A new workshop paper will be published next month. This biology-inspired computer science work shows how data be can secretly hidden in a cyber-physical system. We exemplify two data hiding techniques for CPS using smart buildings.
S. Wendzel, W. Mazurczyk, G. Haas: Don’t You Touch My Nuts: Information Hiding In Cyber Physical Systems, in Proc. IEEE Security and Privacy Workshops (BioSTAR Workshop), IEEE, 2017 (in press).
Cyber Physical Systems (CPS) have raised serious security concerns and thus have been subjected to intensive security research lately. In particular, recent publications suggest that there is a potential to transfer hidden information through CPS environments. In comparison to these existing studies, we demonstrate that CPS cannot only be used to covertly transfer secret data but also to store secret data. Using an analogy to the biological concept of animal scatter hoarding behavior we show sow to perform CPS secret data storage in smart buildings.
Keywords: BACnet, Building Automation, Smart Building, IoT, CPS, Information Hiding, Steganography, Covert Channels
Video of the talk:
Steffen Wendzel: How to increase the security of smart buildings?,
Communications of the ACM, Vol. 59(5), pp. 47-49, ACM, 2016.
Steffen Wendzel, Wojciech Mazurczyk, Luca Caviglione, Michael Meier:
Hidden and Uncontrolled - On the Emergence of Network Steganography,
Information Security Solutions Europe (ISSE'14), in: Securing Electronic Business Processes, pp. 123-133, Brussels, Springer-Vieweg, 2014.
Steffen Wendzel, Sebastian Zander, Bernhard Fechner, Christian Herdin:
Pattern-Based Survey and Categorization of Network Covert Channel Techniques,
Computing Surveys (CSUR), Vol. 47(3), ACM, 2015.
Wojciech Mazurczyk, Steffen Wendzel, Sebastian Zander, Amir Houmansadr, Krzysztof Szczypiorski:
Information Hiding in Communication Networks: Fundamentals, Mechanisms, and Applications,
IEEE Series on Information and Communication Networks Security,
Wiley, 2016 (cf. Amazon.com).