2026 Assessing Vulnerabilities in Maritime Cyber Physical Systems via Binary and Protocol Attack Path Modeling in Simulator Driven Environments Grant uri icon

Abstract

  • Modern maritime vessels and infrastructure increasingly rely on interconnected cyber‑physical systems (CPS) that integrate navigation technologies, operational control systems, and communication platforms across Information Technology (IT) and Operational Technology (OT) networks. While this integration enhances situational awareness and operational efficiency, it also significantly expands the maritime cybersecurity attack surface. Recent regulatory actions, including the IMO’s 2025 maritime cyber‑risk guidelines and the U.S. Coast Guard’s 2025 final rule, highlight growing concern over these risks. Many maritime systems continue to operate with legacy software, proprietary protocols, and limited security controls, while dependencies on administrative networks and remote maintenance interfaces create additional attack vectors. These weaknesses allow adversaries to exploit non‑critical components and escalate access to safety‑critical vessel functions, such as navigation and control systems.
    Despite increased attention to maritime cybersecurity governance and network monitoring, limited research has focused on software‑level vulnerabilities, binary weaknesses, and realistic attack paths within maritime CPS. This project addresses this gap through binary‑level vulnerability analysis and protocol‑based attack‑path modeling, supported by simulator‑driven experiments to evaluate the operational impact of cyber events on vessel functions. By examining how software and protocol vulnerabilities propagate through interconnected maritime systems, the research aligns with the TRM RD.D.1 objectives and aims to provide actionable insights to improve maritime infrastructure resilience and reduce cyber‑physical risks.
  • Modern maritime vessels and infrastructure increasingly rely on interconnected cyber‑physical systems (CPS) that integrate navigation technologies, operational control systems, and communication platforms across Information Technology (IT) and Operational Technology (OT) networks. While this integration enhances situational awareness and operational efficiency, it also significantly expands the maritime cybersecurity attack surface. Recent regulatory actions, including the IMO’s 2025 maritime cyber‑risk guidelines and the U.S. Coast Guard’s 2025 final rule, highlight growing concern over these risks. Many maritime systems continue to operate with legacy software, proprietary protocols, and limited security controls, while dependencies on administrative networks and remote maintenance interfaces create additional attack vectors. These weaknesses allow adversaries to exploit non‑critical components and escalate access to safety‑critical vessel functions, such as navigation and control systems.
    Despite increased attention to maritime cybersecurity governance and network monitoring, limited research has focused on software‑level vulnerabilities, binary weaknesses, and realistic attack paths within maritime CPS. This project addresses this gap through binary‑level vulnerability analysis and protocol‑based attack‑path modeling, supported by simulator‑driven experiments to evaluate the operational impact of cyber events on vessel functions. By examining how software and protocol vulnerabilities propagate through interconnected maritime systems, the research aligns with the TRM RD.D.1 objectives and aims to provide actionable insights to improve maritime infrastructure resilience and reduce cyber‑physical risks.

Date/time Interval

  • 2026-05-01 - 2026-06-01

Date Filed

  • 2026-03-01

Total Award Amount

  • 11500