
The application of a basic geographic information system (GIS) workflow and cloud-based processing of publicly available Sentinel-1 synthetic aperture radar (SAR) images, within a Google Earth Engine environment, demonstrates the ability to track large maritime vessel activity patterns on the Taedong River proximal to Nampo Port in Nampo, Democratic People's Republic of Korea (DPRK) with a high degree of accuracy. This maritime vessel activity was observed over a period of 10 years (2015-2025). The automated methodology utilized to analyze this activity has no statistically significant bias (95% CI -0.22 – 0.45) with a mean absolute error of 0.81 ships per image across the entire area of interest. Analysis identified multiple temporal points of interest where there were significant changes in maritime activity, providing quantitative context for further in-depth qualitative research. The automated methodology described can be replicated on other ports or narrow maritime areas of interest to generate contextual quantitative data on large vessel movements and activity over long time periods.
![[Draft] Quantifying Increases in Maritime Activity in Denied Environments Using Open-Source SAR Data](/_next/image?url=https%3A%2F%2Fd2p0b1m8gqyu6i.cloudfront.net%2Fimages%2FAmnok_tourist_2_R1C1-e152432414617.2e16d0ba.fill-400x200.jpg&w=640&q=75)
The application of a basic geographic information system (GIS) workflow and cloud-based processing of publicly available Sentinel-1 synthetic aperture radar (SAR) images, within a Google Earth Engine environment, demonstrates the ability to track large maritime vessel activity patterns on the Taedong River proximal to Nampo Port in Nampo, Democratic People's Republic of Korea (DPRK) with a high degree of accuracy. This maritime vessel activity was observed over a period of 10 years (2015-2025). The automated methodology utilized to analyze this activity has no statistically significant bias (95% CI -0.22 – 0.45) with a mean absolute error of 0.81 ships per image across the entire area of interest. Analysis identified multiple temporal points of interest where there were significant changes in maritime activity, providing quantitative context for further in-depth qualitative research. The automated methodology described can be replicated on other ports or narrow maritime areas of interest to generate contextual quantitative data on large vessel movements and activity over long time periods.


This article provides a structured assessment of the potential malign use of Geographic Information Systems (GIS) by threat actors of varying technical sophistication to target U.S. cities and critical infrastructure. Using a newly constructed critical infrastructure facility in the United States as the operational test case, the use cases explore how open-source geospatial tools can be used to identify, model, and potentially exploit critical infrastructure vulnerabilities. The facility was selected for its emergent relevance to regional and national supply chains, logistical novelty, and its appearance in both regional and national public discourse surrounding immigration and rural industrial development.
The assessment includes four discrete use case examples corresponding to escalating levels of threat actor capability: Tier 1 (one without and one with AI augmentation), Tier 2, and Tier 3 (see Figure 1). Each scenario demonstrates how openly accessible data and commercially available GIS and AI tools can be operationalized to perform tasks such as infrastructure targeting, route planning, emergency response delay modeling, reconnaissance staging, among others. This framework assists in evaluating adversarial capabilities, mapping threat vectors, and anticipating how generative AI may further reduce the technical barriers to high consequence targeting.
Threat actors across varying skill levels can effectively identify and exploit vulnerabilities in critical infrastructure using open-source geospatial data. Even Tier 1 actors, when augmented by generative AI like ChatGPT, Claude, or Google Gemini, can analyze site access, infer vulnerabilities, and devise attack strategies including physical sabotage, low-level cyber tactics, and disinformation campaigns. More sophisticated actors leverage advanced GIS platforms to model supply chains, critical dependencies, and emergency response scenarios, with the ability to closely mimic professional geospatial intelligence processes. Crucially, generative AI can compress traditional skill barriers[1] and enable non-experts to rapidly convert reconnaissance into actionable attack plans, significantly increasing the risk profile and challenging the reliability of existing infrastructure security paradigms.
