Eric Lanfer

dblp:312/4275 · DBLP profile ↗
← Back
12ranked-venue papers
4as first author
12since 2021 · last 2026
0000-0001-9763-4613ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 3 first-author · 9 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Camera-Ready? Exploring Transport-Layer Performance Limits with GigE Vision
abstract
Industrial machine vision is rapidly adopting cost-effective 25-100 GbE network interfaces, which enable multi-megapixel cameras to generate frames of tens of megabytes at high frame rates with no tolerance for loss. However, the de facto GigE Vision (GEV) standard was developed in the 1 GbE era based on UDP sockets, and its capacity to scale has been the subject of ongoing debate. Although RDMA techniques like RoCEv2 and TCP as an intermediate solution have been suggested by vendors and standardization bodies for long-term adoption, a methodical, application-centric evaluation has been lacking.
Malte Wehmeier, Eric Lanfer, Kathrin Elmenhorst, Nils Aschenbruck
MMSys2
2026 DEMO: COSME - Composable Orchestrated Starlink Mobility Emulation
abstract
Low Earth Orbit (LEO) satellite links are pivotal for ubiquitous vehicle connectivity, yet their performance is impacted by a complex interplay of weather, constellation dynamics, and physical obstructions. While individual models for these impairments exist, protocol and application designers lack a unified tool to evaluate behavior under realistic, composed LEO conditions. We present COSME, a route-aware, real-time mobility emulator that integrates multiple impairment models - including obstruction-based loss, constellation-induced jitter, precipitation-driven bandwidth reduction, and packet loss at handovers - into a single framework. By orchestrating Linux network namespaces via tc and netem, COSME enables the high-fidelity playback of merged impairment traces. We demonstrate COSME through five diverse application showcases, highlighting the impact of different congestion control algorithms and transport protocols on LEO connectivity.
Eric Lanfer, Dominic Laniewski, Till Zimmermann, Nils Aschenbruck
SIGCOMM1
2026 The More We Measure, The Less We See: On the Replicability and Repeatability of Mobile Starlink Measurements
abstract
Lately, growing effort has been invested to analyze the Starlink performance under vehicular user terminal mobility. As such measurement campaigns are labor- and time-consuming, existing studies mostly focus on single test drives. In this paper, we demonstrate that repeatability and replicability of mobile Starlink measurements represent serious challenges, mainly due to numerous factors that can be hardly controlled. First, we conduct an extensive measurement campaign of Starlink's latency and packet loss under vehicular mobility. The campaign focuses on repeatability and consists of 35 single test drives of the identical highway route over the span of four months. Then, we demonstrate that replicability remains challenging. For this, we replicate existing findings and find new, seemingly statistically significant correlations by purposefully cherry-picking single test drives. By considering our complete dataset, we show that in reality, these findings are likely statistical variations caused by uncontrollable factors. Based on this, we discuss the challenges and provide guidelines for meaningful future Starlink measurements under vehicular mobility.
Till Zimmermann, Dominic Laniewski, Eric Lanfer, Nils Aschenbruck
SIGCOMM3
2025 Poster: Generating the WEB-IDS23 Dataset
Eric Lanfer, Dominik Brockmann, Nils Aschenbruck
DIMVA (1)1
2025 Now You See Me / Now You Don't: Constrained Adversarial Attacks in Network Intrusion Detection Across Datasets and Machine Learning Models
abstract
As the number of cyber-attacks is rising, Network Intrusion Detection Systems (NIDS) are becoming increasingly important for the detection and identification of malicious traffic, and Machine Learning techniques are gaining traction for the classification of network traffic. However, especially Deep Learning models are vulnerable to adversarial examples— subtle input perturbations that cause misclassification. While adversarial examples for images must be imperceptible, network data perturbations face complex, domain-specific constraints.We examine the vulnerability of NIDS to adversarial attacks, and compare six machine learning architectures and three black-box attack methods on four Network Intrusion Detection (NID) datasets. We define a threat model that provides minimal knowledge and limited access to an adversary, and use a highly restricted feature subset to apply perturbations to. Our results show attack success rates of 0.1-36.9%, with large, dataset-specific differences between architectures. In a second step, we apply three methods to minimize the size of the perturbations and find that the Pointwise attack is especially well suited for NID data. Finally, we analyze perturbed features and find single features greatly impact classification.
Dominik Brockmann, Eric Lanfer, Nikolas Wintering, Nils Aschenbruck
LCN2
2025 Measuring the Potential for Bundled Starlink Performance within a Single Service Cell
abstract
Low Earth Orbit (LEO) satellite networks such as Starlink allow global and affordable internet access. This not only connects remote residents, but also enables new potentials such as connecting non-stationary agricultural systems in rural areas for high-precision spot farming. One challenge is that tractors and farming robots need to transmit large amounts of data from cameras and laser scanners in real-time, which easily overwhelms the uplink capabilities of a single LEO connection. In this paper, we examine the Starlink performance of multiple terminals within a single service cell to lay ground for multipath link bundling as a possible approach to increase link capabilities. For this purpose, we present two measurement setups consisting of four and seven Starlink dishes placed in one service cell. We conduct multiple measurements and evaluate UDP and TCP throughput, latency, and packet loss. We find that UDP throughput scales almost linearly with the number of dishes, indicating significant bundling potential up to an expected limit. In contrast, TCP BBRv1’s bundling potential is limited, due to inefficiencies in utilizing the links. Moreover, we find that some packet loss events are synchronized within a service cell. For future and independent research, we make our dataset publicly available.
Till Zimmermann, Dominic Laniewski, Eric Lanfer, Stefanie Thieme, Nikolas Wintering, Nils Aschenbruck
LCN3
2024 Automating Network Perimeter Threat Prevention for Decentralized Network Administration
abstract
Decentrally administered networks consist of a plethora of hosts providing various services to the Internet and several administrators are responsible for mitigating software vulnerabilities. Therefore, these networks potentially expose a large attack surface depending on the capabilities and workload of administrators. In this paper, we present the automateD nETwork pERimeter thREat pRevention System (DETERRERS). It automatically scans hosts at the network perimeter, assesses the risk of exposed vulnerabilities, and performs actions based on the assessed risk. This supports administrators in their work and enables faster reaction to software vulnerabilities. Additionally, host-based security policies can be configured in a modular user interface by system administrators and firewall configurations can be generated automatically. We deploy our system in a university network with decentralized administration and evaluate the risk assessment process, the influence on the attack surface of the network, and the time-to-remediate from vulnerabilities.
Nikolas Wintering, Eric Lanfer, Nils Aschenbruck
CNSM2
2024 Demo: The Impact of LEO Satellite Network Instabilities on the Performance of Networking Applications
abstract
Low Earth Orbit (LEO) satellite networks like Starlink are susceptible to both external factors (e.g., weather and obstruction) and internal factors such as frequency and resource allocation changes. This causes performance instabilities by design. In this demo, we show that such instabilities can have a detrimental impact on the performance of TCP and consequently on large parts of today’s internet, as most traffic uses TCP as transport protocol. Consequently, LEO-specific adaptations to either TCP and/or higher-level applications are necessary.
Dominic Laniewski, Stefanie Thieme, Till Zimmermann, Eric Lanfer, Nikolas Wintering, Jannis Mast, Nils Aschenbruck
LCN4
2023 Leveraging Explainable AI Methods Towards Identifying Classification Issues on IDS Datasets
abstract
Nowadays, anomaly-based network intrusion detection system (NIDS) still have limited real-world applications; this is particularly due to false alarms, a lack of datasets, and a lack of confidence. In this paper, we propose to use explainable artificial intelligence (XAI) methods for tackling these issues. In our experimentation, we train a random forest (RF) model on the NSL-KDD dataset, and use SHAP to generate global explanations. We find that these explanations deviate substantially from domain expertise. To shed light on the potential causes, we analyze the structural composition of the attack classes. There, we observe severe imbalances in the number of records per attack type subsumed in the attack classes of the NSL-KDD dataset, which could lead to generalization and overfitting regarding classification. Hence, we train a new RF classifier and SHAP explainer directly on the attack types. Classification performance is considerably improved, and the new explanations are matching the expectations based on domain knowledge better. Thus, we conclude that the imbalances in the dataset bias classification and consequently also the results of XAI methods like SHAP. However, the XAI methods can also be employed to find and debug issues and biases in the data and the applied model. Furthermore, the debugging results in higher trustworthiness of anomaly-based NIDS.
Eric Lanfer, Sophia Sylvester, Nils Aschenbruck, Martin Atzmüller
LCN1
2023 Demo: A Reproducible Link Emulation Environment for the Evaluation of Network-Coded Video Streaming
abstract
This demo presents link ’em version 2, an open source modification of the Linux Network Emulator (netem), to enable trace-based loss and delay emulation of pre-recorded real-world network conditions. It is used in an experimental setup to demonstrate and evaluate the impact of Network Coding-based Forward Erasure Correction for TCP (TCPyNC) on the performance of Dynamic Adaptive Streaming over HTTP (DASH). Thus, the proposed demonstration showcases the novel features of link ’em v2 and highlights the capability of network coding-based FEC to improve the overall video quality and reduce stalling of DASH video streams.
Stefanie Thieme, Dominic Laniewski, Leonhard Brüggemann, Eric Lanfer, Bertram Schütz, Nils Aschenbruck
LCN4
2022 Improving Proximity Classification for Contact Tracing using a Multi-channel Approach
abstract
Due to the COVID-19 pandemic, smartphone-based proximity tracing systems became of utmost interest. Many of these systems use Bluetooth Low Energy (BLE) signal strength data to estimate the distance between two persons. The quality of this method depends on many factors and, therefore, does hardly deliver accurate results. We present a multi-channel approach to improve proximity classification, and a novel, publicly available data set that contains matched IEEE 802.11 (2.4 & 5 GHz) and BLE signal strength data, measured in four different environments. We utilize these data to train machine learning models. The evaluation showed significant improvements in the distance classification and consequently also the contact tracing accuracy. However, we also encountered privacy problems and limitations due to the consistency and interval at which such probes are sent. We discuss these limitations and sketch how our approach could be improved to make it suitable for real-world deployment.
Eric Lanfer, Thomas Hänel, Roland van Rijswijk-Deij, Nils Aschenbruck
LCN1
2022 Developing a Scalable Network of High-Interaction Threat Intelligence Sensors for IoT Security
abstract
In the last decade, numerous Industrial IoT systems have been deployed. Attack vectors and security solutions for these are an active area of research. However, to the best of our knowledge, only very limited insight in the applicability and real-world comparability of attacks exists. To overcome this widespread problem, we have developed and realized an approach to collect attack traces at a larger scale. An easily deployable system integrates well into existing networks and enables the investigation of attacks on unmodified commercial devices.
Till Zimmermann, Eric Lanfer, Nils Aschenbruck
LCN2