论文标题

空中:低端设备的有效自我修复网络

Airmed: Efficient Self-Healing Network of Low-End Devices

论文作者

Das, Sourav, Wedaj, Samuel, Paul, Kolin, Bellur, Umesh, Ribeiro, Vinay Joseph

论文摘要

应用特定的网络物理系统的扩散以及对此类系统(Mirai和Hajime等恶意软件)的各种攻击的出现强调了确保此类网络的需求。大多数现有的安全工作仅集中在发现恶意软件的存在上。然而,鉴于大多数攻击感染了一些设备,大多数攻击能够通过网络传播,因此使用网络的通信能力系统地将病毒传播和同时系统地清洁受影响的节点。为此,我们提出了AIRMED - 一种方法和系统,不仅是检测物联网节点上应用程序软件的损坏,还可以使用其邻居自我纠正自己。 AIRMED的分散机制可以防止自行有恶意软件的传播,也可以用作更新此类IoT设备上应用程序代码的技术。在AirMed的新颖性中,有一种新颖的Bloom滤波器技术以及硬件支持,可从良性应用程序代码中识别恶意软件程序的位置,一种自适应自我检查计算效率,以及均匀的随机添加和流签名,以实现安全和带宽有效的有效代码交换以纠正损坏设备的安全和带宽的代码。我们使用Omnet ++模拟器中TrustLite的嵌入式系统安全体系结构来评估AIRMED的性能。结果表明,空气播放最多可扩展数千台设备,确保保证整个网络的更新,并且可以在10分钟内在内部和外部传播模型中恢复95%的节点。此外,我们评估记忆和沟通成本,并表明AirMed有效,开销非常低。

The proliferation of application specific cyber-physical systems coupled with the emergence of a variety of attacks on such systems (malware such as Mirai and Hajime) underlines the need to secure such networks. Most existing security efforts have focused on only detection of the presence of malware. However given the ability of most attacks to spread through the network once they infect a few devices, it is important to contain the spread of a virus and at the same time systematically cleanse the impacted nodes using the communication capabilities of the network. Toward this end, we present Airmed - a method and system to not just detect corruption of the application software on a IoT node, but to self correct itself using its neighbors. Airmed's decentralized mechanisms prevent the spread of self-propagating malware and can also be used as a technique for updating application code on such IoT devices. Among the novelties of Airmed are a novel bloom-filter technique along with hardware support to identify position of the malware program from the benign application code, an adaptive self-check for computational efficiency, and a uniform random-backoff and stream signatures for secure and bandwidth efficient code exchange to correct corrupted devices. We assess the performance of Airmed, using the embedded systems security architecture of TrustLite in the OMNeT++ simulator. The results show that Airmed scales up to thousands of devices, ensures guaranteed update of the entire network, and can recover 95% of the nodes in 10 minutes in both internal and external propagation models. Moreover, we evaluate memory and communication costs and show that Airmed is efficient and incurs very low overhead.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源