Static Analysis of Packet Forwarding and Filtering Configurations in Industrial Networks

M. Cheminod, L. Seno
{"title":"Static Analysis of Packet Forwarding and Filtering Configurations in Industrial Networks","authors":"M. Cheminod, L. Seno","doi":"10.1109/WFCS57264.2023.10144115","DOIUrl":null,"url":null,"abstract":"Securing industrial networked infrastructures has become increasingly important since the growth in their connectivity brought by production digitalization and the diffusion of paradigms such as Industrial Internet of Things (IIoT). Network segmentation is considered best practice to protect these networks from outside/inside cyber-attacks. To this purpose, network devices equipped with forwarding/filtering capabilities need to be suitably configured and deployed for the enforcement of segment-related security policies. Configuration of these devices in today industrial networked infrastructures is typically the result of a mix of manual and automated processes and, given the heterogeneity of devices and configuration languages, as well as of the supported applications and related requirements, it is often hard to make sure of its correctness and impact, e.g., on traffic latency. In this paper, a model is proposed to jointly describe network forwarding and filtering configuration. Techniques are then provided to perform static analyses such as verification of reachability intents and configuration equivalence, as well as the estimation of the latency introduced for handling specific traffic.","PeriodicalId":345607,"journal":{"name":"2023 IEEE 19th International Conference on Factory Communication Systems (WFCS)","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-04-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE 19th International Conference on Factory Communication Systems (WFCS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WFCS57264.2023.10144115","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Securing industrial networked infrastructures has become increasingly important since the growth in their connectivity brought by production digitalization and the diffusion of paradigms such as Industrial Internet of Things (IIoT). Network segmentation is considered best practice to protect these networks from outside/inside cyber-attacks. To this purpose, network devices equipped with forwarding/filtering capabilities need to be suitably configured and deployed for the enforcement of segment-related security policies. Configuration of these devices in today industrial networked infrastructures is typically the result of a mix of manual and automated processes and, given the heterogeneity of devices and configuration languages, as well as of the supported applications and related requirements, it is often hard to make sure of its correctness and impact, e.g., on traffic latency. In this paper, a model is proposed to jointly describe network forwarding and filtering configuration. Techniques are then provided to perform static analyses such as verification of reachability intents and configuration equivalence, as well as the estimation of the latency introduced for handling specific traffic.
工业网络中包转发和过滤配置的静态分析
随着生产数字化和工业物联网(IIoT)等模式的扩散,工业网络基础设施的连通性不断提高,保护工业网络基础设施变得越来越重要。网络分段被认为是保护这些网络免受外部/内部网络攻击的最佳实践。为此,需要对具有转发/过滤功能的网络设备进行适当的配置和部署,以实施与网段相关的安全策略。在今天的工业网络基础设施中,这些设备的配置通常是手动和自动化过程混合的结果,并且考虑到设备和配置语言的异质性,以及所支持的应用程序和相关需求,通常很难确保其正确性和影响,例如,对流量延迟的影响。本文提出了一种联合描述网络转发和过滤配置的模型。然后提供了执行静态分析的技术,例如验证可达性意图和配置等价性,以及估计处理特定流量所引入的延迟。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信