Security Evaluation of a Control System Using Named Data Networking

被引:0
作者
Perez, Victor [1 ]
Garip, Mevlut Turker [1 ]
Lam, Silas [1 ]
Zhang, Lixia [1 ]
机构
[1] Univ Calif Los Angeles, Dept Comp Sci, Los Angeles, CA 90095 USA
来源
2013 21ST IEEE INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP) | 2013年
关键词
Computer networks; Computer security; Building automation;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Security is an integral part of networked computer systems. The recent Named Data Networking (NDN) project aims to develop a new Internet architecture that communicates data using names rather than locations, the latter of which is what the current IP-based Internet does with IP addresses. One of the first real-world applications using NDN is a lighting control system. We conduct a red team assessment of the current state of the security of this lighting system and its NDN implementation. The system is representative of a more general class of automated controller systems. Our analysis found that due to NDN's use of named data, the system inherently prevents most attacks that IP-based systems are vulnerable to. Although many parts of the system are secure, we discovered some problems with the verification of timestamps and processing of large packets that led to a severe memory leak. The system also lacks a secure key distribution mechanism. While NDN security is on the right track, there are important security design issues NDN must account for.
引用
收藏
页数:6
相关论文
共 5 条
  • [1] [Anonymous], P CONEXT 09 ROM IT D
  • [2] BISHOP M, 1990, COMP SEC APPL C 1990, P20
  • [3] Burke J., 2012, NDN0011 U CAL
  • [4] Security in Building Automation Systems
    Granzer, Wolfgang
    Praus, Fritz
    Kastner, Wolfgang
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2010, 57 (11) : 3622 - 3630
  • [5] Shi J., 2012, NDN0006 U AR