Gábor Lencse

dblp:97/5081 · DBLP profile ↗
← Back
13ranked-venue papers
9as first author
7since 2021 · last 2025
0000-0001-5552-3237ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 7 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Security and privacy · 1 · 1 first-author
YearPublicationVenuePosition
2025 Methodology for the security analysis of IPv4-as-a-Service IPv6 transition technologies
abstract
Abstract As the depletion of IPv4 addresses accelerates, the urgency of transitioning to IPv6 has intensified. To address this imperative, numerous IPv6 transition technologies have emerged to facilitate this migration process. While existing methodologies offer insights into the security implications of these technologies, this paper presents a novel approach to security analysis that surpasses conventional methods. By leveraging the STRIDE threat modeling technique, which stands for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege, we conduct a comprehensive security analysis of prominent IPv6 transition technologies, including Combination of Stateful and Stateless Translation (464XLAT), Dual-Stack Lite (DS-Lite), Lightweight 4over6 (Lw4o6), and Mapping of Address and Port using Translation (MAP-T)/Mapping of Address and Port with Encapsulation (MAP-E). Our methodology not only evaluates the categorization of transition technologies but also considers the location and the statefulness of the attacked router, whether it is a customer edge router or a provider edge device. Additionally, we introduce an abstraction method to derive potential vulnerabilities at a more general level from those discovered at a more specific level. Through synthesizing previous research endeavors and rigorously examining these technologies for vulnerabilities, our approach offers valuable insights into the security landscape of IPv4-as-a-Service IPv6 transition technologies. By addressing the limitations of existing methodologies and providing a more holistic framework for security analysis, this paper contributes to the ongoing discourse on IPv6 transition strategies. It enhances the resilience of network infrastructures against evolving security threats.
Ameen Al-Azzawi, Gábor Lencse
Comput. J.2
2025 Maptperf: An RFC 8219 compliant tester for benchmarking MAP-T border relay routers
abstract
The Benchmarking Working Group of IETF has published a comprehensive methodology in its RFC 8219 for benchmarking IPv6 transition technologies. The Mapping of Address and Port using Translation (MAP-T) is one of the most prominent of these technologies, which is also considered a stateless IPv4-as-a-Service (IPv4aaS) technology that belongs to the double translation category in RFC 8219. This paper presents the design and implementation of Maptperf, the World's first MAP-T benchmarking tool that complies with the guidelines of RFC 8219 to test the performance of the Border Relay (BR) router device of the technology since it is considered the focal point of its scalability. As part of the work accomplished in this paper, several design considerations, operational requirements, and configuration settings are discussed. Then, a detailed description of the implementation is disclosed, along with various important design decisions that are considered regarding implementation. Finally, the research findings related to Maptperf for two tests, the performance estimation and the functional tests, are presented. The performance estimation test proves how fast and robust Maptperf is via an initial assessment of its performance, while the functional tests include four types of measurements: Throughput, Frame Loss Rate (FLR), Latency, and Packet Delay Variation (PDV) for MAP-T implementations. For the latter case, the authors chose a popular MAP-T BR implementation, Jool, whose function is also validated via a testbed installed for this purpose.
Ahmed Al-hamadani, Gábor Lencse
Comput. Networks2
2024 Security analysis of the MAP-T IPv6 transition technology
abstract
Abstract In this paper, we focus on one of the most prominent IPv6 transition technologies, namely Mapping of Address and Port using Translation (MAP-T), and we give attention to Mapping of Address and Port with Encapsulation (MAP-E) as well. We emphasize the uniqueness of MAP-T and MAP-E, and we discuss the differences between those two technologies, including their topology, functionality, and security vulnerabilities. We apply a threat modeling technique, Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE), to assess potential vulnerabilities in the MAP-T infrastructure. Furthermore, we build a testbed for MAP-T using the open-source software, Jool, and we conduct testing on the translation process capabilities of Jool and its port allocation per subscriber. Finally, we present various attacking scenarios against the main routers of MAP-T, such as IP address spoofing, information disclosure, and source port exhaustion, and we propose mitigation methods for several attacks.
Ameen Al-Azzawi, Gábor Lencse
Comput. J.2
2024 Making stateless and stateful network performance measurements unbiased
abstract
The Benchmarking Working Group (BMWG) of the Internet Engineering Task Force (IETF) has defined a series of Requests for Comments (RFC) to standardize the benchmarking of network interconnect devices (e.g., bridges, routers, different IPv6 transition solutions). The paper points out that there are cases where the performance results are significantly different when a single IP address pair or multiple IP addresses are used. The cause of this phenomenon is rooted in the recent hardware and software advancements: Receive Side Scaling (RSS) makes it possible to distribute packet processing workload over multiple CPU cores. However, this may be implemented in two ways: the first way only includes the IP addresses into the hash function used to distribute the workload among the CPU cores, whereas the second one also includes the port numbers. RFC 4814 proposed an excellent solution for the second case by recommending the usage of pseudorandom port numbers during benchmarking; however, the first case was not handled properly, because no explicit recommendation was given regarding the usage of multiple IP addresses. This paper attempts to bridge this methodological gap; a practical solution is proposed for using pseudorandom IP addresses in various scenarios including the benchmarking of IPv4 and IPv6 routers and Network Address Translation from IPv6 Clients to IPv4 Servers (stateful NAT64) gateways. Its feasibility is shown by disclosing the details of its implementation in siitperf. Then the proposed solution is validated by both stateless and stateful tests. It is shown that the measurement results of the tests following the proposed solution can better characterize the true performance of the network interconnect devices that follow the first type of RSS implementation than the results of the tests using a single IP address pair.
Gábor Lencse
Comput. Commun.1
2024 Benchmarking methodology for IPv4aaS technologies: Comparison of the scalability of the Jool implementation of 464XLAT and MAP-T
abstract
A novel method is proposed for the performance and scalability measurements of the IPv4-as-a-Service (IPv4aaS) technologies. It works according to the dual Device Under Test (DUT) setup of RFC 8219 and is suitable for benchmarking any of the five IPv4aaS technologies: Combination of Stateful and Stateless Translation (464XLAT), Dual-Stack Lite (DS-Lite), Lightweight 4over6 (Lw4o6), Mapping of Address and Port with Encapsulation (MAP-E), and Mapping of Address and Port using Translation (MAP-T). The method is based on the reduction of the aggregate of Customer Edge (CE) and Provider Edge (PE) devices to a stateful network address translation from IPv4 to IPv4 (stateful NAT44) gateway. The most important advantage of the novel method is that a stateful NAT44 tester can be used instead of a technology-specific tester, which usually does not exist. The proposed method is validated by the examination of the performance and scalability of the Jool Implementation of 464XLAT and MAP-T. Scalability is defined by both (1) how performance increases with the number of active Central Processing Unit (CPU) cores; and (2) how performance decreases with the increasing number of concurrent sessions. Maximum connection establishment rate and throughput are used as performance metrics. The scalability of 464XLAT and MAP-T is measured from 1 to 16 CPU cores and from 1 to 256 million connections. The measurement details and results are fully disclosed and discussed.
Gábor Lencse, Ádám Bazsó
Comput. Commun.1
2023 Benchmarking methodology for stateful NAT64 gateways
abstract
The benchmarking of Network Address and Protocol Translation from IPv6 clients to IPv4 servers (stateful NAT64) gateways is challenging from a methodological point of view because the state of the art benchmarking standards have some requirements that are conflicting when applied to stateful NAT64 gateways. In this paper, several methodological gaps are pointed out and a benchmarking methodology is proposed, which is applicable for any stateful NATxy gateways, where x and y are in {4, 6}. It bridges all the gaps by reconciling the conflicting requirements and facilitating the execution of the industry standard benchmarking measurement procedures (throughput, latency, frame loss rate, packet delay variation) with stateful NATxy gateways. New performance metrics specific to stateful testing are also defined: maximum connection establishment rate, connection tear down rate, and connection tracking table capacity. The proposed methodology is suitable for examining the scalability of the stateful NATxy gateways, too. The methodology is validated by applying it to the benchmarking of three radically different stateful NAT64 implementations: Jool, tayga plus iptables, and OpenBSD Packet Filter (PF). The details of the measurements and their results are fully disclosed.
Gábor Lencse, Keiichi Shima, Kenjiro Cho
Comput. Commun.1
2022 Design and implementation of a software tester for benchmarking stateful NATxy gateways: Theory and practice of extending siitperf for stateful tests
abstract
Our siitperf is the world’s first RFC 8219 compliant free software SIIT (Stateless IP/ICMP Translation, also called stateless NAT64) benchmarking tool. It was written in C++ using DPDK (Intel Data Plane Development Kit). Our current effort aims to design and implement a test program for stateful NATxy gateways, including both stateful NAT64 and stateful NAT44 (also called NAPT: Network Address and Port Translation). Due to the object-oriented design of siitperf, it is feasible to extend it for stateful tests, while keeping its original design and features. In this paper, we introduce the problem of benchmarking stateful NATxy gateways and propose various solutions. We disclose the design and the most important implementation decisions of the stateful extension of siitperf. We prove the viability of our design and implementation by a functional NAT64 test and performing the maximum connection establishment rate, throughput, and frame loss rate measurements of the Jool stateful NAT64 implementation. We also carry out an initial performance estimation of the stateful extension of siitperf. Our tester is distributed as free software under the GPLv3 license for the benefit of the research, benchmarking and networking communities.
Gábor Lencse
Comput. Commun.1
2020 Performance analysis of SIIT implementations: Testing and improving the methodology
abstract
In this paper, the viability of the throughput and frame loss rate benchmarking procedures of RFC 8219 is tested by executing them to examine the performance of three free software SIIT (also called stateless NAT64) implementations: Jool, TAYGA, and map646. An important methodological problem of the two tested benchmarking procedures is pointed out: they use improper timeout setting. A solution of individually checking the timeout for each frame is proposed to get more reasonable results, and its feasibility is demonstrated. The unreliability of the results caused by the lack of requirement for repeated tests is also pointed out, and the need for relevant number of tests is demonstrated. The possibility of an optional non-zero frame loss acceptance criterion for throughput measurement is also discussed. The benchmarking measurements are performed using two different computer hardware, and all relevant results are disclosed and compared. The performance of the kernel based Jool was found to scale up well with the number of active CPU cores and Jool also significantly outperformed the two other SIIT implementations, which work in the user space.
Gábor Lencse, Keiichi Shima
Comput. Commun.1
2018 Benchmarking DNS64 implementations: Theory and practice
Gábor Lencse, Youki Kadobayashi
Comput. Commun.1
2018 Methodology for the identification of potential security issues of different IPv6 transition technologies: Threat analysis of DNS64 and stateful NAT64
Gábor Lencse, Youki Kadobayashi
Comput. Secur.1
2017 Investigating the multipath extension of the GRE in UDP technology
Béla Almási, Gábor Lencse, Szabolcs Szilágyi
Comput. Commun.2
2017 Benchmarking methodology for DNS64 servers
Gábor Lencse, Marius Georgescu, Youki Kadobayashi
Comput. Commun.1
2013 Performance Analysis and Comparison of Different DNS64 Implementations for Linux, OpenBSD and FreeBSD
abstract
The transition mechanisms for the first phase of IPv6 deployment are surveyed and the most important DNS64 solutions are selected. The test environment and the testing method are described. As for the selected DNS64 implementations, the performance of both BIND9 and TOTD running under Linux, OpenBSD and FreeBSD are measured and compared. The stability of all the tested DNS64 solutions was analyzed under serious overload conditions to test if they may be used in production environments with strong response time requirements.
Gábor Lencse, Sándor R. Répás
AINA1