首页> 外文会议>Conference on Mobile and Secure Services >Performance evaluation of MAC-layer trust zones over virtual network interfaces
【24h】

Performance evaluation of MAC-layer trust zones over virtual network interfaces

机译:虚拟网络接口上的MAC层信任区的性能评估

获取原文

摘要

In smart building scenarios there are a lot of vulnerable devices that could be exploited to run attacks against other devices within the same LAN. Even though existing solutions mostly tackle the problem by cluster-based authentication and key management schemes, none of them leverages the potential of isolating traffic by network interface virtualization. Thus, we proposed in a previous work a concept to avoid unauthorized communication by considering separating applications with virtual MAC interfaces as the consequence. The decreased attack surface, as the main advantage, is achieved by isolating communication through virtual MAC interfaces based on application-specific demands. To demonstrate the efficiency of this concept we developed an implementation based on state-of-the-art communication protocols. We applied our interface virtualization concept to the IEEE 802.11s WLAN mesh technology, combining it with a lightweight RESTful web service for security credentials deployment. The resulting proof-of-concept implementation in a real-world multi-hop scenario shows performance of the credentials deployment and the impact of the MAC-layer parallelization. The promising results, e.g., no drop of the overall throughput using multiple virtual MAC interfaces, show that our concept can be an efficient solution for future smart buildings.
机译:在智能建筑场景中,可以利用许多易受攻击的设备对同一LAN中的其他设备进行攻击。尽管现有的解决方案大多通过基于群集的身份验证和密钥管理方案解决了该问题,但它们都没有利用网络接口虚拟化隔离流量的潜力。因此,我们在以前的工作中提出了一个概念,即通过考虑使用虚拟MAC接口分离应用程序来避免未经授权的通信。减少攻击面的主要优势是通过根据特定于应用程序的需求隔离通过虚拟MAC接口的通信来实现的。为了证明此概念的有效性,我们开发了基于最新通信协议的实现。我们将接口虚拟化概念应用于IEEE 802.11s WLAN网格技术,并将其与轻量级的RESTful Web服务相结合,用于安全凭证部署。实际的多跳场景中所产生的概念验证实现显示了凭据部署的性能以及MAC层并行化的影响。令人鼓舞的结果,例如使用多个虚拟MAC接口不会降低整体吞吐量,表明我们的概念可以成为未来智能建筑的有效解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号