Skip to content
Review Open access

AIS Cybersecurity: Challenges, Vulnerabilities, and Mitigation Strategies

Jul 2026 · Journal of Marine Science and Engineering · Vol 14, pp. 1258 · 0 citations · 75 references

TL;DR

This survey provides an AIS-first, security-focused synthesis of AIS cybersecurity research, bringing together cybersecurity, maritime operations, and data-science perspectives, that provides practical guidance for securing AIS-based systems and highlights open problems for future standardization and implementation.

Abstract

Maritime operations rely on the Automatic Identification System (AIS), an open broadcast protocol whose unauthenticated, self-reported messages are easily abused. This survey provides an AIS-first, security-focused synthesis of AIS cybersecurity research. It makes three main contributions. First, it explains AIS protocol mechanics and uses them to derive the main security weaknesses that arise from open VHF broadcast, self-reported data, lack of built-in authentication and replay protection, and GNSS dependence. Second, it organizes AIS threats and mitigations into a unified taxonomy that links attack vectors, technical effects, operational impacts, and security measures across the prevent–detect–respond–recover lifecycle. Third, it assesses practical defenses, including authentication proposals, endpoint and network hardening, behavior-aware analytics, cross-sensor validation, and governance measures. The survey shows that existing work is strongest on anomaly detection and AIS data analytics, whereas standards-compatible authentication, scalable key management, backward-compatible deployment, trust-aware display integration, and operational validation remain open challenges. Consequently, AIS security is likely to require layered, staged, and standards-compatible mitigations rather than a single technical fix. By bringing together cybersecurity, maritime operations, and data-science perspectives, the survey provides practical guidance for securing AIS-based systems and highlights open problems for future standardization and implementation.

Read PDF

Similar papers

Conference Open access 2026

Research on Cybersecurity Risks and Protection Strategies Derived from Intelligent Algorithms

The study argues that, facing the constantly evolving attack patterns driven by intelligent algorithms, network security governance cannot rely solely on static rules and post-incident handling, and should further strengthen the capabilities of real-time threat identification, trusted identity verification, cross-entity collaborative response, and dynamic updates of security policies.

Ai-Hao Luo, Bao-Ze Xu · 0 citations
Review 2026

Components and Utilities of Cybersecurity

This paper examines the multifaceted field of cybersecurity, covering key domains such as network, information, cloud, endpoint, and application security, as well as cryptography, ethical hacking, security operations, and emerging technologies like AI/ML. We review current literature, industry standards, and real-world case studies to analyze best practices and challenges across these domains. Emphasis is placed on evolving threat landscapes including ransomware, phishing, and supply-chain attacks, and the regulatory frameworks (GDPR, HIPAA, CCPA) and security standards (NIST CSF, ISO/IEC 27001) that guide organisational defences. We discuss the role of incident response and threat intelligence, and outline future trends such as AI-driven threats and defences, quantum-resistant cryptography, and zero-trust architectures. This comprehensive survey provides industry-level insights and strategic guidance for practitioners, emphasising defence-in-depth and continuous improvement to protect digital assets.

Sunil Kumar Upadhyay, Sanjeev Kumar · 0 citations
Open access Jul 2026

Modern cybersecurity architecture for fraud prevention in administrative services

A cybersecurity architecture oriented toward fraud prevention in a service sector company in Lima, Peru, whose design is grounded in the documentary analysis of 385 technical incident records is proposed, forming a defense-in-depth capable of reducing residual exposure and sustaining a robust anti-fraud response in digitalized administrative environments.

Enrique Castellares Cuya, José Rengifo Espinal · 0 citations
Review Open access Aug 2026

Emerging Trends, Challenges, and Future Directions in Cybersecurity

The dual-use nature of AI, the expanding attack surfaces of cloud computing and the IoT, the evolution of Zero Trust architectures, and the forthcoming disruption of quantum computing to classical public key cryptography are causing rapid, structural shifts in the cybersecurity landscape. This study integrates and builds upon relevant literature of the aforementioned technologies and organizes the AI focused offense and defense, identity-based security, ransomware, cloud-native security, post-quantum cryptography (PQC), supply chain security, IoT/OT security, XDR platform security, and other security frameworks. We review and analyze the gaps that reduce the efficacy of security and defense postures, which include the labor gap in cybersecurity, inconsistent laws and frameworks, aging technologies, the complexity of AI and its governance, and alert fatigue from over-utilization of multiple tools. We identify autonomous security and defense, agile cryptography, AI red team exercises, human-AI defense, and a variety of models using graph theory and network theory to design and implement resilient architectures to mitigate cyber threats, as potential areas for future exploration and research. We aim to provide researchers and practitioners a comprehensive overview of the current cybersecurity environment for the year 2026.

Vishvesh Revoori, Vasudev Karthik Ravindran, Shubham Agarwal · 0 citations
Open access Aug 2026

TOWARD SDN-NATIVE CYBERSECURITY: UNIFIED THREAT MODELING, FORMAL ASSURANCE, BEHAVIORAL DETECTION, AND MULTI-CONTROLLER RESILIENCE

Software-defined networking (SDN) improves programmability and global policy control, but it also concentrates authority, exposes high-impact interfaces, and couples security to rapidly changing network state. Existing work addresses threat taxonomy, formal verification, behavioral detection, distributed control, and threat-informed defense largely as separate concerns. This study designs and analytically evaluates an SDN-native cybersecurity integration contract that unifies: a multidimensional threat model; invariant-based preventive assurance; governed hybrid detection; security-aware multi-controller resilience; ATT&CK informed traceability; and controlled learning. The framework specifies typed evidence exchanges across Observe, Verify, Detect, Orchestrate, Respond, and Learn, with explicit provenance, freshness,confidence, authority, rollback, and post response verification obligations.Analytical requirement mapping and scenario walk throughs show coherent coverage of representative attack paths under stated assumptions and expose residual uncertainties and empirical obligations. The contribution is conceptual and methodological: it does not establish runtime feasibility, quantitative superiority, classifier accuracy, Byzantine tolerance, or deployment readiness. To make subsequent validation reproducible and falsifiable, the paper defines coverage, overhead, resilience, false positive, and recovery measures together with a versioned cyber range instantiation blueprint.

Oumar Y. Maiga, Moussa Koita, I. Traoré et al. · 0 citations