Smiling woman sitting in front of a window. Behind her buildings of Midtown Atlanta are visible.

Cybersecurity Student Spends Summer of Securing the High Seas

When Anna Raymaker began her Ph.D. at Georgia Tech, she hadn't yet decided which area of cybersecurity she wanted to pursue. That changed when she began working on a boat test bed and talking with mariners about the cybersecurity challenges they face at sea.

Those conversations led Raymaker to focus her research on maritime security, including vulnerabilities in the Automatic Identification System (AIS), which ships use to broadcast their location, speed, and course.

This summer, Raymaker brought this research to Massachusetts Institute of Technology (MIT) Lincoln Laboratory, where she built a test bed to study AIS security in a controlled environment. The experience has also led to new research questions, from the security of shipboard Starlink connections to autonomous vessels and other maritime technologies.

We spoke with Raymaker about her research, her experience at Lincoln Laboratory, and what she hopes to investigate next.

What will you be working on at the MIT Lincoln Laboratory next?

After submitting our paper based on this summer’s work to a cybersecurity conference, we are continuing our collaboration and starting a new project to identify critical infrastructure that uses unique protocols. The project is still in the early stages of planning and design, but I’m excited to continue working with the team.

What was the biggest challenge you faced while building and testing the AIS security testbed, and how did you work through it?

The biggest challenge was getting equipment designed to be installed and operated on a boat to function properly in a lab setting. That meant using a Faraday cage so that our AIS transmissions and security experiments wouldn’t accidentally broadcast to nearby ships or interfere with real maritime traffic. I also had to simulate GPS signals and set up additional hardware to trick the AIS transponders into thinking they were operating on a real vessel. Putting all those pieces together into a safe, realistic test bed was challenging, but it ultimately let us study the equipment in a controlled environment.

You mentioned the collaborative culture at Lincoln Laboratory. Can you share a specific interaction or experience with a researcher there that had an impact on you or your work?

Working with Hamed Okhravi, a senior staff member at Lincoln Laboratory, was an amazing experience. He was my mentor and consistently went out of his way to connect me with people who could help me find datasets, access equipment, or get the lab space I needed for my work. For example, when I realized I needed a Faraday cage for my experiments, he connected me with the Mobile Device Lab and helped me get access very quickly. The lab manager was also immediately willing to let me use the space and equipment. That experience really reflected the culture I saw throughout Lincoln Laboratory. Everyone genuinely wanted to help each other get what they needed to move their research forward.

How did Georgia Tech prepare you for the work at Lincoln Laboratory, and did the internship change how you think about your research or future career?

My experience at Georgia Tech was instrumental in preparing me for my work at Lincoln Laboratory. The way I was taught to think through difficult research problems and work independently toward solutions translated well to a large research lab. I was able to hit the ground running and take ownership of a project because Georgia Tech had prepared me to lead research independently. The internship also gave me valuable experience in a research environment outside academia, which broadened my perspective on how I could pursue research in the future.

You’ve said you want to work through the cybersecurity problems mariners have shared with you “one by one.” Which problem do you most want to tackle next, and why?

Next, I’d love to look at Starlink connectivity for ships or for autonomous shipping. Mariners we’ve spoken with have raised concerns about both. With Starlink and increasingly autonomous vessels, they worry that greater remote connectivity could give attackers new ways to access onboard systems and disrupt ship operations. I think those concerns are worth investigating.

We recently had a paper accepted at CCS that examines exposed solar distributed energy resources, and I think applying a similar perspective to exposed maritime equipment could be very interesting. That paper is available here.

We also recently had a paper on measuring GPS spoofing of ships accepted at IEEE S&P. The full paper isn’t online yet, but the project was directly motivated by mariners telling us that they were struggling with GPS spoofing. That made me want to find a way to systematically measure where spoofing was occurring. 

Ultimately, the goal is to turn that kind of research into something useful for mariners, such as warning them when they are entering an area experiencing spoofing or when their own vessel may be affected and they should no longer trust their GPS. That is the kind of research I’d like to continue doing: listening to the problems mariners are actually experiencing and finding ways to investigate and address them.

Photos by Kevin Beasley and Terence Rushin/College of Computing