The modern maritime industry is characterized by networked smart ships that incorporate 9 information and communications technology (ICT) for steering, navigation, control, sensor, and 10 operational systems. Smart ships are potential targets for cybe...
The modern maritime industry is characterized by networked smart ships that incorporate 9 information and communications technology (ICT) for steering, navigation, control, sensor, and 10 operational systems. Smart ships are potential targets for cyber attacks for their network 11 connectivity and ICT application. In this study, we systematically deduced and analyzed the 12 security vulnerabilities of 30 Android-based applications used in the ocean and ships. We extracted 13 the Android application package file and used mobile security framework static analysis to analyze 14 the application’s permission information, privacy, certificates, manifest package files, code 15 vulnerabilities in the file, and password disclosures. The analysis revealed that security 16 vulnerabilities in Android-based applications applied in shipboard equipment could allow remote 17 hackers to gain control of ship engines and communication systems. Additionally, it evaluates the 18 security level of Android applications following the International Maritime Organization and 19 International Association of Classification Societies UR E27 regulations for ship cybersecurity and 20 emphasizes the need for cyber threat mitigation measures for Android ship applications, which 21 have not been studied so far. This study aims to identify potential cybersecurity threats when using the Android operating system on merchant ships, warships, unmanned vessels, and autonomous ships. The findings will inform efforts to implement enhanced cybersecurity systems for ships.