
This paper introduces SDN Cockpit, an easy-to-use and open ecosystem for teaching network softwarization based on mininet and the Ryu controller. The ecosystem allows candidates to gain hands-on-experience with SDN in prefabricated scenarios without having to deal with potentially complex details such as traffic generation. It provides useful tooling for instructors and automated evaluation for assignments. The paper discusses the design goals, the architecture and the workflow of the ecosystem. First experiments with SDN Cockpit show that the approach can improve the motivation and the learning experience of the candidates.
Stateful firewalls are becoming bottlenecks for high-speed communication networks. To counteract, trusted network flows may statically bypass the firewall. As access control lists (ACLs) of moderately priced switches do not allow port selection, they cannot be used for implementation of a static firewall bypass. In this work, we present a software-defined networking (SDN) based solution for a static firewall bypass based on moderately priced commodity hardware. We propose OFFWall, an OpenFlow (OF) controller that translates a whitelist of trusted flows into flow rules and installs them on an SDN switch to implement the firewall bypass. OFFWall has been developed according to the demands of network administrators. Its goal is simplicity and stability so that it can run for long time without updates. Therefore, it is programmed in Rust for runtime stability and compiled to an executable file. Moreover, it offers only a minimal feature set required to install and remove flow rules on the switch. After successful tests in a virtual and physical setup with different complexity, we deployed OFFWall on the network of the Department of Computer Science of the University of Tuebingen.
Purchase decisions for devices in high-throughput networks as well as scientific evaluations of algorithms and technologies need to be based in measurements and clear procedures. Therefore, evaluation of network devices and their performance in high-throughput networks is an important part of research. In this paper, we document our approach and show its applicability for our purpose in an evaluation of two of the most well-known and common open source intrusion detection systems, Snort and Suricata. We used a hardware network testing setup to ensure a realistic environment and documented our testing approach. In our work, we focus on accuracy of the detection especially dependent on bandwidth. We would like to pass on our experiences and considerations.
Es liegt in der Natur wissenschaftlicher Prozesse, dass viele Zwischenergebnisse, aber auch schlicht irrelevante Forschungsdaten gespeichert werden, die bei regelmäßigen Überprüfungen eigentlich gelöscht werden könnten. Weiterhin passiert es häufig, dass potentiell wertvolle Daten aufgrund von Platzmangel unwiederbringlich gelöscht werden. Ein nachhaltiges Forschungsdatenmanagement schafft den Spagat zwischen der Finanzierbarkeit einer wachsenden Datenmenge bei gleichzeitiger Optimierung der Qualität der Daten. Dieser Beitrag diskutiert, wie klassische technische Lösungen durch geeignete mit den einzelnen Wissenschafts-Communities abgestimmte Steuerungsrahmen ergänzt werden können. So ließe sich das hier beschriebene Speicherkonzept als FDMBaustein im Nutzen verbessern, indem die Forschenden zu jedem Zeitpunkt qualifizierende Beschreibungen ihrer Daten hinzufügen, wobei die Angabe derselben eine Grundvoraussetzung für eine langfristige Speicherung darstellen. Für einen echten, den Rahmen der einzelnen Forschungsinstitution übergreifenden, Mehrwert können diese Metadaten über standardisierte Schnittstellen abgefragt und in bestehende und zu entwickelnde fachspezifische Workflows integriert werden. Ein FDMfähiges Speichersystem muss berücksichtigen, dass Daten vieler Forschungsgruppen an verteilten Standorten liegen und von unterschiedlichen Wissenschafts-Communities verwendet werden.
The increasing amount and heterogeneity of devices demands changes in IT infrastructure. Many web service architectures used to meet these demands use the OAuth2 workflow to secure their interfaces. These implementations usually tightly couple web services and an OAuth2 authorization service. The presented extension to the OAuth2 workflow is capable handling authorizations for multiple attached services and therefore combines existing services of a central IT service provider but also allows other services running in a cooperative model with only a single instance of the authorization server. Based on auditing parameters it is possible to present access per resource or per method giving service providers and application developers more insight in how their services are used and show users by whom their personal data is used.
Especially in the area of Intrusion Detection, the concept as well as the understanding of the term "risk" is of fundamental importance. Generally, risk assessment represents an important means of evaluating certain situations, plans, events or systems in a systematic and comprehensive procedure. As in other areas, within the field of IT security, the systematic assessment process (risk analysis) also aims at recommending how to allocate available resources. Referring to this, both, the categorization of traffic (whether traffic has to be classified as an attack or not “benign vs. malicious”) as well as a corresponding estimation of the expected damage (severity) are of central importance. Therefore, within this publication, the authors address the following questions in detail: (1) To what extent are the detection results of different IDSs comparable with regard to the assessment of the risk / extent of damage or are there strong deviations? (2) How do both vendor-dependent and vendor-independent alerts address the topic of risk assessment and enable the implementation of a comprehensive risk concept? To this end, at the heart of this paper, an overview as well as an evaluation of important representatives of open source IDSs is presented, focusing on methods for risk assessment resp. risk rating including cross-vendor risk rating and the Common Vulnerability Scoring System (CVSS). Furthermore, the paper also contains a brief demise of the most important representatives of commercial IDSs.