VLDB 2026 Research / reviewers in the wild / expert
Georg Carle
dblp:c/GeorgCarle
· DBLP profile ↗
177ranked-venue papers
1as first author
73since 2021 · last 2026
0000-0002-2347-1839ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 93 · 1 first-author · 36 since 2021Security and privacy · 11 · 6 since 2021Software engineering, systems software and programming languages · 9 · 3 since 2021Systems, architecture and hardware · 5 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 since 2021Artificial intelligence and machine learning · 2Graphics, computer vision, multimedia, augmented reality and games · 2Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Packet Spraying with Bounded Latency for Asymmetric Industrial Networks
Mohamed Elattar, Zhe Lou, Georg Carle |
ICC | 3 |
| 2026 | Benchmarking Spatio-Temporal Graph Neural Networks for Airborne Network Performance Prediction
Ali Yilmaz Yildirim, Fabien Geyer, Georg Carle |
ICC | 3 |
| 2026 | Still on Target? An Evaluation of IPv6 Target Generation Algorithms
Lion Steger, Liming Kuang, Johannes Zirngibl, Georg Carle, Oliver Gasser |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2026 | Utilizing Hardware-Supported Containers for Low-Latency Networking
Florian Wiedner, Alexander Daichendt, Jonas Andre, Georg Carle |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2025 | A Priority-Based Scheduling Mechanism for Multidrop NetworksabstractSingle Pair Ethernet (SPE) is emerging as a key enabler of seamless end-to-end (E2E) Ethernet communication in domains such as robotics, automotive, and industrial automation. With the growing adoption of Ethernet in industrial environments, multidrop networks like 10BASE-T1S and 10BASE-T1M further extend the capabilities of SPE. However, the Physical Layer Collision Avoidance (PLCA) mechanism used in these networks, while ensuring collision-free and deterministic communication, suffers from substantial access latency and lacks support for traffic prioritization, limiting its suitability for time-sensitive applications. Moreover, PLCA faces scalability issues as its access latency increases with network size. To address these challenges, this paper proposes a priority-based scheduling mechanism that incorporates priority awareness into the network access process. This mechanism enables high-priority traffic to access the network with predictable low latency and consistent performance in large-scale networks. It also supports a configuration that emulates Strict Priority (SP) scheduling over a shared medium, without requiring complex switches. Performance evaluation shows that the proposed mechanism reduces access latency for the highest-priority traffic by at least 85.58% compared to standard PLCA. Mohamed Elattar, Dimitrios Minagias, Zhe Lou, Georg Carle |
GLOBECOM | 4 |
| 2025 | Towards a Larger Model via One-Shot Federated Learning on Heterogeneous Client ModelsabstractLarge models, renowned for superior performance, outperform smaller ones even without billion-parameter scales. While mobile network servers have ample computational resources to support larger models than client devices, privacy constraints prevent clients from directly sharing their raw data. Federated Learning (FL) enables decentralized clients to collaboratively train a shared model by exchanging model parameters instead of transmitting raw data. Yet, it requires a uniform model architecture and multiple communication rounds, which neglect resource heterogeneity, impose heavy computational demands on clients, and increase communication overhead. To address these challenges, we propose FedOL, to construct a larger and more comprehensive server model in one-shot settings (i.e., in a single communication round). Instead of model parameter sharing, FedOL employs knowledge distillation, where clients only exchange model prediction outputs on an unlabeled public dataset. This reduces communication overhead by transmitting compact predictions instead of full model weights and enables model customization by allowing heterogeneous model architectures. A key challenge in this setting is that client predictions may be biased due to skewed local data distributions, and the lack of ground-truth labels in the public dataset further complicates reliable learning. To mitigate these issues, FedOL introduces a specialized objective function that iteratively refines pseudo-labels and the server model, improving learning reliability. To complement this, FedOL incorporates a tailored pseudo-label generation and knowledge distillation strategy that effectively integrates diverse knowledge. Simulation results show that FedOL significantly outperforms existing baselines, offering a cost-effective solution for mobile networks where clients possess valuable private data but limited computational resources. Wenxuan Ye, Xueli An, Onur Ayan, Junfan Wang, Xueqiang Yan, Georg Carle |
GLOBECOM | 6 |
| 2025 | FedABC: Attention-Based Client Selection for Federated Learning with Long-Term ViewabstractNative AI support is a key objective in the evolution of 6G networks, with Federated Learning (FL) emerging as a promising paradigm. FL allows decentralized clients to collaboratively train an AI model without directly sharing their data, preserving privacy. Clients train local models on private data and share model updates, which a central server aggregates to refine the global model and redistribute it for the next iteration. However, client data heterogeneity slows convergence and reduces model accuracy, and frequent client participation imposes communication and computational burdens. To address these challenges, we propose FedABC, an innovative client selection algorithm designed to take a long-term view in managing data heterogeneity and optimizing client participation. Inspired by attention mechanisms, FedABC prioritizes informative clients by evaluating both model similarity and each model's unique contributions to the global model. Moreover, considering the evolving demands of the global model, we formulate an optimization problem to guide FedABC throughout the training process. Following the “later-is-better” principle, FedABC adaptively adjusts the client selection threshold, encouraging greater participation in later training stages. Extensive simulations on CIFAR-10 demonstrate that FedABC significantly outperforms existing approaches in model accuracy and client participation efficiency, achieving comparable performance with 32% fewer clients than the classical FL algorithm FedAvg, and 3.5% higher accuracy with 2% fewer clients than the state-of-the-art. This work marks a step toward deploying FL in heterogeneous, resource-constrained environments, thereby supporting native AI capabilities in 6G networks. Wenxuan Ye, Xueli An, Junfan Wang, Xueqiang Yan, Georg Carle |
ICC | 5 |
| 2025 | Lazy Eye Inspection: Capturing the State of Happy Eyeballs ImplementationsabstractWhile transitioning to an IPv6-only communication, many devices settled on a dual-stack setup. IPv4 and IPv6 are available to these hosts for new connections. Happy Eyeballs (HE) describes a mechanism to prefer IPv6 for such hosts while ensuring a fast fallback to IPv4 when IPv6 fails. The IETF is currently working on the third version of HE. While the standards include recommendations for HE parameter choices, it is up to the client and OS to implement HE. In this paper, we investigate the state of HE in various clients, particularly web browsers and recursive resolvers. We introduce a framework to analyze and measure clients' HE implementations and parameter choices. According to our evaluation, only Safari supports all HE features. Safari is also the only client implementation in our study that uses a dynamic IPv4 connection attempt delay, a resolution delay, and interlaces addresses. We further show that problems with the DNS A record lookup can even delay and interrupt the network connectivity despite a fully functional IPv6 setup with Chrome and Firefox. We operate a publicly available website ( www.happy-eyeballs.net ) which measures the browser's HE behavior, and we publish our testbed measurement framework. Patrick Sattler, Matthias Kirstein, Lars Wüstrich, Johannes Zirngibl, Georg Carle |
IMC | 5 |
| 2025 | Evaluation of Graph Neural Networks in Airborne NetworksabstractPerformance modeling is crucial for managing wireless communication systems, offering insights into complex networks and enabling optimization. In recent years, Machine Learning algorithms have become indispensable for modeling both static and vehicular networks. Among these, Graph Neural Networks have gained prominence due to their flexibility and ability to capture intricate network structures. While Graph Neural Networks have been successfully applied to predict Key Performance Indicators such as delay in multi-hop networks, their effectiveness in Airborne Networks remains underexplored. In this study, we investigate the applicability of Graph Neural Network algorithms, originally developed for static networks, in modeling the performance of Airborne Networks. Our findings reveal that performance of Graph Neural Network in Airborne Networks falls short of their effectiveness in static environments. To address this, we introduce adaptations through enhanced input features, improving their generalization to high network velocity levels and increasing overall performance. Ali Yilmaz Yildirim, Fabien Geyer, Georg Carle |
LANMAN | 3 |
| 2025 | A Lightweight Asynchronous Scheduling Solution for Large-scale Deterministic NetworksabstractDeterministic scheduling is critical for real-time industrial applications requiring predictable, low-latency communication. Existing mechanisms, primarily designed for time-triggered and periodic traffic, struggle to manage bursty traffic effectively and violate latency bounds for low-priority classes within periodic traffic. This paper identifies a latency violation issue in Multiple Cyclic Queuing and Forwarding (Multi-CQF) and Paternoster caused by misaligned cycles across traffic classes. To address this, we propose two solutions: Hybrid Scheduling with Strict Priority and Packet Urgentness (HSSU) and Latency- and Jitter-Bounded Deficit Round Robin (LJB-DRR). HSSU enhances Multi-CQF and Paternoster by introducing class urgentness on top of Strict Priority (SP), resolving latency violations and enabling flexible cycle time configurations. LJB-DRR achieves equivalent latency bounds with a simplified queuing structure. It ensures bounded latency for periodic and bursty traffic through a two-dimensional scheduling mechanism. Evaluation shows that LJB-DRR reduces bursty traffic end-to-end latency by at least 65.82% and significantly lowers packet loss. Mohamed Elattar, Georg Carle |
LCN | 3 |
| 2025 | TEE Time at P4-Performance Analysis of Trusted Execution Environments for Packet ProcessingabstractModern computer networks, such as 5G/6G networks, require high-performance, low-latency, and secure packet processing while ensuring data confidentiality in cloud environments. Trusted Execution Environments (TEEs) address these security requirements and provide encrypted memory areas that protect sensitive data from untrusted cloud providers. This paper presents a performance analysis of TEE technologies, specifically Intel SGX and AMD SEV-SNP, in the context of software-based user-space packet processing with DPDK and the P4 language. We evaluate two architectural approaches: (1) integrating TEEs as external processing modules implemented with SGX and (2) executing the entire P4 pipeline inside a TEE using AMDSEV. Our analysis examines computational and I/O overhead across different CPU architectures. The results show the tradeoffs between TEE designs, implementations, and performance, demonstrating that AMD SEV-SNP offers better scalability with lower performance penalties compared to Intel SGX. Manuel Simon, Sebastian Warter, Sebastian Gallenmüller, Georg Carle |
NetSoft | 4 |
| 2025 | Forward Error Correction and Weighted Hierarchical Fair Multiplexing for HTTP/3 over QUIC
Kilian Holzinger, Daniel Petri, Stefan Lachnit, Marcel Kempf, Henning Stubbe, Sebastian Gallenmüller, Stephan M. Günther, Georg Carle |
Networking | 8 |
| 2025 | Seamless Roaming based on Distributed Multi-Link Operation over IEEE 802.11bnabstractOne goal of the upcoming Wi-Fi 8 standard is to enhance roaming performance. Previous roaming mechanisms, such as IEEE 802.11k/r/v, focus on single link deployments and cannot provide seamless roaming results for demanding use cases like industrial plants and train communication. We propose a seamless roaming mechanism leveraging multi-connectivity through enhanced Multi-Link Operation (MLO) for Wi-Fi 8 networks, allowing a station (STA) to associate to multiple Access Points (AP) simultaneously. Extensive simulations show a reduction in the roaming duration to $247 \mu \mathrm{~s}$, which is almost 15 times less compared to State-of-the-Art single link mechanisms. Additionally, the proposed MLO-based mechanism achieves zero consecutive packet loss and an overall packet loss rate (PLR) below $10^{-} 5$, typical requirements for critical communication in industrial production plants. Ben Mecklenburg, Ahmed Hasan Ansari, Björn Richerzhagen, Michael Bahr, Georg Carle |
WFCS | 5 |
| 2025 | A methodology for reproducible and portable experiment workflows
Henning Stubbe, Sebastian Gallenmüller, Georg Carle |
Comput. Commun. | 3 |
| 2025 | SoK: Truncation Untangled: Scaling Fixed-Point Arithmetic for Privacy-Preserving Machine Learning to Large Models and DatasetsabstractFixed Point Arithmetic (FPA) is widely used in Privacy-Preserving Machine Learning (PPML) to efficiently handle decimal values. However, repeated multiplications in FPA can lead to overflow, as the fractional part doubles in size with each multiplication. To address this, truncation is applied post-multiplication to maintain precision. Various truncation schemes based on Secure Multiparty Computation (MPC) exist, but trade-offs between accuracy and efficiency in PPML models and datasets remain underexplored. In this work, we analyze and consolidate different truncation approaches from the MPC literature. We conduct the first large-scale systematic evaluation of PPML inference accuracy across truncation schemes, ring sizes, neural network architectures, and datasets. Our study provides clear guidelines for selecting the optimal truncation scheme and parameters for PPML inference. All evaluations are implemented in the open-source HPMPC MPC framework, facilitating future research and adoption. Beyond our large scale evaluation, we also present improved constructions for each truncation scheme, achieving up to a fourfold reduction in communication and round complexity over existing schemes. Additionally, we introduce optimizations tailored for PPML, such as strategically fusing different neural network layers. This leads to a mixed-truncation scheme that balances truncation costs with accuracy, eliminating communication overhead in the online phase while matching the accuracy of plaintext floating-point PyTorch inference for VGG-16 on the ImageNet dataset. Christopher Harth-Kitzerow, Ajith Suresh, Georg Carle |
Proc. Priv. Enhancing Technol. | 3 |
| 2025 | High-Throughput Secure Multiparty Computation with an Honest Majority in Various Network SettingsabstractIn this work, we present novel protocols over rings for semi-honest secure three-party computation (3PC) and malicious four-party computation (4PC) with one corruption. While most existing works focus on improving total communication complexity, challenges such as network heterogeneity and computational complexity, which impact MPC performance in practice, remain underexplored. Our protocols address these issues by tolerating multiple arbitrarily weak network links between parties without any substantial decrease in performance. Additionally, they significantly reduce computational complexity by requiring up to half the number of basic instructions per gate compared to related work. These improvements lead to up to twice the throughput of state-of-the-art protocols in homogeneous network settings and up to eight times higher throughput in real-world heterogeneous settings. These advantages come at no additional cost: Our protocols maintain the best-known total communication complexity per multiplication, requiring 3 elements for 3PC and 5 elements for 4PC.We implemented our protocols alongside several state-of-the-art protocols (Replicated 3PC, ASTRA, Fantastic Four, Tetrad) in a novel open-source C++ framework optimized for high throughput. Five out of six implemented 3PC and 4PC protocols achieve more than one billion 32-bit multiplications or over 32 billion AND gates per second using our implementation in a 25 Gbit/s LAN environment. This represents the highest throughput achieved in 3PC and 4PC so far, outperforming existing frameworks like MP-SPDZ, ABY3, MPyC, and MOTION by two to three orders of magnitude. Christopher Harth-Kitzerow, Ajith Suresh, Yongqin Wang, Hossein Yalame, Georg Carle, Murali Annavaram |
Proc. Priv. Enhancing Technol. | 5 |
| 2025 | PIGEON: A High Throughput Framework for Private Inference of Neural Networks using Secure Multiparty ComputationabstractPrivacy-Preserving Machine Learning (PPML) is one of the most relevant use cases for Secure Multiparty Computation (MPC). While private training of large neural networks such as VGG-16 or ResNet-50 on state-of-the-art datasets such as ImageNet is still out of reach, given the performance overhead of MPC, GPU-based MPC frameworks are starting to achieve practical runtimes for private inference. However, we show that, unlike plaintext machine learning, using GPU acceleration for both linear (e.g., convolutions) and non-linear neural network layers (e.g., ReLU) is actually counterproductive in PPML. While GPUs effectively accelerate linear layers compared to CPU-based MPC implementations, the MPC circuits required to evaluate non-linear layers introduce memory overhead and frequent data movement between the GPU and the CPU to handle network communication. This results in slow ReLU performance and high GPU memory requirements in state-of-the-art GPU-based PPML frameworks, hindering them from scaling to multiple images per second inference throughput and more than eight images per batch on ImageNet. To overcome these limitations, we propose PIGEON, an open-source framework for Private Inference of Neural Networks. PIGEON employs a novel ABG programming model that switches between Arithmetic Vectorization and Bitslicing on the CPU for non-linear layers depending on the MPC-specific computation required while offloading linear layers to the GPU. Compared to the state-of-the-art PPML framework Piranha, PIGEON improves ReLU throughput by two orders of magnitude, reduces peak GPU memory utilization by one order of magnitude, and scales better with large batch sizes. This translates to one to two orders of magnitude improvements in throughput for large ImageNet batch sizes (e.g., 192) and more than 70% saturation of a 25 Gbit/s network. Christopher Harth-Kitzerow, Yongqin Wang, Rachit Rajat, Georg Carle, Murali Annavaram |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | Applicability of Hardware-Supported Containers in Low-Latency NetworkingabstractContainers share the kernel with the host OS, which has implications for the network stack. Achieving connectivity between containers exclusively in software is unsuitable for reliable, low-latency applications. While extensive research has been conducted on virtual machines processing real-time traffic with hardware support, the impact of network latencies in containerized environments has received comparatively less attention. This paper analyzes throughput and network latencies in container topologies on a single host featuring single-root input/output virtualization, Linux Containers, and commercial off-the-shelf hardware. Using a state-of-the-art timestamping methodology, we measure latencies with a resolution of 1.25 μs without introducing delay by the measurement methodology itself. We evaluate a single flow in a line topology with up to 64 containers. The experiments demonstrate that pinning interrupt request handlers to non-uniform memory access nodes increases throughput and decreases latencies. Furthermore, we identify dTLB misses, rescheduling interrupts, and soft interrupt floods as critical challenges as they cause spikes in latencies, and isolation is impossible. This paper contributes findings to minimize bottlenecks and limitations for real-time container applications. Alexander Daichendt, Florian Wiedner, Jonas Andre, Georg Carle |
CNSM | 4 |
| 2024 | On-the-fly Table Insertions on Programmable Software Data PlanesabstractNovel applications require a robust and reliable connection to provide the services for next-generation networks. The complex nature of these algorithms needs fast and efficient stateful processing. Using Software-defined Networking (SDN), new algorithms can be implemented into the network in a platform-independent way. The upcoming Portable NIC Architecture (PNA) for P4, a language to program data planes in SDN, allows inserting new table entries without controller interaction. Thus, it unleashes more performant and stateful applications without the overhead of the controller. We implement and evaluate these so-called ‘add-on-miss’ insertions introduced by the PNA for a P4 software target. In addition, we discuss the influence of latency and throughput optimizations on software packet processing systems. We determine the impact of these optimization strategies and which performance properties and costs can be measured with each. In our analysis, we model the costs of insertions based on an extensive baseline and compare them to table entry lookups and updates. We analyze the influence of the frequency of insertions and multi-core scenarios. Finally, we demonstrate that the approach scales for realistic scenarios. Manuel Simon, Sebastian Gallenmüller, Georg Carle |
CNSM | 3 |
| 2024 | CRDT Web Caching: Enabling Distributed Writes and Fast Cache Consistency for REST APIsabstractWeb Application developers have two main options to improve the performance of their REST APIs using Content Delivery Network (CDN) caches: define a Time to Live (TTL) or actively invalidate content. However, TTL-based caching is unsuited for the dynamic data exchanged via REST APIs, and neither can speed up write requests. Performance is important, as client latency directly impacts revenue, and a system’s scalability is determined by its achievable throughput. A new type of Web proxy that acts as an information broker for the underlying data rather than working on the level of HTTP requests presents new possibilities for enhancing REST APIs. Existing Conflict-free Replicated Data Type (CRDT) semantics and standards like JSON:API can serve as a basis for such a broker. We propose CRDT Web Caching (CWC) as a novel method for distributing application data in a network of Web proxies, enabling origins to automatically update outdated cached content and proxies to respond directly to write requests. We compared simple forwarding, TTL-based caching, invalidation-based caching, and CWC in a simulated CDN deployment. Our results show that TTL-based caching can achieve the best performance, but the long inconsistency window makes it unsuitable for dynamic REST APIs. CWC outperforms invalidation-based caching in terms of throughput and latency due to a higher cache-hit ratio, and it is the only option that can accelerate write requests. However, under high system load, increased performance may lead to higher latency for non-acceleratable requests due to the additional synchronization. CWC allows developers to significantly increase REST API performance above the current state-of-the-art. Markus Sosnowski, Richard von Seck, Florian Wiedner, Georg Carle |
CNSM | 4 |
| 2024 | Scheduled Trigger Frames: Enabling Worst-case Latency Bounds for Wi-Fi Industrial UseabstractThe centralized nature of OFDMA (i.e., the AP coordinating uplink and downlink transmissions) introduced in IEEE 802.11ax provides the foundation towards deterministic transmissions in Wi-Fi. Yet, the problem of deterministic channel access and resource allocation still exists. This work presents two time-triggered resource allocation mechanisms which guarantee worst-case latencies for UL transmissions based on scheduled Trigger Frames in OFDMA-based Wi-Fi. These mechanisms support converged networks, i.e., periodic, aperiodic and best effort traffic transmitted on the same network infrastructure. Combined with a previously presented modification that allows the AP to reliably access the channel with a worst-case delay of 55 μs, we show that the proposed resource allocation strategies based on OFDMA can support worst-case latency bounds. Our simulation results show that we can provide a bounded latency of 10 ms for up to 18 STAs for periodic deterministic traffic and a bounded latency of 30 ms for up to 31 STAs for aperiodic deterministic traffic in a 20 MHz channel. Ben Schneider, Björn Richerzhagen, Michael Bahr, Georg Carle |
IWCMC | 4 |
| 2024 | Reproducible Wireless Experiments in a Containerized Environment with Hardware AccessabstractReproducible wireless experiments pose a particular challenge due to their susceptibility to interference and changing channel conditions. Unlike most wired networks, they do not have dedicated connections or well-shared frequencies. This makes broadcast media such as wireless networks a challenge for reproducible experiments that are comparable to real-world scenarios. There are many attempts to approach these difficulties, either by simulation, emulation, or dedicated testbeds. All of them have certain strengths in specific applications, but also certain weaknesses – with respect to accuracy, flexibility, and cost.We therefore propose a combination of a physical link under a controlled environment, together with virtual wireless interfaces (VIFs) used to emulate arbitrary topologies. This allows us to make use of the real-world behavior of hardware with respect to timings such as media access while offering the flexibility of an emulated environment. By using containers for individual emulated nodes that use VIFs we can setup such topologies on a single host. In addition, measurement tools and applications can be run natively within this setup. Désirée Rentz, Lukas Heindl, Jonas Andre, Georg Carle, Stephan M. Günther |
LCN | 4 |
| 2024 | Thresh-Hold: Assessment of Threshold Cryptography in Leader-Based ConsensusabstractByzantine fault tolerant (BFT) systems can be constructed, using the state machine replication (SMR) approach. The usage of threshold cryptography has been widely proposed to confront performance and scalability challenges. We extend the focus on BLS signatures to ECDSA and Schnorr-based schemes and study their impact on BFT-SMR systems. We analyze their suitability for BFT-SMR and study the complexity of four practical, derived schemes. We implement these schemes for the seminal, leader-based HotStuff protocol. Finally, we experimentally quantify both performance impact and replica load under varying threshold schemes and parameters. Architectural constraints limit the applicability of threshold schemes to BFT-SMR. While BLS is the most compatible of the studied schemes, it incurs a significant base cost. We observe that for smaller deployments this increased base cost outweighs the theoretical scaling and performance benefits. Using optimizations such as command batching results in comparable throughput over all studied schemes, albeit with significant latency differences. Our results suggest, that both leader and client are potential bandwidth bottlenecks, already for relatively small payload sizes. Richard von Seck, Filip Rezabek, Georg Carle |
LCN | 3 |
| 2024 | Distributed Intelligence for Dynamic Task Migration in the 6G User Plane using Deep Reinforcement LearningabstractIn-Network Computing (INC) is a currently emerging paradigm. Realizing INC in 6G networks could mean that user plane entities (UPEs) carry out computations on packets while transmitting them. These computations may have specific requirements in terms of their completion time. In case of high compute pressure at one UPE, migrating computations to another UPE may be beneficial, in order to avoid exceeding the completion time requirement. Centralized migration approaches suffer from increased signaling and are prone to react too slow. Therefore, this paper investigates the applicability of distributed intelligence to tackle the problem of compute task migration in the 6G User Plane. Each UPE is equipped with an intelligent agent, enabling autonomous decisions on whether computations should be migrated to another UPE. To enable the intelligent agents to learn and apply an optimal task migration policy, we investigate and compare two state-of-the-art Deep Reinforcement Learning (DRL) approaches: Advantage Actor-Critic (A2C) and Double Deep Q-Network (DDQN). We show, via simulations, that the performance of both solutions, in terms of the percentage of tasks exceeding their completion time requirement, is near-optimal and training A2C is at least 60% faster than DDQN. Sayantini Majumdar, Susanna Schwarzmann, Riccardo Trivisonno, Georg Carle |
NOMS | 4 |
| 2024 | Distributed Intelligence for Automated 6G Network Management Using Reinforcement LearningabstractThe deployment of network elements in 6G is expected to be significantly more distributed than the existing 5G deployments. Distributed management paradigms are compatible with such distributed network deployments. Further, owing to their ability to solve complex problems by evaluating the impact of actions on the environment, intelligent solutions based on Reinforcement Learning (RL) for distributed management are promising. However, there are still several unsolved challenges before distributed intelligence could be seamlessly integrated in 6G. This work defines relevant research questions, reports on the progress made in the PhD project and presents the next steps and future directions for the advancement of this topic. Sayantini Majumdar, Susanna Schwarzmann, Riccardo Trivisonno, Georg Carle |
NOMS | 4 |
| 2024 | Shells Bells: Cyber-Physical Anomaly Detection in Data CentersabstractMonitoring the side-channel sound can improve anomaly detection (AD) in data centers (DCs). However, a DC’s dense setup results in a composite soundscape which makes it difficult to attribute sounds to individual devices.We propose a novel cyber-physical AD approach that validates device activity in realistic composite audio signals. By leveraging information from management network traffic, we predict changes in the DC soundscape. We use a convolutional neural network to compare our predictions with real observations to validate correct device activity and identify anomalies. Our evaluation using data from a real DC environment identifies spoofed and masqueraded activity with an accuracy of 98.62 %. Lars Wüstrich, Sebastian Gallenmüller, Stephan M. Günther, Georg Carle, Marc-Oliver Pahl |
NOMS | 4 |
| 2024 | QUIC Hunter: Finding QUIC Deployments and Identifying Server Libraries Across the Internet
Johannes Zirngibl, Florian Gebauer, Patrick Sattler, Markus Sosnowski, Georg Carle |
PAM (2) | 5 |
| 2024 | QUIC on the Fast Lane: Extending Performance Evaluations on High-rate LinksabstractQUIC is a new protocol standardized in 2021 designed to improve on the widely used TCP / TLS stack. The main goal is to speed up web traffic via HTTP, but it is also used in other areas like tunneling. Based on UDP, it offers features like reliable in-order delivery, flow and congestion control, stream-based multiplexing, and always-on encryption using TLS 1.3. Unlike TCP, QUIC integrates these capabilities in user space, relying on kernel interaction solely for UDP. Operating in user space allows more flexibility but sacrifices some kernel-level efficiency and optimization that TCP benefits from. Various QUIC implementations exist, each distinct in programming language, architecture, and design. QUIC is already widely deployed on the Internet and has been evaluated, focussing on low latency, interoperability, and standard compliance. However, benchmarks on high-speed network links are still scarce. This paper presents an extension to the QUIC Interop Runner, a framework for testing the interoperability of QUIC implementations. Our contribution enables reproducible QUIC benchmarks on dedicated hardware and high-speed links. We provide results on 10G links, including multiple implementations, evaluate how OS features like buffer sizes and NIC offloading impact QUIC performance, and show which data rates can be achieved with QUIC compared to TCP. Moreover, we analyze different CPUs and CPU architectures influence reproducible and comparable performance measurements. Furthermore, our framework can be applied to evaluate the effects of future improvements to the protocol or the OS. Our results show that QUIC performance varies widely between client and server implementations from around 50 Mbit/s to over 6000 Mbit/s. We show that the OS generally sets the default buffer size too small. Based on our findings, the buffer size should be increased by at least an order of magnitude. Our profiling analysis identifies Packet I/O as the most expensive task for QUIC implementations. Furthermore, QUIC benefits less from AES NI hardware acceleration while both features improve the goodput of TCP to around 8000 Mbit/s. The lack of support for NIC offloading from QUIC implementations results in missed opportunities for performance improvement. The assessment of CPUs from different vendors and generations revealed significant performance variations. We employed core pinning to examine if the performance of QUIC implementations is affected by the allocation to specific CPU cores. The results indicated an increased goodput of up to 20% when running on a specifically chosen core compared to a randomly assigned core. This outcome highlights the impact of CPU core selection on the performance of QUIC implementations but also for reproducible measurements. Marcel Kempf, Benedikt Jaeger, Johannes Zirngibl, Kevin Ploch, Georg Carle |
Comput. Commun. | 5 |
| 2024 | Exploring Data Plane Updates on P4 Switches with P4RuntimeabstractThe development and roll-out of new Ethernet standards increase the available bandwidths in computer networks. This growth presents significant advantages, enabling novel applications. At the same time, the increase introduces new challenges; higher data rates reduce the available time budget to process each packet. This development also impacts software-defined networks. Their data planes need to keep up with the increased traffic rates. Nevertheless, the control plane must not be ignored; fast reaction times are necessary to handle the increased rates handled by data planes efficiently. In our work, we analyze the interaction of a high-performance data plane and different implementations for the control plane. We selected a P4 switching ASIC as our data plane. For the control plane, we investigate vendor-specific implementations and a standardized implementation called P4Runtime. To determine the performance of the control plane, we introduce a novel measurement methodology. This methodology allows measuring the delay between the initiation of rule updates on the control plane and their application on the data plane. We investigate the behavior of the data plane, its performance and non-atomicity of updates. Based on our findings, we apply different optimization strategies to improve control plane performance. Our measurements show that neglecting the control plane performance may impact network behavior due to delayed updates, but we also show how to minimize this delay and, thereby, its impact. We have released the experiment artifacts of our study including experiment scripts and measurement data. Henning Stubbe, Sebastian Gallenmüller, Manuel Simon, Eric Hauser, Dominik Scholz, Georg Carle |
Comput. Commun. | 6 |
| 2024 | Performance evaluation of containers for low-latency packet processing in virtualized network environments
Florian Wiedner, Max Helm, Alexander Daichendt, Jonas Andre, Georg Carle |
Perform. Evaluation | 5 |
| 2024 | Toward Massive Distribution of Intelligence for 6G Network Management Using Double Deep Q-NetworksabstractIn future 6G networks, the deployment of network elements is expected to be highly distributed, going beyond the level of distribution of existing 5G deployments. To fully exploit the benefits of such a distributed architecture, there needs to be a paradigm shift from centralized to distributed management. To enable distributed management, Reinforcement Learning (RL) is a promising choice, due to its ability to learn dynamic changes in environments and to deal with complex problems. However, the deployment of highly distributed RL – termed massive distribution of intelligence – still faces a few unsolved challenges. Existing RL solutions, based on Q-Learning (QL) and Deep Q-Network (DQN) do not scale with the number of agents. Therefore, current limitations, i.e., convergence, system performance and training stability, need to be addressed, to facilitate a practical deployment of massive distribution. To this end, we propose improved Double Deep Q-Network (IDDQN), addressing the long-term stability of the agents’ training behavior. We evaluate the effectiveness of IDDQN for a beyond 5G/6G use case: auto-scaling virtual resources in a network slice. Simulation results show that IDDQN improves the training stability over DQN and converges at least 2 times sooner than QL. In terms of the number of users served by a slice, IDDQN shows good performance and only deviates on average 8% from the optimal solution. Further, IDDQN is robust and resource-efficient after convergence. We argue that IDDQN is a better alternative than QL and DQN, and holds immense potential for efficiently managing 6G networks. Sayantini Majumdar, Susanna Schwarzmann, Riccardo Trivisonno, Georg Carle |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | EFACTLS: Effective Active TLS Fingerprinting for Large-Scale Server Deployment CharacterizationabstractActive measurements allow the collection of server characteristics on a large scale that can aid in discovering hidden relations and commonalities among server deployments. Finding these relations opens up new possibilities for clustering and classifying server deployments; for example, identifying a previously unknown cybercriminal infrastructure can be valuable cyber-threat intelligence. In this work, we propose a methodology based on active measurements to acquire Transport Layer Security (TLS) metadata from servers and leverage it for fingerprinting. Our fingerprints capture characteristic behavior of the TLS stack, primarily influenced by the server’s implementation, configuration, and hardware support. Using an empirical optimization strategy that maximizes information gained from every handshake to minimize measurement costs, we generated 10 general-purpose Client Hellos. They served as scanning probes to create an extensive database of TLS configurations to classify servers. We propose the Shannon Entropy to measure collected information and compare different approaches. This study fingerprinted 8 million servers from the Tranco top list and two Command and Control (C2) blocklists over 60 weeks with weekly snapshots. The resulting data formed the foundation for two long-term case studies: classification of Content Delivery Network and C2 servers. Moreover, the detection was fine-grained enough to detect C2 server families. The proposed methodology demonstrated a precision of 99% and enabled a stable identification of new servers over time. This study shows how active measurements can provide valuable security-relevant insights and improve our understanding of the Internet. Markus Sosnowski, Johannes Zirngibl, Patrick Sattler, Georg Carle, Claas Grohnfeldt, Michele Russo, Daniele Sgandurra |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | Synthesizing and Scaling WAN Topologies Using Permutation-Invariant Graph Generative ModelsabstractReal-world Wide Area Network (WAN) topologies are scarce. The shift towards machine learning in network management and optimization brings a need for large datasets, including real-world topologies. WAN topologies can be generated using graph generative models. Graph generative models can be divided into parameterized and data-driven approaches. Data-driven approaches can be further divided into permutation-invariant and permutation-variant. In this paper, we improve on existing work, which utilized adjacency-matrix-based, permutation-variant Generative Adversarial Networks to synthesize WAN topologies. We achieve this by using existing, data-driven approaches that are permutation-invariant w.r.t. their input. Our results show a decrease in the mean Kolmogorov-Smirnov distance over various graph theoretical metrics of 80 %. Furthermore, we employ graph upscaling models to increase WAN topology sizes while preserving their properties up to a scaling factor of 256. We publish all datasets and hope they can be of help in training machine learning models, such as communication network performance prediction models or digital twins, enabling better automated network management. Max Helm, Georg Carle |
CNSM | 2 |
| 2023 | Fast and Scalable Network Slicing by Integrating Deep Learning with Lagrangian MethodsabstractNetwork slicing is a key technique in 5G and beyond for efficiently supporting diverse services. Many network slicing solutions rely on deep learning to manage complex and high-dimensional resource allocation problems. However, deep learning models suffer limited generalization and adaptability to dynamic slicing configurations. In this paper, we propose a novel frame-work that integrates constrained optimization methods and deep learning models, resulting in strong generalization and superior approximation capability. Based on the proposed framework, we design a new neural-assisted algorithm to allocate radio resources to slices to maximize the network utility under inter-slice resource constraints. The algorithm exhibits high scalability, accommodating varying numbers of slices and slice configurations with ease. We implement the proposed solution in a system-level network simulator and evaluate its performance extensively by comparing it to state-of-the-art solutions including deep reinforcement learning approaches. The numerical results show that our solution obtains near-optimal quality-of-service satisfaction and promising generalization performance under different network slicing scenarios. Tianlun Hu, Qi Liao 0003, Qiang Liu 0013, Antonio Massaro, Georg Carle |
GLOBECOM | 5 |
| 2023 | Advancing Federated Learning in 6G: A Trusted Architecture with Graph-Based AnalysisabstractIntegrating native AI support into the network architecture is an essential objective of 6G. Federated Learning (FL) emerges as a potential paradigm, facilitating decentralized AI model training across a diverse range of devices under the co-ordination of a central server. However, several challenges hinder its wide application in the 6G context, such as malicious attacks and privacy snooping on local model updates, and centralization pitfalls. This work proposes a trusted architecture for supporting FL, which utilizes Distributed Ledger Technology (DLT) and Graph Neural Network (GNN), including three key features. First, a pre-processing layer employing homomorphic encryption is incorporated to securely aggregate local models, preserving the privacy of individual models. Second, given the distributed nature and graph structure between clients and nodes in the pre-processing layer, GNN is leveraged to identify abnormal local models, enhancing system security. Third, DLT is utilized to decentralize the system by selecting one of the candidates to perform the central server's functions. Additionally, DLT ensures reliable data management by recording data exchanges in an immutable and transparent ledger. The feasibility of the novel architecture is validated through simulations, demonstrating improved performance in anomalous model detection and global model accuracy compared to relevant baselines. Wenxuan Ye, Chendi Qian, Xueli An, Xueqiang Yan, Georg Carle |
GLOBECOM | 5 |
| 2023 | Distributing Intelligence for 6G Network Automation: Performance and Architectural ImpactabstractIn future 6G networks, distributed management of network elements is expected to be a promising paradigm. Recent research progress in Artificial Intelligence (AI) is rapidly driving the adoption of distributed management. However, distributed management using intelligence or distributed AI inherently suffers from a number of issues - potential conflicts, signaling required to ensure cooperation and the convergence time of the algorithm. To this end, an early understanding and analysis of the overall effort to implement distributed AI in 6G, is still unexplored. This work, therefore, examines the impact of distributed AI, by analyzing its performance and how the existing 5G architecture could be enhanced to support it in 6G. We aim to understand the impact of distributed AI in 6G by selecting a relevant beyond 5G use case - auto-scaling virtual resources in a network slice. We present the performance and architecture analysis for two distributed algorithms from the domain of Reinforcement Learning - Q-Learning and Deep Q-Networks. We argue that despite its aforementioned issues, distributed AI brings benefits such as dynamic and adaptive decision-making, making it highly applicable for certain use cases in 6G. Sayantini Majumdar, Riccardo Trivisonno, Wint Yi Poe, Georg Carle |
ICC | 4 |
| 2023 | An Accuracy Study of Emulation Daemons for IEEE 802.11 NetworksabstractIrreproducibility and external influences are common in wireless experiments. In addition, setups with multiple, possibly moving nodes are expensive to create for testing purposes. To address these issues, several wireless emulators and simulators are available. Wireless medium emulators are of particular interest because they allow the use of software designed for real wireless environments without adaptation. In this paper we evaluate the accuracy of the wireless medium emulators hwsim, wmediumd, and yawmd. We compare throughput and round-trip time with results from actual wireless transmissions in a shielded environment. We found large differences between real hardware and these emulators: hwsim throughput results are more than an order of magnitude higher than actual wireless transmissions and measured round-trip times are much lower than expected. wmediumd adds wireless logic such as data rates and media access to the emulation. However, we measured data rates well below one-fifth of the actual data rate available in wireless environments. The RTT under load with wmediumd and yawmd experiments are much higher than in real wireless transmissions and tend to vary widely. yawmd is more accurate in terms of performance but comes with more inaccurate RTTs than wmediumd with TCP traffic. Jonas Andre, Stephan M. Günther, Georg Carle |
LCN | 3 |
| 2023 | A Multi-Tenancy System Architecture for Online ExaminationsabstractTime-synchronous online examinations pose new demands on our infrastructure: lectures with more than 1000 students are common at TUM, and in case of time-synchronous examinations students concurrently download working instructions or submit solutions – with possibly multiple such examinations being conducted at the same time. Furthermore, the architecture has to withstand students that impatiently reload the download page multiple times as well as the sudden increase in traffic at the start and end of an exam. In addition, the architecture has to be resilient against both deliberate attacks of individuals and handling of unsuspecting users.In this paper we discuss our implementation of an examination management platform as multi-tenancy system based on operational requirements, demands on scalability, and bottlenecks we encountered in our attempt to roll out the infrastructure for as many examinations as needed. Jonas Andre, Johannes Naab, Benedikt Jaeger, Georg Carle, Leander Seidlitz, Stephan M. Günther |
NOMS | 4 |
| 2023 | On the Accuracy of Active Capacity Estimation in the InternetabstractEstimating the capacity of network paths is a frequently and versatilely used technique for network and flow analysis used by service providers and researchers to analyze available bandwidth, performance limitations of connections, or infrastructure deployments. While researchers evaluated different capacity estimation approaches in the early 2000s, there are no recent studies on the accuracy of estimates and capacity deployments in today’s Internet.This paper is purposed to survey the accuracy of actively conducted capacity estimation in today’s Internet. We implement passive packet pair dispersion-based capacity estimation according to the PPrate algorithm and conduct active measurements with TCP and ICMP traffic on controlled targets in the Internet and on public web servers to analyze the accuracy and stability of estimated capacities in the Internet.Our study confirms the general accuracy of PPD-based measurements through the Internet while we observe and discuss impacts by interrupt coalescence, receive offloading, and ICMP rate limiting of middleboxes. Measurements to over 3500 web servers taken from the Alexa top 1M list indicate capacities of at least 1 Gbit/s for the majority of paths to measurement targets, while ICMP-based measurements frequently result in significant underestimation due to ICMP rate limiting. Janluka Janelidze, Benedikt Jaeger, Patrick Sattler, Patryk Brzoza, Georg Carle |
NOMS | 6 |
| 2023 | DissecTLS: A Scalable Active Scanner for TLS Server Configurations, Capabilities, and TLS FingerprintingabstractAbstract Collecting metadata from Transport Layer Security (TLS) servers on a large scale allows to draw conclusions about their capabilities and configuration. This provides not only insights into the Internet but it enables use cases like detecting malicious Command and Control (C &C) servers. However, active scanners can only observe and interpret the behavior of TLS servers, the underlying configuration and implementation causing the behavior remains hidden. Existing approaches struggle between resource intensive scans that can reconstruct this data and light-weight fingerprinting approaches that aim to differentiate servers without making any assumptions about their inner working. With this work we propose DissecTLS, an active TLS scanner that is both light-weight enough to be used for Internet measurements and able to reconstruct the configuration and capabilities of the TLS stack. This was achieved by modeling the parameters of the TLS stack and derive an active scan that dynamically creates scanning probes based on the model and the previous responses from the server. We provide a comparison of five active TLS scanning and fingerprinting approaches in a local testbed and on toplist targets. We conducted a measurement study over nine weeks to fingerprint C &C servers and analyzed popular and deprecated TLS parameter usage. Similar to related work, the fingerprinting achieved a maximum precision of 99 % for a conservative detection threshold of 100 %; and at the same time, we improved the recall by a factor of 2.8. Markus Sosnowski, Johannes Zirngibl, Patrick Sattler, Georg Carle |
PAM | 4 |
| 2023 | Priority-aware Inter-Server Receive Side ScalingabstractNext-generation automotive networks will be characterized by a high number of interconnected sensors, actuators and applications on electronic control units communicating with each other over a high-speed Ethernet backbone network. As these applications have various criticalities, high volumes of fluctuating traffic with different priorities will have to be processed in a reliable and efficient manner. To cope with these challenges, we present Priority-aware Inter-Server Receive Side Scaling (prioRSS), a new SmartNIC-based hardware accelerator designed for automotive compute nodes. prioRSS builds upon Receive Side Scaling and introduces priority-awareness into an intra- and inter-node load balancer. It uses a priority-partitioned indirection table within which flows of the same priority are bundled. Low-latency reconfigurations issued by a Network Health Monitoring software allow for adapting the table content to changing network conditions. Simulative evaluations and comparisons to a priority-unaware version of our design show that prioRSS enables per-priority resource assignments without degrading end-to-end packet latencies while using the same table memory space. Paired with a priority-aware scheduler, end-to-end latencies of high priority flows can be notably reduced compared to average packet latencies, at the expense of lowest priority traffic. The best results are acquired when partitioning the table proportionally to the associated traffic share. Franz Biersack, Kilian Holzinger, Henning Stubbe, Thomas Wild, Georg Carle, Andreas Herkersdorf |
PDP | 5 |
| 2023 | Deterministic Channel Access Using MU EDCA in OFDMA-based Wi-Fi NetworksabstractWith its recent developments, Wi-Fi is becoming one of the key technologies to provide flexible yet deterministic communication in Industrial IoT Scenarios. IEEE 802.11ax employs a paradigm shift from a distributed to a centralized coordination strategy with its new channel access mechanism called Orthogonal Frequency Division Multiple Access (OFDMA). Using OFDMA, the Access Point (AP) always has to win contention against its associated Stations (STA) before it can initiate a trigger-based transmission. However, contention-based, distributed channel access mechanisms are still supported in IEEE 802.11ax networks, interfering with any hard real-time communication. Multi-user Enhanced Distributed Channel Access (MU EDCA), introduced in IEEE 802.11ax, was designed to influence when to use the distributed or the centralized coordination strategy. It allows to shift the probability of STAs accessing the channel towards the AP, such that the AP can initiate an OFDMA-based transmission. OFDMA is a promising starting point for real-time transmissions in Wi-Fi, We propose a modification of MU EDCA that guarantees worst-case channel access times for the AP in networks which only consist of Wi-Fi 6 capable devices (e.g., in the 6-GHz band). Simulations result in a worst-case channel access delay for the AP of$55\ \mu s$independent of the number of STAs. Ben Schneider, Chitiphat Chongaroonngamsaeng, Björn Richerzhagen, Michael Bahr, Georg Carle |
WFCS | 5 |
| 2023 | Trust and Performance in Future AI-Enabled, Open, Multi-Vendor Network Management AutomationabstractCognitive Autonomous Networks (CAN) promise to advance Self Organizing Networks (SON) by applying artificial intelligence to significantly raise the degree of automation in mobile networks. In CAN, Cognitive Functions (CFs) learn the optimal configuration parameter values to optimize specific network metrics, with the execution coordinated via a controller. In open, multi-vendor systems however, the CF’s learning ability may raise a new risk: a manipulative CF (MCF) may learn not only its objective, but also to manipulate the coordination system in pursuit of that objective. In this paper we propose and evaluate our proposed functionality, called CoDeRa, that neutralizes manipulative CF behavior. However, although CoDeRa is effective against MCFs, it is inadequate to resolving error propagation in CF coordination, caused by corrupted network data, for which we have proposed an alternate simpler and cost efficient network management architecture. Our evaluation shows that the proposed design is robust against the observed concerns, and in context of ongoing worldwide standardization efforts, we summarize the relevance and implications of our proposed architecture. Anubhab Banerjee, Stephen S. Mwanje, Georg Carle |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2022 | Flow-level Tail Latency Estimation and Verification based on Extreme Value TheoryabstractModeling extreme latencies in communication net-works can contribute information to network planning and flow admission under service level agreements. Extreme Value Theory is such an approach that utilizes real-world measurement data. It is often applied without verifying the resulting model predictions on larger datasets. Here we show that such models can provide accurate predictions over larger datasets while being applied to 100 random network topologies and configurations. We found that applying derived models with a bounded tail to a twentyfold time period results in a prediction accuracy of 75% for extreme latency exceedances. Furthermore, we show that tail latency quantiles can be predicted on a flow level with median absolute percentage errors ranging from 0.7% to 16.8%. Therefore, we consider this approach to be useful for dimensioning networks under latency-constrained service level agreements. Max Helm, Florian Wiedner, Georg Carle |
CNSM | 3 |
| 2022 | PTP Security Measures and their Impact on Synchronization AccuracyabstractThe Precision Time Protocol (PTP) synchronizes clocks in a network with high precision. The protocol finds use in many areas, such as smart manufacturing, intra-vehicular networks, and critical infrastructure. It becomes clear that striving for security is an important goal. If an attacker succeeds in disturbing the network synchronization, the impact can result in a cascading set of failures. Unfortunately, neither the previous two IEEE standards for PTP, nor the popular implementation linuxptp, feature or implement sufficient security options.This work focuses on implementing the security extensions for PTP based on the latest PTP standard IEEE 1588-2019 to minimize the threat of attacks and their possible impact. We provide a detailed analysis on PTP synchronicity and security. Based on that, we design and implement software-only tooling to quantify the PTP performance using commercial off-the-shelf hardware and open-source solutions on a linear topology with four to nine hops.The measurements compare the End-to-End (E2E) and Peer-to-Peer (P2P) delay calculation modes and the usage of Transparent Clocks (TC) in parts of the network. Both E2E and P2P show visible degradation of clock synchronization with each hop and standard deviations of 118.6 to 571 ns. The TCs perform better, demonstrating a standard deviation between 90 to 140 ns on four to nine hops. We evaluate different logSyncInterval values corresponding to different PTP profiles and do not observe a major impact on the clock behavior caused by the extensions. The measurement precision of the system is within ±40 ns.Our evaluation of the newly implemented security extensions to linuxptp shows that the security extensions do not have a significant impact on the clock synchronization and our approach is a feasible addition to PTP. Besides, our contributions can aid network managers in assessing their PTP synchronicity systematically. Filip Rezabek, Max Helm, Tizian Leonhardt, Georg Carle |
CNSM | 4 |
| 2022 | Network Slicing via Transfer Learning aided Distributed Deep Reinforcement LearningabstractDeep reinforcement learning (DRL) has been in-creasingly employed to handle the dynamic and complex re-source management in network slicing. The deployment of DRL policies in real networks, however, is complicated by heterogeneous cell conditions. In this paper, we propose a novel transfer learning (TL) aided multi-agent deep reinforcement learning (MADRL) approach with inter-agent similarity analysis for inter-cell inter-slice resource partitioning. First, we design a coordinated MADRL method with information sharing to intelligently partition resource to slices and manage inter-cell interference. Second, we propose an integrated TL method to transfer the learned DRL policies among different local agents for accelerating the policy deployment. The method is composed of a new domain and task similarity measurement approach and a new knowledge transfer approach, which resolves the problem of from whom to transfer and how to transfer. We evaluated the proposed solution with extensive simulations in a system-level simulator and show that our approach outperforms the state-of-the-art solutions in terms of performance, convergence speed and sample efficiency. Moreover, by applying TL, we achieve an additional gain over 27% higher than the coordinated MADRL approach without TL. Tianlun Hu, Qi Liao 0003, Qiang Liu 0013, Georg Carle |
GLOBECOM | 4 |
| 2022 | Improving Scalability of 6G Network Automation with Distributed Deep Q-NetworksabstractIn recent years, owing to the architectural evolution of 6G towards decentralization, distributed intelligence is being studied extensively for 6G network automation. Distributed intelligence, based on Reinforcement Learning (RL), particularly Q-Learning (QL), has been proposed as a potential direction. The distributed framework consists of independent QL agents, attempting to reach their own individual objectives. The agents need to learn using a sufficient number of training steps before they converge to the optimal performance. After convergence, they can take reliable management actions. However, the scalability of QL could be severely hindered, particularly in the convergence time - when the number of QL agents increases. To overcome the scalability issue of QL, in this paper, we explore the potentials of the Deep Q-Network (DQN) algorithm, a function approximation-based method. Results show that DQN outperforms QL by at least 37% in terms of convergence time. In addition, we highlight that DQN is prone to divergence, which, if solved, could rapidly advance distributed intelligence for 6G. Sayantini Majumdar, Leonardo Goratti, Riccardo Trivisonno, Georg Carle |
GLOBECOM | 4 |
| 2022 | Inter-Cell Slicing Resource Partitioning via Coordinated Multi-Agent Deep Reinforcement LearningabstractNetwork slicing enables the operator to configure virtual network instances for diverse services with specific requirements. To achieve the slice-aware radio resource scheduling, dynamic slicing resource partitioning is needed to orchestrate multi-cell slice resources and mitigate inter-cell interference. It is, however, challenging to derive the analytical solutions due to the complex inter-cell interdependencies, inter-slice resource constraints, and service-specific requirements. In this paper, we propose a multi-agent deep reinforcement learning (DRL) approach that improves the max-min slice performance while maintaining the constraints of resource capacity. We design two coordination schemes to allow distributed agents to coordinate and mitigate inter-cell interference. The proposed approach is extensively evaluated in a system-level simulator. The numerical results show that the proposed approach with inter-agent coordination outperforms the centralized approach in terms of delay and convergence. The proposed approach improves more than two-fold increase in resource efficiency as compared to the baseline approach. Tianlun Hu, Qi Liao 0003, Qiang Liu 0013, Dan Wellington, Georg Carle |
ICC | 5 |
| 2022 | Scalability of Distributed Intelligence Architecture for 6G Network AutomationabstractDistributed automation is expected to play a significant role in the management of 6G networks, as it avoids the drawbacks of a single point of failure and signaling overhead inherent in a centralized paradigm. However, the issue of conflicts is intrinsic to a distributed architecture and when left unaddressed, may severely impair system KPIs. Considering the conflict problem, it is unclear if distributed automation would be scalable to realize the potential of 6G networks. In this paper, we validate the scalability of distributed intelligence, specifically based on Q-Learning, Q-Learning for Cooperation (QLC), consisting of intelligent agents that learn to cooperate on a discrete state space. Results show that the performance of QLC is scalable when compared to the optimal, computed by a centralized solution. Scalability may be limited by the convergence time that increases with the number of agents and the size of the discrete state space. The cooperation overhead is also not critical. These findings indicate that QLC is promising and may be applied to other use cases if the speed of convergence is not a significant detriment in distributing intelligence in 6G. Sayantini Majumdar, Riccardo Trivisonno, Georg Carle |
ICC | 3 |
| 2022 | Towards a tectonic traffic shift?: investigating Apple's new relay networkabstractApple recently published its first Beta of the iCloud Private Relay, a privacy protection service with promises resembling the ones of VPNs. The architecture consists of two layers (ingress and egress), operated by disjoint providers. The service is directly integrated into Apple's operating systems, providing a low entry-level barrier for a large user base. It seems to be set up for significant adoption with its relatively moderate entry-level price. Patrick Sattler, Juliane Aulbach, Johannes Zirngibl, Georg Carle |
IMC | 4 |
| 2022 | Rusty clusters?: dusting an IPv6 research foundationabstractThe long-running IPv6 Hitlist service is an important foundation for IPv6 measurement studies. It helps to overcome infeasible, complete address space scans by collecting valuable, unbiased IPv6 address candidates and regularly testing their responsiveness. However, the Internet itself is a quickly changing ecosystem that can affect long-running services, potentially inducing biases and obscurities into ongoing data collection means. Frequent analyses but also updates are necessary to enable a valuable service to the community. Johannes Zirngibl, Lion Steger, Patrick Sattler, Oliver Gasser, Georg Carle |
IMC | 5 |
| 2022 | BFT-Blocks: The Case for Analyzing Networking in Byzantine Fault Tolerant ConsensusabstractByzantine fault tolerant (BFT) consensus allows the construction of robust, distributed systems via the state-machine replication (SMR) approach. Still, after more than 40 years of research, limitations on performance and scalability for practical systems remain. A large corpus of existing work improves on consensus complexity, performance and introduces a multitude of optimization techniques. The state-of-the-art is complex. On the other hand, many protocols designed for practical deployments are built on strong, common assumptions about underlying communication and authentication primitives. To fulfill these assumptions, often, commodity tools and libraries are employed without further analysis and caution for negative interplay.Instead of contributing to the existing complexity, we choose a different approach. In this paper, we outline the feasibility and potential impact of the optimization of common building blocks of BFT-SMR systems. We systemize existing work in terms of common model assumptions and identify optimization potential. Finally, we choose the building block of networking transport as a representative example and analyze its optimization space, both in context of general BFT-SMR systems and a case study of the HotStuff protocol. We describe behavior, challenges, and desired configuration of network transports for use in byzantine agreement, and identify lossy links as the main catalyst for significant performance differences between protocols and configurations. Richard von Seck, Filip Rezabek, Benedikt Jaeger, Sebastian Gallenmüller, Georg Carle |
NCA | 5 |
| 2022 | Towards the Classification of TCP Throughput ChangesabstractAnalyzing throughput limitations of TCP connections has been a frequently studied topic. While existing approaches determine throughput limitations for whole connections or specific segments of connections, this paper surveys whether such approaches can also be used to classify individual changes in the throughput of a connection.In this paper, we introduce an approach to classify changes in TCP throughput based on their coincide with changes between TCP transfer periods. We evaluate different change point detection methods with generated TCP traffic providing ground truth data regarding throughput changes. Further, we survey the matching between throughput change points and transfer periods in passively captured Internet traffic. We conclude that the classification of TCP throughput changes with TCP transfer periods is feasible for a significant share of changes and observe significant differences in matching results depending on the used change point detection method. Benedikt Jaeger, Max Reimann, Jonas Fromm, Georg Carle |
NOMS | 5 |
| 2022 | SmartNIC-based Load Management and Network Health Monitoring for Time Sensitive ApplicationsabstractTime sensitive network applications, for example in Intra-Vehicular Networks, aim to give predictable end-to-end latency guarantees. As a consequence, processing resources of involved host systems remain partially unused, because they are reserved for rare worst cases. This circumstance provides the opportunity to reduce dimensioning overheads by managing the load on the nodes flexibly within the network. In our proposed approach, a SmartNIC involving an FPGA-based load balancer achieves dynamic routing of flows whilst preserving end-to-end latency guarantees. A flow-oriented online network measurement component continuously supervises network traffic with regards to compliance to flow specifications and constraints such as bounded one-way delay, absence of packet loss, and jitter. We use the supervisor to enhance forwarding decisions on the data plane. Initial evaluation yields a saving potential of around 30 %. We showcase quick dynamic reconfiguration of the FPGA when triggered by real-time measurement of the one-way delay using realistic automotive network traffic. Kilian Holzinger, Franz Biersack, Henning Stubbe, Angela Gonzalez Mariño, Abdoul Kane, Francesc Fons, Haigang Zhang, Thomas Wild, Andreas Herkersdorf, Georg Carle |
NOMS | 10 |
| 2022 | Clustering Mobile Network Data with Decorrelating Adversarial NetsabstractDeep learning plays a crucial role in enabling cognitive automation for the mobile networks of the future. Deep clustering – a subset of deep learning – is a valuable tool for many network automation use cases. Unfortunately, most state-of-the-art clustering algorithms target image datasets, which makes them hard to apply to mobile network automation due to their highly tuned nature and assumptions about the data. In this paper, we propose a new algorithm, Decorrelating Adversarial Nets for Clustering-friendly Encoding (DANCE), intended to be a reliable deep clustering method for mobile network automation use cases. DANCE uses a reconstructive clustering approach, separating clustering-relevant from clustering-irrelevant features in a latent representation. This separation removes unnecessary information from the clustering, increasing consistency and peak performance. We comprehensively evaluate DANCE and other select state-of-the-art deep clustering algorithms, and show that DANCE outperforms these algorithms by a significant margin in a mobile user behavior clustering task based on data gained from a simulated scenario. Marton Kajo, Janik Schnellbach, Stephen S. Mwanje, Georg Carle |
NOMS | 4 |
| 2022 | Robust Deep Learning against Corrupted Data in Cognitive Autonomous NetworksabstractNeural-net-based deep learning algorithms are starting to be utilized in many network functions. Deep neural nets are traditionally not resistant against missing or corrupted inputs, a scenario which is likely to happen in mobile networks. If the data corruption does not stem from malicious intent, the task of reconstructing missing inputs is called imputation. In this paper, we discuss how such imputation methods could be utilized in network functions, to make the network robust against non-adversarial data corruption. We propose an integrated approach, where the imputation is undertaken by the same model which implements the machine learning task in the network function. We evaluate state-of-the-art imputation methods and our integrated imputation thoroughly, using data generated in a mobile network simulator. Our results show excellent performance with the integrated imputation, but also raises some questions with regards to how deep-learning-based network functions should be used in such scenarios. Marton Kajo, Janik Schnellbach, Stephen S. Mwanje, Georg Carle |
NOMS | 4 |
| 2022 | AC/DCIM: Acoustic Channels for Data Center Infrastructure MonitoringabstractData center infrastructure monitoring (DCIM) uses various features to track a data center’s state. In addition to collecting device-level information, the monitoring also includes physical features such as temperature or power intake to detect equipment failures and anomalies. Measuring physical features requires dedicated sensors at specific vantage points for efficient and reliable data collection. We propose a novel approach for DCIM using acoustic channels. Audio-based DCIM offers substantial benefits: sensors are affordable, data collection is non-intrusive, and audio processing is well-understood. Information extraction from acoustic channels can be challenging due to audio consisting of multiple devices’ mixed and often noisy signals. Our paper demonstrates the feasibility of single-node state detection over audio side-channels. Experiments in a real data center show that our sound-based approach can successfully detect errors. Lars Wüstrich, Sebastian Gallenmüller, Marc-Oliver Pahl, Georg Carle |
NOMS | 4 |
| 2022 | CRGC: A Practical Framework for Constructing Reusable Garbled Circuits
Christopher Harth-Kitzerow, Georg Carle, André Luckow, Johannes Klepsch |
SECRYPT | 2 |
| 2022 | Toward Control and Coordination in Cognitive Autonomous NetworksabstractThe incorporation of Artificial Intelligence (AI) and Machine Learning (ML) in mobile networks is expected to raise the degree of automation by proposing Cognitive Autonomous Networks (CAN). In CAN, learning based functions, called Cognitive Functions (CFs), adjust network control parameters to optimize specific Key Performance Indicators (KPIs). The CFs share the same resources, and this very often introduces an overlap among their target control parameter adjustment, i.e., at one point of time, multiple CFs may want to change the same control parameter albeit by different amounts depending on their respective levels of interest in that parameter. Correspondingly, a Controller is required in CAN to coordinate the sharing of the parameter among the independent CFs to meet their varying extents of interests. Although a Nash Social Welfare Function (NSWF) based Controller was introduced at first, to overcome the problems of this Controller a second Controller was introduced based on Eisenberg-Gale Solution (EGS). To use an EGS based Controller, impact of each network control parameter on each CF, called Config-Weight (CW), needs to be calculated. In this paper we propose a Shapley value based method for CW calculation, prove the optimality of the method mathematically and by simulation, provide a comparison between the Controllers in a simulation environment that resembles 5G network and find that up to 9.18% improvement can be obtained using the EGS based Controller. Anubhab Banerjee, Stephen S. Mwanje, Georg Carle |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | A Framework for Reproducible Data Plane Performance ModelingabstractLanguages for programming data planes like P4 sparked a plethora of new applications in the data plane. The dynamic, evolving environment makes it challenging to understand what performance can be expected when running a program in a specific data plane target. However, knowing this is crucial for network operators when upgrading their networks. Dominik Scholz, Hasanin Harkous, Sebastian Gallenmüller, Henning Stubbe, Max Helm, Benedikt Jaeger, Nemanja Deric, Endri Goshi, Zikai Zhou, Wolfgang Kellerer, Georg Carle |
ANCS | 11 |
| 2021 | High-Performance Match-Action Table Updates from within Programmable Software Data PlanesabstractFor long, P4's mantra was that table entries could only be updated by the control plane. With the ongoing Portable NIC Architecture (PNA) standardization efforts, this is changing. In fact, PNA presumably includes explicit methods for table updates from within the data planes. Now, it is onto manufacturers and developers to integrate and use this mechanism in future P4 data planes. This would enable novel and improved applications, e.g., requiring means for maintaining state. Manuel Simon, Henning Stubbe, Dominik Scholz, Sebastian Gallenmüller, Georg Carle |
ANCS | 5 |
| 2021 | Open-Source MQTT EvaluationabstractMQTT is a lightweight publish-subscribe protocol used in the Internet of Things. Its popularity leads to several implementations in different languages. In this paper, we evaluate the most popular open-source MQTT implementations, Mosquitto, HiveMQ, EMQX, VerneMQ, MQTT.js and Paho. Our evaluation includes interoperability, resource consumption and latency. We create a generic test framework independent of any MQTT implementation or language. According to our interoperability results, major client and server implementations conform to the base requirements of the standard and thus can interoperate. The language of implementation is a crucial factor for resource consumption and causes considerable differences in scalability. Our results show that latencies between implementations in lossy networks differ. Overall, there is a trade-off between resource consumption and network latency. Melvin Bender, Erkin Kirdan, Marc-Oliver Pahl, Georg Carle |
CCNC | 4 |
| 2021 | On Detection of Manipulative Cognitive Functions in Cognitive Autonomous NetworksabstractIntroduction of artificial intelligence is expected to raise the degree of automation in mobile networks by succeeding Self Organizing Networks (SON) with Cognitive Autonomous Networks (CAN). In CAN, learning based Cognitive Functions (CFs) work on different network parameters to optimize specific Key Performance Indicators (KPIs). However, learning ability of a CF poses a serious threat to the stability of the system. A manipulative CF (like a rogue agent) may use its learning capabilities to understand the working procedure of the system and manipulate it to achieve its own objective. Existence of such a CF can cause severe performance degradation of the overall system. In this paper we propose a simple yet effective machine learning based approach to detect manipulative CF(s) in CAN. We evaluate the performance of our proposed solution in a simulation environment that closely resembles a real life 5G scenario and provide analysis of the results with necessary precautions to be taken in a multi vendor scenario. Anubhab Banerjee, Stephen S. Mwanje, Georg Carle |
CNSM | 3 |
| 2021 | An Intent-Driven Orchestration of Cognitive Autonomous Networks for RAN managementabstractIntent Based Networks (IBNs) are mainly used to transform a user's intent into network configuration, operation, and maintenance strategies. In this paper we propose an a generic end-to-end design of an intent based network management system which we further customize to use in RAN control parameter and KPI management utilizing an existing technology (Cognitive Autonomous Network (CAN)). We introduce three new concepts in intent based network management: intent specification platform (ISP), formal intent and Intent Fulfillment System (IFS), which are not only relevant for this specific use case but can also be used by other network components. We discuss how our proposed solution can be implemented in Python as a standalone module so that it can be used with suitable networking simulators. Along with these, we also provide an overview of standardization impact of our research to show that it conforms with the worldwide mobile network management standardization efforts. Anubhab Banerjee, Stephen S. Mwanje, Georg Carle |
CNSM | 3 |
| 2021 | Ducked Tails: Trimming the Tail Latency of(f) Packet Processing SystemsabstractLatency can be caused by delayed processing of packets on the nodes of a computer network. Latency figures tend to fluctuate, eventually creating substantial spikes leading to a long-tailed latency distribution. The absolute latency value and its distribution over time impact the service quality of computer networks-an essential requirement for novel services such as networked industrial control systems or remote medical procedures. In this work, we present our measurement methodology for packet processing systems to determine the latency reliably, and more importantly, its distribution, using highly accurate and precise hardware timestamping on off-the-shelf network interface cards (NICs). Further, we introduce an optimized software stack to run low-latency applications on regular Linux servers. Our investigation focuses on realtime features of the Linux kernel. The performance of our optimized software stack is demonstrated using a real-world application, the Snort intrusion prevention system (IPS). Across various scenarios, we achieve a maximum worst-case latency as low as 25 µs. This result is an almost 5-fold reduction of the measured tail latencies compared to a previous study. Sebastian Gallenmüller, Florian Wiedner, Johannes Naab, Georg Carle |
CNSM | 4 |
| 2021 | EnGINE: Developing a Flexible Research Infrastructure for Reliable and Scalable Intra-Vehicular TSN NetworksabstractDriver assistance, self-driving, and multimedia systems have two common implications: increasing demand on network bandwidth and the need for more powerful computation nodes. As a result, intra-vehicular networks (IVNs) change their layout. They are built around central nodes connected to the rest of the vehicle via Ethernet. The usage of Ethernet presents a challenge, as it lacks support for deterministic behavior by design. The solution is found within the IEEE Time-Sensitive Networking (TSN) standards, introducing real-time, low-latency, and deterministic communication into the Ethernet ecosystem. These new networked systems need to be thoroughly evaluated with IVN requirements in mind. To assess numerous configurations of IVN setups, in this work, we introduce a novel Environment for Generic In-vehicular Networking Experiments — EnGINE. It allows, among many others, repeatable, reproducible, and replicable TSN experiments with high precision and flexibility, which is not possible to run using proprietary solutions. EnGINE is based exclusively on commercial off-the-shelf components and is orchestrated by a flexible Ansible framework. This approach allows us to configure various topologies emulating realistic IVNs behavior, which is challenging using simulations. Based on available related work, we further address the challenges found in the IVNs. We derive additional requirements for experiments in the TSN domain and present our approach to fulfill them in an experimental setting. We believe that EnGINE provides the ideal environment for TSN network experiments. Filip Rezabek, Marcin Bosk, Thomas Paul, Kilian Holzinger, Sebastian Gallenmüller, Angela Gonzalez Mariño, Abdoul Kane, Francesc Fons, Haigang Zhang, Georg Carle, Jörg Ott |
CNSM | 10 |
| 2021 | The pos framework: a methodology and toolchain for reproducible network experimentsabstractIn scientific research, the independent reproduction of experimental results is the source of trust. The release of experimental artifacts enables the reproduction of results; however, additional efforts of researchers are required to prepare and document their experiments accordingly. To honor this increased effort, multiple initiatives were implemented to incentivize the creation and release of experimental artifacts, e.g., awards for papers that provide experimental artifacts. Sebastian Gallenmüller, Dominik Scholz, Henning Stubbe, Georg Carle |
CoNEXT | 4 |
| 2021 | Precise real-time monitoring of time-critical flowsabstractEthernet is increasingly used in areas where time-critical and safety-relevant data are transported over the network along with best-effort flows, for example in intra vehicle networks or industrial networks. The resulting complex network architectures, time-sensitive networking configurations and system interactions are hard to foresee during the design phase. Therefore, it is hard to rule out any violations of flow specifications or timing and reliability requirements, especially in the presence of unpredictable failures. Kilian Holzinger, Henning Stubbe, Franz Biersack, Angela Gonzalez Mariño, Abdoul Kane, Francesc Fons, Haigang Zhang, Thomas Wild, Andreas Herkersdorf, Georg Carle |
CoNEXT | 10 |
| 2021 | Optimal configuration determination in Cognitive Autonomous Networks
Anubhab Banerjee, Stephen S. Mwanje, Georg Carle |
IM | 3 |
| 2021 | Scalable TCP Throughput Limitation Monitoring
Florian Wiedner, Benedikt Jaeger, Paul Emmerich, Georg Carle |
IM | 5 |
| 2021 | It's over 9000: analyzing early QUIC deployments with the standardization on the horizonabstractAfter nearly five years and 34 draft versions, standardization of the new connection oriented transport protocol QUIC was finalized in May 2021. Designed as a fundamental network protocol with increased complexity due to the combination of functionality from multiple network stack layers, it has the potential to drastically influence the Internet ecosystem. Nevertheless, even in its early stages, the protocol attracted a variety of parties including large providers. Our study shows, that more than 2.3 M IPv4 and 300k IPv6 addresses support QUIC hosting more than 30 M domains. Johannes Zirngibl, Philippe Buschmann, Patrick Sattler, Benedikt Jaeger, Juliane Aulbach, Georg Carle |
Internet Measurement Conference | 6 |
| 2021 | Failure Handling for Time-Sensitive Networks using SDN and Source RoutingabstractWe propose a Software-Defined Network (SDN)based approach for ultra-fast recovery of Time Sensitive Networks (TSN) in the case of failure events. We exploit the Source Routing paradigm for explicit path control and the creation of a stateless TSN data plane. We further propose a TSN failure recovery routing heuristic used to minimise link congestion, while we also introduce the concept of TSN subgraphs to quickly reschedule the flows traversing the problematic area. We evaluate our approach using SDN-based Source Routing and Linux-based TSN scheduling integrated into Mininet. Gagan Nandha Kumar, Kostas Katsalis, Panagiotis Papadimitriou 0001, Paul Pop, Georg Carle |
NetSoft | 5 |
| 2021 | Adaptive Batching for Fast Packet Processing in Software Routers using Machine LearningabstractProcessing packets in batches is a common technique in high-speed software routers to improve routing efficiency and increase throughput. With the growing popularity of novel paradigms such as Network Function Virtualization, advocating for the replacement of hardware-based networking modules towards software-based network functions deployed on commodity servers, we observe that batching techniques have been successfully implemented to reduce the HW/SW performance gap. As batch creation and management is at the very core of high-speed packet processors, it provides a significant impact to the overall packet processing capabilities of the system, affecting latency, throughput, CPU utilization and power consumption. It is commonly accepted to adopt a fixed maximum batching size (usually in the range between 32 and 512) to optimize for the worst case scenario (i.e. minimum-size packets at full bandwidth capacity). Such approach may result in a loss of efficiency despite a 100% utilization of the CPU. In this work we explore the possibilities of enhancing the runtime batch creation in VPP, a popular software router based on the Intel DPDK framework. Instead of relying on the automatic batch creation, we apply machine learning techniques to optimize the batching size for lower CPU-time and higher power efficiency in average scenarios, while maintaining its high performance in the worst case. Peter Okelmann, Leonardo Linguaglossa, Fabien Geyer, Paul Emmerich, Georg Carle |
NetSoft | 5 |
| 2020 | NCSbench: Reproducible Benchmarking Platform for Networked Control SystemsabstractThe evolution of the Internet of Things accelerated the development of Cyber-Physical Systems. Among them, Networked Control Systems (NCS) gained notable attention thanks to their application to industrial operations. Experimental NCS require expertise from control, computation, and communication disciplines. This requirement, together with the fragmentation of implementation platforms and experimental investigations, represents a challenge for the reproducibility and comparison of research results. In this paper, we tackle this problem by proposing a novel NCS benchmarking methodology that aids the reproducibility of NCS experiments. Relying on a novel approach to model the architectural elements and the delays of NCS, the methodology defines the experiment parameters and the relevant Key Performance Indicators (KPIs) that need to be observed during its execution. Furthermore, we detail the implementation of the first reproducible benchmarking platform for NCS. The proposed platform is open-source and designed to be easily reproducible and extensible by anyone. Finally, we replicate and evaluate the platform following the proposed NCS benchmarking methodology. The experimental results evaluate and compare the KPIs during the execution of the platform in different benchmarking scenarios, proving the validity of the proposed benchmarking methodology. Samuele Zoppi, Onur Ayan, Fabio Molinari, Zenit Music, Sebastian Gallenmüller, Georg Carle, Wolfgang Kellerer |
CCNC | 6 |
| 2020 | NCSbench Demo: Reproducible Benchmarking Platform for Networked Control SystemsabstractCyber-Physical Systems (CPS) are widely spreading thanks to fast-paced technological breakthroughs of microcontrollers and communication networks. Among them, Networked Control Systems (NCS) gained notable attention thanks to their application in industrial operations. In NCS, the interconnection of a control logic with sensors and actuators used to steer a physical system occurs over a communication network. Despite large research interest on NCS, the reproducibility and comparison of experimental results are difficult to achieve. This is caused by the lack of well-established models and methodologies that combine the theoretical and practical aspects of NCS. We tackle this problem by proposing and demonstrating NCSbench: the first open-source reproducible benchmarking platform for NCS. NCSbench enables the benchmarking of research experiments using a networked two-wheeled inverted pendulum robot. For each benchmarking experiment, a set of values is measured and used to quantify the key performance indicators (KPIs) of the NCS. In our demonstration, we visualize in real-time the evolution of the benchmarking KPIs on a web-based Graphical User Interface. Samuele Zoppi, Onur Ayan, Fabio Molinari, Zenit Music, Sebastian Gallenmüller, Georg Carle, Wolfgang Kellerer |
CCNC | 6 |
| 2020 | Open-Source OPC UA Security and ScalabilityabstractOPC UA is widely adopted for remote-control in industrial environments. It has a central role for industrial control systems as it enables remote management. Compromising OPC UA can lead to compromising entire production facilities. Consequently, OPC UA requires a high level of security. Major commercial OPC UA implementations have compliance certificates ensuring that their security models obey the specification. However, open-source OPC UA implementations that have wide deployment mostly lack these certificates. In this work, we investigate the security models of the four most commonly used open-source implementations: open62541, node-opcua, UA-.NETStandard, and python-opcua. Furthermore, their scalabilities for the number of clients and OPC UA nodes are also analyzed. Nikolas Mühlbauer, Erkin Kirdan, Marc-Oliver Pahl, Georg Carle |
ETFA | 4 |
| 2020 | Performance Analysis of VPN Gateways
Maximilian Pudelko, Paul Emmerich, Sebastian Gallenmüller, Georg Carle |
Networking | 4 |
| 2020 | Online Monitoring of TCP Throughput LimitationsabstractMonitoring and optimizing network performance is essential for data center operators and service providers. To better understand network performance, the throughput limiting factor of TCP connections can be analyzed. Previous research introduces approaches for the offline analysis of root causes of TCP throughput based on previously captured traffic. With increasing computational power and packet processing capabilities on commodity hardware, previously existing analysis limitations get overcome nowadays.This paper presents a scalable tool to analyze the throughput limitation of TCP flows in real-time, i.e., while the tool observes traffic on a network interface. We describe the adaption of existing approaches for TCP throughput limitation analysis and required passive capacity estimation to satisfy online analysis requirements.We evaluate the effectiveness and accuracy of our implementation with a generated data set for different TCP congestion control algorithms and varying network parameters. Furthermore, we survey the performance of our implementation with thousands of concurrent flows and discuss trade-offs and limitations of such sophisticated analysis in real-time.We provide our code as free and open-source. Kilian Holzinger, Benedikt Jaeger, Paul Emmerich, Georg Carle |
NOMS | 5 |
| 2020 | 5G QoS: Impact of Security Functions on LatencyabstractNetwork slicing is considered a key enabler to 5th Generation (5G) communication networks. Mobile network operators may deploy network slices-complete logical networks customized for specific services expecting a certain Quality of Service (QoS). New business models like Network Slice-as-a-Service offerings to customers from vertical industries require negotiated Service Level Agreements (SLA), and network providers need automated enforcement mechanisms to assure QoS during instantiation and operation of slices. In this paper, we focus on ultra-reliable low-latency communication (URLLC). We propose a software architecture for security functions based on off-the-shelf hardware and open-source software and demonstrate, through a series of measurements, that the strict requirements of URLLC services can be achieved. As a real-world example, we perform our experiments using the intrusion prevention system (IPS) Snort to demonstrate the impact of security functions on latency. Our findings lead to the creation of a model predicting the system load that still meets the URLLC latency requirement. We fully disclose the artifacts presented in this paper including pcap traces, measurement tools, and plotting scripts at https://gallenmu.github.io/low-latency. Sebastian Gallenmüller, Johannes Naab, Iris Adam, Georg Carle |
NOMS | 4 |
| 2020 | Deep Clustering of Mobile Network Data with Sparse AutoencodersabstractUnsupervised machine learning methods, such as clustering algorithms could be powerful tools for automation. By simplifying data through structuring, these algorithms can help network management use-cases where autonomous agency or elevated levels of cognition is required. Recent developments in deep learning allow clustering algorithms to gain unprecedented insight into the data, creating meaningful clusters as a result. In this paper, we propose a Sparse Clustering Autoencoder, capable of autonomously encoding cell behavior into a graph-like representation we call Network State Transition Graphs. We compare our proposed algorithm against other deep learning-based clustering algorithms, and demonstrate its utility on data from a real, large-scale mobile network deployment. Marton Kajo, Benedek Schultz, Georg Carle |
NOMS | 3 |
| 2020 | Hardening X.509 Certificate Issuance using Distributed Ledger TechnologyabstractThe security of cryptographic communication protocols that use X.509 certificates depends on the correctness of those certificates. This paper proposes a system that helps to ensure the correct operation of an X.509 certification authority and its registration authorities. We achieve this goal by enforcing a policy-defined, multi-party validation and authorization workflow of certificate signing requests. Besides, our system offers full accountability for this workflow for forensic purposes. As a foundation for our implementation, we leverage the distributed ledger and smart contract framework Hyperledger Fabric. Our implementation inherits the strong tamper-resistance of Fabric which strengthens the integrity of the computer processes that enforce the validation and authorization of the certificate signing request, and of the metadata collected during certificate issuance. Holger Kinkelin, Richard von Seck, Christoph Rudolf, Georg Carle |
NOMS | 4 |
| 2020 | Environment Modeling and Abstraction of Network States for Cognitive FunctionsabstractCognitive Autonomous Networks (CANs) promise to overcome the shortcomings of current Self-Organizing Network (SON) implementations, i.e., the limited flexibility and adaptability to changing environments, by applying cognition. In CAN, intelligent network automation functions, herein called Cognitive Functions (CFs), apply machine learning techniques to learn context-specific behavioral policies with which to automate network operations. For proper operation, the CAN system needs to learn the environment in which the functions are operating and to abstract the environment and performance observations into states to which the CFs must respond. This paper proposes a design and implementation of an Environmental-state Modeling and Abstraction (EMA) engine that could be tasked to learn the required abstract states in a consistent way across multiple CFs. Stephen S. Mwanje, Marton Kajo, Sayantini Majumdar, Georg Carle |
NOMS | 4 |
| 2020 | Optimally Self-Healing IoT ChoreographiesabstractIn the industrial Internet of Things domain, applications are moving from the Cloud into the Edge, closer to the devices producing and consuming data. This means that applications move from the scalable and homogeneous Cloud environment into a potentially constrained heterogeneous Edge network. Making Edge applications reliable enough to fulfill Industry 4.0 use cases remains an open research challenge. Maintaining operation of an Edge system requires advanced management techniques to mitigate the failure of devices. This article tackles this challenge with a twofold approach: (1) a policy-enabled failure detector that enables adaptable failure detection and (2) an allocation component for the efficient selection of failure mitigation actions. The parameters and performance of the failure detection approach are evaluated, and the performance of an energy-efficient allocation technique is measured. Finally, a vision for a complete system and an example use case are presented. Jan Seeger, Arne Bröring, Georg Carle |
ACM Trans. Internet Techn. | 3 |
| 2019 | User Space Network DriversabstractThe rise of user space packet processing frameworks like DPDK and netmap makes low-level code more accessible to developers and researchers. Previously, driver code was hidden in the kernel and rarely modified-or even looked at-by developers working at higher layers. These barriers are gone nowadays, yet developers still treat user space drivers as black-boxes magically accelerating applications. We want to change this: every researcher building high-speed network applications should understand the intricacies of the underlying drivers, especially if they impact performance. We present ixy, a user space network driver designed for simplicity and educational purposes to show that fast packet IO is not black magic but careful engineering. ixy focuses on the bare essentials of user space packet processing: a packet forwarder including the whole NIC driver uses less than 1,000 lines of C code. This paper is partially written in tutorial style on the case study of our implementations of drivers for both the Intel 82599 family and for virtual VirtIO NICs. The former allows us to reason about driver and framework performance on a stripped-down implementation to assess individual optimizations in isolation. VirtIO support ensures that everyone can run it in a virtual machine. Our code is available as free and open source under the BSD license at https://github.com/emmericp/ixy. Paul Emmerich, Maximilian Pudelko, Thomas Zwickl, Georg Carle |
ANCS | 6 |
| 2019 | The Case for Writing Network Drivers in High-Level Programming LanguagesabstractDrivers are written in C or restricted subsets of C++ on all production-grade server, desktop, and mobile operating systems. They account for 66 % of the code in Linux, but 39 out of 40 security bugs related to memory safety found in Linux in 2017 are located in drivers. These bugs could have been prevented by using high-level languages for drivers. We present user space drivers for the Intel ixgbe 10 Gbit/s network cards implemented in Rust, Go, C#, Java, OCaml, Haskell, Swift, JavaScript, and Python written from scratch in idiomatic style for the respective languages. We quantify costs and benefits of using these languages: High-level languages are safer (fewer bugs, more safety checks), but run-time safety checks reduce throughput and garbage collection leads to latency spikes. Out-of-order CPUs mitigate the cost of safety checks: Our Rust driver executes 63 % more instructions per packet but is only 4 % slower than a reference C implementation. Go's garbage collector keeps latencies below 100 μs even under heavy load. Other languages fare worse, but their unique properties make for an interesting case study. All implementations are available as free and open source at https://githud.com/ixy-languages/ixy-languages. Paul Emmerich, Sebastian Voit, Georg Carle, Simon Ellmann, Fabian Bonk, Alex Egger, Esaú García Sánchez-Torija, Thomas Günzel, Sebastian Di Luzio, Alexandru Obada, Maximilian Stadlmeier |
ANCS | 3 |
| 2019 | Cryptographic Hashing in P4 Data PlanesabstractP4 introduces a standardized, universal way for data plane programming. Secure and resilient communication typically involves the processing of payload data and specialized cryptographic hash functions. We observe that current P4 targets lack the support for both. Therefore, applications and protocols, which require message authentication codes or hashing structures that are resilient against attacks such as denial-of-service, cannot be implemented. To enable authentication and resilience, we make the case for extending P4 targets with cryptographic hash functions. We propose an extension of the P4 Portable Switch Architecture for cryptographic hashes and discuss our prototype implementations for three different P4 target platforms: CPU, NPU, and FPGA. To assess the practical applicability, we conduct a performance evaluation and analyze the resource consumption. Our prototype implementations show that cryptographic hashing can be integrated efficiently. We cannot identify a single hash function delivering satisfying performance on all investigated platforms. Therefore, we recommend a set of hash functions to optimize target-specific performance. Dominik Scholz, Andreas Oeldemann, Fabien Geyer, Sebastian Gallenmüller, Henning Stubbe, Thomas Wild, Andreas Herkersdorf, Georg Carle |
ANCS | 8 |
| 2019 | Multi-party authorization and conflict mediation for decentralized configuration management processes
Holger Kinkelin, Heiko Niedermayer, Marc Müller, Georg Carle |
IM | 4 |
| 2019 | Data Querying and Access Control for Secure Multiparty Computation
Marcel von Maltitz, Georg Carle |
IM | 2 |
| 2019 | Adaptive Network Management for Safety-Critical Systems
Cora Lisa Perner, Holger Kinkelin, Georg Carle |
IM | 3 |
| 2019 | Prefix Top Lists: Gaining Insights with Prefixes from Domain-based Top Lists on DNS DeploymentabstractDomain-based top lists such as the Alexa Top 1M strive to portray the popularity of web domains. Even though their shortcomings (e.g., instability, no aggregation, lack of weights) have been pointed out, domain-based top lists still are an important element of Internet measurement studies. Johannes Naab, Patrick Sattler, Jonas Jelten, Oliver Gasser, Georg Carle |
Internet Measurement Conference | 5 |
| 2019 | A Generalized TDoA/ToA Model for ToF PositioningabstractMany applications require positioning. Time of Flight (ToF) methods calculate distances by measuring the propagation time of signals. We present a novel ToF localization method. Our new approach works infrastructure-less, without pre-defined roles like Anchors or Tags. It generalizes existing synchronization-less Time Difference of Arrival (TDoA) and Time of Arrival (ToA) algorithms. We show how known algorithms can be derived from our new method. A major advantage of our approach is that it provides a comparable or better clock error robustness, i.e. the typical errors of crystal oscillators have negligible impact for TDoA and ToA measurements. We show that our channel usage is for most cases superior compared to the state-of-the art. Maximilian von Tschirschnitz, Marcel Wagner, Marc-Oliver Pahl, Georg Carle |
IPIN | 4 |
| 2019 | Clock Error Analysis of Common Time of Flight based Positioning MethodsabstractToday, many applications such as production or rescue settings rely on highly accurate entity positioning. Advanced Time of Flight (ToF) based positioning methods provide high-accuracy localization of entities. A key challenge for ToF based positioning is to synchronize the clocks between the participating entities.This paper summarizes and analyzes ToA and TDoA methods with respect to clock error robustness. The focus is on synchronization-less methods, i.e. methods which reduce the infrastructure requirement significantly. We introduce a unified notation to survey and compare the relevant work from literature. Then we apply a clock error model and compute worst case location-accuracy errors. Our analysis reveals a superior error robustness against clock errors for so called Double-Pulse methods when applied to radio based ToF positioning. Maximilian von Tschirschnitz, Marcel Wagner, Marc-Oliver Pahl, Georg Carle |
IPIN | 4 |
| 2019 | Reproducible measurements of TCP BBR congestion control
Benedikt Jaeger, Dominik Scholz, Daniel Raumer, Fabien Geyer, Georg Carle |
Comput. Commun. | 5 |
| 2019 | Agile Network Access Control in the Container AgeabstractLinux containers, such as those managed by Docker, are an increasingly popular way to package and deploy complex applications. However, the fundamental security primitive of network access control for a distributed microservice deployment is often ignored or left to the network operations team. High-level application-specific security requirements are not appropriately enforced by low-level network access control lists. Apart from coarse-grained separation of virtual networks, Docker neither supports the application developer to specify nor the network operators to enforce fine-grained network access control between containers. In a fictional story, we follow DevOp engineer Alice through the lifecycle of a Web application. From the initial design and software engineering through network operations and automation, we show the task expected of Alice and propose tool-support to help. As a full-stack DevOp, Alice is involved in high-level design decisions as well as low-level network troubleshooting. Focusing on network access control, we demonstrate shortcomings in today's policy management and sketch a tool-supported solution. We survey related academic work and show that many existing tools fail to bridge between the different levels of abstractions a full-stack engineer is operating on. Our toolset is formally verified using Isabell/HOL and is available as an open source. Cornelius Diekmann, Johannes Naab, Andreas Korsten, Georg Carle |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2018 | Clusters in the Expanse: Understanding and Unbiasing IPv6 Hitlists
Oliver Gasser, Quirin Scheitle, Pawel Foremski, Qasim Lone, Maciej Korczynski, Stephen D. Strowes, Luuk Hendriks, Georg Carle |
Internet Measurement Conference | 8 |
| 2018 | The Rise of Certificate Transparency and Its Implications on the Internet Ecosystem
Quirin Scheitle, Oliver Gasser, Theodor Nolte, Johanna Amann, Lexi Brent, Georg Carle, Ralph Holz, Thomas C. Schmidt, Matthias Wählisch |
Internet Measurement Conference | 6 |
| 2018 | Building a Traffic Policer for DDoS Mitigation on Top of Commodity HardwareabstractTraffic policing is the process of ensuring that network traffic complies with its policies with methods like traffic shaping. As the distribution of sources involved in a DDoS attack differs significantly from the typical distribution of customers for web services, traffic shapers and policers can be used in DDoS mitigation. In the past, software-based middleboxes, like traffic shapers, easily became overloaded and therefore a vulnerability for DDoS attacks. Although recent advances in network stack design on commodity hardware increased the performance, the software on top of the network stack also needs to provide adequate throughput and scalability regarding the number of limited subnets. Therefore, we build a high-performance and scalable traffic policer called MoonPol and evaluated it in a DDoS mitigation scenario. MoonPol runs on any commodity hardware, takes advantage of the underlying framework, DPDK, and combines it with appropriate algorithms and data structures. Data structures for efficient lookups are implemented together with the token bucket algorithm to police a traffic of fine-grained IP address ranges. Benchmarking results show that the single core throughput of the policer running on a 3.2 GHz CPU, is 6.5 Mpps with limiting 1 Million subnets, i.e., 492 CPU cycles per packet. With 250K subnets of all countries in the world, the throughput is 6.66 Mpps. Erkin Kirdan, Daniel Raumer, Paul Emmerich, Georg Carle |
ISNCC | 4 |
| 2018 | RockFS: Cloud-backed File System Resilience to Client-Side AttacksabstractCloud-backed file systems provide on-demand, high-availability, scalable storage. Their security may be improved with techniques such as erasure codes and secret sharing to fragment files and encryption keys in several clouds. Attacking the server-side of such systems involves penetrating one or more clouds, which can be extremely difficult. David R. Matos, Miguel L. Pardal, Georg Carle, Miguel Correia 0001 |
Middleware | 3 |
| 2018 | Leveraging Secure Multiparty Computation in the Internet of ThingsabstractCentralized systems in the Internet of Things---be it local middleware or cloud-based services---fail to fundamentally address privacy of the collected data. We propose an architecture featuring secure multiparty computation at its core in order to realize data processing systems which already incorporate support for privacy protection in the architecture. Marcel von Maltitz, Georg Carle |
MobiSys | 2 |
| 2018 | Equal-volume quantization of mobile network data using bounding spheres and boxesabstractMobile network management systems often utilize quantization algorithms for abstraction and simplification of information, to be later processed by human operators or automated functions. In use cases such as visualization of high dimensional data or processing of anomalous observations, the off- the-shelf algorithms might produce misleading results, without the user realizing that the problem lies in the choice of the applied method. In this paper, we provide a quantization algorithm called Bounding Sphere Quantization (BSQ) that performs better than standard approaches when applied to these use cases, by minimizing the maximum error in the quantization. Since the proposed algorithm is computationally expensive, we also explore an alternative approach, which approximates the results achieved by BSQ while greatly reducing computational complexity. Our evaluation shows that BSQ provides more intuitive results that work better for the selected use cases when compared to the well-known k-Means algorithm. Marton Kajo, Benedek Schultz, Janne Ali-Tolppa, Georg Carle |
NOMS | 4 |
| 2018 | Trustworthy configuration management for networked devices using distributed ledgersabstractNumerous IoT applications, like building automation or process control of industrial sites, exist today. These applications inherently have a strong connection to the physical world. Hence, IT security threats cannot only cause problems like data leaks but also safety issues which might harm people. Attacks on IT systems are not only performed by outside attackers but also insiders like administrators. For this reason, we present ongoing work on a Byzantine fault tolerant configuration management system (CMS) that provides control over administrators, restrains their rights, and enforces separation of concerns. We reach this goal by conducting a configuration management process that requires multi-party authorization for critical configurations to prevent individual malicious administrators from performing undesired actions. Only after a configuration has been authorized by multiple experts, it is applied to the targeted devices. For the whole configuration management process, our CMS guarantees accountability and traceability. Lastly, our system is tamper-resistant as we leverage Hyperledger Fabric, which provides a distributed execution environment for our CMS and a blockchain-based distributed ledger that we use to store the configurations. A beneficial side effect of this approach is that our CMS is also suitable to manage configurations for infrastructure shared across different organizations that do not need to trust each other. Holger Kinkelin, Valentin Hauner, Heiko Niedermayer, Georg Carle |
NOMS | 4 |
| 2018 | A management framework for secure multiparty computation in dynamic environmentsabstractSecure multiparty computation (SMC) is a promising technology for privacy-preserving collaborative computation. In the last years several feasibility studies have shown its practical applicability in different fields. However, it is recognized that administration, and management overhead of SMC solutions are still a problem. A vital next step is the incorporation of SMC in the emerging fields of the Internet of Things and (smart) dynamic environments. In these settings, the properties of these contexts make utilization of SMC even more challenging since some vital premises for its application regarding environmental stability and preliminary configuration are not initially fulfilled. We bridge this gap by providing FlexSMC, a management and orchestration framework for SMC which supports the discovery of nodes, supports a trust establishment between them and realizes robustness of SMC session by handling nodes failures and communication interruptions. The practical evaluation of FlexSMC shows that it enables the application of SMC in dynamic environments with reasonable performance penalties and computation durations allowing soft real-time and interactive use cases. Marcel von Maltitz, Stefan Smarzly, Holger Kinkelin, Georg Carle |
NOMS | 4 |
| 2018 | In Log We Trust: Revealing Poor Security Practices with Certificate Transparency Logs and Internet Measurements
Oliver Gasser, Benjamin Hof, Max Helm, Maciej Korczynski, Ralph Holz, Georg Carle |
PAM | 6 |
| 2018 | Leveraging interconnections for performance: the serving infrastructure of a large CDNabstractToday's large content providers (CP) are busy building out their service infrastructures or "peering edges" to satisfy the insatiable demand for content created by an ever-expanding Internet edge. One component of these serving infrastructures that features prominently in this build-out is their connectivity fabric; i.e., the set of all Internet interconnections that content has to traverse en route from the CP's various "deployments" or "serving sites" to end users. However, these connectivity fabrics have received little attention in the past and remain largely ill-understood. Florian Wohlfart, Nikolaos Chatzis, Caglar Dabanoglu, Georg Carle, Walter Willinger |
SIGCOMM | 4 |
| 2018 | Verified iptables Firewall Analysis and VerificationabstractThis article summarizes our efforts around the formally verified static analysis of iptables rulesets using Isabelle/HOL. We build our work around a formal semantics of the behavior of iptables firewalls. This semantics is tailored to the specifics of the filter table and supports arbitrary match expressions, even new ones that may be added in the future. Around that, we organize a set of simplification procedures and their correctness proofs: we include procedures that can unfold calls to user-defined chains, simplify match expressions, and construct approximations removing unknown or unwanted match expressions. For analysis purposes, we describe a simplified model of firewalls that only supports a single list of rules with limited expressiveness. We provide and verify procedures that translate from the complex iptables language into this simple model. Based on that, we implement the verified generation of IP space partitions and minimal service matrices. An evaluation of our work on a large set of real-world firewall rulesets shows that our framework provides interesting results in many situations, and can both help and out-compete other static analysis frameworks found in related work. Cornelius Diekmann, Lars Hupel, Julius Michaelis, Max W. Haslbeck, Georg Carle |
J. Autom. Reason. | 5 |
| 2017 | Mind the Gap - A Comparison of Software Packet GeneratorsabstractNetwork research relies on packet generators to assess performance and correctness of new ideas. Software-based generators in particular are widely used by academic researchers because of their flexibility, affordability, and open-source nature. The rise of new frameworks for fast IO on commodity hardware is making them even more attractive. Longstanding performance differences of software generation versus hardware in terms of throughput are no longer as big of a concern as they used to be few years ago. This paper investigates the properties of several high-per-formance software packet generators and the implications on their precision when a given traffic pattern needs to be generated. We believe that the evaluation strategy presented in this paper helps understanding the actual limitations in high-performance software packet generation, thus helping the research community to build better tools. Paul Emmerich, Sebastian Gallenmüller, Gianni Antichi, Andrew W. Moore 0002, Georg Carle |
ANCS | 5 |
| 2017 | Building Fast but Flexible Software RoutersabstractCreating quick and dirty prototypes is a simple and effective way to demonstrate the feasibility of new ideas in network research. Though, small scale proof-of-concepts may lack the performance needed to apply them to real world test cases. Thanks to powerful packet processing frameworks such as netmap and DPDK, high-performance packet forwarding systems can be implemented in software today. We present MoonRoute, a framework dedicated to developing powerful software routers. It is built on top of DPDK and utilizes a highly parallelized architecture to achieve high performance (see Section 2).MoonRoute offers methods to reuse existing libraries and a scripting interface for easy extensibility (see Section 3). An example implementation based on the MoonRoute framework is carefully evaluated to demonstrate the performance and compare it to other relevant software routers (see Section 4). The entire MoonRoute framework including a reference implementation of a software router is available as free software under MIT license [2]. A technical report featuring details about our architecture and more profiling results is available [1]. Sebastian Gallenmüller, Paul Emmerich, Rainer Schonberger, Daniel Raumer, Georg Carle |
ANCS | 5 |
| 2017 | Privacy Assessment Using Static Taint Analysis (Tool Paper)
Marcel von Maltitz, Cornelius Diekmann, Georg Carle |
FORTE | 3 |
| 2017 | An experimental system for verifying topology changes in mobile communication networksabstractAutomatic Configuration Management (CM) parameter change assessment, the so-called Self-Organizing Network (SON) verification, is an important enabler for stable and high-quality modern mobile communication networks. However, it also presents a new set of challenges. While improving network stability and resolving unexpected conflicts caused by parallel configuration changes, SON verification can have trouble coping with very dynamic networks that exhibit frequent topology changes. Such changes can be, for example, due to energy saving features which try to maximize the energy efficiency of a mobile network by adapting the topology to the network traffic. The experimental system presented in this paper demonstrates a new paradigm for handling such changes. It extends the currently available SON verification principles by providing a solution for the assessment of the impact of topology changes and for correcting them, in case the changes lead to degraded performance. The system includes a wide variety of visualization capabilities, including the various network states, user behavior, and performance statistics. Tsvetko Tsvetkov, Janne Ali-Tolppa, Henning Sanneck, Georg Carle |
IM | 4 |
| 2017 | Mission accomplished?: HTTPS security after diginotarabstractDriven by CA compromises and the risk of man-in-the-middle attacks, new security features have been added to TLS, HTTPS, and the web PKI over the past five years. These include Certificate Transparency (CT), for making the CA system auditable; HSTS and HPKP headers, to harden the HTTPS posture of a domain; the DNS-based extensions CAA and TLSA, for control over certificate issuance and pinning; and SCSV, for protocol downgrade protection. Johanna Amann, Oliver Gasser, Quirin Scheitle, Lexi Brent, Georg Carle, Ralph Holz |
Internet Measurement Conference | 5 |
| 2016 | A Steiner tree-based verification approach for handling topology changes in self-organizing networksabstractIn today's Self-Organizing Networks (SONs) we differentiate between closed-loop functions, which have a predefined absolute goal, and such that form an action plan that achieves a high expected utility. Both function types perform changes to Configuration Management (CM) parameters, but only the second type may re-adapt the action plan in order to maximize the utility. A SON verification approach is one member of this particular function class. It is seen as a special type of anomaly detection that divides the network into sets of cells, triggers an anomaly detection algorithm for those sets, and finally generates CM undo actions for the abnormally performing cells. Unfortunately, one of the challenges verification strategies are facing are network topology changes. Typically, cells are switched on or off when energy saving features are enabled. However, enabling or disabling cells can negatively influence a verification mechanism which may create a suboptimal action plan or even blame certain CM changes that actually did not harm performance. In order to overcome this issue, we present an approach that is based on Steiner trees. In graph theory, a Steiner tree is a Minimum Spanning Tree (MST) whose costs can be reduced by adding additional vertexes to the graph. We use this tree to filter out anomalies caused by topology adjustments and such induced by other CM changes. In this paper, we also evaluate the proposed solution in several scenarios. First, in a simulation study we evaluate the functions that are used to build the Steiner tree. Second, we show how it positively affects the network performance when having concurrent CM and topology changes. Tsvetko Tsvetkov, Janne Ali-Tolppa, Henning Sanneck, Georg Carle |
CNSM | 4 |
| 2016 | Rate-Adaptive Link Quality Estimation for Coded Packet NetworksabstractCoded packet networks allow for proactive injection of redundant packets to compensate for packet loss. Link metrics are usually based on the estimated transmission counter (ETX). This metric is used to determine the expected number of coded packets needed, but does not make guarantees for a specific decoding probability. In this paper we show that relying on the ETX metric leads to a surprisingly high probability that decoding is not possible. Based on this result, we derive a redundancy scheme to allow for an adjustable decoding probability. In a third step, we extend this scheme to also consider the reliability of link quality estimates themselves. We provide a numerically stable and hardware-accelerated implementation of our redundancy scheme, and compare all approaches in a simulated environment. Finally, we show the effect of the new redundancy scheme on different transport layer protocols in a wireless setup with random linear network coding. Maurice Leclaire, Stephan M. Günther, Marten Lienen, Maximilian Riemensberger, Georg Carle |
LCN | 5 |
| 2016 | Anomaly detection for SOME/IP using complex event processingabstractRecent developments favor the adoption of IP-based protocols in automotive and aerospace domains. The increased connectivity between components helps to cut costs and enables better re-use of standardized components. However, increased connectivity also increases the attack surface of the overall system and necessitates dedicated security solutions. This paper presents an anomaly detection system for SOME/IP, a standardized automotive middleware protocol. Within the system, Esper, a complex event processing engine, applies a domain-specific rule set to a stream of SOME/IP packets. Possible attacks and protocol violations on the SOME/IP protocol are identified, suitable rules for detection are presented, and finally, the performance of the system is evaluated. Nadine Herold, Stephan-Alexander Posselt, Oliver Hanka, Georg Carle |
NOMS | 4 |
| 2016 | Distributed smart space orchestrationabstractMany networked devices that can interface their physical environments are available off-the-shelf or can be built in 2016. A comprehensive management of those Smart Devices is required to unlock the existing potential. However, the amount and heterogeneity of the devices make their management difficult. A suitable abstraction is missing. This paper identifies requirements on managing Smart Devices from diverse research fields, assesses relevant existing work, proposes a new management middleware design, and evaluates it quantitatively and qualitatively. The presented novel middleware architecture could become an enabler for a software maker culture. Marc-Oliver Pahl, Georg Carle, Gudrun Klinker |
NOMS | 2 |
| 2016 | A minimum spanning tree-based approach for reducing verification collisions in self-organizing networksabstractThe verification of Configuration Management (CM) changes has become an important step in the operation of a mobile Self-Organizing Network (SON). Typically, a verification mechanism operates in three phases. At first, it partitions the network into verification areas, then it triggers an anomaly detection algorithm for those areas, and finally generates CM undo requests for the abnormally performing ones. Those requests set the CM parameters to a previous stable state. However, verification areas may overlap and share anomalous cells which results in a verification collision. As a consequence, the verification mechanism is not able to simultaneously deploy the undo requests since there is an uncertainty which to execute and which to potentially omit. In such a case, it has to serialize the deployment process and resolve the collisions. This procedure, though, can be negatively impacted if unnecessary collisions are processed, since they might delay the execution of the queued CM undo requests. To overcome this issue, we propose an approach for changing the size of the verification areas with respect to the detected collisions. We achieve our goal by using a Minimum Spanning Tree (MST)-based clustering approach that is able to group similarly behaving cells together. Based on the group they have been assigned to, we remove cells from a verification area and prevent false positive collisions from being further processed. Furthermore, we evaluate the proposed solution in two different scenarios. First, we highlight its benefits by applying it on CM and Performance Management (PM) data collected from a real Long Term Evolution (LTE) network. Second, in a simulation study we show how it positively affects the network performance after eliminating the false positives. Tsvetko Tsvetkov, Janne Ali-Tolppa, Henning Sanneck, Georg Carle |
NOMS | 4 |
| 2016 | Analyzing Locality of Mobile Messaging Traffic using the MATAdOR Framework
Quirin Scheitle, Matthias Wachs, Johannes Zirngibl, Georg Carle |
PAM | 4 |
| 2016 | GPLMT: A Lightweight Experimentation and Testbed Management Framework
Matthias Wachs, Nadine Herold, Stephan-Alexander Posselt, Florian Dold, Georg Carle |
PAM | 5 |
| 2016 | TinyIPFIX: An efficient application protocol for data exchange in cyber physical systems
Corinna Schmitt, Thomas Kothmayr, Benjamin Ertl, Wen Hu 0001, Lothar Braun, Georg Carle |
Comput. Commun. | 6 |
| 2016 | HEAP: Reliable Assessment of BGP Hijacking AttacksabstractThe detection of BGP prefix hijacking attacks has been the focus of research for more than a decade. However, the state-of-the-art techniques fall short of detecting more elaborate types of attack. To study such attacks, we devise a novel formalization of Internet routing, and apply this model to routing anomalies in order to establish a comprehensive attacker model. We use this model to precisely classify attacks and to evaluate their impact and detectability. We analyze the eligibility of attack tactics that suit an attacker's goals and demonstrate that related work mostly focuses on less impactful kinds of attacks. We further propose, implement, and test the Hijacking Event Analysis Program (HEAP), a new approach to investigate hijacking alarms. Our approach is designed to seamlessly integrate with the previous work in order to reduce the high rates of false alarms inherent to these techniques. We leverage several unique data sources that can reliably disprove malicious intent. First, we make use of an Internet routing registry to derive business or organizational relationships between the parties involved in an event. Second, we use a topology-based reasoning algorithm to rule out events caused by legitimate operational practice. Finally, we use Internet-wide network scans to identify SSL/TLS-enabled hosts, which helps to identify non-malicious events by comparing public keys prior to and during an event. In our evaluation, we prove the effectiveness of our approach, and show that day-to-day routing anomalies are harmless for the most part. More importantly, we use HEAP to assess the validity of publicly reported alarms. We invite researchers to interface with HEAP in order to crosscheck and narrow down their hijacking alerts. Johann Schlamp, Ralph Holz, Quentin Jacquemart, Georg Carle, Ernst W. Biersack |
IEEE J. Sel. Areas Commun. | 4 |
| 2016 | Verification of Configuration Management Changes in Self-Organizing NetworksabstractThe verification of configuration management (CM) changes is an essential operation in a mobile self-organizing network (SON). Usually, a verification approach operates in three steps: it divides the network into verification areas, triggers an anomaly detection algorithm for those areas, and finally generates CM undo requests for the abnormally performing ones. Those requests set CM parameters to a previous stable state. However, the successful completion of this process can be quite challenging, since there are factors that might negatively impact its outcome. For instance, if a temporal degradation occurs during the optimization of a cell, a verification mechanism may wrongly assume that it is anomalous, and interrupt the optimization process. Furthermore, a verification strategy experiences difficulties when it faces verification collisions, i.e., conflicting undo requests that cannot be simultaneously deployed. At first, it has to determine whether the collision is a false positive one. Then, it has to resolve it by finding out which requests have the highest probability of restoring the network performance. In addition, it needs to consider the time that is given for rolling back CM changes. In this paper, we contribute to the area of SON verification by providing a solution that addresses those problems. Our approach makes use of constraint optimization techniques to resolve collisions as well as find the appropriate order for deploying undo requests. In addition, we use a minimum spanning tree-based clustering technique to eliminate false positive collisions. Further, we evaluate our solution in a simulation study in which we show its positive effect on the network performance. Tsvetko Tsvetkov, Janne Ali-Tolppa, Henning Sanneck, Georg Carle |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2015 | Comparison of Frameworks for High-Performance Packet IOabstractNetwork stacks currently implemented in operating systems can no longer cope with the packet rates offered by 10 Gbit Ethernet. Thus, frameworks were developed claiming to offer a faster alternative for this demand. These frameworks enable arbitrary packet processing systems to be built from commodity hardware handling a traffic rate of several 10 Gbit interfaces, entering a domain previously only available to custom-built hardware. In this paper, we survey various frameworks for high-performance packet IO. We analyze the performance of the most prominent frameworks based on representative measurements in packet forwarding scenarios. Therefore, we quantify the effects of caching and look at the tradeoff between throughput and latency. Moreover, we introduce a model to estimate and assess the performance of these packet processing frameworks. Sebastian Gallenmüller, Paul Emmerich, Florian Wohlfart, Daniel Raumer, Georg Carle |
ANCS | 5 |
| 2015 | Demonstrating topoS: Theorem-prover-based synthesis of secure network configurationsabstractIn network management, when it comes to security breaches, human error constitutes a dominant factor. We present our tool topoS which automatically synthesizes low-level network configurations from high-level security goals. The automation and a feedback loop help to prevent human errors. Except for a last serialization step, topoS is formally verified with Isabelle/HOL, which prevents implementation errors. In a case study, we demonstrate topoS by example. For the first time, the complete transition from high-level security goals to both firewall and SDN configurations is presented. Cornelius Diekmann, Andreas Korsten, Georg Carle |
CNSM | 3 |
| 2015 | Certifying spoofing-protection of firewallsabstractWe present an algorithm to certify IP spoofing protection of firewall rulesets. The algorithm is machine-verifiably proven sound and its use is demonstrated in real-world scenarios. Cornelius Diekmann, Lukas Schwaighofer, Georg Carle |
CNSM | 3 |
| 2015 | Performance benchmarking of a software-based LTE SGWabstractNetwork Functions Virtualization (NFV) is a concept that aims at providing network operators with benefits in terms of cost, flexibility, and vendor independence by utilizing virtualization techniques to run network functions as software on commercial off-the-shelf (COTS) hardware. In contrast, prior solutions rely on specialized hardware for each function. Performance evaluation of such systems usually requires a dedicated testbed for each individual component. Rather than analyzing these proprietary black-box components, Virtualized Network Functions (VNFs) are pieces of software that run on COTS hardware and whose properties can be investigated in a generic testbed. However, depending on the underlying hardware, operating system, and implementation, VNFs might behave differently. Therefore, mechanisms for the performance evaluation of VNFs should be similar to benchmarking of software, where different implementations are compared by applying them to predefined test cases and scenarios. This work presents a first step towards a benchmarking framework for VNFs. Given two different implementations of a VNF that acts as LTE Serving Gateway (SGW), influence factors and key performance indicators are identified and a comparison between the two mechanisms is drawn. Stanislav Lange, Anh Nguyen-Ngoc, Steffen Gebert, Thomas Zinner, Michael Jarschel, Andreas Köpsel, Marc Suñé, Daniel Raumer, Sebastian Gallenmüller, Georg Carle, Phuoc Tran-Gia |
CNSM | 10 |
| 2015 | Semantics-Preserving Simplification of Real-World Firewall Rule Sets
Cornelius Diekmann, Lars Hupel, Georg Carle |
FM | 3 |
| 2015 | A Constraint Optimization-Based Resolution of Verification Collisions in Self-Organizing NetworksabstractThe verification of Configuration Management (CM) changes is an important step in the operation of a Self-Organizing Network (SON). In order to perform its tasks, a verification mechanism makes use of an observation and a correction time window. In the first window it assesses the impact of deployed CM changes by monitoring the network's Performance Management (PM) data. Furthermore, it partitions the network in one or more verification areas, detects anomalies within them, and generates CM undo requests, each having the purpose to set CM parameters to some previous state. In the second window it deploys those requests to the network. However, two or more verification areas might be overlapping and share anomalous cells. As a consequence, we have verification collisions preventing two or more generated CM undo requests to be deployed at same time. Thereby, the verification mechanism might not be able to deploy all generated CM undo actions for the given correction window. In this paper, we propose a method that makes use of constraint optimization techniques to identify which requests can be merged together in order to meet the time requirement. We achieve our goal by using constraint softening based on so-called performance rating values of the requests. We evaluate our method in two different scenarios. First, we highlight the need for handling verification collisions by observing CM and PM data of a real Long Term Evolution (LTE) network. Second, a simulation study shows the ability of our method to keep the network performance at a high level. Tsvetko Tsvetkov, Georg Carle, Christoph Frenzel, Henning Sanneck |
GLOBECOM | 2 |
| 2015 | A graph coloring approach for scheduling undo actions in self-organizing networksabstractIn a mobile Self-Organizing Network (SON) a coordinator is necessary to avoid the execution of conflicting SON function instances. Typically, such a coordinator bases its decision to accept or reject a network parameter change request on a rule set that considers only known conflicts. Moreover, it does not observe the impact of approved changes on the network. For this reason, SON verification approaches have been specified to assess the impact of deployed configuration changes and identify those that are causing an undesired network behavior. Similarly to anomaly detection techniques, a SON verification mechanism has a mathematical model that specifies how the network behavior should look like and defines any behavior that significantly deviates form the expectations as abnormal. Furthermore, the outcome is a corrective action, also called an undo action, that sets network parameters to some previous configuration. The question that often remains unanswered is how conflicting undo actions should be scheduled. A SON coordinator does not have the knowledge to resolve them and may, therefore, prevent such from being deployed. In this paper we present a scheduling approach of such undo actions that uses minimum graph coloring in order to identify the sets of cells whose configuration can be safely rolled back. Our evaluation is split in two parts. In the first part we highlight the importance of our approach by observing a real Long Term Evolution (LTE) network. The second part is based on simulation data in which we show the ability of our method to keep the performance of the network at a high level. Tsvetko Tsvetkov, Henning Sanneck, Georg Carle |
IM | 3 |
| 2015 | MoonGen: A Scriptable High-Speed Packet GeneratorabstractWe present MoonGen, a flexible high-speed packet generator. It can saturate 10 GbE links with minimum-sized packets while using only a single CPU core by running on top of the packet processing framework DPDK. Linear multi-core scaling allows for even higher rates: We have tested MoonGen with up to 178.5 Mpps at 120 Gbit/s. Moving the whole packet generation logic into user-controlled Lua scripts allows us to achieve the highest possible flexibility. In addition, we utilize hardware features of commodity NICs that have not been used for packet generators previously. A key feature is the measurement of latency with sub-microsecond precision and accuracy by using hardware timestamping capabilities of modern commodity NICs. We address timing issues with software-based packet generators and apply methods to mitigate them with both hardware support and with a novel method to control the inter-packet gap in software. Features that were previously only possible with hardware-based solutions are now provided by MoonGen on commodity hardware. MoonGen is available as free software under the MIT license in our git repository at https://github.com/emmericp/MoonGen Paul Emmerich, Sebastian Gallenmüller, Daniel Raumer, Florian Wohlfart, Georg Carle |
Internet Measurement Conference | 5 |
| 2015 | Towards carrier grade SDNs
Syed Naveed Rizvi, Daniel Raumer, Florian Wohlfart, Georg Carle |
Comput. Networks | 4 |
| 2014 | MonSamp: an SDN Application for QoS MonitoringabstractSoftware Defined Networks are intended to be less complex, more flexible, and free of vendor-lock-ins. Therefore the Software Defined Networking (SDN) instantiation OpenFlow has been designed according to these properties. The efforts are expected to result in lower expenditure and operational costs. To reach these objectives, mechanisms of classical networks that provide established functionalities have to be revalued and either transformed or redesigned from scratch to take advantage from SDNs. In this paper we describe our vision on flow sampling suitable for traffic monitoring in those networks. Without the loss of generality our approach was specifically created to monitor the quality of service for flows. We describe monitoring as one of possibly many applications that communicate with the SDN controller via the SDN Northbound API. We implemented a prototype SDN application called MonSamp and performed tests to demonstrate the feasibility of our concept. Daniel Raumer, Lukas Schwaighofer, Georg Carle |
FedCSIS | 3 |
| 2014 | Verifying Security Policies Using Host Attributes
Cornelius Diekmann, Stephan-Alexander Posselt, Heiko Niedermayer, Holger Kinkelin, Oliver Hanka, Georg Carle |
FORTE | 6 |
| 2014 | Malicious BGP hijacks: Appearances can be deceivingabstractBGP hijacking is a well known threat to the Internet routing infrastructure. There has been considerable interest in developing tools that detect prefix hijacking but such systems usually identify a large number of events, many of them being due to some benign BGP engineering practice or misconfiguration. Ramachandran et al. [1] and later Hu et al. [2] also correlated suspicious routing events with spam and claimed to have found evidence of spammers temporarily stealing prefixes to send spam. In an effort to study at large scale the existence and the prevalence of malicious BGP hijacks in the Internet we developed a system which (i) identifies hijacks using BGP, traceroute and IRR data and (ii) investigates traffic originating from the reported networks with spam and netflow data. In this paper we present a real case where suspicious BGP announcements coincided with spam and web scam traffic from corresponding networks. Through this case study we show that a correlation of suspicious routing events with malicious activities is insufficient to evidence harmful BGP hijacks. We thus question previously reported cases and conclude that identifying malicious BGP hijacks requires additional data sources as well as feedback from network owners in order to reach decisive conclusions. Pierre-Antoine Vervier, Quentin Jacquemart, Johann Schlamp, Olivier Thonnard, Georg Carle, Guillaume Urvoy-Keller, Ernst W. Biersack, Marc Dacier |
ICC | 5 |
| 2014 | Towards stochastic flow-level network modeling: Performance evaluation of short TCP flowsabstractWe present in this paper a stochastic flow-level network model for the performance evaluation of IP networks with multiple bottlenecks supporting short-lived and long-lived TCP flows. Flow-level network models are efficient at estimating the mean bandwidth of TCP flows in various topologies, but they are generally limited to the study of infinite flows. This paper extends such models in order to evaluate short-lived flows alternating between idle and active periods where data of random size is transferred. We study the interaction between multiple flows and derive mean bandwidths, durations of file transfer or average number of active flows. We first study a single bottleneck, and then extend our analysis to networks with multiple bottlenecks as well as the effect of slow-start. We apply our results to various networks and assess the accuracy of our approach by comparing our analytical results with results of the discrete event simulator ns-2. Fabien Geyer, Stefan Schneele, Georg Carle |
LCN | 3 |
| 2014 | A deeper understanding of SSH: Results from Internet-wide scansabstractUntil recently, relatively little was known about the characteristics of the SSH protocol on the Internet, until two larger studies analysed the cryptographic properties of SSH host keys and identified weaknesses in a number of SSH devices. However, there is no succinct comprehensive image yet how the SSH landscape looks like from the point of view of deployment practices, especially with respect to key management. In this paper, we present the results of Internet-wide SSH scans that we carried out over a period of 7 months, which resulted in the largest data set to date. We enriched our data set with large-scale mappings obtained from DNS scans, AS and WHOIS lookups, and a geo-IP database. We analysed the distribution of server and protocol versions, and found that while SSH 2 has displaced SSH 1, the rate of software updates seems to be slow. We analysed the mentioned cryptographic weaknesses and found they have become fewer, but continue to persist one year after the disclosure. Finally, we investigated the reasons for duplicate yet cryptographically strong keys. We found these are used in very different setups at varying degrees of security. Some are indeed dangerous weaknesses, others are the result of a careful and centralised setup. By example of the ten most common keys, we show the circumstances in which they occur and assess the security of each deployment. Finally, we analysed the deployment of ciphers and associated key lengths and found good results in terms of security. As our scans are of a sensitive nature, we also document the ethical considerations that guided us. Oliver Gasser, Ralph Holz, Georg Carle |
NOMS | 3 |
| 2014 | Analysis of injection capabilities and media access of IEEE 802.11 hardware in monitor modeabstractSupport for monitor mode and frame injection is key to setup wireless testbeds based on IEEE802.11 hardware that allow implementation and evaluation of custom link-layer protocols, e.g. network coding, opportunistic routing, and software defined networking. While monitor mode is a widely supported feature, frame injection seems to be limited to legacy data rates in the 2.4GHz band if supported at all. In addition we found that many devices do not adhere to basic media access procedures when operating in monitor mode, which has severe effects in contended environments. In this paper we investigate the injection capabilities and MAC procedures of different chipsets. To enable IEEE802.11n rates and 5GHz, we developed a series of small patches, which mostly apply to the generic part of the Linux drivers. In addition we present a command line tool for automated evaluation of injection capabilities of different devices. The patches, tools, and the underlying injection library used in this paper are publicly available [1]. Stephan M. Günther, Maurice Leclaire, Julius Michaelis, Georg Carle |
NOMS | 4 |
| 2014 | Crowdsourced context-modeling as key to future smart spacesabstractManaging smart spaces with software requires the acquisition and processing of context information about a space. To be usable for exchanging information, a context representation has to be structured with a context model. Existing context-modeling techniques usually require experts and lack support for collaborative distributed creation, which prevents a crowdsourced development in a distributed collaborative way by non-experts. To facilitate context modeling, this paper presents a hybrid meta model that combines features from key-value, markup, object oriented, and ontology based context-modeling approaches. An architecture is introduced that allows the dynamic collaborative extension and crowdsourced convergence of context models. Marc-Oliver Pahl, Georg Carle |
NOMS | 2 |
| 2014 | Detection and resolution of ineffective function behavior in Self-Organizing NetworksabstractThe Self-Organizing Network (SON) paradigm enables automated management of next generation mobile communication networks by introducing a set of autonomous functions that jointly achieve self-configuration, self-optimization, and self-healing. Each SON function is driven by a specific objective to optimize one or more Key Performance Indicators (KPIs). If a function encounters situations in which the given targets cannot be achieved, it can produce undesired behavior, resulting in an impaired SON. This paper presents the idea of SON Operational Troubleshooting function and outlines a concept for the automatic detection, analysis, and mitigation of operational problems. Christoph Frenzel, Tsvetko Tsvetkov, Henning Sanneck, Bernhard Bauer 0001, Georg Carle |
WoWMoM | 5 |
| 2013 | CoMaDa: An adaptive framework with graphical support for Configuration, Management, and Data handling tasks for wireless sensor networksabstractNowadays, users request comfortable frameworks and development environments independent of the applications. Those solutions should offer as many support as possible, should be user friendly, and allow manipulation and visualization of different things at the same time. Those requirements become very important in the area of wireless sensor networks due to different vendors, wide range of application field, and the high amount of collected data. Currently existing solutions cover only a limited range of service and are usually fixed on hardware, operating system or application. In order to offer the user the wide range of flexibility the CoMaDa framework was developed, which is presented in this paper and combines all above mentioned user requirements by working with virtual representation of real wireless sensor networks and support in real time. CoMaDa offers the user support for configuration of components, network management functionalities, and data visualization at the same time. CoMaDa is build in a flexible way, which allows the user to integrate new features (e.g. personal code, hardware support, visualization option) with less input and, therefore, adapt the existing CoMaDa to every setup as requested. Corinna Schmitt, Andre Freitag, Georg Carle |
CNSM | 3 |
| 2013 | QoS-aware optimal resilient virtual networksabstractNetwork virtualization is seen as a possible solution to the ossification problem of the Internet by providing flexible and scalable virtual networks running over heterogeneous physical infrastructure. As for today's networks, it is very crucial to evaluate the virtual networks' adaptability to fulfill the demanding quality requirements of the diverse service offers. In addition, such an environment should promote protection strategies to face the unpredictable network failures, which cause significant service interruptions and consequently lead to definite revenue losses. Therefore, we introduce Quality of Service (QoS) modeling in virtual networks and provide three novel QoS-aware, resilient and cost-optimal virtual network design solutions. Through comprehensive simulations we show the necessity for such QoS models in virtual networks, where a no-QoS model fails to meet the requirements of 76% of the services for some service distributions. Finally, we compare the performance of the three proposed solutions having QoS-guarantees and resilience at different virtualization layers and show that there is a trade-off between virtual network cost and network utilization. Arsany Basta, Isil Burcu Barla Harter, Marco Hoffmann, Georg Carle |
ICC | 4 |
| 2013 | Adaptive load-aware sampling for network monitoring on multicore commodity hardware
Lothar Braun, Cornelius Diekmann, Nils Kammenhuber, Georg Carle |
Networking | 4 |
| 2013 | DTLS based security and two-way authentication for the Internet of Things
Thomas Kothmayr, Corinna Schmitt, Wen Hu 0001, Michael Brünig, Georg Carle |
Ad Hoc Networks | 5 |
| 2012 | X.509 Forensics: Detecting and Localising the SSL/TLS Men-in-the-Middle
Ralph Holz, Thomas Riedmaier, Nils Kammenhuber, Georg Carle |
ESORICS | 4 |
| 2012 | Delay Performance of Resilient Cloud Services over NetworksabstractEven though both delay and availability are of high importance for cloud services, it is mostly impossible today to guarantee a certain latency and availability for end-to-end cloud services traversing the telecommunication networks. An enabler is network virtualization with isolated virtual networks and combined control for network and IT resources. In this paper, we introduce two fundamental architectural alternatives in resilience design for cloud services using virtual networks, where in the former, resilience is provided solely by the physical infrastructure provider and in the latter only by the virtual network operator. We show that the resilience design plays a key role in terms of latency of the cloud services. Our simulation results show that the guaranteed maximum delay for the cloud services can differ by more than 90% depending on the implemented resilience design. This can have a big impact on the service performance in large networks especially for today's applications, where each millisecond might count. Isil Burcu Barla Harter, Dominic A. Schupke, Georg Carle |
ISPA | 3 |
| 2012 | Network Calculus and mixed-integer LP applied to a switched aircraft cabin networkabstractThis work addresses the applicability of a switched queuing network as the sole communication network in an aircraft cabin, and proposes an algorithm based on a mixed-integer program to determine hard bounds for the end-to-end delay. These hard bounds guarantee mandatory performance bounds for safety-relevant functions in the aircraft cabin, such as audio announcements or smoke detection. Techniques from the field of deterministic Network Calculus are used to benchmark the results from our novel approach. The results show that our solution allows improved mapping of non-preemptive queuing networks, compared to relevant state-of-the-art approaches. Emanuel Heidinger, Nils Kammenhuber, Alexander Klein, Georg Carle |
IWQoS | 4 |
| 2012 | Resilient Virtual Network Design for End-to-End Cloud Services
Isil Burcu Barla Harter, Dominic A. Schupke, Georg Carle |
Networking (1) | 3 |
| 2012 | Analyzing caching benefits for YouTube traffic in edge networks - A measurement-based evaluationabstractRecent studies observed video download platforms which contribute a large share to the overall traffic mix in today's operator networks. Traffic related to video downloads has reached a level where operators, network equipment vendors, and standardization organizations such as the IETF start to explore methods in order to reduce the traffic load in the network. Success or failure of these techniques depend on caching potentials of the target applications' traffic patterns. Our work aims at providing detailed insight into caching potentials of one of the leading video serving platforms: YouTube. We monitored interactions of users of a large operator network with the YouTube video distribution infrastructure for the time period of one month. From these traffic observations, we examine parameters that are relevant to the operation and effectiveness of an in-network cache deployed in an edge-network. Furthermore, we use our monitoring data as input for a simulation and determine the caching benefits that could have been observed if caching had been deployed. Lothar Braun, Alexander Klein, Georg Carle, Helmut Reiser, Jochen Eisl |
NOMS | 3 |
| 2012 | Spring-based geolocationabstractGiven an IP address, it is a challenging task to obtain its geographic location. Besides approaches which associate coordinates with IP addresses in a predominantly static way, there are also measurement based approaches that exploit the correlation between the propagation delay of signals and round trip times of probe packets. We analyze multiple approaches solely based on delay measurements, i. e. without the use of third-party knowledge, and obtain mean errors of just under 100 km. In this paper, we propose a new model for IP geolocation which combines the strengths of different previous techniques and reduces IP geolocation to the problem of finding equilibrium points in a spring system. Our approach, called Spring-Based Geolocation (SBG), is able to reduce the mean error to less than 75km in our experiments without adding significant complexity. In fact, our model allows for additional data sources in a natural way, which has the potential to further improve results. Stephan M. Günther, Johann Schlamp, Georg Carle |
NOMS | 3 |
| 2012 | Iterative multi-party agreement negotiation for establishing collaborations
Andreas Klenk, Andreas Beck-Greinwald, Hannes Angst, Georg Carle |
Serv. Oriented Comput. Appl. | 4 |
| 2011 | Investigating the OpenPGP Web of Trust
Alexander Ulrich, Ralph Holz, Peter Hauck, Georg Carle |
ESORICS | 4 |
| 2011 | The SSL landscape: a thorough analysis of the x.509 PKI using active and passive measurementsabstractThe SSL and TLS infrastructure used in important protocols like HTTPs and IMAPs is built on an X.509 public-key infrastructure (PKI). X.509 certificates are thus used to authenticate services like online banking, shopping, e-mail, etc. However, it always has been felt that the certification processes of this PKI may lack in stringency, resulting in a deployment where many certificates do not meet the requirements of a secure PKI. Ralph Holz, Lothar Braun, Nils Kammenhuber, Georg Carle |
Internet Measurement Conference | 4 |
| 2011 | Collecting router information for error diagnosis and troubleshooting in home networksabstractWith the increasing number of heterogeneous devices that are connected to an average home network, troubleshooting in case of network problems becomes more and more complicated. This is not only because most home users are consumers and not experts in the field of networking, but also because it is usually hard to find the relevant information useful for a systematic error diagnosis. Potential sources of information, such as the web interface of a home router, are not standardized and usually not available to people, e.g. friends or help-lines, that are willing to help from outside of the home. However, many home routers run a Linux driven operating system and are therefore capable of providing a manifold amount of interesting data for debugging network related errors. This paper presents a tool which allows gathering highly customizable data on Linux based home routers using arbitrary textual sources, such as the proc-filesystem, command-line output and configuration files. Additionally, we describe the necessary steps for securely transferring the information to an external helper. Andreas Müller 0003, Gerhard Miinz, Georg Carle |
LCN | 3 |
| 2011 | Securing the internet of things with DTLSabstractUsecases for wireless sensor networks, such as building automation or patient care, often collect and transmit sensitive information. Yet, many deployments currently do not protect this data through suitable security schemes. We propose an end-to-end security scheme build upon existing internet standards, specifically the Datagram Transport Layer Security protocol (DTLS). By relying on an established standard existing implementations, engineering techniques and security infrastructure can be reused which enables easy security uptake. We present a system architecture for this scheme and show its feasibility through the evaluation of our implementation. Thomas Kothmayr, Wen Hu 0001, Corinna Schmitt, Michael Brünig, Georg Carle |
SenSys | 5 |
| 2011 | A simple distributed mechanism for accounting system self-configuration in next-generation charging and billing
Ralph Kühne, George B. Huitema, Georg Carle |
Comput. Commun. | 3 |
| 2010 | Gathering Sensor Data in Home Networks with IPFIX
Thomas Kothmayr, Corinna Schmitt, Lothar Braun, Georg Carle |
EWSN | 4 |
| 2010 | Efficient Protection in Single-Domain Networks Using Network CodingabstractQuality of service requirements and the increasing amount of data transmission demand for efficient protection mechanisms. Existing mechanisms like 1+1 and 1+N path protection offer instantaneous recovery but they suffer from high capacity needs and nodal degree requirements, respectively. The high nodal degree requirement makes an implementation of the 1+N mechanism in transport networks difficult. In this paper, we develop two new mechanisms by applying network coding on a virtualized protection scheme. These mechanisms are more resource-efficient compared to 1+1, and are implementable in transport networks even under stringent nodal degree constraints. The difference between the two mechanisms lies in complexity and performance. Therefore, either of them can be preferred as a good compromise between 1+1 and 1+N in different scenarios according to the needs and available resources. Isil Burcu Barla Harter, Franz Rambach, Dominic A. Schupke, Georg Carle |
GLOBECOM | 4 |
| 2010 | Comparing and improving current packet capturing solutions based on commodity hardwareabstractCapturing network traffic with commodity hardware has become a feasible task: Advances in hardware as well as soft- ware have boosted off-the-shelf hardware to performance levels that some years ago were the domain of expensive special-purpose hardware. However, the capturing hardware still needs to be driven by a well-performing software stack in order to minimise or avoid packet loss. Improving the capturing stack of Linux and FreeBSD has been an extensively covered research topic in the past years. Although the majority of the proposed enhancements have been backed by evaluations, these have mostly been conducted on different hardware platforms and software versions, which renders a comparative assessment of the various approaches difficult, if not impossible. Lothar Braun, Alexander Didebulidze, Nils Kammenhuber, Georg Carle |
Internet Measurement Conference | 4 |
| 2010 | Collecting sensor data using compressed IPFIXabstractDuring the last years the application areas and corresponding requirements for Wireless Sensor Networks (WSN) raised due to limited resources of devices and requirements of the application. The scenarios (e.g. home networks) call for an integration of a WSN into an existing IP-based infrastructure which is realized by 6LoW-PAN. To save resources and to ensure a long life time of the WSN resource consuming tasks such as transmissions must be reduced. Therefore, we present a Compressed IPFIX protocol. It optimizes the transmission by reducing the packet size and the transmission amount by separation between meta information and data. Additional tasks can be performed on top of IPFIX to optimize the efficient usage of the limited resources. Corinna Schmitt, Lothar Braun, Thomas Kothmayr, Georg Carle |
IPSN | 4 |
| 2010 | Policy-driven workflows for mobile network management automationabstractFuture wireless networks will experience a continuous growth regarding the number of network elements with increasingly complex interrelations between the configuration of multiple network elements. Another trend is the seamless integration of multiple radio technologies into a single wireless network. Both developments increase network management complexity and require new management concepts with a very high degree of automation. For this purpose, a novel management approach based on a combination of workflow and policy technologies is presented. The goal is to simplify and automate management tasks in mobile networks in order to raise the state of self-organization while the network still remains under control of the operator. The approach provides the means for a dynamic system to automatically adapt to context changes. Moreover, an experimental system is presented for the purposes of concept validation and evaluation along with a real world use case. Raphael Romeikat, Bernhard Bauer 0001, Tobias Bandh, Georg Carle, Henning Sanneck, Lars-Christoph Schmelz |
IWCMC | 4 |
| 2010 | Optimized network configuration parameter assignment based on graph coloringabstractThe trend for future mobile networks is to move away from Network Elements (NEs) delivered with specially tailored configurations towards off-the-shelf products. The configurations of NEs are automatically created with respect to their context including information on location and configuration of neighboring NEs. To minimize time-consuming and error-prone human interaction, automatic behavior is required for all stages of a NE's life cycle. The possibility to pre-assess the effects of configuration changes is inevitable in order to avoid service degradation caused by unnecessary reconfigurations. Graph coloring-based Physical Cell ID (PCID) assignment for LTE networks was introduced previously. The foundation on graph coloring theory allowed to transfer knowledge from this domain to the task of PCID assignment in order to pre-asses if an assignment is possible and how many PCIDs are required. Now the focus lies on adaptations of the basic approach to satisfy additional operator requirements such as safety margins. Those adaptations should provide equally good results in terms of used PCIDs with only minimal impact on costs and operation and maintenance tasks. Variations of the basic PCID assignment approach are discussed to address other types of problems. Tobias Bandh, Georg Carle, Henning Sanneck, Lars-Christoph Schmelz, Raphael Romeikat, Bernhard Bauer 0001 |
NOMS | 2 |
| 2010 | Packet sampling for worm and botnet detection in TCP connectionsabstractMalware and botnets pose a steady and growing threat to network security. Therefore, packet analysis systems examine network traffic to detect active botnets and spreading worms. However, with the advent of multi-gigabit link speeds, capturing and analysing header and payload of every packet requires enormous amounts of computational resources and is therefore not feasible in many situations. We address this problem by presenting an efficient packet sampling algorithm that picks a small number of packets from the beginning of every TCP connection. Bloom filters are used to store the required connection state information with constant amount of memory. Our analysis of worm and botnet traffic shows that the large majority of attack signatures is actually found in these packets. Thus, our sampling algorithm can be deployed in front of a detection system to reduce the amount of inspected packets without degrading the detection results significantly. Lothar Braun, Gerhard Münz, Georg Carle |
NOMS | 3 |
| 2010 | A decentralised service composition approach for peer-to-peer video delivery
Michael Kleis, Benoit Radier, Sanaa Elmoumouhi, Georg Carle, Mikaël Salaün |
Peer-to-Peer Netw. Appl. | 4 |
| 2009 | ANTS - A Framework for Knowledge Based NAT TraversalabstractToday most home networks are connected to the Internet via Network Address Translation (NAT) devices. NAT is an obstacle for services that should be accessible from the public Internet. Especially applications following the peer-to-peer paradigm suffer from the existence of NAT. Various NAT Traversal methods emerged in research and standardization, but none of them can claim to be a general solution working in the heterogeneous environment of today's networks. This paper introduces the Advanced NAT Traversal Service (ANTS), a framework improving the communication of existing and future applications across NAT devices. The core idea of ANTS is to use previously acquired knowledge about NAT behavior and services for setting up new connections. We introduce the architecture of the extensible framework and propose a signaling protocol for the coordination of distributed instances. Finally, we compare the framework to ICE showing that ANTS is not only more flexible, but also faster due to the decoupled connectivity checks. Andreas Müller 0003, Andreas Klenk, Georg Carle |
GLOBECOM | 3 |
| 2009 | Graph coloring based physical-cell-ID assignment for LTE networksabstractAutoconfiguration of the radio parameters is a key feature for next generation mobile networks. Especially for LTE the NGMN Forum has brought it up as a major requirement. It is indispensable that algorithms used for autoconfiguration terminate quickly and do not cause infinite iterative reconfigurations within the network. Tobias Bandh, Georg Carle, Henning Sanneck |
IWCMC | 2 |
| 2008 | On the Applicability of Knowledge Based NAT-Traversal for Home Networks
Andreas Müller 0003, Andreas Klenk, Georg Carle |
Networking | 3 |
| 2008 | Adaptive encryption for the realization of real-time transmission of sensitive medical video streamsabstractThis paper presents an analysis of the potential of adaptive encryption of streaming video data over 3G networks. The results obtained promote the design of a network component (the so called ldquointelligent networkrdquo) that facilitates the secure real-time transmission of video data. Case studies involving the sensitive area of telemedicine can be implemented by means of this component. The transport layer protocol SCTP is the basis for technical realization, which has interesting features and extensions. The combination of these features and the management of the intelligent network allows the implementation of sensitive applications. Kai Kamphenkel, Markus Blank, Jens Bauer, Georg Carle |
WOWMOM | 4 |
| 2007 | Peer-to-Peer-Based Infrastructure Support for Massively Multiplayer Online GamesabstractMultiplayer games played over the Internet have become very popular in the lastfew years. An interesting subcategory are the so-called massively multiplayeronline games (MMOGs) that allow thousands of player characters to share asingle game world. Such a world is usually run on a high-performance and high-availability server cluster. However, even with games that have been extensivelybeta-tested, downtimes of several hours because of hard- or software failures arenot uncommon. Downtimes, especially in the first few weeks after the release,can negatively affect the image of the game and the company that created it.Traditionally, a cluster of servers contains one virtual world of a MMOG.Such infrastructure is inflexible and error-prone. One would rather like to havea system that allows disconnecting a server at runtime while others take overits tasks. Server-based MMOGs can have performance problems if players areconcentrated in certain parts of the game world or some worlds are overpopu-lated. Thus, there is also a need for load balancing mechanisms. Peer-to-Peer(P2P) systems quite naturally support the use of load balancing.In this paper we use a structured P2P technology for the organization of theinfrastructure and thus for the reduction of downtimes in MMOGs. We splitthe game world in disjunctive rectangular zones and distribute them on differentnodes of the P2P network.Online games are an interesting challenge and chance for the future devel-opment of the P2P paradigm. A wide variety of aspects of only theoreticallysolved and especially yet completely unsolved problems are covered by this ap-plication. Security and trust problems appear as well as the need to preventcheating. The application is not as tolerant to faults as instant messaging or filesharing. Consistent data storage is a problem, decisions and transactions haveto be performed in a decentralized way. Moreover, the P2P network is not usedas pure lookup service, but more as a communication and application-specificsocial structure.The rest of this paper is organized as follows: First we discuss related work inSection 2 and give a brief introduction to P2P and MMOGs and their challengesin Section 3. Section 4 shows our approach to use structured P2P Systems forMMOGs and section 5 the evaluation with player traces from a real MMOG.Finally, Section 6 provides conclusions. Simon Rieche, Klaus Wehrle, Marc Fouquet, Heiko Niedermayer, Leo Petrak, Georg Carle |
CCNC | 6 |
| 2007 | Dynamic Multipath Onion Routing in Anonymous Peer-To-Peer Overlay NetworksabstractAlthough recent years provided many protocols for anonymous routing in overlay networks, they commonly rely on the same communication paradigm: Onion Routing. In Onion Routing a static tunnel through an overlay network is build via layered encryption. All traffic exchanged by its end points is relayed through this tunnel. In contrast, this paper introduces dynamic multipath Onion Routing to extend the static Onion Routing paradigm. This approach allows each packet exchanged between two end points to travel along a different path. To provide anonymity the first half of this path is selected by the sender and the second half by the receiver of the packet. The results are manifold: First, dynamic multipath Onion Routing increases the resilience against threats, especially pattern and timing based analysis attacks. Second, the dynamic paths reduce the impact of misbehaving and overloaded relays. Finally, inspired by Internet routing, the forwarding nodes do not need to maintain any state about ongoing flows and so reduce the complexity of the router. In this paper, we describe the design of our dynamic Multipath Onion RoutEr (MORE) for peer-to-peer overlay networks, and evaluate its performance. Furthermore, we integrate address virtualization to abstract from Internet addresses and provide transparent support for IP applications. Thus, no application-level gateways, proxies or modifications of applications are required to sanitize protocols from network level information. Acting as an IP-datagram service, our scheme provides a substrate for anonymous communication to a wide range of applications using TCP and UDP. Olaf Landsiedel, Lexi Pimenidis, Klaus Wehrle, Heiko Niedermayer, Georg Carle |
GLOBECOM | 5 |
| 2007 | Real-time Analysis of Flow Data for Network Attack DetectionabstractWith the wide deployment of flow monitoring in IP networks, the analysis of the exported flow data has become an important research area. It has been shown that flow data can be used to detect traffic anomalies, DoS attacks, and the propagation of worms. In practice, anomalies and attacks should be detected as fast as possible in order to allow taking appropriate countermeasures. We describe the necessary steps from the raw flow data to the detection result in a systematic way. Furthermore, we present TOPAS, a system and framework for real-time analysis of flow data, that has been developed in order to meet these requirements. Performance measurements and various application examples point out the capabilities and benefits of our approach. Gerhard Münz, Georg Carle |
Integrated Network Management | 2 |
| 2007 | Automated Real Time Performance Management for Mobile NetworksabstractReal Time Performance Management (RTPM) is expected to be a key features offuture developments of mobile networks. Although it is already requested by operators of mobile networks only basic approaches have been realized. Implementing access to real time performance data in a mobile network, with a large number of manageable nodes, leads to a huge resource consumption. Not only network bandwidth but also processing resources. Current PM schemes can hardly be extended to support real time performance management. We present a policy based approach that is capable to deal with challenges imposed by the request for real time performance data. Typical workflows are identified and analysed. Based on these analyses a policy based performance management system is introduced that allows a balanced configuration which does not exceed available resources but still satisfies the information requirements of the human operators. Tobias Bandh, Georg Carle, Henning Sanneck, Lars-Christoph Schmelz |
WOWMOM | 2 |
| 2007 | Wired/wireless internet communications
Torsten Braun, Georg Carle, Sonia Fahmy, Yevgeni Koucheryavy |
Comput. Commun. | 2 |
| 2006 | Using Netconf for Configuring Monitoring ProbesabstractNetconf is a new protocol for configuration and management of network devices, based on a flexible XML-encoded message format. Netconf aims to overcome the short-comings of SNMP and CLIs that are predominantly used for configuration tasks. We demonstrate that Netconf is highly suitable for the configuration of IPFIX/PSAMP monitoring probes, as required in order to dynamically and remotely adapt to the varying needs of applications that receive and process monitoring data. In this regard, we present an XML-based data model covering all common configurable parameters for flow metering and aggregation, packet sampling, and data export. Finally, we describe how we implemented the Netconf-based configuration approach based on Web Services and SOAP. Gerhard Münz, Albert Antony, Falko Dressler, Georg Carle |
NOMS | 4 |
| 2006 | Wired/wireless Internet communications
Torsten Braun, Georg Carle, Yevgeni Koucheryavy, Vassilis Tsaoussidis |
Comput. Commun. | 2 |
| 2002 | An MPEG performance model and its application to adaptive forward error correctionabstractWe present a general analytical model for predicting the reconstructed frame rate of an MPEG stream. Our model captures the temporal relationships between I-, P, and B-frames but is independent of the channel and media characteristics. We derive an adaptive FEC scheme from the general model and verify it by comparing it to the results of a simulation. The prediction error of the model compared to the simulation for a wide array of parameter values is less than 5%. We then use the derived adaptive FEC scheme to study the optimal rate allocation (i.e., between generating a higher frame rate or increasing the protection for a lower frame rate) when equation-based TCP rate control is used to couple packet rates to channel characteristics such as round trip time and packet loss probabilities. Surprisingly, we find that optimal protection levels for I- and P-frames are relatively static as loss rates increase from 1% to 4% while changes in the frame type pattern are used to ameliorate the effects of the increased loss. The study demonstrates how our model can be used to reveal joint source/channel coding tradeoffs and how they relate to encoding and transmission parameters. Ketan Mayer-Patel, Long Le, Georg Carle |
ACM Multimedia | 3 |
| 2001 | Intra-flow loss recovery and control for VoIPabstract"Best effort" packet-switched networks, like the Internet, do not offer a reliable transmission of packets to applications with real-time constraints such as voice. Thus, the loss of packets impairs the application-level utility. For voice this utility impairment is twofold: on one hand, even short bursts of lost packets may decrease significantly the ability of the receiver to conceal the packet loss and the speech signal playout is interrupted. On the other hand, some packets may be particular sensitive to loss as they carry more important information in terms of user perception than other packets.We first develop an end-to-end model based on loss run-lengths with which we can describe the loss distribution within a flow. These packet-level metrics are then linked to user-level objective speech quality metrics. Using this framework, we find that for low-compressing sample-based codecs (PCM) with loss concealment isolated packet losses can be concealed well, whereas burst losses have a higher perceptual impact. For high-compressing frame-based codecs (G.729) on one hand the impact of loss is amplified through error propagation caused by the decoder filter memories, though on the other hand such coding schemes help to perform loss concealment by extrapolation of decoder state. Contrary to sample-based codecs we show that the concealment performance may "break" at transitions within the speech signal however.We then propose mechanisms which differentiate between packets within a voice data flow to minimize the impact of packet loss. We designate these methods as "intra-flow" loss recovery and control. At the end-to-end level, identification of packets sensitive to loss (sender) as well as loss concealment (receiver) takes place. Hop-by-hop support schemes then allow to (statistically) trade the loss of one packet, which is considered more important, against another one of the same flow which is of lower importance. As both packets require the same cost in terms of network transmission, a gain in user perception is obtainable. We show that significant speech quality improvements can bem achieved and additional data and delay overhead can be avoided while still maintaining a network service which is virtually identical to best effort in the long term. Henning Sanneck, Nguyen Tuong, Long Le, Adam Wolisz, Georg Carle |
ACM Multimedia | 5 |
| 1999 | A queue management algorithm for intra-flow service differentiation in the "best effort" InternetabstractEnd-to-end QoS can be improved by exploiting knowledge about the flow structure to influence the flow within the network. This leads to a graceful degradation under congestion ("intra-flow" QoS). Typically this is accomplished by filtering higher-layer information within the network, which is both expensive in terms of resources, as well as undesirable with regard to network security. In this paper, we present a queue management algorithm called DiffRED (differential random early detection) that allows us to enhance intra-flow QoS without higher-layer filtering. The algorithm differentiates between packets marked by the sender as either more or less eligible to be dropped in comparison to unmarked packets. This gives the application some control over the packet loss process and thus enhances the performance of available end-to-end loss recovery mechanisms, end-to-end fairness and finally the perceived quality. The algorithm helps to bridge the huge gap between the current "best-effort" Internet and full deployment of inter-flow service differentiation. We introduce simple metrics to describe the loss process of individual flows and present simulation results for a voice service using the proposed scheme. We demonstrate how the algorithm provides a significant intra-flow QoS enhancement and evaluate the impact on conventional traffic. Henning Sanneck, Georg Carle |
ICCCN | 2 |
| 1998 | RTMC: An Error Control Protocol for IP-based Audio-Visual Multicast ApplicationsabstractTransport of audio visual data is becoming an important application of the IP-based best-effort service on the Internet. We present an error control protocol for provision of a real-time reliable multicast transport service. The protocol RTMC (real-time multicast) uses forward error correction (FEC) for protecting first transmissions (i.e. proactive error control) and retransmissions. Results of the performance evaluation show that RTMC error control imposes low latency, and is scalable to a large number of receivers. Georg Carle, Jörg Ottensmeyer |
ICCCN | 1 |
| 1998 | How Bad is Reliable Multicast without Local Recovery?abstractWe examine the impact of the loss recovery mechanisms on the performance of a reliable multicast protocol. Approaches to reliable multicast can be divided into two major classes: source-based recovery, and distributed recovery. For both classes we consider the state of the art: for source-based recovery, a type 2 hybrid ARQ scheme with parity retransmission; for distributed recovery, a scheme with local multicast retransmission and local feedback processing. We further show the benefits of combining the two approaches and consider a type 2 hybrid ARQ scheme with local retransmission. The schemes are compared for up to 10/sup 6/ receivers under different loss scenarios with respect to network bandwidth usage and completion time of a reliable transfer. We show that the protocol based on local retransmissions via type 2 hybrid ARQ performs best for bandwidth and latency. For networks, where local retransmission is not possible, we show that a protocol based on type 2 hybrid ARQ comes close to the performance of a protocol with local retransmissions. Jörg Nonnenmacher, Martin S. Lacher, Matthias Jung 0002, Ernst W. Biersack, Georg Carle |
INFOCOM | 5 |