industrial control systems

Giacomo Longo,Francesco Lupia,Andrea Pugliese,Enrico Russo
DOI: https://doi.org/10.1016/j.jisa.2024.103724
IF: 4.96
2024-05-01
Journal of Information Security and Applications
Abstract:The advancement of the maritime industry towards technologically integrated and automated systems has significantly increased the complexity of onboard Industrial Control Systems (ICS), raising concerns about cybersecurity risks. In this paper, we examine typical onboard ICS configurations through an adversarial lens. We introduce a threat model that leverages domain-specific peculiarities, e.g., maritime protocols, and targets vulnerability vectors to execute software attacks against the infrastructures of shipboard ICS. This includes a case study on a critical subsystem of ship machinery: the steering gear system. We have developed a novel attack methodology intended for use by targeted malware. A comprehensive experimental assessment confirms the feasibility of attacks devised according to our methodology.
computer science, information systems
What problem does this paper attempt to address?