IEEE 802.1 Time-sensitive Networking~(TSN) standards are envisioned to replace legacy network protocols in critical domains to ensure reliable and deterministic communication over off-the-shelf Ethernet equipment. However, they lack security countermeasures and can even impose new attack vectors that may lead to hazardous consequences. This paper presents the first open-source security monitoring and intrusion detection mechanism, TSNZeek, for IEEE 802.1 TSN protocols. We extend an existing monitoring tool, Zeek, with a new packet parsing grammar to process TSN data traffic and a rule-based attack detection engine for TSN-specific threats. We also discuss various security-related configuration and design aspects for IEEE 802.1 TSN monitoring. Our experiments show that TSNZeek causes only ~5% CPU overhead on top of Zeek and successfully detects various threats in a real TSN testbed.
翻译:IEEE 802.1 Time-sensitive Networking (TSN)标准被设想用于取代关键领域中的传统网络协议,以确保在现成的以太网设备上进行可靠和确定性通信。然而,它们缺乏安全对策,甚至可能带来新的攻击向量,从而导致危险后果。本文提出了第一个用于IEEE 802.1 TSN协议的开源安全监控和入侵检测机制TSNZeek。我们扩展了现有的监控工具Zeek,采用新的数据包解析语法来处理TSN数据流量,采用基于规则的攻击检测引擎来监测TSN特有的威胁。同时,我们还讨论了与IEEE 802.1 TSN监测相关的各种安全配置和设计方面的问题。我们的实验证明TSNZeek在Zeek的基础上只引起了约5%的CPU负载,并成功检测出了真实TSN测试平台上的各种威胁。