Enhancing Networks Via Virtualized Network Functions

Total Page:16

File Type:pdf, Size:1020Kb

Enhancing Networks Via Virtualized Network Functions Enhancing Networks via Virtualized Network Functions A DISSERTATION SUBMITTED TO THE FACULTY OF THE GRADUATE SCHOOL OF THE UNIVERSITY OF MINNESOTA BY Yang Zhang IN PARTIAL FULFILLMENT OF THE REQUIREMENTS FOR THE DEGREE OF DOCTOR OF PHILOSOPHY Professor Zhi-Li Zhang May, 2019 © Yang Zhang 2019 ALL RIGHTS RESERVED Acknowledgements This dissertation is accomplished with tremendous help from many amazing people. First of all, I would like to acknowledge my advisor, Professor Zhi-Li Zhang, for his con- tinuous support, criticism, encouragement, and guidance on conducting research and achieving personal long-term career goals throughout my stay in graduate school. He taught me, among many things, how to transform my stilted speaking and writing into engaging storylines, and how to identify the simplicity at the core of complex technical concepts. His knowledge, wis- dom, dedication, and strive for excellence amazed me, and I have been constantly inspired by his never-ending passion and commitment towards research. I am also indebted to a variety of brilliant researchers outside of university over the years. I want to thank my collaborators: Ruben Torres, Fang Hao, Sarit Mukherjee, T V Lakshman, Bo Han, Bilal Anwer, Joshua Reich, Aman Shaikh, Vijay Gopalakrishnan, Jean Tourrilhes, and Puneet Sharma. I am grateful to all of them for their time, help, and the wisdom they have shared with me. Their valuable feedback helped me turn my research efforts into reality. I cherish the awesome time that I spent with my lab mates in discussing research, daily life, and our future. In particular, Hesham Mekky, Eman Ramadan, Zhongliu Zhuo, Arvind Narayanan, and Zehua Guo. I have learned a lot through the discussions over the years. I am thankful to all my fellow graduate students working with Professors David Du, Tian He, and Feng Qian for their valuable feedback on my research during our group meetings and for maintaining a friendly and intellectually creative environment. I am grateful to Professors Abhishek Chandra, Yousef Saad, Georgios Giannakis, and David Du, who were very kind to serve as my committee members. I would like to especially acknowl- edge Professor Chandra here, who served as a committee member of my PhD qualification, thesis proposal, defense, and wrote recommendation letter for my fellowship application. Finally, I thank my family and friends for support during this arduous but fruitful journey. i My research was supported by various sources of funds: DoD ARO MURI Award W911NF- 12-1-0385, DTRA grant HDTRA1- 09-1-0050, NSF grants CNS-1411636, CNS-1618339, CNS- 1617729, CNS 1814322 and CNS183677. ii Dedication To those who held me up over the years iii Abstract In an era of ubiquitous connectivity, various new applications, network protocols, and on- line services (e.g., cloud services, distributed machine learning, cryptocurrency) have been con- stantly creating, underpinning many of our daily activities. Emerging demands for networks have led to growing traffic volume and complexity of modern networks, which heavily rely on a wide spectrum of specialized network functions (e.g., Firewall, Load Balancer) for per- formance, security, etc. Although (virtual) network functions (VNFs) are widely deployed in networks, they are instantiated in an uncoordinated manner failing to meet growing demands of evolving networks. In this dissertation, we argue that networks equipped with VNFs can be designed in a fash- ion similar to how computer software is today programmed. By following the blueprint of joint design over VNFs, networks can be made more effective and efficient. We begin by presenting Durga, a system fusing wide area network (WAN) virtualization on gateway with local area network (LAN) virtualization technology. It seamlessly aggregates multiple WAN links into a (virtual) big pipe for better utilizing WAN links and also provides fast fail-over thus minimizing application performance degradation under WAN link failures. Without the support from LAN virtualization technology, existing solutions fail to provide high reliability and performance required by today’s enterprise applications. We then study a newly standardized protocol, Mul- tipath TCP (MPTCP), adopted in Durga, showing the challenge of associating MPTCP subflows in network for the purpose of boosting throughput and enhancing security. Instead of designing a customized solution in every VNF to conquer this common challenge (making VNFs aware of MPTCP), we implement an online service named SAMPO to be readily integrated into VNFs. Following the same principle, we make an attempt to take consensus as a service in software- defined networks. We illustrate new network failure scenarios that are not explicitly handled by existing consensus algorithms such as Raft, thereby severely affecting their correct or ef- ficient operations. Finally, we re-consider VNFs deployed in a network from the perspective of network administrators. A global view of deployed VNFs brings new opportunities for per- formance optimization over the network, and thus we explore parallelism in service function chains composing a sequence of VNFs that are typically traversed in-order by data flows. iv Contents Acknowledgements i Dedication iii Abstract iv List of Tables ix List of Figures x 1 Introduction 1 1.1 Contributions and Organization . .2 1.2 Bibliographic Note . .3 2 Background and Motivation 5 2.1 Software Defined Wide Area Network . .5 2.2 MPTCP Awareness . .6 2.3 Consensus in Software-Defined Network . .7 2.4 Service Function Chaining and Parallelizable VNFs . .9 3 Fusing LAN Virtualization with WAN Virtualization 10 3.1 Main Results . 10 3.2 Mitigating the Impact of WAN Link Failures . 11 3.2.1 End system MPTCP to the Rescue? . 11 3.2.2 WAN-aware MPTCP . 13 3.3 Durga Overview and Mechanisms . 14 v 3.3.1 Tunnel Handoff . 14 3.3.2 MPTCP Proxy . 16 3.3.3 WAN aware MPTCP . 17 3.3.4 MPTCP Recovery Optimization . 19 3.3.5 Mechanisms Integration . 20 3.4 Vertical Handoff Performance Metrics . 21 3.5 Evaluation of Durga . 22 3.5.1 Bandwidth Aggregation Evaluation . 23 3.5.2 Handoff Traces Evaluation . 24 3.5.3 Handoff Metric Evaluation . 25 3.5.4 TCP/IP Congestion Control . 27 3.5.5 Handoff Impact on Applications . 28 3.5.6 Evaluation in the Wild . 31 3.6 Related Work . 33 3.7 Summary . 34 4 Making Network Functions Aware of Multiple TCP 35 4.1 Main Results . 35 4.2 MPTCP Subflow Association . 36 4.2.1 Token-based Solution . 36 4.2.2 Challenges in Network . 37 4.3 SAMPO Overview . 38 4.4 MPTCP Subflow Association . 39 4.4.1 DSN-based Association . 40 4.4.2 Analysis of DSN-based Association . 41 4.5 Evaluation . 51 4.5.1 Experimental Setup . 51 4.5.2 Experimental Results . 53 4.6 Related Work . 56 4.7 Summary . 57 5 Taking Consensus as a Service in Software Defined Network 58 5.1 Main Results . 58 vi 5.2 Fundamentals . 59 5.2.1 Raft Overview . 59 5.2.2 P4 Overview . 61 5.3 Raft Meets SDN . 61 5.4 System Design . 64 5.4.1 Possible Solutions During Leader Election . 64 5.4.2 Offloading Raft to P4 Switch . 66 5.5 Evaluation . 68 5.5.1 Raft with Routing via PrOG . 68 5.5.2 Raft-aware P4 Switch . 70 5.6 Related Work . 71 5.7 Summary . 72 6 Parallelizing Network Functions For Accelerating Service Function Chains 73 6.1 Main Results . 73 6.2 Challenges in Parallelizing VNFs . 74 6.3 HydraNF Overview . 76 6.4 HydraNF Controller . 78 6.4.1 SPG Construction . 78 6.4.2 SPG Provisioning . 82 6.5 HydraNF Data Plane . 85 6.5.1 Mirror and Merge Modules . 85 6.5.2 Placement of Mirror and Merge . 87 6.6 Evaluation . 88 6.6.1 HydraNF Performance . 90 6.6.2 HydraNF Overhead . 92 6.7 Related Work . 93 6.8 Discussion . 95 6.9 Summary . 96 7 Conclusion, Lessons Learned & Thoughts for the Future 97 7.1 Summary of Contributions . 97 7.2 Lessons Learned & Thoughts for the Future . 98 vii References 101 viii List of Tables 3.1 Throughput aggregation comparison . 23 3.2 Vertical handoff performance of different mechanisms . 26 3.3 Impact of TCP congestion control (BFD=1s) . 29 3.4 HTTP download duration with intermittent link in controlled testbed (seconds for 2GB file) . 29 3.5 TCP transaction rate with intermittent link in controlled testbed (transactions / seconds) . 30 3.6 HTTP download duration with intermittent link in GENI testbed, 100ms BFD (seconds for 20MB file) . 31 3.7 TCP transaction rate with intermittent link in GENI testbed, 100ms BFD (trans- actions / seconds) . 32 3.8 Parameters to access Amazon EC2 . 32 3.9 Parameters to access Amazon EC2 . 32 5.1 Decomposed Latency between Raft Leader and a Follower. a: RPC latency at leader side + bidirectional latency between S1 and P4 1; b: bidirectional la- tency in P4 1; c: bidirectional latency between P4 1 and P4 2; d: bidirectional latency in P4 2; e: bidirectional latency between P4 2 and S2 + latency at Raft follower . 70 6.1 Service Function Chains Used in the Experiments . ..
Recommended publications
  • SOLUTIONS Products &
    Top Brands • Quality Equipment • Total Solutions Products & Splicing Equipment SOLUTIONS Test Equipment Consumables & Tools Cable Connectivity Cable Assemblies Outside Plant Cable Management Active Components Premise Security 2016–2017 Product Catalog Part of the Group Company Profile ince its formation in 1995, FiberOptic.com has become the number one on-line provider of fiber optic products, Straining and rental solutions. The Fiber Optic Marketplace, LLC began as an on-line business–to–business portal for the fiber optic community, and has expanded its business both domestically and internationally. The company’s customers include Fortune 500 companies, telecommunications providers, the military, installers, contractors and educational institutions from across the globe. In addition to efficient product distribution, FiberOptic.com offers classroom, on– site and on-line training courses for individuals interested in fiber optic theory and installation. Experienced fiber optics instructors conduct training classes throughout the year at our location in Breinigsville, Pennsylvania. On-site training programs are also available for groups of six students or more. The company also offers equipment rentals including fusion splicers and OTDRs. The Fiber Optic Marketplace, LLC is committed to maintaining excellent customer service and client relations. As we continue into the future, the company will continue to offer expertise in the field of fiber optics by providing customized solutions for our customers’ project requirements. We will continue to uphold our status as the number one on-line provider of fiber optic products, training and rental solutions. SHIPPING OPTIONS • Same day shipping for in-stock products ordered before 3PM EST. • You choose your shipping method: UPS, FedEx, DHL or U.S.
    [Show full text]
  • KINTSUGI Identifying & Addressing Challenges in Embedded Binary
    KINTSUGI Identifying & addressing challenges in embedded binary security jos wetzels Supervisors: Prof. dr. Sandro Etalle Ali Abbasi, MSc. Department of Mathematics and Computer Science Eindhoven University of Technology (TU/e) June 2017 Jos Wetzels: Kintsugi, Identifying & addressing challenges in embed- ded binary security, © June 2017 To my family Kintsugi ("golden joinery"), is the Japanese art of repairing broken pottery with lacquer dusted or mixed with powdered gold, silver, or platinum. As a philosophy, it treats breakage and repair as part of the history of an object, rather than something to disguise. —[254] ABSTRACT Embedded systems are found everywhere from consumer electron- ics to critical infrastructure. And with the growth of the Internet of Things (IoT), these systems are increasingly interconnected. As a re- sult, embedded security is an area of growing concern. Yet a stream of offensive security research, as well as real-world incidents, contin- ues to demonstrate how vulnerable embedded systems actually are. This thesis focuses on binary security, the exploitation and miti- gation of memory corruption vulnerabilities. We look at the state of embedded binary security by means of quantitative and qualitative analysis and identify several gap areas and show embedded binary security to lag behind the general purpose world significantly. We then describe the challenges and limitations faced by embedded exploit mitigations and identify a clear open problem area that war- rants attention: deeply embedded systems. Next, we outline the cri- teria for a deeply embedded exploit mitigation baseline. Finally, as a first step to addressing this problem area, we designed, implemented and evaluated µArmor : an exploit mitigation baseline for deeply em- bedded systems.
    [Show full text]
  • Junos OS NAT Configuration Examples for Screenos Users
    Network Configuration Example Junos OS NAT Configuration Examples for ScreenOS Users Published: 2014-01-10 Copyright © 2014, Juniper Networks, Inc. Juniper Networks, Inc. 1194 North Mathilda Avenue Sunnyvale, California 94089 USA 408-745-2000 www.juniper.net Juniper Networks, Junos, Steel-Belted Radius, NetScreen, and ScreenOS are registered trademarks of Juniper Networks, Inc. in the United States and other countries. The Juniper Networks Logo, the Junos logo, and JunosE are trademarks of Juniper Networks, Inc. All other trademarks, service marks, registered trademarks, or registered service marks are the property of their respective owners. Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice. Network Configuration Example Junos OS NAT Configuration Examples for ScreenOS Users NCE0073 Copyright © 2014, Juniper Networks, Inc. All rights reserved. The information in this document is current as of the date on the title page. YEAR 2000 NOTICE Juniper Networks hardware and software products are Year 2000 compliant. Junos OS has no known time-related limitations through the year 2038. However, the NTP application is known to have some difficulty in the year 2036. END USER LICENSE AGREEMENT The Juniper Networks product that is the subject of this technical documentation consists of (or is intended for use with) Juniper Networks software. Use of such software is subject to the terms and conditions of the End User License Agreement (“EULA”) posted at http://www.juniper.net/support/eula.html. By downloading, installing or using such software, you agree to the terms and conditions of that EULA.
    [Show full text]
  • Juniper Networks Inc
    JUNIPER NETWORKS INC FORM 10-K (Annual Report) Filed 02/26/13 for the Period Ending 12/31/12 Address 1194 NORTH MATHILDA AVE SUNNYVALE, CA 94089 Telephone 4087452000 CIK 0001043604 Symbol JNPR SIC Code 3576 - Computer Communications Equipment Industry Communications Equipment Sector Technology Fiscal Year 12/31 http://www.edgar-online.com © Copyright 2013, EDGAR Online, Inc. All Rights Reserved. Distribution and use of this document restricted under EDGAR Online, Inc. Terms of Use. Table of Contents UNITED STATES SECURITIES AND EXCHANGE COMMISSION Washington, D.C. 20549 Form 10-K (Mark One) ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 For the fiscal year ended December 31, 2012 OR TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 For the transition period from__________ to____________ Commission file number 001-34501 JUNIPER NETWORKS, INC. (Exact name of registrant as specified in its charter) Delaware 77-0422528 (State or other jurisdiction of incorporation or organization) (IRS Employer Identification No.) 1194 North Mathilda Avenue Sunnyvale, California 94089 (408) 745-2000 (Address of principal executive offices)(Zip Code) ( Registrant's telephone number, including area code) Securities registered pursuant to Section 12(b) of the Act: Title of Each Class Name of Each Exchange on Which Registered Common Stock, par value $0.00001 per share New York Stock Exchange Securities registered pursuant to Section 12(g) of the Act: None Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act.
    [Show full text]
  • Certification Report Juniper Junos OS 20.2R1 for SRX345, SRX345-DUAL-AC, SRX380 and SRX1500
    Australasian Information Security Evaluation Program Certification Report Juniper Junos OS 20.2R1 for SRX345, SRX345-DUAL-AC, SRX380 and SRX1500 Version 1.0, 03 December 2020 Table of contents Executive summary 1 Introduction 3 Overview 3 Purpose 3 Identification 3 Target of Evaluation 5 Overview 5 Description of the TOE 5 TOE Functionality 5 TOE physical boundary 5 Architecture 8 Clarification of scope 9 Evaluated functionality 9 Non-TOE hardware/software/firmware 9 Non-evaluated functionality and services 9 Security 9 Usage 10 Evaluated configuration 10 Secure delivery 10 Installation of the TOE 11 Version verification 11 Documentation and guidance 11 Secure usage 11 ii Evaluation 13 Overview 13 Evaluation procedures 13 Functional testing 13 Entropy testing 13 Penetration testing 13 Certification 14 Overview 14 Assurance 14 Certification result 14 Recommendations 14 Annex A – References and abbreviations 16 References 16 Abbreviations 17 iii Executive summary This report describes the findings of the IT security evaluation of Juniper Networks Junos OS 20.2R1 for SRX345, SRX345-DUAL-AC, SRX380 and SRX1500 appliances against Common Criteria approved Protection Profiles (PPs). Each Juniper Networks SRX Services Gateway appliance is a security system that supports a variety of high-speed interfaces for medium/large networks and network applications. Juniper Networks appliances share common Junos firmware, features, and technology for compatibility across platforms. This report concludes that the Target of Evaluation (TOE) has complied with the following PPs [4]: . collaborative Protection Profile for Network Devices, version 2.1, 24 September 2018 (NDcPP) . PP-Module for Stateful Traffic Filter Firewalls, Version 1.3, 27 September 2019 (FW_MOD) .
    [Show full text]
  • Junos® OS Intrusion Detection and Prevention User Guide Copyright © 2021 Juniper Networks, Inc
    Junos® OS Intrusion Detection and Prevention User Guide Published 2021-09-21 ii Juniper Networks, Inc. 1133 Innovation Way Sunnyvale, California 94089 USA 408-745-2000 www.juniper.net Juniper Networks, the Juniper Networks logo, Juniper, and Junos are registered trademarks of Juniper Networks, Inc. in the United States and other countries. All other trademarks, service marks, registered marks, or registered service marks are the property of their respective owners. Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice. Junos® OS Intrusion Detection and Prevention User Guide Copyright © 2021 Juniper Networks, Inc. All rights reserved. The information in this document is current as of the date on the title page. YEAR 2000 NOTICE Juniper Networks hardware and software products are Year 2000 compliant. Junos OS has no known time-related limitations through the year 2038. However, the NTP application is known to have some difficulty in the year 2036. END USER LICENSE AGREEMENT The Juniper Networks product that is the subject of this technical documentation consists of (or is intended for use with) Juniper Networks software. Use of such software is subject to the terms and conditions of the End User License Agreement ("EULA") posted at https://support.juniper.net/support/eula/. By downloading, installing or using such software, you agree to the terms and conditions of that EULA. iii Table of Contents
    [Show full text]
  • Day One: Junos® Pyez Cookbook
    DAY ONE: JUNOS® PyEZ COOKBOOK Books Networks Juniper Day One: Junos PyEZ Cookbook is a complete network automation cookbook with a set-up guide, a start-up sandbox, and a complete showcase of automation scripts that are readily available on GitHub. The cookbook is a joint effort by Juniper’s engineers and all the many Junos users and customers who want to show you how ‘EZ’ network automation can be. You ONE:DAY don’t have to be a coder when you can leverage Junos as your network OS. DAY ONE: JUNOS® PyEZ COOKBOOK “The decision to read a technical book involves a cost-benefit analysis. ‘Is the information I’m going to learn worth my time and energy?’ If your currently operating a network of Juniper devic- es using the Junos OS command line interface, then the unequivocal answer is ‘Yes!’ Written by an experienced team of Juniper’s customers, ambassadors, partners, and employees, Day One: Junos PyEZ Cookbook demonstrates its authors’ real-world experience in operating and auto- JUNOS Co-written by Juniper Customers, mating networks. More importantly, the book breaks what could be daunting tasks into small Ambassadors, Partners, and Employees and relevant recipes. You will be creating useful network automation tools with the Junos PyEZ library on day one. Happy Automating!” Stacy Smith, Sr. Software Developer for Junos Automation, Juniper Networks, ® Co-Author of Automating Junos Administration COOKBOOK PyEZ IT’S DAY ONE AND YOU HAVE A JOB TO DO, SO LEARN HOW TO: n Understand Basic Python Concepts; Get the Downloads and Resources to Set Up
    [Show full text]
  • Request System Power Off
    Request System Power Off Niki frank reminiscently. Unlicensed Jackie tubulates notably. Conjectural Vincent retiringly that ecclesiastic counselling pithy and premeditate wrongly. Be able to boot from the node id information and system power, and will get diagnostic information To schedule the treaty to shutdown with a cronjob or there just share to look open and. It is occasionally possible mortgage even Linux servers to dispense into an unrecoverable error which in hand may result in trying halt or server shutdown. Power off your kidney by unplugging the power loss or turning off the shave at. Be adequately cooled the Routing Engine shuts down entire system by disabling. Start going in which must press j series, but none which today still happens when you would be? Halt instructs the hardware to mimic all CPU functions but leaves the precise in a powered-on state department usually let someone random to thumb down your machine. EPO it is usual for a UPS and other affected equipment to require their manual restart. Tv is recoverable using them off runaway processes, tailor your server did not from a requests for localstorage names can. Juniper srx firewall devices using system would have is running configuration and cleanly unmounted and side or even though it up and also notified are special. Http requests so helpful users will be off power off, some things work only a few unanswered questions or perform a filesystem, you choose ultimately depends on. They leave your vps or junoscript session has provision to. When you shutting down my organization, you want to delay before troubleshooting or add action section describes how a system power off? All node is run is logged in process is structured and does not mandatory that is used for validation purposes.
    [Show full text]
  • Release Notes
    ® ® Juniper Networks Junos 11.4 for the MAG-CM060 Release Notes Release 11.4 October 2012 Revision 1 These release notes describe device documentation and known problems with Release 11.4 of the Junos OS for the MAG Series Junos Pulse Gateway MAG-CM060. Contents Junos OS Release Notes for MAG Series Junos Pulse Gateway MAG-CM060 . 2 CMC Overview . 2 Limitations in Junos OS Release 11.4 for the MAG-CM060 . 2 Interfaces . 2 SNMP . 2 CLI . 2 Outstanding Issues in Junos OS Release 11.4 for the MAG-CM060 . 2 J-Web . 2 Resolved Issues in Junos OS Release 11.4 for MAG Series Junos Pulse Gateway . 3 CLI . 3 J-Web . 4 Junos OS Documentation and Release Notes . 5 Documentation Feedback . 5 Requesting Technical Support . 5 Revision History . 6 Copyright © 2012, Juniper Networks, Inc. 1 Junos 11.4 Software Release Notes for the MAG-CM060 Junos OS Release Notes for MAG Series Junos Pulse Gateway MAG-CM060 • CMC Overview on page 2 • Limitations in Junos OS Release 11.4 for the MAG-CM060 on page 2 • Outstanding Issues in Junos OS Release 11.4 for the MAG-CM060 on page 2 • Resolved Issues in Junos OS Release 11.4 for MAG Series Junos Pulse Gateway on page 3 CMC Overview The Juniper Networks® MAG Series Junos® Pulse Gateways are a family of modular, purpose designed gateways that can meet the accelerated secure connectivity needs of small to large enterprises. Deployed in combination with Juniper’s award winning Junos Pulse client, which can be deployed on mobile devices, laptops, and desktops, the modular MAG Series Junos Pulse Gateways provide a single point of convergence for the SSL VPN, mobile device security and management, NAC, and other network applications for the enterprise.
    [Show full text]
  • Abril De 2021
    Boletín de abril de 2021 Avisos Técnicos Vulnerabilidad de gestión incorrecta de URL en VMware Carbon Black Cloud Workload Fecha de publicación: 05/04/2021 Importancia: Crítica Recursos afectados: VMware Carbon Black Cloud Workload, versión 1.0.1 y anteriores ejecutándose en sistemas Linux. Descripción: Egor Dimitrenko, investigador de Positive Technologies, ha reportado a VMware una vulnerabilidad, con severidad crítica, en la que un atacante podría realizar una escalada de privilegios debido a una gestión incorrecta de URL. Solución: Actualizar VMware Carbon Black Cloud Workload a la versión 1.0.2. Detalle: Un atacante, con acceso de red a la interfaz administrativa del dispositivo VMware Carbon Black Cloud Workload, podría obtener un token de autenticación válido, concediendo acceso a la API de administración del dispositivo. La explotación exitosa de esta vulnerabilidad podría permitir al atacante ver y alterar los ajustes de configuración administrativa. Se ha asignado el identificador CVE-2021-21982 para esta vulnerabilidad. Etiquetas: Actualización, Virtualización, VMware, Vulnerabilidad Múltiples vulnerabilidades en varios productos de Cisco Fecha de publicación: 08/04/2021 Importancia: Crítica Recursos afectados: Rúters Cisco Small Business: RV110W Wireless-N VPN Firewall; RV130 VPN Router; RV130W Wireless-N Multifunction VPN Router; RV215W Wireless-N VPN Router. Software SD-WAN vManage, versión 18.4 y anteriores, 19.2, 19.3, 20.1, 20.3 y 20.4. Descripción: Se han identificado 2 vulnerabilidades de severidad crítica y otras 2 de severidad alta que podrían permitir a un atacante, remoto y no autenticado, realizar una escalada de privilegios o ejecutar código arbitrario. Solución: En el caso del Software SD-WAN vManage, se recomienda actualizar a las versiones estables 19.2.4, 20.3.3 y 20.4.1 respectivamente.
    [Show full text]
  • Sysadministrivia S0E13: "Better Late Than Never"
    Sysadministrivia Linux, Lagers, and Late Nights S0E13: "Better Late than Never" Posted 2015-08-31 08:25 Modified 2018-12-03 03:35 Comments 0 Navigation Previous Episode Next Episode S0E12: "It Hurts when IP" S0E14: "A Failed Experiment" Log Recorded (UTC) Aired (UTC) Editor 2015-07-31 04:55:19 2015-08-31 08:25:45 MOQ Verification Format SHA256 GPG Audio File MP3 87575aea34439873404702a49bd038f1c376e0596b51d0ce44206ce046d7189c click click OGG ed06b642e6c190f4a89af3c189636a133f7a7da346d4820517c5b0546156d43a click click Quicklisten: We discuss an Android vulnerability, GNU/Linux malware, OpenSSH v7.x, more NSA nonsense, a case study of extreme-low-latency networks, BSD comparison, and some home NAS software. Notes Errata Music Notes The Stagefright vulnerability (CVEs: CVE-2015-1538, CVE-2015-1539, CVE-2015-3827, CVE-2015-3826, CVE-2015-3828, CVE-2015-3824, CVE-2015- 3829). You can find more information and a PoC here. The iOS thing I ran the Stagefright detector app and it seems CyanogenMod (at least the nightlies, as of 08.29.2015) is not vulnerable. Speaking of Android/CyanogenMod and security, you may want to check out Copperhead OS, a hardened and privacy-focused fork of CyanogenMod. @MalwareMustDie is awesome. They found this malware, and present an awesome case study on it. Jthan suggests joining a mailing list. Here are some good ones. Mitre, OSS-Sec, Full Disclosure, etc.- a lot of really good lists are available for subscription at SecLists.org (maintained by the Nmap project maintainer/author, Fyodor). Not only has OpenSSH 6.9 released, but all the way up to 7.1 has as well! You can read the changelog document we reference here… But you can read the changelog for 7.1 here.
    [Show full text]
  • Assurance Activity Report Junos OS 19.2R1-S2 for SRX5400, SRX5600 and SRX5800 Series
    FOR PUBLIC RELEASE Assurance Activity Report Junos OS 19.2R1-S2 for SRX5400, SRX5600 and SRX5800 Series ffa90e2856686b53f1aa8978a4192c219b1d7f42ef7aaa0442d558e8eec2af614e9cba2663779fe390e644039ad61177e7371f7c12ee1fa901661cb1c8a86f1e7be96b58d16958ab9783623f786af68b3dcc9d5a97e1352e31b2ceebcaabc6925ffabb4cfab1f4ec9213b 51e042a93e76bb3f796b25e2c975a17762c2ff194940f11fc9c14a5b1b504c07a375ed2b00ab9777a1a8e4865baac29d06a38452c01fa640a005de1dfe78d170ca710666216d0f7e907cc93d13e13c09fee644ae540097935deedf598c7a687b8ee4fcf78fd6be0a71ada 4b40b6f0d884053fd3ef7100b6eed01daa308c14c3c95 2f3d6529baaaee58b69c01fc1f898217b28cb4ca43f7f77c1b32db4bd1f866df9e0cf2cf5b7dbeb17d42a0ae90352e78477695f94d6fba11e84f279f41a760a27971e8c2e16f063df5fc477cf3b2a438e7ca3abe 01e366df55de0fa9a89406373d34b2f6b27e60edfbc7f935e4c8db7368aee78294609f10489c277fbbb76ec5cb25b12fde50353b7004712db8dd54bb59bc2778067233163fc97c865873911bfd8bdf342cfa79b0379b7662e8cd11149f8d9a6cbd083248e4a07ddd3ad13 31e0d12be8e7a9696e721b973c3f3252c23e6687530ebe3d32c912233afa6f13fec94e20597cd0ac83efd8bc68bcc067b3db74b4e4f5b85d2cd7756ad92006ff9763acf78850ca34dec5dafe523dffb525aeeb0629797c4dc1168e8366b24ab3cbfd11a513ebf8137acee 37329032e83390a8b5f43e7eba8b042c00dadd5238e65f63e09ec7e47628312490fb35e563 25ff19ee9e35648dd44f330 964957437322936cfe76166a882728 14d3a7f2ce72106d017cfa8b113e68591c96981aa0db291d0263bae313608c67136648623ce50275c20e06 0759cfb65a220c20c075162f56cb7e0c551b87bdafb9da055d08f8b3597d87a831bea5fba2469c8f8f35357f43c0fd3c3980304f7d78b60de073ccf9705844e48e5c9b3291965bedd50de080bb7bb6d43be5fe2ed6c2030003073a3b31e548e9b6aac75b6ff2405e7a065
    [Show full text]