GNSS spoofing event detection and attribution
GNSS spoofing displaces reported positions while leaving a physical trace detectable by SAR and multi-constellation signal analysis. This page covers detection methods, documented incidents, and honest limits.
Sensors
- Spire Global AIS constellation: Over 100 LEO satellites receiving AIS position reports globally, with typical revisit under 20 minutes in mid-latitudes. Provides the reported GNSS-derived position that may be spoofed, forming the baseline against which physical position is checked.
- Sentinel-1 SAR (ESA Copernicus): C-band synthetic aperture radar at 5 m resolution in Stripmap mode, 12-day exact repeat at the equator (6-day with both satellites). Detects actual vessel position independent of any onboard navigation system, enabling direct comparison with AIS-reported coordinates.
- HawkEye 360 RF monitoring constellation: Clusters of LEO satellites geolocating RF emitters by time-difference-of-arrival and frequency-difference-of-arrival. Can detect anomalous signal energy in GNSS frequency bands (L1 at 1575.42 MHz, L2 at 1227.60 MHz) and help bound the geographic origin of a spoof transmitter.
- Commercial GNSS receiver C/N0 data: Carrier-to-noise density ratio logged by shipborne or airborne GNSS receivers. A sudden rise in C/N0 across multiple satellites simultaneously is a published indicator of a spoofing signal overpowering genuine constellation signals; anomaly data can be collected and aggregated by fleet operators.
- Multi-constellation cross-check (GPS, GLONASS, Galileo, BeiDou): Spoofing a single constellation is far easier than spoofing all four simultaneously. Receivers that track GPS and Galileo independently will show position disagreement during a single-constellation spoof event, a cross-check increasingly available on modern maritime and aviation receivers.
What spoofing actually does to a position fix
Jamming is loud and obvious: receivers lose lock and operators know something is wrong. Spoofing is quieter and more dangerous. A spoof transmitter broadcasts counterfeit GNSS signals at slightly higher power than the genuine constellation, causing receivers to compute a plausible-looking position fix that is simply wrong. The vessel or aircraft continues navigating, AIS continues broadcasting, and nothing in the onboard display suggests a problem.
The physical displacement can be modest, a few hundred metres, or dramatic. In the Black Sea in June 2017, over twenty vessels near the port of Novorossiysk reported positions placing them inland at Gelendzhik Airport, a displacement of roughly 25 to 32 kilometres documented by maritime risk firm Windward and subsequently cited in US Maritime Administration advisories. The Persian Gulf has seen repeated incidents since at least 2019, with vessels near Iranian waters reporting position clusters that do not match their actual tracks. These are not data errors. They are deliberate.
SAR as the lie detector
Synthetic aperture radar does not care what a vessel's GNSS receiver believes. It illuminates the ocean with microwave energy and records the backscatter from physical objects. A ship's steel hull produces a strong, unambiguous return. Sentinel-1 in Interferometric Wide Swath mode covers a 250 km swath at 10 m resolution, sufficient to locate a large vessel to within roughly one to two pixels, or 10 to 20 metres, after geometric correction.
The detection method is straightforward in principle: take a Sentinel-1 scene covering the area of interest, run a constant false alarm rate (CFAR) detector to identify vessel returns, then compare each detected position against contemporaneous AIS reports from the same window. A vessel whose AIS position falls more than a few hundred metres from its SAR-detected position is a candidate spoof victim. At 12-day repeat (6-day with both Sentinel-1A and 1B operating), this is not a real-time tool. It is a forensic one. That distinction matters for how it is used.
Cloud cover is irrelevant to SAR, which is a genuine advantage over optical sensors for maritime surveillance. The honest limit is revisit: a spoofing event that lasts two hours and then stops may leave no SAR overpass within that window. Persistent monitoring requires commercial SAR constellations with higher revisit, such as ICEYE or Capella, tasked on specific areas of concern.
Signal-layer detection: what RF monitoring adds
SAR tells you where a vessel actually is. RF monitoring can tell you where a spoof transmitter might be. HawkEye 360's geolocation method uses time-difference and frequency-difference of arrival across satellite clusters to locate emitters to an accuracy that the company publishes as typically within a few kilometres, depending on geometry and signal duration. A spoof transmitter operating continuously in a fixed location is a detectable RF source.
The complication is that spoof transmitters can be mobile, shipborne, or low-powered enough to be difficult to isolate from background noise. Published open-source analysis of Persian Gulf incidents has suggested transmitters operating from Iranian coastal or island positions, but orbital RF geolocation at current precision cannot distinguish a transmitter on a specific vessel from one on a nearby shore installation. That ambiguity is real and should not be papered over.
C/N0 anomaly data collected from commercial shipping fleets adds a third layer. When dozens of vessels in the same region simultaneously log elevated carrier-to-noise ratios on GPS L1 while their computed positions cluster at an implausible point, the statistical signature is hard to explain any other way. Aggregating this data across a fleet is a published technique recommended in academic literature on spoofing detection, and it does not depend on satellite overpasses at all.
Attribution: what the evidence can and cannot prove
Detection and attribution are different problems. Detection, confirming that spoofing occurred and identifying affected vessels, is tractable with the methods above. Attribution, identifying who operated the transmitter and with what intent, is harder and carries a higher evidentiary bar.
The Black Sea 2017 events occurred in a region where Russian electronic warfare capability is well documented in open military literature, and the timing coincided with reported activity near Sochi. The Persian Gulf incidents correlate geographically with areas of Iranian maritime tension. These correlations are noted in published maritime security literature and US government advisories, but correlation is not proof of state operation. A well-resourced non-state actor can acquire GNSS spoof hardware. The honest position is that orbital data can narrow the geographic origin of a transmitter and establish a timeline, but legal attribution requires additional intelligence.
What satellite data does provide is a contemporaneous, tamper-resistant record. SAR scenes are archived. RF intercepts carry timestamps and geometry. AIS logs are retained by multiple independent receivers globally. That record has forensic value even when it stops short of naming a perpetrator.
Operational limits every buyer should understand
Sentinel-1's 6 to 12-day revisit makes it unsuitable for real-time spoofing alerts. It is the right tool for post-event investigation and pattern analysis across a region over weeks or months. Commercial SAR with daily or sub-daily revisit changes that calculus but adds cost.
AIS itself can be manipulated independently of GNSS spoofing, a subject covered separately in the AIS message spoofing and manipulation pattern analysis page in this library. The two attack types can occur simultaneously, which complicates cross-referencing. When AIS reports are themselves fabricated, SAR becomes the primary ground truth rather than a cross-check.
Multi-constellation receivers are the most practical near-term defence for operators. A receiver tracking GPS and Galileo independently will flag position disagreement during a single-constellation spoof. This does not require any satellite data product; it requires receiver firmware and operator awareness. Satellize's analytics work sits upstream of that, at the fleet-level and regional-level pattern detection stage, where aggregating evidence across many vessels and multiple sensor types produces assessments that no single vessel operator could generate alone.
Typical figures
| SAR spatial resolution (Sentinel-1 IW mode) | 10 m (range) × 10 m (azimuth) after multi-look processing |
| Sentinel-1 revisit (dual-satellite) | 6-day exact repeat at mid-latitudes; 12-day with single satellite |
| AIS position report latency (Spire LEO) | Typically under 20 minutes at mid-latitudes; longer near poles |
| HawkEye 360 emitter geolocation accuracy | Typically within a few kilometres; geometry and signal duration dependent |
| GNSS frequencies monitored | GPS L1 (1575.42 MHz), L2 (1227.60 MHz); GLONASS, Galileo E1/E5, BeiDou B1/B2 equivalents |
| Minimum vessel detection size (Sentinel-1 CFAR) | Approximately 20 m length in calm sea states; smaller vessels may be missed in high sea clutter |
| SAR archive depth (Sentinel-1) | From April 2014 (Sentinel-1A launch); globally variable coverage density |
| Position displacement detectable by SAR cross-check | Reliably above ~200 m; sub-200 m displacements approach pixel-level noise |
| Delivery formats | GeoJSON vessel position anomaly layers, PDF incident reports, CSV event logs, GeoTIFF annotated SAR scenes |
Analytics Satellize can run
| SAR-versus-AIS position discrepancy map | CFAR vessel detection on Sentinel-1 scenes cross-referenced against contemporaneous Spire AIS position reports; displacement vectors computed per vessel | GeoJSON layer showing detected vessel positions, AIS-reported positions and displacement vectors; flagged anomalies above configurable threshold |
| Regional spoofing event timeline | Retrospective analysis of AIS position clustering anomalies (multiple vessels reporting identical or near-identical positions) combined with SAR archive scenes over a defined area and period | PDF incident report with event chronology, affected vessel list, geographic extent and confidence assessment |
| RF transmitter location estimate | HawkEye 360 TDOA/FDOA geolocation of anomalous L-band emissions, filtered to GNSS frequency bands, with uncertainty ellipse computed from satellite geometry at time of collection | GeoJSON uncertainty ellipse with timestamp, frequency and signal-strength metadata |
| Fleet C/N0 anomaly aggregation | Statistical aggregation of carrier-to-noise density logs from client vessel receivers; simultaneous elevation events across multiple vessels in proximity flagged as spoof candidates per published detection heuristics | Alert feed (JSON) with event timestamp, affected vessel IMO numbers, geographic centroid and anomaly magnitude |
| Multi-constellation position consistency score | Comparison of GPS-derived and Galileo-derived position fixes from dual-constellation receiver logs; inter-system disagreement above a configurable threshold scored as a spoof indicator | Per-vessel daily score CSV; threshold-breach alerts integrated into client maritime operations dashboard |
| Persistent spoofing zone characterisation | Density analysis of AIS-versus-SAR discrepancy events over a rolling 90-day window to identify geographic zones with statistically elevated spoofing incidence, drawing on published Black Sea and Persian Gulf incident patterns as reference baselines | Monthly GeoTIFF risk-zone layer with incident density heat map and accompanying written assessment |
Who does the work
We can get this done for you. Satellize runs its own analyst desk and a strong science team. You do not buy a data feed and work out what it means; our people source the imagery, run the analysis described on this page, and hand you the answer with its confidence limits stated. Discuss this requirement.