CyberShip-IoT: A dynamic and adaptive SDN-based security policy enforcement framework for ships

被引:25
|
作者
Sahay, Rishikesh [1 ]
Meng, Weizhi [1 ]
Estay, D. A. Sepulveda [2 ]
Jensen, Christian D. [1 ]
Barfod, Michael Bruhn [2 ]
机构
[1] Tech Univ Denmark, Dept Appl Math & Comp Sci, DK-2800 Lyngby, Denmark
[2] Tech Univ Denmark, Dept Management Engn, DK-2800 Lyngby, Denmark
关键词
Internet-of-Things; OpenFlow; SDN; Ship system; Policy language and enforcement; SCADA system; SOFTWARE-DEFINED NETWORKING; INTRUSION DETECTION;
D O I
10.1016/j.future.2019.05.049
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the wide adoption of Information and Communication Technology (ICT) in the marine environment, ship systems are increasingly similar to other networked computing systems. The integration of positioning systems with navigational and propulsion control systems and the increasing reliance on Supervisory Control And Data Acquisition (SCADA) systems for monitoring the ship's performance makes modern ships vulnerable to a wide range of cyber security issues. Moreover, frequent or permanent onshore connection makes the ship's communication network a potential target for cyber-criminals. Such attacks can incapacitate the vessel, i.e., through a ransomware attack, or greatly degrade the performance of the ship systems, i.e., causing delays in the propagation of control messages between critical components within the ship. Furthermore, crew members and marine engineers are challenged with the task of configuring security policies for networked devices, using low-level device specific syntax, which is an error prone and time consuming process. In addition to this, crew members must also be familiar with the specific syntax for low-level network management task, which exacerbates the problem. The emergence of Software-Defined Networking (SDN) helps reduce the complexity of the network management tasks and we believe that a similar approach may be used to address the larger problem. We therefore propose the CyberShip-IoT framework to provide a network level defense for the communication network component of ship systems. CyberShip-IoT offers a high-level policy language and a translation mechanism for automated policy enforcement in the ship's communication network. The modular design of the framework provides flexibility to deploy detection mechanism according to their requirements. To evaluate the feasibility and effectiveness of this framework, we develop a prototype for a scenario involving the communication network of a typical ship. The experimental results demonstrate that our framework can effectively translate high-level security policies into OpenFlow rules of the switches without incurring much latency, ultimately leading to efficient attack mitigation and reduced collateral damage. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页码:736 / 750
页数:15
相关论文
共 50 条
  • [1] CyberShip-IoT: A Dynamic and Adaptive SDN-Based Security Policy Enforcement Framework for Ships' (vol 100, pg 736, 2019)
    Sahay, Rishikesh
    Meng, Weizhi
    Estay, D. A. Sepulveda
    Jensen, Christian D.
    Barfod, Michael Bruhn
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 118 : 492 - 494
  • [2] TD-RA policy-enforcement framework for an SDN-based IoT architecture
    Lahlou, Sara
    Moukafih, Youness
    Sebbar, Anass
    Zkik, Karim
    Boulmalf, Mohammed
    Ghogho, Mounir
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2022, 204
  • [3] SDN-Based Security Framework for the IoT in Distributed Grid
    Gonzalez, Carlos
    Charfadine, Salim Mahamat
    Flauzac, Olivier
    Nolot, Florent
    [J]. 2016 INTERNATIONAL MULTIDISCIPLINARY CONFERENCE ON COMPUTER AND ENERGY SCIENCE (SPLITECH), 2016, : 81 - 85
  • [4] CyberShip: An SDN-Based Autonomic Attack Mitigation Framework for Ship Systems
    Sahay, Rishikesh
    Sepulveda, D. A.
    Meng, Weizhi
    Jensen, Christian Damsgaard
    Barfod, Michael Bruhn
    [J]. SCIENCE OF CYBER SECURITY, SCISEC 2018, 2018, 11287 : 191 - 198
  • [5] SDN-based Dynamic Policy Specification and Enforcement for Provisioning SECaaS in Cloud
    Tupakula, Uday
    Varadharajan, Vijay
    Karmakar, Kallol
    [J]. WEB INFORMATION SYSTEMS ENGINEERING, WISE 2017, PT II, 2017, 10570 : 550 - 561
  • [6] SDN-Based Security Enforcement Framework for Data Sharing Systems of Smart Healthcare
    Meng, Yunfei
    Huang, Zhiqiu
    Shen, Guohua
    Ke, Changbo
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (01): : 308 - 318
  • [7] Explainable Security in SDN-Based IoT Networks
    Sarica, Alper Kaan
    Angin, Pelin
    [J]. SENSORS, 2020, 20 (24) : 1 - 30
  • [8] A Framework for Security Enhancement in SDN-based Datacenters
    Ammar, Moustafa
    Rizk, Mohamed
    Abdel-Hamid, Ayman
    Aboul-Seoud, Ahmed K.
    [J]. 2016 8TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2016,
  • [9] Research on SDN-based IoT Security Architecture Model
    Zheng, Shiji
    [J]. PROCEEDINGS OF 2019 IEEE 8TH JOINT INTERNATIONAL INFORMATION TECHNOLOGY AND ARTIFICIAL INTELLIGENCE CONFERENCE (ITAIC 2019), 2019, : 575 - 579
  • [10] Security network policy enforcement through a SDN framework
    Berardi, Davide
    Callegati, Franco
    Melis, Andrea
    Prandini, Marco
    [J]. 2018 28TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2018, : 97 - 100