Sie befinden Sich nicht im Netzwerk der Universität Paderborn. Der Zugriff auf elektronische Ressourcen ist gegebenenfalls nur via VPN oder Shibboleth (DFN-AAI) möglich. mehr Informationen...
Ergebnis 11 von 20
2019 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), 2019, p.57-66
2019
Volltextzugriff (PDF)

Details

Autor(en) / Beteiligte
Titel
Network Reconnaissance and Vulnerability Excavation of Secure DDS Systems
Ist Teil von
  • 2019 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), 2019, p.57-66
Ort / Verlag
IEEE
Erscheinungsjahr
2019
Quelle
IEEE/IET Electronic Library
Beschreibungen/Notizen
  • Data Distribution Service (DDS) is a realtime peer-to-peer protocol that serves as a scalable middleware between distributed networked systems found in many Industrial IoT domains such as automotive, medical, energy, and defense. Since the initial ratification of the standard, specifications have introduced a Security Model and Service Plugin Interface (SPI) architecture, facilitating authenticated encryption and data centric access control while preserving interoperable data exchange. However, as Secure DDS v1.1, the default plugin specifications presently exchanges digitally signed capability lists of both participants in the clear during the crypto handshake for permission attestation; thus breaching confidentiality of the context of the connection. In this work, we present an attacker model that makes use of network reconnaissance afforded by this leaked context in conjunction with formal verification and model checking to arbitrarily reason about the underlying topology and reachability of information flow, enabling targeted attacks such as selective denial of service, adversarial partitioning of the data bus, or vulnerability excavation of vendor implementations.
Sprache
Englisch
Identifikatoren
DOI: 10.1109/EuroSPW.2019.00013
Titel-ID: cdi_ieee_primary_8802507

Weiterführende Literatur

Empfehlungen zum selben Thema automatisch vorgeschlagen von bX