Lars-Christian Schulz

dblp:224/6549 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
5since 2021 · last 2024
0009-0009-9065-6372ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
3 papers
Internet architecture and protocols · 48% Software-defined and programmable networks · 28% Network measurement and analytics · 10%
Network and information security
2 papers
Network security · 100%

Topics — the 10 heaviest of 12, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Internet architecture and protocols › future internet architecture
path-aware networking
2.132024
Secure in-Band Network Telemetry for the SCION Internet Architecture on Tofino · ICNP 2024
Scion Edge Router for Legacy IP Applications Based on Intel Tofino · ICNP 2024
Supporting Dynamic Secure Interdomain Routing · ICNP 2022
Software-defined and programmable networks
programmable data plane
1.522024
Secure in-Band Network Telemetry for the SCION Internet Architecture on Tofino · ICNP 2024
Scion Edge Router for Legacy IP Applications Based on Intel Tofino · ICNP 2024
Internet architecture and protocols › future internet architecture
SCION
1.522024
Secure in-Band Network Telemetry for the SCION Internet Architecture on Tofino · ICNP 2024
Scion Edge Router for Legacy IP Applications Based on Intel Tofino · ICNP 2024
Network measurement and analytics › network telemetry
in-band network telemetry
0.812024
Secure in-Band Network Telemetry for the SCION Internet Architecture on Tofino · ICNP 2024
Software-defined and programmable networks › programmable data plane
p4
0.812024
Scion Edge Router for Legacy IP Applications Based on Intel Tofino · ICNP 2024
Routing and switching
inter-domain routing
0.612022
Supporting Dynamic Secure Interdomain Routing · ICNP 2022
Network optimization and economics
network economics
0.612022
Supporting Dynamic Secure Interdomain Routing · ICNP 2022
Network security › routing security
secure interdomain routing
0.212022
Supporting Dynamic Secure Interdomain Routing · ICNP 2022
Performance modeling and evaluation
benchmarking
0.112018
An Eight-Dimensional Systematic Evaluation of Optimized Search Algorithms on Modern Processors · Proc. VLDB Endow. 2018
Hardware accelerators and domain-specific architectures
hardware-aware optimization
0.112018
An Eight-Dimensional Systematic Evaluation of Optimized Search Algorithms on Modern Processors · Proc. VLDB Endow. 2018

Methods — techniques the papers use, named apart from their topics

p4 · 1.5prototype · 1.1p4 programming · 0.8
YearPublicationVenuePosition
2024 ID-INT: Secure Inter-Domain In-Band Telemetry
abstract
In-band network telemetry (INT) is a powerful tool for gathering status information from network components in a distributed and timely way. Until now, INT has mostly been deployed in data center environments or single operator WANs, because it lacks mechanisms for authentication and is not widely standardized. SCION is a novel, path-based Internet architecture providing strong resilience and security properties. In this paper, we propose Inter-domain In-band Network Telemetry (ID-INT) as a protocol extension for SCION. ID-INT leverages SCION’s public key infrastructure to authenticate telemetry data while augmenting SCION’s end host path control with real-time network information. Promising applications of ID-INT include intra-AS path tracing, congestion control, SLA verification, and carbon-aware routing. We implement ID-INT in the open-source SCION stack and provide a proof of concept for an AS-hosted telemetry collection service. We show that cryptographically authenticated ID-INT can be fully implemented in the SCION router’s fast-path with no measurable impact on router performance. If optional encryption is employed in addition to authentication, router throughput drops by no more than 13% even if every packet carries telemetry.
Lars-Christian Schulz, David Hausheer
CNSM1
2024 Scion Edge Router for Legacy IP Applications Based on Intel Tofino
abstract
Today's BGP-based Internet offers almost no control over forwarding paths to end users. Few opportunities exist to influence paths on an application-by-application basis, e.g., the traffic class field in the IP header, but that is usually dropped when a packet reaches the first ISP. In contrast, path-aware networking (PAN) as implemented in the SCION Internet architecture offers a wealth of path choices from which applications can pick desirable subsets. However, only a few dozen applications support SCION natively today. Instead, SCION deployments connect legacy applications through SCIONIP Gateways (SIGs) that provide an overlay IP network on top of SCION. In this work, we introduce an alternative SCION to legacyIP compatibility mechanism suitable for P4-programmable hardware that can replace the SIG, called SCION-IP translation. The SCION-IP Translator addresses two issues of the SIG. First, the SIG requires fragmentation and reassembly of the underlying IP packets - a process not easily done in P4. More importantly, SIGs form an overlay network on top of SCION. Native SCION applications cannot communicate with legacy applications. Thus, the SIG hinders native application development. The main innovation of the SCION-IP Translator is that it translates headers directly without introducing another (tunneling) layer to the network stack. We prototype a SCION-IP Translator using Intel Tofino switches of the first and second generation and provide insights from deploying SCION-IP translation in a university network participating in the SCION Education, Research and Academic network (SCIERA).
Lars-Christian Schulz, Robin Wehner, David Hausheer
ICNP1
2024 Secure in-Band Network Telemetry for the SCION Internet Architecture on Tofino
abstract
Today's Internet frequently suffers from unreliable packet forwarding and security vulnerabilities, while it largely depends on the Border Gateway Protocol (BGP) that obscures routing complexities from end-hosts. Path-Aware Networking (PAN) is a novel paradigm that aims to overcome BGP's limitations by offering end-hosts control over packet routing. However, an optimal path choice based on PAN requires realtime performance data about the different path options. Programmable data planes and Software-Defined Networking (SDN) enable to add real-time telemetry data to user packets. However, existing implementations are limited to single administrative domains, lacking the security and privacy required for interdomain telemetry. This paper proposes the first hardware implementation of Inter-Domain In-band Network Telemetry (ID-INT), extending the P4-based SCION border router targeting Tofino 2. Leveraging SCION's path-aware features and robust security mechanisms, like the DRKey system for secure key derivation, our ID-INT implementation on Tofino ensures telemetry data authenticity and integrity. We demonstrate the benefits of ID-INT on Tofino by evaluating the Deadline-aware Multipath Transport Protocol (DMTP) as an example application utilizing ID-INT data to improve its responsiveness to network conditions. Our testbed experiments show that ID-INT enables DMTP to dynamically adjust the sending rate based on instantaneous queue length data, highlighting ID-INT's practical benefits in enhancing an application's performance.
Robin Wehner, Tony John, Lars-Christian Schulz, David Hausheer
ICNP3
2023 DDoS Detection in P4 Using HYPERLOGLOG and COUNTMIN Sketches
abstract
Distributed denial-of-service (DDoS) attacks are a growing threat in the Internet. For example, the increasing number of small low-powered devices participating in the Internet of Things can be hijacked by botnets and used to perpetrate powerful DDoS attacks if they are not secured correctly. Different works have already investigated how such attacks may be detected using efficient probabilistic data structures known as “sketches”. Additionally, software-defined networking and data plane programmability have created new opportunities to develop new DDoS attack detection approaches that are performed entirely by the data plane. In this work, we specifically investigate an approach that uses a combination of HYPERLOGLOG and COUNTMIN sketches to detect DDoS attacks in P4-programmable network switches. We present an implementation of this approach for a software-based P4 switch and evaluate its accuracy, achieved detection latencies and its effect on throughput in an emulated environment. Our implementation achieves detection latencies as low as 0.97 s. The impact on switch throughput is limited to approximately 10% if the final detection step is offloaded to the controller. We explore the impact of different sketch sizes on detection accuracy and find a trade-off between accuracy and memory requirements.
Vera Clemens, Lars-Christian Schulz, Marten Gartner, David Hausheer
NOMS2
2022 Supporting Dynamic Secure Interdomain Routing
abstract
Path aware networking (PAN) is an approach that allows endpoints to participate in the end-to-end path selection, letting them choose paths best suited for each application. This approach offers numerous potential benefits including rapid fail-over, concurrent use of parallel paths, and QoS enabled networks, even spanning multiple domains. The dynamic interconnection of different autonomous systems (ASes) in path aware networks offers both challenges and opportunities for network service providers, which in turn provide opportunities for traffic engineering previously not possible. The SCION path-aware network architecture has been designed from the ground up with security in mind, and features a trust structure that can serve as a basis for more dynamic interconnection between ASes. In this paper, we describe a prototype spot market that lets the ASes sell time-limited excess capacity, allowing buyers to divert traffic to cheaper alternatives temporarily. We believe this market allows for new opportunities both in traffic engineering and inter-domain connectivity that have not existed before. The market benefits all parties involved, as the formerly wasted bandwidth is now used, and provides additional revenue—in varying degrees—to all the participating entities.
Lars-Christian Schulz, Elham Ehsani Moghadam, Juan A. García-Pardo, David Hausheer, Kenneth L. Calvert
ICNP1
2018 An Eight-Dimensional Systematic Evaluation of Optimized Search Algorithms on Modern Processors
abstract
Searching in sorted arrays of keys is a common task with a broad range of applications. Often searching is part of the performance critical sections of a database query or index access, raising the question what kind of search algorithm to choose and how to optimize it to obtain the best possible performance on real-world hardware. This paper strives to answer this question by evaluating a large set of optimized sequential, binary and k-ary search algorithms on a modern processor. In this context, we consider hardware-sensitive optimization strategies as well as algorithmic variations resulting in an eight-dimensional evaluation space. As a result, we give insights on expected interactions between search algorithms and optimizations on modern hardware. In fact, there is no single best optimized algorithm, leading to a set of advices on which variants should be considered first given a particular array size.
Lars-Christian Schulz, David Broneske, Gunter Saake
Proc. VLDB Endow.1