首页> 外文会议>International Conference on Mobile and Secure Services >Performance evaluation of MAC-layer trust zones over virtual network interfaces
【24h】

Performance evaluation of MAC-layer trust zones over virtual network interfaces

机译:虚拟网络接口上MAC层信任区域的性能评估

获取原文

摘要

In smart building scenarios there are a lot of vulnerable devices that could be exploited to run attacks against other devices within the same LAN. Even though existing solutions mostly tackle the problem by cluster-based authentication and key management schemes, none of them leverages the potential of isolating traffic by network interface virtualization. Thus, we proposed in a previous work a concept to avoid unauthorized communication by considering separating applications with virtual MAC interfaces as the consequence. The decreased attack surface, as the main advantage, is achieved by isolating communication through virtual MAC interfaces based on application-specific demands. To demonstrate the efficiency of this concept we developed an implementation based on state-of-the-art communication protocols. We applied our interface virtualization concept to the IEEE 802.11s WLAN mesh technology, combining it with a lightweight RESTful web service for security credentials deployment. The resulting proof-of-concept implementation in a real-world multi-hop scenario shows performance of the credentials deployment and the impact of the MAC-layer parallelization. The promising results, e.g., no drop of the overall throughput using multiple virtual MAC interfaces, show that our concept can be an efficient solution for future smart buildings.
机译:在智能建筑方案中,有很多易受攻击的设备可以被利用来运行与同一LAN内的其他设备进行攻击。尽管现有的解决方案主要通过基于群集的身份验证和密钥管理方案来解决问题,但是它们都不利用网络接口虚拟化隔离流量的可能性。因此,我们在先前的工作中提出了一个概念,以避免未经授权的通信,通过考虑与虚拟MAC接口的分离应用程序。通过基于特定于应用程序的需求通过虚拟MAC接口隔离通信来实现减少的攻击表面作为主要优点。为了展示本概念的效率,我们基于最先进的通信协议开发了一种实现。我们将界面虚拟化概念应用于IEEE 802.11 WLAN网格技术,将其与轻量级依赖Web服务相结合以进行安全凭据部署。生成的概念验证实现在实际的多跳方案中显示了凭据部署的性能和MAC层并行化的影响。有前途的结果,例如,使用多个虚拟MAC接口的总吞吐量没有下降,表明我们的概念可以是未来智能建筑的有效解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号