VLDB 2026 Research / reviewers in the wild / expert
Michael Menth
dblp:80/2984
· DBLP profile ↗
91ranked-venue papers
29as first author
28since 2021 · last 2026
0000-0002-3216-1015ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 57 · 24 first-author · 12 since 2021Systems, architecture and hardware · 12 · 1 first-author · 11 since 2021Software engineering, systems software and programming languages · 7 · 2 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Performance Evaluation of Selection Strategies for Inter-Satellite Paths in Walker-Delta Constellations
Marvin Felix Braun, Moritz Flüchter, Michael Menth |
NetSoft | 3 |
| 2026 | High-Speed Generation of Periodic Traffic Patterns on P4TG for DDoS and Burst-Load EvaluationabstractTraffic generators are essential tools for evaluating the robustness and performance of networked systems. P4TG is an open-source, hardware-accelerated traffic generator implemented in P4 for the Intel Tofino ASIC. It has been adopted by researchers and industry due to its flexibility and multi-terabit generation capability, and its low cost compared to other traffic generators. However, like most existing generators, it primarily produces constant bit rate traffic, which does not reflect the highly time-varying behavior observed in real networks, such as flashcrowds and microbursts. Such patterns are difficult to emulate at scale with current tools. We present a data plane mechanism for P4TG that shapes periodic, time-varying traffic patterns, including patterns representative of DDoS attacks and burst-load scenarios. Pattern shaping in P4TG can be applied to its generated traffic at an aggregate throughput of up to 4 Tbit/s. We evaluate pattern accuracy and analyze scalability across different sampling resolutions and periods. Further, we demonstrate practical use cases, including zero-loss throughput determination and buffer capacity measurement. Finally, we present microburst-based attack scenarios that overload UDP receivers, switch buffers, and degrade TCP throughput on shared links while remaining undetectable to conventional rate monitoring. Fabian Ihle, Etienne Zink, Michael Menth |
NetSoft | 3 |
| 2026 | Extensions to BIER Tree Engineering (BIER-TE) for large multicast domains and 1:1 protectionabstractBit Index Explicit Replication (BIER) was developed by the IETF as a new forwarding paradigm for stateless multicast packet forwarding. IP multicast (IPMC) creates a per-hop forwarding state for each IP multicast group. In contrast, ingress nodes of a BIER domain equip packets with a bitstring indicating egress nodes, and BIER nodes forward the packets according to that bitstring. As the bitstring size is limited, e.g., 256 bits, only that number of egress nodes can be addressed. To scale BIER to larger networks, the egress nodes can be assigned to subsets and addressed with with a subset-specific bitstrings including a subset ID. This approach is even compliant with fast reroute (FRR) mechanisms for BIER. BIER-TE extends BIER with tree engineering capabilities, i.e., the bitstring is repurposed to indicate both egress nodes and links, so that explicit paths can be encoded over which packets are transmitted. However, BIER’s scaling mechanism cannot be adopted out of the box for BIER-TE because the encoding of explicit paths requires that all contained links belong to the same subset. Obviously, chosen subsets for BIER-TE scaling must represent connected sub-topologies. In this work, we extend BIER-TE for scaling. When an ingress node sends a packet to an egress node in another subset, it tunnels the packet to the ingress node of that subset. We further protect the communication against link and node failures, which is particularly challenging when the ingress node of a subset fails, and which is a major contribution of this paper. The suggested protocol solution combines existing concepts like tunneling, egress protection, and BIER-TE-FRR. We identify various behaviors of BIER-TE nodes, and implement them on the P4-programmable Tofino switching ASIC to demonstrate the feasibility of the proposed approach. Finally, we evaluate and discuss the forwarding performance of the prototype. Moritz Flüchter, Steffen Lindner, Fabian Ihle, Toerless Eckert, Michael Menth |
J. Netw. Comput. Appl. | 5 |
| 2025 | R-TWT in Wi-Fi 7 and Beyond: Enabling Bounded Latency, Energy Efficiency, and ReliabilityabstractApplications with deterministic quality of service (QoS) requirements are becoming widespread, driving the evolution of wireless networks to meet strict performance demands. Wi-Fi 7, the latest generation of IEEE 802.11 standard, introduces Restricted Target Wake Time (R-TWT). It serves latency-sensitive traffic by providing contention-free channel access for certain devices and reducing their energy consumption. This paper evaluates the performance of R-TWT across diverse service types and network sizes in terms of worst-case latency, energy efficiency, collision rate, and throughput. The results, generated using the ns-3 simulator, show that R-TWT achieves bounded latency for sensitive traffic types, such as Internet of Things (IoT) and real-time (RT) applications. Moreover, R-TWT outperforms legacy mechanisms, i.e., Power Saving Mode (PSM) and Distributed Coordination Function (DCF), by achieving higher energy efficiency and a lower collision rate. Furthermore, R-TWT maintains stable and scalable performance as network size increases. This makes it a robust solution for latency-sensitive and energy-efficient wireless applications. Erfan Mozaffari Ahrar, Francesc Wilhelmi, Lorenzo Galati-Giordano, Pasquale Imputato, Michael Menth, Stefano Avallone |
ETFA | 5 |
| 2025 | Detecting QoS Degradation in Time-Critical Networks due to Misconfiguration or AttacksabstractCommunication in Industrial Control Systems (ICSs) depends on predictable timing to ensure reliable operation. In converged networks, this timing can be disrupted not only by cyber attacks but also by misconfiguration or benign misbehavior of devices. Such issues degrade Quality of Service (QoS) through delays or jitter, without altering packet content, making it hard to detect them with traditional monitoring systems.This paper presents a configuration-agnostic monitoring system that detects QoS degradation using statistical anomaly detection. We evaluate three detection methods, single-value thresholds, exponential moving averages, and distribution-based analysis, and show that distribution-based detection offers the most robust results. The system supports both passive and active timing measurement to balance accuracy and overhead. By operating independently of network configuration, the proposed approach enables early detection of timing anomalies caused by misbehavior, misconfiguration, or attacks, demonstrating applicability in real-world industrial networks. Lukas Bechtel, Lukas Popperl, Michael Menth, Tobias Heer |
ETFA | 3 |
| 2025 | Time-Limited Software Firewall Based on DPDK Supporting TSN and DetNet TrafficabstractThe convergence of IT and OT networks introduces strict latency and security requirements, especially in virtualized industrial environments. While TSN and DetNet provide bounded-latency traffic delivery, traditional software firewalls break determinism due to variable rule evaluation times. Hence, we propose a time-limited firewall design that limits per-packet rule evaluation time to a fixed budget, ensuring deterministic processing even under high load. To preserve security despite partial rule checks, we propose that a deferred filtering stage verifies and, if necessary, retroactively corrects earlier forwarding decisions. We implement this design in a software firewall prototype and evaluate it under maximum packet rate. The system guarantees limited latency for all packets, maintains high throughput, and ensures eventual security consistency, all without requiring specialized hardware. Lukas Bechtel, Markus Schramm, Michael Menth, Tobias Heer |
ETFA | 3 |
| 2025 | Security Gateway for Automated Micro-Segmentation and VPN Encryption in Industrial Legacy SystemsabstractIn today’s industrial networks, secure communication among participants is crucial. Security measures commonly employed in IT networks, e.g., network segmentation and Virtual Private Networks (VPN), prevent unauthorized access by restricting communication flows within logical segments and ensure data confidentiality by encryption, respectively. In industrial networks, however, security measures are often not used due to legacy devices lacking the required capabilities to implement them. Thus, maintaining network security is particularly difficult. In this work, we take up the concept of retrofitting security measures using a security gateway. The gateway is placed in front of a legacy device and takes over tasks such as micro-segmentation and VPN encryption. A resulting challenge is the derivation of appropriate micro-segments and VPN tunnels. We address this challenge using heuristics based on observed network traffic. We demonstrate the feasibility of the approach through a Proof-of-Concept (PoC). The proposed semi-automated approach allows for retrofitting of security measures, thereby ensuring a seamless migration from the existing to a more secure infrastructure and contributing to the secure integration of legacy devices. Sabrina Kaniewski, Lukas Bechtel, Pascal Kneisel, Michael Menth, Tobias Heer |
ETFA | 4 |
| 2025 | Transforming the Network into a Filter: Distributed Firewall Rules for Time-Critical TrafficabstractIndustrial networks require strict security policies while supporting time-sensitive communication for automation and control processes. Traditional centralized firewalls enforce security by filtering traffic between network segments but introduce unacceptable delays for real-time applications. This paper presents a novel approach that distributes firewall rules across industrial switches, leveraging their Access Control Lists (ACLs) to transform the entire network into a unified, low-latency filtering system. The proposed algorithm accounts for challenges such as rule semantics adaptation, dynamic end-device locations, network redundancy, and ACL resource constraints. It systematically analyzes network topology, calculates rule placement strategies, and ensures correct filtering behavior across distributed enforcement points. Evaluation results demonstrate that our approach significantly reduces filtering delays while maintaining security, enabling real-time communication in industrial environments. Lukas Bechtel, Samuel Müller 0007, Michael Menth, Tobias Heer |
WFCS | 3 |
| 2025 | IoTWall: An Efficient Host-Based Firewall for Resource-Constrained IoT DevicesabstractIn areas such as the industrial sector, IoT devices have become an important component. For example, they serve as temperature sensors or switches. Often, IoT devices share the wireless network with other devices, increasing the potential for attacks through compromised hosts in the network. IoT devices typically lack a packet filtering mechanism that network administrators can configure to limit access to the IoT device by trusted hosts. To enhance IoT device security, we present IoTWall, a lightweight host firewall designed to run on resourceconstrained IoT devices. IoTWall is easy to integrate into existing IoT software projects with only a few code changes to encourage developers to adopt stronger security measures. A REST API enables easy configuration by network administrators without requiring code changes. We also show that IoTWall operates efficiently within the constraints of resource-constrained devices with acceptable latency and energy consumption. Markus Schramm, Lukas Bechtel, Florian Hoss, Michael Menth, Tobias Heer |
WFCS | 4 |
| 2025 | ELVIS: eBPF-based extensions of linux hosts for using virtual network functions with service function chaining and in-band network telemetryabstractService function chaining (SFC) is a technology that enables dynamic steering of packets to processing nodes, also called Service Functions (SFs), e.g., firewalls, IDSs, or NAT gateways. An SFC classifier located at the border of SFC-enabled domains encodes information about the order of SFs, the Service Function Chain, into packet headers. This encoded information, called SFC encapsulation, is used by the network to steer packets to the respective SFs. Because most existing SFs do not support SFC encapsulations natively, a proxy is required to make them SFC-compatible. However, simple proxies operate in a stateless manner and are not capable of preserving per-packet metadata. In this paper, we propose a dynamic SFC proxy that is capable of preserving metadata by caching the SFC encapsulation while a packet is processed by a SF. In addition, the proxy implements In-band Network Telemetry (INT) to support monitoring and debugging related to SFs. INT is a network monitoring framework that adds packet-specific metrics to the header stack of a packet. Although INT has been standardized with a focus on network switches and routers, a proxy-based implementation for SFs extends its usability in an SFC scenario. We present concept, use cases, and an eBPF-based implementation of the INT-enabled caching SFC proxy. Finally, we evaluate the performance of a prototype. Marco Häberle, Benjamin Steinert, Michael Menth |
Comput. Networks | 4 |
| 2024 | GeNESIS: Generator for Network Evaluation Scenarios of Industrial SystemsabstractThe lack of standardized, realistic industrial net-work scenarios hinders the comparative evaluation of scientific research for industrial networks. Current evaluations often use non-public or synthetic scenarios, making it difficult to compare results across different studies. This paper introduces GeNESIS, a tool designed to generate and exchange realistic, reproducible industrial network evaluation scenarios. GeNESIS produces comprehensive topologies formatted according to IETF standards, including network devices and connections. Additionally, it gen-erates configurations for network devices, supporting evaluations such as algorithm comparisons or network simulations. GeNESIS was created to evaluate firewall configurations but is designed to further support other use cases, such as QoS or reliability. By providing a standardized exchange format, GeNESIS ensures the simple availability of evaluation scenarios, promoting compara-bility and reproducibility in industrial network research. Lukas Bechtel, Samuel Müller 0007, Michael Menth, Tobias Heer |
ETFA | 3 |
| 2024 | Monitoring IP- ID Behavior for Spoofed IPv4 Traffic DetectionabstractMonitoring network traffic and devices is crucial for ensuring secure network operation, particularly in industrial networks, which operate for a long time and contain a mix of devices, i.e., devices with state-of-the-art security and legacy devices whose security features are often insufficient. Such legacy devices require additional compensating security measures for secure operation, especially due to increasing connectivity, exposing legacy devices to new security threats, such as spoofing. For this purpose, we propose an anomaly detection mechanism based on the IPv4 Identifier (IP-ID) field that provides hints for spoofed IPv4 devices. The IP-ID field is a 16-bit value in the IPv4 header. Receiving hosts use it to identify and reassemble parts of a fragmented IP packet. Multiple variants for assigning IP-IDs exist. For example, many legacy devices use a global counter with a fixed increment between subsequent packets. The proposed mechanism is based on the observation that IP-IDs in spoofed traffic may not comply with the previously observed IP-ID assignment behavior of the device. Such deviations can be detected as an anomaly and taken as a hint for spoofing. We provide an overview of existing assignment behaviors and present a classification algorithm using captured traffic. Likewise, we present a simple monitoring algorithm for detecting deviations in a host's classified IP-ID assignment behavior. We address various challenges, such as incomplete captures and unsuited deployment positions, and how to deal with them. We evaluate the feasibility of the algorithms on real-world traces. Further, we present a proof-of-concept implementation that detects various spoofing attacks in a testbed. The proposed mechanism improves security in industrial and related brownfield networks by passively detecting spoofed devices. Sabrina Kaniewski, Lukas Bechtel, Michael Menth, Tobias Heer |
ETFA | 3 |
| 2024 | Secure Resource Allocation Protocol (SecRAP) for Time-Sensitive NetworkingabstractThe convergence of operational technology (OT) and information technology (IT) networks through Time-Sensitive Networking (TSN) promises enhanced efficiency and new use cases in industrial settings. However, ensuring security in this shared infrastructure is crucial to prevent potential attacks that could compromise Quality of Service (QoS) of real-time streams and pose risks to operations and safety. This paper focuses on auditing the security of the Resource Allocation Protocol (RAP), a distributed QoS signaling protocol for TSN. We analyze the vulnerability of RAP to attacks during admission control, where end stations request network resources for data transmission. We leverage the Dolev-Yao attacker model to assess the security properties of RAP in both distributed hop-by-hop admission control and hybrid admission control with a central controller. We introduce novel security extensions to RAP, called Secure Resource Allocation Protocol (SecRAP), to mitigate the identified attack vectors. Finally, we present a prototype and discuss the security properties of SecRAP. Lukas Osswald, Steffen Lindner, Lukas Bechtel, Tobias Heer, Michael Menth |
ETFA | 5 |
| 2024 | Autonomous integration of TSN-unaware applications with QoS requirements in TSN networksabstractModern industrial networks transport both best-effort and real-time traffic. Time-Sensitive Networking (TSN) was introduced by the IEEE TSN Task Group as an enhancement to Ethernet to provide high quality of service (QoS) for real-time traffic. In a TSN network, applications signal their QoS requirements to the network before transmitting data. The network then allocates resources to meet these requirements. However, TSN-unaware applications can neither perform this registration process nor profit from TSN’s QoS benefits. The contributions of this paper are twofold. First, we introduce a novel network architecture in which an additional device acts as a central user configuration (CUC) for TSN-unaware applications and autonomously signals their QoS requirements to the network. Second, we propose a processing method to detect real-time streams in a network and extract the necessary information for the TSN stream signaling. It leverages a Deep Recurrent Neural Network (DRNN) to detect periodic traffic, extracts an accurate traffic description, and uses traffic classification to determine the source application. As a result, our proposal allows TSN-unaware applications to benefit from TSNs QoS guarantees. Our evaluations underline the effectiveness of the proposed architecture and processing method. Moritz Flüchter, Steffen Lindner, Lukas Osswald, Jérôme Arnaud, Michael Menth |
Comput. Commun. | 5 |
| 2024 | Performance Comparison of Offline Scheduling Algorithms for the Time-Aware Shaper (TAS)abstractTime-sensitive networking is an emerging technology that enables deterministic and reliable transmission in bridged Ethernet networks. The enhancement for scheduled traffic defined in IEEE 802.1Qbv [1] allows to implement time-aware shaping (TAS) which grants periodic slices for transmission to various priority queues of a bridge. TAS is an enabler for traffic scheduling, i.e., frame transmissions of periodic streams at senders and the TAS on intermediate bridges are configured such that these frames experience no loss and hardly any queuing delay. Thereby, deterministic bounds on delay and jitter can be guaranteed to such streams. However, the standard does not provide an algorithm to compute transmission schedules. Therefore, more than 100 research works [Stüber et al. (2023)] propose various algorithms for computing such schedules. Nevertheless, there are still many challenges to solve in this area. In this work, we implement eleven of these algorithms and compare their performance under various conditions with regard to schedule quality and runtime. It reveals that the performance of the algorithms varies a lot and points out their shortcomings. The set of problem instances for this study covers a wide range of parameters and is released to the public so that the performance of new algorithms can be easily compared to those in this study. Thomas Stüber, Manuel Eppler, Lukas Osswald, Michael Menth |
IEEE Trans. Ind. Informatics | 4 |
| 2024 | P4-PSFP: P4-Based Per-Stream Filtering and Policing for Time-Sensitive NetworkingabstractTime-Sensitive Networking (TSN) extends Ethernet to enable real-time communication. In TSN, bounded latency and zero congestion-based packet loss are achieved through mechanisms such as the Credit-Based Shaper (CBS) for bandwidth shaping and the Time-Aware Shaper (TAS) for traffic scheduling. Generally, TSN requires streams to be explicitly admitted before being transmitted. To ensure that admitted traffic conforms with the traffic descriptors indicated for admission control, Per-Stream Filtering and Policing (PSFP) has been defined. For credit-based metering, well-known token bucket policers are applied. However, time-based metering requires time-dependent switch behavior and time synchronization with sub-microsecond precision. While TSN-capable switches support various TSN traffic shaping mechanisms, a full implementation of PSFP is still not available. To bridge this gap, we present a P4-based implementation of PSFP on a 100 Gb/s per port hardware switch. We explain the most interesting aspects of the PSFP implementation whose code is available on GitHub. We demonstrate credit-based and time-based policing and synchronization capabilities to validate the functionality and effectiveness of P4-PSFP. The implementation scales up to 35840 streams depending on the stream identification method. P4-PSFP can be used in practice as long as appropriate TSN switches lack this function. Moreover, its implementation may be helpful for other P4-based hardware implementations that require time synchronization. Fabian Ihle, Steffen Lindner, Michael Menth |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | P4-LISP: A P4-Based High-Performance Router for the Locator/Identifier Separation ProtocolabstractThe networking paradigm locator/identifier split decouples locating and identifying functionality of addresses. Thereby it improves multi-homing, fail-over, mobility, traffic engineering over the Internet, and routing scalability.The Locator/Identifier Separation Protocol (LISP) is a prominent incarnation of that paradigm which recently became an Internet standard. However, existing LISP implementations are either proprietary or have limited performance, which makes their deployment difficult in high-speed networks. Programming Protocol-independent Packet Processors (P4) is a programming language that facilitates the implementation of custom data plane processing on high-performance switches with line rates of up to 400 Gbit/s.In this work, we present P4-LISP, an open-source P4-based proof of concept implementation of a high-performance LISP router. It supports all relevant features such as ITR, ETR, RTR, P-ITR, P-ETR, NAT-traversal, LISP-NAT, and mobile nodes. As control plane, the open-source implementation lispers.net has been integrated on the switch. Security features are added to protect the control plane from being overloaded by the high-performance data plane. The paper describes the architecture of P4-LISP in detail and extensively evaluates performance, functionality, controller performance, and overload protection. Benjamin Steinert, Marco Häberle, Jan-Oliver Nick, Dino Farinacci, Michael Menth |
NetSoft | 5 |
| 2023 | A survey on data plane programming with P4: Fundamentals, advances, and applied research
Frederik Hauser, Marco Häberle, Daniel Merling, Steffen Lindner, Vladimir Gurevich, Florian Zeiger, Reinhard Frank, Michael Menth |
J. Netw. Comput. Appl. | 8 |
| 2023 | A survey of contemporary open-source honeypots, frameworks, and tools
Niclas Ilg, Paul Duplys, Dominik Germek, Michael Menth |
J. Netw. Comput. Appl. | 4 |
| 2023 | Learning Multicast Patterns for Efficient BIER Forwarding With P4abstractBit Index Explicit Replication (BIER) is an efficient domain-based transport mechanism for IP multicast (IPMC) that indicates receivers of a packet through a bitstring in the packet header. Recently, BIER forwarding has been implemented on 100 Gbit/s per port hardware using the P4 programming language. However, the implementation requires packet recirculation to iteratively serve one next-hop after another. The objective of this paper is to reduce this inefficiency. Static multicast groups can be configured on P4 switches so that traffic can be sent to all next-hops without recirculation. We leverage that feature to make BIER forwarding more efficient. However, only a limited number of static multicast groups can be configured on a switch, which is not sufficient to cover all potential port patterns. In a first step, we develop efficient BIER forwarding that utilizes static multicast groups derived from so-called configured port clusters. Then, we design port clustering algorithms that observe multicast patterns and compute configured port clusters which are more efficient than randomly selected port clusters. These methods are based on Spectral Clustering, an unsupervised machine learning technique. We perform simulations that underline the effectiveness of this approach to reduce inefficient packet recirculations. We further implement the new forwarding behaviour on programmable hardware and provide a controller that samples BIER packets on the switch, runs the port clustering algorithms, and updates the configured static multicast groups. We validate this open source implementation in a testbed and show that the experimental results are in line with the simulation results. Steffen Lindner, Daniel Merling, Michael Menth |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Efficiency of BIER Multicast in Large NetworksabstractBit Index Explicit Replication (BIER) has been introduced by the IETF to transport IP multicast (IPMC) traffic within a BIER domain. Its advantage over IPMC is improved scalability regarding the number of multicast groups. However, scaling BIER to large networks is a challenge. To that end, receivers of a BIER domain are assigned to smaller subdomains. To deliver an IPMC packet over a BIER domain, a copy is sent to any subdomain with a receiver for that packet. Consequently, some links may carry multiple copies of the same IPMC packet, which contradicts the multicast idea. In this paper, we propose and compare various algorithms to select subdomains for BIER in order to keep the overall BIER traffic low despite multiple packet copies. We apply them to investigate the traffic savings potential of IPMC and BIER relative to unicast under various conditions. We show that the traffic savings depend on network topology, network size, and the size of the multicast groups. Also the extra traffic caused by BIER depends on these factors. In spite of some redundant packets, BIER can efficiently reduce the overall traffic in most network topologies. Similarly to IPMC, BIER also avoids heavily loaded links. Finally, we demonstrate that BIER subdomains optimized for failure-free conditions do not cause extensive overload in case of single link failures. Daniel Merling, Thomas Stüber, Michael Menth |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Alternative Best Effort (ABE) for Service Differentiation: Trading Loss Versus DelayabstractThe idea of an Alternative Best Effort (ABE) per-hop behaviour (PHB) emerged about 20 years ago. It provides a low-delay traffic class in the Internet at the expense of more packet loss than Best Effort (BE). Therefore, ABE is better suited than BE for loss-tolerant but delay-sensitive applications. Furthermore, ABE traffic should not degrade the service for BE traffic in terms of packet loss and delay. Therefore, Internet service providers may leave the choice of using BE or ABE to their customers as they achieve service differentiation without compromising other traffic. In this work, we revisit ABE and pursue the fundamental question whether an ABE service is technically feasible, how its service would look like and interact with existing transport protocols? We present a novel scheduler called Deadlines, Saved Credits, and Decay (DSCD) for combined scheduling of BE and ABE traffic. It allows to control ABE’s delay advantage over BE and copes with varying bandwidth. We provide an implementation of DSCD in the Linux network stack and demonstrate its efficiency. A side product of the implementation is an efficient approximation of the exponential function in the kernel and a bandwidth estimation method that even works at moderate link utilization. We study DSCD in a semi-virtualized testbed with real networking stacks to understand implications for transport protocols in a BE/ABE Internet. The study analyzes ABE’s impact on loss and delay under various conditions and gives recommendations for configuration. Steffen Lindner, Gabriel Paradzik, Michael Menth |
IEEE/ACM Trans. Netw. | 3 |
| 2022 | Analyzing and modeling the latency and jitter behavior of mixed industrial TSN and DetNet networksabstractToday, industrial real-time communication is commonly designed based on two key principles to satisfy the challenging Quality of Service (QoS) requirements of industrial applications: a) local communication and b) purpose-built networks. IEEE Time-Sensitive Networking (TSN) and IETF Deterministic Networking (DetNet) promise to lift these two limitations. This facilitates the transformation of previously loosely integrated automation network parts from isolated, purpose-built real-time networks to more tightly integrated, open, multi-purpose networks of networks. With TSN and DetNet, each of these interconnected networks, e.g., machine or backbone networks, can and will be fined-tuned for optimal performance regarding the different real-time applications located inside them. The resulting patchwork of DetNet-connected TSN networks, however, creates a challenge for cross-network real-time communication: predicting QoS properties, such as the end-to-end latency. To address this challenge, we propose a model that allows calculating best-case and worst-case latencies for time-critical communication across different DetNet-connected TSN networks. This enables validating end-to-end communication requirements in open, multi-purpose industrial networks. Our evaluation with real industrial hardware shows the applicability of our proposed model. Lukas Wüsteney, David Hellmanns, Markus Schramm, Lukas Osswald, René Hummen, Michael Menth, Tobias Heer |
CoNEXT | 6 |
| 2022 | Secure Service Function Chaining in the Context of Zero Trust SecurityabstractService Function Chaining (SFC) enables dynamic steering of traffic through a set of service functions based on classification of packets, allowing network operators fine-grained and flexible control of packet flows. New paradigms like Zero Trust (ZT) pose additional requirements to the security of network architectures. This includes client authentication, confidentiality, and integrity throughout the whole network, while also being able to perform operations on the unencrypted payload of packets. However, these requirements are only partially addressed in existing SFC literature. Therefore, we first present a comprehensive analysis of the security requirements for SFC architectures. Based on this analysis, we propose a concept towards the fulfillment of the requirements while maintaining the flexibility of SFC. In addition, we provide and evaluate a proof of concept implementation, and discuss the implications of the design choices. Leonard Bradatsch, Marco Häberle, Benjamin Steinert, Frank Kargl, Michael Menth |
LCN | 5 |
| 2022 | A Caching SFC Proxy Based on eBPFabstractService Functions (SFs) are intermediate processing nodes on the path of IP packets. With SF chaining (SFC), packets can be steered to multiple physical or virtual SFs in a specific order. SFC-unaware SFs can be used flexibly but they do not support SFC-specific encapsulation of packets. Therefore, an SFC proxy needs to remove the encapsulation of a packet before processing by an SFC-unaware SF, and to add it again afterwards. Such an SFC proxy typically runs on a server hosting virtual network functions (VNFs) that serve as SFs. Simple SFC proxies adapt a flow-specific static header stack. That is, each VNF requires an own SFC proxy, and the proxy cannot be extended to support per-packet metadata in the SFC encapsulation. The caching SFC proxy presented in this work caches packet-specific headers while packets are processed by a VNF, i.e., packet-specific header information is preserved. We present concept, use cases, and an eBPF-based implementation of the caching SFC proxy. In addition, we evaluate the performance of a prototype. Marco Häberle, Benjamin Steinert, Michael Menth |
NetSoft | 4 |
| 2021 | RAP Extensions for the Hybrid Configuration ModelabstractModern applications in industrial automation rely on a deterministic network service, i.e., low latency, high reliability, and network convergence. Therefore, the IEEE 802.1 TSN Task Group introduces Time-Sensitive Networking (TSN). Besides mechanisms for traffic shaping, time synchronization, and reliability, TSN introduces three different configuration models for resource reservation: the fully distributed, the fully centralized, and the centralized network/distributed (hybrid) user model. Furthermore, IEEE P802.1Qdd specifies the Resource Allocation Protocol (RAP) to enable resource reservation for TSN streams in the fully distributed model. In this paper, we give an introduction to RAP, and propose extensions to RAP for the use in the hybrid configuration model. Additionally, we implement a prototype which is published under an open-source license. Lukas Osswald, Steffen Lindner, Lukas Wüsteney, Michael Menth |
ETFA | 4 |
| 2021 | Impact of Packet Filtering on Time-Sensitive Networking TrafficabstractThe Industrial Internet of Things, Industry 4.0 and cloud computing are fundamentally transforming today's industrial networks towards high connectivity. At the same time, the number of cyber-attacks against industrial infrastructure increased drastically over the last years, requiring to tightly limit the connectivity between the networked devices of a plant. For both of these trends, there are mechanisms evolving and partially already in place. Network segmentation with packet filters is a key mechanism for achieving improved network security while Time-Sensitive Networking (TSN) is a promising option to realize advanced real-time applications in future industrial networks. However, although being built based on widely accepted standards and despite their practical relevance, these two concepts don't play together well. In this paper, we analyze the problems that arise when TSN networks are segmented using today's firewalls and packet filters. In particular, we discuss and quantify the impact of delay and jitter caused by packet filters on TSN traffic. We also show that the delays and jitter introduced by CPU-based filtering can be prohibitively high in real-time scenarios. Based on our analysis, we present and compare three approaches to overcome the challenges created by the combination of these two major trends in industrial networks. Lukas Wüsteney, Michael Menth, René Hummen, Tobias Heer |
WFCS | 2 |
| 2021 | Robust LFA Protection for Software-Defined Networks (RoLPS)abstractIn software-defined networks, forwarding entries on switches are configured by a controller. In case of an unreachable next-hop, traffic is dropped until forwarding entries are updated, which takes significant time. Therefore, fast reroute (FRR) mechanisms are needed to forward affected traffic over alternate paths in the meantime. Loop-free alternates (LFAs) and remote LFAs (rLFAs) have been proposed for FRR in IP networks. However, they cannot protect traffic for all destinations and some LFAs may create loops under challenging conditions. This paper proposes robust LFA protection for software-defined networks (RoLPS). RoLPS augments the coverage of (r)LFAs with novel explicit LFAs (eLFAs). RoLPS ranks available LFAs according to protection quality and complexity for selection of the best available LFA. Furthermore, we introduce advanced loop detection (ALD) so that RoLPS stops loops caused by LFAs. We evaluate RoLPS-based protection variants on a large set of representative networks with unit and non-unit link costs. We study their protection coverage, additional forwarding entries, and path extensions for rerouted traffic, and compare them with MPLS facility backup. Results show that RoLPS can protect traffic against all single link or node failures, and against most double failures while inducing only little overhead. We implement FRR on the P4-programmable switch ASIC Tofino and provide a control plane logic based on RoLPS. Measurement results show that the prototype achieves a throughput of 100 Gb/s, reroutes traffic within less than a millisecond, and reliably detects and drops looping traffic. Daniel Merling, Steffen Lindner, Michael Menth |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | P4 In-Network Source Protection for Sensor Failover
Steffen Lindner, Marco Häberle, Florian Heimgaertner, Naresh Nayak 0001, Sebastian Schildt, Dennis Grewe, Hans Löhr, Michael Menth |
Networking | 8 |
| 2020 | xRAC: Execution and Access Control for Restricted Application Containers on Managed HostsabstractWe propose xRAC to permit users to run special applications on managed hosts and to grant them access to protected network resources. We use restricted application containers (RACs) for that purpose. A RAC is a virtualization container with only a selected set of applications. Authentication verifies the RAC user’s identity and the integrity of the RAC image. If the user is permitted to use the RAC on a managed host, launching the RAC is authorized and access to protected network resources may be given, e.g., to internal networks, servers, or the Internet. xRAC simplifies traffic control as the traffic of a RAC has a unique IPv6 address so that it can be easily identified in the network. The architecture of xRAC reuses standard technologies, protocols, and infrastructure. Those are the Docker virtualization platform and 802.1X including EAP-over-UDP and RADIUS. Thus, xRAC improves network security without modifying core parts of applications, hosts, and infrastructure. In this paper, we review the technological background of xRAC, explain its architecture, discuss selected use cases, and investigate on the performance. To demonstrate the feasibility of xRAC, we implement it based on standard components with only a few modifications. Finally, we validate xRAC through experiments. We publish the testbed setup guide and prototypical implementation on GitHub [1]. Frederik Hauser, Mark Schmidt 0002, Michael Menth |
NOMS | 3 |
| 2020 | Demo: Execution and Access Control for Restricted Application Containers on Managed Hosts (xRAC)abstractRestricted application containers (RACs) encapsulate applications with their dependencies and configuration for execution on a hypervisor host. xRAC [1] is a novel approach for execution control and network access control (NAC). That is, a RAC can be executed only after successful authentication and authorization (AA) and obtain limited access to network resources. A RAC has a unique IPv6 address so that its traffic is identifiable and controllable by network components. For AA, xRAC adopts and extends components and procedures of 802.1X. We publish its source code and a testbed setup guide on GitHub [2]. In this paper, we give a brief overview on the architecture and functionality of xRAC, describe the prototypical implementation, a testbed, and four demo scenarios. Frederik Hauser, Michael Menth |
NOMS | 2 |
| 2020 | P4-based implementation of BIER and BIER-FRR for scalable and resilient multicast
Daniel Merling, Steffen Lindner, Michael Menth |
J. Netw. Comput. Appl. | 3 |
| 2018 | A Learning Automaton-Based Controller Placement Algorithm for Software-Defined NetworksabstractSoftware-defined networking (SDN) moves the control plane of network devices like switches and routers to the controller. The controller is in charge of managing the whole network through application programming interfaces (APIs). Fault tolerance in the SDN networks can be handled by leveraging multiple controllers. Placing controllers in an SDN network can be seen as facility location problem which is an NP-hard problem. In this paper, we propose a simple heuristic algorithm for controller placement in SDN networks leveraging a learning automaton (LA) approach. The proposed algorithm can place the controllers based on a predefined propagation latency between the controllers and the switches while minimizing the overall propagation latency. We perform several simulations, from the available topologies of ToplogyZoo, and the results show the superiority of the proposed algorithm when compared to competing current state-of-the-art algorithms in terms of propagation latency. Habib Mostafaei, Michael Menth, Mohammad S. Obaidat |
GLOBECOM | 2 |
| 2018 | Software-defined wireless sensor networks: A survey
Habib Mostafaei, Michael Menth |
J. Netw. Comput. Appl. | 2 |
| 2017 | A software-defined firewall bypass for congestion offloadingabstractWith increasing network bandwidths, stateful firewalls are likely to become communication bottlenecks in networks. To mitigate this problem, we propose to bypass selected traffic around firewalls using software-defined networking (SDN). We discuss various approaches and elaborate the following concept. A controller samples outgoing packets at the firewall using sFlow to detect congestion. In case of congestion, flows already admitted by the firewall are identified and offloaded at an appropriate rate by installing flow-specific bypass rules on an OpenFlow-capable switch. We suggest two different algorithms to select appropriate flows and provide a proof-of-concept implementation in a network testbed using the Ryu controller framework. Experimental results illustrate the system behavior at different load levels with and without offloading. We provide an analytical system model to predict the offloading performance for other system parameters than experimentally evaluated and validate the model with our experimental results. A parameter study suggests that the offloaded traffic rate may be a multiple of the firewall's capacity if the switch supports sufficient flow rules or is able to match for TCP flags. Florian Heimgaertner, Mark Schmidt 0002, David Morgenstern, Michael Menth |
CNSM | 4 |
| 2017 | Establishing a session database for SDN using 802.1X and multiple authentication resourcesabstractNetwork control systems based on identities allow fine-grained access control for users. They require a network-wide session database containing information about active authenticated and authorized users. We propose an authentication and authorization (AA) module (AAM) as a controller application for software-defined networking to establish a network-wide session database and provide a prototypical implementation with OpenFlow. End systems issue authentication requests and the switch redirects them to the AAM. The AAM either relays them to a RADIUS server as in legacy 802.1X (pass-through mode) or processes them based on directly attached AA resources (authentication server mode). After successful authentication, the AAM authorizes the requesting user and maintains a network-wide session database of authenticated and authorized identities. As the AAM interfaces to end systems and AA resources through existing protocols, i.e., EAP and RADIUS, its use is compatible with current infrastructures. Through implementation as distributed network functions, the AAM can be scaled so that high rates of authentication requests can be supported. Frederik Hauser, Mark Schmidt 0002, Michael Menth |
ICC | 3 |
| 2017 | Performance comparison of resilience mechanisms for stateless multicast using BIERabstractBit Indexed Explicit Replication (BIER) is a novel multicast forwarding scheme for IP networks that avoids states in replicating routers by encoding the multicast information into a bit string in the packet header. In addition, the BIER-TE variant encodes the multicast tree in the header and allows for network programmability. We propose the use of maximally redundant trees (MRTs) for 1+1 protection in BIER that currently lacks this feature. We further discuss three different fast reroute (FRR) protection schemes for BIER-TE we have proposed in the Internet Engineering Task Force (IETF). They use header modification only (HM), rely on point-to-point tunnels (PPT), or leverage BIER-in-BIER encapsulation (BBE). We compare them regarding protection coverage, path lengths, traffic loads, required network capacity, state requirements and overhead in a large number of networks. The results serve the discussions in IETF where BIER and BIER-TE are currently standardized. Wolfgang Braun, Manuel Albert, Toerless Eckert, Michael Menth |
IM | 4 |
| 2017 | Demo: Scalable and reliable software-defined multicast with BIER and P4abstractWe present an architecture for software-defined multicast that provides scalable and reliable multicast services. We consider the Bit Indexed Explicit Replication (BIER) architecture and Traffic Engineering for BIER (BIER-TE) for packet transport to mitigate scalability concerns of traditional IP multicast. We briefly discuss the advantages of an SDN-based multicast architecture leveraging BIER and discuss implementation options: OpenFlow and the P4 language. We present our prototype based on P4. We implement traditional IP multicast and several BIER variants that may be deployed simultaneously with the prototype. We present various demo scenarios that show the feasibility and the advantages of this architecture. Wolfgang Braun, Joshua Hartmann, Michael Menth |
IM | 3 |
| 2017 | On Moving Averages, Histograms and Time-DependentRates for Online MeasurementabstractMoving averages (MAs) are often used in adaptive systems to monitor the state during operation. Their output is used as input for control purposes. There are multiple methods with different ability, complexity, and parameters. We propose a framework for the definition of MAs and develop performance criteria, e.g., the concept of memory, that allow to parameterize different methods in a comparable way. Moreover, we identify deficiencies of frequently used methods and propose corrections. We extend MAs to moving histograms which facilitate the approximation of time-dependent quantiles. We further extend the framework to rate measurement, discuss various approaches, and propose a novel method which reveals excellent properties. The proposed concepts help to visualize time-dependent data and to simplify design, parametrization, and evaluation of technical control systems. Michael Menth, Frederik Hauser |
ICPE | 1 |
| 2017 | Demo: Time Series Online Measurement for Python (TSOMpy)abstractTSOMpy is a Python library for online measurement of time series, i.e., it provides functions to calculate moving averages, moving histograms, and time-dependent rates. The demo illustrates various methods for these concepts and points out their differences. The tool can be used to apply online measurement to time series randomly generated according to specified stochastic processes or to own data sets. The library furthermore allows the reproduction of the tables and figures presented in [1]. Michael Menth, Frederik Hauser |
ICPE | 1 |
| 2017 | Distributed Load Balancing for the Resilient Publish/Subscribe Overlay in SeDAXabstractSEcure data-centric application eXtension (SeDAX) is a publish/subscribe information-centric networking architecture, where publishers send messages to the appropriate message broker over a Delaunay-triangulated overlay network. Resilient data forwarding and data redundancy enable a high level of reliability. Overlay nodes and topics are addressed via geo-coordinates. A topic is stored on primary and secondary nodes, those nodes closest and second-closest to the topic's coordinate, respectively. The overlay automatically reroutes a topic's messages to its secondary node should its primary node fail. In the original proposal, SeDAX determines the coordinate of a topic by hashing its name. This kind of topic allocation is static, which can lead to unintended load imbalances. We propose a topic delegation mechanism to make the assignment of topics to nodes dynamic. Our proposed mechanism is the only existing method to improve the flexibility and resource management of the SeDAX architecture so far. We define three resilience levels that allow information on the SeDAX overlay to survive 0, 1, or 2 node failures, imposing different loads on SeDAX nodes. For this elaborated SeDAX approach, we suggest a distributed resource management system that detects traffic imbalances among SeDAX nodes and re-assigns topics to other coordinates for load balancing purposes. We evaluate the load imbalance for the different resilience levels, for different topic characteristics, and in particular for topics with storage requirements growing over time. The proposed algorithm leads to well balanced load on SeDAX nodes while keeping load redistribution at a reasonable level. Michael Höfling, Cynthia G. Mills, Michael Menth |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2016 | Advanced communication modes for the publish/subscribe C-DAX middlewareabstractC-DAX is a cyber-secure publish/subscribe middleware tailored to the needs of smart grids, offering end-to-end security, and scalable and resilient communication among participants in a smart grid. While C-DAX' broker-based publish/subscribe mechanisms are well-suited for scalable information dissemination with regard to high numbers of publishers and subscribers, (1) additional transmission delays are inherent to the design because of multi-hop application layer forwarding, and (2) interactive (probably legacy) applications are prohibited due to the one-way publish/subscribe paradigm and potential dependencies on IP communication. This work presents two advanced communication modes for the C-DAX architecture, addressing those issues: (1) broker-less publish/subscribe for delay-sensitive applications, and (2) transparent IP-tunneling over publish/subscribe for legacy applications. Those modes further improve C-DAX' suitability for smart grid applications, including enhanced real-time application support, and transparent support for legacy smart grid communication protocols. Michael Höfling, Florian Heimgaertner, Michael Menth |
NOMS | 3 |
| 2016 | Activity-based congestion management for fair bandwidth sharing in trusted packet networksabstractCongestion management detects congestion in a network and resolves it, e.g., by dropping or marking packets. A challenge is to drop or mark the right packets if fair capacity sharing is desired, especially if a few heavy users monopolize the bandwidth, e.g., by opening many flows or using non-responsive transport protocols. To this end, we propose activity-based congestion management (ABC). Users are assigned reference rates and their traffic is equipped with activity information. The activity indicates by which factor the transmission rate of a user exceeds his reference rate. ABC leverages active queue management (AQM) in routers or switches and uses the packets' activity information to adapt the drop or mark probabilities of the AQM. ABC is scalable as switches do not require user states, multiple queues, or signalling. We investigated ABC by means of simulation under conditions where a heavy user wants to monopolize a bottleneck's bandwidth. ABC provides an ecosystem where users with non-responsive constant-bitrate (CBR) traffic can maximize their throughput on a congested bottleneck link by adapting their sending rate to their fair share induced by their reference rate. Users with responsive TCP traffic obtain approximately fair capacity shares. Moreover, ABC protectes TCP traffic when competing with traffic from CBR users. We investigate the impact of system parameters and give recommendations for configuration. Michael Menth, Nikolas Zeitler |
NOMS | 1 |
| 2016 | Routing optimization for IP networks with loop-free alternates
Matthias Hartmann, David Hock, Michael Menth |
Comput. Networks | 3 |
| 2015 | Integration of IEEE C37.118 and publish/subscribe communicationabstractIEEE C37.118 is the current standard for synchrophasor measurements in power systems. It defines the measurement method and communication protocols for the entities in a synchrophasor network. The standard offers two different modes for client-server communication, but cannot be used unchanged over publish/subscribe communication architectures, whose major advantage is simplified and incremental integration of new applications. This work reviews the communication part of IEEE C37.118, and provides an adapter-based solution to easily connect and integrate entities in a synchrophasor network over a publish/subscribe communication architecture. The proposed adapters offer standard-compliant communication between the synchrophasor measurement network entities to facilitate the exchange of measurement data. Michael Höfling, Florian Heimgaertner, Daniel Fuchs, Michael Menth, Paolo Romano 0001, Teklemariam Tsegay Tesfay, Mario Paolone, Jimmie Adolph, Vidar Gronas |
ICC | 4 |
| 2015 | Scalable resilience for Software-Defined Networking using Loop-Free Alternates with loop detectionabstractIn this paper we propose a novel resilience scheme for OpenFlow-based Software-Defined Networking (SDN). To forward packets in line speed, OpenFlow switches store their flow tables in expensive, limited TCAM due to which the stored tables cannot be large. Most resilience mechanisms require additional entries thus the implementation in OpenFlow may quickly exceed the available TCAM. Loop-Free Alternates (LFAs) are a standardized mechanism for fast reroute in IP networks which do not require additional entries. However, LFAs cannot protect against all single link and node failures. Moreover, some LFAs even cause loops in case of some node failures or multiple failures, making additional links unusable. Excluding such LFAs reduces the fraction of protected destinations (protection coverage) in nodes even further. We suggest a scheme for detection of loops caused by LFAs. It maximizes the protection coverage because it allows all LFAs to be used without creating loops. We describe how LFAs and the loop detection scheme can be implemented in OpenFlow networks with only little packet overhead and a single additional entry per switch. We evaluate our proposal on real network topologies of varying size and connectivity. In particular, we quantify the benefit gained from loop detection. Amongst others, we study the percentage of failures that cannot be protected by LFAs at all, and the percentage of failures in which conventional LFAs cause extra loops. Wolfgang Braun, Michael Menth |
NetSoft | 2 |
| 2015 | Comparison of Relevance Estimation Mechanisms for Cooperative Awareness Messages in VANETsabstractCooperative Awareness Messages (CAMs) regularly distribute state information about vehicles in Vehicular Ad-hoc Networks (VANETs). Hardware modules in series vehicles have limited processing capabilities so that only a subset of received CAMs can be processed which may be chosen by a relevance estimation mechanism (REM). In this work, we review several REMs that differ in complexity. We compare them using various approaches in different road scenarios. The results show that more complex REMs provide similar results in simple road scenarios but clearly improved results for demanding road scenarios. Jakob Breu, Michael Menth |
VTC Fall | 2 |
| 2014 | Comparison of delay bounds for Ethernet networks based on simple Network Calculus algorithmsabstractThis paper gives a simple introduction to Network Calculus (NC), a theory to calculate end-to-end delay bounds for packet-switched communication networks. It illustrates how various networking parameters affect delay bounds when flows are multiplexed. Various algorithms for the calculation of end-to-end delay bounds are revisited and their performance is compared under different conditions. The framework is applicable to feedforward networks and useful to determine delay bounds for flows in Ethernet networks. Michael Menth, Mark Schmidt 0002, Sebastian Veith, Stephan Kehrer, Andreas Dreher |
ISCC | 1 |
| 2014 | Distributed load balancing for resilient information-centric SeDAX networksabstractSeDAX is a publish/subscribe information-centric networking architecture where publishers send messages to the appropriate message broker over a Delaunay-triangulated overlay network. Resilient data forwarding and data redundancy enable a high level of reliability. Overlay nodes and topics are addressed via geo-coordinates. A topic is stored on primary and secondary nodes, those nodes closest and second-closest to the topic's coordinate, respectively. The overlay automatically reroutes a topic's messages to its secondary node should its primary node fail. Currently, SeDAX determines the coordinate of a topic by hashing its name. This kind of topic allocation is static, which can lead to unintended load imbalances. In this paper, we propose a topic delegation mechanism to make the assignment of topics to nodes dynamic. Our proposed mechanism is the only existing method to improve the flexibility and resource management of the SeDAX architecture so far. We define the load of SeDAX nodes and coordinates at different levels of resilience. On this basis, we develop distributed algorithms for load balancing. Simulations show that significant load imbalance can occur with static topic assignment and that the proposed algorithms achieve very good load balancing results. Michael Höfling, Cynthia G. Mills, Michael Menth |
NOMS | 3 |
| 2014 | Demo: a virtualized lab testbed with physical network outlets for hands-on computer networking educationabstractThis demo presents a testbed for computer networking education. It leverages hardware virtualization to accommodate 6 PCs and 2 routers on a single testbed host to reduce costs, energy consumption, space requirements, and heat emission. The testbed excels by providing dedicated physical Ethernet and USB interfaces for virtual machines so that students can interconnect them with cables and switches like in a non-virtualized testbed Mark Schmidt 0002, Florian Heimgaertner, Michael Menth |
SIGCOMM | 3 |
| 2013 | Performance comparison of not-via addresses and maximally redundant trees (MRTs)
Michael Menth, Wolfgang Braun |
IM | 1 |
| 2012 | Modeling and evaluation of address resolution scalability in VPLSabstractMore and more services are provided by large data centers with a potentially very large number of physical or virtual hosts. As the number of hosted services and service consumers increases, also the number of hosts inside a data center raises to cope with the increasing end-user demand. Current data center networks are usually based on Ethernet and mechanisms like load balancing or redundancy between data centers require a transparent connection of these Ethernet networks over a Wide Area Network (WAN). Due to the large number of hosts, these interconnected data center networks face scalability problems on different protocol layers. One such issue, which is currently discussed within the IETF, is the scalability of the link layer Address Resolution Protocol (ARP). This paper studies the control traffic caused by address resolution for interconnected data centers. We develop an analytical model for the ARP traffic between data center locations that takes into account the number of hosts and connected sites. This model can then be used to quantify the ARP traffic for a data center interconnect solution. As an example, we apply our model to Virtual Private LAN Services (VPLS). In addition, we study how an ARP proxy can improve the overall scalability, and we show that a proxy significantly reduces the ARP traffic at VPLS switches. Dominik Klein 0002, Rastin Pries, Michael Scharf, Michael Söllner, Michael Menth |
ICC | 5 |
| 2012 | Performance of PCN-Based Admission Control Under Challenging ConditionsabstractPrecongestion notification (PCN) is a packet-marking technique for IP networks to notify egress nodes of a so-called PCN domain whether the traffic rate on some links exceeds certain configurable bounds. This feedback is used by decision points for admission control (AC) to block new flows when the traffic load is already high. PCN-based AC is simpler than other AC methods because interior routers do not need to keep per-flow states. Therefore, it is currently being standardized by the IETF. We discuss various realization options and analyze their performance in the presence of flash crowds or with multipath routing by means of simulation and mathematical modeling. Such situations can be aggravated by insufficient flow aggregation, long round-trip times, on/off traffic, delayed media, inappropriate marker configuration, and smoothed feedback. Michael Menth, Frank Lehrieder |
IEEE/ACM Trans. Netw. | 1 |
| 2011 | A subscription model for time-scheduled data transfersabstractWe recently witness new services that can afford some delay until data transmission starts, but then benefit from a very large available bandwidth. A popular example is the migration of virtual machines between different sites of a geographically dispersed service provider. In this paper, we propose a subscription model for time-scheduled data transfers. Transmission requests are served consecutively, giving the flows access to the physical bandwidth. This is in contrast to today's Internet where flows are served in parallel so that they compete for the available bandwidth. We present the architecture to enable such data beams. Furthermore, we model and analyze the performance under different conditions and compare it with concurrent transmission. Dominik Klein 0002, Michael Menth, Rastin Pries, Phuoc Tran-Gia, Michael Scharf, Michael Söllner |
Integrated Network Management | 2 |
| 2011 | PCN-based marked flow termination
Michael Menth, Frank Lehrieder |
Comput. Commun. | 1 |
| 2010 | Optimizing unique shortest paths for resilient routing and fast reroute in IP-based networksabstractIntradomain routing in IP networks follows shortest paths according to administrative link costs. When several equal-cost shortest paths exist, routers that use equal-cost multipath (ECMP) distribute the traffic over all of them. To produce single-shortest path (SSP) routing, a selection mechanism (tie-breaker) chooses just one of the equal-cost paths. Tie-breakers are poorly standardized and use information that may change over time, which makes SSP routing unpredictable. Therefore, link costs producing unique shortest paths (USP) are preferred. In this paper, we show that optimized SSP routing can lead to significantly higher link utilization than expected in case of non-deterministic tie-breakers. We investigate the impact of the allowed link cost range on the general availability of USP routing. We use a heuristic algorithm to generate link costs for USP routing and to minimize the maximum link utilization in networks with and without failures. Fast reroute (FRR) mechanisms can repair failures faster than conventional IP rerouting by pre-computing shortest backup paths around failed network elements. However, when multiple equal-cost paths exist, the backup path layout is unpredictable. We adapt our heuristic to optimize USP routing for IP-FRR using not-via addresses and MPLS-FRR with facility and one-to-one backup. Finally, we compare the performance of USP with various other routing schemes using realistic Rocket-fuel topologies. David Hock, Matthias Hartmann, Michael Menth, Christian Schwartz |
NOMS | 3 |
| 2010 | Loop-free alternates and not-via addresses: A proper combination for IP fast reroute?
Michael Menth, Matthias Hartmann, Rüdiger Martin, Tarik Cicic, Amund Kvalbein |
Comput. Networks | 1 |
| 2010 | PCN-based measured rate termination
Michael Menth, Frank Lehrieder |
Comput. Networks | 1 |
| 2010 | FIRMS: A Mapping System for Future Internet RoutingabstractThe locator/identifier split is a design principle for new routing architectures that make Internet routing more scalable. To find the location of a host, it requires a mapping system that returns appropriate locators in response to map-requests for specific identifiers. In this paper, we propose FIRMS, a "Future Internet Routing Mapping System". It is fast, scalable, reliable, secure, and it is able to relay initial packets. We introduce its design, show how it deals with partial failures, explain its security concept, and evaluate its scalability. Michael Menth, Matthias Hartmann, Michael Höfling |
IEEE J. Sel. Areas Commun. | 1 |
| 2009 | PCN-Based Flow Termination with Multiple Bottleneck LinksabstractPre-congestion notification (PCN) is a new packet marking scheme based on which simple measurement-based admission control (AC) and flow termination (FT) are implemented. FT is useful for traffic management in unexpected events, e.g., when admitted flows lead to overload on a link after rerouting which may be due to a link or node failure. While AC is a classic flow control function, FT is new and only little understood so far. The limited literature on FT focuses mainly on a single overloaded link. However, when a link or node fails, redirected traffic is likely to cause overload on multiple backup links (bottlenecks) at the same time. As the packet marking probability for flows traversing multiple bottlenecks is larger than for flows traversing only the most severe bottleneck, more traffic is possibly terminated than needed, i.e. over termination occurs. This paper quantifies potential over termination in case of multiple bottlenecks for different FT mechanisms which are currently discussed by the IETF. Frank Lehrieder, Michael Menth |
ICC | 2 |
| 2009 | Marking Conversion for Pre-Congestion NotificationabstractPre-congestion notification (PCN) defines admissible rates (AR) and supportable rates (SR) per link and marks the PCN traffic rate above these thresholds as AR- or SR-overload. The IETF standardizes simple mechanisms for admission control (AC) and flow termination (FT) based on this PCN-feedback for high-priority DiffServ traffic. While admission control (AC) has been extensively discussed in the literature, flow termination (FT) is a new control function. In this paper we propose an algorithm that converts marked AR-overload into marked SR-overload by unmarking appropriate packets. Classic marked flow termination (MFT) is based on marked AR-overload and works well even with a small number of PCN flows per ingress-egress aggregate and in case of multipath routing. Thanks to the new marking converter MFT also works with marked AR-overload so that a single marking scheme suffices to support AC and FT. We investigate whether MFT with marking conversion based on AR-overload retains the benefits classic MFT. Frank Lehrieder, Michael Menth |
ICC | 2 |
| 2009 | CAPEX-Aware Design of Survivable DWDM Mesh NetworksabstractThis paper reviews the basic architecture and component costs of opaque, transparent, and semi-transparent DWDM networks and looks at the network design problem from a capital expenditure (CAPEX) point of view. Given are a fiber topology and a demand matrix with different bit rates. Required is the least-cost optical equipment for that topology together with the routing and potential muxponder-based aggregation of all demands such that they can be supported by the newly designed network. We look at the problem for networks without resilience requirements and for survivable networks using 1+1 protection against single fiber cuts. We model this problem for the three types of optical networks by integer linear programs (ILPs) in a canonical way. Christopher Pluntke, Michael Menth, Michael Duelli |
ICC | 2 |
| 2009 | Impact of Best Effort Frame Bursting in IEEE 802.11 NetworksabstractWireless LAN strongly prioritizes high priority traffic over low priority best effort traffic. This causes reduced access to the medium for low priority traffic and under some conditions even leads to starvation. To compensate the throughput reduction of low priority traffic, we propose frame bursting in this paper. That means low priority traffic is sent infrequently, but many frames may be sent in a burst. Our simulation results show that the throughput of the low priority best effort traffic class can be significantly increased without disrupting high priority traffic. Rastin Pries, Dirk Staehle, Stefan Menth, Michael Menth, Phuoc Tran-Gia |
VTC Spring | 4 |
| 2009 | Threshold configuration and routing optimization for PCN-based resilient admission control
Michael Menth, Matthias Hartmann |
Comput. Networks | 1 |
| 2009 | Relaxed multiple routing configurations: IP fast reroute for single and correlated failuresabstractMulti-topology routing is an increasingly popular IP network management concept that allows transport of different traffic types over disjoint network paths. The concept is of particular interest for implementation of IP fast reroute (IP FRR). The authors have previously proposed an IP FRR scheme based on multi-topology routing called Multiple Routing Configurations (MRC). MRC supports guaranteed, instantaneous recovery from any single link or node failure in biconnected networks as well as from many combined failures, provided sufficient bandwidth on the surviving links. Furthermore, in MRC different failures result in routing over different network topologies, which gives a good control of the traffic distribution in the networks after a failure Tarik Cicic, Audun Fosselie Hansen, Amund Kvalbein, Matthias Hartmann, Rüdiger Martin, Michael Menth, Stein Gjessing, Olav Lysne |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2009 | Source models for speech traffic revisited
Michael Menth, Andreas Binzenhöfer, Stefan Mühleck |
IEEE/ACM Trans. Netw. | 1 |
| 2009 | Resilience analysis of packet-witched communication networks
Michael Menth, Michael Duelli, Rüdiger Martin, Jens Milbrandt |
IEEE/ACM Trans. Netw. | 1 |
| 2008 | Performance Evaluation of PCN-Based Admission ControlabstractPre-congestion notification (PCN) marks packets when the PCN traffic rate exceeds an admissible link rate and this marking information is used as feedback from the network to take admission decisions for new flows. This idea is currently under standardization in the IETF. Different marking algorithms are discussed and various admission control algorithms are proposed that decide based on the packet markings whether further flows should be accepted or blocked. In this paper, we propose a two-layer architecture that makes the coexistence of various algorithms explicit. We propose novel control algorithms, investigate their behavior under various conditions, and compare them with existing approaches. Michael Menth, Frank Lehrieder |
IWQoS | 1 |
| 2008 | Relaxed multiple routing configurations for IP fast rerouteabstractMulti-topology routing is an increasingly popular IP network management concept that allows transport of different traffic types over disjoint network paths. The concept is of particular interest for implementation of IP fast reroute (IP FRR). First, it can support guaranteed, instantaneous recovery from any link or node failure. Second, different failures result in routing over different network topologies, which augments the parameter space for load distribution optimizations. Multiple routing configurations (MRC) is the state-of-the-art IP FRR scheme based on multi-topology routing today. In this paper we present a new, enhanced IP FRR scheme which we call ldquorelaxed MRCrdquo (rMRC). rMRC simplifies the topology construction and increases the routing flexibility in each topology. According to our experimental evaluation, rMRC has several benefits compared to MRC. The number of backup topologies required to provide protection against the same set of failures is reduced, hence reducing state in routers. In addition, the backup paths are shorter, and the link utilization is significantly better. Tarik Cicic, Audun Fosselie Hansen, Amund Kvalbein, Matthias Hartmann, Rüdiger Martin, Michael Menth |
NOMS | 6 |
| 2008 | Resilient network admission control
Michael Menth, Stefan Kopf, Joachim Charzinski, Karl J. Schrodi |
Comput. Networks | 1 |
| 2007 | Accuracy and Dynamics of Multi-Stage Load Balancing for Multipath Internet RoutingabstractFlow-based load balancing algorithms for multipath Internet routing are often used for traffic engineering. However, the target load distribution and the load balanced result agree only on average, and there is a significant inaccuracy over time due to stochastic effects. Dynamic load balancing reduces this inaccuracy by relocating flows to other paths in regular time intervals. This causes packet reordering. Therefore, the flow reassignment rate should be kept low. In this paper we consider load balancing in networks. It differs from load balancing at a single node by the fact that several load balancing steps may be performed at consecutive nodes in series. This affects the flow reassignment rate and the load balancing accuracy due to interdependencies and polarization effects. We quantify the impact by simulation results, explain the observed phenomena, and give recommendations for load balancing in practice. Rüdiger Martin, Michael Menth, Michael Hemmkeppler |
ICC | 2 |
| 2007 | Optimization of the Self-Protecting Multipath for Deployment in Legacy NetworksabstractThe self-protecting multipath (SPM) is a simple protection switching mechanism that can be implemented, e.g., by MPLS. We present a linear program for the optimization of the SPM load balancing parameters to maximize the amount of transportable traffic with resilience requirements. This is needed to configure the SPM for the deployment in legacy networks. Our study shows that the SPM is very efficient in the sense that it can carry 50% - 200% more protected traffic than IP rerouting in sufficiently meshed networks. The investigation of the computation time and the memory consumption recommends the COIN LP (CLP) as preferred LP solver. The computation time of the program depends mainly on the number of links in the network and networks with up to 240 links can be optimized within one hour on a standard PC. Michael Menth, Rüdiger Martin, Ulrich Spörlein |
ICC | 1 |
| 2007 | Integer SPM: Intelligent Path Selection for Resilient Networks
Rüdiger Martin, Michael Menth, Ulrich Spörlein |
Networking | 2 |
| 2007 | Robust IP Link Costs for Multilayer Resilience
Michael Menth, Matthias Hartmann, Rüdiger Martin |
Networking | 1 |
| 2006 | Capacity Requirements for the One-to-One Backup Option in MPLS Fast RerouteabstractMPLS fast reroute (MPLS-FRR) mechanisms deviate the traffic in case of network failures at the router closest to the outage location to achieve an extremely fast reaction time. We review the one-to-one backup and the facility backup that are options for MPLS-FRR to deviate the traffic via a detour or a bypass around the failed elements, respectively. Basically, the backup paths can take the shortest path that avoids the outage location from the point of local repair to the tail-end router or to the merge point with the primary path. We suggest two simple modifications that lead to a new path layout which can be implemented by one-to-one and by facility backup. We evaluate the backup capacity requirements, the length of the backup paths, and the number of backup paths per primary path in a parametric study regarding the network characteristics. Our proposals save a considerable amount of backup capacity compared to the standard mechanisms. They are suitable for application in practice since they are simple and conform to the standards. Rüdiger Martin, Michael Menth, Korhan Canbolat |
BROADNETS | 2 |
| 2006 | Accuracy and Dynamics of Hash-Based Load Balancing Algorithms for Multipath Internet RoutingabstractThis paper studies load balancing for multipath Internet routing. We focus on hash-based load balancing algorithms that work on the flow level to avoid packet reordering which is detrimental for the throughput of transport layer protocols like TCP. We propose a classification of hash-based load balancing algorithms, review existing ones and suggest new ones. Dynamic algorithms can actively react to load imbalances which causes route changes for some flows and thereby again packet reordering. Therefore, we investigate the load balancing accuracy and flow reassignment rate of load balancing algorithms. Our exhaustive simulation experiments show that these performance measures depend significantly on the traffic properties and on the algorithms themselves. As a consequence, our results should be taken into account for the application of load balancing in practice. Rüdiger Martin, Michael Menth, Michael Hemmkeppler |
BROADNETS | 2 |
| 2006 | Time-Exponentially Weighted Moving Histograms (TEWMH) for Application in Adaptive SystemsabstractThe distribution of a stationary point process can be sampled by an ordinary histogram. If the distribution of the process varies over time, a static histogram still yields results that are averaged over time since the beginning of the data collection. In this paper, we propose the time-exponentially weighted moving histogram (TEWMH) to derive an estimate for the time-dependent distribution of an instationary point process. The importance of the samples decays exponentially over time such that young samples contribute more to the empirical distribution than old ones. The strength of the decay can be controlled by a simple parameter which determines the memory of the histogram. We present a simple implementation of the TEWMH such that this mechanism can be well applied in practice. The empirical distribution serves for the derivation of other time-dependent statistical measures such as time-dependent percentiles of the observed random variable. These provide useful feedback in adaptive systems. We illustrate the application of the TEWMH for experience-based admission control (EBAC) and show its benefits. Michael Menth, Jens Milbrandt, Jan Junker |
GLOBECOM | 1 |
| 2006 | Impact of Unprotected Multi-Failures in Resilient SPM Networks: a Capacity Dimensioning ApproachabstractRestoration or protection switching mechanisms protect traffic in packet-switched networks against local outages by deviating it around the failure location. This assures connectivity, but sufficient backup capacity is also needed to maintain quality of service (QoS) for the duration of the outage. To that end, sufficient capacity must be provided on the links so that the network can survive a set of protected failure scenarios without congestion due to redirected traffic. The self- protecting multipath (SPM) is a protection switching mechanism for which the required backup capacity can be minimized by linear optimization methods. However, unprotected multi-failures may lead to congestion in such "resilient networks" since backup capacity may be missing. In this paper, we quantify and compare the impact of unprotected double failures on the QoS for the optimized SPM, single shortest path routing (SSP), and equal- cost multipath (ECMP) routing. Michael Menth, Rüdiger Martin, Ulrich Spörlein |
GLOBECOM | 1 |
| 2006 | Network Dimensioning for the Self-Protecting Multipath: A Performance StudyabstractThe self-protecting multipath (SPM) is a simple protection switching mechanism that can be implemented, e.g., by MPLS. We present a linear program to optimize the SPM load balancing parameters for network dimensioning. Our study shows that the SPM is a very efficient mechanism in the sense that it requires only little backup capacity since it outperforms the p-cycle approach and the shortest path rerouting by far. The investigation of the computation time and the memory consumption recommends the Simplex method as an LP solver rather than an interior point method (IPM). The computation time of the program depends mainly on the number of links in the network and it is well feasible for small and and medium size networks. For large networks, however, fast heuristics are required. Michael Menth, Rüdiger Martin, Ulrich Spörlein |
ICC | 1 |
| 2006 | Analysis of the Message Waiting Time for the FioranoMQ JMS ServerabstractThe Java messaging service (JMS) is a means to organize communication among distributed applications according to the publish/subscribe principle. If the subscribers install filter rules on the JMS server, JMS can be used as a message routing platform, but it is not clear whether its message throughput is sufficiently high to support large-scale systems. We perform measurements for the FioranoMQ JMS server and derive a simple model for its message processing time that takes message filters and the message replication grade into account. Then, we analyze the JMS server capacity and the message waiting time for various application scenarios. We show that the message waiting time is not an issue as long as the server throughput is sufficiently high. Finally, we assess the capacity of two different distributed JMS architectures whose objective is to increase the capacity of the JMS beyond the limit of a single server. Michael Menth, Robert Henjes |
ICDCS | 1 |
| 2006 | Performance of Experience-Based Admission Control in the Presence of Traffic Changes
Jens Milbrandt, Michael Menth, Jan Junker |
Networking | 2 |
| 2006 | Capacity overprovisioning for networks with resilience requirementsabstractThis work focuses on capacity overprovisioning (CO) as an alternative to admission control (AC) to implement quality of service (QoS) in packet-switched communication networks. CO prevents potential overload while AC protects the QoS of the traffic during overload situations. Overload may be caused, e. g., by uctuations of the traffic rate on a link due to its normal stochastic behavior (a), by traffic shifts within the network due to popular contents (b), or by redirected traffic due to network failures (c). Capacity dimensioning methods for CO need to take into account all potential sources of overload while AC can block excess traffic caused by (a) and (b) if the capacity does not suffice. The contributions of this paper are (1) the presentation of a capacity dimensioning method for networks with resilience requirements and changing traffic matrices, (2) the investigation of the impact of the mentioned sources of overload (a-c) on the required capacity for CO in networks with and without resilience requirements, and (3) a comparison of this equired capacity with the one for AC. Our results show that in the presence of strong traffic shifts CO requires more capacity than AC. However, if resilience against network failures is required, both CO and AC need additional backup capacity for the redirected traffic. In this case, CO can use the backup capacity to absorb other types of overload. As a consequence, CO and AC have similar bandwidth requirements. These findings are robust against the network size. Michael Menth, Rüdiger Martin, Joachim Charzinski |
SIGCOMM | 1 |
| 2006 | Service differentiation with MEDF scheduling in TCP/IP networks
Michael Menth, Rüdiger Martin |
Comput. Commun. | 1 |
| 2005 | Comparison of Border-to-Border Budget Based Network Admission Control and Capacity Overprovisioning
Rüdiger Martin, Michael Menth, Joachim Charzinski |
NETWORKING | 2 |
| 2004 | Impact of routing and traffic distribution on the performance of network admission controlabstractIn contrast to link admission control (LAC), which limits the truffle on a single link, network admission control (NAC) methods limit the traffic within a network. In this paper we present four basic budget based NAC approaches that have different complexity. They categorize most resource management schemes from a performance point of view regarding the maximum bandwidth utilization. Our results show that the option of single- or multi-path routing has a significant impact on the NAC performance while it is rather independent of the structure of the traffic matrix. Michael Menth, Jens Milbrandt, Stefan Kopf |
ISCC | 1 |
| 2004 | Experience-based admission control (EBAC)abstractClassical admission control approaches take either descriptor or measurement based information about the traffic into account without relating them to each other. We propose a experience-based AC (EBAC) which uses an empirical percentile of the effective reservation utilization to determine a suitable overbooking factor. In this paper, we show the impact of different measurement time scale resolutions and different quantiles on the performance of the system. We propose aging mechanisms for statistic collection to make the system adaptive to traffic mixes that change over time. We illustrate their effectiveness by simulation results. Michael Menth, Jens Milbrandt, Simon Oechsner |
ISCC | 1 |
| 2004 | Self-Protecting Multipaths - A Simple and Resource-Effcient Protection Switching Mechanism for MPLS Networks
Michael Menth, Andreas Reifert, Jens Milbrandt |
NETWORKING | 1 |
| 2004 | A performance evaluation framework for network admission control methodsabstractWe introduce the notion of link and network admission control (LAC, NAC) and present three fundamentally different budget based NAC methods which categorize most of today's implemented NAC approaches. We propose a performance evaluation framework for their comparison. The required network capacity for each method is dimensioned for a certain flow blocking probability, and the average resource utilization is taken as performance measure. We point out several implementation options and investigate their impact. Based on numerical results, we give recommendations for preferred procedures. Finally, we compare different NAC methods under varying load conditions. Michael Menth, Stefan Kopf, Jens Milbrandt |
NOMS (1) | 1 |
| 2003 | MEDF - A Simple Scheduling Algorithm for Two Real-Time Transport Service Classes with Application in the UTRANabstractIn this paper, we consider real-time speech traffic, real-time circuit-switched data (CSD) and nonreal-time packet-switched data (PSD) in the UMTS terrestrial radio access network (UTRAN). The focus is on the single low-bandwidth link that interconnects the radio network controller (RNC) and the base station (node B). We show that all traffic on this link has real-time requirements. But we take advantage of the radio link control (RLC) layer protocol and formulate suitable quality of service (QoS) criteria that lead to two different transport service classes (TSC): A stringent TSC for speech traffic and CSD, and a tolerant TSC for PSD. The RNC transmits packets from both TSCs via a single low-bandwidth link to the node B. Since transmission capacity on this interface is a serious cost factor in the UTRAN, the link utilization should be optimized while respecting the QoS requirements of both TSCs. We propose a modified version (MEDF) of the earliest deadline first (EOF) algorithm for that task. In contrast to EDF, the MEDF is easy to implement in hardware and in contrast to algorithms like weighted fair queueing (WFQ), the knowledge of the traffic mix is not needed for a suitable parameter setting in the MEDF scheduler. The simulation results show its superiority over first-in-first-out (FIFO), static priority (SP), and weighted round robin (WRR) scheduling. The analysis of the waiting time distribution explains why MEDF performs better than the other scheduling strategies. Michael Menth, Matthias Schmid, Herbert Heiss, Thomas Reim |
INFOCOM | 1 |
| 2003 | Introduction to Budget Based Network Admission Control MethodsabstractIn this paper we describe the new concept of network admission control (NAC) and delimit it against link admission control (LAC). Four basically different budget based NAC methods are presented. Michael Menth, Stefan Kopf, Jens Milbrandt, Joachim Charzinski |
LCN | 1 |
| 2001 | MPEG-L/MRP: implementing adaptive streaming of MPEG videos for interactive internet applicationsabstractExisting multimedia streaming technologies offer no specific support for user interaction like jumping to bookmarks in a video, or switching to reverse play. When the users, e.g., jump to a bookmark, the player requests frames for the new presentation point from the server and resumes playing only when the data has arrived. Our solution for this problem is the client prefetching the buffering strategy, MPEG-L/MRP, that ensures that the frames which are needed for a response to a possible user interaction are already in the client's buffer, which leads to qucik and smooth reaction to user interactions. In case of variable bandwidth, our MPEG-1 streaming approach selects only a subset of all frames to be fetched from the server and supports a smooth presentation at a reduced frame rate with correct timelines.The technical demonstration shows the interactive streaming of MPEG-videos and illustrates our buffering and prefetching strategy. Susanne Boll, Wolfgang Klas, Michael Menth, Christian Heinlein |
ACM Multimedia | 3 |