Security Evaluation of a Control System Using Named Data Networking

被引:0
|
作者
Perez, Victor [1 ]
Garip, Mevlut Turker [1 ]
Lam, Silas [1 ]
Zhang, Lixia [1 ]
机构
[1] Univ Calif Los Angeles, Dept Comp Sci, Los Angeles, CA 90095 USA
关键词
Computer networks; Computer security; Building automation;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Security is an integral part of networked computer systems. The recent Named Data Networking (NDN) project aims to develop a new Internet architecture that communicates data using names rather than locations, the latter of which is what the current IP-based Internet does with IP addresses. One of the first real-world applications using NDN is a lighting control system. We conduct a red team assessment of the current state of the security of this lighting system and its NDN implementation. The system is representative of a more general class of automated controller systems. Our analysis found that due to NDN's use of named data, the system inherently prevents most attacks that IP-based systems are vulnerable to. Although many parts of the system are secure, we discovered some problems with the verification of timestamps and processing of large packets that led to a severe memory leak. The system also lacks a secure key distribution mechanism. While NDN security is on the right track, there are important security design issues NDN must account for.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Supporting Climate Research using Named Data Networking
    Olschanowsky, Catherine
    Shannigrahi, Susmit
    Papadopoulos, Christos
    2014 IEEE 20TH INTERNATIONAL WORKSHOP ON LOCAL & METROPOLITAN AREA NETWORKS (LANMAN), 2014,
  • [32] Green Named Data Networking Using Renewable Energy
    Jo, Seng-Kyoun
    Wang, Lin
    Kangasharju, Jussi
    Muehlhaeuser, Max
    E-ENERGY'18: PROCEEDINGS OF THE 9TH ACM INTERNATIONAL CONFERENCE ON FUTURE ENERGY SYSTEMS, 2018, : 414 - 416
  • [33] NDN DeLorean: An Authentication System for Data Archives in Named Data Networking
    Yu, Yingdi
    Afanasyev, Alexander
    Seedorf, Jan
    Zhang, Zhiyi
    Zhang, Lixia
    PROCEEDINGS OF THE 4TH ACM CONFERENCE ON INFORMATION-CENTRIC NETWORKING (ICN 2017), 2017, : 11 - 21
  • [34] Data Aggregation in Named Data Networking
    Harada, Sho
    Yan, Zhiwei
    Park, Yong-Jin
    Nisar, Kashif
    Ibrahim, Ag Asri Ag
    TENCON 2017 - 2017 IEEE REGION 10 CONFERENCE, 2017, : 1839 - 1842
  • [35] Experimental Evaluation of Named Data Networking (NDN) in Tactical Environments
    Campioni, Lorenzo
    Tortonesi, Mauro
    Wissingh, Bastiaan
    Suri, Niranjan
    Hauge, Mariann
    Landmark, Lars
    MILCOM 2019 - 2019 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2019,
  • [36] A SURVEY ON NAMED DATA NETWORKING
    Soniya, M. Micheal Santha
    Kumar, K.
    2015 2ND INTERNATIONAL CONFERENCE ON ELECTRONICS AND COMMUNICATION SYSTEMS (ICECS), 2015, : 1515 - 1519
  • [37] Multipath Forwarding Strategies and SDN Control for Named Data Networking
    Alhowaidi, Mohammad
    Nadig, Deepak
    Ramamurthy, Byrav
    Bockelman, Brian
    Swanson, David
    2018 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATIONS SYSTEMS (ANTS), 2018,
  • [38] Named Data Networking: A survey
    Saxena, Divya
    Raychoudhury, Vaskar
    Suri, Neeraj
    Becker, Christian
    Cao, Jiannong
    COMPUTER SCIENCE REVIEW, 2016, 19 : 15 - 55
  • [39] Popularity-based Congestion Control in Named Data Networking
    Park, Heungsoon
    Jang, Hoseok
    Kwon, Taewook
    2014 SIXTH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS (ICUFN 2014), 2014, : 166 - 171
  • [40] A Responsibility-based Transport Control for Named Data Networking
    Nikzad, Mortaza
    Jamshidi, Kamal
    Bohlooli, Ali
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2020, 106 : 518 - 533