Günter Schäfer

dblp:64/4710 · also Guenter Schaefer · DBLP profile ↗
← Back
52ranked-venue papers
0as first author
6since 2021 · last 2026
0000-0002-3506-7702ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 25Security and privacy · 11 · 6 since 2021Systems, architecture and hardware · 5Human-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 Automated Distribution of Out-of-Band Key Material in Virtual Private Networks
David Schatz, Hedwig Koerfgen, Günter Schäfer
ICISSP (2)3
2025 On the Security of Opportunistic Re-Keying
abstract
Asymmetric cryptography is a cornerstone for security in modern IT infrastructures like virtual private networks (VPNs). Unfortunately, the security of currently deployed schemes is threatened by the ongoing research in quantum computing. And while quantum-resistant alternatives exist, known as post-quantum cryptography (PQC), analyses regarding their (implementation) security are not as mature, yet. Consequently, solely relying on PQC might be susceptible to “store now, decrypt later” attacks. Instead, many researchers suggest using “hybrid” key exchanges, e.g., combining classical asymmetric cryptography, PQC, and symmetric alternatives like quantum key distribution (QKD) and multipath key reinforcement (MKR). In this article, we formalize the idea of “opportunistic re-keying”, where a session key is continuously updated using input key material that might be known or even chosen by an attacker. Assuming that at least one input key material is not known to the attacker, we prove th e security of the construction in the random oracle model. I.e., when an ideal random function is used for combining the current internal state and new input to generate the next session key and state. Further, we suggest two concrete parameter sets for the construction, corresponding to the security categories 3 and 5 of the NIST standardization process for PQC.
Stefan Lucks, David Schatz, Günter Schäfer
SECRYPT3
2023 Evaluating Statistical Disclosure Attacks and Countermeasures for Anonymous Voice Calls
abstract
Assuming a threat model of a global observer, statistical disclosure attacks have been proposed to efficiently de-anonymize communication relationships in text-based mix networks over time. It is commonly assumed that such attacks are also able to disclose call relationships in anonymous communication networks (ACNs) that support voice calls. One straightforward countermeasure is to expect users to permanently send and receive packets that mimic a Voice over IP (VoIP) call. However, this is not practical in real world scenarios, like on mobile devices. In this article, we adapt one specific statistical disclosure attack (Z-SDA-MD) to voice calls and quantitatively study less resource-intensive countermeasures. As base countermeasure, we evaluate a round-based communication model, corresponding to a timed mix. A simulation study of this scenario shows that the Z-SDA-MD is not well suited for a general disclosure of call relationships because of too many false positives. Nevertheless, the attack is able to correctly identify the most frequent relationships. Still, the accuracy in that regard may significantly be decreased by increasing the duration of one round, by decoupling actions (call setup and teardown) of caller and callee by a random number of rounds, and by occasional fake calls to a fixed set of “fake friends”. Overall, our study shows that anonymous voice calls may be implemented with an acceptable trade-off between anonymity, call setup time, and bandwidth overhead.
David Schatz, Michael Roßberg, Günter Schäfer
ARES3
2023 Virtual Private Networks in the Quantum Era: A Security in Depth Approach
David Schatz, Friedrich Altheide, Hedwig Koerfgen, Michael Roßberg, Günter Schäfer
SECRYPT5
2021 Optimizing Packet Scheduling and Path Selection for Anonymous Voice Calls
abstract
Onion routing is a promising approach to implement anonymous voice calls. Uniform-sized voice packets are routed via multiple relays and encrypted in layers to avoid a correlation of packet content in different parts in the network. By using pre-built circuits, onion encryption may use efficient symmetric ciphers. However, if packets are forwarded by relays as fast as possible—to minimize end-to-end latency—network flow watermarking may still de-anonymize users. A recently proposed countermeasure synchronizes the start time of many calls and batch processes voice packets with the same sequence number in relays. However, if only a single link with high latency is used, it will also negatively affect latency of all other calls. This article explores the limits of this approach by formulating a mixed integer linear program (MILP) that minimizes latency “bottlenecks” in path selection. Furthermore, we suggest a different scheduling strategy for voice packets, i.e. implementing independent de-jitter buffers for all flows. In this case, a MILP is used to minimize the average latency of selected paths. For comparison, we solve the MILPs using latency and bandwidth datasets obtained from the Tor network. Our results show that batch processing cannot reliably achieve acceptable end-to-end latency (below 400 ms) in such a scenario, where link latencies are too heterogeneous. In contrast, when using de-jitter buffers for packet scheduling, path selection benefits from low latency links without degrading anonymity. Consequently, acceptable end-to-end latency is possible for a large majority of calls.
David Schatz, Michael Roßberg, Günter Schäfer
ARES3
2021 Hydra: Practical Metadata Security for Contact Discovery, Messaging, and Dialing
abstract
Communication metadata may leak sensitive information even when content is encrypted, e.g. when contacting medical services. Unfortunately, protecting metadata is challenging. Existing approaches for anonymous communications either are vulnerable in a strong (but feasible) threat model or have practicability issues like intense usage of asymmetric cryptography. We propose Hydra, a mix network that is able to provide multiple anonymous services in a uniform way. In contrast to previous messaging systems with strong anonymity, we deliberately use padded onion-encrypted circuits. This allows to support connectionless applications like contact discovery with authenticated key exchange, messaging, and dialing (signalling for connection-oriented communications) with strong anonymity and relatively low latency. Our cryptography benchmarks show that Hydra is able to process messages an order of magnitude faster than state of the art messaging systems with strong anonymity. At the same time, bandwidth overhead is comparable to previous systems. We further develop an analytical model to predict the end-to-end latency of Hydra and validate it in a testbed.
David Schatz, Michael Roßberg, Günter Schäfer
ICISSP3
2020 Vector packet encapsulation: the case for a scalable IPsec encryption protocol
abstract
The IPsec protocol family, although not always undisputed, has shown to be extremely reliable over the last two decades. However, given the fact that communication networks evolved tremendously since ESP was standardized, this paper proposes changes to the security protocol to accommodate for the needs of modern wide area and data center networks. In particular it addresses optimizations for high-speed software implementations as well as use cases in data center networks. The evaluation shows that rather small yet targeted changes are sufficient to allow for more flexible and scalable implementations.
Michael Pfeiffer 0006, Franz Girlich, Michael Roßberg, Günter Schäfer
ARES4
2020 Poster: Seamless Client Integration for Fast Roaming in Wireless Mesh Networks
Martin Backhaus, Markus Theil, Michael Roßberg, Günter Schäfer
Networking4
2020 Seamless Multimedia Streaming in Controller-Less Wireless Mesh Networks With Mobile Stations
Markus Theil, Martin Backhaus, Michael Roßberg, Günter Schäfer
Networking4
2020 Feedback-Based Hidden-Terminal Mitigation for Distributed Scheduling in Cellular V2X
Philip Wendland, Günter Schäfer
Networking2
2020 Improving Network-Assisted Roaming for Controller-Less Wi-Fi
abstract
Large Wi-Fi installations may make use of Wi-Fi controllers managing client mobility and different Virtual Local Area Networks (VLANs). However, as they might form a bottleneck, controller-less solutions are on the rise, e.g., cloud-managed solutions or mesh networks. IEEE 802.11 defines a framework for providing roaming assistance through neighbor reports and transition requests (IEEE 802.11k and IEEE 802.11v), but leaves generating meaningful candidates included in these frames open to the implementor. Without central controllers, deriving these candidates for Stations (STAs) is much more difficult. Access Points (APs) with more autonomy need to know other APs located in their proximity to provide roaming assistance for STAs. In this paper, we design and evaluate a network-assisted roaming architecture for controller-less Wi-Fi networks. APs learn roaming events in their vicinity and steer STAs by means of refined, yet standard-compliant neighbor reports and transition requests to better suited APs. Our results using a real-system prototype indicate a noticeable decrease of roaming times when comparing various reference approaches to our proposal.
Martin Backhaus, Markus Theil, Michael Roßberg, Günter Schäfer
PIMRC4
2020 Towards the Complexity of the Widest Path Problem in Hybrid Multi-Channel WMNs
abstract
Finding a widest path to transmit the maximum possible data rate is well-known in the field of computer science. For computational complexity, the network type has a significant impact: It is relatively easy to solve for simple graphs, whereas it is NP-complete for wireless networks based on slotted time models. These models neither facilitate the problem of finding widest paths, nor are they best suited to reflect realistic networks based on IEEE802.11. Therefore, this paper studies the widest path problem for hybrid multi-channel Wireless Mesh Networks (WMNs) without slotted time. In our model, wireless data rates are equally shared among edges within interference range. We prove NP-completeness of the widest path problem (even for a simpler model), but heuristics already demonstrated good results in practical settings.
Martin Backhaus, Günter Schäfer
WiMob2
2020 Robustness and Scalability Improvements for Distance Vector Routing in Large WMNs
abstract
IEEE 802.11s enables rapid deployment of Wireless Mesh Networks (WMNs) to supply basic wireless connectivity for client hardware. Application of distance vector based routing protocols proved advantageous in WMNs for efficiency, i.e., low overhead. However, it remains unclear, if plain distance vector routing protocols allow for adequate robustness against outages in large installations. Particularly, the required time for routing re-convergence may be too long, as in practice, the count-to-infinity phenomenon needs to be dealt with. This paper proposes Spare Forwarding Entries (SFEs), resulting in a proactive mechanism improving robustness against outages when compared to the reactive behavior of distance vector protocols. It works as an extension of distance vector operation, i.e., efficiency can be preserved. We integrate SFE into the well-known Babel routing protocol and also propose measures to increase scalability. Simulation studies indicate that SFEs improve robustness against node outages significantly. In certain scenarios, the Packet Delivery Ratio (PDR) was doubled with our mechanisms in place. Further modifications let Babel-based WMNs scale up to 300 nodes. Moreover, convergence times and overhead are significantly smaller.
Martin Backhaus, Markus Theil, Michael Roßberg, Günter Schäfer
WiMob4
2019 Strong Tenant Separation in Cloud Computing Platforms
abstract
Cloud computing, with its large, homogeneous infrastructures, has a high sensitivity to security incidents due to the multitude of affected services and tenants. To contain a potential attacker within a compromised subsystem, a strict separation between individual resources, e.g. virtual servers and networks, must be established. However, this separation usually relies on the integrity of the entire cloud platform. Due to the considerable size and complexity of the software powering these platforms and recently found attacks on hardware components, i.e. Spectre and Meltdown, this may not always represent a reasonable assumption.
Michael Pfeiffer 0006, Michael Roßberg, Simon Buttgereit, Günter Schäfer
ARES4
2019 Towards a Security Architecture for Hybrid WMNs
abstract
Currently deployed Wireless Mesh Networks (WMNs) are mostly hybrid, i.e., some Mesh Points (MPs) also employ additional Access Point (AP) radios to connect non-mesh stations (STAs). Today's Wi-Fi security protocols are unsuited in the use case of WMNs, as they can neither derive key material without central authentication servers nor tolerate compromised MPs, as it is required in outdoor deployments. To establish high security standards while embracing the distributed nature of WMNs, we need a novel security architecture, that does not rely on central entities and protects traffic between MPs with End-to-End Encryption (E2EE). We propose and evaluate a distributed security architecture for WMNs with attached APs, which uses certificates early in the authentication process. The architecture provides E2EE between MPs and authentic MAC addresses of all STAs and MPs. STAs, e.g., resource constrained Internet of Things (IoT) devices, cannot participate in the end-to-end encryption, but need to be securely attached to the WMN with mobility and other requirements in mind. The evaluation in our Wi-Fi testbed shows the authentication protocol's suitability for fast (re-)authentication in mobile scenarios.
Markus Theil, Martin Backhaus, Michael Roßberg, Günter Schäfer
ARES4
2018 A Comprehensive Framework to Evaluate Wireless Networks in Simulation and Real Systems
abstract
A thorough performance evaluation of protocols and algorithms for (wireless) networks requires simulation and real-system experiments, as both of them provide individual benefits. Usually, this calls for two separate implementations: One tailored to a discrete-event simulator and a second designed to run on real hardware. Therefore, significant effort is required to implement the same mechanisms or protocols twice. To avoid this overhead, we propose a comprehensive framework based on DPDK and OMNeT ++, allowing to run simulations and real-system experiments from the very same codebase. Hence the best of both worlds is available: scalable scenarios and reproducibility when simulating, and realistic behavior and real-world performance metrics when running real-system experiments. Our evaluation of several representative real-world networking scenarios analyzes similarities between simulation and real-system results and discusses the framework qualitatively. Quantitative results indicate that the approach performs well, i.e., it allows even for productive deployment using the codebase later on, and results from both worlds are comparable.
Martin Backhaus, Markus Theil, Michael Roßberg, Günter Schäfer, David Sukiennik
DS-RT4
2018 Towards a Flexible User-Space Architecture for High-Performance IEEE 802.11 Processing
abstract
Exploiting bandwidth potentials and managing complexity of current and future IEEE 802.11 networking standards becomes increasingly difficult when using today's operating system kernels and high-throughput wireless network interfaces due to overhead caused by interrupts and kernels of complex general-purpose operating systems. These problems can be tackled by employing special purpose forwarding planes deeply integrated with wireless drivers. To do so we propose a user-space implementation of drivers and Wi-Fi stack, built upon the Data Plane Development Kit (DPDK) from the wired world. This allows for scalable frame processing, as well as flexible and easy experimenting with new protocols and approaches (compared to kernel development). Our prototypic evaluation reveals that user-space processing of IEEE 802.11 frames can increase throughput and decrease delay of a wireless connection significantly, e.g., 100% more throughput for small frames and 27% less delay. We also point out common obstacles when adapting wireless drivers from kernel to user space and provide advice on how to overcome them. The code base is made publicly available.
Martin Backhaus, Markus Theil, Michael Roßberg, Günter Schäfer
WiMob4
2017 Towards construction of efficient and optimally resilient VPN topologies by exactly calculating Maximum Disjoint Paths
abstract
By carefully selecting and establishing overlay edges and computing multiple underlay-edge-disjoint paths, the ability to still fulfill demands in a VPN in case of edge-failures can be significantly increased. This article presents an approach to construct efficient and optimally resilient VPN overlay topologies together with the corresponding overlay paths to fulfill a given set of demands (connectivity between pairs of nodes). For this, we developed an Integer Linear Programming (ILP) formulation for exactly calculating the metric of Maximum Disjoint Paths in two-layer network topologies which also computes the respective overlay paths. By careful adaptation of the ILP formulation, it is possible to compute solutions for networks of significant size. Based on this ILP, an algorithm is presented that computes efficient and optimally stable overlay topologies. An evaluation of a typical VPN networking scenario shows that compared to the obvious approach of realizing maximal possible connectivity by a fully meshed overlay, our approach reaches the same desired connectivity with far fewer overlay edges.
Martin Backhaus, Günter Schäfer
ICC2
2017 Covert-channel-resistant congestion control for traffic normalization in uncontrolled networks
abstract
Traffic normalization, i.e. enforcing a constant stream of fixed-length packets, is a well-known measure to completely prevent attacks based on traffic analysis. In simple configurations, the enforced traffic rate can be statically configured by a human operator, but in large virtual private networks (VPNs) the traffic pattern of many connections may need to be adjusted whenever the overlay topology or the transport capacity of the underlying infrastructure changes. We propose a rate-based congestion control mechanism for automatic adjustment of traffic patterns that does not leak any information about the actual communication. Overly strong rate throttling in response to packet loss is avoided, as the control mechanism does not change the sending rate immediately when a packet loss was detected. Instead, an estimate of the current packet loss rate is obtained and the sending rate is adjusted proportionally. We evaluate our control scheme based on a measurement study in a local network testbed. The results indicate that the proposed approach avoids network congestion, enables protected TCP flows to achieve an increased goodput, and yet ensures appropriate traffic flow confidentiality.
Martin Byrenheid, Michael Roßberg, Günter Schäfer, Robert Dorn
ICC3
2017 Towards optimally resilient topologies against optimal attacks
abstract
By overlay topology optimization with regard to the minimum number of overlay edges that need to breakdown until all communication between two chosen nodes ceases, the robustness against optimal attacks can be maximized and the network can still perform its operation despite (multiple) link-failures. This article presents an approach to construct optimally resilient topologies on the basis of a metric used by an optimal attacker: the minimum overlay cut. We developed a bilevel Integer Linear Program (ILP) formulation for exactly calculating optimal overlay topologies on small problem instances consisting of two-layer networks. Since bilevel optimization is very hard to perform in practice on bigger networks, we propose an approximation algorithm as well, whose quality can be assessed on smaller instances. An evaluation of a typical VPN networking scenario shows that compared to the obvious approach of realizing maximal robustness towards attackers by a fully meshed overlay, our approach reaches the same desired connectivity with far fewer overlay edges.
Martin Backhaus, Günter Schäfer
IM2
2017 Worst-case attacker models for two-layered networks based on the Minimum Overlay Cut
abstract
Appropriate attacker models are generally known to be a fundamental prerequisite for any security evaluation of complex systems or networks. This paper deals with worst-case attacker models targeted to cause maximum damage in an overlay network by deliberately disturbing links within the underlying transport network topology. The flexibility of rerouting in underlay and overlay networks leads to complex dynamics in the topology of such two-layered overlay networks, which needs to be appropriately considered in attacker modeling. In this article, we present two worst-case attacker models based on the Minimum Overlay Cut, which either try to maximize network damage with a given number of possible outages, or aim at a given level of damage with minimal effort. For this, we developed a novel Integer Linear Programming (ILP) formulation for the Minimum Cut, that uses less binary variables than existing approaches, and is therefore better suited to deal with larger networks as well as multiple demands. An evaluation of a typical VPN overlay scenario shows that our worst-case models give significantly more realistic assessments of potential damages than two alternatively evaluated random and greedy strategies.
Martin Backhaus, Günter Schäfer
ISCC2
2017 Parcus: Energy-Aware and Robust Parallelization of AUTOSAR Legacy Applications
abstract
Embedded multicore processors are an attractive alternative to sophisticated single-core processors for the use in automobile electronic control units (ECUs), due to their expected higher performance and energy efficiency. Parallelization approaches for AUTOSAR legacy software exploit these benefits. Nevertheless, these approaches focus on extracting performance neglecting the system's worst-case sensor/actuator latency and energy consumption. This paper presents Parcus, an energy-and latency-aware parallelization technique that combines both runnable-and tasklevel parallelism. Parcus explicitly models the traversal of data from sensor to actuator through task instances, enabling to consider the latency imposed by parallelization techniques. The parallel schedule quality (PSQ) metric quantifies the success of the parallelization, for which it takes the latency and the processor frequency into account. We demonstrate the applicability of Parcus with an automotive case study. The results show that Parcus can fully utilize the processor's energy-saving potential.
Sebastian Kehr, Eduardo Quiñones, Dominik Langen, Bert Böddeker, Günter Schäfer
RTAS5
2016 Supertask: Maximizing runnable-level parallelism in AUTOSAR applications
Sebastian Kehr, Milos Panic, Eduardo Quiñones, Bert Böddeker, Jorge Becerril Sandoval, Jaume Abella 0001, Francisco J. Cazorla, Günter Schäfer
DATE8
2015 Parallel execution of AUTOSAR legacy applications on multicore ECUs with timed implicit communication
abstract
Parallelization of AUTOSAR legacy applications is a fundamental step to exploit the performance of multi-core ECUs (MCEs). However, the migration of an application from a single-core ECU (SCE) to a MCE presents two challenges: first, the extraction of parallelism from an application (composed of tasks) is not always possible due to communication among tasks. Second, reproducing the same data-flow on all target MCEs is required to guarantee the same (predictable) functional behaviour without exhaustive validation and testing efforts. This paper introduces timed implicit communication (TIC) for decoupling task communication to allow parallel execution of producer and consumer, while the same data-flow is achieved on all MCEs. Therefore, AUTOSAR implicit communication is applied at task-level and extended by defined communication times, which are derived from the original SCE configuration. This is realized by storing produced data in a buffer with a publication timestamp attached. TIC is implemented at AUTOSAR RTE level and does not require modification of source code.
Sebastian Kehr, Eduardo Quiñones, Bert Böddeker, Günter Schäfer
DAC4
2015 Towards a model for global-scale backbone networks
abstract
Synthetic network models play an integral role in nowadays research of computer networks. This is for the lack of real network data and to perform experiments with a statistical significant number of replications. While most of the modeling work currently focuses on layer 3 topologies, e.g., AS level, this work is on generating realistic layer 1 topologies. These topologies are of fundamental significance for network resilience, for example. By constructing β-skeleton graphs, augmented with population and technology indications, our approach is able to generate highly realistic graphs. This is shown by a comparison to US networks, whose topology is publicly available.
Michael Grey, Markus Theil, Michael Roßberg, Günter Schäfer
ICC4
2015 Program partitioning based on static call graph analysis for privilege separation
abstract
The major cause of IT security incidents are software issues, hence this article presents an automated approach for source code partitioning and privilege separation. Based on static call graph analysis, functions and program parts of a monolithic software are separated in several processes and grouped by the privilege they need. For the partitioning we introduce a metric that estimates the potential security gain by considering the complexity and privilege distribution of the separated software. Furthermore, we present a partitioning heuristic that uses this metric to create a secure software partitioning.
Markus Trapp, Michael Roßberg, Günter Schäfer
ISCC3
2014 Towards distributed geolocation by employing a delay-based optimization scheme
abstract
To support position-dependent services, like matchmaking algorithms for online games or geographic backup routes, the estimation of peer locations became a key requisite for a range of applications, recently. However, exact localization may be impossible, e.g., due to nodes lacking Global Positioning System (GPS) access for reasons of cost, energy, or signal unavailability. Alternative approaches, e.g., by nearby WLAN BSSIDs or IP geolocation, rely on databases and normally contain large outliers, in particular when concerning underrepresented mapping locations. This led us to the study of a complementary idea: By embedding nodes on a sphere and periodically minimizing local positioning errors by delay-based multilateration, we efficiently estimate node positions by distributed means, given a fair amount of position hints. Based on simulations that rely on real-world PlanetLab latency data, we show that global-scope peer locations can be estimated with an accuracy of a few hundred kilometers, where the novel approach outperforms a previously proposed spring-mass-based method by about 50%.
Michael Grey, David Schatz, Michael Roßberg, Günter Schäfer
ISCC4
2014 Resilient and underlay-aware P2P live-streaming
Mathias Fischer 0001, Sascha Grau, Giang T. Nguyen 0002, Günter Schäfer
Comput. Networks4
2013 Geocast into the past: Towards a privacy-preserving spatiotemporal multicast for cellular networks
abstract
This article introduces the novel concept of Spatiotemporal Multicast (STM), which is the issue of sending a message to mobile devices that have been residing at a specific area during a certain time span in the past. A wide variety of applications can be envisioned for this concept, including crime investigation, disease control, and social applications. An important aspect of these applications is the need to protect the privacy of its users. In this article, we present an extensive overview of applications and objectives to be fulfilled by an STM service. Furthermore, we propose a first Cluster-based Spatiotemporal Multicast (CSTM) approach and provide a detailed discussion of its privacy features. Finally, we evaluate the performance of our scheme in a large-scale simulation setup.
Sander Wozniak, Michael Roßberg, Franz Girlich, Günter Schäfer
ICC4
2013 Distributed monitoring of self-configuring Virtual Private Networks
Michael Roßberg, Michael Grey, Markus Trapp, Franz Girlich, Günter Schäfer
IM5
2013 Capabilities and objectives of distributed image processing on smart camera systems
abstract
The challenge of bringing more intelligence to the infrastructure of modern cities requires a change of thinking and states a demand for new algorithms and strategies. One important outcome of those algorithms is a realtime estimation of the prevalent spatio-temporal conditions of public transportation networks by making use of distributed image processing on networked smart camera systems. This paper provides a detailed analysis of two exemplary networked applications that can use the derived data. A conducted simulation study based on the infrastructure of real cities shows the potential of using autonomously generated knowledge, that smart camera systems can provide. Especially, inter-camera object tracking, as well as adaptive and smart navigation tasks can benefit considerably and substantiate the need for autonomous and confidential image processing.
Rene Golembewski, Steve Goering, Günter Schäfer
ISCC3
2012 Efficient communication for large-scale robust image processing with smart camera devices
abstract
Large-scale data acquisition and distributed processing of video material requires smart camera devices to collaborate over arbitrary transport networks with no further centralized coordinating instances. Especially in the context of surveillance and security in public transportation networks, the knowledge of spatio-temporal traffic flows can support applications like anomaly detection, smart navigation, or prosecution. Therefore, the problem of autonomously estimating a logical camera topology with respect to scalability, agility and robustness must be solved by efficient communication about distributed detected events. Simple broadcasting or flooding of information does not scale well with the number of nodes and leads to strong requirements on bandwidth and processing power. Thus, a generic system model, describing the process of generating event-based distributed knowledge without making use of flooding, broadcast or multicast, is introduced and evaluated. The results of a conducted simulation study reveal the potential of saving a significant amount of messages on the one hand, and being able to handle poor performance of object recognition algorithms on the other hand.
Rene Golembewski, Günter Schäfer, Tobias Gerlach
CISDA2
2012 Attack-Resistant Distributed Time Synchronization for Virtual Private Networks
abstract
To securely exchange data over public networks, such as the Internet, organizations often utilize Virtual Private Networks (VPNs). However, relying on these potentially large overlay networks makes them vital targets for Denial-of-Service(DoS) attacks. Thus, recent approaches for VPN auto-configuration address DoS resistance by employing distributed management algorithms. Nevertheless, there is no satisfying solution for time synchronization within VPNs that is designed for resistance against DoS as well as internal attacks. For example, NTP relies on hierarchical structures, and cannot comply with DoS resistance. Thus, in this article we present a novel, fully distributed and fault tolerant time synchronization approach, which is designed to be transparently integrated in VPN gateways. Combining diffusion- based round-trip-synchronization with an internal attacker detection, the proposed mechanism is making a contribution to resilient VPN design. Simulation results reveal a robustness against rather powerful internal attackers.
Michael Roßberg, Rene Golembewski, Günter Schäfer
ICCCN3
2011 On the Dependencies between Source Neighbors in Optimally DoS-stable P2P Streaming Topologies
abstract
We study tree-based peer-to-peer streaming topologies that minimize the maximum damage that can be caused by the failure of any number of peers. These optimally stable topologies can be characterized by a distinctive damage sequence. Although checking whether a given topology is optimally stable is a co-NP-complete problem, a large subclass of these topologies can be constructed by applying a simple set of rules. One of these rules states that every optimally stable topology must have optimally stable inter-dependencies between the nodes directly adjacent to the streaming source (called heads). However, until now, only a single stable head topology was known. In this article, we first give a short outline to previous results about optimally stable topologies. Then, we identify necessary and sufficient requirements for the optimal stability of head topologies, thereby largely increasing the number of known representatives from this class. All requirements can be checked in polynomial time. Furthermore, we show how to efficiently decide stability for head topologies with at most four stripes and give a procedure that, given a stable topology, produces a stable topology with an arbitrary number of stripes. Reversing this procedure can also speed up stability testing. Finally, we describe strategies how stable head topologies can be constructed in real-world streaming systems.
Sascha Grau, Mathias Fischer 0001, Günter Schäfer
ICDCS3
2011 Underlay-robust application layer multicast
abstract
In recent years, ALM emerged as cost-efficient and scalable form of content distribution by overcoming the classical client-server bottleneck. The client bandwidth is incorporated to stream distribution, so that every client that receives the stream forwards it as well. ALM systems are usually classified in push, pull and hybrid approaches [1]. In the remainder of this article we are focusing on live-streaming, which imposes strict delay constraints on the content distribution and thus cannot be realized with pull-based approaches. Hence, we concentrate on push-based ALM that splits a stream in multiple substreams (so-called stripes) by using Multiple Description Coding (MDC) and assigns each of them a separate spanning tree. However, the results of this article apply to hybrid and partially to pull-based approaches as well.
Mathias Fischer 0001, Sebastian Delling, Sascha Grau, Günter Schäfer
IPCCC4
2011 A survey on automatic configuration of virtual private networks
Michael Roßberg, Günter Schäfer
Comput. Networks2
2011 On Complexity and Approximability of Optimal DoS Attacks on Multiple-Tree P2P Streaming Topologies
abstract
We investigate the hardness of malicious attacks on multiple-tree topologies of push-based Peer-to-Peer streaming systems. In particular, we study the optimization problem of finding a minimum set of target nodes to achieve a certain damage objective. For this, we differentiate between three natural and increasingly complex damage types: global packet loss, service loss when using Multiple Description Coding, and service loss when using Forward Error Correction. We show that each of these attack problems is NP-hard, even for an idealized attacker with global knowledge about the topology. Despite tree-based topologies seem susceptible to such attacks, we can even prove that (under strong assumptions about NP) there is no polynomial time attacker, capable of guaranteeing a general solution quality within factors of c_1 \log (n) and c_2 2^{\log^{1-\delta } n} (with n topology nodes, \delta = 1 / \log \log^d n for d<1/2 and constants c_1, c_2), respectively. To our knowledge, these are the first lower bounds on the quality of polynomial time attacks on P2P streaming topologies. The results naturally apply to major real-world DoS attackers and show hard limits for their possibilities. In addition, they demonstrate superior stability of Forward Error Correction systems compared to Multiple Description Coding and give theoretical foundation to properties of stable topologies.
Sascha Grau, Mathias Fischer 0001, Michael Brinkmeier, Günter Schäfer
IEEE Trans. Dependable Secur. Comput.4
2009 Towards a Denial-of-Service Resilient Design of Complex IPsec Overlays
abstract
By monitoring the exchanged IPsec traffic an adversary can usually easily discover the layout of virtual private networks (VPNs). Of even worse extend is the disclosure if compromised IPsec gateways are considered, for example in remote environments. This revelation enables attackers to identify vital components and may allow him to compromise the availability of the overall infrastructure by launching well-targeted denial-of-service (DoS) attacks against them. In this article we present a formal model to analyze the resilience of VPN infrastructures against DoS attacks, to estimate the impact of compromised gateways, and to formalize the planning process of more resilient infrastructures.
Michael Brinkmeier, Michael Roßberg, Günter Schäfer
ICC3
2009 Optimally DoS Resistant P2P Topologies for Live Multimedia Streaming
abstract
Using a peer-to-peer approach for live multimedia streaming applications offers the promise to obtain a highly scalable, decentralized, and robust distribution service. When constructing streaming topologies, however, specific care has to be taken in order to ensure that quality of service requirements in terms of delay, jitter, packet loss, and stability against deliberate denial of service attacks are met. In this paper, we concentrate on the latter requirement of stability against denial-of-service attacks. We present an analytical model to assess the stability of overlay streaming topologies and describe attack strategies. Building on this, we describe topologies, which are optimally stable toward perfect attacks based on global knowledge, and give a mathematical proof of their optimality. The formal construction and analysis of these topologies using global knowledge lead us to strategies for distributed procedures, which are able to construct resilient topologies in scenarios, where global knowledge can not be gathered. Experimental results show that the topologies created in such a real-world scenario are close to optimally stable toward perfect denial of service attacks.
Michael Brinkmeier, Günter Schäfer, Thorsten Strufe
IEEE Trans. Parallel Distributed Syst.2
2008 A Distributed IP Mobility Approach for 3G SAE
abstract
Future generations of mobile operator networks, based on an all-IP-based flat architecture and a multitude of different access technologies, require a proper IP-based mobility management in place. In this article, a scalable and completely distributed mobility management is presented which is based on a Distributed Hash Table data structure. The Distributed IP Mobility Approach (DIMA) remains completely compatible towards Mobile IP and its variants Hierarchical Mobile IP and Proxy Mobile IP. We examine the average service time per packet and the load caused by lookups in the system, by applying a suitable mobility model and by using a traffic model consisting of a mix of representative traffic classes (HTTP, VoIP, Audio and Video streaming). Thereby, we show that the system remains scalable allowing to serve an arbitrary amount of participants, provides a network-based route optimization and a better resilience than Mobile IP at the cost of only slightly increased signalling effort.
Mathias Fischer 0001, Frank-Uwe Andersen, Andreas Köpsel, Günter Schäfer, Morten Schläger
PIMRC4
2008 A Key Management Solution for Overlay-Live-Streaming
abstract
Confidential communication of live-generated multimedia data distributed via application level multicast (ALM) still remains a mostly unaddressed subject even though some important usage scenarios, e.g. paid subscription services or personal video-streaming, are anticipated to gain more widespread use as the Internet continues to evolve into the common transport platform for all kinds of services. In this article, we examine the specific requirements for key management schemes to be used in ALM-based distribution systems and analyze existing key management approaches with respect to these requirements [1, 2, 3]. Based on the results of this analysis, we design a new key management scheme that combines ideas of the Logical Key Hierarchy (LKH) protocol [4, 5] and the Iolus approach [6]. We compare the resulting scheme to a simple approach that is based on pairwise keys between neighboring nodes without further key-hierarchy based optimization and that serves as a benchmark. Our results of a comparative simulation study clearly indicate the suitability of our scheme for ALM-based livestreaming.
Mathias Fischer 0001, Günter Schäfer, Robert Karl Schmidt, Thorsten Strufe
SecureComm2
2008 Credential Management for Automatic Identification Solutions in Supply Chain Management
abstract
Current systems for automatic identification of goods presume a single administrative domain. However, in supply chain management systems temporary cooperations of multiple companies exist, and the usage of one identification device, such as a radio-frequency identification (RFID) tag, per company is infeasible for reasons of costs, space requirements, traceability, and higher collision rate. This paper analyzes the security requirements resulting from the usage of a single tag for multiple companies and proposes a novel system architecture and accompanying cryptographic protocols that address the security objectives entity authentication, controlled access, data confidentiality and integrity, as well as untraceability of RFID tags. The architecture is designed to provide high availability and graceful degradation in case of compromise of system parts. The results of an implementation and simulation study give insights on appropriate data structures for realizing key functionality, and demonstrate the feasibility with off-the-shelf hardware.
Marcel Henseler, Michael Roßberg, Günter Schäfer
IEEE Trans. Ind. Informatics3
2006 BCBS: An Efficient Load Balancing Strategy for Cooperative Overlay Live-Streaming
abstract
In this paper, we present Bandwidth Class Based Streaming (BCBS), an application layer multicast for multimedia services. BCBS focuses on multi source live streaming, and following a locality model based on round trip times, it creates network efficient streaming meshes. The load balancing selects multiple nodes as streaming sources and is organised subscription based instead of request based. We describe a simulation study of the load balancing and tree construction procedures. The results show that BCBS creates network efficient overlays with respect to stretch and link stress.
Thorsten Strufe, Günter Schäfer, Arthur Chang
ICC2
2006 Concept for Hierarchical and Distributed Processing of Area Based Triggers
abstract
Area based triggers denote notifications being generated if a mobile client changes its spatial relation to a defined area, e.g. if it enters or leaves it. By these triggers, new valuable services can be provided for mobile users. One of the main challenges is to design a suited approach for the computation of the triggers based on the defined areas and the current whereabouts of the mobile clients. With a rising number of areas and participants of these services, the need for a scalable solution to process the triggers emerges. This paper examines a new approach for the distributed, hierarchical processing of area based triggers based on the aggregation and segregation of both triggers and the setup messages requesting the services in a carrier access network. We investigate the signaling effort and computational complexity of the approach based on the required effort for an emerging position update of a mobile client in the network. The results are compared analytically with two other approaches, a centralized and a hierarchical one. Our analysis shows that our approach leads to a superior performance in terms of the effort for signaling and computation
Sven D. Hermann, Günter Schäfer, Adam Wolisz, Michael Lipka
PerCom2
2005 Performance analysis of a Denial of Service protection scheme for optimized and QoS-aware handover
Michel Sortais, Günter Schäfer, Stefan Adams, Changpeng Fan, Adam Wolisz
Comput. Networks3
2004 ISP-operated protection of home networks with FIDRAN
abstract
In order to fight against the increasing number of network security incidents due to mal-protected home networks permanently connected to the Internet via DSL, TV cable or similar technologies, we propose that Internet service providers (ISP) operate and manage intrusion prevention systems (IPS) which are to a large extend executed on the consumer's gateway to the Internet (e.g., DSL router). The paper analyses the requirements of ISP-operated intrusion prevention systems and presents our approach for an IPS that runs on top of an active networking environment and is automatically configured by a vulnerability scanner. We call the system FIDRAN (Flexible Intrusion Detection and Response framework for Active Networks). The system autonomously analyses the home network and correspondingly configures the IPS. Furthermore, our system detects and adjusts itself to changes in the home network (new service, new host, etc.). First performance comparisons show that our approach - while offering more flexibility and being able to support continuous updating by active networking principles - competes well with the performance of conventional intrusion prevention systems like Snort-Inline.
Andreas Hess 0003, Günter Schäfer
CCNC2
2004 Distributed access control for consumer operated mobile ad-hoc networks
abstract
We propose a concept for realizing access control in mobile ad-hoc networks to exclude nodes that do not contribute to the provision of network services from using them. Each node observes the behavior of its neighbors in order to build up opinions about their willingness to take part in different network activities. In turn, service is provided only to nodes that have positive opinions about them. A precondition for assigning opinions to nodes is having a means for authentication; we rely on a web-of-trust structure for this, where all nodes can issue certificates for others after they have verified their identities. A proactive certificate management system makes it possible - as the presented evaluation results show - to find optimal certificate chains between given keys and to retrieve the needed certificates quickly.
Daniel Kraft, Günter Schäfer
CCNC2
2004 Security analysis and concept for the multicast-based handover support architecture MOMBASA
abstract
The multicast-based mobility architecture, MOMBASA, has proven to be an efficient and elegant approach for achieving low latency handover with minimum packet loss in mobile Internet communications (Festag, A. et al., Proc. Performance Tools, p.212-19, 2002). The original MOMBASA specification, however, did not include any precautions against malicious attacks on its protocol operation. We present the principal results of a security analysis of the MOMBASA architecture and describe our security concept to counter the identified threats. A main focus is put on attacks against the MOMBASA protocol operation coming into the access network from two main sources: the public Internet and the wireless link. The design of our security concept is specifically suited to ensuring a seamless handover by augmenting the predictive handover functionality of MOMBASA with an accompanying predictive distribution of authentication keys. Furthermore, the security concept includes a rate control mechanism for traffic destined for idle mobile nodes in order to limit the risks of potential denial of service (DoS) attacks against the paging mechanism. While our security measures effectively counter the identified threats from the wireless link and the Internet, first measurements with our prototype implementation show only negligible degradation of handover performance compared to unsecured MOMBASA operation.
Lars Westerhoff, S. Reinhardt, Günter Schäfer, Adam Wolisz
GLOBECOM3
2004 Realizing a flexible access control mechanism for active nodes based on active networking technology
abstract
This paper presents a model and mechanism for flexible access control of loadable on-demand services in an active network, using code origin authentication and runtime supervision. During the development of the access control mechanism, we strongly focused on keeping the mechanism as efficient as possible, and to realize a modular design which allows to dynamically upgrade and configure the mechanism, making use of the active networking technology itself, while at the same time ensuring that mandatory security checks cannot be circumvented. Each service has to pass initial checks before it can he executed on an active node. Our approach provides access control that is dynamic, extensible and efficient, realizing a demand-driven supervision which avoids supervision of those actions that do not need to be supervised. Specific access control modules are realized as active services and activated when needed. Finally, we present results that have been achieved with a first prototype developed for the active networking platform (active multicast network) which are very promising.
Andreas Hess 0003, Günter Schäfer
ICC2
2003 FIDRAN: A Flexible Intrusion Detection and Response Framework for Active Networks
abstract
Securing communication networks can no longer be ensured by singular and isolated security technologies like Internet firewalls or intrusion detection systems but rather calls for a combination of existing and emerging detection and response mechanisms, e.g. DDoS response mechanisms, anomaly detection, honey pots, etc. Today, most current systems prove to be too static to provide an adequate platform for a constructive teamwork of different security technologies. Therefore, we developed the FIDRAN framework for flexible intrusion detection and response that is based on an underlying active networking environment and that allows to dynamically combining existing and emerging security technologies. FIDRAN follows a highly modular approach that allows to extend the functionality of the framework by the integration of new security modules which are implemented as active networking services, making use of next generation networks capabilities like dynamic distribution and deployment of services on active network nodes. A further advantage of the realization of FIDRAN on top of an active networking environment is the simplification and automation of maintenance work and configuration tasks.
Andreas Hess 0003, Günter Schäfer
ISCC3
2001 Traffic Shaping in End Systems Attached to QoS-supporting Networks
abstract
Quality of service (QoS) supporting network architectures, like the differentiated services architecture, require a certain agreement regarding service levels. Traffic characteristics like data rates will be part of such agreements and, thus, senders must take care to stay within the agreed limits. Traffic shaping is one important mechanism to avoid penalties in networks (dropped or delayed packets) due to violations of the agreement. This paper presents a new class-based QoS traffic shaper for Linux that aims at shaping aggregate traffic as well as individual flows within an aggregate. In comparison to other approaches (e.g., class-based queuing), our flow based queuing mechanism causes significantly less jitter. Implemented in end-systems, this approach even benefits from direct interaction with applications to create traffic in accordance to application requirements.
Marc Bechler, Hartmut Ritter, Günter Schäfer, Jochen H. Schiller
ISCC3
2000 FATIMA: A Firewall-Aware Transparent Internet Mobility Architecture
abstract
Ubiquitous communication will be one of the paradigms for the next decades. The use of the Internet in such applications demands for a highly reliable and secure system, especially when used in non-academical environments like remote offices, e-commerce, or traffic telematics. Today's Internet, even with the mobility extension Mobile IP, has not been designed with private addresses, firewalls, network address translation quality of service etc. in mind. Several optimisations already exist-however security is often neglected. This paper proposes the firewall-aware transparent Internet mobility architecture FATIMA, which integrates security functionality but is transparent to existing Mobile IP implementations. All security critical functions are concentrated in a firewall, all control messages are authenticated, and micro-mobility is supported. Corporate networks with private addresses are supported seamlessly, and further extensions allow for the use of dynamic home addresses and quality of service support.
Stefan Mink, Frank Pählke, Günter Schäfer, Jochen H. Schiller
ISCC3