Network communication using the Internet Protocol (IP) is a pillar of modern Internet applications. IP allows data packets to travel the world through a complex set of interconnected computer networks managed by different operators. How IP-based data communication changes over time can be interesting from an end-system's perspective without relying on underlying network providers. This article presents an extensive, trace-driven analysis of user data traffic (covering five years of observations, six large Internet service providers (covering research, business and consumer category type), twenty autonomous systems, and fourteen countries. Our three primary findings are: i users data packet transmission paths are not deterministic and does not always select the geographically shortest path; ii) user packets take different routes that cover many countries and detour between two fixed points. Even after changing the types of Internet service provider type (e.g., from commercial to research), the routing can differ significantly between two locations. iii) Packet transmission delay can be influenced by changing the Internet service provider and IP protocol versions (i.e., from IPv4 to IPv6).
5G Standalone (SA) networks introduce the Subscriber Concealed Identifier (SUCI) and the 5G Authentication and Key Agreement (5G-AKA) protocol to eliminate the plaintext identity exposure of earlier generations. However, privacy leakage can persist through observable protocol behaviour rather than exposed identifiers. This paper presents an experimental evaluation of two such attack classes—the SUCI-catcher and the SQN inference attack—implemented as a transparent N2-interface proxy on a fully virtualised, 3GPP Release 16-compliant testbed built on OpenAirInterface, UERANSIM, and a custom NGAP proxy. The SUCI-catcher exploits the binary outcome of the 5G-AKA challenge-response exchange as a presence oracle, successfully recording SUCIs from six subscribers and confirming target presence without recovering any keying material, weakening location privacy and unlinkability in a controlled virtualised environment. The SQN inference attack recovers subscriber sequence-number bits through controlled synchronisation failures, accurately inferring 8 bits of SQN verified against ground-truth core network state, and demonstrating that SQN changes between observations track subscriber activity, weakening undetectability in a controlled virtualised environment. Both attacks share a structural dependency on abusing core-network authentication-vector generation. Operator-level rate-limiting and anomaly detection are identified as near-term mitigations; long-term protection requires protocol-level changes to 5G-AKA.
To build trust between patients and health institutions, implementing a privacy-preserving mechanism to handle personal health information is crucial. Therefore, federated learning (FL) is gaining popularity in health data analysis, due to its ability to enhance trustworthiness by sharing model-related information rather than data. Blockchain, with its decentralization, immutability, and traceability features, has also been integrated with FL to address existing privacy concerns. In this paper, we introduce FL+2, which is designed to address the infrastructural security and model-focused traceability challenges associated with FL-based medical analysis. FL+2 incorporates a first layer that utilizes a strict data transmission control mechanism using a P4 switch for infrastructural security. The second layer ensures model traceability (for better model privacy) and data access (including data delegation) control via blockchain. Here, we present the early results of the proposed FL+2 prototype, which was implemented in our in-house cloud/fog testbed. We discuss how a P4 switch as well as blockchain-based controlled data access and traceability mechanism offer specific security benefits and the associated development overhead.
The fifth generation (5G) of wireless communication offers gigabit-per-second speeds, ultra-low latency, and massive device connectivity. However, the introduction of network function virtualization (NFV), software-defined networking (SDN), network slicing, and mobile edge computing (MEC) has also created a complex security frontier. Addressing these challenges requires continuous and realistic validation of defenses in controlled experimentation environments. In this paper, we present an open-source, low-cost, fully software-based 5G testbed designed as a cyber range platform for security research and education. Built upon the OpenAirInterface (OAI) framework and commercial off-the-shelf hardware, the testbed supports an end-to-end 5G Stand-Alone (SA) deployment with gNodeB, core network, and user equipment (UE). It enables reproducible experimentation that may demonstrate a broad range of security scenarios, including privacy and tracking-based vulnerabilities like capturing user identifiers, as well as availability attacks such as Denial of Service (DoS) attacks targeting core network functions. The paper outlines our reproducible implementation and shares our experiences in building and operating the platform as a cyber range.
Modern smartphones, equipped with advanced mobile network technologies, deliver substantial computing capabilities, but they are energy-constrained because of battery capacity limitations. It is now feasible to offload computationally demanding tasks to cloud and fog computing infrastructures to overcome this limitation. A reliable network connection is required for stable communication between mobile devices and cloud or fog systems. This experimental campaign examines the reliability of mobile network connectivity during prolonged road trips, spanning approximately 44,000 km across Norway, Sweden, Denmark, Estonia, and Finland. We collected long-term latency and loss data to evaluate service quality and roaming performance, including cross-border transitions. Our findings reveal significant variability in network reliability, with frequent roaming events in certain countries, and occasional long service outages lasting up to 680 s. These results highlight the challenges of maintaining uninterrupted connectivity for critical services, in dynamic environments. This study provides a foundation for further large-scale investigations into mobile network resilience beyond the Nordic countries.
Network-based applications rely on the underlying network infrastructure to reliably forward packets between nodes. The way packets are forwarded has a significant impact on service quality. Therefore, it is important to gain a better understanding of data packet routes. To obtain detailed information about network paths, continuous and long-term packet analysis is required. To achieve this, we present our open-source framework HiPerConTracer 3.0 for large-scale IP trace analysis. It performs Ping and Traceroute measurements to provide detailed insights into packet routes and packet timing by tracing routes between senders and receivers in public and private networks. Particularly, it runs its own measurements, without need to obtain data, or cooperation from, the underlying network service providers or remote server owners. Our tool supports large-scale data collection, storage, and post-processing stages. It supports easy-to-understand route visualization, round-trip time measurements, and hop counts. A proof-of-concept analysis revealed that packet route lengths can change drastically when traveling through unexpected countries, regions, and network operators.
Fog computing is an intermediate layer between edge devices and cloud computing that provides execution support to minimize application delays. Fog aims at improving latency and the quality of experience. Unlike legacy monolithic systems, in which resources are tightly coupled, disaggregated architectures aim to improve resource utilization, scalability, and energy efficiency, while supporting various large-scale workloads. This paper proposes a data communication fabric for disaggregated hardware-architecture-based fog platforms. Particularly, it integrates an often-overlooked component, i.e., privacy as a core design principle. The proposed architecture focuses on distributed and decentralized network traffic management using a vector packet processing platform. To improve latency and privacy, we have presented a target disaggregated hardware and a communication mechanism for efficient data packet management at local and global levels. We demonstrated that vector-packet-processing-based switches outperform traditional Linux bridging, achieving higher throughput (up to $1.7 \mathrm{Gbit} / \mathrm{s}$ vs. 0.9 Gbit/s) and lower latency (under 1 ms kernel-space round-trip time).
This study investigates the dynamics of network latency optimizations, with a focus on the role of reflection server tuning. In an era marked by the demand for precise and low-latency network measurements, our exploration unveils the interplay of diverse parameters in achieving optimal performance. Notably, the implementation of a tuned profile on Linux emerges as a standout strategy, showcasing significant rewards in network efficiency. We highlight the importance of early acceptance of latency-critical traffic in the firewall chain and emphasize the cumulative impact of various optimizations. These findings have practical implications for network administrators and system architects, providing valuable insights for the deployment of efficient and low-latency network infrastructures, essential in the landscape of emerging technologies such as 5G networks and edge computing solutions.
With the booming development of blockchain technology, blockchain-based data transactions have been applied in many fields such as finance, healthcare and logistics. It can help users to realize data transactions and management more conveniently, securely, transparently and efficiently. However, there is a certain problem of identity privacy leakage when data transactions are conducted on blockchain. Therefore, the issue of user identity privacy protection has become the core issue of data transactions on the blockchain, which is crucial to the sustainable development and wide application of the blockchain. This paper discusses the privacy protection in the process of data transactions on blockchain in terms of user identity anonymity, introduces and analyzes in detail the current research status and implementation technologies for realizing identity anonymity on blockchain, explains the threats and challenges for realizing identity anonymity, analyzes the existing problems, and gives an outlook and summary of the future research directions for realizing identity anonymity on blockchain.
At present, smart contracts cannot guarantee absolute security, and they have exposed many security issues and caused incalculable losses. Due to the existence of these security vulnerabilities, researchers have designed many detection and classification tools to identify and discover them. In this article, we present a classification of smart contract security vulnerabilities based on a large number of detailed articles. Then, we introduce the latest smart contract vulnerability detection methods, summarize the process model of detection tools based on artificial intelligence methods, and compare and analyze various detection tools. Finally, we provide an outlook on future research directions based on the current status of smart contract security.
Cloud computing is now a ‘go-to’ platform for running various types of application. A wide spectrum of users needing software and hardware resources have embraced the cloud. Following the cloud business model, one is either a cloud-based service provider or a cloud service (hardware and software) user. There is a continuous evolution in the cloud ecosystem to support the ever-changing features of user applications. The cloud ecosystem has added a new resource delegation model to accommodate such new requirements. This new resource delegation model is known as fog. Both, cloud and fog platforms, employ complex hardware and software to provide better run-time support for applications. This paper presents a message-based privacy-aware application execution zone management framework for the cloud/fog platform. The framework aims to create a static execution zone based on the performance of the user application and the data privacy requirements. It also enables the user to set the resource termination conditions. Here, we have prototyped the proposed framework and showed how the proposed approach works with message structure and experiments with a P4 switch. We also present how the prototype could be implemented on a cloud/fog platform.
Optical networks are spanning the world. They are the main medium for carrying all types of data-traffic. From a vulnerability and security perspective, it is therefore the most important part of the network to protect against any physical impacts that may cause disruptions or security incidents. In this paper, we demonstrate and describe a scalable, low-cost monitoring system based on detecting the state of polarisation in the fibre cables. We give examples on how any direct movement of fibre-cables or fibre-cords as well as indirect vibrations on the cable can be detected, and how basic characteristics in the patterns can be used for recognition of these events.
Cloudified mobile networks are expected to deliver a multitude of services with reduced capital and operating expenses. A characteristic example is 5G networks serving several slices in parallel. Such mobile networks, therefore, need to ensure that the SLAs of customised end-to-end sliced services are met. This requires monitoring the resource usage and characteristics of data flows at the virtualised network core, as well as tracking the performance of the radio interfaces and UEs. A centralised monitoring architecture can not scale to support millions of UEs though. This paper, proposes a 2-stage distributed telemetry framework in which UEs act as early warning sensors. After UEs flag an anomaly, a ML model is activated, at network controller, to attribute the cause of the anomaly. The framework achieves 85% F1-score in detecting anomalies caused by different bottlenecks, and an overall 89% F1-score in attributing these bottlenecks. This accuracy of our distributed framework is similar to that of a centralised monitoring system, but with no overhead of transmitting UE-based telemetry data to the centralised controller. The study also finds that passive in-band network telemetry has the potential to replace active monitoring and can further reduce the overhead of a network monitoring system.
IT systems monitoring is a crucial process for managing and orchestrating network resources, allowing network providers to rapidly detect and react to most impediment causing network degradation. However, the high growth in size and complexity of current operational networks (2022) demands new solutions to process huge amounts of data (including alarms) reliably and swiftly. Further, as the network becomes progressively more virtualized, the hosting of NFV on cloud environments adds a magnitude of possible bottlenecks outside the control of the service owners. In this paper, we propose two deep learning anomaly detection solutions that leverage service exposure and apply it to automate the detection of service degradation and root cause discovery in a cloudified mobile network that is orchestrated by ETSI OSM. A testbed is built to validate these AI models. The testbed collects monitoring data from the OSM monitoring module, which is then exposed to the external AI anomaly detection modules, tuned to identify the anomalies and the network services causing them. The deep learning solutions are tested using various artificially induced bottlenecks. The AI solutions are shown to correctly detect anomalies and identify the network components involved in the bottlenecks, with certain limitations in a particular type of bottlenecks. A discussion of the right monitoring tools to identify concrete bottlenecks is provided.
Most of today’s IP traffic is cloud traffic. Due to a vast, complex and non-transparent Internet infrastructure, securely accessing and delegating data is not a trivial task. Existing technologies of Information-Centric Networking (ICN) make content distribution and access easy while primarily relying on the existing cloud-based security features. The primary aim of ICN is to make data independent of its storage location and application. ICN builds upon traditional distributed computing, which means ICN platforms also can suffer from similar data security issues as distributed computing platforms. We present our ongoing work to develop a secure, proactive data distribution framework. The framework answers the research question, i.e., How to extend online data protection with a secure data distribution model for the ICN platform? Our framework adds a data protection layer over the content distribution network, using blockchain and relying on the fog to distribute the contents with low latency. Our framework is different from the existing works in multiple aspects, such as i) data are primarily distributed from the fog nodes, ii) blockchain is used to protect data and iii) blockchain allows statistical and other information sharing among stakeholders (such as content creators) following access rights. Sharing statistics about content distribution activity can bring transparency and trustworthiness among the stakeholders, including the subscribers, into the ICN platforms. We showed such a framework is possible by presenting initial performance results and our reflections while implementing it on a cloud/fog research testbed.
Mobile devices are becoming ubiquitous in our daily lives, but they have limited computational capacity. Thanks to the advancement in the network infrastructure, task offloading from resource-constrained devices to the near edge and the cloud becomes possible and advantageous. Complete task offloading is now possible to almost limitless computing resources of public cloud platforms. Generally, the edge computing resources support latency-sensitive applications with limited computing resources, while the cloud supports latency-tolerant applications. This paper proposes one lightweight task-scheduling framework from cloud service provider perspective, for applications using both cloud and edge platforms. Here, the challenge is using edge and cloud resources efficiently when necessary. Such decisions have to be made quickly, with a small management overhead. Our framework aims at solving two research questions. They are: (i) How to distribute tasks to the edge resource pools and multi-clouds? (ii) How to manage these resource pools effectively with low overheads? To answer these two questions, we examine the performance of our proposed framework based on Reliable Server Pooling (RSerPool). We have shown via simulations that RSerPool, with the correct usage and configuration of pool member selection policies, can accomplish the cloud/edge setup resource selection task with a small overhead.
Accurately measuring Round-Trip Times (RTT) for Internet communications is important for various research topics, ranging from protocol performance and congestion control to routing and network security. Unix systems, particularly Linux and FreeBSD, provide some features to obtain network packet timing information, but there is a lack of documentation for these. With High-Performance Connectivity Tracer (HiPerConTracer), there is already an open source tool for running large-scale, long-running and high-frequency ICMP Ping and Traceroute measurements. However, it lacks support of high-precision timing. As part of this paper, first the network packet timestamping features of Unix systems are analysed and introduced, to provide the reader with a detailed overview over the available methods, their usage, as well as their limitations. Then, enhancements to HiPerConTracer are presented for adding high-precision timestamping support, as well as a UDP module to also perform UDP Ping and Traceroute measurements. Finally, the newly added features are demonstrated in a proof-of-concept analysis.
Cloud computing makes complex processing an off-premise activity by offering software- and hardware-based services using standard security protocols over the Internet. It has been seen that the cloud is not ideal for latency-sensitive applications. Thanks to the current growth of network communication and infrastructure, fog adds a computing resource delegation model between the user and the cloud. Fog aims to improve latency-sensitive applications support. Here, we propose one unified, proactive resource orchestration framework from a cloud/fog service provider perspective. The framework consists of a predictor and a resource allocator module. Users subscribe to these resources to execute their applications. The framework is modular and does not require application-specific information. A service provider can customise each module. We have presented the framework prototype by showing each module's simulated performance results using the parameters of our cloud/fog research testbed.
Our dependency on the telecommunication infrastructure is continuously increasing, as different infrastructures – such as energy and telecommunication – now have mutual dependencies. This calls for increased monitoring of the fibre network, which is a highly critical part of the infrastructure. State of Polarisation (SoP) of light propagating through fibre transmission systems is impacted by any vibrations and mechanical impacts on the fibre. By continuously monitoring the SoP, any unexpected movements of a fibre along a fibre-path may be traced. Movements may be caused by e.g. work in node-rooms impacting patch-cords, trawlers or other types of sub-sea equipment touching or hooking into sub-sea fibre cables, digging close to a fibre-cable, or geophysical phenomena like earthquakes. In this paper, we describe a low-cost, scalable system for SoP monitoring and give examples of patterns monitored in different types of fibre infrastructures. The monitoring system consists of single-unit rack-mount instruments connected to taps from live optical transmission signals. Each instrument has local storage for 1-2 years of data, and is periodically automatically uploading data to a server for backup and data-access purposes. Examples of observed patterns are impact from a thunderstorm on a Fibre-To-The-Home (FTTH) cable, 50 Hz on a fibre-cable spun around a high-voltage power air-cable, as well as animal impact on a patch-cord.
Internet infrastructure is becoming ubiquitous thanks to the advancement in computing and the network domain. Reliable network communication is essential to offer good quality services, but it is not trivial. There are privacy concerns. Metadata may leak user information, even if traffic is encrypted. Some countries have data privacy preserving-related regulations, but end-users cannot control how their data packets should travel through networks. Even worse, the user cannot declare their privacy preferences. This paper presents an approach to tackle such privacy issues through data privacy-aware routing, where users can specify their preferences for packet routing using marking and filtering. Routing can work according to such specifications. It is implemented by P4, allowing a vendor-independent realisation with standard off-the-shelf hardware and open-source software components. We presented the initial experimental results of a proof-of-concept test on a unified cloud/foe research testbed.