DEF CON 33 - Fingerprinting Maritime NMEA2000 Networks - Constantine Macris TheDini & Anissa Elias

DEF CON 33 - Fingerprinting Maritime NMEA2000 Networks - Constantine Macris TheDini & Anissa Elias

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 25:34

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Here's the revised summary addressing the feedback, incorporating key details from the transcript that were missing or underemphasized:

Summary: Dean and Ana developed a deterministic fingerprinting method for NMEA 2000 networks to establish baselines of maritime network behavior and detect anomalies. This addresses critical security gaps in the widely used but vulnerable maritime protocol, which lacks authentication and open-source research.

Key Takeaways:

  • NMEA 2000 Vulnerability: Built on ISO 11783 (compatible with automotive CAN bus), NMEA 2000 is ubiquitous on ships but inherently insecure—lacking authentication and encryption. Publicly available research and PGN documentation are extremely limited, hindering security analysis [Transcript: ~4:00-5:30, ~7:00-8:00].
  • Core Challenge & Motivation: The high cost of maritime equipment and scarcity of open data/research make understanding "normal" network behavior difficult. Their work provides a foundation for open-source maritime cybersecurity research [Transcript: ~7:00-8:30, ~22:00-23:00].
  • Deterministic Fingerprinting Method: Their approach combines three critical elements into a mathematical fingerprint:
    1. Device Inventory: Identifying all known devices on the network (using PGN 126993 & source addresses) [Transcript: ~9:30, ~14:30].
    2. PGN Database: Cataloging all Parameter Group Numbers (PGNs) observed, including undocumented proprietary ones, and linking them to messages [Transcript: ~9:30, ~12:00-14:00].
    3. PGN Frequency Analysis: Monitoring the average transmission frequency of unique PGN-device combinations over time to characterize normal behavior [Transcript: ~14:30-16:00].
  • Anomaly Detection: The fingerprint (F) triggers alerts for any deviation: unknown devices, new/unknown PGNs (especially proprietary ones), or significant changes (>85% difference) in PGN transmission frequency from a specific device [Transcript: ~16:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Even though we're not at 4:00 right now, doors have closed. So, I'm going to make the executive decision that we can start. Okay. So, you go first. Okay. You're the first. >> Uh yeah. So, uh today we're going to be talking about a method that we developed uh for Namia 2000 fingerprinting. So, um really quick, I'll do some introductions. My name is Dean. This is Ana. I am a PhD candidate at the University of Rhode Island uh where I'm in the cyber physical systems lab and um I am a prior uh commercial mariner. I worked on ships for about seven years in New York City. I went to the United States Merchant Marine Academy. Um I was there I joined the cyber team. So I was at least aware of uh you know bits and bites uh nibbles. I think that was the joke. It was 2002 to 2006. So ESX was a thing fo…