Live data from Hacker News

Ships fooled in GPS spoofing attack suggest Russian cyberweapon

newscientist.com

41–50 of 78 posts

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#41

Earlier quoted context omitted.

> if the attackers actually are able to spoof both types of signal. Interestingly, the military GPS signal is encrypted using what is called the A/S "anti-spoof" code. Which was deployed in the '70s. So you know they've been thinking about it for quite some time. Practically speaking: Assuming one can shield the spoofer receiver from its own transmitter there's no real reason why a spoofer can't set up a receiver at…

>there's no real reason why a spoofer can't set up a receiver at one location and rebroadcast the encrypted signal as received there I can't really see this working if you have an inertial navigation backup system. It would be easy to detect the large error in GPS position and just ignore the GPS.

This is kind of fun, so to play some more: suppose the spoofing platform is mobile; say, a UAV that starts out very very near the target of the spoofing, and gradually moves away at a rate designed to confuse such a check.

You can see why military stuff gets expensive. The world gets complicated when folks are actively trying to screw with you.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#42

This is fairly old news. Reports are a year or two old and suggest that Russian security uses GPS spoofing anywhere V. Putin may be located, presumably as a defense against drone type attacks or surveillance. The spoofed location is often an airport. The black sea spoofing could be related to a visit to e.g., Sochi. Alternatively Russia could be deploying the spoofers on ships now, which would seem to have offensive…

Can attest this. Area near Kremlin is spoofed to Vnukovo airport for several years already. There were reports about putin's dacha spoofed to the nearest aiport too.

I really do not know about reasons and efficacy. Professional grade multi-gnss receivers can easily filter this crap out, at least they could 5 years ago...

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#43

This is fairly old news. Reports are a year or two old and suggest that Russian security uses GPS spoofing anywhere V. Putin may be located, presumably as a defense against drone type attacks or surveillance. The spoofed location is often an airport. The black sea spoofing could be related to a visit to e.g., Sochi. Alternatively Russia could be deploying the spoofers on ships now, which would seem to have offensive…

Here is a CNN report on it http://money.cnn.com/2016/12/02/technology/kremlin-gps-signa...

They spoof no-fly zones to trick the drones that abide by them. It's hard to image building or retrofitting a surveillance or weapon drone and leaving limiters in place.

I first heard about it on a running forum but I cannot find the link. Apparently, joggers were getting an extra 20 km on their runs because of the spoofing.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#44
post #6

many NATO guided bombs, missiles and drones rely on GPS navigation There are separate code sets for civilian and military GPS, and the latter should only be availability to US military equipment manufacturers. What I wonder is whether that means some NATO equipment will be misdirected by spoofing attacks and other will not, or if the attackers actually are able to spoof both types of signal.

There are several types of spoofing attacks and it's possible to use spoofing as type of jamming attack against military GPS units from a distance where pure jamming is not effective. Older receivers require lock into C/A code before moving to encrypted P(Y). The new M-code attempts to solve some of these issues.

The simplest form of GPS spoofing sends made up signals that misdirects the GPS receiver. Military equipment is protected against these kinds of attacks with authenticated signals. Carry-off attacks (satellite-lock takeover) start with broadcasting perfectly synced repeat of the original signal. This kind of attack can be used to make munitions and missiles to lose their signal lock in critical time.

It's also possible that there are multiple weaknesses and bugs in the military receivers that can be exploited.

Iranians were somehow able to trick RQ-170 drone to land on Iran.

When Iranians captured U.S. Navy patrol boat it was because there was mysterious navigation error.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#45

Earlier quoted context omitted.

Also, I believe most airliners have 2 or 3 INS systems, so it would be easy to see (or detect) if one of them has failed. It seems unlikely that all the gyros would silently fail...that would only happen if the gyros tumbled, or power failure to the gyros, but there would presumably be an error indication in either of those situations. (Also, these days they use ring laser gyros, which don't tumble or stop spinning).

Speaking of which, are RLGs actually difficult to manufacture or is the military intentionally stopping them from getting into civilian hands? Even the best cell phone sensor fusion seems to result in an obnoxiously shitty map experience.

The power requirements for even the most miniature RLGs is still pretty large relative to cell phone peripherals, and they are still physically pretty large. DARPA has had focus efforts in the MEMs arena for more than a decade now, including atomic clocks and optical systems but its not stuff you can put in a square mm of silicon and feed with a couple of microamps.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#46

Earlier quoted context omitted.

Also, I believe most airliners have 2 or 3 INS systems, so it would be easy to see (or detect) if one of them has failed. It seems unlikely that all the gyros would silently fail...that would only happen if the gyros tumbled, or power failure to the gyros, but there would presumably be an error indication in either of those situations. (Also, these days they use ring laser gyros, which don't tumble or stop spinning).

Speaking of which, are RLGs actually difficult to manufacture or is the military intentionally stopping them from getting into civilian hands? Even the best cell phone sensor fusion seems to result in an obnoxiously shitty map experience.

Phones use MEMS sensors, which are much cheaper than laser gyros. I'm not sure if google maps uses the accelerometer, or just the GPS and compass.

In my experience, phone maps work well if the device has a good GPS signal. It's just the compass that gives a shitty experience. I wish google would ignore the compass and just use GPS direction when you're moving. They used to do this, but now they seem to rely in the inherently crappy compass for direction.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#47

Earlier quoted context omitted.

> if the attackers actually are able to spoof both types of signal. Interestingly, the military GPS signal is encrypted using what is called the A/S "anti-spoof" code. Which was deployed in the '70s. So you know they've been thinking about it for quite some time. Practically speaking: Assuming one can shield the spoofer receiver from its own transmitter there's no real reason why a spoofer can't set up a receiver at…

You're talking about a GPS repeater. Such systems are commercially available to rebroadcast a GPS signal within a building where the signal wouldn't penetrate, but require a license to operate, IIRC. As for countermeasures, well, whoever's holding the receiver is bound to get suspicious if they move and the reported position doesn't. :) Jokes aside, there is work being done integrating other sensors (inertial, compas…

> there is work being done integrating other sensors

Integrated navigation systems GPS/INS are already default in many critical civilian systems. They sell these systems as a single package.

These systems are still vulnerable against satellite-lock takeover where the spoofer who starts with repeating the correct signal and diverges from it gradually.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#48

Earlier quoted context omitted.

> if the attackers actually are able to spoof both types of signal. Interestingly, the military GPS signal is encrypted using what is called the A/S "anti-spoof" code. Which was deployed in the '70s. So you know they've been thinking about it for quite some time. Practically speaking: Assuming one can shield the spoofer receiver from its own transmitter there's no real reason why a spoofer can't set up a receiver at…

>there's no real reason why a spoofer can't set up a receiver at one location and rebroadcast the encrypted signal as received there I can't really see this working if you have an inertial navigation backup system. It would be easy to detect the large error in GPS position and just ignore the GPS.

Large commercial ships already have INS backups and it can be spoofed just fine using carry-off attack. Spoofed signal gradually diverges from the correct signal and inertial navigation can't spot the difference.

Re: Ships fooled in GPS spoofing attack suggest Russian cyberweapon

#50

Earlier quoted context omitted.

Speaking of which, are RLGs actually difficult to manufacture or is the military intentionally stopping them from getting into civilian hands? Even the best cell phone sensor fusion seems to result in an obnoxiously shitty map experience.

The power requirements for even the most miniature RLGs is still pretty large relative to cell phone peripherals, and they are still physically pretty large. DARPA has had focus efforts in the MEMs arena for more than a decade now, including atomic clocks and optical systems but its not stuff you can put in a square mm of silicon and feed with a couple of microamps.

Huh, I'd have guessed the opposite: that a laser, optics, and a piezo vibrator would be easy to integrate, while a MEMS gyroscope would be much harder. I ask anyone who gives the slightest hint of familiarity with the field because I suspect that my surface-level understanding is just missing the juicy photonics challenge that's roadblocking integration.

The alternative hypothesis of military heel-dragging (similar to the case of bolometers) is much less exciting, but verifying it would at least allow me to stop poking around :)

Post reply on HN