Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Fixes and Improvements

December 10th, 2012, 11:58 GMT · By

GPS Software Attacks More Dangerous Than Jamming and Spoofing, Experts Say

SHARE:

Adjust text size:

GPS systems vulnerable to software attacks
Enlarge picture
Security researchers from the Carnegie Mellon University, in collaboration with experts from Coherent Navigation, have identified new attack vectors against the Global Positioning System (GPS).

Numerous studies have demonstrated the fact that GPS is vulnerable to jamming and spoofing, but by viewing the GPS as a computer system, experts have managed to develop new attacks against this infrastructure.

Their experiments have demonstrated that GPS and GPS-dependent systems are far more vulnerable than we thought.

According to the researchers, a malicious 45-second GPS broadcast is capable of taking down more than 30% of the Continually Operating Reference Station (CORS) network, which is used for safety and life-critical applications. Furthermore, it could also disrupt 20% of the Networked Transport of RTCM via Internet Protocol (NTRIP) systems.

A total of three new attack methods have been identified: GPS data level attacks, GPS receiver software attacks, and GPS dependent system attacks.

GPS data level attacks are somewhat similar to spoofing, but they can cause more damage. For instance, such an attack can remotely crash a high-end receiver.

The second types of attacks leverage the fact that GPS receivers run some kind of computer software that can be remotely compromised.

The worst thing is that, since GPS receivers are most often seen as devices instead of computers, the security holes leveraged by attackers can remain unpatched for extended periods of time.

GPS dependent system attacks exploit the fact that GPS navigation solutions are considered to be trusted inputs by high-level software.

In order to mitigate such threats, experts recommend stronger verification of GPS receiver software and the deployment of regular software updates for IP-enabled devices.

Another mitigation strategy refers to the use of Electronic GPS Attack Detection System (EGADS) that alerts users when an attack is underway, and an Electronic GPS Whitening System (EGWS) that re-broadcasts a whitened signal to otherwise vulnerable receivers.

One noteworthy thing about these types of attacks is that they don’t require sophisticated or expensive equipment. The hardware utilized by the researchers costs only about $2,500 (1,950 EUR).


2,493 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Security Experts: Organizations Should Focus on the Big Picture Instead of Just Plugging Holes

Only 5% of Antivirus Solutions Capable of Detecting Unknown Viruses, Study Finds

Cloud Browsers like Opera Mini or Amazon Silk Could Be Abused for DDoS Attacks, Password Cracking

Cooperation Between CERTs and Law Enforcement Is Crucial, ENISA Says

International Nuclear Agency Hacked, Attackers Demand Investigation on Israel

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM