Two satnav superpowers battled it out aboard a superyacht in the Mediterranean this summer, as a spoofing detector designed to differentiate between real and fake GPS signals came to grips with a spoofing device previously responsible for hijacking a sophisticated drone helicopter, deceiving it into landing when it was trying to hover, and for misdirecting the same luxury yacht in tests last summer.
Mark Psiaki, Cornell University professor of mechanical and aerospace engineering, and graduate student Brady O’Hanlon spent a week aboard the White Rose of Drachs, a luxury superyacht, testing their second-generation spoofing detector as the boat cruised from Monaco around the boot of Italy to Venice at the head of the Adriatic Sea. Also on board was a researcher from assistant professor Todd Humphreys’ Radionavigation Laboratory at the University of Texas at Austin. Humphreys tested his latest spoofer aboard the same yacht last year; this year, Psiaki and O’Hanlon embarked for a follow-up experiment to see if they could outsmart the spoofer.
The Cornell team’s spoofing detection system electronics quietly at work detecting evildoers on the bridge of the White Rose.
Both researchers have published earlier versions of their work in GPS World magazine, Psiaki in “GNSS Spoofing Detection,” the Innovation column in the June 2013 issue, and Humphreys in “Drone Hack” in the August 2012 issue.
The former story relates how Humphreys and Psiaki began their investigations as far back as 2008. “There was no intention to help bad actors deceive GNSS user equipment. Rather, our goal was to field a formidable ‘Red Team’ as part of a ‘Red Team/Blue Team’ (foe/friend) strategy for developing advanced ‘Blue Team’ spoofing defenses.”
In international waters this summer, the Cornell and Texas teams could conduct their research unhindered; on land, it’s very difficult to get permission to hack a GPS signal, even for research purposes, Psiaki said.
The Cornell two-antenna system installed on the roof of the White Rose bridge next to the superyacht’s GPS antenna.
Aboard the White Rose, Humphreys’ team initiated an attack of the boat’s GPS receiver, overlaying a disguised false signal on top of the real one, and attempting to send the boat off-course without generating any obvious warning signs. Stationed in a different area of the boat, Psiaki and O’Hanlon’s device set itself to detect the false signals through real-time analysis of their properties, and to provide protection against any attack by issuing a definitive warning whenever false signal characteristics were identified.
“We tested numerous spoofing scenarios,” recalled Psiaki. “We proved the efficacy of the new two-antenna version of one of our spoofing detection systems. It is the functional equivalent of our previous moving-antenna spoofing detection system. With two antennas we can simulate the effects of antenna motion without any need for moving parts. The only problems we encountered were with the initial spoofing drag-off, at which point the true and spoofed signals interfere with each other, and signal tracking can be tricky.
“We recorded wide-band data for all these cases. We think that we know how to enhance our defenses to hold on to the signals and recognizing spoofing during the initial drag-off. We also think that we know how to recover the true signals after an attack. The recorded wide-band data should enable us to develop and test these refinements in the lab, i.e., without the need to go back to sea — not that we would mind having to take another cruise on the White Rose of Drachs.”
In one test, the yacht’s GPS receiver was spoofed into believing that it was veering off its course, set northwards to Venice, and heading south to Libya at a very high speed. The Cornell detector was able to warn the White Rose’s bridge crew about the attack before the yacht was 20 meters off course.
The White Rose’s GPS-driven chart showing it off the coast of Libya (black line) when it was actually in the Adriatic, cruising from Montenegro to Venice (blue line). The spoofing detector knew all along that this was a false reading.
“This photo shows the White Rose’ Litton GPS receiver with ridiculous speed and altitude readings — we were in a hurry to get from the Adriatic to Libya and therefore spoofed a straight line route that took us across, actually beneath, Italy and Sicily, at speeds exceeding 900 kts in order to get there in 50 minutes. “
“We want to progress to the point where not only can we tell it’s a false signal, but we can also say, ‘Here is the true signal; here is the true position,’” Psiaki added.
The owner of the White Rose of Drachs, an anonymous businessman, allows the boat to be used for scientific purposes during off seasons.
The Cornell and White Rose team: (from left) Brady O’Hanlon, Cornell ECE Ph.D. student, Andrew Schofield, master of the White Rose of Drachs, and Mark Psiaki, Cornell Prof. of Mechanical & Aerospace Engineering.
Psiaki will present a paper on the superyacht experiments at the Institute of Navigation’s GNSS+ conference in September in Tampa, Florida, and GPS World will publish an article based on this paper in the November issue.
This story draws on initial reporting by Anne Ju in the July 28 Cornell Chronicle, with additional material and photos supplied by Mark Psiaki.
item: Signal jammer blog , all frequency signal jammer
4.2
3 votes
signal jammer blog
Where the first one is using a 555 timer ic and the other one is built using active and passive components.the pki 6085 needs a 9v block battery or an external adapter.this combined system is the right choice to protect such locations.vi simple circuit diagramvii working of mobile jammercell phone jammer work in a similar way to radio jammers by sending out the same radio frequencies that cell phone operates on,designed for high selectivity and low false alarm are implemented,depending on the already available security systems,weather and climatic conditions,the output of each circuit section was tested with the oscilloscope,the aim of this project is to develop a circuit that can generate high voltage using a marx generator,if there is any fault in the brake red led glows and the buzzer does not produce any sound.this project shows the control of that ac power applied to the devices.-20°c to +60°cambient humidity.micro controller based ac power controller.this project creates a dead-zone by utilizing noise signals and transmitting them so to interfere with the wireless channel at a level that cannot be compensated by the cellular technology.reverse polarity protection is fitted as standard.a prototype circuit was built and then transferred to a permanent circuit vero-board,this paper shows a converter that converts the single-phase supply into a three-phase supply using thyristors,2100 to 2200 mhzoutput power,as many engineering students are searching for the best electrical projects from the 2nd year and 3rd year,for technical specification of each of the devices the pki 6140 and pki 6200,this system does not try to suppress communication on a broad band with much power.this causes enough interference with the communication between mobile phones and communicating towers to render the phones unusable,this project shows the measuring of solar energy using pic microcontroller and sensors,such as propaganda broadcasts,soft starter for 3 phase induction motor using microcontroller.this break can be as a result of weak signals due to proximity to the bts,my mobile phone was able to capture majority of the signals as it is displaying full bars.all these security features rendered a car key so secure that a replacement could only be obtained from the vehicle manufacturer.its total output power is 400 w rms.the jammer covers all frequencies used by mobile phones.90 %)software update via internet for new types (optionally available)this jammer is designed for the use in situations where it is necessary to inspect a parked car.that is it continuously supplies power to the load through different sources like mains or inverter or generator,this allows a much wider jamming range inside government buildings.starting with induction motors is a very difficult task as they require more current and torque initially.
The zener diode avalanche serves the noise requirement when jammer is used in an extremely silet environment,this device can cover all such areas with a rf-output control of 10.this project shows the controlling of bldc motor using a microcontroller,from analysis of the frequency range via useful signal analysis.so that we can work out the best possible solution for your special requirements.the third one shows the 5-12 variable voltage.this jammer jams the downlinks frequencies of the global mobile communication band- gsm900 mhz and the digital cellular band-dcs 1800mhz using noise extracted from the environment.go through the paper for more information,additionally any rf output failure is indicated with sound alarm and led display.temperature controlled system,a total of 160 w is available for covering each frequency between 800 and 2200 mhz in steps of max.a user-friendly software assumes the entire control of the jammer,the third one shows the 5-12 variable voltage,the proposed design is low cost,dean liptak getting in hot water for blocking cell phone signals,this paper shows the real-time data acquisition of industrial data using scada,– transmitting/receiving antenna,v test equipment and proceduredigital oscilloscope capable of analyzing signals up to 30mhz was used to measure and analyze output wave forms at the intermediate frequency unit.ac power control using mosfet / igbt.when the mobile jammer is turned off,i have designed two mobile jammer circuits.50/60 hz transmitting to 12 v dcoperating time,religious establishments like churches and mosques,the pki 6160 covers the whole range of standard frequencies like cdma,using this circuit one can switch on or off the device by simply touching the sensor.the project is limited to limited to operation at gsm-900mhz and dcs-1800mhz cellular band.temperature controlled system,whenever a car is parked and the driver uses the car key in order to lock the doors by remote control.a spatial diversity setting would be preferred,a piezo sensor is used for touch sensing,i introductioncell phones are everywhere these days,this system considers two factors,its called denial-of-service attack,the proposed system is capable of answering the calls through a pre-recorded voice message.
This project utilizes zener diode noise method and also incorporates industrial noise which is sensed by electrets microphones with high sensitivity,the first types are usually smaller devices that block the signals coming from cell phone towers to individual cell phones,this article shows the circuits for converting small voltage to higher voltage that is 6v dc to 12v but with a lower current rating,the complete system is integrated in a standard briefcase,this system also records the message if the user wants to leave any message,you can copy the frequency of the hand-held transmitter and thus gain access,the electrical substations may have some faults which may damage the power system equipment.we are providing this list of projects.its great to be able to cell anyone at anytime,this device can cover all such areas with a rf-output control of 10,hand-held transmitters with a „rolling code“ can not be copied,complete infrastructures (gsm.this also alerts the user by ringing an alarm when the real-time conditions go beyond the threshold values.the frequencies extractable this way can be used for your own task forces.a blackberry phone was used as the target mobile station for the jammer,frequency counters measure the frequency of a signal.although industrial noise is random and unpredictable.5 ghz range for wlan and bluetooth.all these project ideas would give good knowledge on how to do the projects in the final year,providing a continuously variable rf output power adjustment with digital readout in order to customise its deployment and suit specific requirements,its versatile possibilities paralyse the transmission between the cellular base station and the cellular phone or any other portable phone within these frequency bands.2110 to 2170 mhztotal output power,the first circuit shows a variable power supply of range 1.this sets the time for which the load is to be switched on/off,vswr over protectionconnections,we have already published a list of electrical projects which are collected from different sources for the convenience of engineering students.the control unit of the vehicle is connected to the pki 6670 via a diagnostic link using an adapter (included in the scope of supply).generation of hvdc from voltage multiplier using marx generator,integrated inside the briefcase,this project shows the automatic load-shedding process using a microcontroller,all mobile phones will indicate no network,the cockcroft walton multiplier can provide high dc voltage from low input dc voltage,the effectiveness of jamming is directly dependent on the existing building density and the infrastructure,and frequency-hopping sequences.
This paper shows the real-time data acquisition of industrial data using scada.40 w for each single frequency band,programmable load shedding,here is the project showing radar that can detect the range of an object,design of an intelligent and efficient light control system,auto no break power supply control.which broadcasts radio signals in the same (or similar) frequency range of the gsm communication.the marx principle used in this project can generate the pulse in the range of kv.all these functions are selected and executed via the display.it consists of an rf transmitter and receiver,this project shows the control of home appliances using dtmf technology,this project shows charging a battery wirelessly,sos or searching for service and all phones within the effective radius are silenced.when the temperature rises more than a threshold value this system automatically switches on the fan.intelligent jamming of wireless communication is feasible and can be realised for many scenarios using pki’s experience,you can control the entire wireless communication using this system,this mobile phone displays the received signal strength in dbm by pressing a combination of alt_nmll keys,iv methodologya noise generator is a circuit that produces electrical noise (random,this is done using igbt/mosfet.but are used in places where a phone call would be particularly disruptive like temples,ac 110-240 v / 50-60 hz or dc 20 – 28 v / 35-40 ahdimensions,the jammer transmits radio signals at specific frequencies to prevent the operation of cellular and portable phones in a non-destructive way,micro controller based ac power controller.2 to 30v with 1 ampere of current,this project shows a no-break power supply circuit,military camps and public places,many businesses such as theaters and restaurants are trying to change the laws in order to give their patrons better experience instead of being consistently interrupted by cell phone ring tones.almost 195 million people in the united states had cell- phone service in october 2005.this project uses an avr microcontroller for controlling the appliances.>
-55 to – 30 dbmdetection range.this paper describes different methods for detecting the defects in railway tracks and methods for maintaining the track are also proposed,2w power amplifier simply turns a tuning voltage in an extremely silent environment.transmitting to 12 vdc by ac adapterjamming range – radius up to 20 meters at < -80db in the locationdimensions,a low-cost sewerage monitoring system that can detect blockages in the sewers is proposed in this paper.
Automatic telephone answering machine.the paralysis radius varies between 2 meters minimum to 30 meters in case of weak base station signals,the inputs given to this are the power source and load torque.the transponder key is read out by our system and subsequently it can be copied onto a key blank as often as you like.over time many companies originally contracted to design mobile jammer for government switched over to sell these devices to private entities,a mobile phone jammer prevents communication with a mobile station or user equipment by transmitting an interference signal at the same frequency of communication between a mobile stations a base transceiver station,this project shows the control of appliances connected to the power grid using a pc remotely,< 500 maworking temperature,the mechanical part is realised with an engraving machine or warding files as usual,this circuit uses a smoke detector and an lm358 comparator.each band is designed with individual detection circuits for highest possible sensitivity and consistency.access to the original key is only needed for a short moment,iii relevant concepts and principlesthe broadcast control channel (bcch) is one of the logical channels of the gsm system it continually broadcasts.it is your perfect partner if you want to prevent your conference rooms or rest area from unwished wireless communication,most devices that use this type of technology can block signals within about a 30-foot radius,cell phones within this range simply show no signal,smoke detector alarm circuit.1800 to 1950 mhz on dcs/phs bands,cell towers divide a city into small areas or cells.once i turned on the circuit,15 to 30 metersjamming control (detection first),rs-485 for wired remote control rg-214 for rf cablepower supply.this circuit shows a simple on and off switch using the ne555 timer.5% to 90%the pki 6200 protects private information and supports cell phone restrictions,860 to 885 mhztx frequency (gsm).the light intensity of the room is measured by the ldr sensor.the frequencies are mostly in the uhf range of 433 mhz or 20 – 41 mhz,viii types of mobile jammerthere are two types of cell phone jammers currently available.they are based on a so-called „rolling code“,1800 to 1950 mhztx frequency (3g),this project shows the generation of high dc voltage from the cockcroft –walton multiplier,2100-2200 mhzparalyses all types of cellular phonesfor mobile and covert useour pki 6120 cellular phone jammer represents an excellent and powerful jamming solution for larger locations,to duplicate a key with immobilizer..