Ingmar Poese

dblp:17/9081 · DBLP profile ↗
← Back
19ranked-venue papers
2as first author
8since 2021 · last 2024
0000-0002-6326-9854ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 14 · 2 first-author · 5 since 2021Security and privacy · 3 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Systems, architecture and hardware · 1Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2024 IPD: Detecting Traffic Ingress Points at ISPs
abstract
Detecting where traffic enters a network enhances network operation, but poses a complex measurement problem that requires analyzing a continuous traffic stream from all border routers---a challenging task for ISPs in the absence of a scalable approach.
Stefan Mehner, Jens Helge Reelfs, Ingmar Poese, Oliver Hohlfeld
SIGCOMM3
2024 Measurement-Noise Filtering for Automatic Discovery of Flow Splitting Ratios in ISP Networks
abstract
Network telemetry and analytics is essential for providing highly dependable services in modern computer networks. In particular, network flow analytics for internet service provider (ISP) networks allows operators to inspect and reason about traffic patterns in their networks in order to react to anomalies. High performance network analytics systems are designed with scalability in mind and can consequently only observe partial information about the network traffic. Still, they need to provide a holistic view of the traffic, including the distribution of different traffic flows on each link. It is impractical to monitor such fine-grained telemetry, and in large, heterogeneous networks, it is often too complex and error prone, if not impossible, to access and maintain all technical specifications and router-specific configurations needed to determine, for example, the load balancing weights used when traffic is split onto multiple paths. The ratios by which flows are split on the possible paths must be derived indirectly from the measured flow demands and link utilizations. Motivated by a case study provided by a major European ISP, we suggest an efficient method to estimate the flow splitting ratios. Our approach, based on quadratic linear programming, is scalable and achieves robustness to the measurement noise found in a typical network analytics deployment by filtering out certain constraints in the linear program. Finally, we implement an automated tool for estimating the flow splitting ratios and document its applicability on real data from the ISP.
Morten Konggaard Schou, Ingmar Poese, Jirí Srba
Formal Aspects Comput.2
2023 Enhancing Global Network Monitoring with Magnifier
Tobias Bühler, Romain Jacob, Ingmar Poese, Laurent Vanbever
NSDI3
2023 Characterizing the VPN Ecosystem in the Wild
Aniss Maghsoudlou, Lukas Vermeulen, Ingmar Poese, Oliver Gasser
PAM3
2023 Discovery of Flow Splitting Ratios in ISP Networks with Measurement Noise
abstract
Network telemetry and analytics is essential for providing highly dependable services in modern computer networks. In particular, network flow analytics for ISP networks allows operators to inspect and reason about traffic patterns in their networks in order to react to anomalies. High performance network analytics systems are designed with scalability in mind, and can consequently only observe partial information about the network traffic. Still, they need to provide a holistic view of the traffic, including the distribution of different traffic flows on each link. It is impractical to monitor such fine-grained telemetry, and in large, heterogeneous networks it is often too complex and error-prone, if not impossible, to access and maintain all technical specifications and router-specific configurations needed to determine e.g. the load balancing weights used when traffic is split onto multiple paths. The ratios by which flows are split on the possible paths must be derived indirectly from the measured flow demands and link utilizations. Motivated by a case study provided by a major European ISP, we suggest an efficient method to estimate the flow splitting ratios. Our approach, based on quadratic linear programming, is scalable and robust to the measurement noise found in a typical network analytics deployment. Finally, we implement an automated tool for estimating the flow splitting ratios and document its applicability on real data from the ISP.
Morten Konggaard Schou, Ingmar Poese, Jirí Srba
PRDC2
2022 FlowDNS: correlating netflow and DNS streams at scale
abstract
Knowing customer's interests, e.g. which Video-On-Demand (VoD) or Social Network services they are using, helps telecommunication companies with better network planning to enhance the performance exactly where the customer's interests lie, and also offer the customers relevant commercial packages. However, with the increasing deployment of CDNs by different services, identification, and attribution of the traffic on network-layer information alone becomes a challenge: If multiple services are using the same CDN provider, they cannot be easily distinguished based on IP prefixes alone. Therefore, it is crucial to go beyond pure network-layer information for traffic attribution.
Aniss Maghsoudlou, Oliver Gasser, Ingmar Poese, Anja Feldmann
CoNEXT3
2022 On the Benefits of Joint Optimization of Reconfigurable CDN-ISP Infrastructure
abstract
ISP networks have become a critical infrastructure in our society. Traffic in these networks is growing and is increasingly dominated by a small number of large CDNs connecting at multiple locations. Simultaneously, the networks are becoming more flexible, in terms of routing, CDN user mapping, and also regarding the IP topology: emerging optical technologies allow to flexibly reconfigure the network. This paper studies the potential gains of these reconfiguration flexibilities. The idea is to make CDN-ISP infrastructure demand-aware, that is, to re-optimize it towards the changing end-user demands over time. We present an optimization framework and conduct an extensive evaluation using data from a large European ISP. We find that such a reconfigurable infrastructure has indeed a high potential: by leveraging spatial and diurnal traffic patterns, the efficiency of ISP networks and CDNs is improved significantly. Specifically, the required backbone capacity is reduced by 15% while reducing path lengths by 30%, on average and during the critical peak hour. Moreover, such infrastructures can leverage re-optimizations during specific events, like the COVID-19 pandemic, and under link failures. We optimistically assume a cooperative environment of ISPs and CDNs, and we conclude by discussing trends that foster the identified benefits in practice.
Johannes Zerwas, Ingmar Poese, Stefan Schmid 0001, Andreas Blenk
IEEE Trans. Netw. Serv. Manag.2
2021 Spillover Today? Predicting Traffic Overflows on Private Peering of Major Content Providers
abstract
Large content providers and content distribution network operators usually connect with large Internet service providers (eyeball networks) through dedicated private peering. The capacity of these private network interconnects is provisioned to match the volume of the real content demand by the users. Unfortunately, in cases in which there is a surge in traffic demand, (e.g., due to trending content or massive software updates) the capacity of the private interconnect may deplete, requiring the content provider/distributor to reroute the excess traffic through transit providers. Although such overflow events are rare, they negatively impact content providers, Internet service providers, and end-users. Such impact includes unexpected delays and disruptions that reduce the quality of the user experience, as well as direct costs paid by the Internet service provider to the transit providers. In this article, we examine the problem of predicting an overflow event in order to enable content and Internet service providers to handle the excess traffic in a timely manner. We propose an ensemble of deep learning models trained to predict overflow events over a short-term horizon of 2–4 hours and predict the specific interconnections through which the excess traffic will enter the Internet service provider. Evaluated with 2.5 years (2017-2019) of traffic measurement data from a large European Internet service provider, the models were shown to successfully recall 65% of the events with precision of 51% on average. While the lockdowns imposed by the COVID-19 pandemic reduced the overflow prediction accuracy, the pandemic’s impact on the accuracy was temporary. Although the lockdown continued on and off, the performance of models trained before the pandemic regained their performance during April-May 2020.
Elad Rapaport, Ingmar Poese, Polina Zilberman, Oliver Holschke, Rami Puzis
IEEE Trans. Netw. Serv. Manag.2
2020 The Lockdown Effect: Implications of the COVID-19 Pandemic on Internet Traffic
abstract
Due to the COVID-19 pandemic, many governments imposed lock-downs that forced hundreds of millions of citizens to stay at home. The implementation of confinement measures increased Internet traffic demands of residential users, in particular, for remote working, entertainment, commerce, and education, which, as a result, caused traffic shifts in the Internet core.
Anja Feldmann, Oliver Gasser, Franziska Lichtblau, Enric Pujol-Gil, Ingmar Poese, Christoph Dietzel, Matthias Wichtlhuber, Juan Tapiador, Narseo Vallina-Rodriguez, Oliver Hohlfeld, Georgios Smaragdakis
Internet Measurement Conference5
2020 Exploring Network-Wide Flow Data With Flowyager
abstract
Many network operations, ranging from attack investigation and mitigation to traffic management, require answering network-wide flow queries in seconds. Although flow records are collected at each router, using available traffic capture utilities, querying the resulting datasets from hundreds of routers across sites and over time, remains a significant challenge due to the sheer traffic volume and distributed nature of flow records. In this article, we investigate how to improve the response time for a priori unknown network-wide queries. We present Flowyager, a system that is built on top of existing traffic capture utilities. Flowyager generates and analyzes tree data structures, that we call Flowtrees, which are succinct summaries of the raw flow data available by capture utilities. Flowtrees are self-adjusted data structures that drastically reduce space and transfer requirements, by 75% to 95%, compared to raw flow records. Flowyager manages the storage and transfers of Flowtrees, supports Flowtree operators, and provides a structured query language for answering flow queries across sites and time periods. By deploying a Flowyager prototype at both a large Internet Exchange Point and a Tier-1 Internet Service Provider, we showcase its capabilities for networks with hundreds of router interfaces. Our results show that the query response time can be reduced by an order of magnitude when compared with alternative data analytics platforms. Thus, Flowyager enables interactive network-wide queries and offers unprecedented drill-down capabilities to, e.g., identify DDoS culprits, pinpoint the involved sites, and determine the length of the attack.
Said Jawad Saidi, Aniss Maghsoudlou, Damien Foucard, Georgios Smaragdakis, Ingmar Poese, Anja Feldmann
IEEE Trans. Netw. Serv. Manag.5
2019 Steering hyper-giants' traffic at scale
abstract
Large content providers, known as hyper-giants, are responsible for sending the majority of the content traffic to consumers. These hyper-giants operate highly distributed infrastructures to cope with the ever-increasing demand for online content. To achieve commercial-grade performance of Web applications, enhanced end-user experience, improved reliability, and scaled network capacity, hyper-giants are increasingly interconnecting with eyeball networks at multiple locations. This poses new challenges for both (1) the eyeball networks having to perform complex inbound traffic engineering, and (2) hyper-giants having to map end-user requests to appropriate servers.
Enric Pujol-Gil, Ingmar Poese, Johannes Zerwas, Georgios Smaragdakis, Anja Feldmann
CoNEXT2
2019 DDoS Hide & Seek: On the Effectiveness of a Booter Services Takedown
abstract
Booter services continue to provide popular DDoS-as-a-service platforms and enable anyone irrespective of their technical ability, to execute DDoS attacks with devastating impact. Since booters are a serious threat to Internet operations and can cause significant financial and reputational damage, they also draw the attention of law enforcement agencies and related counter activities. In this paper, we investigate booter-based DDoS attacks in the wild and the impact of an FBI takedown targeting 15 booter websites in December 2018 from the perspective of a major IXP and two ISPs. We study and compare attack properties of multiple booter services by launching Gbps-level attacks against our own infrastructure. To understand spatial and temporal trends of the DDoS traffic originating from booters we scrutinize 5 months, worth of inter-domain traffic. We observe that the takedown only leads to a temporary reduction in attack traffic. Additionally, one booter was found to quickly continue operation by using a new domain for its website.
Daniel Kopp, Jair Santanna, Matthias Wichtlhuber, Oliver Hohlfeld, Ingmar Poese, Christoph Dietzel
Internet Measurement Conference5
2018 Dissecting Apple's Meta-CDN during an iOS Update
Jeremias Blendin, Fabrice Bendfeldt, Ingmar Poese, Boris Koldehofe, Oliver Hohlfeld
Internet Measurement Conference3
2018 Tracing Cross Border Web Tracking
Costas Iordanou, Georgios Smaragdakis, Ingmar Poese, Nikolaos Laoutaris
Internet Measurement Conference3
2018 Stroboscope: Declarative Network Monitoring on a Budget
Olivier Tilmans, Tobias Bühler, Ingmar Poese, Stefano Vissicchio, Laurent Vanbever
NSDI3
2018 A First Look at QUIC in the Wild
Jan Rüth, Ingmar Poese, Christoph Dietzel, Oliver Hohlfeld
PAM2
2012 PaDIS emulator: an emulator to evaluate CDN-ISP collaboration
abstract
We present PaDIS Emulator, a fully automated platform to evaluate CDN-ISP collaboration for better content delivery, traffic engineering, and cost reduction. The PaDIS Emulator enables researchers as well as CDN and ISP operators to evaluate the benefits of collaboration using their own operational networks, configuration, and cost functions.
Ingmar Poese, Benjamin Frank, Simon Knight 0002, Niklas Semmler, Georgios Smaragdakis
SIGCOMM1
2012 Content-aware traffic engineering
abstract
Recent studies show that a large fraction of Internet traffic is originated by Content Providers (CPs) such as content distribution networks and hyper-giants. To cope with the increasing demand for content, CPs deploy massively distributed server infrastructures. Thus, content is available in many network locations and can be downloaded by traversing different paths in a network. Despite the prominent server location and path diversity, the decisions on how to map users to servers by CPs and how to perform traffic engineering by ISPs, are independent. This leads to a lose-lose situation as CPs are not aware about the network bottlenecks nor the location of end-users, and the ISPs struggle to cope with rapid traffic shifts caused by the dynamic CP server selection process.
Benjamin Frank, Ingmar Poese, Georgios Smaragdakis, Steve Uhlig, Anja Feldmann
SIGMETRICS2
2010 Improving content delivery using provider-aided distance information
abstract
Content delivery systems constitute a major portion of today’s In-ternet traffic. While they are a good source of revenue for Internet Service Providers (ISPs), the huge volume of content delivery traf-fic also poses a significant burden and traffic engineering challenge for the ISP. The difficulty is due to the immense volume of trans-fers, while the traffic engineering challenge stems from the fact that most content delivery systems themselves utilize a distributed infrastructure. They perform their own traffic flow optimization and realize this using the DNS system. While content delivery sys-tems may, to some extent, consider the user’s performance within their optimization criteria, they currently have no incentive to con-sider any of the ISP’s constraints. As a consequence, the ISP has “lost control ” over a major part of its traffic. To overcome this im-pairment, we propose a solution where the ISP offers a Provider-aided Distance Information System (PaDIS). PaDIS uses informa-tion available only to the ISP to rank any client-host pair based on distance information, such as delay, bandwidth or number of hops. In this paper we show that the applicability of the system is sig-nificant. More than 70 % of the HTTP traffic of a major European ISP can be accessed via multiple different locations. Moreover, we show that deploying PaDIS is not only beneficial to ISPs, but also to users. Experiments with different content providers show that improvements in download times of up to a factor of four are possible. Furthermore, we describe a high performance implemen-tation of PaDIS and show how it can be deployed within an ISP.
Ingmar Poese, Benjamin Frank, Bernhard Ager, Georgios Smaragdakis, Anja Feldmann
Internet Measurement Conference1