Live data from Hacker News

Ships fooled in GPS spoofing attack suggest Russian cyberweapon

newscientist.com

21–30 of 78 posts

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#21
post #6

many NATO guided bombs, missiles and drones rely on GPS navigation There are separate code sets for civilian and military GPS, and the latter should only be availability to US military equipment manufacturers. What I wonder is whether that means some NATO equipment will be misdirected by spoofing attacks and other will not, or if the attackers actually are able to spoof both types of signal.

I don't know that any military equipment relies on GPS. They use it preferentially, but have other things they can fall back to. JDAMs, for example, have an inertial navigation system in addition to GPS. I'm sure that these weapons have the ability to detect spoofing by seeing that GPS is diverging significantly from the INS output. The weapon is less accurate without GPS so spoofing (or just plain jamming) could be used to reduce its accuracy somewhat, but probably couldn't be used to make it hit a completely different target.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#22

Where is the proof that Russia is behind all this?

On the map probably. If you wanted to do this, it wouldn't be handy to do it in a country or for a country that actively scans for radio spoofing, jamming or illegal use of radio bands. Considering that out of all the countries nearby only one or two would have the means it's not hard to figure out would would want to do this.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#23

Earlier quoted context omitted.

> if the attackers actually are able to spoof both types of signal. Interestingly, the military GPS signal is encrypted using what is called the A/S "anti-spoof" code. Which was deployed in the '70s. So you know they've been thinking about it for quite some time. Practically speaking: Assuming one can shield the spoofer receiver from its own transmitter there's no real reason why a spoofer can't set up a receiver at…

Is this really possible? I don't know much technical details about GPS, but I thought a large component was time-based. If my understanding is correct, wouldn't rebroadcasting fail because the times didn't match correctly?

The question is: match with what?

Part of the GPS calculation is to figure out what time it is. There is no reference needed other than what the satellites broadcast. If you are rebroadcasting the entire GPS signal it includes all of the satellites, and will be self-consistent.

Also, in the case of a rebroadcast it need not be delayed by more than something on the order of a microsecond or so.

If the receiver has some sort of out-of-channel time reference that is accurate to nanosecond levels I suppose that could be used as a check, but that sort of thing takes an atomic clock and doesn't fit in a wristwatch.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#24

This is fairly old news. Reports are a year or two old and suggest that Russian security uses GPS spoofing anywhere V. Putin may be located, presumably as a defense against drone type attacks or surveillance. The spoofed location is often an airport. The black sea spoofing could be related to a visit to e.g., Sochi. Alternatively Russia could be deploying the spoofers on ships now, which would seem to have offensive…

Sounds like a semi-reliable Putin Detector could be set up if you wanted to...

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#25

Earlier quoted context omitted.

> if the attackers actually are able to spoof both types of signal. Interestingly, the military GPS signal is encrypted using what is called the A/S "anti-spoof" code. Which was deployed in the '70s. So you know they've been thinking about it for quite some time. Practically speaking: Assuming one can shield the spoofer receiver from its own transmitter there's no real reason why a spoofer can't set up a receiver at…

Is this really possible? I don't know much technical details about GPS, but I thought a large component was time-based. If my understanding is correct, wouldn't rebroadcasting fail because the times didn't match correctly?

>Is this really possible? I don't know much technical details about GPS, but I thought a large component was time-based.

Yes, it's possible mostly because you can drown out the weak signals coming from satellites with much stronger terrestrial ones.

There is also a new generation of GPS planned that will help mitigate future attacks, but it's getting delayed like crazy: https://en.wikipedia.org/wiki/GPS_Block_IIIA

Also, see this article on how it's technically feasible: https://media.defcon.org/DEF%20CON%2023/DEF%20CON%2023%20pre...

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#26
post #6

many NATO guided bombs, missiles and drones rely on GPS navigation There are separate code sets for civilian and military GPS, and the latter should only be availability to US military equipment manufacturers. What I wonder is whether that means some NATO equipment will be misdirected by spoofing attacks and other will not, or if the attackers actually are able to spoof both types of signal.

> if the attackers actually are able to spoof both types of signal. Interestingly, the military GPS signal is encrypted using what is called the A/S "anti-spoof" code. Which was deployed in the '70s. So you know they've been thinking about it for quite some time. Practically speaking: Assuming one can shield the spoofer receiver from its own transmitter there's no real reason why a spoofer can't set up a receiver at…

>there's no real reason why a spoofer can't set up a receiver at one location and rebroadcast the encrypted signal as received there

I can't really see this working if you have an inertial navigation backup system. It would be easy to detect the large error in GPS position and just ignore the GPS.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#27

Earlier quoted context omitted.

> if the attackers actually are able to spoof both types of signal. Interestingly, the military GPS signal is encrypted using what is called the A/S "anti-spoof" code. Which was deployed in the '70s. So you know they've been thinking about it for quite some time. Practically speaking: Assuming one can shield the spoofer receiver from its own transmitter there's no real reason why a spoofer can't set up a receiver at…

Is this really possible? I don't know much technical details about GPS, but I thought a large component was time-based. If my understanding is correct, wouldn't rebroadcasting fail because the times didn't match correctly?

At its core, GPS works by having each satellite continually broadcast the current time. By observing the time-of-flight differences from multiple satellites (at least 4), the receiver can then compute its position and the current time.

There's a lot more to it, of course, in terms of how it's encoded and how you know where the satellites are and such, but that's the basic principle.

Note that the receiver itself doesn't know what time it is until it gets a position lock from the satellites. Receivers can have onboard clocks, which helps them calculate their position and the time more quickly than starting up with no idea of the time at all, but it's just a helper, not a requirement. Even if you have one, the onboard clock will necessarily be much less accurate than the ones on the GPS satellites, so any (reasonable) delta will be assumed to be clock drift, not spoofing.

So, if I set up a receiver at point A, then rebroadcast the signals I receive to your receiver at point B, and your receiver is blocked from getting the true signals at B, your receiver will think it's at point A. It will also think that the current time is behind, by whatever the rebroadcasting delay is, but it won't have any way of knowing that's wrong.

As far as mitigation goes, if your receiver was running before the spoof signal started to arrive then you could easily notice that things had suddenly gone crazy. I think military equipment that depends on GPS also has backup inertial navigation systems which would quickly show any divergence, and allow it to continue without GPS input (albeit at reduced accuracy).

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#28
That is laughable and doesn't provide any kind of military utility. What is the value of spoofing GPS by putting everyone into the same point, with zero inferred velocity and acceleration vectors, while other data sources like inertial will easily tell the supposed victim this is all wrong?

Also, M-code can't be affected this way because it is encrypted, and military grade GPS receivers use virtual directed beams so they are next to impossible to simply jam, either.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#29

Earlier quoted context omitted.

> if the attackers actually are able to spoof both types of signal. Interestingly, the military GPS signal is encrypted using what is called the A/S "anti-spoof" code. Which was deployed in the '70s. So you know they've been thinking about it for quite some time. Practically speaking: Assuming one can shield the spoofer receiver from its own transmitter there's no real reason why a spoofer can't set up a receiver at…

>there's no real reason why a spoofer can't set up a receiver at one location and rebroadcast the encrypted signal as received there I can't really see this working if you have an inertial navigation backup system. It would be easy to detect the large error in GPS position and just ignore the GPS.

You'll need two alternatives to GPS to be able to tell whether it's a malfunction in GPS, or the inertial nav. e-loran is such a third alternative.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#30
post #6

many NATO guided bombs, missiles and drones rely on GPS navigation There are separate code sets for civilian and military GPS, and the latter should only be availability to US military equipment manufacturers. What I wonder is whether that means some NATO equipment will be misdirected by spoofing attacks and other will not, or if the attackers actually are able to spoof both types of signal.

> if the attackers actually are able to spoof both types of signal. Interestingly, the military GPS signal is encrypted using what is called the A/S "anti-spoof" code. Which was deployed in the '70s. So you know they've been thinking about it for quite some time. Practically speaking: Assuming one can shield the spoofer receiver from its own transmitter there's no real reason why a spoofer can't set up a receiver at…

Detection 1: Constantly run HFDF on all GPS frequencies. You know where your own transmitters live. Process of elimination.

Detection 2: Compare GPS velocity vector to INS velocity vector. For fixed installations, have two receivers spaced some distance apart and compare GPS location.

Detection 3: Measure the time delay between GPS and your RTC. With a GPS disciplined RTC, drift should be low enough to make this viable.

Detection 4: Look for jumps in GPS location or time.

Mitigation 1: Send black vans, soldiers, or missiles as appropriate to rogue transmission locations determined by HFDF or the encoded position of spoofed signal.

Mitigation 2: Frequency-agile and mobile GPS substitutes almost certainly have a prominent role in EW strategy. Of course, as you note, the details have to be classified, but it's pretty easy to speculate what form the overall strategy will take.

Post reply on HN