Section 1: Data Distribution Service
This series consists of three parts. It is focused on Data Distribution Service (DDS). DDS drives systems like railways, autonomous cars and spacecraft. It handles military tanks, luggage handling, and luggage handling. We will also examine the status of DDS, and make recommendations for enterprises to reduce the risk.
Let's
begin by talking about DDS and how it is used in different industries.
Overview
DDS
is a standard middleware software program that uses the publish-subscribe
paradigm. This software allows you to create middleware layers that allow
machine-to-machine communication. This software is essential for embedded
systems and applications that have real-time requirements. The Object Management
Group (7 OMG7)7 maintains DDS. It is used in critical applications to ensure a
reliable link between controllers and actuators.
DDS
is the first link in the software supply chain. This makes hacker targets
easy and attractive. These companies and agencies are just a few of the
ones that use DDS. This is not a complete list.
- Kennedy
Space Center, National Aeronautics and Space Administration
- Siemens
invests in wind power plants
- Bosch and
Volkswagen collaborate to create autonomous valet parking systems
- Air-traffic
control can be done with both Nav Canada and European CoFlight
DDS
is a communication mediumware that allows programs to interoperate across
programming languages. DDS is a data-centric publishing protocol and
subscription protocol that allows developers create flexible shared data spaces
that allow applications to exchange typed information.
DDS
is an excellent application programming interface (API) from a programmer's
point of view. DDS allows serialization and deserialization for any
custom-built-in data types via an interface language, (IDL), in addition to
plain bytes, C-strings and C-strings.
DDS
Applications
DDS
is the foundation for other industry standards like OpenFMB (smart Grid
Applications) and Adaptive AutoSAR (smart Grid Applications). DDS is the
default middleware of Robot Operating System 2 ("ROS 2"), which is
the standard OS for automating robotics.
DDS
can also be used in conjunction with Real-Time Publish -Subscribe, (RTPS) to
create mission-critical high-quality middleware layers. DDS can be used to
transport artificial intelligence (AI), from the electronic control unit to
their driving motors.
Here
are some DDS-related examples. External resources give estimates of the
number or expected future devices in each sector.
|
Sector |
Examples Of Use Cases |
Notable users |
|
Telecommunications
networks and networks |
* SDN
(Software-defined Networking) technologies *Appliance Life Cycle *Management tools (LCM),
which includes 5G |
* Fujitsu |
|
Defense |
* Command-and-control
(C&C), systems * Navigation
systems and systems * Start systems |
*National Aeronautics
and Space Administration, (NASA). * NATO Generic
Vehicle Architecture, (NGVA)15 * Spanish Army |
|
Virtualization and
Cloud |
* Inter and
intra-communications among security operation centers (SOC). |
* VVIDIA |
|
Energy |
* Power generation
distribution * Research |
* GE Healthcare * Plug-and-Play
program to interoperate with medical devices (MDPnP). |
|
Mining |
* Precision mining * Mining system
automation * Geological
modeling |
* Komatsu * Diagramlogic * Atlas Copco |
|
Industrial
internet-of-things (IIoT), and robotics |
* Universal
middleware |
* Robot Operating System
(ROS 2) * Robo by AWS * IRobot |
|
Public and Private
Transportation |
*Autonomous Vehicles * Air Traffic
Control Railway management *Control |
*Volkswagen, and Bosch16 * Coflight
Consortium Selex–SI Thales * Nav Canada |
Examining
DDS Attack Feasibility
Our
security experts reviewed DDS standards, and found multiple security
flaws. In November 2021, 13 CVE IDs were added for six of the most widely
used DDS implementations. Standard specifications also contained a
vulnerability.
We
scanned over 100 companies in many industries. We also scan software and
research companies from other countries. Some of these CVEs were
identified and affected. Other CVEs were also identified by using almost
90 90 ISP numbers, and other details.
To
get feedback from our findings, we interviewed DDS users and system
integrations experts as well as researchers in their respective research
areas. The specifications of DDS were reviewed, along with six of the most
popular implementations around the world that have thousands of deployments.
DDS
is the most powerful threat in the software supply chain. Between
2020-2021 66% of attacks were on suppliers' codes. During our research, we
discovered a source-code repository host in an proprietary DDS
implementation. This would have given an attacker access to the source
codes (MITRE ATT&CK, T0873).
DIGITAL
DEVICES LTD
Long before Apple set an average consumers
mindset to replacing their handheld gadgets in two years, Digital Devices
Ltd believed in Moore's law that computing will double every two years.
With our heritage from the days of IBM Personal Computer XT, our founders have
gone through the technology advancements of the 1990s and 2000s realizing that
technology is an instrumental part of any business's success. With such a fast
pace industry, an IT department can never be equipped with the tools and
training needed to maintain their competitive edge. Hence, Digital Devices has put together a team of engineers and
vendor partners to keep up with the latest industry trends and recommend
clients on various solutions and options available to them. From forming close
relationships with networking and storage vendors like Juniper, SolarWinds and VMWare to
high-performance computing by HPE or AWS Cloud solutions, Digital Devices
Limited offers the latest technology solutions to fit the
ever-growing needs of the industry.
Our
experts can guide you through the specifications and build cost efficiencies
while providing high end, state-of-the-art customer services. We research and
analyses market and its current demand and supply chain by offering wide range
of bulk supplies of products like AKG C414 XLII,
Shireen Cables DC-1021, Shireen Cables
DC-2021, Dell p2419h monitor, Dell U2419H, Dell P2719H, Dell P2219H, Lenovo 62A9GAT1UK,
LG 65UH5F-H and Complete IT Infrastructure products
and services.
Comments
Post a Comment