A Seattle-based security researcher has devised a way to test for net neutrality. Dan Kaminsky will share details of this technique, which will eventually be rolled into a free software tool, on Wednesday at the Black Hat USA security conference in Las Vegas. The software can tell if computers are treating some types of TCP/IP traffic better than others -- dropping data that is being used in VOIP (voiceover Internet Protocol) calls, or treating encrypted data as second class, for example.
The U.S. Congress is presently debating whether to enact "net neutrality" laws that would prevent this from happening. Net neutrality would force Internet service providers like AT&T and Comcast to give all Internet traffic the same quality of service. Advocates of these laws say they are essential to preserving the openness that has made the Internet a success. Broadband providers say that such laws could prevent them from developing a new generation of services.
Kaminsky calls his technique "TCP-based Active Probing for Faults." He says that the software he's developing will be similar to the Traceroute Internet utility that is used to track what path Internet traffic takes as it hops between two machines on different ends of the network.
But unlike Traceroute, Kaminsky's software will be able to make traffic appear as if it is coming from a particular carrier, or being used for a certain type of application, like VOIP. It will also be able to identify where the traffic is being dropped, and could ultimately be used to finger service providers who are treating some network traffic as second-class.
At Black Hat, Kaminsky will show how to perform a basic version of TCP-based Active Probing using currently available tools. He will release his own, more sophisticated software sometime within the next six months as part of a free suite of tools called Paketto Keiretsu, version 3, he said in an interview Tuesday.
The security researcher said he is curious to see what people do with his software. "People are going to start looking [at networks] and who knows what they are going to find," he said.
Already a handful of carriers have tried blocking certain types of Internet services. In March 2005, the U.S. Federal Communications Commission (FCC) fined Madison River Communications $15,000 for blocking Vonage Holdings' VOIP service, but the FCC has since changed its broadband carrier requirements and it's unclear whether it would again issue a similar fine.
Kaminsky believes that net neutrality will eventually become law, and that the type of software he is developing will help keep the carriers honest. "If you're going to enforce by law that networks be neutral, the question becomes, 'How do you test for this?'" he said. "I'm going to make sure that the tools are going to be in place."
Kaminsky plans to post information on TCP-based Active Probing for Faults at: http://www.doxpara.com.
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »