• DocumentCode
    680449
  • Title

    Security evaluation of a control system using Named Data Networking

  • Author

    Perez, Victor ; Garip, Mevlut Turker ; Lam, Stanley ; Lixia Zhang

  • Author_Institution
    Dept. of Comput. Sci., Univ. of California Los Angeles, Los Angeles, CA, USA
  • fYear
    2013
  • fDate
    7-10 Oct. 2013
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Security is an integral part of networked computer systems. The recent Named Data Networking (NDN) project aims to develop a new Internet architecture that communicates data using names rather than locations, the latter of which is what the current IP-based Internet does with IP addresses. One of the first real-world applications using NDN is a lighting control system. We conduct a red team assessment of the current state of the security of this lighting system and its NDN implementation. The system is representative of a more general class of automated controller systems. Our analysis found that due to NDN´s use of named data, the system inherently prevents most attacks that IP-based systems are vulnerable to. Although many parts of the system are secure, we discovered some problems with the verification of timestamps and processing of large packets that led to a severe memory leak. The system also lacks a secure key distribution mechanism. While NDN security is on the right track, there are important security design issues NDN must account for.
  • Keywords
    IP networks; Internet; building management systems; computer network security; controllers; lighting control; networked control systems; IP addresses; IP-based Internet architecture; IP-based systems; NDN project; NDN security; automated controller systems; control system security evaluation; lighting control system; memory leak; named data networking project; networked computer systems; packet processing; red team assessment; secure key distribution mechanism; timestamp verification; Buildings; IP networks; Internet; Lighting; Lighting control; Security; Building automation; Computer networks; Computer security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Protocols (ICNP), 2013 21st IEEE International Conference on
  • Conference_Location
    Goettingen
  • Type

    conf

  • DOI
    10.1109/ICNP.2013.6733672
  • Filename
    6733672