Time-Based GNSS Attack Detection

📅 2025-02-06
🏛️ IEEE Transactions on Aerospace and Electronic Systems
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Civilian GNSS receivers are vulnerable to time spoofing attacks, which compromise timing integrity without requiring physical access. Method: This paper proposes a hardware-agnostic, real-time detection framework that fuses multiple trusted time sources—including network time synchronization and high-stability crystal oscillators—to construct a constellation- and attack-type-agnostic time verification architecture. It establishes a high-precision clock bias model and designs dual-stage detection algorithms: microsecond-level (150 μs) abrupt jump detection and nanosecond-level (30 ns) smooth hijacking identification, supporting cross-layer adversarial evaluation—including simulated network-coordinated attacks. Contribution/Results: The method achieves 100% detection accuracy across all attack scenarios—abrupt jumps, smooth hijacking, and composite attacks—while precisely identifying sub-30-ns timing deviations. Deployment requires zero modifications to existing GNSS receivers or infrastructure, ensuring full operational transparency and minimal integration overhead.

Technology Category

Application Category

📝 Abstract
To safeguard Civilian Global Navigation Satellite Systems (GNSS) external information available to the platform encompassing the GNSS receiver can be used to detect attacks. Cross-checking the GNSS-provided time against alternative multiple trusted time sources can lead to attack detection aiming at controlling the GNSS receiver time. Leveraging external, network-connected secure time providers and onboard clock references, we achieve detection even under fine-grained time attacks. We provide an extensive evaluation of our multi-layered defense against adversaries mounting attacks against the GNSS receiver along with controlling the network link. We implement adversaries spanning from simplistic spoofers to advanced ones synchronized with the GNSS constellation. We demonstrate attack detection is possible in all tested cases (sharp discontinuity, smooth take-over, and coordinated network manipulation) without changes to the structure of the GNSS receiver. Leveraging the diversity of the reference time sources, detection of take-over time push as low as 150us is possible. Smooth take-overs forcing variations as low as 30ns are also detected based on on-board precision oscillators. The method (and thus the evaluation) is largely agnostic to the satellite constellation and the attacker type, making time-based data validation of GNSS information compatible with existing receivers and readily deployable.
Problem

Research questions and friction points this paper is trying to address.

Detect GNSS time-based attacks
Cross-check GNSS time with trusted sources
Ensure compatibility with existing GNSS receivers
Innovation

Methods, ideas, or system contributions that make the work stand out.

Cross-checking GNSS time
Using secure time providers
Onboard clock references
🔎 Similar Papers
No similar papers found.
M
M. Spanghero
Networked Systems Security (NSS) Group – KTH Royal Institute of Technology, Stockholm, Sweden
P
P. Papadimitratos
Networked Systems Security (NSS) Group – KTH Royal Institute of Technology, Stockholm, Sweden