بنية الثقة الصفرية المرنة لأمن السيبراني للبنى التحتية لإنترنت الأشياء الصناعية
Flexible zero trust architecture for the cybersecurity of industrial IoT infrastructures

المجلة: Ad Hoc Networks، المجلد: 156
DOI: https://doi.org/10.1016/j.adhoc.2024.103414
تاريخ النشر: 2024-02-07
المؤلف: Claudio Zanasi وآخرون
الموضوع الرئيسي: الشبكات المعرفة بالبرمجيات و5G

نظرة عامة

تقدم البحث بنية أمنية جديدة مصممة لإدارة أنظمة الإنترنت الصناعي للأشياء (IIoT) بشكل آمن وسط التحديات التي تطرحها الرقمنة واعتماد تكنولوجيا السحابة. الحلول الحالية للأمن السيبراني غير كافية للطبيعة المتنوعة لأجهزة IIoT، التي تتطلب عمليات حقيقية صارمة، وموثوقية عالية، واتخاذ قرارات لامركزية. تستخدم البنية المقترحة تقسيم الشبكة إلى ميكرو وتدمج شبكة معرفة بالبرمجيات (SDN) لتطبيق السياسات الموحدة، إلى جانب طبقة إدارة أمنية مركزية تبسط تنفيذ السياسات عبر بيئات متنوعة. يظهر نموذج أولي أن هذه البنية، التي تتميز بشبكة SDN من نظير إلى نظير وعملية توزيع سياسات غير متزامنة، تضمن المرونة ضد الفشل الفردي بينما تسهل العمليات اللامركزية والإدارة المركزية لطوبولوجيا الشبكة وسياسات الأمان.

في الختام، تنفذ البنية إطار عمل Zero Trust للتقسيم الدقيق مصمم خصيصًا للأنظمة الصناعية، وقابل للتكيف مع بيئات السحابة المتعددة والسحابة الهجينة. باستخدام حل Nebula SDN، يقوم بأتمتة إنشاء وتوزيع تكوينات الموارد والشهادات الرقمية، مما يضمن اتصالات آمنة داخل الشبكة. تدعم البنية أنظمة تشغيل وتكوينات أجهزة متنوعة، مما يسمح بالتكامل السلس لمختلف الأجهزة. ستتضمن التحسينات المستقبلية محرك تحليلي يستخدم الذكاء الاصطناعي لاكتشاف الأنشطة الضارة، مما يحسن من وضع الأمان والمرونة ضد التهديدات. تشير هذه المقاربة إلى حل شامل لتأمين البنى التحتية الحديثة، بما في ذلك أنظمة IIoT ومنصات السحابة، مع الالتزام بمبادئ الأمن السيبراني Zero Trust.

مقدمة

تسلط مقدمة هذه الورقة البحثية الضوء على التأثير التحويلي للأنظمة السيبرانية الفيزيائية والحوسبة السحابية على البيئات الصناعية، مع التأكيد على عدم كفاية التدابير الأمنية التقليدية مثل الشبكات الخاصة الافتراضية (VPNs) في مواجهة التهديدات السيبرانية المتطورة. يتم تقديم ظهور نموذج الأمان Zero Trust كتحول ضروري في النموذج، حيث لا يُعتبر أي مكون داخل الشبكة موثوقًا به بشكل ضمني، مما يتطلب التعرف المستمر وتفويض جميع التفاعلات. يتم اعتماد هذا النموذج بشكل متزايد عبر مختلف القطاعات، مما يعكس نهجًا استباقيًا للأمن السيبراني.

لمعالجة تعقيدات إدارة السياسات الأمنية الديناميكية في هذا المشهد الجديد، يقترح المؤلفون دمج التقسيم الدقيق مع الشبكات المعرفة بالبرمجيات (SDN). يسمح هذا النهج بإجراء تعديلات في الوقت الحقيقي على تكوينات الشبكة بناءً على السياسات وسلوك المستخدم، مما يعزز الأمان بينما يدير تحديات قابلية الوصول إلى العقد وإدارة الشبكة المضافة. توضح الورقة ثلاث مساهمات رئيسية: بنية Zero Trust جديدة مصممة للبيئات الصناعية المتنوعة، واستراتيجية إدارة الشبكة لتبسيط التقسيم الدقيق، ونموذج أولي للتحقق من الحلول المقترحة. ستتناول الأقسام التالية من الورقة الأعمال ذات الصلة، وتفاصيل البنية، والنتائج التجريبية، والاعتبارات المستقبلية.

النتائج

تظهر النتائج التجريبية جدوى وكفاءة الحل المقترح القائم على SDN، خاصة في البيئات ذات الموارد المحدودة. تم استخدام منصة الاختبار، التي تتكون من جهازين افتراضيين واثنين من مجموعات Kubernetes، لتقييم أداء خادم ويب يدير طلبات HTTP GET تحت أحمال عمل عملاء متغيرة، تتراوح من 50 إلى 300 عميل. من الجدير بالذكر أن خادم الويب، حتى مع موارد محدودة (1 جيجابايت RAM و1 vCPU)، تعامل بفعالية مع أكثر من 50 اتصالًا متزامنًا، مع بقاء الحمل الزائد الناتج عن بنية Nebula ضئيلًا. تم تحسين وقت الاستجابة ومعدلات الفشل بشكل كبير عند استخدام شبكة Nebula المضافة مقارنة ببنية أساسية، وذلك بفضل مزايا البنية الموزعة ووضع تشغيل TCP-over-UDP.

تقتصر قابلية توسيع الحل المقترح بشكل أساسي على طبقة الإدارة، وخاصة خدمة التكوين، التي تحافظ على الحالة العالمية للشبكة. ومع ذلك، يمكن توسيع كل من خدمة NEST وسلطة الشهادات بشكل مستقل بسبب طبيعتها غير الحالة، مما يسمح بمعالجة متوازية للطلبات. تم تصميم البنية للتعامل بكفاءة مع أحجام كبيرة من الطلبات الواردة، مع التركيز على الحفاظ على اتساق البيانات عبر النسخ. يعزز استخدام علامات الأمان لتعريف السياسات من قابلية الإدارة ويقلل من تكرار تغييرات السياسات، مما يجعل النظام أكثر تكيفًا مع تعديلات طوبولوجيا الشبكة. بشكل عام، تؤكد النتائج على التطبيق العملي لحل Nebula في البيئات الصناعية والإنترنت للأشياء في العالم الحقيقي، مما يظهر قوته وقابلية توسيعه مقارنة بالنهج التقليدية المركزية لـ SDN.

المناقشة

في هذا القسم، يناقش المؤلفون تنفيذ بنية Zero Trust (ZTA) مصممة خصيصًا لأنظمة الإنترنت الصناعي للأشياء (IIoT)، مع التأكيد على أهمية التقسيم الدقيق في تعزيز الأمان. ينتقدون الأطر النظرية الحالية التي تتجاهل التحديات العملية في نشر التقسيم الدقيق، خاصة في البيئات الديناميكية مثل 5G-IoT. تدمج الحل المقترح الخدمات الصغيرة مع شبكة معرفة بالبرمجيات (SDN) ونظام إدارة مركزي، مما يعالج قضايا القابلية للتوسع والأمان بينما يقلل من المخاطر المرتبطة بالتحكم المركزي، مثل نقاط الفشل الفردية. تعزز البنية نهجًا لامركزيًا لتطبيق السياسات، مما يسمح للموارد الفردية بإدارة الأمان بشكل مستقل، مما يعزز المرونة ويقلل من سطح الهجوم.

يبرز المؤلفون ضرورة تصميم مركزي للموارد ولامركزي، وهو أمر حاسم للحفاظ على استمرارية العمليات في الأنظمة الصناعية الآلية. يقترحون نموذجًا هجينًا يوازن بين فوائد الإدارة المركزية وقابلية توسيع وحدات التحكم الموزعة. يستفيد هذا النموذج من الشهادات الرقمية للمصادقة المتبادلة والتشفير من النهاية إلى النهاية، مما يضمن اتصالات آمنة بين الموارد. تشمل تفاصيل التنفيذ نموذجًا أوليًا يعتمد على Nebula SDN، الذي يسهل الاتصالات المشفرة ويبسط إدارة السياسات من خلال نظام إدارة التكوين وخدمة توزيع الشهادات. تُظهر بنية منصة الاختبار، التي تم نشرها على Microsoft Azure والأجهزة الشخصية، جدوى البنية المقترحة مع الحفاظ على الحد الأدنى من الحمل الزائد، مما يبرز عمليتها للتطبيقات في العالم الحقيقي.

Journal: Ad Hoc Networks, Volume: 156
DOI: https://doi.org/10.1016/j.adhoc.2024.103414
Publication Date: 2024-02-07
Author(s): Claudio Zanasi et al.
Primary Topic: Software-Defined Networks and 5G

Overview

The research presents a novel security architecture tailored for the secure management of Industrial Internet of Things (IIoT) systems amidst the challenges posed by digitalization and cloud technology adoption. Existing cybersecurity solutions are inadequate for the heterogeneous nature of IIoT devices, which require hard real-time operations, high reliability, and decentralized decision-making. The proposed architecture employs network micro-segmentation and integrates a software-defined network (SDN) for unified policy enforcement, alongside a centralized security management layer that simplifies policy execution across diverse environments. A prototype demonstrates that this architecture, featuring a peer-to-peer SDN and an asynchronous policy distribution process, ensures resilience against individual failures while facilitating decentralized operations and centralized management of network topology and security policies.

In conclusion, the architecture implements a micro-segmentation Zero Trust framework specifically designed for industrial systems, adaptable to multi-cloud and hybrid-cloud environments. Utilizing the Nebula SDN solution, it automates the generation and distribution of resource configurations and digital certificates, ensuring secure communication within the network. The architecture supports diverse operating systems and hardware configurations, allowing seamless integration of various devices. Future enhancements will include an analytical engine leveraging artificial intelligence to detect malicious activities, thereby improving the security posture and resilience against threats. This approach signifies a comprehensive solution for securing modern infrastructures, including IIoT systems and cloud platforms, while adhering to Zero Trust cybersecurity principles.

Introduction

The introduction of this research paper highlights the transformative impact of cyber-physical systems and cloud computing on industrial environments, emphasizing the inadequacy of traditional security measures like Virtual Private Networks (VPNs) in the face of evolving cyber threats. The emergence of the Zero Trust security model is presented as a necessary paradigm shift, where no component within the network is implicitly trusted, necessitating continuous identification and authorization of all interactions. This model is increasingly adopted across various sectors, reflecting a proactive approach to cybersecurity.

To address the complexities of managing dynamic security policies in this new landscape, the authors propose an integration of micro-segmentation with Software Defined Networking (SDN). This approach allows for real-time modifications to network configurations based on policies and user behavior, enhancing security while managing the challenges of node reachability and overlay network administration. The paper outlines three main contributions: a novel Zero Trust Architecture tailored for heterogeneous industrial settings, a network management strategy to streamline micro-segmentation, and a prototype validation of the proposed solutions. The subsequent sections of the paper will delve into related works, the architecture details, experimental results, and future considerations.

Results

The experimental results demonstrate the feasibility and efficiency of the proposed SDN-based solution, particularly in resource-constrained environments. The testbed, comprising two virtual machines and two Kubernetes clusters, was utilized to evaluate the performance of a Web server managing HTTP GET requests under varying client loads, ranging from 50 to 300 clients. Notably, the Web server, even with minimal resources (1 GB RAM and 1 vCPU), effectively handled over 50 concurrent connections, with the overhead introduced by the Nebula architecture remaining minimal. The response time and failure rates were significantly improved when using the Nebula overlay network compared to a baseline architecture, attributed to the advantages of a distributed architecture and the TCP-over-UDP operation mode.

The scalability of the proposed solution is primarily limited by the management layer, particularly the Configuration Service, which maintains the global state of the network. However, both the NEST Service and the certificate authority can be independently scaled due to their stateless nature, allowing for parallel processing of requests. The architecture is designed to handle high volumes of incoming requests efficiently, with a focus on maintaining data consistency across replicas. The use of security tags for policy definitions enhances manageability and minimizes the frequency of policy changes, making the system more adaptable to network topology modifications. Overall, the results affirm the practical applicability of the Nebula solution in real-world industrial and IoT environments, showcasing its robustness and scalability compared to traditional centralized SDN approaches.

Discussion

In this section, the authors discuss the implementation of a Zero Trust Architecture (ZTA) tailored for Industrial Internet of Things (IIoT) systems, emphasizing the importance of micro-segmentation in enhancing security. They critique existing theoretical frameworks that overlook practical challenges in deploying micro-segmentation, particularly in dynamic environments like 5G-IoT. The proposed solution integrates micro-services with a software-defined network (SDN) and a centralized management system, addressing scalability and security issues while mitigating risks associated with centralized control, such as single points of failure. The architecture promotes a decentralized approach to policy enforcement, allowing individual resources to manage security autonomously, thereby enhancing resilience and reducing the attack surface.

The authors highlight the necessity of a resource-centric and decentralized design, which is crucial for maintaining operational continuity in automated industrial systems. They propose a hybrid model that balances the benefits of centralized management with the scalability of distributed controllers. This model leverages digital certificates for mutual authentication and end-to-end encryption, ensuring secure communication between resources. The implementation details include a prototype based on the Nebula SDN, which facilitates encrypted communication and simplifies policy management through a configuration management system and a certificate distribution service. The testbed infrastructure, deployed on Microsoft Azure and personal devices, demonstrates the feasibility of the proposed architecture while maintaining minimal overhead, thus underscoring its practicality for real-world applications.