Increasing volatilities within power transmission and distribution force power grid operators to amplify their use of communication infrastructure to monitor and control their grid. The resulting increase in communication creates a larger attack surface for malicious actors. Indeed, cyber attacks on power grids have already succeeded in causing temporary, large-scale blackouts in the recent past. In this paper, we analyze the communication infrastructure of power grids to derive resulting fundamental challenges of power grids with respect to cybersecurity. Based on these challenges, we identify a broad set of resulting attack vectors and attack scenarios that threaten the security of power grids. To address these challenges, we propose to rely on a defense-in-depth strategy, which encompasses measures for (i) device and application security, (ii) network security, and (iii) physical security, as well as (iv) policies, procedures, and awareness. For each of these categories, we distill and discuss a comprehensive set of state-of-the art approaches, as well as identify further opportunities to strengthen cybersecurity in interconnected power grids.
The fundamental changes in power supply and increasing decentralization require more active grid operation and an increased integration of ICT at all power system actors. This trend raises complexity and increasingly leads to interactions between primary grid operation and ICT as well as different power system actors. For example, virtual power plants control various assets in the distribution grid via ICT to jointly market existing flexibilities. Failures of ICT or targeted attacks can thus have serious effects on security of supply and system stability. This paper presents a holistic approach to providing methods specifically for actors in the power system for prevention, detection, and reaction to ICT attacks and failures. The focus of our measures are solutions for ICT monitoring, systems for the detection of ICT attacks and intrusions in the process network, and the provision of actionable guidelines as well as a practice environment for the response to potential ICT security incidents.
In a previous article [1] we proposed a layered framework to support the assessment of the security risks associated with the use of autonomous vehicles in military operations and determine how to manage these risks appropriately. We established consistent terminology and defined the problem space, while exploring the first layer of the framework, namely risks from the mission assurance perspective. In this paper, we develop the second layer of the framework. This layer focuses on the risk assessment of the vehicles themselves and on producing a highlevel security design adequate for the mission defined in the first layer. To support this process, we also define a reference model for autonomous vehicles to use as a common basis for the assessment of risks and the design of the security controls.
Unmanned vehicles with varying degrees of autonomy have the potential to deliver substantial operational value across an array of NATO missions, but with new possibilities come new security risks. Before these vehicles can be trusted to properly support a mission, such risks must be identified, assessed, and managed accordingly. However, as the range of the potential applications and capabilities of these vehicles is so vast, and the technology still not mature, it is important to lay a common foundation to derive consistent guidelines and achieve interoperable and effective security capabilities across NATO. This paper summarises preliminary results on common high-level security requirements based on a structured risk assessment of available missions and vehicles. This also includes the development of risk and security models tailored for unmanned and autonomous vehicles that can be refined and extended as new operational concepts and technological applications appear.
Malicious software poses a great risk to critical infrastructure. Researchers have proposed numerous ways to analyze malware behavior in order to understand and respond to this threat. However, only little attention has been paid to the organization of the malware analysis process itself. In this paper we present the Malware Analysis and Storage System (MASS), a novel framework for malware analysis. MASS is designed as a distributed and scalable system and aims to empower cooperation between malware researchers. We will describe the central aspects of the framework and explain the malware analysis process flow. Furthermore, we will present a performance evaluation to demonstrate the suitability of the framework for typical malware analysis tasks.
It is known that the accumulated contact data of all stations of multistatic sonar arrays cannot be handled by traditional VHF links. While other technologies like satellite communication systems could handle the amount of data, these systems are usually too costly in terms of money, weight, or power consumption to be deployed on sonar buoys. Therefore, we installed commercial off-the-shelf WLAN with 4W boosters on a vessel and buoys and measured the achievable communication ranges and data rates during a sea trial. With our experiments we were able to reach ranges of 10km and beyond. Afterwards we derived functions and parameters from our measured data to help predicting the WLAN performance for similar scenarios.
Routing in MANETs still is a challenging task. Especially for proactive protocols where nodes periodically send control messages, a vast amount of the available data rate is used for link detection and the dissemination of topology information. Numerous enhancements to existing routing protocols to reduce the overhead caused by control messages have been proposed. Most of them use complex algorithms or keep track of previous messages. Due to the complexity and sometimes requirements for special hardware or information sources, none of these extensions are widely used. Therefore, we propose two extensions which are simple to implement yet provide significant overhead reduction for typical control messages. The first extension removes unnecessary bytes and redundancy from control messages. The second extension introduces smaller messages sent as replacements when the information did not change since the last message. Both extensions can be used in parallel or individually, providing a good amount of overhead reduction while being simple to implement and integrate.
One of the primary application scenarios for mobile wireless multi-hop networks are disaster areas. However, these pose specific challenges for routing, such as mobility and highly unpredictable links. The main applications for disaster area networks - group-based voice communication and group-oriented, map-based tracking - can be realized using multicast groups. Thus, we decided to implement ODMRP for disaster area deployments. In several disaster area maneuver on-site deployments, we identified the need for extensions, making the protocol more suitable for real-world deployments. In this paper, we propose three extensions to ODMRP: (1) link quality based routing, (2) prioritization of control messages, and (3) overhead reduction mechanisms. In simulations as well as in real-world measurements, we show the benefit of the extensions proposed.
In typical Mobile Ad-Hoc Network (MANET) applications, the network topology changes frequently due to device movement, or link failure. Consequently, a fast response to connectivity changes is one of the most important challenges in MANETs. Most proactive routing protocols detect changes by exchanging control messages. The Neighborhood Discovery Protocol (NHDP) specifies the exchange of these kind of messages. As shown in prior studies, the proposed fixed intervals of NHDP cause unnecessary protocol overhead or late link detection. Our Adaptive HELLO (AH) scheme adapts the interval dynamically with respect to the actual situation and coordinates it between the nodes when necessary. The result is a fast link change detection and an overhead reduction in certain scenarios.
Wireless multi-hop networks meet the requirements of disaster area scenarios by their definition. Recently, different mesh and Wireless Sensor Network (WSN) testbeds were deployed. However, these deployments do not meet the specific characteristics of disaster area scenarios. Developing algorithms and protocols for public safety scenarios and deploying public safety networks is a huge challenge. We have developed BonnSens a commercial off-the-shelf (COTS)-based prototype of a mesh-based command and control sensing system for public safety scenarios. In this poster, we present experiences as well as first measurement results from an on-site deployment in a disaster area maneuver. Overall, our goal is to see which approaches are applicable for public safety networks and where further specific challenges are.
Public safety organizations need robust communication networks to transmit different kind of sensor information. These networks must be reliable even when all infrastructure has been destroyed. Wireless multi-hop networks (such as Mobile Ad-Hoc Networks (MANETs), Wireless Sensor Networks (WSNs), and Wireless Mesh Networks (WMNs)) are supposed to meet the requirements of (1) spontaneous deployment, (2) being independent of any kind of existing infrastructure, and (3) robustness in the sense of self-organization and self-healing by their very definition. These networks have been a topic in research for more than a decade now. Recently, real-world tests and deployments provide valuable insights concerning challenges and future research directions. There are different mesh and WSN testbeds (e.g., [4, 9, 10]) enabling the research community to run tests in static real-world networks. However, concerning public safety requirements, there are significant differences: (1) No spontaneous deployment, (2) no or at least no mobility typical for public safety, (3) no typical applications and traffic for public safety scenarios. Due to these characteristics, developing algorithms and protocols for public safety scenarios and deploying public safety networks is a huge challenge. To overcome this challenge, we developed a prototype based on commercial off-the-shelf (COTS) hardware. The prototype comprises typical public safety application and is spontaneously deployable. Furthermore, this prototype enables us to perform evaluations with real public safety endusers, e.g. by deploying the prototype in maneuvers. In our demo, we will demonstrate our COTS-based prototype.
Underwater networks have attracted significant attention over the last few years. They can be used in scenarios like environmental monitoring and mine countermeasure but may also be part of modern marine warfare. A prominent example is Anti Submarine Warfare (ASW) with multistatic sonars. These networks may be sparse with potentially long distances between single nodes such that direct communication is not always possible. Furthermore, long propagation delays and shadowzones have a negative impact on the communication channel. A solution to overcome these challenges is to realize a multi-hop network by using ad-hoc routing. A well known protocol from terrestrial networks is the On-Demand Multi-cast Routing-Protocol (ODMRP). In this paper, we present an optimization for ODMRP, named Route-Discovery-Suppression, to improve its performance for the deployment in underwater networks. We evaluate the performance through simulations in different scenarios and show its impact in comparison to other routing protocols.
For the simulative and emulative performance evaluation of tactical indoor communication systems modeling mobility is an important task. Typical assumptions are a uniformly distribution of destinations, shortest paths movement without obstacles, and randomly chosen speeds. These assumptions do not hold for tactical indoor scenarios. In this paper, we introduce a new rule-based indoor mobility model for tactical scenarios. We show that the realistic modeling has a great impact on the evaluation of routing protocols. Furthermore, we demonstrate that even complex movements can be represented by small rulesets.
Simulation and emulation are techniques frequently used for performance evaluation of wireless multi-hop networks. If the wireless devices are mobile, the movement patterns of these objects are found to have significant impact on the simulation and emulation results. This is quite obvious as the movements influence the topology of the network. In this paper we describe and present BonnMotion. BonnMotion is an open-source Java software which creates and analyzes mobility scenarios. It has been developed at the University of Bonn, Germany, where it serves as a tool for the investigation of mobile multi-hop network scenario characteristics. The scenarios can also be exported for the network simulators ns-2, GloMoSim/QualNet, COOJA, and MiXiM.