Nikolas Wintering

dblp:353/5401 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
6since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 1 first-author · 5 since 2021
YearPublicationVenuePosition
2025 Now You See Me / Now You Don't: Constrained Adversarial Attacks in Network Intrusion Detection Across Datasets and Machine Learning Models
abstract
As the number of cyber-attacks is rising, Network Intrusion Detection Systems (NIDS) are becoming increasingly important for the detection and identification of malicious traffic, and Machine Learning techniques are gaining traction for the classification of network traffic. However, especially Deep Learning models are vulnerable to adversarial examples— subtle input perturbations that cause misclassification. While adversarial examples for images must be imperceptible, network data perturbations face complex, domain-specific constraints.We examine the vulnerability of NIDS to adversarial attacks, and compare six machine learning architectures and three black-box attack methods on four Network Intrusion Detection (NID) datasets. We define a threat model that provides minimal knowledge and limited access to an adversary, and use a highly restricted feature subset to apply perturbations to. Our results show attack success rates of 0.1-36.9%, with large, dataset-specific differences between architectures. In a second step, we apply three methods to minimize the size of the perturbations and find that the Pointwise attack is especially well suited for NID data. Finally, we analyze perturbed features and find single features greatly impact classification.
Dominik Brockmann, Eric Lanfer, Nikolas Wintering, Nils Aschenbruck
LCN3
2025 Measuring the Potential for Bundled Starlink Performance within a Single Service Cell
abstract
Low Earth Orbit (LEO) satellite networks such as Starlink allow global and affordable internet access. This not only connects remote residents, but also enables new potentials such as connecting non-stationary agricultural systems in rural areas for high-precision spot farming. One challenge is that tractors and farming robots need to transmit large amounts of data from cameras and laser scanners in real-time, which easily overwhelms the uplink capabilities of a single LEO connection. In this paper, we examine the Starlink performance of multiple terminals within a single service cell to lay ground for multipath link bundling as a possible approach to increase link capabilities. For this purpose, we present two measurement setups consisting of four and seven Starlink dishes placed in one service cell. We conduct multiple measurements and evaluate UDP and TCP throughput, latency, and packet loss. We find that UDP throughput scales almost linearly with the number of dishes, indicating significant bundling potential up to an expected limit. In contrast, TCP BBRv1’s bundling potential is limited, due to inefficiencies in utilizing the links. Moreover, we find that some packet loss events are synchronized within a service cell. For future and independent research, we make our dataset publicly available.
Till Zimmermann, Dominic Laniewski, Eric Lanfer, Stefanie Thieme, Nikolas Wintering, Nils Aschenbruck
LCN5
2024 Automating Network Perimeter Threat Prevention for Decentralized Network Administration
abstract
Decentrally administered networks consist of a plethora of hosts providing various services to the Internet and several administrators are responsible for mitigating software vulnerabilities. Therefore, these networks potentially expose a large attack surface depending on the capabilities and workload of administrators. In this paper, we present the automateD nETwork pERimeter thREat pRevention System (DETERRERS). It automatically scans hosts at the network perimeter, assesses the risk of exposed vulnerabilities, and performs actions based on the assessed risk. This supports administrators in their work and enables faster reaction to software vulnerabilities. Additionally, host-based security policies can be configured in a modular user interface by system administrators and firewall configurations can be generated automatically. We deploy our system in a university network with decentralized administration and evaluate the risk assessment process, the influence on the attack surface of the network, and the time-to-remediate from vulnerabilities.
Nikolas Wintering, Eric Lanfer, Nils Aschenbruck
CNSM1
2024 Demo: The Impact of LEO Satellite Network Instabilities on the Performance of Networking Applications
abstract
Low Earth Orbit (LEO) satellite networks like Starlink are susceptible to both external factors (e.g., weather and obstruction) and internal factors such as frequency and resource allocation changes. This causes performance instabilities by design. In this demo, we show that such instabilities can have a detrimental impact on the performance of TCP and consequently on large parts of today’s internet, as most traffic uses TCP as transport protocol. Consequently, LEO-specific adaptations to either TCP and/or higher-level applications are necessary.
Dominic Laniewski, Stefanie Thieme, Till Zimmermann, Eric Lanfer, Nikolas Wintering, Jannis Mast, Nils Aschenbruck
LCN5
2023 Trade-Off Between Compression and FEC in Image Transmission Over Wifibroadcast
abstract
Wireless transmission of images in real time over large distances is a challenge for applications such as agricultural UAV-based remote sensing. The Wifibroadcast project uses standard WiFi hardware to provide a purely unidirectional transmission link for such situations. This paper examines the trade-off between image compression and FEC for image transmission via Wifibroadcast. The goal is to achieve highest robustness against transmission errors with regards to visual quality. For this, we conducted two experiments: First, we implemented a complete simulation of the transmission process to assess different degrees of packet and byte corruption. Afterward, we incorporated real network traces into the simulation in order to model realistic corruption patterns. The results show that for uniformly distributed byte corruption patterns, compression in combination with redundancy does not yield benefits to visual quality. However, if packet loss is the dominating corruption source, FEC is able to make image transmission more robust.
Nikolas Wintering, Jannis Mast, Thomas Hänel, Nils Aschenbruck
LCN1
2023 Evaluating Wifibroadcast for Long-Distance UAV-to-Ground Data Transmission
abstract
Using existing general purpose wireless technologies, it is difficult to transmit large amounts of data from Unmanned Aerial Vehicles (UAVs) to a ground station during flight. Thus, there is a demand for specialized solutions. Wifibroadcast proposes a solution for this use case, utilizing a unidirectional and connectionless design to transmit data using unmodified low-cost WiFi hardware. In this paper, we measure and evaluate the performance of Wifibroadcast for UAV to ground transmissions over large distances and provide a direct comparison against standard IEEE 802.11. We demonstrate that Wifibroadcast is able to outperform WiFi in all tested scenarios while identifying specific characteristics, limitations, and requirements of a long-distance transmission on both the 5 GHz and 2.4 GHz frequency bands.
Jannis Mast, Thomas Hänel, Nikolas Wintering, Nils Aschenbruck
WoWMoM3