Restricting Data Flows to Secure Against Remote Attack
Title | Restricting Data Flows to Secure Against Remote Attack |
Publication Type | Conference Paper |
Year of Publication | 2020 |
Authors | ORaw, J., Laverty, D. |
Conference Name | 2020 International Conference on Cyber Security and Protection of Digital Services (Cyber Security) |
Date Published | June 2020 |
Publisher | IEEE |
ISBN Number | 978-1-7281-6428-1 |
Keywords | Air gaps, air-gapped networks, composability, critical infrastructure, Data Diode, data flows, fully securing networks, highly secure systems, Human Behavior, human factors, IEEE compliant PMU data streams, Interiority, IT industry, Metrics, Network security, one-way flows, one-way networks, pubcrawl, remote attacks, resilience, Resiliency, SDN, SDN techniques, security, security of data, software defined networking, Software Defined Node, unidirectional security |
Abstract | Fully securing networks from remote attacks is recognized by the IT industry as a critical and imposing challenge. Even highly secure systems remain vulnerable to attacks and advanced persistent threats. Air-gapped networks may be secure from remote attack. One-way flows are a novel approach to improving the security of telemetry for critical infrastructure, retaining some of the benefits of interconnectivity whilst maintaining a level of network security analogous to that of unconnected devices. Simple and inexpensive techniques can be used to provide this unidirectional security, removing the risk of remote attack from a range of potential targets and subnets. The application of one-way networks is demonstrated using IEEE compliant PMU data streams as a case study. Scalability is demonstrated using SDN techniques. Finally, these techniques are combined, demonstrating a node which can be secured from remote attack, within defined limitations. |
URL | https://ieeexplore.ieee.org/abstract/document/9138875 |
DOI | 10.1109/CyberSecurity49315.2020.9138875 |
Citation Key | oraw_restricting_2020 |
- network security
- unidirectional security
- Software Defined Node
- software defined networking
- security of data
- security
- SDN techniques
- SDN
- Resiliency
- resilience
- remote attacks
- pubcrawl
- one-way networks
- one-way flows
- Air gaps
- Metrics
- IT industry
- Interiority
- IEEE compliant PMU data streams
- Human Factors
- Human behavior
- highly secure systems
- fully securing networks
- data flows
- Data Diode
- critical infrastructure
- composability
- air-gapped networks