The Experts below are selected from a list of 222 Experts worldwide ranked by ideXlab platform
H.m. Kluepfel - One of the best experts on this subject based on the ideXlab platform.
-
ACM Conference on Computer and Communications Security - Securing a global village and its resources: Baseline Security for interconnected signaling system #7 telecommunications networks
Proceedings of the 1st ACM conference on Computer and communications security - CCS '93, 1993Co-Authors: H.m. KluepfelAbstract:The resulting national focus on Network Integrity issues, spawned the development of an industry commitment to affect and realize a minimum Security Baseline for interconnected SS7 networks. In addition the affected carriers in those outage have accelerated their pursuit of secure solutions to today's intelligent networking. [2] This paper will focus on the development of the Baseline and the current effort to take the Baseline into national, e.g., National Institute of Technology and Standards (NIST), and internationally recognized standard bodies or forums, e.g., the Council of European Committees Green Book on Information Security, and the American National Standards Institute efforts on Telecommunications Management Networks within T1M1.5. Avoiding the standard broad based approach to the subject, this paper is addressed to the nationally and internationally interconnected telecommunications carrier systems managers and administrators who are often the “frst compromised” and “last to know” that they, their clients and customers are at risk from the networked vulnerabilities of a trusted partner's network or the dumbing down of the deployed Security technology from a vendor.
-
securing a global village and its resources Baseline Security for interconnected signaling system 7 telecommunications networks
Computer and Communications Security, 1993Co-Authors: H.m. KluepfelAbstract:The resulting national focus on Network Integrity issues, spawned the development of an industry commitment to affect and realize a minimum Security Baseline for interconnected SS7 networks. In addition the affected carriers in those outage have accelerated their pursuit of secure solutions to today's intelligent networking. [2] This paper will focus on the development of the Baseline and the current effort to take the Baseline into national, e.g., National Institute of Technology and Standards (NIST), and internationally recognized standard bodies or forums, e.g., the Council of European Committees Green Book on Information Security, and the American National Standards Institute efforts on Telecommunications Management Networks within T1M1.5. Avoiding the standard broad based approach to the subject, this paper is addressed to the nationally and internationally interconnected telecommunications carrier systems managers and administrators who are often the “frst compromised” and “last to know” that they, their clients and customers are at risk from the networked vulnerabilities of a trusted partner's network or the dumbing down of the deployed Security technology from a vendor.
-
Securing a global village and its resources: Baseline Security for interconnected Signaling System #7 telecommunications networks
1993 Proceedings of IEEE International Carnahan Conference on Security Technology, 1993Co-Authors: H.m. KluepfelAbstract:The authors describes recent experience in countering the growing problem of network integrity Security threats. He outlines the need for a Security Baseline standard for all SS7 (Signaling System #7) networked service providers. In describing the evolving intrusion threats to the global public network, he defines and comments on the seriousness of the problem. The important concept emphasized is that all service providers on the SS7 network may be placed at risk by the absence of effective Security mechanisms in any one service provider's SS7 domain. The focus of the present work is to help define a Baseline standard of due care on Security applicable to any interconnectd SS7 service provider's or customer network to create a global industry equivalent to national and international trusted computer Security evaluation criteria.
Joan Arnedo-moreno - One of the best experts on this subject based on the ideXlab platform.
-
NBiS - Experimental Evaluation of Anonymous Protocols under the JXTA Middlewar
2012 15th International Conference on Network-Based Information Systems, 2012Co-Authors: Joan Arnedo-moreno, Noemí Pérez-gilabert, Marc Domingo-prietoAbstract:JXTA is a peer-to-peer (P2P) middleware which has undergone successive iterations through its 10 years of history, slowly incorporating a Security Baseline that may cater to different applications and services. However, in order to appeal to a broader set of secure scenarios, it would be interesting to take into consideration more advanced capabilities, such as anonymity. There are several proposals on anonymous protocols that can be applied in the context of a P2P network, but it is necessary to be able to choose the right one given each application's needs. In this paper, we provide an experimental evaluation of two relevant protocols, each one belonging to a different category of approaches to anonymity: unimessage and split message. We base our analysis on two scenarios, with stable and non-stable peers, and three metrics: round trip-time (RTT), node processing time and reliability.
-
Towards secure mobile P2P applications using JXME.
2012Co-Authors: Marc Domingo-prieto, Joan Arnedo-moreno, Jordi Herrera-joancomartí, Josep Prieto-blázquezAbstract:Mobile devices have become ubiquitous, allowing the integration of new information from a large range of devices. However, the development of new applications requires a powerful framework which simplifies their construction. JXME is the JXTA implementation for mobile devices using J2ME, its main value being its simplicity when creating peer-to-peer (P2P) applications on limited devices. On that regard, an issue that is becoming very important in the recent times is being able to provide a Security Baseline to such applications. This paper analyzes the current state of Security in JXME and proposes a simple Security mechanism in order to protect JXME applications against a broad range of vulnerabilities.
-
Experimental Evaluation of Anonymous Protocols under the JXTA Middlewar
2012 15th International Conference on Network-Based Information Systems, 2012Co-Authors: Joan Arnedo-moreno, Noemí Pérez-gilabert, Marc Domingo-prietoAbstract:JXTA is a peer-to-peer (P2P) middleware which has undergone successive iterations through its 10 years of history, slowly incorporating a Security Baseline that may cater to different applications and services. However, in order to appeal to a broader set of secure scenarios, it would be interesting to take into consideration more advanced capabilities, such as anonymity. There are several proposals on anonymous protocols that can be applied in the context of a P2P network, but it is necessary to be able to choose the right one given each application's needs. In this paper, we provide an experimental evaluation of two relevant protocols, each one belonging to a different category of approaches to anonymity: unimessage and split message. We base our analysis on two scenarios, with stable and non-stable peers, and three metrics: round trip-time (RTT), node processing time and reliability.
-
NBiS - Lightweight Security for JXME-Proxied Relay Authentication
2011 14th International Conference on Network-Based Information Systems, 2011Co-Authors: Marc Domingo-prieto, Joan Arnedo-morenoAbstract:Mobile devices have become ubiquitous, allowing the integration of new information from a big range of objects. But the development of new applications requires a powerful framework which simplifies their construction. JXME is the JXTA protocols implementation for mobile devices using J2ME. The main value of JXME is its simplicity when creating peer-to-peer (P2P) applications on limited devices. However, providing a minimum Security Baseline to such applications is becoming a key issue, which is specially challenging when constrained devices are concerned. This paper proposes a simple Security mechanisms in order to protect applications against a broad range of vulnerabilities. The protocol overhead has been experimentally tested in order to assess its low impact on device performance, an important requisite on limited devices.
-
Lightweight Security for JXME-Proxied Relay Authentication
2011 14th International Conference on Network-Based Information Systems, 2011Co-Authors: Marc Domingo-prieto, Joan Arnedo-morenoAbstract:Mobile devices have become ubiquitous, allowing the integration of new information from a big range of objects. But the development of new applications requires a powerful framework which simplifies their construction. JXME is the JXTA protocols implementation for mobile devices using J2ME. The main value of JXME is its simplicity when creating peer-to-peer (P2P) applications on limited devices. However, providing a minimum Security Baseline to such applications is becoming a key issue, which is specially challenging when constrained devices are concerned. This paper proposes a simple Security mechanisms in order to protect applications against a broad range of vulnerabilities. The protocol overhead has been experimentally tested in order to assess its low impact on device performance, an important requisite on limited devices.
Marc Domingo-prieto - One of the best experts on this subject based on the ideXlab platform.
-
NBiS - Experimental Evaluation of Anonymous Protocols under the JXTA Middlewar
2012 15th International Conference on Network-Based Information Systems, 2012Co-Authors: Joan Arnedo-moreno, Noemí Pérez-gilabert, Marc Domingo-prietoAbstract:JXTA is a peer-to-peer (P2P) middleware which has undergone successive iterations through its 10 years of history, slowly incorporating a Security Baseline that may cater to different applications and services. However, in order to appeal to a broader set of secure scenarios, it would be interesting to take into consideration more advanced capabilities, such as anonymity. There are several proposals on anonymous protocols that can be applied in the context of a P2P network, but it is necessary to be able to choose the right one given each application's needs. In this paper, we provide an experimental evaluation of two relevant protocols, each one belonging to a different category of approaches to anonymity: unimessage and split message. We base our analysis on two scenarios, with stable and non-stable peers, and three metrics: round trip-time (RTT), node processing time and reliability.
-
Towards secure mobile P2P applications using JXME.
2012Co-Authors: Marc Domingo-prieto, Joan Arnedo-moreno, Jordi Herrera-joancomartí, Josep Prieto-blázquezAbstract:Mobile devices have become ubiquitous, allowing the integration of new information from a large range of devices. However, the development of new applications requires a powerful framework which simplifies their construction. JXME is the JXTA implementation for mobile devices using J2ME, its main value being its simplicity when creating peer-to-peer (P2P) applications on limited devices. On that regard, an issue that is becoming very important in the recent times is being able to provide a Security Baseline to such applications. This paper analyzes the current state of Security in JXME and proposes a simple Security mechanism in order to protect JXME applications against a broad range of vulnerabilities.
-
Experimental Evaluation of Anonymous Protocols under the JXTA Middlewar
2012 15th International Conference on Network-Based Information Systems, 2012Co-Authors: Joan Arnedo-moreno, Noemí Pérez-gilabert, Marc Domingo-prietoAbstract:JXTA is a peer-to-peer (P2P) middleware which has undergone successive iterations through its 10 years of history, slowly incorporating a Security Baseline that may cater to different applications and services. However, in order to appeal to a broader set of secure scenarios, it would be interesting to take into consideration more advanced capabilities, such as anonymity. There are several proposals on anonymous protocols that can be applied in the context of a P2P network, but it is necessary to be able to choose the right one given each application's needs. In this paper, we provide an experimental evaluation of two relevant protocols, each one belonging to a different category of approaches to anonymity: unimessage and split message. We base our analysis on two scenarios, with stable and non-stable peers, and three metrics: round trip-time (RTT), node processing time and reliability.
-
NBiS - Lightweight Security for JXME-Proxied Relay Authentication
2011 14th International Conference on Network-Based Information Systems, 2011Co-Authors: Marc Domingo-prieto, Joan Arnedo-morenoAbstract:Mobile devices have become ubiquitous, allowing the integration of new information from a big range of objects. But the development of new applications requires a powerful framework which simplifies their construction. JXME is the JXTA protocols implementation for mobile devices using J2ME. The main value of JXME is its simplicity when creating peer-to-peer (P2P) applications on limited devices. However, providing a minimum Security Baseline to such applications is becoming a key issue, which is specially challenging when constrained devices are concerned. This paper proposes a simple Security mechanisms in order to protect applications against a broad range of vulnerabilities. The protocol overhead has been experimentally tested in order to assess its low impact on device performance, an important requisite on limited devices.
-
Lightweight Security for JXME-Proxied Relay Authentication
2011 14th International Conference on Network-Based Information Systems, 2011Co-Authors: Marc Domingo-prieto, Joan Arnedo-morenoAbstract:Mobile devices have become ubiquitous, allowing the integration of new information from a big range of objects. But the development of new applications requires a powerful framework which simplifies their construction. JXME is the JXTA protocols implementation for mobile devices using J2ME. The main value of JXME is its simplicity when creating peer-to-peer (P2P) applications on limited devices. However, providing a minimum Security Baseline to such applications is becoming a key issue, which is specially challenging when constrained devices are concerned. This paper proposes a simple Security mechanisms in order to protect applications against a broad range of vulnerabilities. The protocol overhead has been experimentally tested in order to assess its low impact on device performance, an important requisite on limited devices.
John W. Piper - One of the best experts on this subject based on the ideXlab platform.
-
Identification and application of Security measures for petrochemical industrial control systems
Journal of Loss Prevention in The Process Industries, 2013Co-Authors: H. M. Leith, John W. PiperAbstract:Abstract The financial success of the chemical and petrochemical industry will increasingly depend upon the Security of process control systems. This paper presents recommendations and insights gleaned from over 100 Security risk assessment (SRA) and process control analyses, using requirements Baselines extracted from the National Institute of Standards and Technology (NIST) special publication 800-53 (and Appendix A), the Recommended Security Controls for Federal Information Systems and Organizations , in conjunction with NIST special publication 800-82, Guide to Industrial Control Systems(ICS) Security, to provide the bridge in application of 800-53 controls to IC/SCADA. The paper identifies how current and projected malevolent threats posed by insiders, outsiders, collusion, and system-induced threats can erode system performance in terms of shut downs, sabotage, production disruption, and contamination. The issue is not whether there are clear and present cyber threats, nor whether there are business prudent practices that can be implemented to counter those threats; but rather that there is such a diverse compendium, at times conflicting and often technically obtuse guidance, that clarity is needed to narrow the focus of this guidance to assist those responsible for implementing effective process control Security. The paper focuses on application of business-prudent controls and discusses how disparities in implementation of controls can exacerbate system vulnerabilities. Topics include issues of processes control system management, systems documentation, use of contractors and remote contractor access, system authorities that exceed user needs, misalignment of staff perception of information asset values, exposures related to use of USB ports, lack of encryption, and background surety gaps for individuals and contractor companies with access to process control systems. The paper examines the dynamics of communicating information from process control systems to business IT systems and the pressure from business operations to capture process data and make it available in near real-time through administrative networks. Such pressures may influence systems administrators to overlook or ignore firewall and systems engineering architecture, increasing potentials for two-way interface between business and process control that significantly increases exploit exposures. Despite the availability of excellent guidelines for physical and technical Security of IT related assets, these practices are too often unheeded in favor of expediency or expanded access. The paper includes a discussion of Risk Management Framework models that should be considered to enhance the correspondences and relationships between multiple organizational domains, thereby promoting more effective cyber Security for current and future process control systems. The paper summarizes the process for establishing Security for industrial control systems (ICS), and addresses cyber Security Baseline requirements and expectations, within a risk management framework that provides a decision basis, threat dynamics, common vulnerabilities, and prudent mitigation measures. Much of this summary has been derived from The Information Technology Laboratory at the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, Recommended Security Controls for Federal Information Systems and NIST SP 800-82, Guide to Industrial Control Systems (ICS) Security. NIST has also published Applying NIST SP 800-53 to Industrial Control Systems which demonstrates the relationship of 800-53 to ICS Security and the application of more than 20 control families and over 625 control elements to ICS Security. Although originally designed for Federal systems, portions of these publications also provide a solid foundation for critical commercial and industrial information control systems in terms of addressing the basic questions that companies in the process industry should consider when selecting Security controls, including: • What controls are actually needed to protect process systems, while supporting operations and safeguarding critical assets? • Can the selected controls suggested for Federal systems effectively be implemented for systems in the process industry? • Once selected and implemented, will these controls really be effective in protecting the processes? NIST SP 800-53, Recommended Security Controls for Federal Information Systems, helps answer questions to strengthen commercial processes information Security programs. The Security controls articulated in NIST SP 800-53 provide guidance and recommend practices applicable to Security systems in process industries, to provide a foundation for understanding the fundamental concepts of Security controls. The introductory material presents the concept of Security controls and their use within well-defined information Security programs. Some of the issues discussed include the structural components of controls, how the controls are organized into families, and the use of controls to support information Security programs. The guide outlines the essential steps that should be followed to determine needed controls, to assure the effectiveness of controls, and to maintain the effectiveness of installed controls. The appendices in NIST SP 800-53 provide additional resources including general references, definitions, explanation of acronyms, a breakdown of Security controls for graduated levels of Security requirements, a catalog of Security controls, and information relating Security controls to other standards and control sets. The controls are organized into classes of operational, management, and technical controls, and then into families within each class. To maintain parity and applicability with advances in technology, NIST also plans to review and to update the controls in the catalog as technology changes and new safeguards and new information Security countermeasures are identified. NIST SP 800-53 and related documents are available at http://csrc.nist.gov/publications/nistpubs/index.html . The extensive reference list in SP 800-53 includes standards, guidelines, and recommendations that process industry companies can use as the foundation for comprehensive Security planning and lifecycle management processes. Additionally, a significant effort of broad commercial and government cooperation, the Consensus Audit Guideline (CAG) provides a 20-element cyber Security controls roster supporting a common commercial framework for cyber Security, correlating to the NIST 800-53 Control Library.
-
Identification and application of Security measures for petrochemical industrial control systems
Journal of Loss Prevention in the Process Industries, 2013Co-Authors: H. M. Leith, John W. PiperAbstract:The financial success of the chemical and petrochemical industry will increasingly depend upon the Security of process control systems. This paper presents recommendations and insights gleaned from over 100 Security risk assessment (SRA) and process control analyses, using requirements Baselines extracted from the National Institute of Standards and Technology (NIST) special publication 800-53 (and Appendix A), the Recommended Security Controls for Federal Information Systems and Organizations, in conjunction with NIST special publication 800-82, Guide to Industrial Control Systems(ICS) Security, to provide the bridge in application of 800-53 controls to IC/SCADA. The paper identifies how current and projected malevolent threats posed by insiders, outsiders, collusion, and system-induced threats can erode system performance in terms of shut downs, sabotage, production disruption, and contamination. The issue is not whether there are clear and present cyber threats, nor whether there are business prudent practices that can be implemented to counter those threats; but rather that there is such a diverse compendium, at times conflicting and often technically obtuse guidance, that clarity is needed to narrow the focus of this guidance to assist those responsible for implementing effective process control Security. The paper focuses on application of business-prudent controls and discusses how disparities in implementation of controls can exacerbate system vulnerabilities. Topics include issues of processes control system management, systems documentation, use of contractors and remote contractor access, system authorities that exceed user needs, misalignment of staff perception of information asset values, exposures related to use of USB ports, lack of encryption, and background surety gaps for individuals and contractor companies with access to process control systems. The paper examines the dynamics of communicating information from process control systems to business IT systems and the pressure from business operations to capture process data and make it available in near real-time through administrative networks. Such pressures may influence systems administrators to overlook or ignore firewall and systems engineering architecture, increasing potentials for two-way interface between business and process control that significantly increases exploit exposures. Despite the availability of excellent guidelines for physical and technical Security of IT related assets, these practices are too often unheeded in favor of expediency or expanded access. The paper includes a discussion of Risk Management Framework models that should be considered to enhance the correspondences and relationships between multiple organizational domains, thereby promoting more effective cyber Security for current and future process control systems. The paper summarizes the process for establishing Security for industrial control systems (ICS), and addresses cyber Security Baseline requirements and expectations, within a risk management framework that provides a decision basis, threat dynamics, common vulnerabilities, and prudent mitigation measures. Much of this summary has been derived from The Information Technology Laboratory at the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, Recommended Security Controls for Federal Information Systems and NIST SP 800-82, Guide to Industrial Control Systems (ICS) Security. NIST has also published Applying NIST SP 800-53 to Industrial Control Systems which demonstrates the relationship of 800-53 to ICS Security and the application of more than 20 control families and over 625 control elements to ICS Security. Although originally designed for Federal systems, portions of these publications also provide a solid foundation for critical commercial and industrial information control systems in terms of addressing the basic questions that companies in the process industry should consider when selecting Security controls, including: • What controls are actually needed to protect process systems, while supporting operations and safeguarding critical assets? • Can the selected controls suggested for Federal systems effectively be implemented for systems in the process industry? • Once selected and implemented, will these controls really be effective in protecting the processes? NIST SP 800-53, Recommended Security Controls for Federal Information Systems, helps answer questions to strengthen commercial processes information Security programs. The Security controls articulated in NIST SP 800-53 provide guidance and recommend practices applicable to Security systems in process industries, to provide a foundation for understanding the fundamental concepts of Security controls. The introductory material presents the concept of Security controls and their use within well-defined information Security programs. Some of the issues discussed include the structural components of controls, how the controls are organized into families, and the use of controls to support information Security programs. The guide outlines the essential steps that should be followed to determine needed controls, to assure the effectiveness of controls, and to maintain the effectiveness of installed controls. The appendices in NIST SP 800-53 provide additional resources including general references, definitions, explanation of acronyms, a breakdown of Security controls for graduated levels of Security requirements, a catalog of Security controls, and information relating Security controls to other standards and control sets. The controls are organized into classes of operational, management, and technical controls, and then into families within each class. To maintain parity and applicability with advances in technology, NIST also plans to review and to update the controls in the catalog as technology changes and new safeguards and new information Security countermeasures are identified. NIST SP 800-53 and related documents are available at http://csrc.nist.gov/publications/nistpubs/index.html. The extensive reference list in SP 800-53 includes standards, guidelines, and recommendations that process industry companies can use as the foundation for comprehensive Security planning and lifecycle management processes. Additionally, a significant effort of broad commercial and government cooperation, the Consensus Audit Guideline (CAG) provides a 20-element cyber Security controls roster supporting a common commercial framework for cyber Security, correlating to the NIST 800-53 Control Library. © 2013 Elsevier Ltd.
Qinghua Li - One of the best experts on this subject based on the ideXlab platform.
-
An Overview of Cyber-Physical Security of Battery Management Systems and Adoption of Blockchain Technology
IEEE Journal of Emerging and Selected Topics in Power Electronics, 1Co-Authors: Justin Ochoa, Tasnimun Faika, Jia Di, Alan Mantooth, Qinghua LiAbstract:Lithium-ion (Li-ion) batteries are a key energy storage component in various electrical and electronic systems such as mobile phones and electric vehicles. A properly designed battery management system (BMS) is crucial to guarantee the safety, reliability, and optimal performance of the battery as well as to interconnect the battery systems with each other and external systems through communication channels. However, Security threats of the Li-ion battery systems are often overlooked by BMS developers in the design phase. The cyberSecurity of BMSs is an essential factor to consider as more battery systems require internet connectivity for functionality such as intelligent monitoring, control, and maintenance. This paper discusses overall Security vulnerabilities from potential cyber-attacks and defense strategies as well as adoption of current blockchain technology in BMSs, which will be used as a cyber Security Baseline reference to BMS developers. The implementation of blockchain technology is promising to protect BMSs from malicious cyber-physical attacks and ensure the secure utilization of battery systems for numerous applications in cyber-physical environments.