KalKi: A Software-Defined IoT Security Platform

被引:0
|
作者
Echeverria, Sebastian [1 ]
Lewis, Grace [1 ]
Mazzotta, Craig [1 ]
Grabowski, Christopher [1 ]
O'Meara, Kyle [1 ]
Vasudevan, Amit [1 ]
Novakouski, Marc [1 ]
McCormack, Matthew [2 ]
Sekar, Vyas [2 ]
机构
[1] Carnegie Mellon Software Engn Inst, Pittsburgh, PA 15213 USA
[2] Carnegie Mellon Univ, CyLab, Pittsburgh, PA 15213 USA
基金
美国安德鲁·梅隆基金会;
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Commercial IoT devices are increasingly being integrated into software systems. However, given the also increasing number of IoT vulnerability reports, there is a pressing need to enable organizations to achieve such integration with high assurance, especially for systems with high security and safety requirements. We present KalKi, a software-defined IoT security platform that moves security enforcement to the network to enable safe integration of IoT devices, even if the devices are not fully trusted or configurable. KalKi leverages software-defined networking (SDN) concepts and constructs, combined with a rich policy model that specifies both cyber and kinetic attacks, to create a safe, highly-dynamic and extensible IoT integration platform. Our experiments demonstrate high performance, scat ability and resilience, even in the presence of a powerful attacker.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Snout: A Middleware Platform for Software-Defined Radios
    Becker, Johannes K.
    Starobinski, David
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (01): : 644 - 657
  • [32] Demo: FIexRAN - A Software-Defined RAN Platform
    Foukas, Xenofon
    Nikaein, Navid
    Kassem, Mohamed M.
    Marina, Mahesh K.
    Kontovasilis, Kimon
    PROCEEDINGS OF THE 23RD ANNUAL INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND NETWORKING (MOBICOM '17), 2017, : 465 - 467
  • [33] Programmable Security in the Age of Software-Defined Infrastructure
    Gu, Guofei
    PROCEEDINGS OF THE 2021 CLOUD COMPUTING SECURITY WORKSHOP, CCSW 2021, 2021, : 1 - 1
  • [34] SOFTWARE-DEFINED NETWORKING SECURITY: PROS AND CONS
    Dabbagh, Mehiar
    Hamdaoui, Bechir
    Guizani, Mohsen
    Rayes, Ammar
    IEEE COMMUNICATIONS MAGAZINE, 2015, 53 : 73 - 79
  • [35] Security Challenges and Opportunities of Software-Defined Networking
    Dacier, Marc C.
    Koenig, Hartmut
    Cwalinski, Radoslaw
    Kargl, Frank
    Dietrich, Sven
    IEEE SECURITY & PRIVACY, 2017, 15 (02) : 96 - 100
  • [36] Improving the Routing Security in Software-Defined Networks
    Ai, Jianjian
    Guo, Zehua
    Chen, Hongchang
    Cheng, Guozhen
    IEEE COMMUNICATIONS LETTERS, 2019, 23 (05) : 838 - 841
  • [37] Security in Software-Defined Networking: Threats and Countermeasures
    Zhaogang Shu
    Jiafu Wan
    Di Li
    Jiaxiang Lin
    Athanasios V. Vasilakos
    Muhammad Imran
    Mobile Networks and Applications, 2016, 21 : 764 - 776
  • [38] Security in Software-Defined Networking: Threats and Countermeasures
    Shu, Zhaogang
    Wan, Jiafu
    Li, Di
    Lin, Jiaxiang
    Vasilakos, Athanasios V.
    Imran, Muhammad
    MOBILE NETWORKS & APPLICATIONS, 2016, 21 (05): : 764 - 776
  • [39] Semantic Security Tools in Software-Defined Networks
    Antoshina, E. Ju.
    Chalyy, D. Ju.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2018, 52 (07) : 605 - 607
  • [40] SDSA: A Framework of a Software-Defined Security Architecture
    Liu Yanbing
    Lu Xingyu
    Jian Yi
    Xiao Yunpeng
    CHINA COMMUNICATIONS, 2016, 13 (02) : 178 - 188