Live data from Hacker News

Ships fooled in GPS spoofing attack suggest Russian cyberweapon

newscientist.com

31–40 of 78 posts

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#31

This is fairly old news. Reports are a year or two old and suggest that Russian security uses GPS spoofing anywhere V. Putin may be located, presumably as a defense against drone type attacks or surveillance. The spoofed location is often an airport. The black sea spoofing could be related to a visit to e.g., Sochi. Alternatively Russia could be deploying the spoofers on ships now, which would seem to have offensive…

Sounds like a semi-reliable Putin Detector could be set up if you wanted to...

It would also be fairly short-lived in battle, since the spoofer is broadcasting its own location in a highly accurate "place ordnance here" manner.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#32

Earlier quoted context omitted.

>there's no real reason why a spoofer can't set up a receiver at one location and rebroadcast the encrypted signal as received there I can't really see this working if you have an inertial navigation backup system. It would be easy to detect the large error in GPS position and just ignore the GPS.

You'll need two alternatives to GPS to be able to tell whether it's a malfunction in GPS, or the inertial nav. e-loran is such a third alternative.

Only if you assume they're equally likely to fail. Since INS is much less susceptible to spoofing and ought to have a fairly low nominal failure rate, in wartime it might be reasonable to assume disagreements are due to spoofing.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#33

This is fairly old news. Reports are a year or two old and suggest that Russian security uses GPS spoofing anywhere V. Putin may be located, presumably as a defense against drone type attacks or surveillance. The spoofed location is often an airport. The black sea spoofing could be related to a visit to e.g., Sochi. Alternatively Russia could be deploying the spoofers on ships now, which would seem to have offensive…

Sounds like a semi-reliable Putin Detector could be set up if you wanted to...

Let's think through that. In order to spoof GPS, you need to overpower the true GPS signal with your own. You put some transmitters in a location, and anyone attempting to get a GPS fix while in that location gets spoofed data and the wrong location.

Now, if you're close enough to get the spoofed signal, you're close enough to see Putin's entourage and know he's probably nearby. If you're not close, you don't get spoofed. So I'm uncertain of the utility of this Putin Detector.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#34
post #6

many NATO guided bombs, missiles and drones rely on GPS navigation There are separate code sets for civilian and military GPS, and the latter should only be availability to US military equipment manufacturers. What I wonder is whether that means some NATO equipment will be misdirected by spoofing attacks and other will not, or if the attackers actually are able to spoof both types of signal.

> if the attackers actually are able to spoof both types of signal. Interestingly, the military GPS signal is encrypted using what is called the A/S "anti-spoof" code. Which was deployed in the '70s. So you know they've been thinking about it for quite some time. Practically speaking: Assuming one can shield the spoofer receiver from its own transmitter there's no real reason why a spoofer can't set up a receiver at…

You're talking about a GPS repeater. Such systems are commercially available to rebroadcast a GPS signal within a building where the signal wouldn't penetrate, but require a license to operate, IIRC.

As for countermeasures, well, whoever's holding the receiver is bound to get suspicious if they move and the reported position doesn't. :) Jokes aside, there is work being done integrating other sensors (inertial, compass, gyro, etc.) to do dead reckoning to detect errors in the position and motion reported by the GNSS receiver.

As an aside, "GPS" technically refers only to the positioning system operated by the United States. The generic term is "GNSS" (global navigation satellite system) and encompasses GPS, GLONASS, Galileo, Beidou, etc.)

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#35

Earlier quoted context omitted.

You'll need two alternatives to GPS to be able to tell whether it's a malfunction in GPS, or the inertial nav. e-loran is such a third alternative.

Only if you assume they're equally likely to fail. Since INS is much less susceptible to spoofing and ought to have a fairly low nominal failure rate, in wartime it might be reasonable to assume disagreements are due to spoofing.

Also, I believe most airliners have 2 or 3 INS systems, so it would be easy to see (or detect) if one of them has failed.

It seems unlikely that all the gyros would silently fail...that would only happen if the gyros tumbled, or power failure to the gyros, but there would presumably be an error indication in either of those situations. (Also, these days they use ring laser gyros, which don't tumble or stop spinning).

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#36

That is laughable and doesn't provide any kind of military utility. What is the value of spoofing GPS by putting everyone into the same point, with zero inferred velocity and acceleration vectors, while other data sources like inertial will easily tell the supposed victim this is all wrong? Also, M-code can't be affected this way because it is encrypted, and military grade GPS receivers use virtual directed beams so…

M-code encryption doesn't protect against rebroadcast, which is what this attack seems to be. And beam-forming has its own limitations which can be fairly easily overcome by signal strength. It may be that military mitigation involves defining a carefully circumscribed envelope of signal strength, checks against inertial references, alternative time sources, etc. But it's not trivial or laughable.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#37

Earlier quoted context omitted.

Only if you assume they're equally likely to fail. Since INS is much less susceptible to spoofing and ought to have a fairly low nominal failure rate, in wartime it might be reasonable to assume disagreements are due to spoofing.

Also, I believe most airliners have 2 or 3 INS systems, so it would be easy to see (or detect) if one of them has failed. It seems unlikely that all the gyros would silently fail...that would only happen if the gyros tumbled, or power failure to the gyros, but there would presumably be an error indication in either of those situations. (Also, these days they use ring laser gyros, which don't tumble or stop spinning).

Speaking of which, are RLGs actually difficult to manufacture or is the military intentionally stopping them from getting into civilian hands? Even the best cell phone sensor fusion seems to result in an obnoxiously shitty map experience.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#38
post #2

You will be relieved to know that the military is on top of this and regularly trains for GPS jamming scenarios https://www.ofcom.org.uk/spectrum/information/gps-jamming-ex...

If you RTFA, you'll note that jamming is different than spoofing. And no it doesn't make me feel relieved that the military "is on top of this". Whose military? Why should we trust them? State actors with the capability to spoof GPS signals can do much harm to even their own citizens.

Whose military?

If you "RTFA" you will observe that OFCOM is the UK regulator.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#39

That is laughable and doesn't provide any kind of military utility. What is the value of spoofing GPS by putting everyone into the same point, with zero inferred velocity and acceleration vectors, while other data sources like inertial will easily tell the supposed victim this is all wrong? Also, M-code can't be affected this way because it is encrypted, and military grade GPS receivers use virtual directed beams so…

M-code encryption doesn't protect against rebroadcast, which is what this attack seems to be. And beam-forming has its own limitations which can be fairly easily overcome by signal strength. It may be that military mitigation involves defining a carefully circumscribed envelope of signal strength, checks against inertial references, alternative time sources, etc. But it's not trivial or laughable.

M-code contains time and ephemeris data, yes? (Since it's supposed to be "autonomous".) It seems like it would be quite easy to detect replay attacks.
Post reply on HN