The Experts below are selected from a list of 1035 Experts worldwide ranked by ideXlab platform

Alex J. Halderman - One of the best experts on this subject based on the ideXlab platform.

  • Umbra: Embedded Web Security through
    2016
    Co-Authors: Travis Finkenauer, Alex J. Halderman
    Abstract:

    Abstract Embedded devices with web interfaces are prevalent, but, due to memory and processing constraints, implementations typically make use of Common Gateway Interface (CGI) binaries written in low-level, memory-unsafe languages. This creates the possibility of memory corrup-tion attacks as well as traditional web attacks. We present Umbra, an application-Layer Firewall specifically designed for protecting web inter-faces in embedded devices. By acting as a “friendly man-in-the-middle,” Umbra can protect against attacks such as cross-site request forgery (CSRF), information leaks, and authentication bypass vulnerabilities. We evaluate Umbra’s security by analyzing recent vulnerabilities listed in the CVE database from several embedded vendors and find that it would have prevented half of the vulnerabilities. We also show that Umbra comfortably runs within the constraints of an embedded system while incurring minimal performance overhead

  • umbra embedded web security through application Layer Firewalls
    2015
    Co-Authors: Travis Finkenauer, Alex J. Halderman
    Abstract:

    Embedded devices with web interfaces are prevalent, but, due to memory and processing constraints, implementations typically make use of Common Gateway Interface (CGI) binaries written in low-level, memory-unsafe languages. This creates the possibility of memory corruption attacks as well as traditional web attacks. We present Umbra, an application-Layer Firewall specifically designed for protecting web interfaces in embedded devices. By acting as a “friendly man-in-the-middle,” Umbra can protect against attacks such as cross-site request forgery (CSRF), information leaks, and authentication bypass vulnerabilities. We evaluate Umbra’s security by analyzing recent vulnerabilities listed in the CVE database from several embedded vendors and find that it would have prevented half of the vulnerabilities. We also show that Umbra comfortably runs within the constraints of an embedded system while incurring minimal performance overhead.

Travis Finkenauer - One of the best experts on this subject based on the ideXlab platform.

  • Umbra: Embedded Web Security through
    2016
    Co-Authors: Travis Finkenauer, Alex J. Halderman
    Abstract:

    Abstract Embedded devices with web interfaces are prevalent, but, due to memory and processing constraints, implementations typically make use of Common Gateway Interface (CGI) binaries written in low-level, memory-unsafe languages. This creates the possibility of memory corrup-tion attacks as well as traditional web attacks. We present Umbra, an application-Layer Firewall specifically designed for protecting web inter-faces in embedded devices. By acting as a “friendly man-in-the-middle,” Umbra can protect against attacks such as cross-site request forgery (CSRF), information leaks, and authentication bypass vulnerabilities. We evaluate Umbra’s security by analyzing recent vulnerabilities listed in the CVE database from several embedded vendors and find that it would have prevented half of the vulnerabilities. We also show that Umbra comfortably runs within the constraints of an embedded system while incurring minimal performance overhead

  • umbra embedded web security through application Layer Firewalls
    2015
    Co-Authors: Travis Finkenauer, Alex J. Halderman
    Abstract:

    Embedded devices with web interfaces are prevalent, but, due to memory and processing constraints, implementations typically make use of Common Gateway Interface (CGI) binaries written in low-level, memory-unsafe languages. This creates the possibility of memory corruption attacks as well as traditional web attacks. We present Umbra, an application-Layer Firewall specifically designed for protecting web interfaces in embedded devices. By acting as a “friendly man-in-the-middle,” Umbra can protect against attacks such as cross-site request forgery (CSRF), information leaks, and authentication bypass vulnerabilities. We evaluate Umbra’s security by analyzing recent vulnerabilities listed in the CVE database from several embedded vendors and find that it would have prevented half of the vulnerabilities. We also show that Umbra comfortably runs within the constraints of an embedded system while incurring minimal performance overhead.

Adriano Valenzano - One of the best experts on this subject based on the ideXlab platform.

  • performance evaluation and modeling of an industrial application Layer Firewall
    2018
    Co-Authors: Manuel Cheminod, Luca Durante, Lucia Seno, Adriano Valenzano
    Abstract:

    The availability of performance studies and simple models for Firewalls able to deal with industrial application-Layer communication protocols, such as Modbus/TCP, is crucial when the impact of these devices has to be estimated, even roughly, before their actual deployment in industrial networks. Unfortunately, most manufacturers do not provide this kind of information for commercial off-the-shelf available products. Thus, a viable solution is the development and experimental validation of simple models that can be used by designers to predict those Firewall characteristics not explicitly related to their security capabilities. As an example, latency introduced on message forwarding is an aspect of significant interest in many industrial control systems, where delays and jitters in data delivery can severely impact on the effectiveness of the control actions. This paper reports on our experience in developing a performance model for a commercial device able to perform advanced application-Layer filtering, in particular of Modbus/TCP traffic. A set of ad hoc designed experiments, performed by means of a purposely developed laboratory testbed, enabled both model development and validation, confirming a good correspondence of the estimated performance with the device actual behavior.

Manuel Cheminod - One of the best experts on this subject based on the ideXlab platform.

  • performance evaluation and modeling of an industrial application Layer Firewall
    2018
    Co-Authors: Manuel Cheminod, Luca Durante, Lucia Seno, Adriano Valenzano
    Abstract:

    The availability of performance studies and simple models for Firewalls able to deal with industrial application-Layer communication protocols, such as Modbus/TCP, is crucial when the impact of these devices has to be estimated, even roughly, before their actual deployment in industrial networks. Unfortunately, most manufacturers do not provide this kind of information for commercial off-the-shelf available products. Thus, a viable solution is the development and experimental validation of simple models that can be used by designers to predict those Firewall characteristics not explicitly related to their security capabilities. As an example, latency introduced on message forwarding is an aspect of significant interest in many industrial control systems, where delays and jitters in data delivery can severely impact on the effectiveness of the control actions. This paper reports on our experience in developing a performance model for a commercial device able to perform advanced application-Layer filtering, in particular of Modbus/TCP traffic. A set of ad hoc designed experiments, performed by means of a purposely developed laboratory testbed, enabled both model development and validation, confirming a good correspondence of the estimated performance with the device actual behavior.

Hafiz Farooq Ahmad - One of the best experts on this subject based on the ideXlab platform.

  • autonomous short latency system for web application Layer Firewall
    2010
    Co-Authors: Hironao Takahashi, Kinji Mori, Hafiz Farooq Ahmad
    Abstract:

    Real time application was required many types of industrial controllers, factory machines since 20-century. It is also utilizing many types of real time controllers for vehicle such as train, automobile and so on [1]. On the other hand, Web services that are using Internet are required short latency system. When the accesses are increased, services of quality are so important factors to achieve their requirement. Thus, these web services are facing different levels of requirement. One is short latency of time service and other one is protection from malicious access. To support two of both at same time, it is big challenge in Web service today. The main issue is malicious web attacks on web application Layer level accesses that came up recently. Today's web service provider is attempting to achieve this level of service. There are a few Web application level security technology but the all of their approach is black list or white list base. To analyze these HTTP protocol accesses, web site is always required high performance list search and compares them. From the analyzing processes have some events overhead. Keeping short latency of time, it needs high I/O performance solution. This paper is proposing L3 block cache node with eventually consistency technology to achieve timeliness autonomous decentralized system. The latency of time is compared with traditional approach system. Jmeter based web access response evaluation is shown very positive result. Thus, proposing short latency node system is great solution for Web Application Firewall with short latency.