A Synchronous GNSS Spoofing Attack Model by Exploiting Basic Safety Message Transmissions for Connected and Automated Vehicles
Muhammad Sami Irfan, Minhaj Uddin Ahmad, Zakia Zaman, Sagar Dasgupta, Mizanur Rahman, The University of Alabama
Location:
Palm
Date/Time: Wednesday, Sep. 16, 4:23 p.m.
Global Navigation Satellite Systems (GNSS), particularly the Global Positioning System (GPS), remain foundational to modern transportation, navigation, and safety-critical cyber-physical systems. However, civilian GPS signals are openly specified, low-power, and unauthenticated, rendering them vulnerable to spoofing attacks in which an adversary transmits counterfeit satellite signals to mislead a target receiver. The current literature on spoofing attacks outlines two major spoofing attack forms: asynchronous and synchronous. These attack modes are differentiated by their approach towards capturing the GNSS receiver tracking loops. In asynchronous attacks, the attacker need only perform an approximate alignment of the spoofed signal’s code delay and doppler frequency with that of the authentic signal incident at the victim receiver antenna. The attacker then forces the victim receiver to lose its lock on the authentic signal by either performing jamming beforehand or establishing a substantial power advantage on the spoofed signal. This is the most practical form of spoofing and is readily implementable without requiring advanced knowledge of victim receiver’s position or velocity. However, this also makes them easily detectable through a number of Signal Quality Monitoring (SQM) metrics statistics [1]. Therefore, a more sophisticated approach like the synchronous spoofing attack aims to evade this detection by using a spoofed signal that is closely aligned with the authentic signal in terms of code delay and doppler frequency. This allows the spoofer to make the receiver lock on to the spoofed signal with minimal power advantage whilst triggering no SQM based detections in a seamless manner. In contrast to the asynchronous spoofing attack, synchronous spoofing attacks are difficult to implement in practice due to the need of generating closely aligned signal parameters with the authentic signal at the victim receiver antenna. Using simulated data, prior studies in this regard have explored the practical requirements in terms of code delay and doppler alignment that is necessary for successful synchronous attacks [2]. The fundamental challenge for the spoofer then becomes the tracking of the victim receiver to achieve such precise alignment necessary for successful synchronous attacks.
In the threat against autonomous vehicle navigation, an attacker would need to track the vehicle in order to determine its relative position and thereby generate a synchronous attack. This presents an additional hurdle that needs to be overcome. However, modern connected and automated vehicles (CAVs) are equipped with on-board units (OBUs) that relay the vehicle’s GPS location, speed, heading and acceleration at up to 10 times each second via wireless broadcasts known as Basic Safety Message (BSM). These broadcasts take place though the Cellular Vehicle-to-Everything (C-V2X) protocol and are open and unencrypted, thereby can be received by other OBU devices in the vicinity. Thus, for an attacker aiming to perform a synchronous attack on a CAV without triggering traditional SQM detection metrics, the BSMs present a side channel that can be used to extract the victim receiver’s location and dynamics states to effectively track the victim. In light of this exploitable vulnerability of CAVs, in this study we have the following objectives:
I. Development of a synchronous spoofing attack model against a CAV that exploits BSM transmissions for target receiver tracking
II. Investigating the tolerance limits for successful execution of the attack model and the maximum achievable position and velocity deviations without violating synchronous attack conditions
The attack model development involves the generation of accurate code delay and doppler frequency parameters that are aligned with the authentic signal parameters at the victim antenna. It is therefore necessary for the attacker to estimate these values. To this end, we design a tracking filter that leverages GPS location and vehicle dynamics measurements extracted from BSM broadcasts to estimate the required code delay and doppler frequency value necessary to align a spoofed signal with the authentic signal at the victim antenna. Additionally, the attacker needs to account for measurement lags, hardware delays, BSM transmission and reception delays, code delay offset due to the distance between spoofer and victim antennas and the receiver clock bias. Consequently, a constrained optimization is performed over this delay values to minimize the difference between the BSM reported location and the location corresponding to the spoofer’s generated signal. The tracked code delay and doppler frequency values in conjunction with satellite broadcast ephemeris along with appropriate compensations for the above delays are then used to synthesize spoofed signals that are to be transmitted to the victim receiver.
To validate the attack model, it is implemented on data collected from real-world experiments. On the vehicle end, a vehicle mounted data collection setup is prepared consisting of a commercial OBU, an accurate GNSS receiver with precise point positioning as reference and a radio frequency (RF) front end device to record raw GNSS intermediate frequency (IF) samples as baseband IQ files. The commercial OBU comes with a single antenna that integrates GNSS and cellular reception. A separate antenna is thus used to record a highly accurate GNSS reference solution using the reference receiver. The same antenna is connected to the RF front end via a splitter to record the raw IF samples. The antenna for the reference receiver and IF recording setup is placed at a slight offset to ensure that the captured IF signal is as representative as possible to the signal incident at the OBU antenna. During experiments, the OBU transmits its GNSS location and vehicle speed, heading and acceleration. Simultaneously, the reference receiver records an accurate (~2.5cm horizontal error) log of the vehicle location, and the RF front end captures the raw GNSS signal. The reference logs serve as ground truth values thereby enabling the study of OBU location accuracy on attack efficacy. On the attacker side, another OBU is equipped to receive the victim vehicle’s BSM transmissions. The victim vehicle’s location and dynamics information are then extracted from the received BSM and fed into the tracking filter for attack generation. Experiments are carried out for static condition and constant velocity straight line motion.
Upon the generation of the code delay and doppler frequency parameters and the subsequent synthesis of the spoofed signal as IF samples, it is digitally combined with the recorded IF samples from the victim vehicle. The combined signal is then processed through a software defined GNSS receiver. The processed signal is then used to evaluate the efficacy of the spoofing method using the receiver correlator outputs. SQM metrics are used to assess the effect of the spoofing signal on correlator output distortion. At first, only the recorded IF samples are processed to calculate the SQM metric statistics under nominal unspoofed conditions. Subsequently, the SQM metrics of the combined authentic and spoofed signals are calculated. The tolerance limits for the attack are established by quantifying the difference between the nominal SQM distribution against the spoofed SQM distribution when successful capture of the receiver tracking loop is achieved. Additionally, for successful attacks, the limits of location and velocity manipulation are investigated by observing the location output of the receiver whilst maintaining undetectable correlator distortions for a range of location offset and location drag-off rate.
The results are intended to inform the design of CAV GNSS receivers that are resilient to such forms of attack and account for the vulnerability due to BSM transmissions. Beyond theoretical formulations of spoofing attacks, this study provides the first practical demonstration of a synchronous spoofing attack against CAVs.
References:
[1] E. G. Manfredini, B. Motella, & F. Dovis, “Signal quality monitoring for discrimination between spoofing and environmental effects, based on multidimensional ratio metric tests,” In Proceedings of the 28th International Technical Meeting of the Satellite Division of the Institute of Navigation (ION GNSS+ 2015) (pp. 3100-3106), 2015.
[2] N. O. Tippenhauer, C. Pöpper, K. B. Rasmussen, & S. Capkun, “On the requirements for successful GPS spoofing attacks,” In Proceedings of the 18th ACM conference on Computer and communications security (pp. 75-86), 2011.
For Attendees
Program
Registration
Hotel
Conference Events
Travel and Visas
Exhibits
Kepler Nominations
For Authors and Chairs
Abstract Management
Author Resource Center
Student Paper Awards
Editorial Review Policies
Publication Ethics Policies
For Exhibitors
Exhibitor Resource Center
Other Years
Future Meetings
Past Meetings