首页> 外文学位 >Improving the Security of Building Automation Systems Through an seL4-based Communication Framework
【24h】

Improving the Security of Building Automation Systems Through an seL4-based Communication Framework

机译:通过基于seL4的通信框架提高楼宇自动化系统的安全性

获取原文
获取原文并翻译 | 示例

摘要

Existing Building Automation Systems (BASs) and Building Automation Networks (BANs) have been shown to have serious cybersecurity problems. Due to the safety-critical and interconnected nature of building subsystems, local and network access control needs to be finer grained, taking into consideration the varying criticality of applications running on heterogeneous devices. In this paper, we present a secure communication framework for BASs that 1) enforces rich access control policy for operating system services and objects, leveraging a microkernel-based architecture; 2) supports fine-grained network access control on a per-process basis; 3) unifies the security control of inter-device and intra-device communication using proxy processes; 4) tunnels legacy insecure communication protocols (e.g., BACnet) through a secure channel, such as SSL, in a manner transparent to legacy applications. We implemented the framework on seL4, a formally verified microkernel. We conducted extensive experiments and analysis to compare the performance and effectiveness of our communication systems against a traditional Linux-based implementation of the same control scenario. Our experiments show that the communication performance of our system is faster or comparable to the Linux-based architecture in embedded systems.
机译:现有的楼宇自动化系统(BAS)和楼宇自动化网络(BAN)已显示出严重的网络安全问题。由于建筑物子系统的安全性和互连性至关重要,因此考虑到在异构设备上运行的应用程序的关键程度不同,需要对本地和网络访问控制进行更细化的划分。在本文中,我们提出了一种用于BAS的安全通信框架,该框架包括:1)利用基于微内核的体系结构,对操作系统服务和对象实施丰富的访问控制策略; 2)支持基于每个进程的细粒度网络访问控制; 3)使用代理进程统一设备间和设备内通信的安全控制; 4)以对遗留应用程序透明的方式,通过安全通道(例如SSL)建立遗留不安全通信协议(例如BACnet)的隧道。我们在正式验证的微内核seL4上实现了该框架。我们进行了广泛的实验和分析,以将通信系统的性能和有效性与相同控制方案的基于Linux的传统实现方案进行比较。我们的实验表明,我们的系统的通信性能更快或与嵌入式系统中基于Linux的体系结构相当。

著录项

  • 作者

    Habeeb, Richard.;

  • 作者单位

    University of South Florida.;

  • 授予单位 University of South Florida.;
  • 学科 Computer science.
  • 学位 M.S.C.S.
  • 年度 2018
  • 页码 58 p.
  • 总页数 58
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

  • 入库时间 2022-08-17 11:53:34

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号