
This article first introduces the logical concepts of Software Defined Networking in an OpenFlow context and looks at the capabilities of OpenFlow based SDN. It then tried to give some examples of problems that can not or are hard to be solved with classical routing and switching equipment to show network administrators where this technology can add value to daily operations.
Im Anschluss an das Thema der ZKI-Herbsttagung 2015, „Konzepte zur Zusammenarbeit“, führt dieser Artikel die Diskussion fort, wie Kooperationen von Rechenzentren praktisch umgesetzt werden können. Es werden verschiedene rechtliche Hüllen skizziert und Erfahrungen aus Projekten und existierenden Kooperationsformen ausgewertet. Erörtert werden Argumente, die bei der Abwägung zwischen öffentlich-rechtlichen und privatrechtlichen Formen zu bedenken sind. Es wird problematisiert, wie der Übergang von befristeten Projekten, mit denen Innovationen angestoßen und gesteuert werden sollen, in den nachhaltigen Betrieb erfolgreich bewältigt kann. Dieser Bereich ist wenig entwickelt, weil es an einem übergreifenden Verständnis über Charakter und Ziele von Projekten mangelt und Steuerungs- und Governanceformen bislang zu wenig thematisiert werden, aus denen dauerhafte Strukturen wachsen können.
Layer-4 port knocking is a seasoned mechanism to hide network services in order to make them available only to authorized users in an on-demand manner. A typical legitimate use case is to enable world-wide SSH-based system administration access without allowing the whole Internet to directly connect to the SSH service on the machine in order to minimize attack vectors. However, port knocking can also be used by attackers who successfully have compromised a system and installed some kind of backdoor; in this case, port knocking is used to evade detection by the legitimate system owners for as long as possible. This article presents a novel approach to flowanalysis-based detection of hidden backdoors and port knocking sequences; it correlates layer-4 port scans with flow records, which are, e.g., based on NetFlow records, and analyses the results in order to perform a purely network-based backdoor detection without the need to retrieve additional information from each individual machine connected to the local network. As the flow-recordbased approach has inherent limitations, such as high latency and therefore lacking real-time capability, the potential of software-defined networking applications (SDN controller apps) for this purpose is discussed. The presented approach has been implemented as a prototype, which was thoroughly tested in a lab environment; the results of those results and identified issues as well as ways to improve the approach are discussed. Finally, an outlook to real-world application is given.
Abstract As a newer concept, in comparison to hypervisor technologies, container-based virtualization is a rather lightweight virtualization concept. By not emulating any hardware it has a much lower overhead with good isolation. The basic idea is to generate isolated containers which use the same kernel as the host system, instead of individual ones per virtual machine. Hence the virtualized applications or systems have to be compatible to the same kernel. Networking testbeds like ToMaTo can benefit from such technology, since it allows to run many virtual machines in parallel. In this paper, three representatives of Linux container-based virtualization technologies will be presented: OpenVZ, Linux-VServer and LXC. The main features and concepts of each technology will be discussed, followed by a comparison about performance, security, virtualization system integration and client software. At the end their value for ToMaTo will be rated.
AbstractAccessing remote IT services through identity federations (IFs) is based on solid technical protocols such as the Security Assertion Markup Language (SAML) and OpenID Connect. However, reliable delegated user authentication and authorization also pose organizational challenges regarding the quality management of user data. Level of Assurance (LoA) concepts have been adapted and applied to IFs, but their inhomogeneous proliferation bears the risk of aggravating instead of simplifying the manual work steps. This is increased by the providing IT services for multiple or dynamically set up IFs. This article presents a novel LoA management approach that has been designed for a high degree of automation, adopts the approach for the dynamic metadata exchange by GÉANT-TrustBroker and exemplifies its usage.
AbstractAlthough testbeds and experimental facilities are accepted as tools for research in the scope of distributed systems research, such as Future Internet Research, they lack sustainability; once established as a project, they must be maintained and renewed every few years. However, unfortunately, due to an absence of long-term funding for operating/maintenance and reinvestment, a lot of these are terminated just after the project is complete.In this paper, we describe a software-defined testbed on demand; this is based on the Topology Management Tool (ToMaTo), a software environment which was developed within the G-Lab project. ToMaTo, initially designed to run on the G-Lab infrastructure, is now independent of the underlying infrastructure and can be deployed on any Cloud infrastructure on demand. We describe here the deployment of ToMaTo to the CloudLab infrastructure offered by the NSF-funded CloudLab project.This approach offers a new method for sustainable testbeds where neither upfront investment nor the recurring and operating/maintenance costs for the infrastructure will burden the budgets of the projects.
Abstract In diesem Artikel wird ein vom IT Center der RWTH Aachen University entwickeltes und in der Praxis bewährtes Reporting-Tool vorgestellt, welches das IT Center in seinem IT-Controlling nachhaltig unterstützt und zur Gewährleistung und Steigerung der Qualität seiner angebotenen Dienste beiträgt. Wir bedienen uns dabei gängigen Methoden aus dem IT Service Management und zeigen auf, wie wir diese für unsere Zwecke anwenden. Neben der technischen Umsetzung gehen wir noch auf das Thema Kennzahlen und kennzahlenbasiertes Reporting aus theoretischer Sicht ein und stellen die damit verbundenen Herausforderungen dar.
AbstractThe Internet is a successful network that connects people all over the world. However, it has some fundamental architectural problems which require application developers and service providers to spend a tremendous effort in combating these. Examples for these efforts are content delivery networks or mobile TCP. Thus, it can be said that the Internet is currently not fulfilling the requirements on the global network anymore. The Internet of the future, or its replacement, must solve these problems.There are multiple clean-slate approaches for information-centric networking. However, they are inherently incompatible to the Internet or applications building on it.This work presents a novel resource transport protocol that is optimized for detection by software-defined networks and may be re-routed to in-network processors. Furthermore, it is shown how this protocol can be used to support concepts of ICN even in today’s Internet. Moreover, the resource format that is used in this work is independent from the underlying network, resulting in possible reuse in other networks as well. Applications and protocols building on this resource format can thus easily be re-used in clean-slate networks like NDN.
Im Kontext der Business Intelligence (BI) werden Informationen zu Geschäftsvorgängen, basierend auf den sogenannten Fakten, in grafischen oder tabellarischen Berichten zur Anzeige zusammengeführt. BI-Systeme stellen umfangreiche Mittel bereit, um auf den zugrundeliegenden Datenräumen inhaltlich zu filtern, zu aggregieren oder anderweitig zu analysieren. Im Rahmen eines Entwicklungsprojekts sollten insbesondere nicht-aggregierende BI-Berichte, die sich auf Ebene von Einzelfakten bewegen, mit der Workflowsteuerung einer Intranet-Webapplikation verknüpft und den Anwendern transparent über diese verfügbar gemacht werden.
Cloud Computing offers a way to outsource IT infrastructure and thereby reduce costs, especially for SMEs. However, companies remain skeptical of using the clouds of foreign organizations because of privacy and security concerns. Due to lack of experience and a too high up-front investment, companies also restrain from setting up their own cloud. The SwarmCloud project aims at creating a swarm-like network of cloud blocks that can cooperate in a decentralized manner. Each block is a minimal cloud system that is easily affordable for small companies. The SwarmCloud network automatically connects several blocks to form a federated higherlevel cloud system. Scaling such a network to millions of blocks requires a novel decentralized approach to network coordination and resource discovery. This paper proposes and evaluates a scalable network structure for the SwarmCloud network that leverages peerto-peer paradigms to build swarms of millions of blocks.
Under the brand name “sciebo – theCampuscloud” (derived from “science box”) a consortium of more than 20 research and applied science universities started a large scale private cloud storage service hosted on premise at the universities designed to be available for up to 500,000 students and researchers in North Rhine-Westphalia. Starting with the much anticipated data privacy compliant sync & share functionality, sciebo offers the potential to become a more general cloud platform for collaboration and research data management which will be actively pursued in upcoming scientific and infrastructural projects. This project report describes the formation of the venture, its targets and the technical and the legal solution as well as the current status and the next steps.
For the last decades, Alois Potton’s columns gave us much food for thought: sometimes in all seriousness, at other times quite humoristically, and sometimes filled with acrid irony. But now that Potton has retired, PIK needs to find an adequate replacement for his continued contributions – however difficult it will be to find someone to follow in Potton’s footsteps. Fortunately Potton did not just leave his footsteps, but also the idea to establish a new conference focused on “Humor in Informatics” (http://humor-informatik.de/). Based on the groundwork laid down by Potton himself, Peter Reichl from the University of Vienna is now organizing these events and we have seen a number of contributions that I am sure Potton would like, too. In his spirit, PIK’s editorial team is working with the conference organizers to identify select articles that are worth publishing in PIK. In the future, it is these contributions that will begin to fill Potton’s footsteps; or at least part of them. However, humor has a lot to do with the cultural background it originates from. As a result, it is not easy to translate the German contributions into English. The British or the US American kinds of humor differ from the German one. Because most of the contributions to this conference are in German (even though I think that the organizers of this conference are happy to accept English contributions) PIK’s editorial team has decided not to translate the contributions from German to English or vice versa. In the future you will thus see both German and English columns and commentaries, but wewill encourage our German contributors to provide bilingual titles and a short abstract in English for our international audience. In turn, you should feel encouraged to get in touch with authors of contributions you find interesting to put their food for thought towork. We hope that this replacement for Alois Potton can begin to fill his footsteps and in some ways can shed light on basic concepts, ideas, andmethods of Informatics while encouraging an active dialog in and beyond the journal.
During the late 1980s and the early 1990s the role of IT within enterprises changed dramatically. Traditional host systems were replaced and the upcoming of open systems made it possible for nearly every department to design its own IT. Fulfilling specific needs, the challenges for those responsible for the IT management, therefore grew and altered [PHI04, BAU10] Some years ago the primary task of IT management was to take care of a small number of different systems and applications. Themajor skills of IT managers were technology oriented. With the changes mentioned above the requirements shifted to aligning the IT with the business needs and the overall strategy of the whole enterprise. These changes made a C-level position responsible for the entire IT necessary. The major focus changed from technology and applications to supporting core processes with efficient and highly integrated IT systems. The Chief Information Officer (CIO) and later the term IT Governance [ISO08] were born. In the late 1990s the CIO movement reached German Universities. Now, fifteen years of experiences later, is a good point in time for the evaluation of IT Governance models established differently at German universities. The ZKI e. V. (Zentren für Kommunikation und Informationsverarbeitung in Forschung und Lehre, centers for communication and information processing in research and higher education) is the German consortium of higher education (HE) IT service centers and public funded research centers. Members of ZKI are universities, universities of applied sciences and big research facilities with public funding, represented by the directors of the IT centers as well as companies with a high interest in HE IT. Since 2001 the „Deutsche Forschungsgemeinschaft“ (DFG, German research foundation) in [DFG01, DFG06, DFG10], the ZKI [ZKI03, ZKI08, ZKI12], the rectors‘ conference [HRK13], and others [vdH08, Fer09, Gör11] recommended to establish a general manager for the ICT at universities called Chief Information Officer (CIO). Between 2005 and 2010 some of the German ministries of higher education (Germany has a different ministry of HE in each of the 16 lands) requested the designation of a university CIO. In 2014 the ZKI reviewed the consequences of these recommendations: – Howwas the CIO-concept transformed into practice? – What is good practice? – Is it possible to measure whether the CIO’s work is successful or not?
The identification of the exact path that packets are routed in the network is quite a challenge. This paper presents a novel, efficient traceback strategy in combination with a defence system against distributed denial of service (DDoS) attacks named Tracemax. A single packets can be directly traced over many more hops than the current existing techniques allow. It let good connections pass while bad ones get thwarted. Initiated by the victim the routers in the network cooperate in tracing and become automatically self-organised and self-managed. The novel concept support analyses of packet flows and transmission paths in a network infrastructure. It can effectively reduce the effect of common bandwidth and resource consumption attacks and foster in addition early warning and prevention.
Zusammenfassung: Dieser Beitrag beschreibt die Zusammenstellung einer Linux-Dualboot-Infrastruktur für Entwickler in einem mittelständischen Unternehmen, dessen Fokus die Softwareentwicklung ist. Die Entwickler benötigen dabei eine Flexibilität, die von den bekannten Enterprise-Linuxen für Desktop-Umgebungen nicht geboten wird. Dabei laufen Auslieferung und Konfiguration des Linux-Betriebssystems weitestgehend automatisiert ab. Inhalt des Beitrags ist insbesondere eine aktuelle Evaluation von Linux-Distributionen, Konfigurationsmanagementund Auslieferungswerkzeugen, die dem Leser hilft, eine für seine eigene Situation geeignete Lösung zu finden. Für das betrachtete Unternehmen bestand diemit Erfolg eingesetzte Lösung aus einer Kombination von Ubuntu LTS, FAI und Puppet.