The Automatic Identification System (AIS) is a tracking system used in vessels and vessel traffic control services to identify and locate vessels and is being regarded as the main tool for complementing the navigator’s direct visual/audible information augmented with RADAR data to prevent collisions at sea. Despite its criticality, AIS in its general use, with the corresponding message broadcasting protocol, is not secured from cyberattacks. Its security vulnerabilities have been extensively discussed in the literature, and several real incidents have been reported. To address this issue, several research papers have been published proposing anomaly/attack detection systems based either on machine learning (ML) approaches requiring large datasets or on logic-based rule systems built with the help of maritime experts. In this chapter, we propose an alternative ML approach to develop an attack detection system using Inductive Logic Programming (ILP), a symbolic AI method, to incrementally learn rules that help detect anomalies in AIS data that potentially could indicate spoofing attacks. As a main result, we demonstrate that ILP frameworks that combine relational logic and numerical reasoning stand out for the ability to generalise from a small set of examples and provide explainable evidence of anomaly occurrence, making it suitable for operational use in maritime environments.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Using Incremental Inductive Logic Programming for Learning Spoofing Attacks on Maritime Automatic Identification System Data

  • Aboubaker Seddiq Benterki,
  • Gabor Visky,
  • Jüri Vain,
  • Leonidas Tsiopoulos

摘要

The Automatic Identification System (AIS) is a tracking system used in vessels and vessel traffic control services to identify and locate vessels and is being regarded as the main tool for complementing the navigator’s direct visual/audible information augmented with RADAR data to prevent collisions at sea. Despite its criticality, AIS in its general use, with the corresponding message broadcasting protocol, is not secured from cyberattacks. Its security vulnerabilities have been extensively discussed in the literature, and several real incidents have been reported. To address this issue, several research papers have been published proposing anomaly/attack detection systems based either on machine learning (ML) approaches requiring large datasets or on logic-based rule systems built with the help of maritime experts. In this chapter, we propose an alternative ML approach to develop an attack detection system using Inductive Logic Programming (ILP), a symbolic AI method, to incrementally learn rules that help detect anomalies in AIS data that potentially could indicate spoofing attacks. As a main result, we demonstrate that ILP frameworks that combine relational logic and numerical reasoning stand out for the ability to generalise from a small set of examples and provide explainable evidence of anomaly occurrence, making it suitable for operational use in maritime environments.