Matthias Wählisch

dblp:91/5978 · DBLP profile ↗
← Back
82ranked-venue papers
16as first author
35since 2021 · last 2026
0000-0002-3825-2807ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 59 · 13 first-author · 22 since 2021Security and privacy · 8 · 2 first-author · 5 since 2021Systems, architecture and hardware · 3 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Secrets Best Not Shared: DNS Privacy Enhancements for the Constrained IoT
abstract
Attackers often identify DNS traffic to disrupt or compromise Internet services. While prior work has focused on encrypting queries using DNS over TLS, HTTPS, or QUIC to counter such attacks, we consider IETF protocols designed for resource-constrained IoT devices and empirically analyze the potential of obfuscating DNS traffic in addition to encryption. We create a dataset of machine-to-machine-compatible data objects along with the corresponding DNS resolution processes, evaluating 296 deployment scenarios of resolving host names, including DNS over the Constrained Application Layer Protocol (CoAP) and an onion routing flavor of CoAP under varying link-layer conditions. We compare them to DNS over HTTPS. Using Random Forest and a header field analysis, we identify fields that leak most information. Our findings show that DNS over CoAP with equalized packet lengths, block-wise transfer, and header compression reduces the accuracy of identifying DNS frames to 86% and further to 77% with payload compression. Our approach outperforms DNS over HTTPS, where classifiers always identify DNS frames based on IP addresses. The dataset is publicly available.
Martine Lenders, Thomas C. Schmidt, Matthias Wählisch
EuroS&P3
2025 Forward to Hell? On the Potentials of Misusing Transparent DNS Forwarders in Reflective Amplification Attacks
abstract
The DNS infrastructure is infamous for facilitating reflective amplification attacks. Various countermeasures such as server shielding, access control, rate limiting, and protocol restrictions have been implemented. Still, the threat remains throughout the deployment of DNS servers. In this paper, we report on and evaluate the often unnoticed threat that derives from transparent DNS forwarders, a widely deployed, incompletely functional set of DNS components. Transparent DNS forwarders transfer DNS requests without rebuilding packets with correct source addresses. As such, transparent forwarders feed DNS requests into (mainly powerful and anycasted) open recursive resolvers, which thereby can be misused to participate unwillingly in distributed reflective amplification attacks. We show how transparent forwarders raise severe threats to the Internet infrastructure. They easily circumvent rate limiting and achieve an additional, scalable impact via the DNS anycast infrastructure. We empirically verify this scaling behavior up to a factor of 14. Transparent forwarders can also assist in bypassing firewall rules that protect recursive resolvers, making these shielded infrastructure entities part of the global DNS attack surface.
Maynard Koch, Florian Dolzmann, Thomas C. Schmidt, Matthias Wählisch
CCS4
2025 The SAP Cloud Infrastructure Dataset: A Reality Check of Scheduling and Placement of VMs in Cloud Computing
Arno Uhlig, Iris Braun, Matthias Wählisch
IMC3
2025 CoRa: A Collision-Resistant LoRa Symbol Detector of Low Complexity
José Álamos, Thomas C. Schmidt, Matthias Wählisch
INFOCOM3
2025 Lessons Learned from Operating a Large Network Telescope
abstract
Network telescopes (aka darknets) collect unsolicited Internet traffic (aka Internet background radiation or IBR), which includes benign and malicious scanning as well as artifacts of spoofed denial-of-service attacks and misconfigured software and hosts. Analysis of this traffic has revealed macroscopic insights into security-related events and global network dynamics such as outages. Operating a large-scale network telescope is challenging but often taken for granted, more so than in more mature scientific disciplines. We offer the first study documenting our experiences operating the UCSD Network Telescope, the largest and longest-operating network telescope supporting scientific research. We provide background on the history of the telescope, and focus on increasing operational challenges as the underlying network evolves. We develop and apply techniques to leverage third-party scanning activity to validate the integrity of the data, and to discover misconfigurations in the instrumentation. These insights are crucial for understanding measurement results, which we illustrate using concrete examples. We discuss how our findings generalize to support the expanding ecosystem of other passive techniques, such as honeypots, to track security phenomena.
Alexander Männel 0002, Jonas Mücke, K. C. Claffy, Max Gao, Ricky K. P. Mok, Marcin Nawrocki, Thomas C. Schmidt, Matthias Wählisch
SIGCOMM8
2024 The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS Assessments
abstract
Motivated by the impressive but diffuse scope of DDoS research and reporting, we undertake a multistakeholder (joint industry-academic) analysis to seek convergence across the best available macroscopic views of the relative trends in two dominant classes of attacks - direct-path attacks and reflection-amplification attacks. We first analyze 24 industry reports to extract trends and (in)consistencies across observations by commercial stakeholders in 2022. We then analyze ten data sets spanning industry and academic sources, across four years (2019-2023), to find and explain discrepancies based on data sources, vantage points, methods, and parameters. Our method includes a new approach: we share an aggregated list of DDoS targets with industry players who return the results of joining this list with their proprietary data sources to reveal gaps in visibility of the academic data sources. We use academic data sources to explore an industry-reported relative drop in spoofed reflection-amplification attacks in 2021-2022. Our study illustrates the value, but also the challenge, in independent validation of security-related properties of Internet infrastructure. Finally, we reflect on opportunities to facilitate greater common understanding of the DDoS landscape. We hope our results inform not only future academic and industry pursuits but also emerging policy efforts to reduce systemic Internet security vulnerabilities.
Raphael Hiesgen, Marcin Nawrocki, Marinho P. Barcellos, Daniel Kopp, Oliver Hohlfeld, Echo Chan, Roland Dobbins, Christian Doerr, Christian Rossow, Daniel R. Thomas, Mattijs Jonker, Ricky K. P. Mok, Xiapu Luo, John Kristoff, Thomas C. Schmidt, Matthias Wählisch, K. C. Claffy
IMC16
2024 ReACKed QUICer: Measuring the Performance of Instant Acknowledgments in QUIC Handshakes
abstract
In this paper, we present a detailed performance analysis of QUIC instant~ACK, a standard-compliant approach to reduce waiting times during the QUIC connection setup in common CDN deployments. To understand the root causes of the performance properties, we combine numerical analysis and the emulation of eight QUIC implementations using the QUIC Interop Runner. Our experiments comprehensively cover packet loss and non-loss scenarios, different round trip times, and TLS certificate sizes. To clarify instant ACK deployments in the wild, we conduct active measurements of 1M~popular domain names. For almost all domain names under control of Cloudflare, Cloudflare uses instant ACK, which in fact improves performance. We also find, however, that instant ACK may lead to unnecessary retransmissions or longer waiting times under some network conditions, raising awareness of drawbacks of instant ACK in the future.
Jonas Mücke, Marcin Nawrocki, Raphael Hiesgen, Thomas C. Schmidt, Matthias Wählisch
IMC5
2024 PUF for the Commons: Enhancing Embedded Security on the OS Level
abstract
Security is essential for the Internet of Things (IoT). Cryptographic operations for authentication and encryption commonly rely on random input of high entropy and secure, tamper-resistant identities, which are difficult to obtain on constrained embedded devices. In this paper, we design and analyze a generic integration of physically unclonable functions (PUFs) into the IoT operating system RIOT that supports about 250 platforms. Our approach leverages uninitialized SRAM to act as the digital fingerprint for heterogeneous devices. We ground our design on an extensive study of PUF performance in the wild, which involves SRAM measurements on more than 700 IoT nodes that aged naturally in the real-world. We quantify static SRAM bias, as well as the aging effects of devices and incorporate the results in our system. This work closes a previously identified gap of missing statistically significant sample sizes for testing the unpredictability of PUFs. Our experiments on COTS devices of 64 kB SRAM indicate that secure random seeds derived from the SRAM PUF provide 256 Bits-, and device unique keys provide more than 128 Bits of security. In a practical security assessment we show that SRAM PUFs resist moderate attack scenarios, which greatly improves the security of low-end IoT devices.
Peter Kietzmann, Thomas C. Schmidt, Matthias Wählisch
IEEE Trans. Dependable Secur. Comput.3
2024 The Log4j Incident: A Comprehensive Measurement Study of a Critical Vulnerability
abstract
On December 10, 2021, Log4Shell was disclosed to the public and was quickly recognized as a most severe vulnerability. It exploits a bug in the wide-spread Log4j library that allows for critical remote-code-execution (RCE). Any service that uses this library and exposes an interface to the Internet is potentially vulnerable. In this paper, we report about a measurement study starting with the day of disclosure. We follow the rush of scanners during the first two months after the disclosure and observe the development of the Log4Shell scans in the subsequent year. Based on traffic data collected at several vantage points we analyze the payloads sent by researchers and attackers. We find that the initial rush of scanners ebbed quickly, but continued in waves throughout 2022. Benign scanners showed interest only in the first days after the disclosure, whereas malicious scanners continue to target the vulnerability. During both periods, a single entity appears responsible for the majority of the malicious activities.
Raphael Hiesgen, Marcin Nawrocki, Thomas C. Schmidt, Matthias Wählisch
IEEE Trans. Netw. Serv. Manag.4
2024 The Resource Public Key Infrastructure (RPKI): A Survey on Measurements and Future Prospects
abstract
The adoption of the Resource Public Key Infrastructure (RPKI) is increasing. To better understand and improve RPKI deployment, measuring route origin authorization (ROA) objects, RPKI route origin validation (ROV), and RPKI resilience is essential. In this paper, we survey RPKI-related research that aims to understand RPKI deployment. Additionally, we enrich our survey with many industry and IETF-related contributions. Our work provides an in-depth analysis of the many ideas and challenges discussed in studies of the RPKI ecosystem and includes lessons from mistakes made in the past, which we should avoid in the future.
Nils Rodday, Ítalo S. Cunha, Randy Bush, Ethan Katz-Bassett, Gabi Dreo Rodosek, Thomas C. Schmidt, Matthias Wählisch
IEEE Trans. Netw. Serv. Manag.7
2023 SoK: A Data-driven View on Methods to Detect Reflective Amplification DDoS Attacks Using Honeypots
abstract
In this paper, we revisit the use of honeypots for detecting reflective amplification attacks. These measurement tools require careful design of both data collection and data analysis including cautious threshold inference. We survey common amplification honeypot platforms as well as the underlying methods to infer attack detection thresholds and to extract knowledge from the data. By systematically exploring the threshold space, we find most honeypot platforms produce comparable results despite their different configurations. Moreover, by applying data from a large-scale honeypot deployment, network telescopes, and a real-world baseline obtained from a leading DDoS mitigation provider, we question the fundamental assumption of honeypot research that convergence of observations can imply their completeness. Conclusively we derive guidance on precise, reproducible honeypot research, and present open challenges.
Marcin Nawrocki, John Kristoff, Raphael Hiesgen, Chris Kanich, Thomas C. Schmidt, Matthias Wählisch
EuroS&P6
2023 6LoRa: Full Stack IPv6 Networking with DSME-LoRa on Low Power IoT Nodes
José Álamos, Thomas C. Schmidt, Matthias Wählisch
EWSN3
2023 IPv6 over Bluetooth Advertisements: An alternative approach to IP over BLE
Hauke Petersen, János Brodbeck, Thomas C. Schmidt, Matthias Wählisch
EWSN4
2022 On the interplay between TLS certificates and QUIC performance
abstract
In this paper, we revisit the performance of the QUIC connection setup and relate the design choices for fast and secure connections to common Web deployments. We analyze over 1M Web domains with 272k QUIC-enabled services and find two worrying results. First, current practices of creating, providing, and fetching Web certificates undermine reduced round trip times during the connection setup since sizes of 35% of server certificates exceed the amplification limit. Second, non-standard server implementations lead to larger amplification factors than QUIC permits, which increase even further in IP spoofing scenarios. We present guidance for all involved stakeholders to improve the situation.
Marcin Nawrocki, Pouyan Fotouhi Tehrani, Raphael Hiesgen, Jonas Mücke, Thomas C. Schmidt, Matthias Wählisch
CoNEXT6
2022 Usable Security for an IoT OS: Integrating the Zoo of Embedded Crypto Components Below a Common API
Lena Boeckmann, Peter Kietzmann, Leandro Lanzieri, Thomas C. Schmidt, Matthias Wählisch
EWSN5
2022 Dynamic Clock Reconfiguration for the Constrained IoT and its Application to Energy-efficient Networking
Michel Rottleuthner, Thomas C. Schmidt, Matthias Wählisch
EWSN3
2022 Poster Abstract: Offloading Crypto Processing with RIOT
abstract
Secure elements allow for offloading complex crypto operations from embedded devices to external, protected hardware. In this poster, we present a concept for transparently accessing multiple secure elements behind a unified API as a feature of an IoT OS.
Lena Boeckmann, Peter Kietzmann, Thomas C. Schmidt, Matthias Wählisch
IPSN4
2022 Secure and Authorized Client-to-Client Communication for LwM2M
abstract
Constrained devices on the Internet of Things (IoT) continuously produce and consume data. LwM2M manages millions of these devices in a server-centric architecture, which challenges edge net-works with expensive uplinks and time-sensitive use cases. In this paper, we contribute two LwM2M extensions to enable client-to-client (C2C) communication: (i) an authorization mechanism for clients, and (ii) an extended management interface to allow secure C2C access to resources. We analyse the security properties of the proposed extensions and show that they are compliant with LwM2M security requirements. Our performance evaluation on off-the-shelf IoT hardware reveals that C2C communication out-performs server-centric deployments. First, LwM2M deployments with edge C2C communication yield a ≈ 90% faster notification delivery and ≈ 8 times higher throughput compared to common server-centric scenarios, while keeping a small memory overhead of ≈ 8%. Second, in server-centric communication, the delivery rate degrades when resource update intervals drop below 100 ms.
Leandro Lanzieri, Peter Kietzmann, Thomas C. Schmidt, Matthias Wählisch
IPSN4
2022 Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope
Raphael Hiesgen, Marcin Nawrocki, Alistair King, Alberto Dainotti, Thomas C. Schmidt, Matthias Wählisch
USENIX Security Symposium6
2022 WIP: Exploring DSME MAC for LoRa - A System Integration and First Evaluation
abstract
LoRa is a popular wireless technology that enables low-throughput (bytes) long-range communication (km) at low energy consumption (mW). Its transmission, though, is on one side prone to interference during long on-air times, and on the other side subject to duty cycle restrictions. LoRaWAN defines a MAC and a vertical stack on top of LoRa. LoRaWAN circumvents the above limitations by imposing a centralized network architecture, which heavily reduces downlink capacity and prevents peer-to-peer communication. This makes it unusable for many deployments. The Deterministic and Synchronous Multichannel Extension (DSME) of IEEE 802.15.4e benefits of time-slotted communication and peer-to-peer communication and has the potential to overcome LoRaWAN limitations. In this work, we implement DSME on top of LoRa in the open source IoT OS RIOT and open the field for first evaluation experiments on real hardware. Initial results indicate that DSME-LoRa not only enables reliable peer-to-peer communication for constrained IoT devices, but also scales with an increasing number of nodes.
José Álamos, Peter Kietzmann, Thomas C. Schmidt, Matthias Wählisch
WoWMoM4
2022 A mobility-compliant publish-subscribe system for an information-centric Internet of Things
Cenk Gündogan, Peter Kietzmann, Thomas C. Schmidt, Matthias Wählisch
Comput. Networks4
2022 Content Object Security in the Internet of Things: Challenges, Prospects, and Emerging Solutions
abstract
Content objects are confined data elements that carry meaningful information. Massive amounts of content objects are published and exchanged every day on the Internet. The emerging Internet of Things (IoT) augments the network edge with reading sensors and controlling actuators that comprise machine-to-machine communication using small data objects. IoT content objects are often messages that fit into single IPv6 datagram. These IoT messages frequently traverse protocol translators at gateways, which break end-to-end transport and security of Internet protocols. To preserve content security from end to end via gateways and proxies, the IETF recently developed Object Security for Constrained RESTful Environments (OSCORE), which extends the Constrained Application Protocol (CoAP) with content object security features commonly known from Information Centric Networking (ICN). This paper revisits the current IoT protocol architectures and presents a comparative analysis of protocol stacks that protect request-response transactions. We discuss features and limitations of the different protocols and analyze emerging functional extensions. We measure the protocol performances of CoAP over Datagram Transport Layer Security (DTLS), OSCORE, and the information-centric Named Data Networking (NDN) protocol on a large-scale IoT testbed in single- and multi-hop scenarios. Our findings indicate that (a) OSCORE improves on CoAP over DTLS in error-prone wireless regimes due to omitting the overhead of maintaining security sessions at endpoints, (b) NDN attains superior robustness and reliability due to its intrinsic network caches and hop-wise retransmissions, and (c) OSCORE/CoAP offers room for improvement and optimization in multiple directions.
Cenk Gündogan, Christian Amsüss, Thomas C. Schmidt, Matthias Wählisch
IEEE Trans. Netw. Serv. Manag.4
2022 From the Beginning: Key Transitions in the First 15 Years of DNSSEC
abstract
When the global rollout of the DNS Security Extensions (DNSSEC) began in 2005, a first-of-its-kind trial started: The complexity of a core Internet protocol was magnified in favor of better security for the overall Internet. Thereby, the scale of the loosely-federated delegation in DNS became an unprecedented cryptographic key management challenge. Though fundamental for current and future operational success, our community lacks a clear notion of how to empirically evaluate the process of securely transitioning keys. In this paper, we propose two building blocks to formally characterize and assess key transitions. First, the anatomy of key transitions, i.e., measurable and well-defined properties of key changes; and second, a novel classification model based on this anatomy for describing key transition practices in abstract terms. This abstraction allows for classifying operational behavior. We apply our proposed transition anatomy and transition classes to describe the global DNSSEC deployment. Specifically, we use measurements from the first 15 years of the DNSSEC rollout to detect and understand which key transitions have been used to what degree and which rates of errors and warnings occurred. In contrast to prior work, we consider all possible transitions and not only 1:1 key rollovers. Our results show measurable gaps between prescribed key management processes and key transitions in the wild. We also find evidence that such noncompliant transitions are needed in operations.
Eric Osterweil, Pouyan Fotouhi Tehrani, Thomas C. Schmidt, Matthias Wählisch
IEEE Trans. Netw. Serv. Manag.4
2022 DSME-LoRa: Seamless Long-range Communication between Arbitrary Nodes in the Constrained IoT
abstract
Long range radio communication is preferred in many IoT deployments as it avoids the complexity of multi-hop wireless networks. LoRa is a popular, energy-efficient wireless modulation but its networking substrate LoRaWAN introduces severe limitations to its users. In this paper, we present and thoroughly analyze DSME-LoRa, a system design of LoRa with IEEE 802.15.4 DSME as a MAC layer. DSME-LoRa offers the advantage of seamless client-to-client communication beyond the pure gateway-centric transmission of LoRaWAN. We evaluate its feasibility via a full-stack implementation on the popular RIOT operating system, assess its steady-state packet flows in an analytical stochastic Markov model, and quantify its scalability in massive communication scenarios using large scale network simulations. Our findings indicate that DSME-LoRa is indeed a powerful approach that opens LoRa to standard network layers and outperforms LoRaWAN in many dimensions.
José Álamos, Peter Kietzmann, Thomas C. Schmidt, Matthias Wählisch
ACM Trans. Sens. Networks4
2021 Transparent forwarders: an unnoticed component of the open DNS infrastructure
abstract
In this paper, we revisit the open DNS (ODNS) infrastructure and, for the first time, systematically measure and analyze transparent forwarders, DNS components that transparently relay between stub resolvers and recursive resolvers. Our key findings include four takeaways. First, transparent forwarders contribute 26% (563k) to the current ODNS infrastructure. Unfortunately, common periodic scanning campaigns such as Shadowserver do not capture transparent forwarders and thus underestimate the current threat potential of the ODNS. Second, we find an increased deployment of transparent forwarders in Asia and South America. In India alone, the ODNS consists of 80% transparent forwarders. Third, many transparent forwarders relay to a few selected public resolvers such as Google and Cloudflare, which confirms a consolidation trend of DNS stakeholders. Finally, we introduce DNSRoute++, a new traceroute approach to understand the network infrastructure connecting transparent forwarders and resolvers.
Marcin Nawrocki, Maynard Koch, Thomas C. Schmidt, Matthias Wählisch
CoNEXT4
2021 Mind the gap: multi-hop IPv6 over BLE in the IoT
abstract
Bluetooth Low Energy (BLE) is today's most popular low-power radio technology with compelling radio performance and battery-friendly characteristics, making it a promising deployment option for the Internet of Things (IoT). Little is known, however, about the performance and pitfalls when utilizing BLE as link layer in multi-hop IP over BLE scenarios, because of the lack of available software platforms and deployment experiences. In this work, we present both a fully open-source, configurable software platform and experiments to analyze multi-hop BLE network behavior. Our experiments, conducted in a larger testbed, reveal unexpected performance drawbacks. Even in scenarios with underutilized links, BLE connections break randomly. This results into large transmission delays on the network layer and thus hinders real-world deployments in the constrained IoT. As key reason for this behavior we identify the BLE connection interval. A deterministic interval leads to unpredictable link behavior and connection losses due to overlapping connection events. We propose randomizing connection intervals as mitigation strategy and demonstrate that this prevents connection losses and sporadic link degradation, improving the overall network behavior.
Hauke Petersen, Thomas C. Schmidt, Matthias Wählisch
CoNEXT3
2021 A Performance Study of Crypto-Hardware in the Low-end IoT
Peter Kietzmann, Lena Boeckmann, Leandro Lanzieri, Thomas C. Schmidt, Matthias Wählisch
EWSN5
2021 Poster: DSME-LoRa - A Flexible MAC for LoRa
abstract
LoRa is a popular technology that enables long-range wireless communication (kilometers) at low energy consumption. The transmission exhibits low throughput and underlies duty cycle restrictions. Long on-air times (up to seconds) and range are susceptible to interference. In parallel, common LoRa-devices are battery driven and should mainly sleep. LoRaWAN is the system that defines the LoRa PHY, MAC, and a complete vertical stack. To deal with the above limitations, LoRaWAN imposes rigorous constraints, namely, a centralized network architecture that organizes media access, and heavily reduced downlink capacity. This makes it unusable for many deployments, control systems in particular. In this work, we combine IEEE802.15.4 DSME and LoRa to facilitate node-to-node communication. We present a DSME-LoRa mapping scheme and contribute a simulation model for validating new LoRa use-cases. Our results show 100% packet delivery and predictable latencies irrespective of network size.
José Álamos, Peter Kietzmann, Thomas C. Schmidt, Matthias Wählisch
ICNP4
2021 QUICsand: quantifying QUIC reconnaissance scans and DoS flooding events
abstract
In this paper, we present first measurements of Internet background radiation originating from the emerging transport protocol QUIC. Our analysis is based on the UCSD network telescope, correlated with active measurements. We find that research projects dominate the QUIC scanning ecosystem but also discover traffic from non-benign sources. We argue that although QUIC has been carefully designed to restrict reflective amplification attacks, the QUIC handshake is prone to resource exhaustion attacks, similar to TCP SYN floods. We confirm this conjecture by showing how this attack vector is already exploited in multi-vector attacks: On average, the Internet is exposed to four QUIC floods per hour and half of these attacks occur concurrently with other common attack types such as TCP/ICMP floods.
Marcin Nawrocki, Raphael Hiesgen, Thomas C. Schmidt, Matthias Wählisch
Internet Measurement Conference4
2021 The far side of DNS amplification: tracing the DDoS attack ecosystem from the internet core
abstract
In this paper, we shed new light on the DNS amplification ecosystem, by studying complementary data sources, bolstered by orthogonal methodologies. First, we introduce a passive attack detection method for the Internet core, i.e., at Internet eXchange Points (IXPs). Surprisingly, IXPs and honeypots observe mostly disjoint sets of attacks: 96% of IXP-inferred attacks were invisible to a sizable honeypot platform. Second, we assess the effectiveness of observed DNS attacks by studying IXP traces jointly with diverse data from independent measurement infrastructures. We find that attackers efficiently detect new reflectors and purposefully rotate between them. At the same time, we reveal that attackers are a small step away from bringing about significantly higher amplification factors (14×). Third, we identify and fingerprint a major attack entity by studying patterns in attack traces. We show that this entity dominates the DNS amplification ecosystem by carrying out 59% of the attacks, and provide an in-depth analysis of its behavior over time. Finally, our results reveal that operators of various .gov names do not adhere to DNSSEC key rollover best practices, which exacerbates amplification potential. We can verifiably connect this operational behavior to misuses and attacker decision-making.
Marcin Nawrocki, Mattijs Jonker, Thomas C. Schmidt, Matthias Wählisch
Internet Measurement Conference4
2021 Group Communication with OSCORE: RESTful Multiparty Access to a Data-Centric Web of Things
abstract
Content replication to many destinations is common in the IoT. IP multicast has proven inefficient due to a missing layer-2 support by IoT radios and its synchronous end-to-end transmission, which is susceptible to interference. Information-centric networking (ICN) introduced hop-wise multiparty dissemination of cacheable content, which proves valuable for lossy networks. Even Named-Data Networking (NDN), a prominent ICN, suffers from a lack of deployment.We explore a multiparty content distribution in an information-centric Web of Things built on CoAP. We augment CoAP proxies by request aggregation and response replication, which together with caches enable asynchronous group communication. Further, we integrate object security with OSCORE into the CoAP multicast proxy system for ubiquitous caching of certified content. We compare NDN, CoAP, and our data-centric approach in testbed experiments. Our findings indicate that multiparty content distribution with CoAP proxies performs equally well as NDN, while remaining compatible with the protocol world of CoAP.
Cenk Gündogan, Christian Amsüss, Thomas C. Schmidt, Matthias Wählisch
LCN4
2021 Security of Alerting Authorities in the WWW: Measuring Namespaces, DNSSEC, and Web PKI
abstract
During disasters, crisis, and emergencies the public relies on online services provided by official authorities to receive timely alerts, trustworthy information, and access to relief programs. It is therefore crucial for the authorities to reduce risks when accessing their online services. This includes catering to secure identification of service, secure resolution of name to network service, and content security and privacy as a minimum base for trustworthy communication.
Pouyan Fotouhi Tehrani, Eric Osterweil, Jochen H. Schiller, Thomas C. Schmidt, Matthias Wählisch
WWW5
2021 Sense Your Power: The ECO Approach to Energy Awareness for IoT Devices
abstract
Energy-constrained sensor nodes can adaptively optimize their energy consumption if a continuous measurement is provided. This is of particular importance in scenarios of high dynamics such as with energy harvesting. Still, self-measuring of power consumption at reasonable cost and complexity is unavailable as a generic system service. In this article, we present ECO, a hardware-software co-design that adds autonomous energy management capabilities to a large class of low-end IoT devices. ECO consists of a highly portable hardware shield built from inexpensive commodity components and software integrated into the RIOT operating system. RIOT supports more than 200 popular microcontrollers. Leveraging this flexibility, we assembled a variety of sensor nodes to evaluate key performance properties for different device classes. An overview and comparison with related work shows how ECO fills the gap of in situ power attribution transparently for consumers and how it improves over existing solutions. We also report about two different real-world field trials, which validate our solution for long-term production use.
Michel Rottleuthner, Thomas C. Schmidt, Matthias Wählisch
ACM Trans. Embed. Comput. Syst.3
2021 PHiLIP on the HiL: Automated Multi-Platform OS Testing With External Reference Devices
abstract
Developing an operating systems (OSs) for low-end embedded devices requires continuous adaptation to new hardware architectures and components, while serviceability of features needs to be assured for each individual platform under tight resource constraints. It is challenging to design a versatile and accurate heterogeneous test environment that is agile enough to cover a continuous evolution of the code base and platforms. This mission is even more challenging when organized in an agile open-source community process with many contributors such as for the RIOT OS. Hardware in the Loop (HiL) testing and Continuous Integration (CI) are automatable approaches to verify functionality, prevent regressions, and improve the overall quality at development speed in large community projects. In this paper, we present PHiLIP (Primitive Hardware in the Loop Integration Product), an open-source external reference device together with tools that validate the system software while it controls hardware and interprets physical signals. Instead of focusing on a specific test setting, PHiLIP takes the approach of a tool-assisted agile HiL test process, designed for continuous evolution and deployment cycles. We explain its design, describe how it supports HiL tests, evaluate performance metrics, and report on practical experiences of employing PHiLIP in an automated CI test infrastructure. Our initial deployment comprises 22 unique platforms, each of which executes 98 peripheral tests every night. PHiLIP allows for easy extension of low-cost, adaptive testing infrastructures but serves testing techniques and tools to a much wider range of applications.
Kevin Weiss, Michel Rottleuthner, Thomas C. Schmidt, Matthias Wählisch
ACM Trans. Embed. Comput. Syst.4
2021 The Impact of Networking Protocols on Massive M2M Communication in the Industrial IoT
abstract
Common use cases in the Industrial Internet of Things (IIoT) deploy massive amounts of sensors and actuators that communicate with each other or to a remote cloud. While they form too large and too volatile networks to run on ultra-reliable, time-synchronized low-latency channels, participants still require reliability and latency guaranties. We elaborate this for safety-critical use cases. This paper focuses on the effects of networking protocols for industrial communication services. It analyzes and compares the traditional Message Queuing Telemetry Transport for Sensor Networks (MQTT-SN) with the Constrained Application Protocol (CoAP) as a current IETF recommendation, and also with emerging Information-centric Networking (ICN) approaches, which are ready for deployment. Our findings indicate a rather diverse picture with a large dependence on deployment: Publish-subscribe protocols are more versatile, whereas ICN protocols are more robust in multi-hop environments. MQTT-SN competitively claims resources on congested links, while CoAP politely coexists on the price of its performance.
Cenk Gündogan, Peter Kietzmann, Martine Lenders, Hauke Petersen, Michael Frey, Thomas C. Schmidt, Felix Juraschek, Matthias Wählisch
IEEE Trans. Netw. Serv. Manag.8
2020 BGP Beacons, Network Tomography, and Bayesian Computation to Locate Route Flap Damping
abstract
Pinpointing autonomous systems which deploy specific inter-domain techniques such as Route Flap Damping (RFD) or Route Origin Validation (ROV) remains a challenge today. Previous approaches to detect per-AS behavior often relied on heuristics derived from passive and active measurements. Those heuristics, however, often lacked accuracy or imposed tight restrictions on the measurement methods.
Caitlin Gray, Clemens Mosig, Randy Bush, Cristel Pelsser, Matthew Roughan, Thomas C. Schmidt, Matthias Wählisch
Internet Measurement Conference7
2020 On Measuring RPKI Relying Parties
abstract
In this paper, we introduce a framework to observe RPKI relying parties (i.e., those that fetch RPKI data from the distributed repository) and present insights into this ecosystem for the first time. Our longitudinal study of data gathered from three RPKI certification authorities (AFRINIC, APNIC, and our own CA) identifies different deployment models of relying parties and (surprisingly) prevalent inconsistent fetching behavior that affects Internet routing robustness. Our results reveal nearly 90% of relying parties are unable to connect to delegated publication points under certain conditions, which leads to erroneous invalidation of IP prefixes and likely widespread loss of network reachability.
John Kristoff, Randy Bush, Chris Kanich, George Michaelson, Amreesh Phokeer, Thomas C. Schmidt, Matthias Wählisch
Internet Measurement Conference7
2020 IoT Content Object Security with OSCORE and NDN: A First Experimental Comparison
Cenk Gündogan, Christian Amsüss, Thomas C. Schmidt, Matthias Wählisch
Networking4
2020 Uncovering Vulnerable Industrial Control Systems from the Internet Core
abstract
Industrial control systems (ICS) are managed remotely with the help of dedicated protocols that were originally designed to work in walled gardens. Many of these protocols have been adapted to Internet transport and support wide-area communication. ICS now exchange insecure traffic on an inter-domain level, putting at risk not only common critical infrastructure, but also the Internet ecosystem (e.g., DRDoS attacks).In this paper, we uncover unprotected inter-domain ICS traffic at two central Internet vantage points, an IXP and an ISP. This traffic analysis is correlated with data from honeypots and Internet-wide scans to separate industrial from non-industrial ICS traffic. We provide an in-depth view on Internet-wide ICS communication. Our results can be used (i) to create precise filters for potentially harmful non-industrial ICS traffic, and (ii) to detect ICS sending unprotected inter-domain ICS traffic, being vulnerable to eavesdropping and traffic manipulation attacks.
Marcin Nawrocki, Thomas C. Schmidt, Matthias Wählisch
NOMS3
2020 Designing a LoWPAN convergence layer for the Information Centric Internet of Things
Cenk Gündogan, Peter Kietzmann, Thomas C. Schmidt, Matthias Wählisch
Comput. Commun.4
2020 On the impact of QoS management in an Information-centric Internet of Things
Cenk Gündogan, Jakob Pfender, Peter Kietzmann, Thomas C. Schmidt, Matthias Wählisch
Comput. Commun.5
2019 Down the Black Hole: Dismantling Operational Practices of BGP Blackholing at IXPs
abstract
Large Distributed Denial-of-Service (DDoS) attacks pose a major threat not only to end systems but also to the Internet infrastructure as a whole. Remote Triggered Black Hole filtering (RTBH) has been established as a tool to mitigate inter-domain DDoS attacks by discarding unwanted traffic early in the network, e.g., at Internet eXchange Points (IXPs). As of today, little is known about the kind and effectiveness of its use, and about the need for more fine-grained filtering.
Marcin Nawrocki, Jeremias Blendin, Christoph Dietzel, Thomas C. Schmidt, Matthias Wählisch
Internet Measurement Conference5
2019 A Lesson in Scaling 6LoWPAN - Minimal Fragment Forwarding in Lossy Networks
abstract
This paper evaluates two forwarding strategies for fragmented datagrams in the IoT: hop-wise reassembly and a minimal approach to direct forwarding of fragments. Direct fragment forwarding is challenged by the lack of forwarding information at subsequent fragments in 6LoWPAN and thus requires additional data at nodes. We compare the two approaches in extensive experiments evaluating reliability, end-to-end latency, and memory consumption. In contrast to previous work and due to our real-world testbed setup, we obtained different results and conclusions. Our findings indicate that direct fragment forwarding should be deployed with care, since higher packet transmission rates on the link layer can significantly reduce its reliability, which in turn can even further reduce end-to-end latency because of highly increased link layer retransmissions.
Martine Lenders, Thomas C. Schmidt, Matthias Wählisch
LCN3
2019 ICNLoWPAN - Named-Data Networking for Low Power IoT Networks
abstract
Information Centric Networking is considered a promising communication technology for the constrained IoT, but NDN was designed only for standard network infrastructure. In this paper, we design and evaluate an NDN convergence layer for low power lossy links that (1) augments the NDN stateful forwarding with a highly efficient name eliding, (2) devises stateless compression schemes for standard NDN use cases, (3) adapts NDN packets to the small MTU size of IEEE 802.15.4, and (4) generates compatibility with 6LoWPAN so that IPv6 and NDN can coexist on the same LoWPAN links. Our findings indicate that stateful compression can reduce the size of NDN data packets by more than 70 % in realistic examples. Our experiments show that for common use cases ICNLoWPAN saves 33 % of transmission resources over NDN, and about 20 % over 6LoWPAN.
Cenk Gündogan, Peter Kietzmann, Thomas C. Schmidt, Matthias Wählisch
Networking4
2018 The Rise of Certificate Transparency and Its Implications on the Internet Ecosystem
Quirin Scheitle, Oliver Gasser, Theodor Nolte, Johanna Amann, Lexi Brent, Georg Carle, Ralph Holz, Thomas C. Schmidt, Matthias Wählisch
Internet Measurement Conference9
2018 HoPP: Robust and Resilient Publish-Subscribe for an Information-Centric Internet of Things
abstract
This paper revisits NDN deployment in the IoT with a special focus on the interaction of sensors and actuators. Such scenarios require high responsiveness and limited control state at the constrained nodes. We argue that the NDN request-response pattern which prevents data push is vital for IoT networks. We contribute HoP-and-Pull (HoPP), a robust publish-subscribe scheme for typical IoT scenarios that targets IoT networks consisting of hundreds of resource constrained devices at intermittent connectivity. Our approach limits the FIB tables to a minimum and naturally supports mobility, temporary network partitioning, data aggregation and near real-time reactivity. We experimentally evaluate the protocol in a real-world deployment using the IoT-Lab testbed with varying numbers of constrained devices, each interconnected via IEEE 802.15.4 wireless LoWPANs. Implementations are built on CCN-lite with RIOT and support experiments using various single-and multi-hop scenarios.
Cenk Gündogan, Peter Kietzmann, Thomas C. Schmidt, Matthias Wählisch
LCN4
2018 Seamless Producer Mobility for the Industrial Information-Centric Internet
abstract
No abstract available.
Cenk Gündogan, Peter Kietzmann, Thomas C. Schmidt, Martine Lenders, Hauke Petersen, Matthias Wählisch, Michael Frey, Felix Juraschek
MobiSys6
2018 A PUF Seed Generator for RIOT: Introducing Crypto-Fundamentals to the Wild
abstract
No abstract available.
Peter Kietzmann, Cenk Gündogan, Thomas C. Schmidt, Matthias Wählisch
MobiSys4
2018 RIOT: An Open Source Operating System for Low-End Embedded Devices in the IoT
abstract
As the Internet of Things (IoT) emerges, compact operating systems (OSs) are required on low-end devices to ease development and portability of IoT applications. RIOT is a prominent free and open source OS in this space. In this paper, we provide the first comprehensive overview of RIOT. We cover the key components of interest to potential developers and users: the kernel, hardware abstraction, and software modularity, both conceptually and in practice for various example configurations. We explain operational aspects like system boot-up, timers, power management, and the use of networking. Finally, the relevant APIs as exposed by the OS are discussed along with the larger ecosystem around RIOT, including development and open source community aspects.
Emmanuel Baccelli, Cenk Gündogan, Oliver Hahm, Peter Kietzmann, Martine Lenders, Hauke Petersen, Kaspar Schleiser, Thomas C. Schmidt, Matthias Wählisch
IEEE Internet Things J.9
2016 Demo: Topological Robustness of RPL with TRAIL
Martin Landsmann, Peter Kietzmann, Thomas C. Schmidt, Matthias Wählisch
EWSN4
2016 TRAIL: Topology Authentication in RPL
Heiner Perrey, Martin Landsmann, Osman Ugus, Matthias Wählisch, Thomas C. Schmidt
EWSN4
2016 Towards Better Internet Citizenship: Reducing the Footprint of Internet-wide Scans by Topology Aware Prefix Selection
Johannes Klick, Stephan Lau, Matthias Wählisch, Volker Roth 0002
Internet Measurement Conference3
2016 Special issue: Current and future architectures, protocols, and services for the Internet of Things
Matthias Wählisch, Damla Turgut, Tom Pfeifer, Anura P. Jayasumana
Comput. Commun.1
2015 RiPKI: The Tragic Story of RPKI Deployment in the Web Ecosystem
abstract
Web content delivery is one of the most important services on the Internet. Access to websites is typically secured via TLS. However, this security model does not account for prefix hijacking on the network layer, which may lead to traffic blackholing or transparent interception. Thus, to achieve comprehensive security and service availability, additional protective mechanisms are necessary such as the RPKI, a recently deployed Resource Public Key Infrastructure to prevent hijacking of traffic by networks. This paper argues two positions. First, that modern web hosting practices make route protection challenging due to the propensity to spread servers across many different networks, often with unpredictable client redirection strategies; and, second, that we need a better understanding why protection mechanisms are not deployed. To initiate this, we empirically explore the relationship between web hosting infrastructure and RPKI deployment. Perversely, we find that less popular websites are more likely to be secured than the prominent sites. Worryingly, we find many large-scale CDNs do not support RPKI, thus making their customers vulnerable. This leads us to explore business reasons why operators are hesitant to deploy RPKI, which may help to guide future research on improving Internet security.
Matthias Wählisch, Thomas C. Schmidt, Olaf Maennel, Steve Uhlig, Gareth Tyson
HotNets1
2015 RPKI MIRO: Monitoring and Inspection of RPKI Objects
abstract
The Resource Public Key Infrastructure (RPKI) stores attestation objects for Internet resources. In this demo, we present RPKI MIRO, an open source software framework to monitor and inspect these RPKI objects. RPKI MIRO provides resource owners, RPKI operators, researchers, and lecturers with intuitive access to the content of the deployed RPKI repositories. It helps to optimize the repository structure and to identify failures.
Andreas Reuter 0002, Matthias Wählisch, Thomas C. Schmidt
SIGCOMM2
2015 Federated End-to-End Authentication for the Constrained Internet of Things Using IBC and ECC
abstract
Authentication of smart objects is a major challenge for the Internet of Things (IoT), and has been left open in DTLS. Leveraging locally managed IPv6 addresses with identity-based cryptography (IBC), we propose an efficient end-to-end authentication that (a) assigns a robust and deployment-friendly federation scheme to gateways of IoT subnetworks, and (b) has been evaluated with a modern twisted Edwards elliptic curve cryptography (ECC). Our early results demonstrate feasibility and promise efficiency after ongoing optimizations.
Tobias Markmann, Thomas C. Schmidt, Matthias Wählisch
SIGCOMM3
2015 See How ISPs Care: An RPKI Validation Extension for Web Browsers
abstract
The Resource Public Key Infrastructure (RPKI) allows BGP routers to verify the origin AS of an IP prefix. In this demo, we present a software extension which performs prefix origin validation in the web browser of end users. The browser extension shows the RPKI validation outcome of the web server infrastructure for the requested web domain. It follows the common plug-in concepts and does not require special modifications of the browser software. It operates on live data and helps end users as well as operators to gain better insight into the Internet security landscape.
Matthias Wählisch, Thomas C. Schmidt
SIGCOMM1
2014 Demonstration abstract: simply RIOT: teaching and experimental research in the internet of things
Oliver Hahm, Emmanuel Baccelli, Hauke Petersen, Matthias Wählisch, Thomas C. Schmidt
IPSN4
2014 How dia-shows turn into video flows: Adapting scalable video communication to heterogeneous network conditions in real-time
abstract
Video conferencing over IP (VCoIP) is a major trend in current Internet communication and has particularly spread to the mobile realm. In this environment, users face the problem of heterogeneous and fluctuating network conditions. A promising solution to this issue is the scalable video coding (SVC). It allows an adaptation of the video stream to the available bandwidth, but requires a reliable bandwidth estimation. Adaptation times for conversational video at fluctuating network conditions are critical, and a fast strategy for bandwidth estimation is needed to avoid congestion. In this work, we analyse the capabilities of the sender and the receiver to adapt the video coding to changing network conditions. We derive an early congestion indicator at the sender side based on the jitter variation. For receivers, we use sustained goodput to extract a feasible scaling. In thorough evaluations that include real-world 3G networks, we reveal a faster congestion detection at the sender that are also more robust but less accurate than probing at the receiver.
Fabian Jager, Thomas C. Schmidt, Matthias Wählisch
LCN3
2014 Native actors: how to scale network forensics
abstract
When an organization detects a security breach, it undertakes a forensic analysis to figure out what happened. This investigation involves inspecting a wide range of heterogeneous data sources spanning over a long period of time. The iterative nature of the analysis procedure requires an interactive experience with the data. However, the distributed processing paradigms we find in practice today fail to provide this requirement: the batch-oriented nature of MapReduce cannot deliver sub-second round-trip times, and distributed in-memory processing cannot store the terabytes of activity logs needed to inspect during an incident.
Matthias Vallentin, Dominik Charousset, Thomas C. Schmidt, Vern Paxson, Matthias Wählisch
SIGCOMM5
2013 Updates from the Internet Backbone: An RPKI/RTR Router Implementation, Measurements, and Analysis
Matthias Wählisch, Fabian Holler, Thomas C. Schmidt, Jochen H. Schiller
NDSS1
2013 Lessons from the past: Why data-driven states harm future information-centric networking
Matthias Wählisch, Thomas C. Schmidt, Markus Vahlenkamp
Networking1
2013 Backscatter from the data plane - Threats to stability and security in information-centric network infrastructure
Matthias Wählisch, Thomas C. Schmidt, Markus Vahlenkamp
Comput. Networks1
2013 On name-based group communication: Challenges, concepts, and transparent deployment
Thomas C. Schmidt, Matthias Wählisch, Dominik Charousset, Sebastian Meiling
Comput. Commun.2
2012 RAID the WSN: Packet-based reliable cooperative diversity
abstract
This paper introduces a light-weight packet delivery approach called Packet-based Cooperative Diversity to improve the reliability of Wireless Sensor Networks (WSNs). Our approach is based on the principle of cooperative diversity and fail-over concepts of Redundant Array of Independent Disks (RAID), by grouping, gathering, and rejecting redundant packets with the unique packet ID per message. It is suitable for nodes which require high reliability in message delivery but have enhanced energy capability. Our approach imitates two RAID levels to investigate their effect in reliability by redundancy. Based on an analytical model and ns-2 simulations, we compare the performance of our packet-based diversity schemes with direct transmission. Our schemes improve the reliability significantly in terms of the Improved Message Reconstruction Ratio per Redundancy (MRR/R) about 25% in the analytical model and 15% in simulation. The results indicate that our approach is especially effective in situations with strong interferences.
Yuan Yang 0005, Matthias Wählisch, Yubin Zhao, Marcel Kyas
ICC2
2012 Large-scale measurement and analysis of one-way delay in hybrid multicast networks
abstract
Group communication plays an important role in the distribution of real-time data for IPTV, multimedia conferencing, or online multiplayer games, but IP multicast remains unsupported in today's global Internet. Hybrid solutions that bridge between overlay and underlay multicast are a promising escape from the deployment dilemma of multicast. In this paper, we examine the real-time capabilities of hybrid multicast in a globally distributed environment based on our adaptive architecture H8Mcast within the Planet-Lab testbed. We present a large-scale measurement study and analysis of one-way packet delay distributions in several realistic group scenarios. The unique results in global traces of hybrid multicast data have been achieved by carefully tracking packets and continuously correcting clock offsets. Companion measurements of unicast-based distribution are part of our analysis, as well as the comparative discussion of our results with previous findings from theory and simulation. Our measurements reveal that about 50% of global group members experience a real-time compliant service within the conversational time bounds of 150 ms.
Sebastian Meiling, Thomas C. Schmidt, Matthias Wählisch
LCN3
2012 Exposing a Nation-Centric View on the German Internet - A Change in Perspective on AS-Level
Matthias Wählisch, Thomas C. Schmidt, Markus de Brün, Thomas Häberlen
PAM1
2012 Towards detecting BGP route hijacking using the RPKI
abstract
Prefix hijacking has always been a big concern in the Internet. Some events made it into the international world-news, but most of them remain unreported or even unnoticed. The scale of the problem can only be estimated.
Matthias Wählisch, Olaf Maennel, Thomas C. Schmidt
SIGCOMM1
2012 Bulk of interest: performance measurement of content-centric routing
abstract
The paradigm of information-centric networking subsumes recent approaches to integrate content replication services into a future Internet layer. Current concepts foster either a dynamic mapping that directs content requests to a nearby copy, or an immediate routing on content identifiers. In this paper, we evaluate in practical experiments the performance of content routing, which we analyze with a focus on conceptual aspects. Our findings indicate that the performance of the content distribution system is threatened by a heavy management of states that arise from the strong coupling of the control to the data plane in the underlying routing infrastructure.
Matthias Wählisch, Thomas C. Schmidt, Markus Vahlenkamp
SIGCOMM1
2012 First insights from a mobile honeypot
abstract
Computer systems are commonly attacked by malicious transport contacts. We present a comparative study that analyzes to what extent those attacks depend on the network access, in particular if an adversary targets specifically on mobile or non-mobile devices. Based on a mobile honeypot that extracts first statistical results, our findings indicate that a few topological domains of the Internet have started to place particular focus on attacking mobile networks.
Matthias Wählisch, Sebastian Trapp, Christian Keil, Jochen Schönfelder, Thomas C. Schmidt, Jochen H. Schiller
SIGCOMM1
2012 Vitamin C for your smartphone: the SKIMS approach for cooperativeand lightweight security at mobiles
abstract
Smartphones are popular attack targets, but usually too weak in applying common protection concepts. SKIMS designs and implements a cooperative, cross-layer security system for mobile devices. Detection mechanisms as well as a proactive and reactive defense of attacks are core components of this project. In this demo, we show a comprehensive proof-of-concept of our approaches, which include entropy-based malware detection, a mobile honeypot, and spontaneous, socio-inspired trust establishment.
Matthias Wählisch, Sebastian Trapp, Jochen H. Schiller, Benjamin Jochheim, Theodor Nolte, Thomas C. Schmidt, Osman Ugus, Dirk Westhoff, Martin Kutscher, Matthias Küster, Christian Keil, Jochen Schönfelder
SIGCOMM1
2011 On predictable large-scale data delivery in prefix-based virtualized content networks
Matthias Wählisch, Thomas C. Schmidt, Georg Wittenburg
Comput. Networks1
2011 Distributed SIP conference management with autonomously authenticated sources and its application to an H.264 videoconferencing software for mobiles
Thomas C. Schmidt, Gabriel Hege, Matthias Wählisch, Hans L. Cycon, Mark Palkow, Detlev Marpe
Multim. Tools Appl.3
2010 Adaptive Temporal Scalability of H.264-Compliant Video Conferencing in Heterogeneous Mobile Environments
abstract
In this paper, we present a multipoint video conferencing system that adapts to heterogeneous members including mobiles. The system is built upon a low complexity scalable extension of our H.264 codec DAVC, and a congestion-aware dynamic adaptation layer. Our temporally scaled video codec DSVC has the same RD performance as the non-scaled version with comparable configuration. We achieve this by QP cascading, i.e., assigning gradually refining quantization parameters to the declining temporal layers. We present and analyse a mobile-compliant version of DSVC at reduced complexity that still admits comparable performance. Finally, we report on early work of dynamic layer tuning. Derived of delay variation measures, senders exploit scalable video layering to adapt the video transmission to varying network conditions. Initial results indicate that video performance remains close to optimal.
Hans L. Cycon, Valeri George, Gabriel Hege, Detlev Marpe, Mark Palkow, Thomas C. Schmidt, Matthias Wählisch
GLOBECOM7
2009 Broadcasting in Prefix Space: P2P Data Dissemination with Predictable Performance
abstract
A broadcast mode may augment peer-to-peer overlay networks with an efficient, scalable data replication function, but may also give rise to a virtual link layer in VPN-type solutions. We introduce a generic, simple broadcasting mechanism that operates in the prefix space of distributed hash tables without signaling. This paper concentrates on the performance analysis of the prefix flooding scheme. Starting from simple models of recursive $k$-ary trees, we analytically derive distributions of hop counts and the replication load. Further on, extensive simulation results are presented based on an implementation within the OverSim framework. Comparisons are drawn to Scribe, taken as a general reference model for group communication according to the shared, rendezvous-point-centered distribution paradigm. The prefix flooding scheme thereby confirmed its widely predictable performance and consistently outperformed Scribe in all metrics. Reverse path selection in overlays is identified as a major cause of performance degradation.
Matthias Wählisch, Thomas C. Schmidt, Georg Wittenburg
ICIW1
2009 A common API for hybrid group communication
abstract
Recent efforts are made to construct a globally accessible group communication service by a simultaneous use of network and application layer multicast. Such hybrid approaches provide native multicast to group members wherever available, but relocate data distribution and duplication from the network to applications or gateways if needed. Such services require an abstract programming interface to allow for a transparent use by applications. The contributions of this paper are twofold. First, we explore the problem space of designing a protocol stack for hybrid group communication that covers structured P2P networks. Second, we propose a transparent API that encapsulates a middleware abstraction layer for implementing hybrid multicast, and allows for overlay-underlay agnostic programming.
Matthias Wählisch, Thomas C. Schmidt, Georg Wittenburg
LCN1
2009 BIDIR-SAM: Large-scale content distribution in structured overlay networks
abstract
IPTV, software replication and other large-scale distribution tasks urge the need for efficient multicast mechanisms in overlay networks. Current multicast solutions on the application layer are either efficient, structured, but inflexible, or flexible, unstructured, but of lesser efficiency. This paper introduces scalable adaptive multicast on bi-directional shared trees, a new structured but flexible approach to content distribution. BIDIRSAM is the first DHT-based overlay multicast that distributes any source multicast data according to source-specific shortest path trees. Built upon bi-directional shared prefix trees, the approach distributes packets uniquely via fully redundant paths, and allows for highly flexible network adaptivity. Guided by an overlay abstraction, it operates directly on top of a prefix routing and does not rely on any kind of rendezvous point or bootstrapping.
Matthias Wählisch, Thomas C. Schmidt, Georg Wittenburg
LCN1
2008 AuthoCast: a protocol for mobile multicast sender authentication
abstract
Mobility is considered a key technology of the next generation Internet and has been standardized within the IETF. Rapidly emerging multimedia group applications such as IPTV, MMORPGs and video conferencing increase the demand for mobile group communication, but a standard design of mobile multicast is still awaited. The open problem poses significant operational and security challenges to the Internet infrastructure. This paper introduces a protocol framework for securing mobility handovers of multicast sources. Using an autonomously verifiable, one-way authentication based on cryptographically generated addresses, a common design is derived to jointly comply with the mobile any source and source specific multicast protocols that are currently proposed. This light-weight scheme smoothly extends the unicast enhanced route optimization for mobile IPv6 and adds only little overhead to multicast packets and protocol operations.
Thomas C. Schmidt, Matthias Wählisch, Olaf Christ
MoMM2
2008 Peer-to-peer videoconferencing with H.264 software codec for mobiles
abstract
A rapidly growing number of carriers offer wireless video services to their customers, taking advantage of high quality video codecs implemented in dedicated hardware of selected mobile devices. In this paper we introduce a video conferencing software, which seamlessly integrates mobile with stationary users in a provider and device independent fashion. Innovations of this work are twofold. At first we report on a mobile realization of an H.264 video codec and its performance on a standard consumer Smartphone. Operating within the tight bounds of real-time compliance on mobiles, this software is an adapted version of a highly optimized H.264 codec. This DAVC codec, which we introduce along the line, significantly out-performs compatible H.264 realizations and allows for a scalable adaptation of its frame rate. In the second part we present a barrier-resistant peer-to-peer group communication scheme, which scales well for medium-size conferences and accounts for the heterogeneous nature of mobile and stationary participants. An outlook on mobility related group communication issues and future optimizations based on structured communication layers concludes the work.
Hans L. Cycon, Thomas C. Schmidt, Gabriel Hege, Matthias Wählisch, Detlev Marpe, Mark Palkow
WOWMOM4
2008 AuthoCast - a mobility-compliant protocol framework for multicast sender authentication
abstract
Abstract Mobility is considered a key technology of the next generation Internet and has been standardized within the IETF. Rapidly emerging multimedia group applications such as IPTV, massive mutliplayer games (MMORPGs) and video conferencing increase the demand for mobile group communication, but a standard design of mobile multicast is still awaited. The open problem poses significant operational and security challenges to the Internet infrastructure. This paper introduces a protocol framework for authenticating multicast sources (MSs) and securing their mobility handovers. Its contribution is twofold: at first, the current mobile multicast problem and solution spaces are summarized from the security perspective. At second, a solution to the mobile source authentication problem is presented that complies to IPv6 mobility signaling standards. Using an autonomously verifiable one‐way authentication based on cryptographically generated addresses, a common design is derived to jointly comply with the mobile any source and source specific multicast (SSM) protocols that are currently proposed. This light‐weight scheme smoothly extends the unicast enhanced route optimization for mobile IPv6 and adds only little overhead to multicast packets and protocol operations. Copyright © 2008 John Wiley & Sons, Ltd.
Thomas C. Schmidt, Matthias Wählisch, Olaf Christ, Gabriel Hege
Secur. Commun. Networks2
2007 Exploring the routing complexity of mobile multicast: a semi-empirical study
abstract
Protocol extensions for a mobile Internet have been developed within the IETF, but a standard design of mobile multicast is still awaited. Multicast routing, when adapting its distribution trees to moving listeners or senders, needs to newly established forwarding states. In this paper we quantize the number of states minimally required for servicing listener or sender mobility. Independent of the actual routing protocol in use, these results serve as an inherent measure of complexity for multicast mobility management. Results are based on current Internet measurements and a topological analysis from network simulations. They show a surprisingly low mobility overhead as compared to general multicast forwarding state management.
Matthias Wählisch, Thomas C. Schmidt
CoNEXT1
2003 Global serverless videoconferencing over IP
Thomas C. Schmidt, Matthias Wählisch, Hans L. Cycon, Mark Palkow
Future Gener. Comput. Syst.2