
Despite the wide of range of research and technologies that deal with the problem of routing in computer networks, there remains a gap between the level of network hardware administration and the level of business requirements and constraints. Not much has been accomplished in literature in order to have a direct enforcement of such requirements on the network. This paper presents a new solution in specifying and directly enforcing security policies to control the routing configuration in a software-defined network by using Row-Level Security checks which enable fine-grained security policies on individual rows in database tables. We show, as a first step, how a specific class of such policies, namely multilevel security policies, can be enforced on a database-defined network, which presents an abstraction of a network's configuration as a set of database tables. We show that such policies can be used to control the flow of data in the network either in an upward or downward manner.
Due to the dynamic nature of the Industrie 4.0, future production systems will be reconfigured frequently and as a part of the engineering process, new system configurations will be deployed automatically. In order to keep pace with this development, it will be required to achieve the needed security levels in an automated way and to reduce the current static procedures and manual efforts as much as possible. Therefore, the development and modelling of all cyber security related functionalities is needed. This paper describes an approach for such a modelling based on security requirements and levels of the international standard IEC 62443 part 3-3 and a system description based on OASIS TOSCA for the deployment. The approach is applied to an Industrie 4.0 use case scenario based on edge cloud computing and an evaluation is performed to demonstrate its feasibility.
In this paper, we propose a destination-aware adaptive traffic flow rule aggregation (DATA) mechanism for facilitating traffic flow monitoring in SDN-based networks. This method adapts the number of flow table entries in SDN switches according to the level of detail of traffic flow information that other mechanisms (e.g. for traffic engineering, traffic monitoring, intrusion detection) require. It also prevents performance degradation of the SDN switches by keeping the number of flow table entries well below a critical level. This level is not preset as a hard threshold but learned during operation by using a machine-learning based algorithm. The DATA method is implemented within a RESTful application (DATA App) which monitors and analyzes the ongoing network traffic and provides instructions to the SDN controller to adapt the traffic flow matching strategies accordingly. A thorough performance evaluation of DATA is conducted in an SDN emulation environment. The results show that-compared to the default behavior of common SDN controllers-the proposed DATA approach yields significant SDN switch performance improvements while still providing detailed traffic flow information on demand.
Benchmarking is an important measure for companies to investigate their performance and to increase efficiency. As companies usually are reluctant to provide their key performance indicators (KPIs) for public benchmarks, privacy-preserving benchmarking systems are required. In this paper, we present an enhanced privacy-preserving benchmarking protocol, which we implemented and evaluated based on the real-world scenario of product cost optimisation. It is based on homomorphic encryption and enables cloud-based KPI comparison, providing a variety of statistical measures. The theoretical and empirical evaluation of our benchmarking system underlines its practicability.
In the era of Internet of Things (IoT) the interconnectedness of devices, and thus the need to protect them against threats increased. The widely used threat modeling method STRIDE can be used to identify the system's vulnerabilities and to determine appropriate mitigation solutions. In connected environments, especially the network layer plays a critical role in achieving security. Based on the Network Functions Virtualization (NFV) concept, network functions can be virtualized and provisioned on standard IT hardware. Virtualized Network Functions (VNFs) increase the flexibility of the provisioning, and thus security network functions, such as firewalls, can be easily deployed. However, in a complex distributed system it is time-consuming, error-prone, and for application architects even not possible to identify and provision the required security functions. For the orchestration and management of applications the TOSCA modeling language can be used to describe the application's components and their relations in a deployment model. The standard was mainly developed for cloud applications but was extended to the network layer. In this paper, we present a TOSCA-based approach for threat modeling based on STRIDE that facilitates the automated VNF selection and injection into TOSCA deployment models. The feasibility of our approach is validated by an extension of the TOSCA modeling tool Winery.
Data-centric service-oriented designs are promising for overcoming the current IoT silos. The Virtual State Layer (VSL) is a data-centric middleware that securely unifies the access to distributed heterogeneous IoT components. The VSL solves key challenge of today's IoT: reducing the complexity, enabling interoperability, and providing security-by-design. The described practical setting enables the interactive exploration of a data-centric middleware including a live performance evaluation.
Softwarization and programmability allow for flexible and more efficient network resource utilization. This leads to more dynamic in traffic and behavioral patterns and therefore demands for comprehensive network monitoring. Furthermore, a sound understanding of the network, its resources, and the traffic carried is required for being able to conduct sensible control decisions. This comes along with monitoring data analytics, which is challenging from a resources perspective. The AutoMon project [1] works on a monitoring solution using closed loop control for gaining maximum insight at minimal resource utilization. We developed a control concept, where a controller dynamically adapts the monitoring functions in the network as well as the data analytics part of the network monitoring system. While the concept also covers component metrics and active measurements, our current focus is on flow monitoring as it is most challenging due to the high and often unpredictable amount of data. Our first, yet simple, control algorithms focus on the balancing of storage consumption, as this is the most critical resource. Evaluations by simulation show that they are feasible in clusters with heterogeneous resources and typical flow rate patterns. We implemented a FlowMediator component for dynamic distribution of flow monitoring data, which can take control commands from a controller running these algorithms. Although, we use Software Defined Networking (SDN) concepts, SDN is no prerequisite. Hence, our approach is suitable for brown-field deployments and has been validated in labs using traffic from a large production network.
This demo presents an energy-aware system designed for long-term deployments in urban sensing. It consists of a hardware-software co-design that allows measurement and harvesting of energy on class-1 IoT nodes. We focus on the self-management of energy and its integration with the RIOT operating system. The measurement module is composed of commodity components and designed for easy, flexible integration with various hardware platforms.
Traditionally, network functions were often implemented on expensive special networking hardware (e.g. middle-boxes). The architectural concept of network functions virtualization (NFV) enables the implementation of network functions (e.g. routing, firewall) as virtual network functions (VNF) in software to execute them on off-the-shelf x86 hardware. To leverage the capabilities of multi-core processors, the VNFs must be distributed on several cores. However, when many VNFs are executed on different CPU cores, the VNFs compete for the last level cache (LLC) which is a shared resource between all CPU cores and might become a performance bottleneck. With the help of cache partitioning, it is possible to divide the LLC into dedicated blocks for each VNF. This paper investigates if a performance gain can be achieved by cache partitioning. With the help of real testbed measurements, a Linux router as well as a DPDK-based router is examined. Our results show that cache partitioning can be beneficial if the cache partition size is sufficiently large.
The heart of the Internet of Things (IoT) is data. IoT services processes data from sensors that interface their physical surroundings, and from other software such as Internet weather databases. They produce data to control physical environments via actuators, and offer data to other services. More recently, service-centric designs for managing the IoT have been proposed. Data-centric or name-based communication architectures complement these developments very well. Especially for edge-based or site-local installations, data-centric Internet architectures can be implemented already today, as they do not require any changes at the core. We present the Virtual State Layer (VSL), a site-local data-centric architecture for the IoT. Special features of our solution are full separation of logic and data in IoT services, offering the data-centric VSL interface directly to developers, which significantly reduces the overall system complexity, explicit data modeling, a semantically-rich data item lookup, stream connections between services, and security-by-design. We evaluate our solution regarding usability, performance, scalability, resilience, energy efficiency, and security.
The requirements for video streaming have changed drastically during the past years. In today's Internet, high definition resolutions are considered default for videos, even in mobile settings, and with 4G penetration reaching 90 percent in the US, this no longer poses a big problem. However, while mobile bandwidth has increased, the battery life time of mobile devices has not increased significantly. Furthermore, current data plans are still not large enough to regularly stream movies during the commute. Users still resort to downloading media before travel. In this paper we propose a new HTTP adaptive streaming algorithm that delivers videos in high quality while avoiding stalling events, schedules the download of video segments so that a energy conserving idle state is often reached and keeps the buffer low at points in the video where many viewers abandon the video to save data. While most adaptive streaming algorithms optimize quality and stalling, this is the first attempt to use an adaptive streaming algorithm to reduce energy consumption. Since video streaming providers mostly care about the Quality of Experience when watching videos, energy efficiency is left to the device manufacturers. Therefore, both parties have little incentive to cooperate in this regard. But on the Internet of tomorrow, where most videos are watched on mobile devices, energy efficiency and the Quality of Experience must go hand in hand.
This paper presents link 'em, an open source link emulation bridge for reproducible networking research. While reproducibility is one keystone of good research, most available link emulators are lacking crucial features or are prohibitively expensive. Link 'em is a Raspberry Pi-based layer-2 bridge that runs an extended version of netem in conjunction with a trace database to achieve reproducible link emulation. By invoking our novel packet loss module, which builds upon sagemath and NetfilterQueue, more sophisticated packet loss models can be used in addition to netem's existing ones. The proposed demonstration verifies the achieved reproducibility. This is done by showing the effects of a model-based link emulation via netem and a trace-based emulation using our link 'em bridge on a video live stream, compared to a pre-captured reference stream.
In the aftermath of disasters, access to communication infrastructure is often impaired or fully unavailable. Smartphone-based ad hoc networks can be utilized to re-enable basic communication services and foster coordination and self-help capabilities of those affected. However, their capacity is limited as they need to operate in a disruption-tolerant fashion. At the same time, the communication demand increases significantly after a disaster, potentially overloading the ad hoc network and requiring message prioritization mechanisms. In this work, we contribute insights into the communication behavior and resource demand in a post-disaster ad hoc network based on a large field trial and a survey of related works. We identify-potentially undesired-interactions between delay-tolerant networks (DTNs) with message prioritization and the specific dynamics of a disaster scenario. To study these interactions in greater detail, we propose a generic architecture for the evaluation of prioritized DTNs in disaster scenarios. We identify key issues w.r.t. static and adaptive prioritization approaches based on a proof-of-concept evaluation and outline directions for future research on prioritization in DTNs.
In this experience paper, we summarize the analysis of key technologies that are prerequisite for a secure realtime communication and computing Infrastructure in the smart factory, which supports flexible and reconfigurable production assets with a real-time digital representation. A broad range of Industry 4.0 use cases is evaluated - jointly with industrial application partners - and a set of basic requirements is derived from them. These challenges need to be addressed by available and upcoming ICT technologies in the domains of cloud computing in an industrial environment, virtualization and industrial Edge Computing, 5G radio and network, analytics with big and fast data, and Artificial Intelligence / Machine Learning technologies. The analysis includes mechanisms for secure and reliable connectivity in production, secure wireless communication and secure processes, massive sensor data analysis, and (virtual) network elements like secure gateway. Challenges and opportunities for new applications in production are described in the following.
This contribution discusses challenges and solutions for secure communication that are relevant for the success of the Industry 4.0 paradigm. It shows that IT security has to be solved with respect to the technical challenges of hardware or software components to be used in the Industry 4.0 context. Aditionally, the paper highlights the organizational challenge to reduce security risks to a minimum during the complete industrial life cycle.
The ongoing softwarization of networks comes with several advantages like cost efficiency, increased scalability, and better flexibility by migrating functionality from static, application specific hardware appliances to flexible, lightweight software solutions running on COTS hardware. In order to maximize the performance gains promised by the NFV paradigm, several challenges remain to be solved. In this work, we address the accurate acquisition of key performance indicators, specifically the packet processing time, of softwarized network functions. To this end, we present KOMon, a Kernel-based online monitoring tool to reliably measure the packet processing times of network functions through lightweight in-stack monitoring. We show that KOMon reports highly accurate values in different scenarios and discuss the applicability of the proposed mechanism for different use cases.
Increasing adoption of cellular phones equipped with global positioning system (GPS) chips enables the exploration of pedestrians' mobility patterns. Tasks such as discovering hot-spots in large cities can be addressed through the usage of accumulated GPS coordinates. In this work we utilize spatiotemporal analysis on collected geo-location points to discover Zone of Interests (ZOIs) of pedestrians in large cities to understand people's dynamics. We design an adaptive Markov model to forecast long distance trajectories of pedestrians, which adapts it's behavior constantly by switching from a first or second order Markov chain based on the quality of trace data and users' mobility patterns. From the predicted trajectories, we further introduce a mechanism to predict congested trajectories by estimating the number of pedestrians, who may take the same trajectory in a future moment. We conduct comprehensive empirical experiments using a real-life dataset, namely the Mobile Data Challenge (MDC) dataset with 185 participants. Our mechanisms can deliver a satisfactory pedestrian trajectory prediction with a precision of 86% and a recall of 84% .
The vision of Industry 4.0 is to enable a highly dynamic and flexible manufacturing system. Nevertheless, an uninterrupted and reliable service needs to be ensured to fulfill the safety requirements of the industrial applications. The latest advancements in technologies such as wireless connectivity, hardware virtualization, application offloading, etc. aims to cater to most of these requirements. Moreover, a new paradigm called Edge Computing is becoming a preferred solution to fulfil the latency and availability requirements of the Industry 4.0 applications. However, the dynamic resource management and automated service provisioning remains to be an open challenge in an environment with constantly varying requirements. Service migration is a part of dynamic resource management that enables repositioning of a service from one computation entity, which is e.g., overloaded and cannot satisfy the user requirements, to another computation entity. An uninterrupted service live migration is necessary to satisfy the low latency and high availability requirements of mobile devices on the factory floor. In this paper we introduce and investigate a new approach for an uninterrupted service live migration.
The Software-defined Networking paradigm became widely accepted in academia as well as the industry in the last decade. The logically centralized control-plane provides simple mechanisms to support efficient monitoring as proposed in a plethora of works recently. However, existing works simplify the control-plane to a single entity whereas it is proven that the control-plane must be implemented physically distributed. To this end, we lately proposed DistTM, a system to increase the efficiency while monitoring flows in distributed control-planes by eliminating redundant measurements of shared flows. The system is based on a centralized coordinator that introduces a single-point-of-failure and is vulnerable to network partitioning. To overcome this shortage, we propose a distributed algorithm to assign redundant measurement responsibilities to single controllers and share information among controllers in the work in hand. In an evaluation, we show that we decrease the number of measurements strongly and improve the load fairness among controllers through the collaboration of networks.
IEEE 802.1 Time-sensitive Networking (TSN) enables real-time communication with deterministically bounded network delay and jitter over standard IEEE 802.3 networks ("Ethernet"). In particular, TSN specifies a time-triggered scheduling mechanism in IEEE Std 802.1Qbv implemented by switches to control when outgoing queues get access to switch ports. Besides this time-triggered scheduling mechanism, other scheduling mechanisms can be active in the network at the same time including priority queuing and a credit-based shaper. Moreover, further supporting mechanisms such as the possibility to interrupt frames already in transmission (frame preemption) are specified by the TSN standards. Overall, this leads to a complex network infrastructure transporting both, real-time and non-real-time traffic in one converged network, making it hard to analyze the behavior of converged networks. To facilitate the analysis of TSN networks, we present TSN-specific extensions to the popular OMNeT++/INET framework for network simulations in this paper including, in particular, the time-triggered scheduling mechanism of IEEE Std 802.1Qbv. Besides the design of the TSN simulator, we present a proof-of-concept implementation and exemplary evaluation of TSN networks.