TSNZeek: An Open-source Intrusion Detection System for IEEE 802.1 Time-sensitive Networking

03/20/2023
by   Doganalp Ergenc, et al.
0

IEEE 802.1 Time-sensitive Networking (TSN) standards are envisioned to replace legacy network protocols in critical domains to ensure reliable and deterministic communication over off-the-shelf Ethernet equipment. However, they lack security countermeasures and can even impose new attack vectors that may lead to hazardous consequences. This paper presents the first open-source security monitoring and intrusion detection mechanism, TSNZeek, for IEEE 802.1 TSN protocols. We extend an existing monitoring tool, Zeek, with a new packet parsing grammar to process TSN data traffic and a rule-based attack detection engine for TSN-specific threats. We also discuss various security-related configuration and design aspects for IEEE 802.1 TSN monitoring. Our experiments show that TSNZeek causes only  5 detects various threats in a real TSN testbed.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/31/2023

Towards Developing Resilient and Service-oriented Mission-critical Systems

Mission-critical systems (MCSs) have embraced new design paradigms such ...
research
07/22/2020

Evaluation of Network Based IDS and Deployment of multi-sensor IDS

Cloud-based and network-based technology has witnessed an exponential ri...
research
11/27/2019

Period Adaptation for Continuous Security Monitoring in Multicore Real-Time Systems

We propose a design-time framework (named HYDRA-C) for integrating secur...
research
07/06/2022

RIDS : Real-time Intrusion Detection System for WPA3 enabled Enterprise Networks

With the advent of new IEEE 802.11ax (WiFi 6) devices, enabling security...
research
08/26/2019

DoS Protection through Credit Based Metering – Simulation Based Evaluation for Time-Sensitive Networking in Cars

Ethernet is the most promising solution to reduce complexity and enhance...

Please sign up or login with your details

Forgot password? Click here to reset