Michael Roßberg

dblp:91/2886 · also Michael Rossberg · DBLP profile ↗
← Back
26ranked-venue papers
4as first author
5since 2021 · last 2024
0009-0002-0749-5336ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 3 first-author · 1 since 2021Security and privacy · 8 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2024 Increasing Resilience of SD-WAN by Distributing the Control Plane [Extended Version]
abstract
Modern WAN interconnects utilize SD-WAN to automatically respond to network changes and improve link utilization, latency, and availability. Therefore, they incorporate controllers with a centralized view, which collect network state from managed gateways, calculate suitable forwarding actions, and distribute them accordingly. However, this limits the robustness and availability of the network control plane, especially in the event of node or partial network outages. In this paper, we propose a distributed and highly robust SD-WAN control plane without any central or regional controller. Our solution can handle arbitrary device failures as well as network partitioning. The distributed forwarding decisions are based on user-defined, dynamically evaluated path cost functions, and consider not only path quality but also quality fluctuations. The evaluation shows that our approach can handle several thousand SD-WAN gateways and hundreds of network policies in terms of computation. Further, the communication overhead introduced due to its distributed architecture is discussed and shown to be negligible compared to a central approach. This paper is an extended version of our work published in altheide2023. It describes the information transmitted between sites as well as a strategy for deploying policies, discusses approaches reducing communication bandwidth, introduces grouping of multiple flows without requiring explicit coordination, and provides a detailed analysis of the bandwidth required.
Friedrich Altheide, Simon Buttgereit, Michael Roßberg
IEEE Trans. Netw. Serv. Manag.3
2023 Evaluating Statistical Disclosure Attacks and Countermeasures for Anonymous Voice Calls
abstract
Assuming a threat model of a global observer, statistical disclosure attacks have been proposed to efficiently de-anonymize communication relationships in text-based mix networks over time. It is commonly assumed that such attacks are also able to disclose call relationships in anonymous communication networks (ACNs) that support voice calls. One straightforward countermeasure is to expect users to permanently send and receive packets that mimic a Voice over IP (VoIP) call. However, this is not practical in real world scenarios, like on mobile devices. In this article, we adapt one specific statistical disclosure attack (Z-SDA-MD) to voice calls and quantitatively study less resource-intensive countermeasures. As base countermeasure, we evaluate a round-based communication model, corresponding to a timed mix. A simulation study of this scenario shows that the Z-SDA-MD is not well suited for a general disclosure of call relationships because of too many false positives. Nevertheless, the attack is able to correctly identify the most frequent relationships. Still, the accuracy in that regard may significantly be decreased by increasing the duration of one round, by decoupling actions (call setup and teardown) of caller and callee by a random number of rounds, and by occasional fake calls to a fixed set of “fake friends”. Overall, our study shows that anonymous voice calls may be implemented with an acceptable trade-off between anonymity, call setup time, and bandwidth overhead.
David Schatz, Michael Roßberg, Günter Schäfer
ARES2
2023 Virtual Private Networks in the Quantum Era: A Security in Depth Approach
David Schatz, Friedrich Altheide, Hedwig Koerfgen, Michael Roßberg, Günter Schäfer
SECRYPT4
2021 Optimizing Packet Scheduling and Path Selection for Anonymous Voice Calls
abstract
Onion routing is a promising approach to implement anonymous voice calls. Uniform-sized voice packets are routed via multiple relays and encrypted in layers to avoid a correlation of packet content in different parts in the network. By using pre-built circuits, onion encryption may use efficient symmetric ciphers. However, if packets are forwarded by relays as fast as possible—to minimize end-to-end latency—network flow watermarking may still de-anonymize users. A recently proposed countermeasure synchronizes the start time of many calls and batch processes voice packets with the same sequence number in relays. However, if only a single link with high latency is used, it will also negatively affect latency of all other calls. This article explores the limits of this approach by formulating a mixed integer linear program (MILP) that minimizes latency “bottlenecks” in path selection. Furthermore, we suggest a different scheduling strategy for voice packets, i.e. implementing independent de-jitter buffers for all flows. In this case, a MILP is used to minimize the average latency of selected paths. For comparison, we solve the MILPs using latency and bandwidth datasets obtained from the Tor network. Our results show that batch processing cannot reliably achieve acceptable end-to-end latency (below 400 ms) in such a scenario, where link latencies are too heterogeneous. In contrast, when using de-jitter buffers for packet scheduling, path selection benefits from low latency links without degrading anonymity. Consequently, acceptable end-to-end latency is possible for a large majority of calls.
David Schatz, Michael Roßberg, Günter Schäfer
ARES2
2021 Hydra: Practical Metadata Security for Contact Discovery, Messaging, and Dialing
abstract
Communication metadata may leak sensitive information even when content is encrypted, e.g. when contacting medical services. Unfortunately, protecting metadata is challenging. Existing approaches for anonymous communications either are vulnerable in a strong (but feasible) threat model or have practicability issues like intense usage of asymmetric cryptography. We propose Hydra, a mix network that is able to provide multiple anonymous services in a uniform way. In contrast to previous messaging systems with strong anonymity, we deliberately use padded onion-encrypted circuits. This allows to support connectionless applications like contact discovery with authenticated key exchange, messaging, and dialing (signalling for connection-oriented communications) with strong anonymity and relatively low latency. Our cryptography benchmarks show that Hydra is able to process messages an order of magnitude faster than state of the art messaging systems with strong anonymity. At the same time, bandwidth overhead is comparable to previous systems. We further develop an analytical model to predict the end-to-end latency of Hydra and validate it in a testbed.
David Schatz, Michael Roßberg, Günter Schäfer
ICISSP2
2020 Vector packet encapsulation: the case for a scalable IPsec encryption protocol
abstract
The IPsec protocol family, although not always undisputed, has shown to be extremely reliable over the last two decades. However, given the fact that communication networks evolved tremendously since ESP was standardized, this paper proposes changes to the security protocol to accommodate for the needs of modern wide area and data center networks. In particular it addresses optimizations for high-speed software implementations as well as use cases in data center networks. The evaluation shows that rather small yet targeted changes are sufficient to allow for more flexible and scalable implementations.
Michael Pfeiffer 0006, Franz Girlich, Michael Roßberg, Günter Schäfer
ARES3
2020 Poster: Seamless Client Integration for Fast Roaming in Wireless Mesh Networks
Martin Backhaus, Markus Theil, Michael Roßberg, Günter Schäfer
Networking3
2020 Seamless Multimedia Streaming in Controller-Less Wireless Mesh Networks With Mobile Stations
Markus Theil, Martin Backhaus, Michael Roßberg, Günter Schäfer
Networking3
2020 Improving Network-Assisted Roaming for Controller-Less Wi-Fi
abstract
Large Wi-Fi installations may make use of Wi-Fi controllers managing client mobility and different Virtual Local Area Networks (VLANs). However, as they might form a bottleneck, controller-less solutions are on the rise, e.g., cloud-managed solutions or mesh networks. IEEE 802.11 defines a framework for providing roaming assistance through neighbor reports and transition requests (IEEE 802.11k and IEEE 802.11v), but leaves generating meaningful candidates included in these frames open to the implementor. Without central controllers, deriving these candidates for Stations (STAs) is much more difficult. Access Points (APs) with more autonomy need to know other APs located in their proximity to provide roaming assistance for STAs. In this paper, we design and evaluate a network-assisted roaming architecture for controller-less Wi-Fi networks. APs learn roaming events in their vicinity and steer STAs by means of refined, yet standard-compliant neighbor reports and transition requests to better suited APs. Our results using a real-system prototype indicate a noticeable decrease of roaming times when comparing various reference approaches to our proposal.
Martin Backhaus, Markus Theil, Michael Roßberg, Günter Schäfer
PIMRC3
2020 Robustness and Scalability Improvements for Distance Vector Routing in Large WMNs
abstract
IEEE 802.11s enables rapid deployment of Wireless Mesh Networks (WMNs) to supply basic wireless connectivity for client hardware. Application of distance vector based routing protocols proved advantageous in WMNs for efficiency, i.e., low overhead. However, it remains unclear, if plain distance vector routing protocols allow for adequate robustness against outages in large installations. Particularly, the required time for routing re-convergence may be too long, as in practice, the count-to-infinity phenomenon needs to be dealt with. This paper proposes Spare Forwarding Entries (SFEs), resulting in a proactive mechanism improving robustness against outages when compared to the reactive behavior of distance vector protocols. It works as an extension of distance vector operation, i.e., efficiency can be preserved. We integrate SFE into the well-known Babel routing protocol and also propose measures to increase scalability. Simulation studies indicate that SFEs improve robustness against node outages significantly. In certain scenarios, the Packet Delivery Ratio (PDR) was doubled with our mechanisms in place. Further modifications let Babel-based WMNs scale up to 300 nodes. Moreover, convergence times and overhead are significantly smaller.
Martin Backhaus, Markus Theil, Michael Roßberg, Günter Schäfer
WiMob3
2019 Strong Tenant Separation in Cloud Computing Platforms
abstract
Cloud computing, with its large, homogeneous infrastructures, has a high sensitivity to security incidents due to the multitude of affected services and tenants. To contain a potential attacker within a compromised subsystem, a strict separation between individual resources, e.g. virtual servers and networks, must be established. However, this separation usually relies on the integrity of the entire cloud platform. Due to the considerable size and complexity of the software powering these platforms and recently found attacks on hardware components, i.e. Spectre and Meltdown, this may not always represent a reasonable assumption.
Michael Pfeiffer 0006, Michael Roßberg, Simon Buttgereit, Günter Schäfer
ARES2
2019 Towards a Security Architecture for Hybrid WMNs
abstract
Currently deployed Wireless Mesh Networks (WMNs) are mostly hybrid, i.e., some Mesh Points (MPs) also employ additional Access Point (AP) radios to connect non-mesh stations (STAs). Today's Wi-Fi security protocols are unsuited in the use case of WMNs, as they can neither derive key material without central authentication servers nor tolerate compromised MPs, as it is required in outdoor deployments. To establish high security standards while embracing the distributed nature of WMNs, we need a novel security architecture, that does not rely on central entities and protects traffic between MPs with End-to-End Encryption (E2EE). We propose and evaluate a distributed security architecture for WMNs with attached APs, which uses certificates early in the authentication process. The architecture provides E2EE between MPs and authentic MAC addresses of all STAs and MPs. STAs, e.g., resource constrained Internet of Things (IoT) devices, cannot participate in the end-to-end encryption, but need to be securely attached to the WMN with mobility and other requirements in mind. The evaluation in our Wi-Fi testbed shows the authentication protocol's suitability for fast (re-)authentication in mobile scenarios.
Markus Theil, Martin Backhaus, Michael Roßberg, Günter Schäfer
ARES3
2018 A Comprehensive Framework to Evaluate Wireless Networks in Simulation and Real Systems
abstract
A thorough performance evaluation of protocols and algorithms for (wireless) networks requires simulation and real-system experiments, as both of them provide individual benefits. Usually, this calls for two separate implementations: One tailored to a discrete-event simulator and a second designed to run on real hardware. Therefore, significant effort is required to implement the same mechanisms or protocols twice. To avoid this overhead, we propose a comprehensive framework based on DPDK and OMNeT ++, allowing to run simulations and real-system experiments from the very same codebase. Hence the best of both worlds is available: scalable scenarios and reproducibility when simulating, and realistic behavior and real-world performance metrics when running real-system experiments. Our evaluation of several representative real-world networking scenarios analyzes similarities between simulation and real-system results and discusses the framework qualitatively. Quantitative results indicate that the approach performs well, i.e., it allows even for productive deployment using the codebase later on, and results from both worlds are comparable.
Martin Backhaus, Markus Theil, Michael Roßberg, Günter Schäfer, David Sukiennik
DS-RT3
2018 Towards a Flexible User-Space Architecture for High-Performance IEEE 802.11 Processing
abstract
Exploiting bandwidth potentials and managing complexity of current and future IEEE 802.11 networking standards becomes increasingly difficult when using today's operating system kernels and high-throughput wireless network interfaces due to overhead caused by interrupts and kernels of complex general-purpose operating systems. These problems can be tackled by employing special purpose forwarding planes deeply integrated with wireless drivers. To do so we propose a user-space implementation of drivers and Wi-Fi stack, built upon the Data Plane Development Kit (DPDK) from the wired world. This allows for scalable frame processing, as well as flexible and easy experimenting with new protocols and approaches (compared to kernel development). Our prototypic evaluation reveals that user-space processing of IEEE 802.11 frames can increase throughput and decrease delay of a wireless connection significantly, e.g., 100% more throughput for small frames and 27% less delay. We also point out common obstacles when adapting wireless drivers from kernel to user space and provide advice on how to overcome them. The code base is made publicly available.
Martin Backhaus, Markus Theil, Michael Roßberg, Günter Schäfer
WiMob3
2017 Secure Enrollment of Certificates Using Short PINs
abstract
The enrollment of certificates in large communication infrastructures (VPNs, IoT & VoIP infrastructures) requires non-negligible administrative efforts, as they often need to be generated and provisioned over an authenticated channel in-field. Approaches like SCEP reduce the associated costs, but require long individual passphrases for each device to be operated securely. Addressing this issue, this article presents a provisioning procedure and a cryptographic protocol that make use of Password Authenticated Key Exchanges (PAKEs) to allow for a secure operation with extremely short PINs even on devices with low computational power. Thereby the usability is significantly increased, yet the complexity of the security relevant components decreases in comparison to former approaches. The overall architecture addresses state-of-the-art security objectives such as resistance against Denial-of-Service (DoS) attacks and graceful degradation in the case of a compromise of some devices. Quantitative evaluation is performed utilizing a realistic prototype.
Michael Roßberg, Markus Theil
ARES1
2017 Covert-channel-resistant congestion control for traffic normalization in uncontrolled networks
abstract
Traffic normalization, i.e. enforcing a constant stream of fixed-length packets, is a well-known measure to completely prevent attacks based on traffic analysis. In simple configurations, the enforced traffic rate can be statically configured by a human operator, but in large virtual private networks (VPNs) the traffic pattern of many connections may need to be adjusted whenever the overlay topology or the transport capacity of the underlying infrastructure changes. We propose a rate-based congestion control mechanism for automatic adjustment of traffic patterns that does not leak any information about the actual communication. Overly strong rate throttling in response to packet loss is avoided, as the control mechanism does not change the sending rate immediately when a packet loss was detected. Instead, an estimate of the current packet loss rate is obtained and the sending rate is adjusted proportionally. We evaluate our control scheme based on a measurement study in a local network testbed. The results indicate that the proposed approach avoids network congestion, enables protected TCP flows to achieve an increased goodput, and yet ensures appropriate traffic flow confidentiality.
Martin Byrenheid, Michael Roßberg, Günter Schäfer, Robert Dorn
ICC2
2015 Towards a model for global-scale backbone networks
abstract
Synthetic network models play an integral role in nowadays research of computer networks. This is for the lack of real network data and to perform experiments with a statistical significant number of replications. While most of the modeling work currently focuses on layer 3 topologies, e.g., AS level, this work is on generating realistic layer 1 topologies. These topologies are of fundamental significance for network resilience, for example. By constructing β-skeleton graphs, augmented with population and technology indications, our approach is able to generate highly realistic graphs. This is shown by a comparison to US networks, whose topology is publicly available.
Michael Grey, Markus Theil, Michael Roßberg, Günter Schäfer
ICC3
2015 Program partitioning based on static call graph analysis for privilege separation
abstract
The major cause of IT security incidents are software issues, hence this article presents an automated approach for source code partitioning and privilege separation. Based on static call graph analysis, functions and program parts of a monolithic software are separated in several processes and grouped by the privilege they need. For the partitioning we introduce a metric that estimates the potential security gain by considering the complexity and privilege distribution of the separated software. Furthermore, we present a partitioning heuristic that uses this metric to create a secure software partitioning.
Markus Trapp, Michael Roßberg, Günter Schäfer
ISCC2
2015 Dominating an s-t-Cut in a Network
Ralf Rothenberger, Sascha Grau, Michael Roßberg
SOFSEM3
2014 Towards distributed geolocation by employing a delay-based optimization scheme
abstract
To support position-dependent services, like matchmaking algorithms for online games or geographic backup routes, the estimation of peer locations became a key requisite for a range of applications, recently. However, exact localization may be impossible, e.g., due to nodes lacking Global Positioning System (GPS) access for reasons of cost, energy, or signal unavailability. Alternative approaches, e.g., by nearby WLAN BSSIDs or IP geolocation, rely on databases and normally contain large outliers, in particular when concerning underrepresented mapping locations. This led us to the study of a complementary idea: By embedding nodes on a sphere and periodically minimizing local positioning errors by delay-based multilateration, we efficiently estimate node positions by distributed means, given a fair amount of position hints. Based on simulations that rely on real-world PlanetLab latency data, we show that global-scope peer locations can be estimated with an accuracy of a few hundred kilometers, where the novel approach outperforms a previously proposed spring-mass-based method by about 50%.
Michael Grey, David Schatz, Michael Roßberg, Günter Schäfer
ISCC3
2013 Geocast into the past: Towards a privacy-preserving spatiotemporal multicast for cellular networks
abstract
This article introduces the novel concept of Spatiotemporal Multicast (STM), which is the issue of sending a message to mobile devices that have been residing at a specific area during a certain time span in the past. A wide variety of applications can be envisioned for this concept, including crime investigation, disease control, and social applications. An important aspect of these applications is the need to protect the privacy of its users. In this article, we present an extensive overview of applications and objectives to be fulfilled by an STM service. Furthermore, we propose a first Cluster-based Spatiotemporal Multicast (CSTM) approach and provide a detailed discussion of its privacy features. Finally, we evaluate the performance of our scheme in a large-scale simulation setup.
Sander Wozniak, Michael Roßberg, Franz Girlich, Günter Schäfer
ICC2
2013 Distributed monitoring of self-configuring Virtual Private Networks
Michael Roßberg, Michael Grey, Markus Trapp, Franz Girlich, Günter Schäfer
IM1
2012 Attack-Resistant Distributed Time Synchronization for Virtual Private Networks
abstract
To securely exchange data over public networks, such as the Internet, organizations often utilize Virtual Private Networks (VPNs). However, relying on these potentially large overlay networks makes them vital targets for Denial-of-Service(DoS) attacks. Thus, recent approaches for VPN auto-configuration address DoS resistance by employing distributed management algorithms. Nevertheless, there is no satisfying solution for time synchronization within VPNs that is designed for resistance against DoS as well as internal attacks. For example, NTP relies on hierarchical structures, and cannot comply with DoS resistance. Thus, in this article we present a novel, fully distributed and fault tolerant time synchronization approach, which is designed to be transparently integrated in VPN gateways. Combining diffusion- based round-trip-synchronization with an internal attacker detection, the proposed mechanism is making a contribution to resilient VPN design. Simulation results reveal a robustness against rather powerful internal attackers.
Michael Roßberg, Rene Golembewski, Günter Schäfer
ICCCN1
2011 A survey on automatic configuration of virtual private networks
Michael Roßberg, Günter Schäfer
Comput. Networks1
2009 Towards a Denial-of-Service Resilient Design of Complex IPsec Overlays
abstract
By monitoring the exchanged IPsec traffic an adversary can usually easily discover the layout of virtual private networks (VPNs). Of even worse extend is the disclosure if compromised IPsec gateways are considered, for example in remote environments. This revelation enables attackers to identify vital components and may allow him to compromise the availability of the overall infrastructure by launching well-targeted denial-of-service (DoS) attacks against them. In this article we present a formal model to analyze the resilience of VPN infrastructures against DoS attacks, to estimate the impact of compromised gateways, and to formalize the planning process of more resilient infrastructures.
Michael Brinkmeier, Michael Roßberg, Günter Schäfer
ICC2
2008 Credential Management for Automatic Identification Solutions in Supply Chain Management
abstract
Current systems for automatic identification of goods presume a single administrative domain. However, in supply chain management systems temporary cooperations of multiple companies exist, and the usage of one identification device, such as a radio-frequency identification (RFID) tag, per company is infeasible for reasons of costs, space requirements, traceability, and higher collision rate. This paper analyzes the security requirements resulting from the usage of a single tag for multiple companies and proposes a novel system architecture and accompanying cryptographic protocols that address the security objectives entity authentication, controlled access, data confidentiality and integrity, as well as untraceability of RFID tags. The architecture is designed to provide high availability and graceful degradation in case of compromise of system parts. The results of an implementation and simulation study give insights on appropriate data structures for realizing key functionality, and demonstrate the feasibility with off-the-shelf hardware.
Marcel Henseler, Michael Roßberg, Günter Schäfer
IEEE Trans. Ind. Informatics2