// HACKER NEWS — CYBERSECURITY
Research carried out using NetBSD
Several groups, organizations, and individuals have
conducted research or performed demonstrations utilizing
NetBSD as a vehicle. If you have such material that might
be appropriate for this section, and would like to make
it available here, please
let us know!
NASA Lewis Research Center - Satellite Networks and
Architectures Branch
use NetBSD almost exclusively in their investigation of TCP
for use in satellite networks. They are currently examining
several proposed modifications to the Transmission Control
Protocol (TCP) protocol. Extensions are being tested in an
attempt to improve satellite communication. However, the
extensions are also being tested in terrestrial
environments. Among the extensions being tested are
restransmission mechanisms based on selective
acknowledgements (e.g., FACK TCP) and TCP with larger
initial windows. They are currently testing the mechanisms'
performance benefits and their fairness to other traffic.
They are also working with the Internet Engineering Task
Force (IETF)'s TCP Over Satellite and TCP Implementations
Working Groups.
KAME project
. A research group for implementing IPv6, IPsec and other
recent TCP/IP related technologies into BSD UNIX kernels,
under BSD license. KAME stack got merged into
NetBSD-current tree in June 1999.
The Institute for Media
Communication (IMK)
Value-added Solutions department
. The current set of projects carries out on NetBSD:
Implementing an access control language which
is integretated into the ip stack and can be
configured by the system administrator. This gives
the system manager fine grained control over who is
allowed to access the network, at what time, when
logged in from a remote machine or not, etc...
Certain users can be prohibited network access
altogether ('nobody', 'bin', etc...). This reduces
the risk of abuse on the machines.
Setting up a tunneling server which allows
users to tunnel insecure protocols (pop3, smtp,
etc...) through a secure tunnel transparently.
They have developed a tool that protects
Internet users from receiving unsolicited bulk mail
(aka spam) and are currently evaluating whether it is
a feasible solution.
They are developing a sendmail-replacement
which allows an arbitrary number of simultaneous SMTP
connects with only one process, using asynchronous
i/o. First beta versions are -substantially- faster
than sendmail, qmail or any of the other free
MTAs.
NetBSD TCP Vegas with Live Experiments
. TCP Vegas is an extended slowstart TCP flow control from
Lawrence Brakmo et al. at the University of Arizona. Prof.
Peter B. Danzig and his group at usc.edu ported TCP Vegas
to NetBSD 1.0.