Research suggests medical devices are particularly vulnerable to wireless attacks- whether using conventional or non-conventional protocols. This study provides analysis and comparison of several selected medical devices that will model a functional wireless network, communicating between patient and host. Results enable the identification and detection of attack vectors or vulnerabilities in devices and categorically allow for placement into a model akin to the Purdue/TCP/IP models-focusing on Medical Internet of Things (MIoT). The interconnectivity of multiple devices lends itself to a variety of security issues, including man-in-the-middle attacks. Interception, jamming, and altering of traffic from embedded, wearable, and bedside devices. These have serious consequences regardless of initial intent- as human life and safety are at stake. This study will not only contribute to the advancement of medical device security, but also to improve patient safety, data privacy, and reliability of interconnected healthcare technologies and delivery.
The immediate goal of this work is to determine uses for different hardware reverse engineering tools, compare and contrast which tools correspond with desired tasks, and provide an outline to achieve hardware reverse engineering goals for students or entry level engineers. Hardware reverse engineering is the abstraction of information or design elements from physical components. In our research we will be using easily accessible and relatively inexpensive devices that can be broken down into individual components to provide a clearer understanding of how the different components in a system communicate with each other, and the data that flows between them. Currently, there are few resources available explaining the purpose of these tools. The paper's goal is to resolve this. The variety of tools and techniques is overwhelming and there is a lack of material and resources geared towards someone new to the field. The long-term goal of this research is to establish an introductory working manual utilizing the basic tools of hardware reverse engineering. The research and subsequent manual will be tested and designed for beginners. This research and manual will additionally provide the direction necessary to construct the early framework for standardized instructional material.
The development of unmanned vehicle technology is rapidly proceeding and will result in numerous advances in autonomous vehicles. Most of the research effort to date focuses on the safe and effective operation of these vehicles that will allow them to integrate into society. A research gap exists though in the technical, policy, and legal fields regarding illicit use of these vehicles beyond their programmed functions. In this paper we explore possible misuse of unmanned vehicles and illustrate the need for research in the technical, policy, and legal realms.
Summer immersive experiences provide students the opportunity to explore the limits of their engineering education and develop a depth in a field of study. For institutions that centrally manage these experiences, ranging from experiments conducted at other academic locations to research and development with industry partners, to procurement and development with government laboratories and program offices, it can be difficult to ensure that all participants are receiving quality experiences. A survey had previously been administered to capture the value of student's summer immersive experience based on ABET Student Outcomes. Much of the data proved inconclusive due to the structure of the questions. However the data was used as a baseline for follow on research and guided the development of future surveys.Following the summer of 2013, a new survey was administered to students majoring in aeronautical, electrical, and mechanical engineering at three different colleges who had participated in institution-sponsored immersive experiences. The goal of the survey was to determine why students chose their summer experiences, what made these experiences successful, and how to improve experiences in the future to maximize return on investment. Success was measured not just in whether they experienced the ABET Student Outcomes (a)-(k) but to what level they were challenged in those domains. The results of the survey will be used next summer to influence which experiences are offered and refine how students are paired with a summer experience.
In military doctrine, key terrain refers to areas which, if seized, afford an advantage to an attacker or defender. When applied to geographic terrain, this definition is clear. Key terrain might include a hill that overlooks a valley an enemy wants to control or a crossing point over a river that must be traversed before launching an attack. By definition, dominance of key terrain is likely to decide the overall outcome of a battle. While cyber key terrain is similar to geographic key terrain in some ways, there are also significant and often counterintuitive differences. Some consider cyber terrain to be tied to a physical location and to be represented in cyberspace by routers, switches, cables, and other devices. We will argue that key terrain in cyberspace exists at all of the cyberspace planes, which include the geographic, physical, logical, cyber persona, and supervisory planes [1]. In many cases, features of cyber terrain will not be tied to a specific location, or the geographic location will be irrelevant. In this paper we deconstruct and analyze cyber key terrain, provide a generalized framework for critical analysis, and draw parallels between cyber and physical key terrain while providing examples of key terrain in cyber operations. During a cyber operation, an analysis of key terrain will aid in the strategy and tactics of both the offense and the defense. During peacetime, an understanding of cyber key terrain can be employed broadly, ranging from helping a system administrator focus scarce resources to defend his network all the way to allowing nation-state militaries to develop long-lasting and effective doctrine.
As vehicular networks (a.k.a. VANETs) continue to mature, the benefits they promise come closer to reality. For this to happen, both security and privacy must be provided. Particularly in dense urban environments, novel methods of distributing the often changing identity (pseudonyms or PNs) of the vehicles is necessary in order to ensure vehicles have sufficient PNs. In this paper, we examine three methods of PN distribution through the use of ns-3 simulation. The specific measurements used are: (1) the average overall background data throughput, (2) average overall PNs distributed, (3) maximum number of PNs distributed, and (4) the distribution of the PNs across an array of vehicles in possession of varied numbers of PNs. We demonstrate that a strategy that intelligently limits to whom you distribute PNs in congested environments improves the overall data throughput and provides more PNs to those in need. This paper presents a method to implement this strategy.
Vehicular Networks (VANETs) continue to mature and their installation is becoming a reality. Meanwhile, simulation has become an indispensable tool for validating design and providing insight into how complex systems work. Yet the results of a simulation are only as good as the simulator's configuration. The network simulator 3 (ns-3) provides a host of propagation loss models, some of which are applicable to VANETs. In this work, we evaluate these models and then offer standard values for the propagation loss model parameters in an effort to normalize VANET simulation and provide researchers the ability to compare their work. The proposed values are then demonstrated to achieve the desired effective range as empirically determined in other work.
Vehicular networks are meant to exist wherever the road will take them. This includes small towns, rural highways, suburbs, downtown urban centers, and urban highways. The density of vehicles varies greatly across these environments. This work looks at the effects of implementing Quality of Service (QoS) as well as a relatively similar method that inserts stochastic delays in pseudonym (PN) transmission in the two urban settings of a downtown grid and an urban highway, both under heavily congested conditions. The simulated results (using ns-3) are compared to previous work that examined communication suppression (as opposed to priority as in this work). Four metrics are used for method comparison: average overall background data throughput, average overall PNs distributed, maximum number of PNs distributed, and the distribution of the PNs across the vehicles as a function of need. While some of the results obtained were expected, the overall conclusion that implementing quality of service, or even a simplistic imitation, can significantly improve the overall data throughput and provide more PNs is an interesting result.
This paper describes a novel idea for distributing certificate revocation lists (CRLs) in a vehicular ad hoc network (VANET) scenario. The idea, Most Pieces Broadcast (MPB), takes advantage of the two distinct channel types in VANETs while reducing contention for the wireless medium. Broadcast methods that reduce wireless medium contention in VANETs are highly desirable to assist in keeping the medium available for transmission of time-critical safety messages. MPB scales remarkably well using raptor coding to generate redundant file pieces.
In this paper, the primary objective is to discuss the details of scalable methods for distributing certificate revocation lists and other large files using vehicle-to-vehicle and vehicle-to-infrastructure communications while taking advantage of the multi-channel operations in IEEE 1609.4. We also discuss the results from a simulation study using the ns-3 network simulator to closely replicate the WAVE environment discussed in the IEEE 802.11p and 1609 draft standards. Realistic vehicle traces were used in the simulation study. The results show that the methods developed in this research scale very well for increasing vehicle densities.
The objective of this research is to investigate improved methods for distributing certificate revocation lists (CRLs) in vehicular ad hoc networks (VANETs). VANETs are a subset of mobile ad hoc networks composed of network-equipped vehicles and infrastructure points, which will allow vehicles to communicate with other vehicles and with roadside infrastructure points. While sharing some of the same limitations of mobile ad hoc networks, such as lack of infrastructure and limited communications range, VANETs have several dissimilarities that make them a much different research area. The main differences include the size of the network, the speed of the vehicles, and the network security concerns. Confidentiality, authenticity, integrity, and availability are some of the standard goals of network security. While confidentiality and authenticity at times seem in opposition to each other, VANET researchers have developed many methods for enhancing confidentiality while at the same time providing authenticity. The method agreed upon for confidentiality and authenticity by most researchers and the IEEE 1609 working group is a public key infrastructure (PKI) system. An important part of any PKI system is the revocation of certificates. The revocation process, as well as the distribution of revocation information, is an open research problem for VANETs. This research develops new methods of CRL distribution and compares them to existing methods proposed by other researchers. The new methods show improved performance in various vehicle traffic densities.
VANETs continue to mature and their installation is becoming a reality. Many ideas have been exchanged on how best to balance privacy and security. The use of pseudonyms has been almost universally accepted as a critical part of this equation. Simulated results, using ns-3, demonstrate the need for more than a single road side unit (RSU) contact for pseudonym refill due to the limited number of certificates that can be issued in that transit. This paper provides a universal protocol using multiple RSUs and multiple service channels for the distribution of pseudonyms for refill, intra-regional, and inter-regional purposes.
This paper discusses two new methods for distributing certificate revocation lists (CRL) in a vehicular ad hoc network environment using cooperative methods. The main purpose for using cooperative methods is to attempt to reduce the number of collisions in the dedicated short range communication (DSRC) broadcast environment. The reduced number of collisions will increase the effective throughput of the medium. The first method uses a polling scheme to determine which nodes possess the most number of CRL file pieces. The second method takes advantage of the multiple service channels available in DSRC. Both methods use a form of coding that reduces the impact of the piece problem. Both methods are compared to the Code Torrent method of file distribution.
Concerns for VANET participants will be the reliability and trustworthiness of received messages and the privacy in the use of the VANET to prevent vehicle tracking. To address these concerns, public key certificates have been standardized for VANETS; however, with the use of public key certificates comes additional concerns, especially how to ensure that received certificates are valid. To achieve this aim, timely distribution of certificate revocation lists (CRLs) to VANET participants will be essential. Depending on the policies for the number of pseudonyms carried by vehicles and the triggers for revoking certificates, the size of the CRL may grow very quickly. This paper investigates the parameters that determine the sizes of CRLs in an attempt to quantify the scope of CRL distribution challenges. We also propose adding a "valid after" field to the WAVE Certificate in the IEEE Trial-Use Standard 1609.2 to reduce some of the large CRL sizes we discovered.
Vehicular ad hoc networks (VANETs) provide the means to add convenience, services, and safety to the road. This paper introduces a means to adapt the concepts of Public Key Infrastructure for a VANET environment under the worst case scenario of a pseudonym shift every second. Regions are used to scale down the size of certificate revocation lists (CRLs), administrative overhead, and the search space to link a message to its originator. Regions also provide a means for expansion of the geographical area covered and provides the ability to balance geographic mobility with privacy. The framework outlined below can then be modified to the decided pseudonym shift frequency and/or extended for other purposes.
Each June approximately 1200 new cadets (NCs) are welcomed to the United States Military Academy (USMA) during Reception Day (R-Day). Amid the mass shuffling of bodies and the yelling of the upper-class cadet cadre, all 1200 NCs must completely in process. Changes are made to the in processing system in attempt to make it more efficient. However, the effect of these changes can only be gauged once a year during the following R-Day. In an attempt to expedite the refinement process, the R-Day administrators approached our design team to create a simulation model that could be used to analyze the effect of proposed changes to the system prior to R-Day 2002. Using ProModel® simulation software, our team created a simulation of the in processing system and conducted a statistical analysis of the results in order to recommend improvements to the structure of the system.