Related Experiment Video
Updated: Feb 28, 2026

Practical Methodology of Cognitive Tasks Within a Navigational Assessment
Published on: June 1, 2015
Analysis of Security Vulnerabilities in S-100-Based Maritime Navigation Software
Hoyeon Cho1,2, Changui Lee3, Seojeong Lee3
1Division of Maritime Information Technology, National Korea Maritime and Ocean University, Busan 49112, Republic of Korea.
Automated security tools miss critical vulnerabilities in S-100 electronic chart systems. Expert review is vital for identifying risks like Remote Code Execution (RCE) before mandatory adoption.
Area of Science:
- Maritime technology
- Software security
- Electronic Chart Display and Information Systems (ECDIS)
Background:
- The S-100 standard for ECDIS relies on Lua scripts for chart rendering.
- Current S-100 specifications lack defined security measures for script execution.
- This gap poses significant cybersecurity risks to maritime navigation systems.
Purpose of the Study:
- To evaluate the effectiveness of automated Static Application Security Testing (SAST) tools against expert manual review for S-100 software security.
- To identify and assess vulnerabilities in S-100-compliant software, specifically the OpenS100 reference implementation.
- To inform the International Hydrographic Organization (IHO) about necessary security enhancements to the S-100 standard.
Main Methods:
- Applied four SAST tools to the OpenS100 implementation.
- Conducted an expert manual security review of the same software.
- Developed a Proof of Concept (PoC) to verify identified vulnerabilities, including Remote Code Execution (RCE).
Main Results:
- Automated SAST tools detected numerous defects but missed 83% of expert-identified vulnerabilities.
- A critical flaw enabling RCE (CVSS 9.3) was discovered via malicious portrayal catalogues.
- SAST tools struggled with maritime domain specifics and C++-Lua interface risks.
Conclusions:
- Identified vulnerabilities are linked to S-100 standard specification gaps, not just coding errors.
- Functional safety certifications need enhancement to cover design-level security risks.
- The IHO must integrate security controls like script sandboxing into S-100 before its 2029 adoption deadline.
Related Concept Videos
Errors in Global Positioning System
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security:
Types of Global Positioning System Surveys
Pilot and Numeric Relaying
Leaky Scanning
Design Example: Analyzing Capacity Contours for Flood Risk Assessment
