
Stateful firewalls are becoming bottlenecks for high-speed communication networks. To counteract, trusted network flows may statically bypass the firewall. As access control lists (ACLs) of moderately priced switches do not allow port selection, they cannot be used for implementation of a static firewall bypass. In this work, we present a software-defined networking (SDN) based solution for a static firewall bypass based on moderately priced commodity hardware. We propose OFFWall, an OpenFlow (OF) controller that translates a whitelist of trusted flows into flow rules and installs them on an SDN switch to implement the firewall bypass. OFFWall has been developed according to the demands of network administrators. Its goal is simplicity and stability so that it can run for long time without updates. Therefore, it is programmed in Rust for runtime stability and compiled to an executable file. Moreover, it offers only a minimal feature set required to install and remove flow rules on the switch. After successful tests in a virtual and physical setup with different complexity, we deployed OFFWall on the network of the Department of Computer Science of the University of Tuebingen.
This paper introduces SDN Cockpit, an easy-to-use and open ecosystem for teaching network softwarization based on mininet and the Ryu controller. The ecosystem allows candidates to gain hands-on-experience with SDN in prefabricated scenarios without having to deal with potentially complex details such as traffic generation. It provides useful tooling for instructors and automated evaluation for assignments. The paper discusses the design goals, the architecture and the workflow of the ecosystem. First experiments with SDN Cockpit show that the approach can improve the motivation and the learning experience of the candidates.
Purchase decisions for devices in high-throughput networks as well as scientific evaluations of algorithms and technologies need to be based in measurements and clear procedures. Therefore, evaluation of network devices and their performance in high-throughput networks is an important part of research. In this paper, we document our approach and show its applicability for our purpose in an evaluation of two of the most well-known and common open source intrusion detection systems, Snort and Suricata. We used a hardware network testing setup to ensure a realistic environment and documented our testing approach. In our work, we focus on accuracy of the detection especially dependent on bandwidth. We would like to pass on our experiences and considerations.
Especially in the area of Intrusion Detection, the concept as well as the understanding of the term "risk" is of fundamental importance. Generally, risk assessment represents an important means of evaluating certain situations, plans, events or systems in a systematic and comprehensive procedure. As in other areas, within the field of IT security, the systematic assessment process (risk analysis) also aims at recommending how to allocate available resources. Referring to this, both, the categorization of traffic (whether traffic has to be classified as an attack or not “benign vs. malicious”) as well as a corresponding estimation of the expected damage (severity) are of central importance. Therefore, within this publication, the authors address the following questions in detail: (1) To what extent are the detection results of different IDSs comparable with regard to the assessment of the risk / extent of damage or are there strong deviations? (2) How do both vendor-dependent and vendor-independent alerts address the topic of risk assessment and enable the implementation of a comprehensive risk concept? To this end, at the heart of this paper, an overview as well as an evaluation of important representatives of open source IDSs is presented, focusing on methods for risk assessment resp. risk rating including cross-vendor risk rating and the Common Vulnerability Scoring System (CVSS). Furthermore, the paper also contains a brief demise of the most important representatives of commercial IDSs.
The increasing amount and heterogeneity of devices demands changes in IT infrastructure. Many web service architectures used to meet these demands use the OAuth2 workflow to secure their interfaces. These implementations usually tightly couple web services and an OAuth2 authorization service. The presented extension to the OAuth2 workflow is capable handling authorizations for multiple attached services and therefore combines existing services of a central IT service provider but also allows other services running in a cooperative model with only a single instance of the authorization server. Based on auditing parameters it is possible to present access per resource or per method giving service providers and application developers more insight in how their services are used and show users by whom their personal data is used.
Virtualisierungsund Cloud-Technologien haben den Wandel der IT-Landschaft der letzten Jahre erheblich geprägt und werden von der Wissenschaft zunehmend für ihre eigenen Zwecke genutzt. Rechenzentren sollten auf den steigenden Bedarf in Forschung und Lehre mit der Bereitstellung geeigneter Infrastrukturen antworten. Es wird untersucht, wie Cloud-, Computeund Lehrpool-Umgebungen so bereitgestellt werden können, dass eine bestmögliche Versorgung der Wissenschaft bei gleichzeitig effizienter Nutzung vorhandener Ressourcen erreicht werden kann. Durch die Erzeugung geeigneter virtualisierter Forschungsund Lehrumgebungen können verschiedene Wissenschafts-Communities ihre Vorhaben durchführen, ohne hierfür weiterhin eigene Hardware-Infrastrukturen betreiben zu müssen. Es wird anhand der Umsetzung zweier prototypischer virtualisierter Forschungsumgebungen (VFU) im Bereich der Elementarteilchenphysik und der Bioinformatik diskutiert, wie zukünftige Schnittstellen zwischen Forschenden und Infrastrukturbetreibern aussehen sollten. Als Basis kommen die baden-württemberg-weit angebotenen kooperativen Forschungsinfrastrukturen des Hybrid-Clusters NEMO, der bwCloud und für den wissenschaftlichen Desktop bwLehrpool zum Einsatz. Die auf diesen Systemen eingesetzte Abstraktion durch Virtualisierung ermöglicht eine Skalierung der Ressourcen in den VFUs.