securing santa s sleigh
play

- Securing Santas Sleigh - INET XMAS Presentation 2018 by Timo - PowerPoint PPT Presentation

- Securing Santas Sleigh - INET XMAS Presentation 2018 by Timo Hckel - Securing Santas Sleigh - INET XMAS Presentation 2018 by Timo Hckel Overview 1. Automotive Networks 2. SecVI Research Project 3. Software-Defined Networking


  1. - Securing Santa‘s Sleigh - INET XMAS Presentation 2018 by Timo Häckel

  2. - Securing Santa‘s Sleigh - INET XMAS Presentation 2018 by Timo Häckel

  3. Overview 1. Automotive Networks 2. SecVI Research Project 3. Software-Defined Networking (SDN) 4. Time-Sensitive Software-Defined Networking (TSSDN) 5. Current State and Outlook 6. Party - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  4. 1. Automotive Networks • Electronic Control Units (ECU’s) • About 100 ECU’s in Premium Vehicles • Different Strength • Different Transmission Media • Bus Technologies (CAN, LIN, FlexRay, etc.) • Point-to-Point Connections (Ethernet) • Cross-Communication for Advanced Functions • Step-by-Step to Ethernet - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  5. 1. Automotive Networks • Advantages of Ethernet • Simple and Efficient Communication Architecture • Availability of the Technology • High Bandwidth • But: No Real-Time Guarantees • Real-Time Extensions to Ethernet • Time-Triggered Ethernet (TTE - AS6802) • Audio Video Bridging (AVB - 802.1QBA) • Time-Sensitive Networking (TSN - 802.1Q) - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  6. 1. Automotive Networks • Opening the Network to the Outside • Radio Communication • Cloud Connection • Car-to-X Communication • Current vehicles are vulnerable! https://www.youtube.com/watch?v=RZVYTJarPFs - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  7. - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  8. - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  9. 2. SecVI Research Project Security for Vehicular Information 04/2018 - 03/2021 - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  10. 2. SecVI Research Project • Attack Surface Infotainment: - Bluetooth - WiFi Internet Connection - Radio - USB OBD-II - CD Car-To-X Hardware Access TPMS Keyless Entry - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  11. 2. SecVI Research Project • Goal: Creating a Robust, Secure and Updatable Communication Architecture • Building Blocks • Security Defense Center (Backend) • Secure Gateways (Firewalls) • Secure Networking (SDN + Anomaly Detection) • Secure Communication (Encryption, etc. ) • Secure Boot • Secure Update - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  12. 3. Software-Defined Networking - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  13. 3. Software-Defined Networking - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  14. 3. Software-Defined Networking - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  15. 3. Software-Defined Networking - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  16. 3. Software-Defined Networking - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  17. 3. Software-Defined Networking - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  18. 3. Software-Defined Networking - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  19. 3. Software-Defined Networking ABS Controller BL Break - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  20. 3. Software-Defined Networking BL Break Attacker - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  21. 3. Software-Defined Networking • Advantages: 1. Vendor Neutral Centralized Network Logic 2. Global Network Knowledge 3. Robustness 4. Security Applications • But: We need to avoid the single point of failure. - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  22. 4. Time-Sensitive Software-Defined Networking • Goal: • Make TSN Controllable by an SDN Controller • Make SDN Real-Time Capable and TSN Compatible • Steps: • Combine the Switch Architecture • Extract the TSN Control Logic • Extend OpenFlow to Allow Real-Time Flows - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  23. 4. Time-Sensitive Software-Defined Networking Ingress MAC-based Egress Port Forwarding Ports MAC Table - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  24. 4. Time-Sensitive Software-Defined Networking Per-Stream Ingress MAC-based Enhancements for Egress Filtering and Port Forwarding Scheduled Traffic Ports Policing Schedule MAC Table SR Table Time Sync - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  25. 4. Time-Sensitive Software-Defined Networking Forwarding Plane Ingress MAC-based Egress Port Forwarding Ports MAC Table - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  26. 4. Time-Sensitive Software-Defined Networking Forwarding Plane Ingress Flow-based Egress Port Forwarding Ports Flow Table - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  27. 4. Time-Sensitive Software-Defined Networking Management Plane Network Applications Open Southbound API Control Plane SDN Controller Open Northbound API Forwarding Plane Ingress Flow-based Egress Port Forwarding Ports Flow Table - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  28. 4. Time-Sensitive Software-Defined Networking Management Plane Network Applications Open northbound API Control Plane SDN Controller Open southbound API Forwarding Plane Per-Stream Enhancements Ingress Flow-based Egress Filtering and for Scheduled Port Forwarding Ports Policing Traffic Schedule SR Table Flow Table Time Sync - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  29. 5. Current State and Outlook • Currently • Implementing Time-Sensitive Software Defined Networking • Exploring SDN Hardware and Openflow Simulation • Exploring Automotive Network Security, Attacks and Countermeasures • Future • Introducing SDN to our Demonstration Vehicle • Implement Whitelists for Known C-Matrix of a Vehicle • Let the CCC try to hack the demo vehicle - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  30. 6. Any Questions? - Securing Santa‘s Sleigh - INET XMAS Presentation 11.12.2018 by Timo Häckel

  31. XMAS Party

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend