Abstract—Today, Peer-to-Peer (P2P) already represents 60 percent,of Internet traffic. Although,P2P users are,a,good source for revenue for Internet Service Providers (ISPs), the data volume,caused,by P2P poses a significant challenge to ISPs regarding,traffic engineering. Because,P2P routing,is usually agnostic of the underlying topology, traffic engineering abilities of ISPs are inhibited. This problem,is known,as mismatching problem,between,the,logical P2P overlay,topology,and,the underlying,physical network,topology. To mitigate this problem and, e.g., to avoid traffic congestions, the concept for a new mechanism,is proposed,in this paper. P2P users are provided with accurate,information,on the hop,counts to other peers to select close peers in unstructured,P2P networks. This mechanism does neither require a modification,of the construction algorithm for unstructured,P2P networks,nor create any,communication overhead. Already in the access network, the original Time-To- Live (TTL) value of outgoing,IP packets is copied and,inserted as IP option into these packets by the network,operator. At the traffic destination, the hop count for an IP packet is calculated as the difference between,the copied TTL value and,the TTL value of the IP header. Using the hop count, a relationship between the logical overlay and,the physical network,is established to do traffic engineering. Index Terms—Peer-to-Peer, Hop Count, Locality, Access Net- work, Traffic Engineering.
This demonstration shows the hardware prototype of the IPclip (IP calling line identification presentation) mechanism for IPv6 networks. IPclip is a mechanism, which provides Trust-by-Wire in IP-based networks by adding trustworthy location information to IP packets. It is implemented on an FPGA development board and configurable at runtime via a graphical configuration tool. We show IPclip's basic functionality in a localization scenario using an analysis tool and Google Earth and discuss several application scenarios during the demonstration.
Hash functions have a space complexity of O(n) and a possible time complexity of 0(1). Thus, packet classifiers exploit hashing to achieve packet classification in wire speed. Especially evolvable hash functions can adapt to a changing classification data base. But hash functions do have an important flaw. Some of the hashed keys may result in a large number of collisions. If those keys occur frequently, overall performance of a hash based packet classifier suffers. Although there is only limited or no existing locality in the data to be computed by a packet classifier, utilizing a cache can solve this problem. Unlike classical caches known from microprocessors, which are not adequate for packet classification and lookup algorithms, the proposed cache bases on a different strategy. It caches only the keys producing the most collisions instead of the ones that occur most often. That way, a cache improves the worst case performance of a hash function-based classifier. Based on simulation results, we show that even the mean performance improves significantly.
. Although the Internet has developed into a mass-medium for communication and information exchange over the last couple of years, many problems still exist regarding security and anonymity. One of these Achilles’ Heels is spam . Electronic mail (e-mail) has become one of the most used communication mechanism. It is absolutely easy to use and cost-effective. Unfortunately, the simplicity and effectiveness of e-mail are also major drawbacks. Without additional effort, Internet users’ mailboxes are flooded with unsolicited, bulk e-mails of many different flavors; mostly without any chance to identify the true origin. Thus, most anti-spam techniques rely on spam detection using large filter data bases and pattern matching functions but cannot identify the trustability of the sender. To overcome this lack of security and trustability, a new concept— Trust-by-Wire —is introduced as well as a mechanism called IPclip , which provides the basic means for enhanced e-mail security. The main idea is to guarantee Trust-by-Wire in packet-switched IP networks by providing trustworthy location information along with every IP packet. The availability of suchlike information in conjunction with some trust management is discussed in the light of a conceptual framework, which allows for reliably tracing the geographic origin of e-mails. IPclip furthermore provides an additional trigger for existing spam classification and filtering systems. Thereby, IPclip can neither be fiddled by benign e-mail users, nor by trojaned bots, nor by spammers.
During the last years, the Internet has grown into a mass-medium for communication and information exchange. Millions of people are using the Internet for business and in social life. Users can be reached easily and cost-effectively. Unfortunately the Internet's open structure is the reason for its frequent misuse for illegal and criminal actions such as dissembling phishing attacks. Thus, anti-phishing techniques are needed to recognize potential phishing threats. But mostly these techniques are only of reactive nature, are soon circumvented by expert frauds, or are not efficient enough. This paper describes an anti-phishing framework. A concept for trust management and a mechanism called IPclip are presented. The main idea of IPclip is to guarantee trust-by-wire in packet-switched networks by providing trustworthy location information along with every IP packet. This information is used as supplementary and trustworthy trigger to identify potential phishing threats. Besides, the proposed framework allows for tracing the threat's origin by using a set of location information.
Peter Danielis, Stephan Kubisch, Harald Widiger, Jens Schulz, Dirk Timmermann University of Rostock Institute of Applied Microelectronics and Computer Engineering 18051 Rostock, Germany Tel./Fax: +49 381 498-7272 / -1187251 Email: {peter.danielis;dirk.timmermann}@uni-rostock.de Web: http://www.imd.uni-rostock.de/networking Thomas Bahls, Daniel Duchow Nokia Siemens Networks GmbH & Co. KG Broadband Access Division 17489 Greifswald, Germany Tel./Fax: +49 3834 555-642 / -602 Email: {thomas.bahls;daniel.duchow}@nsn.com
During the last decades, the Internet has steadily developed into a mass medium with millions of users. On the one hand, newfangled services replace traditional ones. Naturally, these are thereby expected to offer at least the same features as their classical pendants, e.g., when VoIP replaces traditional fixed line telephone networks. On the other hand, the requirements on network infrastructures and services have changed. A reason for that is the lack of Trust-by-Wire in packet-switched IP networks. In traditional telephone networks, a phone number directly coheres with a physical line. This direct relationship is not given in modern packet-switched IP networks. An IP address does not identify a physical line! This paper presents a new mechanism, which guarantees Trust-by-Wire in packet- switched IP networks -called Internet Protocol-Calling Line Identification Presentation (IPclip). Unambiguous and trustworthy location information is added on the IP level. Firstly, IPclip's general functionality is presented. Secondly, we discuss IPclip in the light of location-aware emergency calls in nomadic VoIP environments.
The capabilities of passive optical networks (PONs) are strongly influenced by the quality of the used dynamic bandwidth allocation (DBA) algorithm. DBA algorithms control the assignment of available upstream bandwidth to the users connected to the PON. In an oversubscribed environment, that poses a challenge regarding the selection of an appropriate DBA algorithm. Therefore, DBA algorithms are subject of continuous research. To support efficient development and realistic evaluation of DBA algorithms, an FPGA-based hardware evaluation platform is presented. It supports fast implementation and evaluation of both hardware- and software-based algorithms. The evaluation process is featured by software tools, which are used to control stimulus creation. Furthermore, the results of changes in simulated user traffic can be analyzed on a connected workstation.
During the last decades, the Internet has steadily developed into a mass medium. The target group radically changed compared to, e.g., the 90s. Because virtually everyone has access to the Internet, threats due to insecurity and anonymity reach critical levels and have to be tackled by both carriers and Internet Service Providers. Regaining trust-by-wire, comparable to classic fixed line telephones, could mitigate or even solve problems like Spam, Phishing, and the localization of VoIP emergency calls. This paper presents the hardware implementation of a new and highly flexible solution-Internet protocol-calling line identification presentation-which provides additional support for new services to restore peoplepsilas confidence into the Internet. Supported services are VoIP emergency calls, Spam detection and prevention, and phishing prevention. Already in the access network, the hardware adds unambiguous location information on the packetpsilas origin to IP packets. We document the hardware design of the solution. Furthermore, hardware consumption and performance of a prototype are presented.
Selbst mit den neuesten Modellierungswerkzeugen und dem Einzug von Objektorientierung und Abstraktion in die Hardware-Entwicklung ist der Aufwand für die Verifikation immer noch bestimmend für den gesamten Entwurfsprozess. Wiederverwendbarkeit und Flexibilität sind deshalb aus ökonomischer Sicht unabdingbar. Es wird eine SystemC-Verifikationsumgebung vorgestellt, die sich besonders für paketverarbeitende Hardware und Systeme eignet. Der Fokus liegt dabei auf Wiederverwendbarkeit und leichte Portierbarkeit auf zukünftig zu verifizierende Designs. Weiterhin bietet dieses Framework die Möglichkeit, nicht nur textuelle Hardwarebeschreibungen während der verschiedenen Entwurfsschritte eines Designs zu verifizieren, sondern das Design auch zusätzlich auf der Zielplattform den gleichen Testfällen zu unterziehen, zum Beispiel auf einem Entwicklungsboard.
During the last years, Networks-on-Chip (NoCs) have become a true alternative for the design of complex integrated Systems-on-Chip (SoCs). Although NoCs are widely used in ASIC design for complex and multiprocessor SoCs, we mainly address NoCs on FPGAs where aspects like increasing design complexity, parasitics, and end-to-end latency have to be considered similarly. However, since NoCs are not yet matured in current design flows, EDA tools, and industrial applications, a lot of research is still necessary. Thus, one hot research area is the simulation and evaluation of NoCs in general and with regard to feasibility for a given application scenario [1]. This poster presents an evaluation IP core called ECore, which allows functional simulation and performance evaluation of NoC architectures. E-Core is implemented in VHDL on the register-transfer-level (RTL). It is derived from our high-level simulation environment previously presented in [2], [3]. Simulation and verification is feasible at every step in the design process: using abstract models in software for preliminary design space exploration, functional verification with common simulation tools, and evaluation in programmable hardware, which immensely speeds up simulation time, e.g., using FPGA prototyping boards. Section II describes some related work. Section III briefly presents the evaluation IP core. The paper concludes in Section IV.
In modern network applications and especially in Access Networks, the demands towards functionality and throughput are rising permanently. Furthermore, telecommunication carriers have different and changing requirements towards Access Network equipment. They are thus demanding a great deal of flexibility in IP-DSLAMS. To satisfy these various needs, highly flexible and particularly high performing packet processors are required. We propose an architecture for hardware modules, which joins the advantages of software and hardware solutions targeting packet processing. Our architecture provides a powerful and fast solution due to hardware implementation. Furthermore, it enables flexible and adaptive packet processors for different needs and configurations comparable to a software solution based on a network processor. This is accomplished without any overhead of unnecessary functionality and without the difficulties, which occur when it comes to adjusting pure ASIC packet processors to different tasks. Our architectural approach thus provides a good solution for packet processing.
The packet processing system MATMUNI is presented. It is implemented on an FPGA board and configurable at runtime via a graphical configuration tool. Two application scenarios are demonstrated.
In modern networks, the requirements towards network equipment rise together with the bandwidth. Customers and Internet service providers ask for more and more services like Voice-over-IP, IP-TV, and data services with a dependable quality. To satisfy these demands, the requirements towards packet classification as key functionality in network equipment, e.g., routers become overwhelming. We developed a packet classifier based on an evolvable hardware hash function and investigated its performance with real world data. The performance did show a reasonable degradation compared to random numbers. The computation time, which is required for evolving one generation in the genetic algorithm, corresponds to the actual fitness. We did find possibilities to maximize the speed of fitness evaluation by taking advantage of the fact, that the whole packet classifier including the fitness evaluation module is a pure hardware implementation based on FPGA technology. We were thus able to increase the performance of the evolvable packet classifier significantly while limiting the additional required hardware resources
In Ethernet-based access networks, network security plays a more significant role than in ATM-based access environments. We assume that in the foreseeable future Internet access can be established without using the conventional Point-to-Point protocol. Various scenarios already envisage straightforward delivery of selected IP services over Ethernet, e.g., forwarding of multicast services in Ethernet-based DSL access networks [1]. Traffic will be switched on Layer 2 without any further traffic separation by protocol encapsulation (Figure 1). Thus, access segments will be prone to typical Layer 2 attacks: MAC Address Spoofing & Flooding and Address Resolution Protocol (ARP) Spoofing as illustrated in Figure 2. Furthermore, customers demand newfangled services. Providers satisfy these wishes with modern multimedia services. New technologies provide the required bandwidth, e.g., GDSL [2]. Thus, increasing traffic and workload must already be handled in the first aggregation levels of an access network. It is necessary to move functionality towards the customer edge and to decentralize. Following, an approach for a simplified MAC Address Translation (sMAT) scheme for Ethernet-based DSL access networks is introduced. It addresses several relevant issues as discussed in [3]. sMAT focuses on security and
Communication networks today are facing an ever increasing network traffic as well as raising quality-of-service agreements, which together demand for high performance network routers. Since a router has to search a large set or routing rules for every incoming packet, it normally utilizes efficient search mechanisms, such as trees or hash tables. This paper evolves hash functions directly in hardware and also discusses an improved initialization process. On a benchmark test consisting of 65,536 routing rules, the final hash functions consume an average of about 1.3 memory accesses for rule searching for every incoming data packet.
Bandwidth demands of communication networks are rising permanently. Thus, the requirements to modern routers regarding packet classification are rising accordingly. Conventional algorithms for packet classification use either a huge amount of memory or have high computational demands to perform the task. Using a hash function in order to classify packets is promising regarding both memory and computation time. However, such a hash function needs to be of high performance and cheap in hardware costs. These two design goals are contradictory. To limit the costs of a hardware implementation, known good hash functions, as used for software implementations of encryption algorithms, are applicable to only a limited extend. To achieve the goals mentioned above, an adaptive hash function is needed. In this paper, an approach for a hardware packet classifier using an evolvable hash function is presented. It consists of an evolutionary algorithm which is entirely implemented in hardware.
Today, an increasing number of customers subscribes for a high bandwidth internet access. But not only speed is demanded. Reliability, availability, and security move more and more into the customers focus. Carriers and Internet Service Providers, too, have increasing requirements derived from new services they want to offer to their customers or use themselves. A hardware solution is presented, which provides the functionality of MAC Address Translation and Traffic Management. This solution is highly flexible and can be adapted to the providers’ needs. The module is implemented on a Field Programmable Gate Array (FPGA) and offers a wide range of functionality in an Access Network for relatively low costs. Additionally, the selection of an FPGA as implementation target offers the possibility to adapt the functionality to future needs by in-field reconfiguration.
Today, an increasing number of customers subscribes for a high bandwidth internet access. But not only communication speed is demanded. Quality of Service (QoS) moves more and more into the customers focus. Both Carriers and Internet Service Providers (ISPs) have increasing requirements derived from new services they want to offer to their customers. A new hardware solution is presented, which can satisfy many of these upcoming demands, the MPLS User Network Interface (MPLS-UNI). The solution offers reduced MPLS functionality to very cheap hardware costs. All incoming frames are provided with MPLS label stacks. From frames leaving the network the label stacks are removed. The MPLS-UNI works with wirespeed. Only a negligible delay is inserted into the data path.
Today, an increasing number of customers subscribes for a high bandwidth Internet access. But not only communication speed is demanded. Quality-of-service moves more and more into the customers' focus. Both carriers and Internet Service Providers (ISPs) have increasing requirements derived from new services they want to offer to their customers. We present a new hardware solution is presented, which can satisfy many of these upcoming demands. This solution is highly flexible and can be adapted to various applications. The MAC address translation - MPLS user network interface (MATMUNI) provides the functionality of MAC address translation (MAT), multi protocol label switching-user network interface (MPLS-UNI), and a traffic manager (TM). This way, a module implemented on a single FPGA offers a wide range of functionality in an access network for low costs and high flexibility. The selection of an FPGA as implementation target offers the possibility to adapt to future demands towards functionality. Moreover, the all functional elements work with wire speed. Only a negligible delay is inserted into the datapath