13.09.2014 Views

Local Area Networks (LANs) in Aircraft - FTP Directory Listing - FAA

Local Area Networks (LANs) in Aircraft - FTP Directory Listing - FAA

Local Area Networks (LANs) in Aircraft - FTP Directory Listing - FAA

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

design decisions that need to be determ<strong>in</strong>ed if encapsulation gateways are to effectively support<br />

VPN network management.<br />

This study has stated that high-assurance devices cannot be misconfigured. For this reason,<br />

devices <strong>in</strong> Levels A and B VPNs may have comparatively dim<strong>in</strong>ished management requirements<br />

than other airborne devices. The stakeholders need to determ<strong>in</strong>e what that actually means. Does<br />

it mean that the primary management requirement of these devices will be to report their current<br />

status, explicitly <strong>in</strong>clud<strong>in</strong>g the results of the current (Tripwire-like) software <strong>in</strong>tegrity reports?<br />

Will different variants of encapsulation gateways be def<strong>in</strong>ed, with some variants support<strong>in</strong>g<br />

extensive configuration and management functions (e.g., for lower-software assurance VPNs)<br />

and others primarily support<strong>in</strong>g status reports (for higher-assurance VPNs)? Will the<br />

encapsulat<strong>in</strong>g gateways solely function to forward (pass through) traditional SNMP management<br />

communications between network managers and management agents that reside on the devices<br />

with<strong>in</strong> the VPNs? Alternatively, will the management agent actually be located with<strong>in</strong> the<br />

encapsulat<strong>in</strong>g gateway itself such that the agent with<strong>in</strong> the gateway translates SNMP<br />

communications to and from standard network managers <strong>in</strong>to actual management tasks<br />

performed upon the devices located with<strong>in</strong> the VPN that it supports? Many other management<br />

approaches are possible, but it is desirable to f<strong>in</strong>d a consistent approach that is supported by the<br />

aeronautical community <strong>in</strong> which the <strong>in</strong>terfaces and management schemas supported by the VPN<br />

encapsulation gateways are common and consistent worldwide.<br />

From a security perspective, it is important that the encapsulation gateway be configured to drop<br />

all packets addressed to itself that do not use IPsec’s ESP <strong>in</strong> transport mode. Thus, the network<br />

manager will send management queries (or commands) to a specific encapsulation gateway and<br />

the encapsulation gateway will eventually report back to the network manager, with all<br />

communications occurr<strong>in</strong>g via ESP <strong>in</strong> transport mode. Both the encapsulation gateway and the<br />

network manager must authenticate each others’ communications. Approaches to authorize<br />

network managers also need to be carefully considered, with separation of duties with least<br />

privilege be<strong>in</strong>g recommended by this study. The encapsulation gateways will need to be<br />

certified as high-assurance security items (i.e., EAL 5 or higher).<br />

Because network managers located on unencapsulated networks natively do not know about<br />

VPN entities, it is possible to preconfigure a network manager with <strong>in</strong>formation associat<strong>in</strong>g VPN<br />

devices with a specific encapsulation gateway. Alternatively, the encapsulation gateway could<br />

be queried—or pass through such queries directly to the VPN devices—concern<strong>in</strong>g entities<br />

with<strong>in</strong> that VPN, possibly provid<strong>in</strong>g <strong>in</strong>formation about their software identity, current software<br />

version, current status, and configuration (if appropriate).<br />

Network management also conta<strong>in</strong>s software development implications. If software items are to<br />

be managed, then the management schemas by which the software is managed need to be<br />

devised <strong>in</strong> accordance with the network management system used on that aircraft. This requires<br />

coord<strong>in</strong>ation and advanced knowledge of the specific management protocol that will be used, the<br />

mechanisms by which that protocol will be secured, the desired format for the management<br />

schema, and a common approach for schema def<strong>in</strong>ition.<br />

121

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!