We hope you are enjoying the ride as we continue our journey through IPv6. Below
we have a great mix of talks, slides, and videos in this area posted below. We
look forward to hosting more IPv6 (March 14^(th) & 15^(th)) talks next year at
TROOPERS16!
“New Features of the SI6 Networks’IPv6 Toolkit” talk created and given by
Fernando Gont
The IPV6 Toolkit was originally developed for UK CPNI in an effort to enhance
and be able to test the current state of IPv6 security. The toolkit itself was
mainly developed for security analysis and trouble shooting of IPv6 networks and
implementations. It is running on a wide range of *nix based systems (this
probably is considered painful to support given that low level implementation of
network functions) and release under the GPL. You can directly check it out
here: https://github.com/fgont/ipv6toolkit.
Welcome to the third edition of “Beyond the Thunderdome: A Review of
TROOPERS15”. The focus today is on IPv6 and Data Center Networks, so kick back
and enjoy the following talks and videos. And as always, check out our website
www.troopers.de for details on TROOPERS16 March
14-18, 2016.
“Enabling and Securing IPv6 in Service Provider Networks” talk created and given
by Tarko Titan
Telekom.ee had no IPv6, 8 moths ago. They deployed IPv6 in about 4 weeks and by
now about 6% of all transported traffic is IPv6 traffic. Actually the 4 weeks
timeframe is a bit too optimistic but more on that later. Tarko first explains
the biggest problems in the network migration, which were the access network and
the Customer -Provider Edge (CPE). Also Telekom Estonia doesn’t want to make a
tradeoff at security in the IPv6 deployment.
Today’s focus in our blog series will cover large-scale environments:
Cryptography in Cloud environments and Network Automation. Since these topics
will only become more important over time stay tuned for our
TROOPERS16’s developing agenda to see what new talks
will be available (or submit your own talk during our Call for Papers starting
in August via our new CFP Submission tool!)
“Crypto in the Cloud” talk created and given by Frederik Armknecht
IPv6 is often called a “complex protocol”, not least by myself (for example in
my
keynote to the IPv6 Security Summit 2014). In
this post I want to have a quick look at three questions:
– Can IPv6 be considered a “complex protocol”?
– Is it “more complex” than IPv4?
– Can we expect IPv6 networks to be “complex networks”?
I’d like to start with some clarifications and a definition. First of all: when
I discuss IPv6 “as a protocol”, this actually means “the IPv6 procotol family”
incl. those helper protocols needed to support (“core”) IPv6 in performing
properly in most networks, like ICMPv6 and MLD.
Then, of course, we have to define the term “complexity”, which is a difficult
task in itself. [MITCHELL2009] gives an overview of several potential
(definition) approaches in a dedicated chapter and the same undertaking is
performed – in quite different ways – by most of the authors of individual
contributions to [PELITI1988].
Here in Heidelberg we are already gearing up for TROOPERS16 (taking place from
14th to 18th March 2016!). While you are preparing for our Call for Papers or
waiting eagerly to sign up for your spot in one of our legendary trainings take
a look at our newest blog series “Beyond the Thunderdome: A Review of
TROOPERS15”. It may offer some inspiration, help you kill time while waiting for
next year’s TROOPERS, or for those that are new to our conference, give you a
taste for what TROOPERS is all about. See you soon
at TROOPERS16!
Two weeks ago Christopher and I joined the RIPE70 meeting in Amsterdam. Being
part of the group was fun as always and we had quite some interesting
conversations with peers from the IPv6 community.
We could even contribute a bit to some discussions, with two talks. I gave one
titled “Will It Be Routed? – On IPv6 Address Space Allocation & Assignment
Approaches in Very Large Organizations” in the Address Policy Working Group
session on Wednesday. This is the abstract:
There are lots of interesting places to visit in Amsterdam, but if you are there
between the 26th and the 29th of May, then our booth at HAXPO exhibition should
be your main destination.
HAXPO is a great exhibition, where you can
become up-to-date with the latest security technologies, attend various
workshops and get in touch with more than 35 IT and information security
companies. It will take place in the beautiful historical building “Beurs van
Berlage” in the center of Amsterdam. As usual, ERNW will take part in HAXPO. We
will be waiting for you in the Community Village section (booth NL-018). Come
visit and get to know more about us. You are invited to take our hacking
challenges, where the levels of complexity vary from beginners to advanced.
Furthermore, we will bring our KNX hacking suitcase!
In our
talks
in the past we showed what might be possible if an attacker gets access to
backhaul and/or core network of a telecommunication provider. In a security
analysts perspective this is really disgusting, but provider always will
argument that those attack scenarios are not realistic.
Because of legal restrictions we are not able to demonstrate this in practice
(e.g. by breaking in into a BTS environment somewhere in the woods) but what we
can do is this: building a lab.
Sometimes it is really shocking what you can buy on Ebay, right? Here we got one
very interesting component: a Huawei BBU3900 BaseStation which is used by a
couple of providers. Okay, it is for GSM-Rail, but the technology behind is very
equal. And for 100 dollars (plus shipping) you don’t ask further questions…
A few days later than planned (sorry about that), but here we go with part 2
(Part1) and
the demodulation/analysis part.
Initial Analysis
To analyse a captured signal, the tool baudline seems to be the best way at the
moment. So we open it with the following options and have a closer look
(ContextMenu->Input->Open file):
After using the open button, you should be able to see something similar to
this:
I attended this really nice conference in Slovenia on April
16th. It was a smaller conference, but very memorable for the people (students,
IT sec professionals and managers alike) who attended.
I also had the pleasure to present
on How secure am I with EMET?
and
Evaluating the APT armor and
wanted to share the slides with you — feel free to approach me for any kind of
feedback or discussion.