首页> 外文会议>International Conference on Distributed Computing Systems Workshops >Enhanced Security of Building Automation Systems Through Microkernel-Based Controller Platforms
【24h】

Enhanced Security of Building Automation Systems Through Microkernel-Based Controller Platforms

机译:通过基于Microkernel的控制器平台增强楼宇自动化系统的安全性

获取原文

摘要

A Building Automation System (BAS) is a complex distributed Cyber-Physical System that controls building functionalities such as heating, ventilation, and air conditioning (HVAC), lighting, access, emergency control, and so on. There is a growing opportunity and motivation for BAS to be integrated into enterprise IT networks together with various new "smart" technologies to improve occupant comfort and reduce energy consumption. These new technologies coexist with legacy applications, creating a mixed-criticality environment. In this environment, as systems are integrated into IT networks, new attack vectors are introduced. Thus, networked non-critical applications running on the OS platform may be compromised, leaving the control systems vulnerable. The industry needs a reliable computing foundation that can protect and isolate these endangered critical systems from untrusted applications. This work presents a novel kernel-based approach to secure critical applications. Our method uses a security-enhanced, microkernel architecture to ensure the security and safety properties of BAS in a potentially hostile cyber environment. We compare three system design and implementations for a simple BAS scenario: 1) using the microkernel MINIX 3 enhanced with mandatory access control for inter-process communication (IPC), 2) using seL4, a formally verified, capability-based microkernel, and 3) using Linux, a monolithic kernel OS. We show through experiment that when the non-critical applications are compromised in both MINIX 3 and seL4, the critical processes that impact the physical world are not affected. Whereas in Linux, the compromised applications can easily disrupt the physical processes, jeopardizing the safety properties in the physical world. This shows that microkernels are a superior platform for BAS or other similar control environments from a security point of view, and demonstrates through example how to leverage the architecture to build a robust and resilient
机译:建筑自动化系统(BAS)是一种复杂的分布式网络物理系统,可控制建筑功能,如加热,通风和空调(HVAC),照明,访问,应急控制等。越来越多的机遇和动机将与各种新的“智能”技术一起集成在企业IT网络中,以提高乘员舒适性并降低能耗。这些新技术与遗留应用共存,创建了混合关键性环境。在此环境中,随着系统集成到IT网络中,介绍了新的攻击向量。因此,可以损害在OS平台上运行的网络的非关键应用程序,使控制系统易受攻击。该行业需要可靠的计算基础,可以保护和隔离来自不受信任的应用程序的这些濒危关键系统。这项工作提出了一种基于内核的基于内核的方法来保护关键应用。我们的方法使用安全增强的Microkernel架构,以确保BAS的安全性和安全性质在潜在的敌对网络环境中。我们使用SEL4,使用SEL4,Micratificed,Capency的Microkernel和3,使用MicroTernel MINIX 3使用MicroTernel MINIX 3增强的MicroTernel MINIX 3来进行增强的MicroTernel MINIX 3。 )使用Linux,单片内核操作系统。我们通过实验表明,当非关键申请在MINIX 3和SEL4中受到损害时,影响物理世界的关键过程不受影响。在Linux中,受损的应用程序可以轻松扰乱物理过程,危及物理世界中的安全性质。这表明Microkernels是来自安全性的BAS或其他类似控制环境的优越平台,并通过示例演示如何利用架构来构建鲁棒和弹性

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号