Creating a Virtual Ship Environment Optimized for Cybersecurity Use
Jeff Greer (Professor · University of North Carolina in Wilmington)
DEF CON 33 · Day 1 · Main Stage
Overview
In an increasingly interconnected world, the maritime industry, once seen as a realm apart, is now a critical frontier for cybersecurity. Jeff Greer, a professor at the University of North Carolina in Wilmington, addressed this pressing issue in his DEF CON talk, "Creating a Virtual Ship Environment Optimized for Cybersecurity Use." The presentation outlines a novel approach to bridging the significant knowledge gap between cybersecurity students and the complex operational technology (OT) environments found on modern vessels. Greer's work highlights the urgent need for specialized educational tools that can effectively train the next generation of maritime cyber defenders and attackers.

Key moments
- 0:00 Introduction and maritime cyber education problem
- 2:39 Unitest simulator's three cybersecurity use cases
- 4:30 Five critical thinking skills for cyber education
- 6:00 Transdisciplinary approach to maritime cyber security
- 6:55 Unitest X92 simulator's 20 ship subsystems
- 8:00 Detailed simulator decking plans and bridge view
Creating a Virtual Ship Environment Optimized for Cybersecurity Use
Speakers: Jeff Greer, Professor, University of North Carolina in Wilmington
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=WHD8NAY9BhU
Overview
In an increasingly interconnected world, the maritime industry, once seen as a realm apart, is now a critical frontier for cybersecurity. Jeff Greer, a professor at the University of North Carolina in Wilmington, addressed this pressing issue in his DEF CON talk, "Creating a Virtual Ship Environment Optimized for Cybersecurity Use." The presentation outlines a novel approach to bridging the significant knowledge gap between cybersecurity students and the complex operational technology (OT) environments found on modern vessels. Greer's work highlights the urgent need for specialized educational tools that can effectively train the next generation of maritime cyber defenders and attackers.
The core challenge, as Greer articulates, is the inherent lack of maritime domain knowledge among typical undergraduate cybersecurity students, coupled with severe limitations on physical access to ships due to port security and insurance regulations. This dual constraint makes it nearly impossible for students to visualize, understand, and interact with a ship's digital operating environment – a prerequisite for effective cyber defense or offense. To overcome this, Greer initiated a joint study with Unitest Marine Simulators, a Polish company renowned for its state-of-the-art marine engine simulators designed for merchant seaman education and assessment.
Greer’s research focuses on adapting and extending these existing, regulatory-compliant simulators (specifically the Unitest X92 engine room simulator, developed to comply with STCW code) for cybersecurity education. This innovative use case aims to develop a world-class environment for teaching maritime cybersecurity, encompassing everything from basic ship domain knowledge for non-mariners to advanced security-by-design principles and hands-on cyber attack scenario response. The talk details the initial phase of this study, identifying functional gaps in current simulators and outlining a roadmap for future development towards creating truly comprehensive virtual and hybrid maritime cyber ranges.
Background
▶ Watch: Introduction and maritime cyber education problem (0:00)
The genesis of this project lies in a fundamental problem: the cybersecurity workforce, particularly at the undergraduate level, lacks foundational knowledge of the maritime domain. Unlike individuals from naval or coast guard backgrounds, most students cannot conceptualize a ship's intricate digital systems, making it difficult to apply cybersecurity principles effectively. Compounding this, practical experience through physical access to vessels is severely restricted, hindering hands-on learning crucial for understanding the unique challenges of securing operational technology (OT) environments.
Traditional maritime academies (maritimemies) have historically focused on onboard incident response for conventional, non-cyber incidents, largely driven by regulatory compliance like the STCW (Standards of Training, Certification and Watchkeeping) code. However, the modern threat landscape demands a broader perspective, encompassing naval architects designing secure ships, shipbuilders implementing secure systems, surveyors assessing cyber resilience, and landside fleet management overseeing remote operations. This necessitates a transdisciplinary approach to education, integrating maritime domain knowledge with applied cyber risk management theory and system engineering principles.
Greer's study leverages existing Unitest Marine Simulators, which are designed primarily for merchant seaman training and regulatory assessment. These simulators offer high-fidelity representations of ship systems, but their design is shaped by training needs for operational proficiency, not cybersecurity. The critical insight is to re-purpose and augment these simulators. Greer outlines three key use cases for this alternate application:
- Teaching ship domain knowledge to cybersecurity students who are non-mariners.
- Teaching security by design using Model-Based System Engineering (MBSE) or System of Systems Engineering (SoSE) concepts.
- Teaching and assessing student response to relevant cyber attack scenarios.
To facilitate this, Greer emphasizes the importance of a simplified educational framework based on five critical thinking skills: "What is it?", "Why is it important?", "How does it work?", "How can it fail?", and "How can failure be prevented?". These questions provide a structured way to approach complex systems, aligning maritime domain knowledge with system engineering and cyber risk management. The study is sponsored by Spec Innovations, which provides MBSE tools, underscoring the shift towards more rigorous, model-driven approaches to understanding and securing complex systems.
Key Findings
▶ Watch: Five critical thinking skills for cyber education (4:30)
The preliminary phase of Jeff Greer's study with the Unitest X92 simulator yielded several critical observations regarding its suitability and functional gaps for cybersecurity education:
- Limited Scope as a Full Ship Simulator: The Unitest X92 is primarily an engine room simulator. While highly detailed, it does not represent a full ship environment, lacking comprehensive bridge systems, communications infrastructure, and other critical above-the-waterline and below-the-waterline systems. For truly holistic maritime cybersecurity education, a full ship simulator is ideal. Currently, this necessitates using multiple, interfaced simulators (e.g., an engine room simulator linked with a bridge simulator) to cover the complete operational spectrum of a vessel. This impacts all three proposed use cases, particularly the ability to conduct comprehensive cyber attack scenarios.
- Insufficient Control Diagrams for Cyber Purposes: The simulator provides extensive control diagrams for various ship systems, which are invaluable for understanding mechanical and electrical operations. However, these diagrams are not practical for cybersecurity analysis. What is critically needed are network diagrams that illustrate the digital connectivity between systems, as well as visibility into the freestanding digital logic controllers (DLCs) or Programmable Logic Controllers (PLCs) that govern industrial processes within the engine room and other areas. Without this network-centric view, it is challenging to teach security by design principles or develop robust cyber risk management strategies.
- Absence of Cyber-Related Faults in the Simulator Library: The Unitest X92 features a comprehensive fault simulation library designed for training merchant seamen on operational malfunctions (e.g., engine failure, pump issues). Crucially, this library does not include any cyber-related items. This represents a significant gap for teaching and assessing student response to cyber attack scenarios. The ability to induce cyber faults (e.g., denial-of-service on a critical control system, data manipulation in navigation) is fundamental for realistic cybersecurity training.
These findings highlight that while existing maritime simulators provide an excellent foundation for understanding ship operations, they require substantial adaptation and augmentation to become effective tools for cybersecurity education. The study emphasizes the opportunity to evolve these platforms to address the unique requirements of maritime cyber defense, moving beyond traditional operational training to encompass the digital vulnerabilities and attack vectors inherent in modern vessel systems.
Technical Deep Dive
▶ Watch: Transdisciplinary approach to maritime cyber security (6:00)
The technical foundation of Greer's study rests on the Unitest X92 marine engine simulator, a sophisticated platform designed to comply with STCW code for merchant seaman training. This simulator models a stereotypical container ship, functioning as an Apex cyber-physical system comprising over 20 interconnected subsystems. These include the bridge, diesel generators, main engine, auxiliary systems, and various pumps and control mechanisms. The simulator provides detailed decking plans, illustrating the physical layout of these systems, and visual representations of the bridge's connection to the engine control room via the "telegraph"—a historical maritime term for communication.
Within the engine control room, the simulator presents a realistic interface with control panels for the main engine and electrical switchgear. Detailed main engine control diagrams are provided, crucial for understanding the operational logic. The 3D models of the engine, specifically a Winther Gas and Diesel 10-cylinder two-cycle engine (formerly owned by Vortsilla, now by China Shipping), offer a high-fidelity visual and functional representation. Subsystems like the generator sets (primary, backup, emergency) are also simulated with operational status dashboards. The simulator's existing training scenarios and assessments focus on operational proficiency and fault resolution, as mandated by IMO and STCW. However, a significant technical gap identified is the absence of cyber-related fault simulations within this library.
To address the cybersecurity deficiencies, Greer advocates for the application of System of Systems Engineering (SoSE) and Model-Based System Engineering (MBSE). He references work from Purdue University and utilizes MBSE tools from Spec Innovations to simplify complex digital environments through abstraction. Greer has developed a set of methods crucial for analyzing and securing these complex systems:
- Security Domain Boundary and Attack Surface Analysis (Eyebox Method): This involves conceptualizing an "imaginary box" around a vessel or a specific system (e.g., the engine room). Any element that physically or logically "breaks the plane" of this box represents a potential cyber attack vector. These vectors can be categorized into four types:
- Digital cables: Physical connections breaking the boundary.
- RF energy: Wireless communication, GPS, satellite links.
- Cyber supply chain: Trojan horse attacks embedded in delivered hardware or software.
- Authorized personnel: Individuals susceptible to social engineering attacks.
- Unauthorized personnel: Direct attempts to breach physical or digital security.
- Organization Function Analysis: This method investigates how an organization's behavior and operational processes over time can impact the attack surface structure and condition. For example, maintenance procedures, crew changes, or software updates can introduce new vulnerabilities.
- System Operational Dependency Analysis (SODA): Recognizing that the NIST CSF 2.0 emphasizes identifying digital assets, SODA goes further by analyzing the interdependency or coupling of these assets. Coupling can occur through networks, software applications, or shared resources. Classification of coupling is often based on where decision-making occurs (centralized, decentralized, or distributed). Understanding these dependencies is vital for identifying single point failures, common cause failures, and cascading failures, which are critical for both safety and resiliency engineering.
- Criticality Analysis for Systems and Components: Not all cyber risks can be treated equally. This method involves defining parameters (e.g., regulatory compliance, safety, security, resiliency) to classify systems and components based on their mission criticality. This focus helps establish appropriate security scopes and prioritize risk management efforts.
- Cyber Hazard Loss Analysis: This method informs the cyber risk management strategy design by identifying potential cyber hazards and their associated losses. Greer references Nancy Levenson's STPA (System Theoretic Process Analysis) from MIT, which has been adapted for cybersecurity by Dr. William Young of the Air Force Cyber Institute. Additionally, MITRE's TARA (Threat Assessment Remediation Analysis) is recommended for identifying and mitigating threats. Information on potential losses can be sourced from OSINT (Open-Source Intelligence), insurance companies, and threat intelligence feeds.
- Cyber Risk Management Strategy Design: Drawing on NIST SP800-39 (published 2012, still relevant), this involves designing a strategy that distinguishes between strategic and tactical cyber risk. The control plane (the cybersecurity program itself) addresses strategic risk, while the operating plane involves deploying security controls or countermeasures to manage tactical risk and maintain continuity of operations.
Finally, Greer briefly touches upon the inherent complexity of ship network architectures. A typical vessel features at least three distinct network types:
- The NMEA network on the bridge, a serial bus for navigation and communication equipment.
- The Ethernet network for commercial and administrative functions.
- Various specialized industrial networks below decks, such as Modbus and Profibus, controlling engine room and operational systems.
The increasing integration points between these disparate networks present significant security challenges, requiring holistic management from a security point of view.
Demo / Proof of Concept
▶ Watch: Unitest X92 simulator's 20 ship subsystems (6:55)
While Jeff Greer's presentation did not include a live demonstration of a cyber attack on the Unitest X92 simulator, it effectively served as a conceptual proof of concept for its potential. Greer showcased the simulator's robust capabilities for traditional maritime training, detailing its realistic engine control room, main engine diagrams, 3D models, and operational dashboards. He explicitly highlighted the existing fault simulation features, noting the critical absence of cyber-related faults.
The "demo" aspect of the talk was primarily a detailed walkthrough of the simulator's current state and a compelling argument for its adaptation. Greer demonstrated the depth of the simulated environment, from decking plans to specific engine components, illustrating how this existing fidelity could be leveraged to teach maritime domain knowledge. The core of his argument was that by understanding the simulator's current operational capabilities, one could clearly identify the necessary augmentations to transform it into a powerful cybersecurity training platform.
Looking ahead, Phase Two of the study aims to move towards a more advanced proof of concept by developing hybrid cyber ranges. This involves integrating the synthetic ship environment of the Unitest X92 simulator with physical testbeds, network simulators, industrial controllers, and physical security control systems. Greer cited the example of Boeing’s work with the V22 Osprey, where a crashed aircraft was linked to a synthetic world to understand its operations, as inspiration for bridging the virtual and physical. This future work, projected for completion around spring 2026, will serve as the true demonstration of a fully optimized virtual ship environment for cybersecurity use.
Defensive Implications
▶ Watch: Detailed simulator decking plans and bridge view (8:00)
The insights and methodologies presented by Jeff Greer offer profound defensive implications for the maritime sector, emphasizing a proactive, comprehensive, and education-driven approach to cybersecurity.
Firstly, the most immediate implication is the critical need for specialized cybersecurity education tailored to the maritime domain. Defenders cannot effectively protect what they do not understand. By adapting simulators like the Unitest X92, educational institutions can provide cybersecurity professionals with essential maritime domain knowledge, enabling them to visualize ship systems, understand their operational context, and identify unique vulnerabilities. This directly addresses the problem of limited physical ship access, offering a scalable solution for hands-on learning.
Secondly, the emphasis on security by design using Model-Based System Engineering (MBSE) and System of Systems Engineering (SoSE) is paramount. Naval architects, shipbuilders, and system integrators must incorporate cybersecurity considerations from the earliest stages of design. Utilizing methods like Security Domain Boundary and Attack Surface Analysis (Eyebox method) and System Operational Dependency Analysis (SODA) allows for a holistic understanding of potential attack vectors and interdependencies, enabling the creation of more resilient and secure vessel architectures. This moves beyond merely patching vulnerabilities to fundamentally engineering security into the ship's DNA.
Thirdly, the development of robust cyber risk management strategies is essential. Defenders must implement Greer's recommended techniques, such as Criticality Analysis to prioritize assets based on regulatory, safety, security, and resiliency parameters. Cyber Hazard Loss Analysis, informed by STPA and TARA, can help identify probable attack scenarios and their potential impacts, guiding the allocation of defensive resources. This systematic approach ensures that security investments are focused on protecting the most critical systems and functions, minimizing the likelihood and impact of successful attacks.
Furthermore, addressing the identified gaps in simulator capabilities directly informs defensive posture. The lack of network diagrams in current simulators highlights a real-world deficiency in understanding ship IT/OT network architecture. Defenders must demand and develop comprehensive network visibility, mapping all digital assets, communication pathways, and control logic (e.g., PLCs). The absence of cyber-related fault simulations underscores the need for organizations to develop and practice cyber incident response plans that go beyond traditional operational failures, specifically addressing scenarios like ICS/OT compromise, data manipulation, and denial-of-service attacks affecting critical ship systems.
Finally, the talk implicitly advocates for stronger cyber supply chain security. The "Trojan horse attack" vector emphasizes the need for rigorous vetting of hardware and software components integrated into ship systems. Defenders must also consider the human element, implementing training to mitigate social engineering risks among authorized personnel. The complex integration points between NMEA, Ethernet, and industrial networks (Modbus, Profibus) present significant challenges. Defenders must implement strong network segmentation, intrusion detection, and secure gateway solutions to manage these interfaces effectively, preventing lateral movement between different domains of ship operations. The ultimate goal is to move towards hybrid cyber ranges that can simulate and test defensive strategies against realistic, complex, multi-vector attacks in an environment that mirrors the synthetic and physical realities of modern ships.
Key Takeaways
- Maritime cybersecurity education faces significant hurdles: Undergraduate students often lack fundamental maritime domain knowledge, and physical access to ships for hands-on training is severely restricted.
- Existing maritime simulators offer a strong foundation for cyber training: Commercial simulators like the Unitest X92, designed for merchant seaman training, can be adapted to teach ship domain knowledge, security by design, and cyber attack response, despite current limitations like lacking cyber-specific fault simulations.
- System of Systems Engineering (SoSE) and Model-Based System Engineering (MBSE) are crucial: These methodologies, along with tools from Spec Innovations, provide a structured approach to understand, analyze, and secure the complex, interconnected operational technology (OT) environments found on modern vessels.
- Comprehensive risk management requires specialized techniques: Methods like the Eyebox method for attack surface analysis, System Operational Dependency Analysis (SODA) for understanding asset coupling, and Criticality Analysis are essential for identifying, prioritizing, and mitigating cyber risks in maritime systems.
- Future maritime cyber ranges will be hybrid: The next phase of development involves integrating virtual simulators with physical testbeds, industrial controllers, and network simulators to create realistic, hands-on training and assessment environments for complex cyber-physical systems.
- A holistic, transdisciplinary approach is vital: Securing ships demands collaboration across naval architects, shipbuilders, operators, and cybersecurity professionals, integrating maritime domain knowledge, system engineering principles, and advanced cyber risk management strategies.
About the Speaker(s)
Jeff Greer is a distinguished Professor at the University of North Carolina in Wilmington (UNCCW), where he specializes in and teaches maritime cybersecurity. He is a leading figure at UNCCW's Center for Cyber Defense Education and the McCartic research hub, demonstrating his commitment to advancing cybersecurity knowledge and practices. Greer is currently spearheading a joint study with Unitest Marine Simulators out of Poland, focusing on the innovative development of virtual ship environments for cybersecurity training. His passion lies in bridging the knowledge gap between cybersecurity students and the complex operational realities of the maritime domain, preparing the next generation to tackle the unique challenges of securing vessels in an increasingly digital world.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Legitimate niche problem, decent early-stage research, but this is a roadmap talk masquerading as a findings talk. Greer is doing real work in an underserved domain, but the content is too preliminary and too light on technical substance to justify a DEF CON slot over a blog post or a maritime-focused workshop.
Heather Calloway (CISO) — SOLID
Greer identifies a real and underserved problem — maritime OT is genuinely opaque to most of the cybersecurity workforce, and the access constraints are real. But this is a research-in-progress presentation, not a finished program, and the talk stops well short of telling defenders, operators, or security leaders what to do with any of it right now.