All Your GPS Are Belong To Us: Towards Stealthy Manipulation of Road Navigation Systems

Authors: 

Kexiong (Curtis) Zeng, Virginia Tech; Shinan Liu, University of Electronic Science and Technology of China; Yuanchao Shu, Microsoft Research; Dong Wang, Haoyu Li, Yanzhi Dou, Gang Wang, and Yaling Yang, Virginia Tech

Abstract: 

Mobile navigation services are used by billions of users around globe today. While GPS spoofing is a known threat, it is not yet clear if spoofing attacks can truly manipulate road navigation systems. Existing works primarily focus on simple attacks by randomly setting user locations, which can easily trigger a routing instruction that contradicts with the physical road condition (i.e., easily noticeable).

In this paper, we explore the feasibility of a stealthy manipulation attack against road navigation systems. The goal is to trigger the fake turn-by-turn navigation to guide the victim to a wrong destination without being noticed. Our key idea is to slightly shift the GPS location so that the fake navigation route matches the shape of the actual roads and trigger physically possible instructions. To demonstrate the feasibility, we first perform controlled measurements by implementing a portable GPS spoofer and testing on real cars. Then, we design a searching algorithm to compute the GPS shift and the victim routes in real time. We perform extensive evaluations using a trace-driven simulation (600 taxi traces in Manhattan and Boston), and then validate the complete attack via real-world driving tests (attacking our own car). Finally, we conduct deceptive user studies using a driving simulator in both the US and China. We show that 95% of the participants follow the navigation to the wrong destination without recognizing the attack. We use the results to discuss countermeasures moving forward.

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {217476,
author = {Kexiong (Curtis) Zeng and Shinan Liu and Yuanchao Shu and Dong Wang and Haoyu Li and Yanzhi Dou and Gang Wang and Yaling Yang},
title = {All Your {GPS} Are Belong To Us: Towards Stealthy Manipulation of Road Navigation Systems},
booktitle = {27th USENIX Security Symposium (USENIX Security 18)},
year = {2018},
isbn = {978-1-939133-04-5},
address = {Baltimore, MD},
pages = {1527--1544},
url = {https://www.usenix.org/conference/usenixsecurity18/presentation/zeng},
publisher = {USENIX Association},
month = aug
}

Presentation Video 

Presentation Audio