Salty Seagull: A VSAT Honeynet to Follow the Bread Crumb of Attacks in Ship Networks

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Makrakis, Georgios Michail, Pijpker, Jeroen, Hassing, Remco, Loves, Rob, McCombie, Stephen
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866913111626219520
author Makrakis, Georgios Michail
Pijpker, Jeroen
Hassing, Remco
Loves, Rob
McCombie, Stephen
author_facet Makrakis, Georgios Michail
Pijpker, Jeroen
Hassing, Remco
Loves, Rob
McCombie, Stephen
contents Cyber threats against the maritime industry have increased notably in recent years, highlighting the need for innovative cybersecurity approaches. Ships, as critical assets, possess highly specialized and interconnected network infrastructures, where their legacy systems and operational constraints further exacerbate their vulnerability to cyberattacks. To better understand this evolving threat landscape, we propose the use of cyber-deception techniques and in particular honeynets, as a means to gather valuable insights into ongoing attack campaigns targeting the maritime sector. In this paper we present Salty Seagull, a honeynet conceived to simulate a VSAT system for ships. This environment mimics the operations of a functional VSAT system onboard and, at the same time, enables a user to interact with it through a Web dashboard and a CLI environment. Furthermore, based on existing vulnerabilities, we purposefully integrate them into our system to increase attacker engagement. We exposed our honeynet for 30 days to the Internet to assess its capability and measured the received interaction. Results show that while numerous generic attacks have been attempted, only one curious attacker with knowledge of the nature of the system and its vulnerabilities managed to access it, without however exploring its full potential.
format Preprint
id arxiv_https___arxiv_org_abs_2508_11325
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Salty Seagull: A VSAT Honeynet to Follow the Bread Crumb of Attacks in Ship Networks
Makrakis, Georgios Michail
Pijpker, Jeroen
Hassing, Remco
Loves, Rob
McCombie, Stephen
Cryptography and Security
Cyber threats against the maritime industry have increased notably in recent years, highlighting the need for innovative cybersecurity approaches. Ships, as critical assets, possess highly specialized and interconnected network infrastructures, where their legacy systems and operational constraints further exacerbate their vulnerability to cyberattacks. To better understand this evolving threat landscape, we propose the use of cyber-deception techniques and in particular honeynets, as a means to gather valuable insights into ongoing attack campaigns targeting the maritime sector. In this paper we present Salty Seagull, a honeynet conceived to simulate a VSAT system for ships. This environment mimics the operations of a functional VSAT system onboard and, at the same time, enables a user to interact with it through a Web dashboard and a CLI environment. Furthermore, based on existing vulnerabilities, we purposefully integrate them into our system to increase attacker engagement. We exposed our honeynet for 30 days to the Internet to assess its capability and measured the received interaction. Results show that while numerous generic attacks have been attempted, only one curious attacker with knowledge of the nature of the system and its vulnerabilities managed to access it, without however exploring its full potential.
title Salty Seagull: A VSAT Honeynet to Follow the Bread Crumb of Attacks in Ship Networks
topic Cryptography and Security
url https://arxiv.org/abs/2508.11325