Marco Häberle

dblp:239/5155 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
5since 2021 · last 2025
0000-0003-3160-3931ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 ELVIS: eBPF-based extensions of linux hosts for using virtual network functions with service function chaining and in-band network telemetry
abstract
Service function chaining (SFC) is a technology that enables dynamic steering of packets to processing nodes, also called Service Functions (SFs), e.g., firewalls, IDSs, or NAT gateways. An SFC classifier located at the border of SFC-enabled domains encodes information about the order of SFs, the Service Function Chain, into packet headers. This encoded information, called SFC encapsulation, is used by the network to steer packets to the respective SFs. Because most existing SFs do not support SFC encapsulations natively, a proxy is required to make them SFC-compatible. However, simple proxies operate in a stateless manner and are not capable of preserving per-packet metadata. In this paper, we propose a dynamic SFC proxy that is capable of preserving metadata by caching the SFC encapsulation while a packet is processed by a SF. In addition, the proxy implements In-band Network Telemetry (INT) to support monitoring and debugging related to SFs. INT is a network monitoring framework that adds packet-specific metrics to the header stack of a packet. Although INT has been standardized with a focus on network switches and routers, a proxy-based implementation for SFs extends its usability in an SFC scenario. We present concept, use cases, and an eBPF-based implementation of the INT-enabled caching SFC proxy. Finally, we evaluate the performance of a prototype.
Marco Häberle, Benjamin Steinert, Michael Menth
Comput. Networks1
2023 P4-LISP: A P4-Based High-Performance Router for the Locator/Identifier Separation Protocol
abstract
The networking paradigm locator/identifier split decouples locating and identifying functionality of addresses. Thereby it improves multi-homing, fail-over, mobility, traffic engineering over the Internet, and routing scalability.The Locator/Identifier Separation Protocol (LISP) is a prominent incarnation of that paradigm which recently became an Internet standard. However, existing LISP implementations are either proprietary or have limited performance, which makes their deployment difficult in high-speed networks. Programming Protocol-independent Packet Processors (P4) is a programming language that facilitates the implementation of custom data plane processing on high-performance switches with line rates of up to 400 Gbit/s.In this work, we present P4-LISP, an open-source P4-based proof of concept implementation of a high-performance LISP router. It supports all relevant features such as ITR, ETR, RTR, P-ITR, P-ETR, NAT-traversal, LISP-NAT, and mobile nodes. As control plane, the open-source implementation lispers.net has been integrated on the switch. Security features are added to protect the control plane from being overloaded by the high-performance data plane. The paper describes the architecture of P4-LISP in detail and extensively evaluates performance, functionality, controller performance, and overload protection.
Benjamin Steinert, Marco Häberle, Jan-Oliver Nick, Dino Farinacci, Michael Menth
NetSoft2
2023 A survey on data plane programming with P4: Fundamentals, advances, and applied research
Frederik Hauser, Marco Häberle, Daniel Merling, Steffen Lindner, Vladimir Gurevich, Florian Zeiger, Reinhard Frank, Michael Menth
J. Netw. Comput. Appl.2
2022 Secure Service Function Chaining in the Context of Zero Trust Security
abstract
Service Function Chaining (SFC) enables dynamic steering of traffic through a set of service functions based on classification of packets, allowing network operators fine-grained and flexible control of packet flows. New paradigms like Zero Trust (ZT) pose additional requirements to the security of network architectures. This includes client authentication, confidentiality, and integrity throughout the whole network, while also being able to perform operations on the unencrypted payload of packets. However, these requirements are only partially addressed in existing SFC literature. Therefore, we first present a comprehensive analysis of the security requirements for SFC architectures. Based on this analysis, we propose a concept towards the fulfillment of the requirements while maintaining the flexibility of SFC. In addition, we provide and evaluate a proof of concept implementation, and discuss the implications of the design choices.
Leonard Bradatsch, Marco Häberle, Benjamin Steinert, Frank Kargl, Michael Menth
LCN2
2022 A Caching SFC Proxy Based on eBPF
abstract
Service Functions (SFs) are intermediate processing nodes on the path of IP packets. With SF chaining (SFC), packets can be steered to multiple physical or virtual SFs in a specific order. SFC-unaware SFs can be used flexibly but they do not support SFC-specific encapsulation of packets. Therefore, an SFC proxy needs to remove the encapsulation of a packet before processing by an SFC-unaware SF, and to add it again afterwards. Such an SFC proxy typically runs on a server hosting virtual network functions (VNFs) that serve as SFs. Simple SFC proxies adapt a flow-specific static header stack. That is, each VNF requires an own SFC proxy, and the proxy cannot be extended to support per-packet metadata in the SFC encapsulation. The caching SFC proxy presented in this work caches packet-specific headers while packets are processed by a VNF, i.e., packet-specific header information is preserved. We present concept, use cases, and an eBPF-based implementation of the caching SFC proxy. In addition, we evaluate the performance of a prototype.
Marco Häberle, Benjamin Steinert, Michael Menth
NetSoft1
2020 P4 In-Network Source Protection for Sensor Failover
Steffen Lindner, Marco Häberle, Florian Heimgaertner, Naresh Nayak 0001, Sebastian Schildt, Dennis Grewe, Hans Löhr, Michael Menth
Networking2