Strategies for Integrating Controls Flows in Software-Defined In-Vehicle Networks and Their Impact on Network Security

10/08/2020
by   Timo Hackel, et al.
0

Current In-Vehicle Networks (IVNs) connect Electronic Control Units (ECUs) via domain busses. A gateway forwards messages between these domains. Automotive Ethernet emerges as a flat, high-speed backbone technology for IVNs that carries the various control flows within Ethernet frames. Recently, Software-Defined-Networking (SDN) has been identified as a useful building block of the vehicular domain, as it allows the differentiation of packets based on all header fields and thus can isolate unrelated control flows. In this work, we systematically explore the different strategies for integrating automotive control flows in switched Ether-networks and analyze their security impact for a software-defined IVN. We discuss how control flow identifiers can be embedded on different layers resulting in a range of solutions from fully exposed embedding to deep encapsulation. We evaluate these strategies in a realistic IVN based on the communication matrix of a production grade vehicle, which we map into a modern Ethernet topology. We find that visibility of automotive control flows within packet headers is essential for the network infrastructure to enable isolation and access control. With an exposed embedding, the SDN backbone can establish and survey trust zones within the IVN and largely reduce the attack surface of connected cars. An exposed embedding strategy also minimizes communication expenses.

READ FULL TEXT

page 1

page 4

page 7

research
01/03/2022

Secure Time-Sensitive Software-Defined Networking in Vehicles

Current designs of future In-Vehicle Networks (IVN) prepare for switched...
research
11/20/2018

SDN Access Control for the Masses

The evolution of Software-Defined Networking (SDN) has so far been predo...
research
12/21/2021

Network Anomaly Detection in Cars: A Case for Time-Sensitive Stream Filtering and Policing

Connected cars are vulnerable to cyber attacks. Security challenges aris...
research
07/05/2022

Many-fields Packet Classification Using R-Tree and Field Concatenation Technique

Software-defined Networking is an approach that decouples the software-b...
research
10/21/2020

Software-Defined Multi-domain Tactical Networks: Foundations and Future Directions

Software Defined Networking (SDN) has emerged as a programmable approach...
research
09/21/2020

MLSNet: A Policy Complying Multilevel Security Framework for Software Defined Networking

Ensuring that information flowing through a network is secure from manip...
research
03/05/2014

A Taxonomy for Attack Patterns on Information Flows in Component-Based Operating Systems

We present a taxonomy and an algebra for attack patterns on component-ba...

Please sign up or login with your details

Forgot password? Click here to reset