The P2P-based system for the distributed computing of statistics called DuDE is presented. High scalability and failure resilience features of P2P are exploited to achieve a high-performance distributed system, which avoids the bottlenecks of a centralized computing system. To ensure high data availability, a sophisticated algorithm for distributed data storage is integrated. Furthermore, an algorithm for global peer discovery is presented, which allows for finding all data assigned to peers without the need for a central instance. For the realization of DuDE, common working stages of distributed computing are extended to enable a highly scalable computing system based on P2P technology. Generated results from a test system show a nearly perfect linear speedup for distributed computing as well as high processor and memory relief compared to a centralized solution.
Peer-to-Peer (P2P) file sharing generates by far the most Internet traffic reaching up to 70 % in some regions of the world. These data volumes pose a significant challenge to Internet Service Providers (ISPs) regarding traffic engineering. Because P2P routing is usually agnostic of the underlying topology, traffic engineering abilities of ISPs are inhibited and their core networks are overburdened with P2P data. To disburden ISPs' core networks, we propose a new algorithm for the BitTorrent (BT) protocol in order to improve peer selection. BT users are provided with accurate information on the hop counts to other BT users to select physically proximate users. Thereby, the initial Time-To-Live value (TTL) of outgoing IP packets is copied and inserted as part of the BT payload. At the packet's destination, the hop count is calculated as the difference between the copied TTL and the TTL of the IP header. We present simulation results for standard and modified BT implementation and discuss impacts on both the load of ISPs' core networks and BT users' download performance.
L'invention porte sur un procede et un dispositif de traitement de donnees dans un reseau de communication, ledit procede comportant les etapes suivantes : (i) au moins un filtre applicable pour un premier type de connexion est fourni avant au moins un filtre applicable pour un second type de connexion ; et (ii) l'ordre du ou des filtres applicables pour le premier type de connexion et du ou des filtres applicables pour le second type de connexion est inverse lorsque le nombre de filtres requis pour le second type de connexion augmente.
This demonstration shows the hardware prototype of the IPclip (IP calling line identification presentation) mechanism for IPv6 networks. IPclip is a mechanism, which provides Trust-by-Wire in IP-based networks by adding trustworthy location information to IP packets. It is implemented on an FPGA development board and configurable at runtime via a graphical configuration tool. We show IPclip's basic functionality in a localization scenario using an analysis tool and Google Earth and discuss several application scenarios during the demonstration.
. Although the Internet has developed into a mass-medium for communication and information exchange over the last couple of years, many problems still exist regarding security and anonymity. One of these Achilles’ Heels is spam . Electronic mail (e-mail) has become one of the most used communication mechanism. It is absolutely easy to use and cost-effective. Unfortunately, the simplicity and effectiveness of e-mail are also major drawbacks. Without additional effort, Internet users’ mailboxes are flooded with unsolicited, bulk e-mails of many different flavors; mostly without any chance to identify the true origin. Thus, most anti-spam techniques rely on spam detection using large filter data bases and pattern matching functions but cannot identify the trustability of the sender. To overcome this lack of security and trustability, a new concept— Trust-by-Wire —is introduced as well as a mechanism called IPclip , which provides the basic means for enhanced e-mail security. The main idea is to guarantee Trust-by-Wire in packet-switched IP networks by providing trustworthy location information along with every IP packet. The availability of suchlike information in conjunction with some trust management is discussed in the light of a conceptual framework, which allows for reliably tracing the geographic origin of e-mails. IPclip furthermore provides an additional trigger for existing spam classification and filtering systems. Thereby, IPclip can neither be fiddled by benign e-mail users, nor by trojaned bots, nor by spammers.
During the last years, the Internet has grown into a mass-medium for communication and information exchange. Millions of people are using the Internet for business and in social life. Users can be reached easily and cost-effectively. Unfortunately the Internet's open structure is the reason for its frequent misuse for illegal and criminal actions such as dissembling phishing attacks. Thus, anti-phishing techniques are needed to recognize potential phishing threats. But mostly these techniques are only of reactive nature, are soon circumvented by expert frauds, or are not efficient enough. This paper describes an anti-phishing framework. A concept for trust management and a mechanism called IPclip are presented. The main idea of IPclip is to guarantee trust-by-wire in packet-switched networks by providing trustworthy location information along with every IP packet. This information is used as supplementary and trustworthy trigger to identify potential phishing threats. Besides, the proposed framework allows for tracing the threat's origin by using a set of location information.
During the last decades, the Internet has steadily developed into a mass medium with millions of users. On the one hand, newfangled services replace traditional ones. Naturally, these are thereby expected to offer at least the same features as their classical pendants, e.g., when VoIP replaces traditional fixed line telephone networks. On the other hand, the requirements on network infrastructures and services have changed. A reason for that is the lack of Trust-by-Wire in packet-switched IP networks. In traditional telephone networks, a phone number directly coheres with a physical line. This direct relationship is not given in modern packet-switched IP networks. An IP address does not identify a physical line! This paper presents a new mechanism, which guarantees Trust-by-Wire in packet- switched IP networks -called Internet Protocol-Calling Line Identification Presentation (IPclip). Unambiguous and trustworthy location information is added on the IP level. Firstly, IPclip's general functionality is presented. Secondly, we discuss IPclip in the light of location-aware emergency calls in nomadic VoIP environments.
During the last decades, the Internet has steadily developed into a mass medium. The target group radically changed compared to, e.g., the 90s. Because virtually everyone has access to the Internet, threats due to insecurity and anonymity reach critical levels and have to be tackled by both carriers and Internet Service Providers. Regaining trust-by-wire, comparable to classic fixed line telephones, could mitigate or even solve problems like Spam, Phishing, and the localization of VoIP emergency calls. This paper presents the hardware implementation of a new and highly flexible solution-Internet protocol-calling line identification presentation-which provides additional support for new services to restore peoplepsilas confidence into the Internet. Supported services are VoIP emergency calls, Spam detection and prevention, and phishing prevention. Already in the access network, the hardware adds unambiguous location information on the packetpsilas origin to IP packets. We document the hardware design of the solution. Furthermore, hardware consumption and performance of a prototype are presented.
Ethernet-based broadband access network nodes like an IP DSLAM are required to provide many new Ethernet/IP-based features for, e.g., end user device autoconfiguration by DHCP, authentication and authorization based on IEEE 802.1X, and multicast distribution. At control plane, a lot of information exchange is needed to configure, administer, and control these features and services. Cost-effective access network and system structures highly depend on an efficient and optimized feature positioning. ACIP is a new access control and information protocol which enables optimized, cost-effective functional decomposition of features without loosing feature options and supports optimized feature positioning. It provides transport of configuration and control information in Ethernet networks, e.g., for providing DSL line identification used for DHCP relay agent option 82 to centralized systems and for transmitting control information to remotely control DSL user ports by a centralized 802.1X authentication mechanism. ACIP is designed for being as simple as possible and open for new extensions to provide future network control functions
Today, an increasing number of customers subscribes for a high bandwidth internet access. But not only speed is demanded. Reliability, availability, and security move more and more into the customers focus. Carriers and Internet Service Providers, too, have increasing requirements derived from new services they want to offer to their customers or use themselves. A hardware solution is presented, which provides the functionality of MAC Address Translation and Traffic Management. This solution is highly flexible and can be adapted to the providers’ needs. The module is implemented on a Field Programmable Gate Array (FPGA) and offers a wide range of functionality in an Access Network for relatively low costs. Additionally, the selection of an FPGA as implementation target offers the possibility to adapt the functionality to future needs by in-field reconfiguration.
This paper focuses on establishment of new authentication and authorization mechanisms in Ethernet-based fixed Access Networks. We provide approaches for an efficient usage of IEEE Standard 802.1X mechanisms in an Access Network environment for authentication and authorization purposes. We explain how 802.1X Authenticator functionality can be integrated in different Access Network systems such as IP DSLAMs and discuss pros and cons of several approaches that we analyzed. Our main goal is to specify a cost-effective system design by strictly complying with the 802.1X standard on Access Network edges. We describe a design approach of a distributed 802.1X Authenticator which is divided into two parts, implemented on different DSLAM system modules, and extended by an Access Controller. Furthermore, we explain necessary extensions for interworking of the new distributed 802.1X Authenticator parts which also offers solutions for further problems in the range of fixed broadband Access Networks.
Today, an increasing number of customers subscribes for a high bandwidth internet access. But not only communication speed is demanded. Quality of Service (QoS) moves more and more into the customers focus. Both Carriers and Internet Service Providers (ISPs) have increasing requirements derived from new services they want to offer to their customers. A new hardware solution is presented, which can satisfy many of these upcoming demands, the MPLS User Network Interface (MPLS-UNI). The solution offers reduced MPLS functionality to very cheap hardware costs. All incoming frames are provided with MPLS label stacks. From frames leaving the network the label stacks are removed. The MPLS-UNI works with wirespeed. Only a negligible delay is inserted into the data path.
The P2P-based Domain Name System (P-DONAS) is presented. It is implemented on a Xilinx Virtex-4 board and is highly configurable regarding the functional spectrum and many parameters concerning individual functionalities. A GUI has been developed for testing and demonstrating P-DONAS. I. INTRODUCTION The Domain Name System (DNS), which represents one of the Internet core services, has not been designed for the dimension and complexity of today's Internet. Thus, scalability is the major issue (1). Nowadays, Internet Service Providers (ISPs) need to provide and operate regional DNS server farms for resilience and load sharing. Addressing scalability properly means investment in extra equipment, i.e., additional DNS server farms, efforts to operate and manage them, and energy to have server farms run 24/7. To facilitate cost reductions for ISPs, P-DONAS—a Peer-to- Peer (P2P)-based Domain Name System—has been developed. Access nodes of an ISP's access network are organized into a distributed hash table-based P2P network. These access nodes have a certain available storage and computing capacity, which may be used at no extra costs, assuming some idle time or storage capacity being left in an average access node. Each access node acts as traditional DNS server, solely stores a piece of DNS data, and shares it with all other access nodes. DNS requests issued to an access node are resolved via P2P lookups while maintaining full compatibility with traditional DNS. By deploying P-DONAS as both complement and replacement for traditional DNS, additional DNS server farms can be saved. P-DONAS is implemented as hardware/software prototype on a Xilinx Virtex-4 ML405 development board. Thereby, the development board emulates an access node with P-DONAS functionality. To meet different demands, P-DONAS is highly configurable at compilation time, e.g., regarding the actual functional spectrum and many parameters concerning the individual functionalities. Furthermore, a GUI has been developed to test and demonstrate the P-DONAS prototype. Section II presents the P-DONAS prototype. In Section III, the demonstration and test tool is introduced. Section IV briefly sketches a demonstration scenario before the paper concludes in Section V.
This paper focuses on establishment of multicast mechanisms in Access Networks (AN). Multicast is deemed to be an ap- propriate instrument to relieve communication networks, to save resources and, therefore, to improve global network performance. Multicast mechanisms are analysed and evalu- ated for their usage in Access Networks. The general structure of an Access Network and necessary measures to design mul- ticast-capable Access Networks are described. In addition, the complexity of new embedded multicast functions is dis- cussed, and effects by unicast and multicast connections on Access Network are exemplified. As a result, a design sug- gestion of a multicast-capable Access Network is given.