A Tale of Sea and Sky On the Security of Maritime VSAT Communications
James Pavur, Daniel Moser, Martin Strohmeier, Vincent Lenders, Ivan Martinovic
Abstract
Very Small Aperture Terminals (VSAT) have revolutionized maritime operations. However, the security dimensions of maritime VSAT services are not well understood. Historically, high equipment costs have acted as a barrier to entry for both researchers and attackers. In this paper we demonstrate a substantial change in threat model, proving practical attacks against maritime VSAT networks with less than $400 of widely-available television equipment. This is achieved through GSExtract, a purpose-built forensic tool which enables the extraction of IP traffic from highly corrupted VSAT data streams.The implications of this threat are assessed experimentally through the analysis of more than 1.3 TB of real-world maritime VSAT recordings encompassing 26 million square kilometers of coverage area. The underlying network platform employed in these systems is representative of more than 60% of the global maritime VSAT services market. We find that sensitive data belonging to some of the world's largest maritime companies is regularly leaked over VSAT ship-to-shore communications. This threat is contextualized through illustrative case studies ranging from the interception and alteration of navigational charts to theft of passport and credit card details. Beyond this, we demonstrate the ability to arbitrarily intercept and modify TCP sessions under certain network configurations, enabling man-in-the-middle and denial of service attacks against ships at sea. The paper concludes with a brief discussion of the unique requirements and challenges for encryption in VSAT environments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 471811b9-bcf4-4e07-87e8-a23057d24653Cited by top-tier papers11
- ICARUS: Attacking low Earth orbit satellite networksGiacomo Giuliari, Tommaso Ciussani, Adrian Perrig, Ankit SinglaUSENIX ATC 2021 · 99 citations
- RECORD: A RECeption-Only Region Determination Attack on LEO Satellite UsersEric Jedermann, Martin Strohmeier, Vincent Lenders, Jens B. SchmittUSENIX Security 2024 · 18 citations
- Wireless Signal Injection Attacks on VSAT Satellite ModemsRobin Bisping, Johannes Willbold, Martin Strohmeier, Vincent LendersUSENIX Security 2024 · 11 citations
- A Sea of Cyber Threats: Maritime Cybersecurity from the Perspective of MarinersAnna Raymaker, Akshaya Kumar, Miuyin Yong Wong, Ryan Pickren et al.CCS 2025 · 5 citations
- Don't Look Up: There Are Sensitive Internal Links in the Clear on GEO SatellitesWenyi Morty Zhang, Annie Dai, Keegan Ryan, Dave Levin et al.CCS 2025 · 1 citation
Related papers
- A Comprehensive Analysis of Security Vulnerabilities and Attacks in Satellite ModemsLingjing Yu, Jingli Hao, Jun Ma, Yong Sun et al.CCS 2024 · 8 citations
- SoK: Exploiting Network PrintersJens Müller, Vladislav Mladenov, Juraj Somorovsky, Jörg SchwenkS&P 2017 · 31 citations
- Mind the Location Leakage in LEO Direct-to-Cell Satellite NetworksWeisen Liu, Zeqi Lai, Qian Wu, Hewu Li et al.S&P 2025
- Space Odyssey: An Experimental Software Security Analysis of SatellitesJohannes Willbold, Moritz Schloegel, Manuel Vögele, Maximilian Gerhardt et al.S&P 2023
- ActiveThief: Model Extraction Using Active Learning and Unannotated Public DataSoham Pal, Yash Gupta, Aditya Shukla, Aditya Kanade et al.AAAI 2020 · 164 citations
