Security Evaluation of a Control System Using Named Data Networking

被引:0
|
作者
Perez, Victor [1 ]
Garip, Mevlut Turker [1 ]
Lam, Silas [1 ]
Zhang, Lixia [1 ]
机构
[1] Univ Calif Los Angeles, Dept Comp Sci, Los Angeles, CA 90095 USA
关键词
Computer networks; Computer security; Building automation;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Security is an integral part of networked computer systems. The recent Named Data Networking (NDN) project aims to develop a new Internet architecture that communicates data using names rather than locations, the latter of which is what the current IP-based Internet does with IP addresses. One of the first real-world applications using NDN is a lighting control system. We conduct a red team assessment of the current state of the security of this lighting system and its NDN implementation. The system is representative of a more general class of automated controller systems. Our analysis found that due to NDN's use of named data, the system inherently prevents most attacks that IP-based systems are vulnerable to. Although many parts of the system are secure, we discovered some problems with the verification of timestamps and processing of large packets that led to a severe memory leak. The system also lacks a secure key distribution mechanism. While NDN security is on the right track, there are important security design issues NDN must account for.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] A Game Theoretic Framework for Congestion Control in Named Data Networking
    Yao, Jinfa
    Yin, Baoqun
    Tan, Xiaobin
    Bao, Yizhao
    INFORMATION TECHNOLOGY AND CONTROL, 2017, 46 (04): : 605 - 618
  • [42] A Design of Publish Subscribe System over Named Data Networking
    Choi, Kang-Il
    Kim, Haksuh
    Jung, Heeyoung
    Kim, Sunme
    2019 10TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC): ICT CONVERGENCE LEADING THE AUTONOMOUS FUTURE, 2019, : 1192 - 1194
  • [43] On the realization of VANET using named data networking: On improvement of VANET using NDN-based routing, caching, and security
    da Silva, Elidio Tomas
    Duarte Costa, Antonio Luis
    Henriques de Macedo, Joaquim Melo
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2022, 35 (18)
  • [44] Energy conservation strategies in Named Data Networking based MANET using congestion control: A review
    Muchtar, Farkhana
    Abdullah, Abdul Hanan
    Al-Adhaileh, Mosleh
    Zamli, Kamal Zuhairi
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2020, 152
  • [45] Realizing a Virtual Private Network using Named Data Networking
    Partridge, Craig
    Nelson, Samuel
    Kong, Derrick
    PROCEEDINGS OF THE 4TH ACM CONFERENCE ON INFORMATION-CENTRIC NETWORKING (ICN 2017), 2017, : 156 - 162
  • [46] Securing Building Management Systems Using Named Data Networking
    Shang, Wentao
    Ding, Qiuhan
    Marianantoni, Alessandro
    Burke, Jeff
    Zhang, Lixia
    IEEE NETWORK, 2014, 28 (03): : 50 - 56
  • [47] Cache sharing using bloom filters in named data networking
    Mun, Ju Hyoung
    Lim, Hyesook
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2017, 90 : 74 - 82
  • [48] Cache Sharing Using a Bloom Filter in Named Data Networking
    Mun, Ju Hyoung
    Lim, Hyesook
    PROCEEDINGS OF THE 2016 SYMPOSIUM ON ARCHITECTURES FOR NETWORKING AND COMMUNICATIONS SYSTEMS (ANCS'16), 2016, : 127 - 128
  • [49] Securing Named Data Networking routing using Decentralized Identifiers
    Fotiou, Nikos
    Thomas, Yannis
    Siris, Vasilios A.
    Xylomenos, George
    Polyzos, George C.
    2021 IEEE 22ND INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING (IEEE HPSR), 2021,
  • [50] Interest Forwarding in Named Data Networking Using Reinforcement Learning
    Akinwande, Olumide
    SENSORS, 2018, 18 (10)