<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Experimental Testing and Impact Analysis of Jamming and Spoofing Attacks on Professional GNSS Receivers</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sanja Miljanovic</string-name>
          <email>sanja.miljanovic@studenti.unipd.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Francesco Ardizzon</string-name>
          <email>ardizzonfr@dei.unipd.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Laura Crosara</string-name>
          <email>crosaralau@dei.unipd.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nicola Laurenti</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Luca Canzian</string-name>
          <email>luca.canzian@qascom.it</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Enrico Lovisotto</string-name>
          <email>enrico.lovisotto@qascom.it</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nicola Montini</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oscar Pozzobon</string-name>
          <email>oscar.pozzobon@qascom.it</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>T. Ioannides</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Rigas</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Information Engineering, Universiat` degli Studi di Padova</institution>
          ,
          <addr-line>Padova</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>European Space Research and Technology Centre (ESTEC)</institution>
          ,
          <addr-line>Keplerlaan 1, Noordwijk</addr-line>
          ,
          <country country="NL">the Netherlands</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Qascom</institution>
          ,
          <addr-line>Via Marinali 87, Bassano del Grappa</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>In recent years, global navigation satellite systems (GNSSs) have become crucial for many applications; however, GNSS receivers are susceptible to attacks such as jamming and spoofing. As a result, evaluating the impact of these attacks on real receivers is critical in order to develop efective defense strategies. In this paper we propose an evaluation mechanism and also set up an analysis platform to assess and classify impacts of attacks on the position velocity and time (PVT) solution computed by GNSS receivers. We carried out tests of jamming and spoofing attack scenarios employing mass market GNSS receivers in order to validate our procedure. Results obtained for reference scenarios are presented and discussed in the paper, also considering the cooperative action of jamming and spoofing, demonstrating the applicability of the developed tool to evaluate impacts of diferent attacks on GNSS receivers.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;GNSS</kwd>
        <kwd>Spoonfig</kwd>
        <kwd>Jamming</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Global navigation satellite system (GNSS) technology provides real-time positioning and timing
for various civil and military applications. GNSS signals are particularly susceptible to both
inadvertent and intentional interference due to their low received power (from − 163 dBW to
− 152 dBW). Furthermore, civilian GNSS signal and modulation formats are open to the public.
For these reasons, a wide range of attacks are viable. In the field of GNSS security, the major
threats considered are jamming and spoofing [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Jamming is a denial of service attack where
the adversary overshadows the received GNSS signals with a higher power noise-like signal
to make the victim receiver unable to acquire or track the satellite signal, afecting system
availability [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ]. Jammers can disrupt GNSS-based services in wide geographical areas with
radii of several kilometers [
        <xref ref-type="bibr" rid="ref3 ref4">3, 4</xref>
        ]. With a spoofing attack, the attacker produces counterfeit
GNSS signals that are similar to authentic ones, by modifying the original satellite signals in
order to manipulate the victim receiver’s estimated position [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] and/or timing. This attack
is particularly dangerous because it may succeed without the victim being aware of being
attacked.
      </p>
      <p>
        Modern GNSS receivers are equipped with interference mitigation methods, e.g., Receiver
Autonomous Integrity Monitoring (RAIM), and even spoofing detection mechanisms such as
Galileo OS-NMA [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], GPS CHIMERA [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. Because of the presence of these defense mechanisms,
analyzing the impact of common attacks on real receivers is critical for developing increasingly
efective defense methods. A first discussion of jamming impact on commercial GNSS receivers
is provided in [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], while analysis and evaluation of spoofing efects was proposed in [
        <xref ref-type="bibr" rid="ref7 ref8">7, 8</xref>
        ].
In [
        <xref ref-type="bibr" rid="ref10 ref11 ref9">9, 10, 11</xref>
        ] the authors investigate the repercussions of spoofing attacks on mass-market
positioning and navigation units integrated in modern day smartphones, while a comparative
analysis of GPS receivers resilience to software attacks can be found in [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <p>In this paper we propose an evaluation mechanism and set up an analysis platform to classify
attack impacts on GNSS receivers by analyzing the computed position velocity and time (PVT)
solution. In order to validate our procedure, we present the results obtained for some reference
scenarios, considering also a hybrid attack where jamming and spoonfig act cooperatively.
The developed tool could be employed to assess the performance of existing GNSS interference
mitigation and anti-spoofing techniques, as well as a platform to design and test new defence
mechanisms. The work was developed in the context of the position, navigation and timing
cyber response centre (PNT-CRC) project, that will provide a GNSS vulnerability assessment
service to industries, as well as mitigation solutions to enhance robustness of GNSS receivers.
The paper illustrates impact classification methodologies together with examples of metrics
and attack scenarios.</p>
      <p>The reminder of this paper is organized as follows. Section 2 introduces the security model
and metrics that will be taken into consideration for impact classification. Section 3 describes
the methodology for the experimental setup and test, while results and impact analysis are
provided in Section 4. Finally, Section 5 draws the conclusions and presents future developments
of our work.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Security Model and Measures</title>
      <p>In order to analyze the attack impact on a specific scenario we need to examine the PVT
solution computed by the GNSS receiver. For this purpose, it is suficient to process the receiver
output obtaining the information needed for our analysis, specifically: position information
(latitude, longitude, altitude, referred to as LLA), time and fix quality indicator (i.e. ”fix” or
”no fix”). This gives us the receiver status and the provided service, meaning PVT, at a typical
time rate of 1Hz. Therefore, we can build a timed list of points that represents the reported
positions of the receiver as a trajectory. The measured trajectory can be compared with the
true one and the spoofing target, if present. Hence, we introduce the following trajectories as
3D LLA coordinates vectors varying along time t
authentic trajectory pa(t), associated with the legitimate signals;
spoofing trajectory</p>
      <p>ps(t), associated with the spoofing signals;
measured trajectory pr(t), measured by the receiver.</p>
      <p>In order to evaluate the efect of an attack on the tested receiver, we compare the receiver
measurements in nominal conditions and under attack. Thus, we specialize the definition of
pr(t) into prN (t), the trajectory measured by the receiver in the nominal scenario, and prA(t), the
trajectory measured by the receiver under attack. This allows us to compute the positioning
error respectively in the the nominal and under-attack scenarios as
erN(t) = ∥prN(t) − pa(t)∥,
erA(t) = ∥prA(t) − pa(t)∥.</p>
      <sec id="sec-2-1">
        <title>2.1. Metrics</title>
        <p>
          Following the recommendations in [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ], we evaluate the attack impact on the receiver under
the test scenario by choosing as metrics the average, standard deviation, and 95-th percentile
of the position error, represented as mean, std and 95th, respectively. All these statistical
quantities will be estimated over a time window W = (tW − ∆ /2, tW + ∆ /2), centred around
tW and with duration ∆. From them we compute four performance degradation metrics, that
will be later used in section 2.2.4 for classification of the PVT degradation
α ∆ (tW ) = meanW (erA)/meanW (erN)
β ∆ (tW ) = stdW (erA)/stdW (erN)
γ ∆ (tW ) = 95thW (erA)/95thW (erN)
σ rN(tW ) = stdW (erN)
(1)
(2)
(3)
(4)
(5)
(6)
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2. Impact classification</title>
        <p>2.2.1. Failure
This section lists possible impact classes in terms of the resulting receiver condition which shall
be evaluated in sequence.</p>
        <p>This is the condition when receiver firmware crashes. The receiver status, if still reported from
the device, is not nominal but unexpected. Our proposal is to report and investigate for a
failure when the receiver output simply stops coming.</p>
        <sec id="sec-2-2-1">
          <title>2.2.2. Denial of Service (DoS)</title>
          <p>This conditions is declared when PVT solution cannot be computed for a continuous time
window longer than 5 seconds. Three things can happen for the tested receiver:
• Receiver stops sending log data (provided this is not due to a software crash and only
the PVT service is lost);
• Log files from the receiver are incomplete, missing some fields;
• Fix quality indicator is set to ”no fix”.</p>
          <p>If any of these is met, a DoS event is declared.</p>
        </sec>
        <sec id="sec-2-2-2">
          <title>2.2.3. Trajectory spoofing</title>
          <p>This condition causes the receiver to report a diferent position (or trajectory) from the
authentic one. This impact is evaluated only when spoofing attack is active and requires to
jointly monitor the authentic and spoofing trajectory, as well as the position reported by the
receiver. Considering a sequence of time windows Wi, i = 1, 2, . . ., of constant width ∆ and
center points ti spaced of T seconds, a trajectory spoofing is reported if all these conditions
are met
• receiver’s output is nominal, i.e. neither failure nor DoS events are reported;
• meanWi (∥ps(t) − pa(t)∥) &gt; 3 σ rN(ti), meaning authentic and spoofing trajectory difer
significantly, i.e. with a 3-sigma confidence level;
• meanWi (∥prA(t) − ps(t)∥) &lt; meanWi (∥prA(t) − pa(t)∥), meaning reported position is closer
to the spoofing trajectory than the authentic one.</p>
          <p>On the contrary, if any of the above condition is not met, the following impact classes shall be
considered.</p>
        </sec>
        <sec id="sec-2-2-3">
          <title>2.2.4. PVT degradation</title>
          <p>PVT accuracy degrades when the receiver reports a position which is diferent than the real
one. PVT degradation is measured for each receiver with respect to nominal conditions. Let
α ∆ (ti), β ∆ (ti), γ ∆ (ti) denote the performance degradation metrics measured in a sequence of
time windows of span ∆ and center points ti = iT . Then, we define three degradation levels,
as well as a no-degradation status, based on preset threshold values α j , β j and γ j , j = 1, 2, 3,
such that α 1 &lt; α 2 &lt; α 3, β 1 &lt; β 2 &lt; β 3 and γ 1 &lt; γ 2 &lt; γ 3. Thus, with × denoting the Cartesian
product and Sj = (0, α j ) × (0, β j ) × (0, γ j ) ⊂ R3, we have S1 ⊂ S2 ⊂ S3:
1. no-degradation: (α ∆ (ti), β ∆ (ti), γ ∆ (ti)) ∈ S1,
2. minor degradation: (α ∆ (ti), β ∆ (ti), γ ∆ (ti)) ∈ S2 \ S1,
3. major degradation: (α ∆ (ti), β ∆ (ti), γ ∆ (ti)) ∈ S3 \ S2,
4. severe degradation: (α ∆ (ti), β ∆ (ti), γ ∆ (ti)) ∈ R3 \ S3,
where A \ B denotes the set diference. When evaluating the receiver condition in the above
classification, comparison shall be done against the thresholds in sequence from case 1 to 4.</p>
          <p>For greater clarity, in Figure 1 we have reported three diferent trajectories, where the
authentic one is represented by the blue line. In our model, the trajectory in black is classiefid as
”trajectory spoofing”, as it appears to be far from the legitimate trajectory and therefore cannot
represent a degradation of the PVT solution. Instead, the red trajectory initially coincides
with the authentic trajectory , before deviating from it. Therefore, the red trajectory is first
classified as no-degradation and subsequently as minor, major and severe PVT degradation as
the gap between the red and the blue trajectories increases.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Experimental setup and attack scenarios</title>
      <p>In this section a methodology for the experimental setup and test is provided, together with
the description of attack scenarios and testing parameters.</p>
      <sec id="sec-3-1">
        <title>3.1. Experimental setup</title>
        <p>For simulation of scenarios we used QA707 software signal simulator by Qascom [14], that is
used to generate both authentic signal and possible interference or attack signals, all at the same
time. To perform the various tests needed we had to prepare the equipment as illustrated by
the diagram in Figure 2. QA707 simulates the signals (i.e. GNSS and interference), combines
them and stores the resulting composite signal in a single binary file which is fed to the USRP
X300 software-defined radio (SDR). In order to prevent the flow of direct current frequencies
going back into the SDR, potentially damaging the instrumentation, the use of a DC blocker
is advised. As GNSS receiver we used a Septentrio PolaRx5 [15]. The output of the receiver
was logged using the national marine electronics association (NMEA) standard [16], since it
ofers a common output interface across many vendors and receiver models. Moreover, we
will focus on the GPS fix data (GGA) message since it provides all the data needed for the
analysis described in Section 2. Still, notice that the very same procedure can be performed
starting from diferent logging formats, e.g., the Septentrio binary format (SBF). The obtained
experimental setup is depicted in Figure 3.</p>
        <p>In order to perform meaningful tests in an indoor laboratory scenario with wired connection,
we have to adjust the generated signal power to a realistic level. To this purpose, we started
by observing the automatic gain control (AGC) level at the receiver using a Spirent GSS9000
signal simulator, which had been previously calibrated so its output can be assumed reliable.
Then, we observed the AGC value measured by the Septentrio using the USRP X300; finally,
we added signal attenuators in order to achieve the same AGC level observed with the Spirent.
Results are reported in Table 1. In order to obtain similar conditions with respect to nominal
(Spirent) ones, we need to pick an attenuation in the range [40 dB,50 dB] while using USRP
X300 + QA707. Therefore, in the following experiments we picked an attenuation value of
50 dB.</p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2. Scenario configuration</title>
        <p>The QA707 software allows the setup of several configuration parameters that allow to model
several nominal and under attack scenarios.</p>
        <p>A first batch of settings identifies the navigation scenario and includes all the parameters
needed to characterize the navigation simulation, i.e., user position or trajectory, simulation
start time and duration, channel impairments, and number of generated channels. A second
group of settings characterizes the generation of jamming and spoofing attacks. Concerning
jamming attacks, the user can set the jamming power (which can possibly vary during the
attack simulation), central frequency, bandwidth and frequency modulation type (e.g., simple
narrow-band, frequency hopping or chirp).</p>
        <p>Regarding signal-level spoofing attacks, the QA707 allows two types of attack simulations.
The former, referred to as channel spoofing , allows the operator to configure pseudoranges
and Doppler frequency associated to each spoofed channel (i.e. a specific satellite). This type
of simulation can, for example, prevent the PVT algorithm from converging to any position,
setting pseudorange values that do not correspond to any physical point in space. However, in
the channel spoofing mode it is dificult to configure a spoofing attack that is consistent with
a specific spoofing trajectory. Instead, the second attack simulation, called trajectory spoofing ,
allows the operator to configure a spoofing trajectory, so that the spoofing signals associated
to all channels are generated consistently with it. The spoofing trajectory can be both static
(i.e., a fixed position) or dynamic and is fed to QA707 software as an input. For both attack
types, user can define the spoofer transmitting power.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Experimental Results</title>
      <p>The results discussed in this section have been obtained through experimental tests using the
setup depicted in Figure 3. The goal of these tests is to recognize the impacts of diferent types
of jamming and spoofing attacks on commercial GNSS receivers, according to the metrics
and the classification method outlined in Section 2. By way of example, we will discuss
three diferent attack scenarios, namely a jamming scenario, a spoofing scenario and, finally, a
scenario were jamming and spoofing act cooperatively. The trajectories used for the dynamic
scenarios are those reported in Figure 1: the blue one represents the authentic trajectory pa(t)
for all scenarios while the black one is the target trajectory for the spoofing attack ps(t).</p>
      <p>All the tests were performed fixing the following parameters:
Simulated time and day : August 01, 2021, 12:00:00;
Duration : 00:10:00;</p>
      <sec id="sec-4-1">
        <title>Visible satellites 17;</title>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Received GNSS signal power : − 158 dBW;</title>
      <p>Concerning the parameters discussed in Section 2.2, we decided to keep them constant for all
the experiments:
• ∆ = 30 seconds,</p>
      <p>T = 10 seconds;
• α 1 = 2, α 2 = 4, α 3 = 8;
• β 1 = 1.5, β 2 = 3, β 3 = 10;
• γ 1 = 2.5, γ 2 = 5, γ 3 = 8.5.</p>
      <p>
        The threshold values α j , β j and γ j , j = 1, 2, 3, were calculated based on testing documents
for GNSS receivers released by european telecommunications standards institute (ETSI) [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ].
More specifically, in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] GNSS receivers are discriminated into three categories A, B and C,
starting from high-end and loosening the performance requirements to low-end ones, according
to vertical precision accuracy (VPA) and horizontal precision accuracy (HPA) levels1. In
particular, we considered the values regarding the open area scenario which are summarized
in Table 2. Note that the performance requirements for moving scenarios specified in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] are
identical to those for static scenarios, for the metrics under consideration. Since we aim to
1VPA (HPA) is defined as the diference (error) between the position of the location target reported by the
GNSS based location system (GBLS) and its true position projected onto the vertical (horizontal) plane, at a
given time (i.e. with a given timestamp). We remark that these are diferent with respect to the VPA and the
HPA as typically used in the literature (e.g., [17]).
generalize with respect to receiver type and experimental settings, we consider a receiver to
always be in class A while in nominal scenario. Then, the relative dropping of class caused by
the tested attacks, from class A to B or from class A to C, is interpreted as major or severe
degradation, respectively. Therefore, we computed α 2, β 2, γ 2 as tB/tA and α 3, β 3, γ 3 as tC /tA,
rounding to the nearest multiple of 0.5. It is worth noting that we get the same threshold values
whether we start with vertical or horizontal position accuracy performance requirements.
      </p>
      <p>Moreover, we introduce the minor degradation category, in order to characterize cases when
the PVT degradation is noticeable but not so disrupting to change the receiver relative class.
So, the values of α 1, β 1 and γ 1 have been computed halving α 2, β 2 and γ 2, respectively.</p>
      <sec id="sec-5-1">
        <title>4.1. Jamming scenario</title>
        <p>We tested a triangular frequency modulation jamming attack in dynamic PVT model, i.e.
assuming that the position of the receiver is changing over time. We considered a
narrowband jammer transmitting triangular modulated Gaussian noise with bandwidth 100kHz. We
gradually increased the jammer’s power over the time interval considered, from − 119 dBW to
− 112 dBW of received power. In Figure 4 we show impact classification results for the jamming
scenario, for 5 Hz of frequency variation rate (rate of variation of the frequency modulation)
and frequency modulation span (peak-to-peak amplitude of the frequency modulation, across
the central frequency) of 200 kHz. DoS status was detected when the jamming signal power
exceeded − 118 dBW, at 200 seconds of scenario, meaning that the jamming attack was
successful. In Figure 4 the red, green and blue curves depict the values of the parameters α, β and
γ during the tested scenario. Moreover, Figure 4 exhibits an abrupt degradation behaviour
since the receiver status jumps from minor degradation to DoS. This efects is a consequence
of the increasing jamming power: first the receiver manages to mitigate jammer’s interference
but, when the jamming signal power exceeded − 118 dBW, it looses the track on the legitimate
signal, leading to DoS status.</p>
      </sec>
      <sec id="sec-5-2">
        <title>4.2. Spoofing scenario</title>
        <p>We carried out spoofing attack tests both in static (where the authentic and target spoofing
trajectories are fixed positions) and dynamic (moving trajectories) scenarios, considering 10
spoofed satellites out of 17. Spoofing attack is successful if the impact classification procedure
identifies the receiver status as trajectory spoofing. Impact classification results for the static
spoofing scenario are shown in Figure 5, where the power gain of the spoofing signal tested
with respect to the legitimate signal increases uniformly from 10 dB to 17 dB in the considered
time interval. Fixed position spoofing was successful for spoofing signal gains greater than
14 dB, after 374 seconds since the beginning of the test. The results obtained for the dynamic
spoofing attack are shown in Figure 6, for a spoofing signal power uniformly increasing in
the considered time interval from 17 dB to 24 dB gain over the authentic signal. The impact
of the attack on the receiver was classified as trajectory spoofing at 502 seconds of scenario
when the spoofing signal power gain exceeded 23 dB. Therefore, based on the results depicted
in Figure 5 and Figure 6 we can conclude that it is easier for attacker to achieve successful
trajectory spoofing attack in case of a static spoofing scenario than in a dynamic one. Figure
5 and Figure 6 shows also the values of the parameters α, β and γ during the tested scenarios.
Moreover, in both figures we can notice a similar behaviour: when the spoofing gain reaches
a certain threshold, a DoS status is detected since the receiver stops tracking the legitimate
signal. Then, with a further increase of the spoofing power, the receiver locks onto the spoofing
signal and falls into the trajectory spoofing status.</p>
      </sec>
      <sec id="sec-5-3">
        <title>4.3. Joint Jamming and Spoofing scenario</title>
        <p>We tested the reaction of the receiver to the cooperative action of jamming and fixed position
spoofing attacks. We used jamming before the spoofing attack to force the receiver into
acquisition mode by inducing loss-of-lock on the legitimate signal, then we turned of the jammer so
that the spoofing position could be collected by the receiver and, in case the spoofing attack
is successful, recognized as authentic. In Figure 7 we show the impact classification results,
for a narrow-band jammer with band of 100 kHz, frequency modulation span equal to 200 kHz
and constant jamming signal power equal to − 112 dBW. The power gain of the spoofing signal
tested with respect to the legitimate signal was uniformly increased from 10 dBW to 17 dBW
in the time interval between 300 and 600 seconds. Fixed position spoofing was successful for
power gain of 10 dBW. We note that, the cooperative action of jamming and spoofing allows
the spoonfig attack to be successful with a lower power gain than the one detected when only
ifxed position spoofing is applied. In fact, as described in Section 4.2, spoofing alone is
successful for attack signal power gain with respect to the legitimate signal greater than 14 dB,
whereas when the jammer acts before the spoofer, the latter is successful for power gain greater
than 10 dB relative to the legitimate signal.</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>5. Conclusion</title>
      <p>In this paper we have built a thorough efectiveness evaluation mechanism and also set up an
analysis platform to evaluate and classify attack impacts on GNSS receivers; in the future, it
could become a useful tool for assessing the efectiveness of existing defense methods as well
as for developing and testing new defense mechanisms. To validate the proposed procedure,
we carried out tests on mass market GNSS receivers. In detail, we considered several nominal
and under-attack scenarios where the attacker was able to use jamming, spoofing or both: we
observed that, by using joint jamming and spoofing it was possible for the attacker to achieve
the same impact with a lower power consumption, i.e., when a jamming attack acts before
the spoofing, the power required to succeed is lower than the signal power required when the
spoofer acts alone. We observed that, for the reference scenarios, by using the proposed model
we were able to correctly classify the attacks, successfully distinguishing a legitimate from
an under-attack scenario. The proposed method provides a blueprint for impact classification
which difers from detection methods present in the literature since it will allow to test receiver
performance under attack conditions specifically during the development phase.</p>
      <p>The tools developed and the results obtained in this paper are part of the PNT-CRC project,
whose purpose is the development of a centre capable of storing, discovering, and distributing
security threats, vulnerabilities, and mitigations associated to position navigation and timing
(PNT) services, with particular emphasis to the GNSS technology. The PNT-CRC will include
both technology and application specific threats, as well as real time location-based threats
observed in the territory for context awareness and emergency warning. The PNT-CRC will
provide to industries a GNSS vulnerability assessments service as well as mitigation solutions
to enhance robustness of GNSS receivers.</p>
    </sec>
    <sec id="sec-7">
      <title>Acknowledgments</title>
      <p>This work was funded by the European Space Agency under contract n. 4000123484/18/NL/MP:
“Position, Navigation and Timing Cyber-Response Center (PNT-CRC)”.
mance requirements, ETSI TS 103 246-3 V1.3.1 (2020-10), 2020.
[14] QA707: GNSS simulator supporting interference and authentication, https://www.</p>
      <p>qascom.it/GNSS-software-simulation.php, [Online; accessed 03-February-2022].
[15] Septentrio PolaRx5 GNSS receiver, https://www.septentrio.com/en/products/
gnss-receivers/reference-receivers/polarx-5, [Online; accessed 03-February-2022].
[16] NMEA 0183 Standard, https://www.nmea.org/content/STANDARDS/NMEA 0183</p>
      <p>Standard, [Online; accessed 03-February-2022].
[17] C. Hegarty, E. Kaplan, Understanding GPS Principles and Applications, Second Edition,
Artech, 2005.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Wu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Zhang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Yang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Liang</surname>
          </string-name>
          , R. Liu,
          <article-title>Spoonfig and anti-spoofing technologies of global navigation satellite system a survey</article-title>
          ,
          <source>IEEE Access 8</source>
          (
          <year>2020</year>
          )
          <fpage>165444</fpage>
          -
          <lpage>165496</lpage>
          . doi:10.
          <year>1109ACCESS</year>
          .
          <year>2020</year>
          .
          <volume>3022294</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>D.</given-names>
            <surname>Borio</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Dovis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Kuusniemi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. Lo</given-names>
            <surname>Presti</surname>
          </string-name>
          ,
          <article-title>Impact and detection of GNSS jammers on consumer grade satellite navigation receivers</article-title>
          ,
          <source>Proceedings of the IEEE</source>
          <volume>104</volume>
          (
          <year>2016</year>
          )
          <fpage>1233</fpage>
          -
          <lpage>1245</lpage>
          . doi:10.
          <year>1109JPROC</year>
          .
          <year>2016</year>
          .
          <volume>2543266</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>R. H.</given-names>
            <surname>Mitch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. C.</given-names>
            <surname>Dougherty</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. P.</given-names>
            <surname>Psiaki</surname>
          </string-name>
          , Mark L.and
          <string-name>
            <surname>Powell</surname>
            ,
            <given-names>B. W. O</given-names>
          </string-name>
          <string-name>
            <surname>'Hanlon</surname>
            ,
            <given-names>J. A.</given-names>
          </string-name>
          <string-name>
            <surname>Bhatti</surname>
            ,
            <given-names>T. E.</given-names>
          </string-name>
          <string-name>
            <surname>Humphreys</surname>
          </string-name>
          ,
          <article-title>Signal characteristics of civil GPS jammers</article-title>
          ,
          <source>in: Proceedings of the 24th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS</source>
          <year>2011</year>
          ), Portland,
          <string-name>
            <surname>OR</surname>
          </string-name>
          ,
          <year>2011</year>
          , pp.
          <fpage>1907</fpage>
          -
          <lpage>1919</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>T.</given-names>
            <surname>Morong</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Puricer</surname>
          </string-name>
          , P. Kovra,ˇ´
          <article-title>Study of the GNSS jamming in real environment</article-title>
          ,
          <source>International Journal of Electronics and Telecommunications</source>
          <volume>65</volume>
          (
          <year>2019</year>
          )
          <fpage>65</fpage>
          -
          <lpage>70</lpage>
          . doi:10.
          <year>24425ijet</year>
          .
          <year>2019</year>
          .
          <volume>126284</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>I. F.</given-names>
            <surname>Herna</surname>
          </string-name>
          ´ndez, T. Ashur,
          <string-name>
            <given-names>V.</given-names>
            <surname>Rijmen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Sarto</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Cancela</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Calle</surname>
          </string-name>
          ,
          <article-title>Toward an operational navigation message authentication service proposal and justification of additional OSNMA protocol features</article-title>
          ,
          <source>in: European Navigation Conference (ENC)</source>
          ,
          <year>2019</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . doi:10.
          <year>1109EURONAV</year>
          .
          <year>2019</year>
          .
          <volume>8714151</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>J.</given-names>
            <surname>Hinks</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Gillis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Loveridge</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Shawn</surname>
          </string-name>
          , G. Myer,
          <string-name>
            <given-names>J.</given-names>
            <surname>Rushanan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Stoyanov</surname>
          </string-name>
          ,
          <article-title>Signal and data authentication experiments on NTS-3, in: Proceedings of the 34th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+</article-title>
          <year>2021</year>
          ),
          <year>2021</year>
          , pp.
          <fpage>3621</fpage>
          -
          <lpage>3641</lpage>
          . doi:
          <volume>10</volume>
          .
          <fpage>330122021</fpage>
          .17964.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>X.</given-names>
            <surname>Ouyang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Zeng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Hou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Guo</surname>
          </string-name>
          ,
          <article-title>Analysis and evaluation of spoofing efect on GNSS receiver</article-title>
          ,
          <source>in: 2015 IEEE 12th Intl Conf on Ubiquitous Intelligence and Computing and 2015 IEEE 12th Intl Conf on Autonomic and Trusted Computing and 2015 IEEE 15th Intl Conf on Scalable Computing and Communications</source>
          and
          <string-name>
            <surname>Its Associated Workshops (UIC-ATCScalCom</surname>
            <given-names>)</given-names>
          </string-name>
          ,
          <year>2015</year>
          , pp.
          <fpage>1388</fpage>
          -
          <lpage>1392</lpage>
          . doi:10.
          <string-name>
            <surname>1109UIC-ATC-ScalCom-CBDCom-IoP</surname>
          </string-name>
          .
          <year>2015</year>
          .
          <volume>250</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>L.</given-names>
            <surname>Perdue</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Sasaki</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Boime</surname>
          </string-name>
          , E. Sicsik-Paer,
          <article-title>´ Testing GNSS receivers robustness against spoonfig attempts</article-title>
          , in: etc2016 -
          <fpage>36</fpage>
          . European Telemetry and Test Conference, Nu¨rnberg, Germany,
          <year>2016</year>
          , pp.
          <fpage>33</fpage>
          -
          <lpage>39</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>A.</given-names>
            <surname>Rustamov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Gogoi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Minetto</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Dovis</surname>
          </string-name>
          ,
          <article-title>Assessment of the vulnerability to spoofing attacks of GNSS receivers integrated in consumer devices</article-title>
          ,
          <source>in: 2020 International Conference on Localization and GNSS (ICL-GNSS)</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . doi:10.
          <fpage>1109ICL</fpage>
          -
          <lpage>GNSS49876</lpage>
          .
          <year>2020</year>
          .
          <volume>9115489</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>S.</given-names>
            <surname>Ceccato</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Formaggio</surname>
          </string-name>
          , G. Caparra,
          <string-name>
            <given-names>N.</given-names>
            <surname>Laurenti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Tomasin</surname>
          </string-name>
          ,
          <article-title>Exploiting sideinformation for resilient GNSS positioning in mobile phones</article-title>
          ,
          <source>in: 2018 IEEEION Position, Location and Navigation Symposium (PLANS)</source>
          ,
          <year>2018</year>
          , pp.
          <fpage>1515</fpage>
          -
          <lpage>1524</lpage>
          . doi:10.
          <year>1109PLANS</year>
          .
          <year>2018</year>
          .
          <volume>8373546</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>N.</given-names>
            <surname>Spens</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.-K.</given-names>
            <surname>Lee</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Akos</surname>
          </string-name>
          ,
          <article-title>An application for detecting GNSS jamming and spoofing, in: Proceedings of the 34th International Technical Meeting of the Satellite Division of The Institute of Navigation (ION GNSS+</article-title>
          <year>2021</year>
          ), St. Louis, Missouri,
          <year>2021</year>
          , pp.
          <fpage>1981</fpage>
          -
          <lpage>1988</lpage>
          . doi:
          <volume>10</volume>
          .
          <fpage>330122021</fpage>
          .18027.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>G.</given-names>
            <surname>Mori Gonzalez</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Petrunin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Zbikowski</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Voutsis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. Verdeguer</given-names>
            <surname>Moreno</surname>
          </string-name>
          ,
          <article-title>Vulnerability analysis of GPS receiver software</article-title>
          ,
          <source>in: 2019 International Conference on Localization and GNSS (ICL-GNSS)</source>
          ,
          <year>2019</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . doi:10.
          <string-name>
            <surname>1109ICL-GNSS</surname>
          </string-name>
          .
          <year>2019</year>
          .
          <volume>8752862</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <article-title>Satellite Earth Stations and Systems (SES); GNSS based location systems; Part 3 Perfor-</article-title>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>