首页> 外文期刊>Future generation computer systems >CyberShip-IoT: A dynamic and adaptive SDN-based security policy enforcement framework for ships
【24h】

CyberShip-IoT: A dynamic and adaptive SDN-based security policy enforcement framework for ships

机译:Cyber​​Ship-IoT:基于动态和自适应SDN的船舶安全策略实施框架

获取原文
获取原文并翻译 | 示例
       

摘要

With the wide adoption of Information and Communication Technology (ICT) in the marine environment, ship systems are increasingly similar to other networked computing systems. The integration of positioning systems with navigational and propulsion control systems and the increasing reliance on Supervisory Control And Data Acquisition (SCADA) systems for monitoring the ship's performance makes modern ships vulnerable to a wide range of cyber security issues. Moreover, frequent or permanent onshore connection makes the ship's communication network a potential target for cyber-criminals. Such attacks can incapacitate the vessel, i.e., through a ransomware attack, or greatly degrade the performance of the ship systems, i.e., causing delays in the propagation of control messages between critical components within the ship. Furthermore, crew members and marine engineers are challenged with the task of configuring security policies for networked devices, using low-level device specific syntax, which is an error prone and time consuming process. In addition to this, crew members must also be familiar with the specific syntax for low-level network management task, which exacerbates the problem. The emergence of Software-Defined Networking (SDN) helps reduce the complexity of the network management tasks and we believe that a similar approach may be used to address the larger problem. We therefore propose the CyberShip-IoT framework to provide a network level defense for the communication network component of ship systems. CyberShip-IoT offers a high-level policy language and a translation mechanism for automated policy enforcement in the ship's communication network. The modular design of the framework provides flexibility to deploy detection mechanism according to their requirements. To evaluate the feasibility and effectiveness of this framework, we develop a prototype for a scenario involving the communication network of a typical ship. The experimental results demonstrate that our framework can effectively translate high-level security policies into OpenFlow rules of the switches without incurring much latency, ultimately leading to efficient attack mitigation and reduced collateral damage. (C) 2019 Elsevier B.V. All rights reserved.
机译:随着海洋环境中信息和通信技术(ICT)的广泛采用,船舶系统越来越类似于其他网络计算系统。定位系统与导航和推进控制系统的集成以及对监控船舶性能的监控和数据采集(SCADA)系统的日益依赖,使现代船舶容易受到各种网络安全问题的影响。此外,频繁或永久的陆上连接使船舶的通信网络成为网络犯罪分子的潜在目标。此类攻击可能导致船只瘫痪(即通过勒索软件攻击),或极大地降低了船舶系统的性能,即导致船舶内关键组件之间的控制消息传播延迟。此外,船员和海事工程师面临使用低级设备特定语法为联网设备配置安全策略的任务,这是一个容易出错且耗时的过程。除此之外,机组人员还必须熟悉用于低级网络管理任务的特定语法,这使问题更加严重。软件定义网络(SDN)的出现有助于降低网络管理任务的复杂性,我们相信可以使用类似的方法来解决更大的问题。因此,我们提出了Cyber​​Ship-IoT框架,以为舰船系统的通信网络组件提供网络级防御。 Cyber​​Ship-IoT提供了高级策略语言和翻译机制,可在船舶通信网络中自动执行策略。框架的模块化设计提供了根据其需求部署检测机制的灵活性。为了评估该框架的可行性和有效性,我们针对涉及典型船舶通信网络的场景开发了一个原型。实验结果表明,我们的框架可以将高级安全策略有效地转换为交换机的OpenFlow规则,而不会引起太多延迟,最终可以有效缓解攻击并减少附带损害。 (C)2019 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号