Ike Kunze

dblp:241/6143 · DBLP profile ↗
← Back
15ranked-venue papers
6as first author
13since 2021 · last 2025
0000-0001-8609-800XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 4 first-author · 6 since 2021Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2025 VGPrio: Visually Guided HTTP/3 Prioritization
Constantin Sander, Ike Kunze, Dario Veltri, Klaus Wehrle
Networking2
2025 Advancing Network Monitoring with Packet-Level Records and Selective Flow Aggregation
abstract
Due to its superior efficiency, network operators frequently prefer flow monitoring over full packet captures. However, packet-level information is crucial for the timely and reliable detection, investigation, and mitigation of security incidents. Currently, no solution effectively balances these two contradicting approaches, forcing network operators to compromise between efficiency and accuracy. In this paper, we thus propose HybridMon, a hybrid solution that combines condensed packet-level monitoring with selective flow-based aggregation to strike a new balance between efficiency and accuracy. Operating on the data plane of P4-programmable switches, HybridMon enables fine-grained, practical, and flexible network monitoring at Tbps speeds. We validate the effectiveness of HybridMon through extensive evaluations using Internet backbone and university campus traffic traces, demonstrating its reliability and performance in network forensics and intrusion detection contexts. Our results show that HybridMon reliably monitors all flows while reducing the output bandwidth to 12% to 20% compared to packet monitoring when exporting standard features.
Ina Berenice Fink, Ike Kunze, Pascal Hein, Jan Pennekamp, Benjamin Standaert, Klaus Wehrle, Jan Rüth
NOMS2
2025 Congestion-Responsive Queuing for Internet Flows
abstract
Internet congestion management is once again undergoing radical change: QUIC has ignited a cambrian explosion in congestion control (CC) implementations while the many versions of BBR alone have increased the diversity in algorithms used with TCP, both making the congestion landscape more complex. At the same time, the interplay of CC and AQM is also evolving but congestion unresponsiveness remains a threat. In particular, L4S crucially requires a fine-grained CC and AQM interaction to provide its benefits and suffers from unresponsive traffic. Overall, we need more responsive traffic on the Internet as well as mechanisms that can cope with unresponsiveness. We present Congestion-Responsive Queuing (CRQ), our L4S-inspired system which is designed to promote responsive CC, manage unresponsive traffic, and handle QUIC and TCP flows alike. Similar to L4S, CRQ uses two queues for flow isolation. Yet, in contrast to L4S, we isolate flows based on their actual congestion responsiveness, moving responsive flows to one queue and leaving the remaining flows in the other. Our evaluation with an eBPF prototype highlights the efficacy of our design and shows that CRQ can provide effective incentives for responsive CC.
Ike Kunze, Constantin Sander, Mike Kosek, Lars Tissen, Jan Pennekamp, Klaus Wehrle
NOMS1
2025 ConfMod: A Simple Modeling of Confidentiality Requirements for Inter-Organizational Data Sharing
abstract
Exploiting data and information is known to be essential for tapping into unrealized (business) potential. In the context of the Industrial Internet of Things (IIoT), concerns related to the sensitivity of data frequently hinder its sharing (across organizations). Despite this situation, universal approaches that account for and appropriately model the confidentiality needs of stakeholders are still missing. In this paper, we address this research gap by proposing ConfMod, a middleware that simplifies the fine-granular modeling of confidentiality requirements while striving for interoperability with other tools and standardization in the area. We evaluate ConfMod in a diverse set of twelve real-world use cases from industry and show its general feasibility. Hence, we are confident that the functionality and simplicity of ConfMod facilitate an important building block for the IIoT, which will fuel inter-organizational data sharing in the future.
Jan Pennekamp, Paul Weiler, Matthias Bodenbenner, Maximilian Sudmann, István Koren, Ike Kunze, Marcel Fey, Dominik Wolfschläger, Christian Brecher, Robert H. Schmitt, Klaus Wehrle
NOMS6
2024 Madtls: Fine-grained Middlebox-aware End-to-end Security for Industrial Communication
abstract
Industrial control systems increasingly rely on middlebox functionality such as intrusion detection or in-network processing. However, traditional end-to-end security protocols interfere with the necessary access to in-flight data. While recent work on middlebox-aware end-to-end security protocols for the traditional Internet promises to address the dilemma between end-to-end security guarantees and middleboxes, the current state-of-the-art lacks critical features for industrial communication. Most importantly, industrial settings require fine-grained access control for middleboxes to truly operate in a least-privilege mode. Likewise, advanced applications even require that middleboxes can inject specific messages (e.g., emergency shutdowns). Meanwhile, industrial scenarios often expose tight latency and bandwidth constraints not found in the traditional Internet. As the current state-of-the-art misses critical features, we propose Middlebox-aware DTLS (Madtls), a middlebox-aware end-to-end security protocol specifically tailored to the needs of industrial networks. Madtls provides bit-level read and write access control of middleboxes to communicated data with minimal bandwidth and processing overhead, even on constrained hardware.
Eric Wagner 0003, David Heye, Martin Serror, Ike Kunze, Klaus Wehrle, Martin Henze
AsiaCCS4
2024 SpinTrap: Catching Speeding QUIC Flows
abstract
The resilience of the Internet to high traffic loads fundamentally relies on hosts responding to congestion, i.e., that they back off when the network is overloaded. Despite the corresponding wide-spread deployment of congestion control, unresponsive hosts still represent a danger and can wipe out all benefits of modern congestion management approaches, such as L4S. Hence, identifying (and isolating) unresponsive flows can contribute to improving the Internet’s resilience. Yet, existing approaches only provide broad or probabilistic solutions which become inapplicable with QUIC or also harm benign traffic.In this paper, we propose SpinTrap, a speed trap for Internet flows designed to identify unresponsive traffic. Leveraging the QUIC spin bit, SpinTrap first monitors the sending behavior of QUIC flows before assessing their congestion responsiveness by checking for reduced sending rates as reaction to congestion signals (packet loss and ECN markings). Evaluating our eBPF prototype, we show that SpinTrap can accurately track the sending rates and assess the responsiveness of QUIC traffic, singling out flows that do not react to congestion. As such, SpinTrap provides a novel building block for Internet congestion management that can help in improving the Internet’s resilience.
Ike Kunze, Constantin Sander, Lars Tissen, Benedikt Bode, Klaus Wehrle
NOMS1
2023 Does It Spin? On the Adoption and Use of QUIC's Spin Bit
abstract
Encrypted QUIC traffic complicates network management as traditional transport layer semantics can no longer be used for RTT or packet loss measurements. Addressing this challenge, QUIC includes an optional, carefully designed mechanism: the spin bit. While its capabilities have already been studied in test settings, its real-world usefulness and adoption are unknown. In this paper, we thus investigate the spin bit's deployment and utility on the web.
Ike Kunze, Constantin Sander, Klaus Wehrle
IMC1
2023 ECN with QUIC: Challenges in the Wild
abstract
TCP and QUIC can both leverage ECN to avoid congestion loss and its retransmission overhead. However, both protocols require support of their remote endpoints and it took two decades since the initial standardization of ECN for TCP to reach 80% ECN support and more in the wild. In contrast, the QUIC standard mandates ECN support, but there are notable ambiguities that make it unclear if and how ECN can actually be used with QUIC on the Internet. Hence, in this paper, we analyze ECN support with QUIC in the wild: We conduct repeated measurements on more than 180 M domains to identify HTTP/3 websites and analyze the underlying QUIC connections w.r.t. ECN support. We only find 20% of QUIC hosts, providing 6% of HTTP/3 websites, to mirror client ECN codepoints. Yet, mirroring ECN is only half of what is required for ECN with QUIC, as QUIC validates mirrored ECN codepoints to detect network impairments: We observe that less than 2% of QUIC hosts, providing less than 0.3% of HTTP/3 websites, pass this validation. We identify possible root causes in content providers not supporting ECN via QUIC and network impairments hindering ECN. We thus also characterize ECN with QUIC distributedly to traverse other paths and discuss our results w.r.t. QUIC and ECN innovations beyond QUIC.
Constantin Sander, Ike Kunze, Leo Blöcher, Mike Kosek, Klaus Wehrle
IMC2
2022 Evolving the End-to-End Transport Layer in Times of Emerging Computing In The Network (COIN)
abstract
The possibility of richer computing capabilities within Internet network elements, often captured as Computing in the Network (COIN), promises performance and flexibility gains to the wider Internet, akin to those seen in recent data center advances. At the same time, moving computation into the network is seemingly at odds with the fundamental end-to-end principle underlying the development of key technologies in the Internet. In this paper, we do not only argue that the latter is not the case, but we also shed light on what ‘in the network’ may or may not entail, aiming to sharpen a possible research agenda for COIN. Taking the transport layer as an example due to its typical end-to-end realization in and importance for today's Internet, we outline key design considerations for evolving towards a COIN-enabled transport capability. By further creating linkages to existing efforts and concepts, we provide possible future directions for the design of protocols for the future Internet.
Ike Kunze, Dirk Trossen, Klaus Wehrle
ICNP1
2022 A Computer Science Perspective on Digital Transformation in Production
abstract
The Industrial Internet-of-Things (IIoT) promises significant improvements for the manufacturing industry by facilitating the integration of manufacturing systems by Digital Twins. However, ecological and economic demands also require a cross-domain linkage of multiple scientific perspectives from material sciences, engineering, operations, business, and ergonomics, as optimization opportunities can be derived from any of these perspectives. To extend the IIoT to a trueInternet of Production, two concepts are required: first, a complex, interrelated network of Digital Shadows which combine domain-specific models with data-driven AI methods; and second, the integration of a large number of research labs, engineering, and production sites as a World Wide Lab which offers controlled exchange of selected, innovation-relevant data even across company boundaries. In this article, we define the underlying Computer Science challenges implied by these novel concepts in four layers:Smart human interfacesprovide access to information that has been generated bymodel-integrated AI. Given the large variety of manufacturing data, newdata modelingtechniques should enable efficient management of Digital Shadows, which is supported by aninterconnected infrastructure. Based on a detailed analysis of these challenges, we derive a systematized research roadmap to make the vision of the Internet of Production a reality.
Philipp Brauner, Manuela Dalibor, Matthias Jarke, Ike Kunze, István Koren, Gerhard Lakemeyer, Martin Liebenberg, Judith Michael, Jan Pennekamp, Christoph Quix, Bernhard Rumpe, Wil M. P. van der Aalst, Klaus Wehrle, Andreas Wortmann 0001, Martina Ziefle
ACM Trans. Internet Things4
2021 Service-based Forwarding via Programmable Dataplanes
abstract
Access to networks for purposes of executing remote services has become a dominant form of communication, while virtualization has enabled the flexible and fast deployment of those services across distributed locations. This seems at odds with the design that drives the network layer of the Internet. Our paper presents an approach to flexibly deploy a network layer solution for optimizing service access within a single domain, while retaining full connectivity to Internet-based services. We discuss design considerations and the resulting design. We analyze expected gains from our solution.
René Glebke, Dirk Trossen, Ike Kunze, David Lou, Jan Rüth, Mirko Stoffers, Klaus Wehrle
HPSR3
2021 Tofino + P4: A Strong Compound for AQM on High-Speed Networks?
Ike Kunze, Moritz Gunz, David Saam, Klaus Wehrle, Jan Rüth
IM1
2021 Video Conferencing and Flow-Rate Fairness: A First Look at Zoom and the Impact of Flow-Queuing AQM
Constantin Sander, Ike Kunze, Klaus Wehrle, Jan Rüth
PAM2
2020 Congestion Control in the Wild - Investigating Content Provider Fairness
abstract
Congestion control (CC) is an indispensable component of transport protocols to prevent congestion collapse as it distributes the available bandwidth among all competing flows, ideally in a fair manner. It thus has a large impact on performance and there exists a constantly evolving set of CC algorithms, each addressing different performance needs. While the algorithms are commonly tested regarding the problems underlying their implementation, the interaction with existing algorithms is often not considered. Additionally considering the fact that content providers (CPs) such as content distribution networks (CDNs) are known to tune TCP stacks for performance gains, the large assortment of algorithms opens the door for custom parametrization and potentially unfair bandwidth sharing. In this paper, we thus empirically investigate if current Internet traffic generated by CPs still adheres to the conventional understanding of fairness. For this, we compare fairness properties of testbed hosts to actual traffic of six major CPs subject to different queue sizes and queueing disciplines in a home-user setting. Additionally, we investigate how mice and elephant flows from the different CPs interact. We find that some employed CC algorithms lead to significantly asymmetric bandwidth shares and very poor flow completion times for mice flows. Fortunately, AQMs such as FQ_CoDel are able to alleviate such unfairness.
Ike Kunze, Jan Rüth, Oliver Hohlfeld
IEEE Trans. Netw. Serv. Manag.1
2019 TCP's Initial Window - Deployment in the Wild and Its Impact on Performance
abstract
TCP congestion control and particularly its initial congestion window (IW) size is one long-debated topic that can influence Web performance. Its size is, however, assumed to be static by IETF recommendations-despite being network- and application-dependent-and only infrequently changed in its history. To understand if the standardization and research perspective still meets Internet reality, we study the IW configurations in IPv4 and of major content delivery networks (CDNs). We have been regularly inspecting IPv4 for HTTP and TLS servers to investigate their IW configuration and found a steady increase in IETF-recommended configurations. We additionally study how CDNs configure their IWs given their relevance for content distribution. To shed light on network-dependent CDN configurations, we use a globally distributed infrastructure of VPNs giving access to residential access links. We observe that most CDNs are well aware of the IW's impact and find a high amount of customization that is beyond current Internet standards. We find various initial window configurations, most below 50 segments, yet, with exceptions of up to 100 segments-the tenfold of current standards. This paper highlights that Internet reality has drifted away from recommended and standardized practices. Driven by these findings, we investigate the effects of this new reality on the slow start of Cubic and BBR congestion controlled TCP flows. We find that TCP pacing is a key to enable increased IWs when competing against other traffic.
Jan Rüth, Ike Kunze, Oliver Hohlfeld
IEEE Trans. Netw. Serv. Manag.2