Security

Ships Also Targeted by Cyberattacks as Companies Fill Maritime Security Gaps

IT DAILY ·

AI-generated image

✦ AI Summary

Foreign-flagged tankers heading to the United States were found to show signs of network intrusion, prompting the FBI and the Coast Guard to board and inspect the vessels.

The vessels under investigation were the Liberia-flagged VLCC VL Prosperity and the LPG carrier Kohaku, and the two ships were believed to have come under attack while passing through the Strait of Gibraltar in early August.

As cyber threats against ships are becoming a reality amid the shipping industry's digital transformation, IACS has revised UR E26 and E27, while domestic security companies are entering the market for ship security solutions.

Foreign-flagged tankers heading to the United States were found to show signs of network intrusion, prompting local authorities to board and inspect the vessels, AP and other foreign media reported on the 26th. The FBI and the Coast Guard boarded the two foreign-flagged tankers headed to the United States on the 21st and 24th of last month.

The vessels under investigation were the Liberia-flagged VLCC VL Prosperity and the LPG carrier Kohaku. The FBI and the Coast Guard examined the ships' navigation equipment and information systems to check for signs of cyber intrusion.

The two ships were believed to have come under attack while passing through the Strait of Gibraltar in early August. The incident underscored that ships, in an environment where communications and navigation equipment are linked to digital systems, are becoming targets of cyberattacks and that cyber threats against vessels are becoming a reality.

In step with this situation, related rules are being tightened. Domestic security companies are also entering the market for solutions aimed at ships.

The shipping industry has continued its digital transformation (DX), including adding IT elements to vessels to improve operational efficiency. Ships equipped with IT, artificial intelligence (AI), the Internet of Things (IoT), and remote control are called smart ships.

Smart ship equipment is fitted with sensors, and the information collected by those sensors is linked to a centralized control room. Information connected to the control room supports safe navigation.

However, IT technologies linked to ships can also become a channel for cyberattacks. With active communications between ship and shore and exposure to threats through external network connections, ransomware infections of ship systems through those routes are rising. This has caused delays in cargo transport, and in 2019 an internal system deletion incident occurred on a car carrier, with ransomware identified as the cause.

Regarding the latest hacking incident, U.S. authorities said it did not affect crew safety or vessel operations. However, they did not identify the perpetrator, and some foreign media outlets, including The Wall Street Journal, reported that authorities were investigating a possible link to Iran.

As international regulations are being put in place to address cyber threats against ships, the International Association of Classification Societies (IACS) revised UR E26 and E27 related to cyber resilience in 2023. IACS also decided to make the rules mandatory for newbuilds whose construction contracts are signed after July 1, 2024. This is cited as the background to the accelerated push by Igloo Corporation and Kuntech into the ship security market.

Because ships operate in an environment separated from land, it is difficult to take immediate action even when a problem arises. Accordingly, the cyber resilience approach focuses not on perfect defense but on minimizing the impact of operational technology (OT) disruption or damage and restoring normal operations quickly.

More specifically, E26 includes verification of risk factors during ship construction as well as verification that the detection, response, and recovery systems actually function. E27 is a rule that checks whether the systems and equipment installed on ships were developed and manufactured safely.

The security industry is focusing on the expansion of the ship OT security market as regulations become mandatory. To meet E26 requirements, a monitoring system such as SIEM is needed, and to satisfy E26 certification requirements, passing a Pen Test is required, driving demand for related security solutions.

In response, some companies are unveiling new solutions and moving to secure an early foothold in the market. Igloo Corporation and Kuntech are seen as the main players targeting the domestic market. Igloo Corporation has been responding since 2024 with SPiDER OT for Maritime and has obtained E27 certification from KR, BV, and ABS. It has also been recognized by BV for its ability to support Pen Test efforts.

Kim Ki-hyeon, head of Kuntech's NS business group, said newbuilds whose construction contracts were signed after July 2024 are beginning to enter service in the middle of this year, and procedures to check whether operational conditions match the certification details are also starting. He described this year as the first year of on-site application of the regulations and said it would be a turning point for the cyber ship security market this year.

Igloo Corporation has deployed SPiDER OT for Maritime on three 174K CBM-class LNG carriers operated by Hyundai LNG Shipping. The vessels are HLS Bilbao, Puteri Mayang, and Hyundai Princepia.

Kuntech protects ship OT environments with its maritime-specific security platform, TGM (TeraGRID Maritime). TGM is operated with both hardware and software installed onboard and has functions to secure visibility into onboard systems and detect abnormal signals and unauthorized access. It also operates even when satellite lines are disconnected.

Since April 2024, Kuntech has been carrying out the Ministry of Science and ICT and the Institute for Information & Communications Technology Planning & Evaluation (IITP) project titled "Development of Core Security Technologies for Smart Ship International Regulatory Compliance." On August 19 this year, it invited major companies and institutions such as KR, shipbuilders, and equipment suppliers to demonstrate attack scenarios in a testbed that recreated two virtual ships to resemble real ones. The presentation showed an actual attack and the subsequent response procedures.

Kim said budgets in the ship cybersecurity field are small compared with those for other safety equipment, and that there is still a lingering habit of responding only after an incident occurs. He added that regulations and inspections are now pushing back against that inertia.

He also said he expects domestic shipbuilding and shipping companies to choose local technologies as a means of responding to regulations rather than because of market size. He outlined a structure in which classification societies establish the rules, shipyards and shipowners apply them, and security companies provide the technology, and explained that if that structure works first in Korea, the same proposal could be made to overseas classification societies and shipping companies.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241839

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.