GPS Hackers Could Send Weapons to Wrong Target – GAO Report

October 19, 2018

Written by Editor

Blog Editor’s Note: This is a good reminder of the importance of designing in cyber security.  Also the vulnerability of GNSS signals, and that no one is immune to disruptions.
.
InsideGNSS
.

.

A recent General Accountability Office (GAO) report is highly critical of the cyber security, or lack thereof, in U.S. weapons systems. One of the examples of cyber-attacks it lists is GPS spoofing.

The report, published this month, goes on to say:

“…weapon systems are dependent on external systems, such as positioning and navigation systems and command and control systems in order to carry out their missions—and their missions can be compromised by attacks on those other systems. A successful attack on one of the systems the weapon depends on can potentially limit the weapon’s effectiveness, prevent it from achieving its mission, or even cause physical damage and loss of life.”

One method of spoofing that could be used is meaconing, or the interception and rebroadcast of navigation signals. This technique was first used by the British in WWII to divert German bombers away from factories and population centers. Meaconing can often defeat embedded security protocols, like the U.S. military’s M-code GPS, as it copies the entire signal, security protocol and all, so it is very difficult for the aircraft, ship, or weapons system to ignore.

The GAO study conceded that the Department of Defense was only “just beginning to grapple with the scale of vulnerabilities” to weapons systems.

Citing Russia’s reported spoofing of ships in the Black Sea, Britain’s Royal United Service Institute (RUSI) expanded upon GAO’s concerns and postulated that weapons could be redirected to targets other than those intended, such as hospitals. RUSI, an independent think tank engaged in cutting edge defense and security research, published a report on its website last week titled “Hackers can send British weapons to wrong target.”

In this report, written by Dr. Jack Watling, RUSI states, “The worst-case scenario is that you start launching precision strikes at, say, an enemy strongpoint and it lands on a hospital rather than on the target.”

In July 2017, Inside GNSS published Reports of Mass GPS Spoofing Attack in the Black Sea Strengthen Calls for PNT Backup.

Dana Goward is president of the Resilient Navigation & Timing Foundation
and a regular contri
butor to Inside GNSS.

Link to Article

What Can YOU Do? How Can YOU Help?

PNT is the quiet backbone of everything but too many leaders still don’t see the risk.

But you do. You understand the systems, the dependencies, the failure chains. That insight is rare — and it’s exactly what your country needs right now. Contact your government leaders and industry decision-makers and tell them resilient PNT isn’t a feature — it’s the foundation everything else depends on.

Start the Conversation

Use our Resilient PNT Key Talking Points to make the case.

U.S. Advocates

Find your representatives at Congress.gov, then use our email template to reach them in minutes.

When you get a response, let us know. Every conversation strengthens the mission.

More PNT News

“We can track Starlink users…” – Fast Company

“We can track Starlink users…” – Fast Company

Image: Shutterstock What's new: A report that multiple companies are offering governments the ability to geolocate Starlink terminals.  Why it's important: Security concerns - an adversary could target, kidnap, kill, etc. users. Privacy concerns - user location data...

Honeybees teach drones how to navigate without GPS – Cybernews

Honeybees teach drones how to navigate without GPS – Cybernews

Image: Shutterstock What's new: An interesting form of autonomous navigation based on nature. Why it's important: Autonomous systems have an important place in an overall PNT architecture. For some applications they are the best/only method. This system uses just 42...

PNT cyber guidance update – NIST wants your input

PNT cyber guidance update – NIST wants your input

Image: RNT Foundation What's new: Draft updated PNT cyber guidance from NIST. They are seeking public comment and input. Why it's important: PNT and cyber are well intertwined. PNT is an essential tech infrastructure so protecting it from malicious cyber effects is...

GPS Is Not Guaranteed: Impact on ports (Webinar 21 May)

GPS Is Not Guaranteed: Impact on ports (Webinar 21 May)

Image: Shutterstock What's new: A webinar featuring our colleague Matt Shirley. Matt is a professional port pilot and has some interesting insights on maritime reliance on GPS/GNSS, how things could go wrong without resilient PNT, and how things could go better with...

Get PNT News in Your Inbox