...
首页> 外文期刊>Computer networks >TAMBUS: A novel authentication method through covert channels for securing industrial networks
【24h】

TAMBUS: A novel authentication method through covert channels for securing industrial networks

机译:TAMBUS:通过隐蔽通道来保护工业网络的新型认证方法

获取原文
获取原文并翻译 | 示例
           

摘要

Nowadays, many companies still use old and insecure protocols in Industrial Control Systems (ICSs). An example of such protocols is Modbus, one of the most employed industrial protocols. Also, companies are moving to Modbus/TCP when there are TCP devices involved in the facility. While remaining insecure, this migration also disrupts the assumption of air-gapped industrial networks, opening more attack surface to previously isolated systems. Due to legacy and efficiency constraint, the replacement of Modbus/TCP with secure protocols is not possible, generating big security issues.In this paper, we present TAMBUS (Transmitter Authentication and packet integrity in Modbus/TCP). This method is the first that at the same time: is not implemented in a secure by obscurity design and keeps the Modbus/TCP protocol compatible with legacy devices. TAMBUS allows detecting attacks with high statistical confidence, by leveraging two covert channels as a mean of providing security: 1) Storage-based, that hides authentication messages into the Modbus/TCP protocol fields; 2) Timing-based, that considers the inter arrival time of packets. We demonstrate the feasibility and effectiveness of our method through a prototype implementation and testing in an industrial testbed environment. Our experiments confirm that TAMBUS introduces only a small overhead, negligible in most application, and it preserves the regular functioning of industrial systems. In particular, considering the storage-based covert channel, TAMBUS introduces an error into transmitted values of only 1.19x10(-5)%, without traffic overhead. On the other hand, TAMBUS can transmit correct security information through the timing-based covert channel with an accuracy of more than 99.99%.
机译:如今,许多公司仍然在工业控制系统(ICSS)中使用旧的和不安全的协议。这种协议的示例是Modbus,其中一种工业协议之一。此外,当设施中涉及TCP设备时,公司正在转向Modbus / TCP。虽然剩下的不安全,但这种迁移还破坏了空调工业网络的假设,打开了更多的攻击表面到以前的隔离系统。由于遗留和效率约束,不可能更换Modbus / TCP,不可能生成大安全问题。本文提出了Tambus(Modbus / TCP中的发射机认证和数据包完整性)。此方法是第一个同时:未通过默默设计的安全实现,并使Modbus / TCP协议与传统设备兼容。 Tambus允许通过利用两个隐蔽通道作为提供安全性的平均值来检测具有高统计置信度的攻击:1)基于存储的存储,将认证消息隐藏到Modbus / TCP协议字段中; 2)基于时序,考虑数据包的帧间到达时间。我们通过工业测试平台环境中的原型实施和测试展示了我们方法的可行性和有效性。我们的实验证实,Tambus仅在大多数应用中介绍一个小的开销,它可以忽略不计,并保留了工业系统的定期运作。特别是,考虑基于存储的封面通道,Tambus将错误引入仅1.19x10(-5)%的传输值,而无需交通开销。另一方面,Tambus可以通过基于时序的封面通道传输正确的安全信息,精度超过99.99%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号