Practical Considerations for Securely Deploying Mobility

Slides:



Advertisements
Similar presentations
Security Issues In Mobile IP
Advertisements

Secure Mobile IP Communication
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Transitioning to IPv6 April 15,2005 Presented By: Richard Moore PBS Enterprise Technology.
1 Mobile IP Myungchul Kim Tel:
IPv4 and IPv6 Mobility Support Using MPLS and MP-BGP draft-berzin-malis-mpls-mobility-00 Oleg Berzin, Andy Malis {oleg.berzin,
COM555: Mobile Technologies Location-Identifier Separation.
NISNet Winter School Finse Internet & Web Security Case Study 2: Mobile IPv6 security Dieter Gollmann Hamburg University of Technology
1 Securing Mobile Networks An Enabling Technology for National and International Security and Beyond.
MOBILITY SUPPORT IN IPv6
A Study of Mobile IP Kunal Ganguly Wichita State University CS843 – Distributed Computing.
1 Multi-Domained, Multi-Homed Mobile Networks Mobile Platform Internet (MPI) mailing.
Mobile IP.
Neah Bay Presentation. Introduction Western DataCom has been in business for 20+ years providing data communications security solutions to the US Government,
Mobile IP Performance Issues in Practice. Introduction What is Mobile IP? –Mobile IP is a technology that allows a "mobile node" (MN) to change its point.
Mobile IP: Introduction Reference: “Mobile networking through Mobile IP”; Perkins, C.E.; IEEE Internet Computing, Volume: 2 Issue: 1, Jan.- Feb. 1998;
Mobile IP Seamless connectivity for mobile computers.
Host Mobility for IP Networks CSCI 6704 Group Presentation presented by Ye Liang, ChongZhi Wang, XueHai Wang March 13, 2004.
Mobile IP, PMIP, FMC, and a little bit more
1 Mobile Networking As Applied to Any Mobile Network Including Aeronautical Internets Airborne Internet Collaboration Group meeting April 17, 2003 Will.
Re-thinking Security in Network Mobility Jukka Ylitalo Ericsson Research NomadicLab NDSS '05 Workshop - February 2.
IPv6 for Mobile and Wireless Internet Alper E. Yegin DoCoMo USA Labs IPv6 Forum Technical Directorate Member, IETF PANA Working Group Chairman.
Practical Considerations for Securely Deploying Mobility Will Ivancic NASA Glenn Research Center (216)
1 Mobile Networking Including Application to Aeronautical Internets ICNS Conference May 20, 2003 Will Ivancic –
Virtual Private Ad Hoc Networking Jeroen Hoebeke, Gerry Holderbeke, Ingrid Moerman, Bard Dhoedt and Piet Demeester 2006 July 15, 2009.
MOBILE IP GROUP NAME: CLUSTER SEMINAR PRESENTED BY : SEMINAR PRESENTED BY : SANTOSH THOMAS SANTOSH THOMAS STUDENT NO: STUDENT NO:
1 Route Optimization for Large Scale Network Mobility Assisted by BGP Feriel Mimoune, Farid Nait-Abdesselam, Tarik Taleb and Kazuo Hashimoto GLOBECOM 2007.
1 Presentation_ID © 1999, Cisco Systems, Inc. Cisco All-IP Mobile Wireless Network Reference Model Presentation_ID.
1 Mobile-IP Priority Home Agents for Aerospace and Military Applications Terry Bell, Will Ivancic, Dave Stewart, Dan Shell and Phil Paulsen.
Page 1 Unclassified _NB_Next Steps.ppt Phillip E. Paulsen Space Communications Office NASA Glenn Research Center (GRC) Cleveland, Ohio 6 November.
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
1 Securing Mobile and Wireless Networks Is It Possible?
Introduction to Mobile IPv6
MOBILITY Beyond Third Generation Cellular Feb
1 Securing Mobile Networks in an Operational Setting Will Ivancic (216)
Spring 2004 Mobile IP School of Electronics and Information Kyung Hee University Choong Seon HONG
Santhosh Rajathayalan ( ) Senthil Kumar Sevugan ( )
Ασύρματες και Κινητές Επικοινωνίες Ενότητα # 10: Mobile Network Layer: Mobile IP Διδάσκων: Βασίλειος Σύρης Τμήμα: Πληροφορικής.
1 © 1999, Cisco Systems, Inc. Mobile Router Technology Development Dan Shell - Cisco Will Ivancic - NASA Glenn.
1. Mobile Router Networks in Motion (tm) 2. Mobile Router Features Uses Internet standards-bases Mobile-IP technology - RFC 2002 Mobile Router allows.
Glenn Research Center Satellite Networks & Architectures Branch Communications Technology Division IEEE Aerospace Conference March Architecture.
Glenn Research Center Satellite Networks & Architectures Branch Communications Technology Division I-CNS Workshop April/May, Securing Mobile and.
1 Mobile Router Technology Development David Stewart, Will Ivancic, Dan Shell, Kent Leung, Brian Kachmar and Terry Bell.
COM594: Mobile Technologies Location-Identifier Separation.
Mobile IP THE 12 TH MEETING. Mobile IP  Incorporation of mobile users in the network.  Cellular system (e.g., GSM) started with mobility in mind. 
Mobile IP Security Konidala M. Divyan International Research Center for Information Security Network Security (ICE 615) Term Project – 2002 Autumn.
MOBILE IP & IP MICRO-MOBILITY SUPPORT Presented by Maheshwarnath Behary Assisted by Vishwanee Raghoonundun Koti Choudary MSc Computer Networks Middlesex.
Chapter 1: Explore the Network
Introduction Wireless devices offering IP connectivity
Mobile Networking (I) CS 395T - Mobile Computing and Wireless Networks
Multi-Domained, Multi-Homed Mobile Networks
Mobile IP and Upper Layer Interaction
Support for Flow bindings in MIPv6 and NEMO
Introduction to Wireless Networking
Mobility And IP Addressing
2002 IPv6 技術巡迴研討會 IPv6 Mobility
Managing Online Services
Network Virtualization
Mobile ad hoc networking: imperatives and challenges
Securing Mobile Networks
Lecture 45 Review of Lectures Dr. Ghalib A. Shah
Summary of the InternetCAR testbeds
Mobile Router Technology Development
Mobile IP Presented by Team : Pegasus Kishore Reddy Yerramreddy Jagannatha Pochimireddy Sampath k Bavipati Spandana Nalluri Vandana Goyal.
Mobility Support in Wireless LAN
Mobile IP Outline Homework #4 Solutions Intro to mobile IP Operation
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Lecture 4a Mobile IP 1.
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Presentation transcript:

Practical Considerations for Securely Deploying Mobility Will Ivancic NASA Glenn Research Center (216) 433-3494 wivancic@grc.nasa.gov

Network Design Triangle SYZYGY Engineering $$$ Cost $$$ Maturity Policy Protocols Architecture Scalability Mobility Security QoS Bandwidth 5 © 2004 Syzygy Engineering – Will Ivancic

Design Issues Host and/or Network Mobility Security Policy Scalability Corporate and/or Individual Scalability Handoff Speed Intranet or Internet Own and/or Shared Infrastructure May be an issue even within you own Organization Crossing Autonomous Systems Multi-Homing Multiple Radio Links Varying Multi-homed link characteristics (e.g WiFi, Satellite, GPRS, Low-Rate VHF)

Mobile Networking Solutions Routing Protocols  Route Optimization  Convergence Time  Sharing Infrastructure – who owns the network? Mobile-IP  Route Optimization  Convergence Time  Sharing Infrastructure  Security – Relatively Easy to Secure Domain Name Servers  Reliability

Mobility at What Layer? Layer-2 (Radio Link) Layer-3 (Network Layer) SYZYGY Engineering Layer-2 (Radio Link) Fast and Efficient Proven Technology within the same infrastructure Cellular Technology Handoffs WiFi handoffs Layer-3 (Network Layer) Slower Handover between varying networks Layer-3 IP address provides identity Security Issues Need to maintain address Layer-4 (Transport Layer) Research Area Identity not tied to layer-3 IP address Proposed Solutions HIP – Host Identity Protocol SCTP – Stream Control Transport Protocol © 2004 Syzygy Engineering – Will Ivancic

What is the Weather like in Cleveland? Location Identifier SYZYGY Engineering I am in Paris France HQ Keeps Track of Alice. Hello Bob, I am in Cleveland, Ohio I am in Cleveland, Ohio Alice (Mobile Node) Binding Updates Alice (Mobile Node) What is the Weather like in Cleveland? Registration Hello Alice Internet Where is Alice’s Location Manager? Bob (Corresponding Node) Headquarters (Location Manager) © 2004 Syzygy Engineering – Will Ivancic

IPv4 “Real World” Operation CN Proxy had not originated the request; therefore, the response is squelched. Peer-to-peer networking becomes problematic at best. Glenn Research Center Policy: No UDP, No IPSec, etc… Mobile-IP stopped in its tracks. What’s your policy? US Coast Guard Operational Network (Private Address Space) Public Internet P R O X y US Coast Guard Mobile Network HA USCG Requires 3DES encryption. WEP is not acceptable due to known deficiencies. Ingress or Egress Filtering stops Transmission due to topologically Incorrect source address. IPv6 Corrects this problem. FA MR

Current Solution – Reverse Tunneling CN Adds Overhead and kills route optimization. US Coast Guard Operational Network (Private Address Space) Public Internet P R O X y US Coast Guard Mobile Network HA NAT Must Run NAT Transversal Using UDP Tunnels FA Anticipate similar problems for IPv6. MR

Shared Network Infrastructure Public Internet FA MR US Coast Guard Canadian Coast Guard ACME Shipping HA ACME SHIPPING US Navy Encrypting wireless links makes it very difficult to share infrastructure. This is a policy issue.

x Basic Mobile Network Support for IPv6 Link UP Binding Update Nodes Binding Update Mobile Network Note, Mobile Network allows for single Binding Update. Other Mobility Solutions may Oversubscribe link during Binding updates. Link UP Access Router Access Router Internet or Intranet Bidirectional Tunnel Corresponding Node Home Agent

The Next (Current) Research / Deployment Area Mobile Security The Next (Current) Research / Deployment Area

Behind Router – Strategic SYZYGY Engineering Address Changes with Mobility Mobile Network IPE-2M Mobile Router HA-MR Tunnel Roaming Interface HA-FA Tunnel Address can Be Fixed Foreign Agent The Neah Bay is using the IPE in a strategic deployment which refers to the placement of the encryptors, in this case behind the routers. Internet Home Agent IPE-IPE Secure Tunnel IPE-2M Home Network Source – Western DataCom

In-Front of Router – Tactical SYZYGY Engineering In-Front of Router – Tactical Mobile Network Address Changes with Mobility Mobile Router IPE-2M Roaming Interface Secure WAN HA-MR Tunnel IPE-IPE Secure Tunnel The Army demonstration uses a tactical deployment which places the IPE in front of the routers. IPE-2M HA-FA Tunnel Foreign Agent Internet Home Agent Home Network Source – Western DataCom

Mobile IPSec ? Internet Address Changes with Mobility SYZYGY Engineering Mobile IPSec ? Address Changes with Mobility Intranet Mobile IPSec Device Internet Partially Being Addressed MOBIKE HIP Certificate Based Identity? Others? The Army demonstration uses a tactical deployment which places the IPE in front of the routers. Mobile IPSec Device Secure Tunnel Intranet © 2004 Syzygy Engineering – Will Ivancic

IPv6 Ad Hoc Networking Challenges SYZYGY Engineering Denial of Service Duplicate Address Detection (DAD) DoS, Uncooperative Router, etc… Neighbor Discovery trust and threats Network Discovery Reachback, DNS, Key Manager Security IPSec / HAIPES tunnel end-points Security Policies in a dynamic environment Is layer-2 encryption sufficient security? Insecure routing Attackers may inject erroneous routing information to divert network traffic, or make routing inefficient Key Management Lack of key distribution mechanism Hard to guarantee access to any particular node (e.g. obtain a secret key) © 2004 Syzygy Engineering – Will Ivancic

IPv6 Ad Hoc Networking Challenges SYZYGY Engineering Duplicate Address Discovery Not suitable for multi-hop ad hoc networks that have dynamic network topology Need to address situation where two MANET partitions merge Radio Technology Layer-2 media access often incompatible with layer-3 MANET routing protocol Battery exhaustion threat A malicious node may interact with a mobile node very often trying to drain the mobile node’s battery Testing of Applications Integrating MANET into the Internet © 2004 Syzygy Engineering – Will Ivancic