CyberShip-IoT: A dynamic and adaptive SDN-based security policy enforcement framework for ships

被引:25
|
作者
Sahay, Rishikesh [1 ]
Meng, Weizhi [1 ]
Estay, D. A. Sepulveda [2 ]
Jensen, Christian D. [1 ]
Barfod, Michael Bruhn [2 ]
机构
[1] Tech Univ Denmark, Dept Appl Math & Comp Sci, DK-2800 Lyngby, Denmark
[2] Tech Univ Denmark, Dept Management Engn, DK-2800 Lyngby, Denmark
关键词
Internet-of-Things; OpenFlow; SDN; Ship system; Policy language and enforcement; SCADA system; SOFTWARE-DEFINED NETWORKING; INTRUSION DETECTION;
D O I
10.1016/j.future.2019.05.049
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the wide adoption of Information and Communication Technology (ICT) in the marine environment, ship systems are increasingly similar to other networked computing systems. The integration of positioning systems with navigational and propulsion control systems and the increasing reliance on Supervisory Control And Data Acquisition (SCADA) systems for monitoring the ship's performance makes modern ships vulnerable to a wide range of cyber security issues. Moreover, frequent or permanent onshore connection makes the ship's communication network a potential target for cyber-criminals. Such attacks can incapacitate the vessel, i.e., through a ransomware attack, or greatly degrade the performance of the ship systems, i.e., causing delays in the propagation of control messages between critical components within the ship. Furthermore, crew members and marine engineers are challenged with the task of configuring security policies for networked devices, using low-level device specific syntax, which is an error prone and time consuming process. In addition to this, crew members must also be familiar with the specific syntax for low-level network management task, which exacerbates the problem. The emergence of Software-Defined Networking (SDN) helps reduce the complexity of the network management tasks and we believe that a similar approach may be used to address the larger problem. We therefore propose the CyberShip-IoT framework to provide a network level defense for the communication network component of ship systems. CyberShip-IoT offers a high-level policy language and a translation mechanism for automated policy enforcement in the ship's communication network. The modular design of the framework provides flexibility to deploy detection mechanism according to their requirements. To evaluate the feasibility and effectiveness of this framework, we develop a prototype for a scenario involving the communication network of a typical ship. The experimental results demonstrate that our framework can effectively translate high-level security policies into OpenFlow rules of the switches without incurring much latency, ultimately leading to efficient attack mitigation and reduced collateral damage. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页码:736 / 750
页数:15
相关论文
共 50 条
  • [31] SDN-based Federated Learning approach for Satellite-IoT Framework to Enhance Data Security and Privacy in Space Communication
    Uddin, Ryhan
    Kumar, Sathish
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON WIRELESS FOR SPACE AND EXTREME ENVIRONMENTS (WISEE 2022), 2022, : 71 - 76
  • [32] SDN-Based Federated Learning Approach for Satellite-IoT Framework to Enhance Data Security and Privacy in Space Communication
    Uddin, Ryhan
    Kumar, Sathish A. P.
    [J]. IEEE JOURNAL OF RADIO FREQUENCY IDENTIFICATION, 2023, 7 : 424 - 440
  • [33] Traffic Steering for SDN-based Cellular Networks: Policy Dependent Framework
    Hossen, Md. Sazzad
    Jamalipour, Abbas
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2018,
  • [34] R-IDPS: Real Time SDN-Based IDPS System for IoT Security
    Mazhar, Noman
    Saleh, Rosli
    Zaba, Reza
    Zeeshan, Muhammad
    Hameed, M. Muzaffar
    Khan, Nauman
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 73 (02): : 3099 - 3118
  • [35] OpenStackDP: a scalable network security framework for SDN-based OpenStack cloud infrastructure
    Prabhakar Krishnan
    Kurunandan Jain
    Amjad Aldweesh
    P. Prabu
    Rajkumar Buyya
    [J]. Journal of Cloud Computing, 12
  • [36] A dynamic and lightweight framework to secure source addresses in the SDN-based networks
    Zhou, Qizhao
    Yu, Junqing
    Li, Dong
    [J]. COMPUTER NETWORKS, 2021, 193
  • [37] OpenStackDP: a scalable network security framework for SDN-based OpenStack cloud infrastructure
    Krishnan, Prabhakar
    Jain, Kurunandan
    Aldweesh, Amjad
    Prabu, P.
    Buyya, Rajkumar
    [J]. JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2023, 12 (01):
  • [38] A Secured Framework for SDN-Based Edge Computing in IoT-Enabled Healthcare System
    Li, Junxia
    Cai, Jinjin
    Khan, Fazlullah
    Rehman, Ateeq Ur
    Balasubramaniam, Venki
    Sun, Jiangfeng
    Venu, P.
    [J]. IEEE ACCESS, 2020, 8 : 135479 - 135490
  • [39] Certrust: An SDN-Based Framework for the Trust of Certificates against Crossfire Attacks in IoT Scenarios
    Yan, Lei
    Ma, Maode
    Li, Dandan
    Huang, Xiaohong
    Ma, Yan
    Xie, Kun
    [J]. CMES-COMPUTER MODELING IN ENGINEERING & SCIENCES, 2023, 134 (03): : 2137 - 2162
  • [40] An IoT Framework Based on SDN and NFV for Context-Aware Security
    Ong, Arlyn Verina
    Peradilla, Marnel
    [J]. 12TH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS (ICUFN 2021), 2021, : 167 - 172