Method and system for detecting malicious national marine electronic association device
By employing active and passive detection methods, and utilizing packet matching and PGN comparison to identify anomalous NMEA devices in the ship network, the problem of network attacks by unauthorized NMEA devices is solved, achieving effective prevention of malicious devices and compliance with IACS UR E26.
Patent Information
- Application Number
- CN202480036383.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-06-05
- Filing Date
- 2024-05-31
- Publication Date
- 2026-01-02
AI Technical Summary
Existing technologies cannot effectively identify and prevent cyberattacks caused by unauthorized NMEA devices in ship networks, and cannot meet the cybersecurity requirements of IACS UR E26.
By using active and passive detection methods, the ship network detector broadcasts data packets, the management server performs data packet matching and comparison, and the message processing unit extracts the PGN and source address and compares them with the CBS list to identify abnormal NMEA devices and output abnormal signals.
It enables effective identification and attack prevention of unauthorized NMEA devices in ship networks, meets the network security requirements of IACS UR E26, and reduces the risk of network attacks.
Smart Images

Figure CN121264008A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to a method and system for actively and passively detecting malicious National Marine Electronics Association (NMEA) devices, which can identify normal / abnormal NMEA devices on a ship network provided with an NMEA gateway, thereby preventing cyber attacks from unauthorized NMEA devices in a ship BACKGROUND
[0002] Recently, all sensor equipment used in a ship has been integrated and automated using a National Marine Electronics Association (NMEA) 2000 communication protocol. The NMEA 2000 protocol based on Controller Area Network (CAN) communication was officially announced in October 2001 under the leadership of the NMEA in the United States, and has recently been adopted as a sensor network standard for electronic navigation, which is an integrated monitoring solution for a ship.
[0003] As the demand for various communication technologies, such as Ethernet, Universal Serial Bus (USB), serial, and wireless communication (e.g., wireless fidelity (Wi-Fi), Bluetooth, etc.), on a ship network increases, NMEA gateways are being provided to enable mutual communication with NMEA 2000-based navigation and communication equipment.
[0004] The NMEA gateway performs a function of converting messages using an interface that enables bidirectional conversion between the NMEA protocol and protocols such as Ethernet, USB, and Wi-Fi.
[0005] International Association of Classification Societies (IACS) Unified Requirement (UR) E26 Identify Cybersecurity Requirements requires identifying an inventory list of shipboard Computer-Based System (CBS).
[0006] However, since the NMEA gateway is connected to 'n' number of NMEA-based navigation and communication devices and converts the CAN-based NMEA messages into a protocol for an interface (e.g., an Ethernet interface for data transmission / reception), it is not possible to confirm whether any of the NMEA devices is included in the inventory list of the CBS according to the IACS network security requirements, or whether the corresponding NMEA device is a malicious NMEA device installed by an unauthorized person.
[0007] Related art is disclosed in Patent Document 1: Korean Patent Registration No. 10-1321081 (October 23, 2013), Patent Document 2: Korean Patent Registration No. 10-1528547 (June 12, 2015), and Patent Document 3: Korean Patent Early Publication No. 10-2006-0057756 (May 29, 2006). SUMMARY
[0008] Technical Problem
[0009] An object of the present application is to provide a method and system for actively and passively detecting a malicious NMEA device, which can identify normal / abnormal NMEA devices on a ship network provided with an NMEA gateway to minimize a network attack caused by an unconfirmed NMEA device, prevent a network attack from an unauthorized NMEA device in a ship, and ultimately enable compliance with the network security requirement "Identify" of IACS URE 26 regulations.
[0010] Technical Solution
[0011] According to an aspect of the present application, a system for actively detecting a malicious NMEA device includes a ship network detector configured to broadcast a data packet to an NMEA network via a shipboard Ethernet network to detect an NMEA device, an alarm device as an NMEA device among a plurality of NMEA devices that has received the data packet broadcast from the ship network detector, and a management server configured to compare the data packet received by the alarm device with the data packet broadcast from the ship network detector, wherein, when the data packet received by the alarm device matches the data packet broadcast from the ship network detector, the management server determines that the shipboard Ethernet network is connected to the NMEA device on a shipboard operational technology (OT) network, and, when the data packet received by the alarm device does not match the data packet broadcast from the ship network detector, the management server determines that the alarm device is a malicious NMEA device.
[0012] Further, the data frame of the Ethernet packet broadcasted from the ship network detector can include a CAN packet, and a source address of the CAN packet can be designated as the alarm device.
[0013] According to another aspect of the present application, a method for actively detecting a malicious NMEA device includes a packet transmission step in which a ship network detector broadcasts a packet via a shipboard Ethernet network to an NMEA network to detect an NMEA device, an alarm device designation step in which an NMEA device that has received the packet in the packet transmission step is designated as an alarm device, a comparison step in which a management server compares a packet received by the one NMEA device designated as the alarm device in the alarm device designation step with a packet broadcasted from the ship network detector, and a determination step in which the management server determines that the shipboard Ethernet network is connected to an NMEA device on a shipboard operational technology (OT) network when it is confirmed that the packet received by the alarm device matches the packet broadcasted from the ship network detector, and determines that the alarm device is a malicious NMEA device when it is confirmed that the packet received by the alarm device does not match the packet broadcasted from the ship network detector.
[0014] Further, in the alarm device designation step, the data frame of the Ethernet packet received from the ship network detector can include a CAN packet, and a source address of the CAN packet can be designated as the alarm device.
[0015] According to still another aspect of the present application, a method for passively detecting a malicious NMEA device includes an input step in which protocol packets delivered to an Ethernet interface via an NMEA gateway are input to a message processing unit, a data frame extraction step in which the message processing unit confirms whether the protocol packets input in the input step are in an NMEA format and extracts a data frame stored in a payload field from the protocol packets when the protocol packets are confirmed to be in the NMEA format, a Parameter Group Number (PGN) processing step in which a PGN processing unit extracts an NMEA-identifier (ID) from the data frame extracted in the data frame extraction step and extracts a PGN and a source address from the extracted NMEA-ID, a determination step in which a PGN identification unit compares the PGN and the source address extracted in the PGN processing step with a CBS list and, when the PGN and the source address are confirmed not to exist in the CBS list, a PGN determination unit determines that a source of the protocol packets is a malicious NMEA device, and an abnormal signal output step in which, when the source of the protocol packets is determined to be the malicious NMEA device in the determination step, an abnormal signal output unit outputs an abnormal signal to provide a notification.
[0016] In addition, in the abnormal signal output step, the abnormal signal output unit can identify the source address in the header as well as the PGN and the source address in the payload as a malicious NMEA device as identified by the PGN identification unit and output an abnormal signal indicating the same.
[0017] In addition, the method for passively detecting a malicious NMEA device can further include an NMEA route tracing step before the abnormal signal output step in which, when the source of the protocol packets is determined to be a malicious NMEA device, an NMEA route is traced to identify an unconfirmed NMEA device as an abnormal NMEA device.
[0018] According to still another aspect of the present application, a system for passively detecting a malicious NMEA device includes a message processing unit configured to receive input of a protocol packet delivered to an Ethernet interface via a NMEA gateway, confirm whether the input protocol packet is in a NMEA format, and extract a data frame stored in a payload field from the protocol packet upon confirming that the protocol packet is in the NMEA format; a PGN processing unit configured to extract a NMEA-ID from the data frame extracted by the message processing unit, and extract a PGN and a source address from the extracted NMEA-ID; a PGN identification unit configured to compare the PGN and the source address extracted by the PGN processing unit with a CBS list; a PGN determination unit configured to determine that a source of the protocol packet is a malicious NMEA device upon confirming that the PGN and the source address are not present in the CBS list; and an abnormal signal output unit configured to output an abnormal signal to provide a notification upon determining by the PGN determination unit that the source of the protocol packet is the malicious NMEA device.
[0019] In addition, the abnormal signal output unit can identify the source address in the header as well as the PGN and the source address in the payload as a malicious NMEA device as identified by the PGN identification unit, and output an abnormal signal indicating the same.
[0020] In addition, the system for passively detecting a malicious NMEA device can further include a NMEA route tracking unit configured to track a NMEA route and identify an unconfirmed NMEA device as an abnormal NMEA device upon determining by the PGN determination unit that the source of the protocol packet is the malicious NMEA device.
[0021] Advantageous effects
[0022] Embodiments of the present application provide a method and system for actively and passively detecting a malicious NMEA device, which can identify normal / abnormal NMEA devices on a ship network provided with a NMEA gateway to minimize a network attack surface caused by unconfirmed NMEA devices, prevent a network attack from an unauthorized NMEA device in a ship, and ultimately enable compliance with the network security requirement "Identification" of IACS URE26 regulations. BRIEF DESCRIPTION OF DRAWINGS
[0023] Figure 1 is a block diagram of a system for actively detecting a malicious NMEA device according to the present application.
[0024] Figure 2 is a flowchart of a method for actively detecting a malicious NMEA device according to the present application.
[0025] Figure 3is a block diagram of a system for passively detecting a malicious NMEA device according to the present invention.
[0026] Figure 4 is a diagram showing a process of extracting a PGN and a source address in a system for passively detecting a malicious NMEA device according to the present invention.
[0027] Figure 5 is a flowchart of a method for passively detecting a malicious NMEA device according to the present invention. DETAILED DESCRIPTION
[0028] The above and other aspects, features and advantages of the present invention will become apparent from the following detailed description of the embodiments taken in conjunction with the accompanying drawings.
[0029] The terms used in the present specification are for the purpose of describing particular embodiments only and are not intended to be limiting. As used herein, the use of the term "comprises" and / or "comprising", and / or "includes" and / or "including" when used in this specification and in the claims, means that the stated features, integers, steps, operations, elements, components and / or groups thereof are present, but not excluding the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. In addition, the use of the singular herein, such as "a", "an" and "the" and the like, is not intended to exclude the presence of pluralia, unless the context clearly indicates otherwise.
[0030] Hereinafter, exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. It should be understood that the embodiments are provided for the full and complete disclosure of the present invention and to properly convey the essence of the invention to those skilled in the art, and the present invention is not limited to the following embodiments but can be embodied in various ways by those skilled in the art.
[0031] A system and method for actively detecting a malicious NMEA device according to the present invention will be explained with reference to Figure 1 and Figure 2
[0032] Figure 1 is a block diagram of a system for actively detecting malicious NMEA devices according to the present invention. The system for actively detecting malicious NMEA devices can include a ship network detector 11 configured to broadcast data packets to a National Marine Electronics Association (NMEA) network 20 via a shipboard Ethernet network 10 to detect NMEA devices 200, and a management server 300 configured to designate a corresponding NMEA device as an alert device 290 when the data packets broadcast from the ship network detector 11 are received by any of the NMEA devices 200, and to compare the data packets received by the alert device 290 with the data packets broadcast from the ship network detector 11.
[0033] Herein, "actively detecting" refers to a method of simply detecting malicious NMEA devices by broadcasting data packets to the NMEA network 20 via the shipboard Ethernet network 10.
[0034] In addition, when the data packets received by the alert device 29 match the data packets broadcast from the ship network detector 11, the management server 300 can determine that the shipboard Ethernet network 10 is connected to the NMEA devices on a shipboard Operational Technology (OT) network, and when the data packets received by the alert device 29 do not match the data packets broadcast from the ship network detector 11, the management server 300 can determine that the alert device is a malicious NMEA device.
[0035] In addition, the data frames of the Ethernet packets received from the ship network detector 11 can include CAN packets, and the source addresses of the CAN packets can be designated as the alert device 290.
[0036] Referring to Figure 2According to another aspect of the present application, a method for actively detecting a malicious NMEA device can include a data packet transmission step S10 in which a ship network detector 11 broadcasts a data packet to an NMEA network via a shipboard Ethernet network 10 to detect an NMEA device, an alarm device designation step S11 in which an NMEA device that has received the data packet in the data packet transmission step S10 is designated as an alarm device 29, a comparison step S12 in which a management server 30 compares a data packet received by the one NMEA device designated as the alarm device 29 in the alarm device designation step S11 with the data packet broadcast from the ship network detector 11, and a determination step S13 in which the management server 30 determines that the shipboard Ethernet network 10 is connected to an NMEA device on a shipboard operational technology (OT) network when it is confirmed in the comparison step S12 that the data packet received by the alarm device 29 matches the data packet broadcast from the ship network detector 11, and determines that the alarm device 29 is a malicious NMEA device when it is confirmed in the comparison step S12 that the data packet received by the alarm device 29 does not match the data packet broadcast from the ship network detector 11.
[0037] In addition, in the alarm device designation step S11, a data frame of the Ethernet data packet received from the ship network detector 11 can include a CAN data packet, and a source address of the CAN data packet can be designated as the alarm device 29.
[0038] As such, the system and method for actively detecting a malicious NMEA device according to the present application can identify an unauthorized Ethernet-to-NMEA connection in a complex and large shipboard IT / OT network.
[0039] Next, a system and method for passively detecting a malicious NMEA device according to yet another aspect of the present application will be described with reference to Figures 3 to 5
[0040] Figure 3 is a block diagram of a system for passively detecting a malicious NMEA device according to the present application, and Figure 4 is a diagram showing a process of extracting a PGN and a source address. Referring to Figure 3 The system for passively detecting a malicious NMEA device includes a message processing unit 100, a PGN processing unit 110, a PGN identification unit 120, a PGN determination unit 130, an NMEA route tracking unit 140, and an abnormal signal output unit 150.
[0041] In the system for passively detecting a malicious NMEA device according to the present application, the message processing unit 100 receives input of a protocol packet delivered to an Ethernet interface via an NMEA gateway, confirms whether the input protocol packet is in an NMEA format, and extracts a data frame stored in a payload field from the protocol packet upon confirming that the protocol packet is in the NMEA format.
[0042] Here, "NMEA" refers to a standard defined by the National Marine Electronics Association of the United States for transmitting information such as time, position, and bearing.
[0043] The PGN processing unit 110 can be configured to extract an NMEA-ID from the data frame extracted by the message processing unit 100, and to extract a PGN and a source address from the extracted NMEA-ID.
[0044] Here, "PGN (Parameter Group Number)" serves to identify a data type included in a data field of a CAN message, and functions in a manner similar to a message ID in CAN communication.
[0045] The PGN identification unit 120 can be configured to compare the PGN and the source address extracted by the PGN processing unit 110 with a computer-based system (CBS) list, and the PGN determination unit can be configured to determine that the source of the protocol packet is a malicious NMEA device when the PGN value and the source address are confirmed by the PGN identification unit 120 as not existing in the CBS list.
[0046] The NMEA route tracking unit 140 can be configured to track an NMEA route to identify an unconfirmed NMEA device as an abnormal NMEA device and an confirmed NMEA device as a normal NMEA device when the source of the protocol packet is determined by the PGN determination unit 130 to be a malicious NMEA device.
[0047] The abnormal signal output unit 150 can be configured to output an abnormal signal to provide a notification when the source of the protocol packet is determined by the PGN determination unit 130 to be a malicious NMEA device.
[0048] In addition, as shown in Figure 4 the abnormal signal output unit 150 can discriminate the source address in the header as well as the PGN and the source address in the payload as a malicious NMEA device as identified by the PGN identification unit, and output an abnormal signal indicating the same.
[0049] In summary, upon receiving input of a protocol packet delivered to an Ethernet interface via an NMEA gateway, the message processing unit 100 extracts a data frame stored in a payload field from the protocol packet.
[0050] Subsequently, the PGN processing unit 110 extracts the NMEA-ID from the extracted data frame, and extracts the PGN and the source address from the extracted NMEA-ID.
[0051] Subsequently, the PGN identification unit 120 compares the PGN value and the source address with the CBS list, and when the PGN value and the source address are confirmed to be not present in the CBS list, the PGN determination unit 130 determines that the source of the protocol packet is a malicious NMEA device.
[0052] Finally, the abnormal signal output unit 150 can identify the source address in the header as well as the PGN and the source address in the payload as a malicious NMEA device as identified by the PGN identification unit, and output an abnormal signal indicating the same.
[0053] Figure 5 is a flowchart of a method for passively detecting a malicious NMEA device according to the present application. Referring to Figure 5 , the method for passively detecting a malicious NMEA device can include an input step S100 in which a protocol packet delivered to an Ethernet interface via an NMEA gateway is input to a message processing unit 100, a data frame extraction step S120 in which the message processing unit 100 confirms whether the protocol packet input in the input step is in an NMEA format, and extracts a data frame stored in a payload field from the protocol packet when it is confirmed that the protocol packet is in the NMEA format, a PGN processing step S140 in which a PGN processing unit 110 extracts an NMEA-ID from the data frame extracted in the data frame extraction step, and extracts a PGN and a source address from the extracted NMEA-ID, a determination step S160 in which a PGN identification unit compares the PGN and the source address extracted in the PGN processing step S140 with a CBS list, and when the PGN and the source address are not present in the CBS list, a PGN determination unit determines that the source of the protocol packet is a malicious NMEA device, and an abnormal signal output step S180 in which, when it is determined in the determination step S160 that the source of the protocol packet is a malicious NMEA device, an abnormal signal output unit 150 outputs an abnormal signal to provide a notification.
[0054] In addition, in the abnormal signal output step S180 of the method for passively detecting a malicious NMEA device according to the present application, the abnormal signal output unit can identify the source address in the header as well as the PGN and the source address in the payload as a malicious NMEA device as identified by the PGN identification unit, and output an abnormal signal indicating the same.
[0055] Further, the method for passively detecting a malicious NMEA device according to the present application can further include an NMEA route tracking step before the abnormal signal output step, in which, when the source of the protocol packet is determined as a malicious NMEA device, the NMEA route is tracked to identify the unconfirmed NMEA device as an abnormal NMEA device.
[0056] BRIEF DESCRIPTION OF DRAWINGS
[0057] 10: Ethernet network
[0058] 11: Ship network detector
[0059] 20: NMEA network
[0060] 21, 22, 23, 24: NMEA device
[0061] 29: Alarm device
[0062] 30: Management server
[0063] 100: Message processing unit
[0064] 110: PGN processing unit
[0065] 120: PGN identification unit
[0066] 130: PGN determination unit
[0067] 140: NMEA route tracking unit
[0068] 150: Abnormal signal output unit
Claims
1. A system for detecting malicious National Marine Electronics Association (NMEA) devices, comprising: The ship network detector is configured to broadcast data packets to the National Marine Electronics Association (NMEA) network via the shipboard Ethernet network to detect NMEA devices. An alarm device is configured to set an alarm for a receiving National Marine Electronics Association device when any of a plurality of National Marine Electronics Association devices receives a data packet broadcast from a ship network detector; as well as The management server is configured to compare data packets received by the alarm device with data packets broadcast from the ship's network detector. Specifically, when the data packet received by the alarm device matches the data packet broadcast from the ship network detector, the management server determines that the shipboard Ethernet network is connected to a National Marine Electronics Association (NMA) device on the shipboard Operations Technology (OT) network, and when the data packet received by the alarm device does not match the data packet broadcast from the ship network detector, the management server determines that the alarm device is a malicious NMA device.
2. The system according to claim 1, wherein The data frames of the Ethernet packets broadcast from the ship's network detector contain controller area network (CLAN) packets, and The source address of the controller LAN data packet is designated as the alarm device.
3. A method for detecting malicious National Marine Electronics Association (NMEA) devices, comprising: In the data packet transmission step, the ship network detector broadcasts data packets to the National Marine Electronics Association (NMEA) network via the shipboard Ethernet network to detect NMEA devices. The alarm device designation step designates a National Marine Electronics Association device that has received the data packet in the data packet transmission step as an alarm device. In the comparison step, the management server compares the data packets received by the National Marine Electronics Association device designated as the alarm device in the alarm device designation step with the data packets broadcast from the ship network detector. as well as In the determination step, when it is confirmed that the data packet received by the alarm device matches the data packet broadcast from the ship network detector, the management server determines that the shipborne Ethernet network is connected to a National Marine Electronics Association device on the shipborne Operations Technology (OT) network, and when it is confirmed that the data packet received by the alarm device does not match the data packet broadcast from the ship network detector, the management server determines that the alarm device is a malicious National Marine Electronics Association device.
4. The method of claim 3, wherein in the alarm device designation step, the data frame of the Ethernet packet received from the ship network detector includes a controller area network (CLAN) packet, and the source address of the CLAN packet is designated as the alarm device.
5. A method for detecting malicious National Marine Electronics Association (NMEA) devices, comprising: The input step involves inputting protocol data packets delivered to the Ethernet interface via the National Marine Electronics Association gateway into the message processing unit. In the data frame extraction step, the message processing unit confirms whether the protocol data packet input in the input step is in the National Marine Electronics Association format, and extracts the data frame stored in the payload field from the protocol data packet when it is confirmed that the protocol data packet is in the National Marine Electronics Association format. In the parameter group numbering processing step, the parameter group numbering processing unit extracts the National Marine Electronics Association identifier from the data frame extracted in the data frame extraction step, and extracts the parameter group number and source address from the extracted National Marine Electronics Association identifier. In the determination step, the parameter group number identification unit compares the parameter group number and the source address extracted in the parameter group number processing step with the computer-based system list. When the parameter group number and the source address are confirmed not to exist in the computer-based system list, the parameter group number determination unit determines that the source of the protocol data packet is a malicious National Marine Electronics Association device. as well as An abnormal signal output step, wherein when it is determined in the determination step that the source of the protocol data packet is a malicious National Marine Electronics Association device, the abnormal signal output unit outputs an abnormal signal to provide notification.
6. The method according to claim 5, wherein in the abnormal signal output step, the abnormal signal output unit is capable of identifying the source address in the header and the parameter group number and the source address in the payload as malicious National Marine Electronics Association devices, as identified by the parameter group number identification unit, and outputs an abnormal signal indicating the situation.
7. The method according to claim 5, further comprising, before the abnormal signal output step: The National Marine Electronics Association (NMA) route tracing step, in which, when the source of the protocol data packet is determined to be a malicious NMA device, traces the NMA route to identify unidentified NMA devices as anomalous NMA devices.
8. A system for detecting malicious National Marine Electronics Association (NMEA) devices, comprising: The message processing unit is configured to receive input protocol data packets delivered to the Ethernet interface via the National Marine Electronics Association (NMEA) gateway, confirm whether the input protocol data packets are in NMEA format, and extract data frames stored in the payload field from the protocol data packets when the NMEA format is confirmed. The parameter group number processing unit is configured to extract the National Marine Electronics Association identifier from the data frame extracted by the message processing unit, and extract the parameter group number and source address from the extracted National Marine Electronics Association identifier. The parameter group number identification unit is configured to compare the parameter group number and the source address extracted by the parameter group number processing unit with a computer-based system inventory; The parameter group number determination unit is configured to determine that the source of the protocol data packet is a malicious National Marine Electronics Association device when the parameter group number and the source address are confirmed not to exist in the computer-based system list; as well as An anomaly signal output unit is configured to output an anomaly signal to provide notification when the parameter group number determination unit determines that the source of the protocol data packet is a malicious National Marine Electronics Association device.
9. The system of claim 8, wherein the abnormal signal output unit identifies the source address in the header and the parameter group number and source address in the payload as malicious National Marine Electronics Association device, as identified by the parameter group number identification unit, and outputs an abnormal signal indicating the situation.
10. The system according to claim 8, further comprising: The National Marine Electronics Association (NMA) route tracing unit is configured to trace NMA routes and identify unconfirmed NMA devices as anomalous NMA devices when the parameter group number determination unit determines that the source of the protocol data packet is a malicious NMA device.
Citation Information
Patent Citations
Silent and noise detection method using the passive monitoring in communication network based on packet and communication system using it
KR101321081B1
Universal Gateway System for NMEA 2000
KR101528547B1
The embodiment method of multi-function NMEA data monitoring system, and universal NMEA monitor and NMEA controller
KR1020060057756A