基于虚拟网络接口的mac层信任区域性能评估

A. Wall, Hannes Raddatz, Michael Rethfeldt, P. Danielis, D. Timmermann
{"title":"基于虚拟网络接口的mac层信任区域性能评估","authors":"A. Wall, Hannes Raddatz, Michael Rethfeldt, P. Danielis, D. Timmermann","doi":"10.1109/MOBISECSERV.2018.8311442","DOIUrl":null,"url":null,"abstract":"In smart building scenarios there are a lot of vulnerable devices that could be exploited to run attacks against other devices within the same LAN. Even though existing solutions mostly tackle the problem by cluster-based authentication and key management schemes, none of them leverages the potential of isolating traffic by network interface virtualization. Thus, we proposed in a previous work a concept to avoid unauthorized communication by considering separating applications with virtual MAC interfaces as the consequence. The decreased attack surface, as the main advantage, is achieved by isolating communication through virtual MAC interfaces based on application-specific demands. To demonstrate the efficiency of this concept we developed an implementation based on state-of-the-art communication protocols. We applied our interface virtualization concept to the IEEE 802.11s WLAN mesh technology, combining it with a lightweight RESTful web service for security credentials deployment. The resulting proof-of-concept implementation in a real-world multi-hop scenario shows performance of the credentials deployment and the impact of the MAC-layer parallelization. The promising results, e.g., no drop of the overall throughput using multiple virtual MAC interfaces, show that our concept can be an efficient solution for future smart buildings.","PeriodicalId":281294,"journal":{"name":"2018 Fourth International Conference on Mobile and Secure Services (MobiSecServ)","volume":"14 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Performance evaluation of MAC-layer trust zones over virtual network interfaces\",\"authors\":\"A. Wall, Hannes Raddatz, Michael Rethfeldt, P. Danielis, D. Timmermann\",\"doi\":\"10.1109/MOBISECSERV.2018.8311442\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In smart building scenarios there are a lot of vulnerable devices that could be exploited to run attacks against other devices within the same LAN. Even though existing solutions mostly tackle the problem by cluster-based authentication and key management schemes, none of them leverages the potential of isolating traffic by network interface virtualization. Thus, we proposed in a previous work a concept to avoid unauthorized communication by considering separating applications with virtual MAC interfaces as the consequence. The decreased attack surface, as the main advantage, is achieved by isolating communication through virtual MAC interfaces based on application-specific demands. To demonstrate the efficiency of this concept we developed an implementation based on state-of-the-art communication protocols. We applied our interface virtualization concept to the IEEE 802.11s WLAN mesh technology, combining it with a lightweight RESTful web service for security credentials deployment. The resulting proof-of-concept implementation in a real-world multi-hop scenario shows performance of the credentials deployment and the impact of the MAC-layer parallelization. The promising results, e.g., no drop of the overall throughput using multiple virtual MAC interfaces, show that our concept can be an efficient solution for future smart buildings.\",\"PeriodicalId\":281294,\"journal\":{\"name\":\"2018 Fourth International Conference on Mobile and Secure Services (MobiSecServ)\",\"volume\":\"14 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-02-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 Fourth International Conference on Mobile and Secure Services (MobiSecServ)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/MOBISECSERV.2018.8311442\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 Fourth International Conference on Mobile and Secure Services (MobiSecServ)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MOBISECSERV.2018.8311442","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

在智能建筑场景中,有许多易受攻击的设备可以被利用来对同一局域网内的其他设备进行攻击。尽管现有的解决方案主要通过基于集群的身份验证和密钥管理方案来解决这个问题,但它们都没有利用通过网络接口虚拟化隔离流量的潜力。因此,我们在之前的工作中提出了一个概念,通过考虑将应用程序与虚拟MAC接口分离,从而避免未经授权的通信。其主要优点是基于特定的应用需求,通过虚拟MAC接口隔离通信,从而减少了攻击面。为了证明这个概念的有效性,我们开发了一个基于最先进的通信协议的实现。我们将接口虚拟化概念应用于IEEE 802.11s WLAN网状技术,并将其与用于安全凭据部署的轻量级RESTful web服务相结合。在真实的多跳场景中得到的概念验证实现显示了凭据部署的性能和mac层并行化的影响。有希望的结果,例如,使用多个虚拟MAC接口的总吞吐量没有下降,表明我们的概念可以成为未来智能建筑的有效解决方案。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Performance evaluation of MAC-layer trust zones over virtual network interfaces
In smart building scenarios there are a lot of vulnerable devices that could be exploited to run attacks against other devices within the same LAN. Even though existing solutions mostly tackle the problem by cluster-based authentication and key management schemes, none of them leverages the potential of isolating traffic by network interface virtualization. Thus, we proposed in a previous work a concept to avoid unauthorized communication by considering separating applications with virtual MAC interfaces as the consequence. The decreased attack surface, as the main advantage, is achieved by isolating communication through virtual MAC interfaces based on application-specific demands. To demonstrate the efficiency of this concept we developed an implementation based on state-of-the-art communication protocols. We applied our interface virtualization concept to the IEEE 802.11s WLAN mesh technology, combining it with a lightweight RESTful web service for security credentials deployment. The resulting proof-of-concept implementation in a real-world multi-hop scenario shows performance of the credentials deployment and the impact of the MAC-layer parallelization. The promising results, e.g., no drop of the overall throughput using multiple virtual MAC interfaces, show that our concept can be an efficient solution for future smart buildings.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Password-protected secret sharing scheme with the same threshold in distribution and restoration Fast secure computation based on a secret sharing scheme for n < 2k − 1 An evaluation of a virtual network function for real-time threat detection using stream processing The impact of sand propagation environment on the performance of wireless sensor networks Performance evaluation of MAC-layer trust zones over virtual network interfaces
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1