EDBT 2026 Demo / reviewers in the wild / expert
Grenville J. Armitage
dblp:49/184 · also Grenville Armitage
· DBLP profile ↗
49ranked-venue papers
7as first author
2since 2021 · last 2025
0000-0002-2805-6511ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 44 · 7 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 1 first-authorSecurity and privacy · 1Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer networks
6 papers |
Content delivery and video streaming · 57% Network measurement and analytics · 22% Internet architecture and protocols · 9% |
Topics — the 16 heaviest of 18, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Content delivery and video streaming
adaptive video streaming |
0.7 | 1 | 2023 | Sammy: smoothing video traffic to be a friendly internet neighbor · SIGCOMM 2023 |
Content delivery and video streaming
quality of experience |
0.7 | 1 | 2023 | Sammy: smoothing video traffic to be a friendly internet neighbor · SIGCOMM 2023 |
Content delivery and video streaming
traffic smoothing |
0.7 | 1 | 2023 | Sammy: smoothing video traffic to be a friendly internet neighbor · SIGCOMM 2023 |
Transport protocols and congestion control
rate control |
0.2 | 1 | 2023 | Sammy: smoothing video traffic to be a friendly internet neighbor · SIGCOMM 2023 |
Network measurement and analytics › statistical inference
capture-recapture estimation |
0.2 | 1 | 2014 | Capturing ghosts: predicting the used IPv4 space by inferring unobserved addresses · Internet Measurement Conference 2014 |
Internet architecture and protocols › naming and addressing
IPv4 address space |
0.2 | 1 | 2014 | Capturing ghosts: predicting the used IPv4 space by inferring unobserved addresses · Internet Measurement Conference 2014 |
Network measurement and analytics
internet measurement |
0.1 | 1 | 2012 | Mitigating sampling error when measuring internet client IPv6 capabilities · Internet Measurement Conference 2012 |
Network measurement and analytics › traffic classification
machine-learning-based classification |
0.1 | 1 | 2012 | Timely and continuous machine-learning-based classification for interactive IP traffic · IEEE/ACM Trans. Netw. 2012 |
Network measurement and analytics
traffic classification |
0.1 | 1 | 2012 | Timely and continuous machine-learning-based classification for interactive IP traffic · IEEE/ACM Trans. Netw. 2012 |
Routing and switching › inter-domain routing
BGP |
0.1 | 1 | 2010 | A Technique for Reducing BGP Update Announcements through Path Exploration Damping · IEEE J. Sel. Areas Commun. 2010 |
Internet architecture and protocols › naming and addressing
address assignment |
0.1 | 1 | 2014 | Capturing ghosts: predicting the used IPv4 space by inferring unobserved addresses · Internet Measurement Conference 2014 |
Internet architecture and protocols › IPv6
IPv6 deployment |
0.0 | 1 | 2012 | Mitigating sampling error when measuring internet client IPv6 capabilities · Internet Measurement Conference 2012 |
Network management and operations
quality of service management |
0.0 | 1 | 2012 | Timely and continuous machine-learning-based classification for interactive IP traffic · IEEE/ACM Trans. Netw. 2012 |
Internet architecture and protocols
multicast |
0.0 | 1 | 1997 | IP Multicasting over ATM Networks · IEEE J. Sel. Areas Commun. 1997 |
Routing and switching
multicast routing |
0.0 | 1 | 1997 | IP Multicasting over ATM Networks · IEEE J. Sel. Areas Commun. 1997 |
Internet architecture and protocols
ATM networks |
0.0 | 1 | 1997 | IP Multicasting over ATM Networks · IEEE J. Sel. Areas Commun. 1997 |
Methods — techniques the papers use, named apart from their topics
joint ABR and rate control · 0.7application-informed pacing · 0.7trace analysis · 0.2ping scanning · 0.2capture-recapture · 0.2web-based measurement · 0.1sub-flow selection · 0.1naive bayes · 0.1c4.5 decision tree · 0.1ad-based recruitment · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Network Delivery Time Control: a Novel Approach to Rate Adaptation for Low-Latency Video FlowsabstractThis paper presents Network Delivery Time Control (NDTC), a new approach to rate-adaptive, low-latency media streaming for interactive services and currently used by Netflix’s cloud gaming service. At its core is our novel Frame Dithering Available Capacity Estimation (FDACE) heuristic. FDACE dithers frame emission periods of an application’s existing traffic and non-destructively estimates available path capacity from the distribution of frame reception periods over time. Unlike strategies that actively probe for excess capacity, FDACE avoids inducing symptoms of congestion such as increasing network latency or packet losses. Using FDACE-reported path conditions, NDTC dynamically adapts frame emission times, and frame sizes, for timely frame delivery. NDTC incorporates response to traditional congestion signals as a backstop against extreme real-world network conditions. We show that NDTC combines effective capacity estimation, on-time low-latency frame delivery, low self-induced loss rates, and fast response to abrupt network changes. Paul-Louis Ageneau, Grenville J. Armitage |
LCN | 2 |
| 2023 | Sammy: smoothing video traffic to be a friendly internet neighborabstractOn-demand streaming video traffic is managed by an adaptive bi-trate (ABR) algorithm whose job is to optimize quality of experience (QoE) for a single video session. ABR algorithms leave the question of sharing network resources up to transport-layer algorithms. We observe that as the internet gets faster relative to video streaming rates, this delegation of responsibility gives video traffic a burstier on-off traffic pattern. In this paper, we show we can substantially smooth video traffic to improve its interactions with the rest of the internet, while maintaining the same or better QoE for streaming video. We smooth video traffic with two design principles: application-informed pacing, which allows ABR algorithms to set an upper limit on packet-by-packet throughput, and by designing ABR algorithms that work with pacing. We propose a joint ABR and rate-control scheme, called Sammy, which selects both video quality and pacing rates. We implement our scheme and evaluate it at a large video streaming service. Our approach smooths video, making it a more friendly neighbor to other internet applications. One surprising result is that being friendlier requires no compromise for the video traffic: in large scale, production experiments, Sammy improves video QoE over an existing, extensively tested and tuned production ABR algorithm. Bruce Spang, Shravya Kunamalla, Renata Teixeira, Te-Yuan Huang, Grenville J. Armitage, Ramesh Johari, Nick McKeown |
SIGCOMM | 5 |
| 2020 | Detecting Bottleneck Use of PIE or FQ-CoDel Active Queue Management During DASH-like Content StreamingabstractDynamic Adaptive Streaming over HTTP (DASH) is a widely adopted standard for delivering high Quality of Experience (QoE) for consumer video streaming applications. The progressive deployment of Active Queue Management (AQM) schemes - such as PIE and FQ-CoDel - at ISP bottlenecks or home gateways means that consumers' video streams are increasingly impacted by such AQM schemes. However, many existing approaches do not consider adjusting streaming strategies based on the bottleneck queue types. We have previously demonstrated the benefits of AQM schemes for DASH video streams, and proposed adaptive chunklets for an improved streaming performance. In this paper, we demonstrate the problems of queue-agnostic streaming and propose a queue-detection technique during DASH-like streaming. This entirely client-side and application-level technique is capable of detecting likely FIFO, PIE and FQ-CoDel AQM schemes at network bottlenecks. Jonathan Kua, Philip Branch, Grenville J. Armitage |
LCN | 3 |
| 2020 | Adaptive Chunklets and AQM for Higher-Performance Content StreamingabstractCommercial streaming services such as Netflix and YouTube use proprietary HTTP-based adaptive streaming (HAS) techniques to deliver content to consumers worldwide. MPEG recently developed Dynamic Adaptive Streaming over HTTP (DASH) as a unifying standard for HAS-based streaming. In DASH systems, streaming clients employ adaptive bitrate (ABR) algorithms to maximise user Quality of Experience (QoE) under variable network conditions. In a typical Internet-enabled home, video streams have to compete with diverse application flows for the last-mile Internet Service Provider (ISP) bottleneck capacity. Under such circumstances, ABR algorithms will only act upon the fraction of the network capacity that is available, leading to possible QoE degradation. We have previously explored chunklets as an approach orthogonal to ABR algorithms, which uses parallel connections for intra-video chunk retrieval. Chunklets effectively make more bandwidth available for ABR algorithms in the presence of cross-traffic, especially in environments where Active Queue Management (AQM) schemes such as Proportional Integral controller Enhanced (PIE) and FlowQueue-Controlled Delay (FQ-CoDel) are deployed. However, chunklets consume valuable server/middlebox resources which typically handle hundreds of thousands of requests/connections per second. In this article, we propose ‘adaptive chunklets’ -- a novel chunklet enhancement that dynamically tunes the number of concurrent connections. We demonstrate that the combination of adaptive chunklets and FQ-CoDel is the most effective strategy. Our experiments show that adaptive chunklets can reduce the number of connections by almost 30% and consume almost 8% less bandwidth than fixed chunklets while providing the same QoE. Jonathan Kua, Grenville J. Armitage, Philip Branch, Jason But |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2017 | Benefits of FlowQueue-Based Active Queue Management for Interactive Online GamesabstractConsumers frequently get Internet access through a single home gateway. Gateways using conventional FIFO queue management can introduce hundreds or even thousands of milliseconds of additional delay when congested by bulk TCP data transfers. This delay impacts negatively on any latency-sensitive interactive traffic (such as Voice over IP, or First Person Shooter games). Such applications prefer network connectivity having low latency and low packet loss. New approaches using Active Queue management (AQM) schemes keep queuing delays low by getting TCP to react sooner through the implementation of early packet drops. We characterise the collateral damage caused to interactive application flows by single-queue (CoDel and PIE) and multi-queue (FQ-CoDel) AQM schemes, and provide strong experimental evidence to support widespread deployment of multi-queue (FQ) variants. Grenville J. Armitage, Russell Collom |
ICCCN | 1 |
| 2017 | Optimising DASH over AQM-Enabled Gateways Using Intra-Chunk Parallel Retrieval (Chunklets)abstractMultimedia streaming is a significant source of Internet traffic, with Netflix and YouTube accounting for more than 50% of North American fixed network peak download traffic in 2016. Dynamic Adaptive Streaming over HTTP (DASH) is a recent standard for live and on-demand video streaming services, where clients adapt the video quality on-the-fly to match the network capacity by requesting multi-rate video chunk-by-chunk. Emerging Active Queue Management (AQM) schemes such as PIE and FQ-CoDel are being progressively deployed either at the ISP-end and/or home gateway to counter bufferbloat and will impact consumer DASH streams. We propose using intra-chunk parallel connections (chunklets) to retrieve DASH content when bottlenecks implement AQMs. We experimentally evaluate and characterise the impact of using chunklets over traditional FIFO, symmetric/asymmetric PIE and FQ-CoDel AQM bottlenecks. We show FQ-CoDel's flow isolation and fair capacity sharing ability enables DASH chunklets to attain the best throughput multiplication effect, hence translating to better user experience in the presence of competing elastic flows. Jonathan Kua, Grenville J. Armitage |
ICCCN | 2 |
| 2017 | Characterising LEDBAT Performance Through Bottlenecks Using PIE, FQ-CoDel and FQ-PIE Active Queue ManagementabstractLow Extra Delay Background Transport (LEDBAT) is defined in RFC6817 as a congestion control algorithm for lower than best effort transport service that reacts to both delay and loss congestion signals. LEDBAT allows bulk transfer applications (such peer-to-peer file transfer and software updates) to utilize available capacity in the background while limiting additional forward queuing delays at network bottlenecks to 100ms. New Active Queue Management(AQM) schemes similarly aim for low latencies by dropping or marking packets when the bottleneck queuing delay exceeds thresholds much lower than 100ms. Due to renewed interest in deploying modern AQMs on home broadband services, we experimentally evaluate and characterize the impact of placing PIE, FQ-CoDel and FQ-PIE variants of AQM in the path of flows generated by libutp (a widely deployed UDP-based LEDBAT implementation). We uncover, and propose solutions to, some differences between libutp and RFC6817 that lead to poor utilization and incorrect inter-flow capacity sharing over AQM bottlenecks. Rasool Al-Saadi, Grenville J. Armitage, Jason But |
LCN | 2 |
| 2017 | Collaborative and privacy-preserving estimation of IP address space utilisation
Sebastian Zander, Lachlan L. H. Andrew, Grenville J. Armitage |
Comput. Networks | 3 |
| 2017 | Using Active Queue Management to Assist IoT Application Flows in Home Broadband NetworksabstractInternet of Things (IoT) applications such as telehealth, smart appliances, and smart energy are becoming more common within the home. However, they must compete for bandwidth with traditional applications such as video streaming, video conferencing, and bulk file transfers. Such competition can be detrimental to the IoT applications when home gateways use traditional first-in-first-out (FIFO) queue management. Simply increasing bandwidth between the home gateway and the Internet Service Provider (ISP), even when possible, provides no guarantee of bandwidth for IoT applications since many traditional applications will consume as much bandwidth as is available. In this paper, we explore whether active queue management (AQM), now being implemented in home gateways, can provide protection for IoT flows. We investigate the effect of different AQM algorithms deployed at the home gateway in scenarios with multiple concurrent application flows. We find that deploying multiqueue FlowQueue Controlled Delay (FQ-CoDel) or the hybrid FlowQueue Proportional Integral Controller Enhanced (FQ-PIE) at the home gateway can provide excellent capacity sharing, flow isolation, and good protection in terms of throughput and queuing delays for IoT flows and other applications, which cannot be achieved with traditional FIFO or other single-queue AQMs such as Proportional Integral Controller Enhanced (PIE). Jonathan Kua, Suong H. Nguyen, Grenville J. Armitage, Philip Branch |
IEEE Internet Things J. | 3 |
| 2016 | Potential redundant link fail-over strategies for uptime-sensitive medical telemetry applicationsabstractFor some devices and services, a consistently reliable connection to the internet is crucial; a failure to report to an internet service could result in significant financial or property damage or loss of life. We propose a solution through the development and testing of a “High-availability Internet Gateway” (HaIG) which can be installed into a network and utilise multiple redundant internet connections in order to guarantee uptime for a secure tunnel for medical devices. Three potential solutions are evaluated: Layer 2 Bonding (L2B), Multipath TCP (MPTCP) and Stream Control Transport Protocol (SCTP). MPTCP and L2B were found to be less suitable than SCTP at providing a reliable, high-availability fail-over solution. We incorporated the SCTP-based solution into a consumer networking device running OpenWRT, and used controlled testbed trials to demonstrate the use of redundant internet connections for providing a high-availability connection for applications such as remote cardiac monitoring. Isaac True, Grenville J. Armitage |
HealthCom | 2 |
| 2016 | Improving the Fairness of Alternative Backoff with ECN (ABE)abstractExplicit Congestion Notification (ECN) lets a bottleneck's Active Queue Management (AQM) mechanism inform an endpoint about congestion without having to drop a packet. A recently proposed sender-side modification called Alternative Backoff with ECN (ABE) enables reduced latency while maintaining good utilization with ECN. However, under certain circumstances ABE can produce a degree of unfair behavior between ABE-enabled TCP senders and conventional TCP senders. We propose specific guidance for configuring bottleneck AQMs to assist in fairness between ABE-enabled and conventional TCP flows. We evaluate our proposal using RED, then describe how it can be applied to other AQM mechanisms and incrementally introduced into the Internet. Naeem Khademi, Michael Welzl, Grenville J. Armitage, Stein Gjessing |
LCN | 3 |
| 2016 | The Impact of Active Queue Management on DASH-Based Content DeliveryabstractWith Netflix and YouTube accounting for more than 50% of North American, fixed network peak download traffic in 2015, video streaming is a significant source of Internet traffic. Dynamic Adaptive Streaming over HTTP (DASH) is a recent standard for live and on-demand video streaming services, where clients adapt their behaviour on-the-fly to match regularly updated estimates of network capacity. Consumer DASH streams are likely to be bottlenecked by last-mile ISP links, and impacted by emerging active queue management (AQM) schemes being deployed to counter bufferbloat. We experimentally characterise and evaluate the impact of bottlenecks utilising PIE, FQ-PIE, CoDel and FQ-CoDel AQM schemes on DASH streams. We show that PIE's higher burst tolerance provides better streaming quality for single DASH stream over moderate to high RTT paths and when coupled with a FlowQueue scheduler's flow isolation capabilities, FQ-PIE protects DASH streams in the presence of cross-traffic. Jonathan Kua, Grenville J. Armitage, Philip Branch |
LCN | 2 |
| 2015 | Detecting BGP instability using Recurrence Quantification Analysis (RQA)abstractThe Border Gateway Protocol (BGP) is the default Internet routing protocol that manages connectivity among Autonomous Systems (ASes). Although BGP disruptions are rare, when they occur the consequences can be very damaging. Consequently there has been considerable effort aimed at understanding what is normal and abnormal BGP traffic and, in so doing, enable potentially disruptive anomalous traffic to be identified quickly. In this paper, we make two contributions. We show that over time BGP messages from BGP speakers have deterministic, recurrence and non-linear properties, then build on this insight to introduce the idea of using Recurrence Quantification Analysis (RQA) to detect BGP instability. RQA can be used to provide rapid identification of traffic anomalies that can lead to BGP instability. Furthermore, RQA is able to detect abnormal behaviours that may pass without observation. Bahaa Al-Musawi, Philip Branch, Grenville J. Armitage |
IPCCC | 3 |
| 2014 | Capturing ghosts: predicting the used IPv4 space by inferring unobserved addressesabstractThe pool of unused routable IPv4 prefixes is dwindling, with less than 4% remaining for allocation at the end of June 2014. Yet the adoption of IPv6 remains slow. We demonstrate a new capture-recapture technique for improved estimation of the size of "IPv4 reserves" (allocated yet unused IPv4 addresses or routable prefixes) from multiple incomplete data sources. A key contribution of our approach is the plausible estimation of both observed and unobserved-yet-active (ghost) IPv4 address space. This significantly improves our community's understanding of IPv4 address space exhaustion and likely pressure for IPv6 adoption. Using "ping scans", network traces and server logs we estimate that 6.3 million /24 subnets and 1.2 billion IPv4 addresses are currently in use (roughly 60% and 45% of the publicly routed space respectively). We also show how utilisation has changed over the last 2--3 years and provide an up-to-date estimate of potentially-usable remaining IPv4 space. Sebastian Zander, Lachlan L. H. Andrew, Grenville J. Armitage |
Internet Measurement Conference | 3 |
| 2013 | Using delay-gradient TCP for multimedia-friendly 'background' transport in home networksabstractHome networks are seeing increased deployment of Wireless LAN (WiFi) links between conventional, gigabit/second wired Ethernet segments. This means an increasing number of internal bottlenecks, even as home networks are also expected to support latency-sensitive applications, regular TCP flows and an emerging class of low-priority, time-insensitive `background' TCP flows. This paper explores the novel use of CDG v0.1 (a delay-gradient TCP) for such background TCP connections in home networks. We show a CDG flow induces latencies of only tens of milliseconds regardless of the bottleneck's internal buffer size (useful when coexisting with latency-sensitive traffic) while achieving a significant fraction of spare link capacity. We also show CDG does not gratuitously steal capacity from commonly deployed “foreground” TCPs such as CUBIC and NewReno. Grenville J. Armitage, Naeem Khademi |
LCN | 1 |
| 2013 | Minimally-intrusive frequent round trip time measurements using Synthetic Packet-PairsabstractAccurate and frequent round trip time (RTT) measurements are important in testbeds and operational networks. Active measurement techniques inject probe packets that may modify the behaviour of the observed network and may produce misleading RTT estimates if the network handles probe packets differently to regular packets. Previous passive measurement techniques address these issues, but require precise time synchronisation or are limited to certain traffic types. We introduce Synthetic Packet-Pairs (SPP), a novel passive technique for RTT measurement. SPP provides frequently updated RTT measurements using any network traffic already present in the network without the need for time synchronisation. SPP accurately measures the RTT experienced by any application's traffic, even applications that do not exhibit symmetric client-server packet exchanges. We experimentally demonstrate the advantages of SPP. Sebastian Zander, Grenville J. Armitage |
LCN | 2 |
| 2013 | Guest editorial for special issue on network and systems support for games
Shervin Shirmohammadi, Carsten Griwodz, Grenville J. Armitage |
Multim. Syst. | 3 |
| 2012 | Mitigating sampling error when measuring internet client IPv6 capabilitiesabstractDespite the predicted exhaustion of unallocated IPv4 addresses between 2012 and 2014, it remains unclear how many current clients can use its successor, IPv6, to access the Internet. We propose a refinement of previous measurement studies that mitigates intrinsic measurement biases, and demonstrate a novel web-based technique using Google ads to perform IPv6 capability testing on a wider range of clients. After applying our sampling error reduction, we find that 6% of world-wide connections are from IPv6-capable clients, but only 1--2% of connections preferred IPv6 in dual-stack (dual-stack failure rates less than 1%). Except for an uptick around IPv6-day 2011 these proportions were relatively constant, while the percentage of connections with IPv6-capable DNS resolvers has increased to nearly 60%. The percentage of connections from clients with native IPv6 using happy eyeballs has risen to over 20%. Sebastian Zander, Lachlan L. H. Andrew, Grenville J. Armitage, Geoff Huston, George Michaelson |
Internet Measurement Conference | 3 |
| 2012 | Sub-flow packet sampling for scalable ML classification of interactive trafficabstractMachine Learning (ML) classifiers have been shown to provide accurate, timely and continuous IP flow classification when evaluating sub-flows (short moving windows of packets within flows). They can be used to provide automated QoS management for interactive traffic, such as fast-paced multiplayer games or VoIP. As with other ML classification approaches, previous sub-flow techniques have assumed all packets in all flows are being observed and evaluated. This limits scalability and poses a problem for practical deployment in network core or edge routers. In this paper we propose and evaluate subflow packet sampling (SPS) to reduce an ML sub-flow classifier's resource requirements with minimal compromise of accuracy. While random packet sampling increases classification time from <;1 second to over 30 seconds and can reduce accuracy from 98% to <;90%, our tailored SPS technique retains classification times of <;1 second while providing 98% accuracy. Sebastian Zander, Thuy T. T. Nguyen, Grenville J. Armitage |
LCN | 3 |
| 2012 | REED: Optimizing first person shooter game server discovery using network coordinatesabstractOnline First Person Shooter (FPS) games typically use a client-server communication model, with thousands of enthusiast-hosted game servers active at any time. Traditional FPS server discovery may take minutes, as clients create thousands of short-lived packet flows while probing all available servers to find a selection of game servers with tolerable round trip time (RTT). REED reduces a client's probing time and network traffic to 1% of traditional server discovery. REED game servers participate in a centralized, incremental calculation of their network coordinates, and clients use these coordinates to expedite the discovery of servers with low RTTs. Grenville J. Armitage, Amiel Heyde |
ACM Trans. Multim. Comput. Commun. Appl. | 1 |
| 2012 | Timely and continuous machine-learning-based classification for interactive IP trafficabstractMachine Learning (ML) for classifying IP traffic has relied on the analysis of statistics of full flows or their first few packets only. However, automated QoS management for interactive traffic flows requires quick and timely classification well before the flows finish. Also, interactive flows are often long-lived and should be continuously monitored during their lifetime. We propose to achieve this by using statistics derived from sub-flows—a small number of most recent packets taken at any point in a flow's lifetime. Then, the ML classifier must be trained on a set of sub-flows, and we investigate different sub-flow selection strategies. We also propose to augment training datasets so that classification accuracy is maintained even when a classifier mixes up client-to-server and server-to-client directions for applications exhibiting asymmetric traffic characteristics. We demonstrate the effectiveness of our approach with the Naive Bayes and C4.5 Decision Tree ML algorithms, for the identification of first-person-shooter online game and VoIP traffic. Our results show that we can classify both applications with up to 99% Precision and 95% Recall within less than 1 s. Stable results are achieved regardless of where within a flow the classifier captures the packets and the traffic direction. Thuy T. T. Nguyen, Grenville J. Armitage, Philip Branch, Sebastian Zander |
IEEE/ACM Trans. Netw. | 2 |
| 2011 | Practical machine learning based multimedia traffic classification for distributed QoS managementabstractA multi-service Internet requires routers to recognise and prioritise IP flows carrying interactive or multimedia traffic. It is increasingly problematic for legal or administrative reasons to recognise such flows using unique port numbers or deep packet inspection. New work in recent years shows that Machine Learning (ML) techniques can use externally observable statistical characteristics to usefully differentiate such IP traffic. However, most previous work has not addressed the practicality of ML-based traffic classification in terms of CPU and memory usage. Here we describe our design, implementation and performance evaluation of a distributed, ML-based traffic classification and control system for FreeBSD's IP Firewall (IPFW). On an Intel Core i7 2.8 GHz PC our system can classify up to 400 000 packets per second using only one core and our system scales well to up to 100 000 simultaneous flows. Also our implementation allows one classifier PC to control subsequent traffic shaping or blocking at multiple (potentially lower performance) routers or gateways distributed around the network. Sebastian Zander, Grenville J. Armitage |
LCN | 2 |
| 2011 | Multimedia-unfriendly TCP congestion control and home gateway queue managementabstractConsumer broadband services are increasingly a mix of TCP-based and UDP-based applications, often with quite distinct requirements for interactivity and network performance. Consumers can experience degraded service when application traffic collides at a congestion point between home LANs, service provider edge networks and fractional-Mbit/sec `broadband' links. We illustrate two key issues that arise from the impact of TCP-based data transfers on real-time traffic (such as VoIP or online games) sharing a broadband link. First, well-intentioned modifications to traditional TCP congestion control can noticeably increase the latencies experienced by VoIP or online games. Second, superficially-similar packet dropping rules in broadband gateways can induce distinctly different packet loss rates in VoIP and online game traffic. Our observations provide cautionary guidance to researchers who model such traffic mixes, and to vendors implementing equipment at either end of consumer links. Lawrence Stewart, David A. Hayes, Grenville J. Armitage, Michael Welzl, Andreas Petlund |
MMSys | 3 |
| 2011 | Revisiting TCP Congestion Control Using Delay Gradients
David A. Hayes, Grenville J. Armitage |
Networking (2) | 2 |
| 2011 | Stealthier Inter-packet Timing Covert Channels
Sebastian Zander, Grenville J. Armitage, Philip Branch |
Networking (1) | 2 |
| 2011 | Improving HTTP performance using "stateless" TCPabstractTCP is quite a heavyweight protocol when serving very small web pages. We introduce a server-side kernel modification which enables a web server to perform HTTP over a UDP socket while the kernel provides a regular TCP interface 'on the wire' to remote clients. We show that our 'stateless' TCP modification can greatly reduce a server's CPU usage (>20%) and TCP related memory requirements(>90%), potentially enabling it to serve small web pages even under extreme overload conditions. David A. Hayes, Michael Welzl, Grenville J. Armitage, Mattia Rossi |
NOSSDAV | 3 |
| 2011 | Inferring the time-zones of prefixes and autonomous systems by monitoring game server discovery trafficabstractGeolocation of IP addresses is used for determining authenticity of webpages, delivering specific country or location related content and advertisements, or to add security for online transactions. Although IP geolocation databases exist, it is sometimes useful to validate their entries or create new, independent databases using independent sources of information. We propose and demonstrate a method whereby collecting and analyzing online game server discovery traffic over short periods of time can allow us to detect in which timezone a certain prefix or AS is located. Our method provides very good estimates of various AS timezones which we verify using publicly available IP geolocation databases. Mattia Rossi, Philip Branch, Grenville J. Armitage |
NOSSDAV | 3 |
| 2010 | Improved coexistence and loss tolerance for delay based TCP congestion controlabstractLoss based TCP congestion control has been shown to not perform well in environments were there is non-congestion related packet losses. Delay based TCP congestion control algorithms provide a low latency connection with no congestion related packet losses, and have the potential for being tolerant to non-congestion related losses. Unfortunately, delay based TCP does not compete well with loss based TCP, currently limiting its deployment. We propose a delay based algorithm which extends work by Budzisz et al. to provide tolerance to non-congestion related losses, and better coexistence with loss based TCP in lightly multiplexed environments. We demonstrate that our algorithm improves the throughput when there are 1% packet losses by about 150%, and gives more than 50% improvement in the ability to share capacity with NewReno in lightly multiplexed environments. David A. Hayes, Grenville J. Armitage |
LCN | 2 |
| 2010 | Minimising Disruption Caused by Online FPS Game Server Discovery in a Wireless NetworkabstractA key part of First Person Shooter network gaming is the game server discovery phase. Whilst probing for suitable servers from a wireless network, a large burst of network traffic is generated, potentially leading to detrimental effects on network capacity available to other wireless users. This can be minimised using an optimised algorithm to order the discovery probes and subsequently terminate the discovery process early. In this paper we explore further modifications to a previously proposed algorithm and examine its efficacy in further reducing the probe time/traffic during the server discovery phase. We show that it is possible to further reduce the overall discovery process duration by up to 13% while still presenting all suitable servers to the user for selection. Jason But, Christopher Leong, Philip Branch, Grenville J. Armitage |
WCNC | 4 |
| 2010 | A Technique for Reducing BGP Update Announcements through Path Exploration DampingabstractThis paper defines and evaluates Path Exploration Damping (PED) - a router-level mechanism for reducing the volume of propagation of likely transient update messages within a BGP network and decreasing average time to restore reachability compared to current BGP Update damping practices. PED selectively delays and suppresses the propagation of BGP updates that either lengthen an existing AS Path or vary an existing AS Path without shortening its length. We show how PED impacts on convergence time compared to currently deployed mechanisms like Route Flap Damping (RFD), Minimum Route Advertisement Interval (MRAI) and Withdrawal Rate Limiting (WRATE). We replay Internet BGP update traffic captured at two Autonomous Systems to observe that a PED-enabled BGP speaker can reduce the total number of BGP announcements by up to 32% and reduce Path Exploration by 77% compared to conventional use of MRAI. We also describe how PED can be incrementally deployed in the Internet, as it interacts well with prevailing MRAI deployment, and enables restoration of reachability more quickly than MRAI. Geoff Huston, Mattia Rossi, Grenville J. Armitage |
IEEE J. Sel. Areas Commun. | 3 |
| 2009 | Reliable transmission over covert channels in first person shooter multiplayer gamesabstractWe propose and evaluate a novel improvement to a previously published, unreliable covert channel based on the network traffic of multiplayer, first person shooter online games (FPSCC). Covert channels typically embed themselves within pre-existing (overt) data transmissions in order to carry hidden messages. FPSCC encodes covert bits as slight, yet continuous, variations of a player's character's movements. These variations are visually imperceptible to human players, yet occur frequently enough to create a low bit-rate covert channel. The nature of first person shooter network protocols means the original FPSCC channel is noisy (not reliable), experiencing a significant number of bit errors (including synchronisation errors). We have now augmented FPSCC to ensure bits are transmitted reliably. Evaluation of our technique with a prototype demonstrates throughput of up to 13 bits/second without any bit errors. Sebastian Zander, Grenville J. Armitage, Philip Branch |
LCN | 2 |
| 2009 | Collateral Damage: The Impact of Optimised TCP Variants on Real-Time Traffic Latency in Consumer Broadband Environments
Lawrence Stewart, Grenville J. Armitage, Alana Huebner |
Networking | 2 |
| 2009 | Rapid identification of Skype traffic flowsabstractIn this paper we present results of experimental work using machine learning techniques to rapidly identify Skype traffic. We show that Skype traffic can be identified by observing 5 seconds of a Skype traffic flow, with recall and precision better than 98%. We found the most effective features for classification were characteristic packet lengths less than 80 bytes, statistics of packet lengths greater than 80 bytes and inter-packet arrival times. Our classifiers do not rely on observing any particular part of a flow. We also report on the performance of classifiers built using combinations of two of these features and of each feature in isolation. Philip Branch, Amiel Heyde, Grenville J. Armitage |
NOSSDAV | 3 |
| 2008 | A Markov Model of Server to Client IP Traffic in First Person Shooter GamesabstractModeling traffic generated by Internet based multiplayer computer games has attracted a great deal of attention in the past few years. In part this has been driven by a need to simulate the network impact of highly interactive online games such as the first person shooter (FPS). Packet size distributions and autocorrelation models are important elements in the creation of realistic traffic generators for network simulators. In this paper we present a simple technique for constructing Markov chains that model autocorrelated packet length for N-player FPS games based on traffic traces of of 2- player games. This enables us to synthesize the time sequence of the length of server to client traffic as well as its probability distribution. We illustrate the likely generality of our approach using data from seven FPS games that have been popular over the past nine years: half-life, half-life counterstrike, half-life 2, half-life 2 counterstrike, quake III arena, quake 4 and Wolfenstein enemy territory. Philip Branch, Antonio L. Cricenti, Grenville J. Armitage |
ICC | 3 |
| 2008 | Clustering to Assist Supervised Machine Learning for Real-Time IP Traffic ClassificationabstractLiterature on the use of machine learning (ML) algorithms for classifying IP traffic has demonstrated potential to be deployed in real-world IP networks. The key challenges of timely and continuous classification are addressed, in which multiple short sub-flows taken at different points within the original application's flow lifetime are used to train the classifier. The classification decision process is repeated continuously using a sliding window of the flow's most recent N packets. The work left a critical question of how to automate the identification of appropriate sub-flows for training. In this paper we propose a novel approach for sub-flows identification and selection using ML clustering algorithms. We evaluate our approach using accuracy, model build time, classification speed and physical resource consumption metrics. Thuy T. T. Nguyen, Grenville J. Armitage |
ICC | 2 |
| 2008 | Covert channels in multiplayer first person shooter online gamesabstractCovert channels aim to hide the existence of communication between two or more parties. Such channels typically utilise pre-existing (overt) data transmissions to carry hidden messages. Internet-based covert channels often encode new information into unused (or loosely specified) IP packet header fields, or the time intervals between IP packet arrivals. We propose a novel covert channel embedded within the traffic of multiplayer, first person shooter online games. We encode covert bits as slight, yet continuous, variations of a playerpsilas characterpsilas movements. Movement information is propagated to all clients attached to a given game server, yet the channel remains covert so long as the variations are visually imperceptible to the human players. A modified version of Quake III Arena is used to demonstrate our concept. We empirically analyse the covert channelpsilas bit rate, and compare the statistical characteristics of unmodified game traffic with those of game traffic carrying covert information. Sebastian Zander, Grenville J. Armitage, Philip Branch |
LCN | 2 |
| 2008 | An ARMA(1, 1) prediction model of first person shooter game trafficabstractModeling traffic generated by Internet-based multiplayer computer games has attracted a great deal of attention in the past few years. In part this has been driven by a need to simulate correctly the network impact of highly interactive online game genres such as the first person shooter (FPS). Packet size distributions and autocovariance models are important elements in the creation of realistic traffic generators for network simulators. In this paper we present simple techniques for creating representative models for N-player FPS games based on empirically measured traffic of 2- and 3-player games. The models capture the packet size distribution as well as the time series behaviour of game traffic. We illustrate the likely generality of our approach using data from seven FPS games that have been popular over the past nine years: Half-Life, Half-Life Counterstrike, Half-Life 2, Half-Life 2 Counterstrike, Quake III Arena, Quake 4 and Wolfenstein Enemy Territory. Philip Branch, Antonio L. Cricenti, Grenville J. Armitage |
MMSP | 3 |
| 2008 | Client-Side Adaptive Search Optimisation for Online Game Server Discovery
Grenville J. Armitage |
Networking | 1 |
| 2008 | Optimising online FPS game server discovery through clustering servers by origin autonomous systemabstractThis paper describes the use of origin Autonomous System (AS) information to optimise online First Person Shooter (FPS) game server discovery. Online FPS games typically use a client-server model, with thousands of game servers active at any time. Traditional server discovery probes all available servers over multiple minutes in no particular order, creating thousands of short-lived UDP flows. Using Valve's Counterstrike:Source game this paper demonstrates a multi-step process: Sort available game servers by origin AS, probe a subset of servers in each AS, rank each AS in ascending order of estimated round trip time (RTT), then probe all remaining game servers according to the rank of their origin AS. Probing game servers in approximately ascending RTT expedites the identification of playable servers. This new approach may take less than 20% of the time and network traffic of conventional server discovery (without exceeding conventional server discovery time and traffic consumption in the worst case). Grenville J. Armitage |
NOSSDAV | 1 |
| 2006 | Training on multiple sub-flows to optimise the use of Machine Learning classifiers in real-world IP networksabstractLiterature on the use of machine learning (ML) algorithms for classifying IP traffic has relied on full-flows or the first few packets of flows. In contrast, many real-world scenarios require a classification decision well before a flow has finished even if the flow's beginning is lost. This implies classification must be achieved using statistics derived from the most recent N packets taken at any arbitrary point in a flow's lifetime. We propose training the classifier on a combination of short sub-flows (extracted from full-flow examples of the target application's traffic). We demonstrate this optimisation using the naive Bayes ML algorithm, and show that our approach results in excellent performance even when classification is initiated mid-way through a flow with windows as small as 25 packets long. We suggest future use of unsupervised ML algorithms to identify optimal sub-flows for training Thuy T. T. Nguyen, Grenville J. Armitage |
LCN | 2 |
| 2006 | Real-time collaborative network monitoring and control using 3D game engines for representation and interactionabstractIdentifying and reacting to malicious or anomalous IP traffic is a significant challenge for network operators. Automated real-time responses have been simplistic and require followup actions by technically specialised employees. We describe a system where off-the-shelf 3D game-engine technology enables collaborative network control through familiar "interaction" metaphors by translating network events into visually-orthogonal "activities". Anomalous behaviour is targeted by the managers-as-players using in-game techniques, such as "shooting" or "healing", resulting in defensive actions (such as updates to a firewall's access control list) being instantiated behind the scenes. Warren Harrop, Grenville J. Armitage |
VizSEC | 2 |
| 2005 | Passive TCP Stream Estimation of RTT and Jitter ParametersabstractThere exist many tools to passively monitor a link for traffic flows. They are typically used near the edge of the network, but not necessarily at the termination point of data flows - usually within a few hops of end-points. Round trip time (RTT) values for individual flows is of interest for network management purposes and can be used to indicate user experienced network delay, and in network design decisions. Determining the RTT when not at an end-point of a data flow is complicated by the fact that packets may be seen out of order and that witnessed packets may not reach their destination. In this paper we present an algorithm to estimate running RTT and jitter characteristics of TCP streams monitored at the midpoint of a TCP flow Jason But, Urs Keller, Grenville J. Armitage |
LCN | 3 |
| 2005 | Defining and Evaluating Greynets (Sparse Darknets)abstractDarknets are increasingly being proposed as a means by which network administrators can monitor for anomalous, externally sourced traffic. Current darknet designs require large, contiguous blocks of unused IP addresses - not always feasible for enterprise network operators. In this paper we introduce, define and evaluate the concept of a greynet - a region of IP address space that is sparsely populated with 'darknet' addresses interspersed with active (or 'lit') IP addresses. We use raw traffic traces collected within a university network to evaluate how sparseness affects a greynet 's effectiveness and hence show that enterprise operators can achieve useful levels of network scan detection, with only small numbers of 'dark' IP addresses making up their greynets Warren Harrop, Grenville J. Armitage |
LCN | 2 |
| 2005 | Automated Traffic Classification and Application Identification using Machine LearningabstractThe dynamic classification and identification of network applications responsible for network traffic flows offers substantial benefits to a number of key areas in IP network engineering, management and surveillance. Currently such classifications rely on selected packet header fields (e.g. port numbers) or application layer protocol decoding. These methods have a number of shortfalls e.g. many applications can use unpredictable port numbers and protocol decoding requires a high amount of computing resources or is simply infeasible in case protocols are unknown or encrypted. We propose a novel method for traffic classification and application identification using an unsupervised machine learning technique. Flows are automatically classified based on statistical flow characteristics. We evaluate the efficiency of our approach using data from several traffic traces collected at different locations of the Internet. We use feature selection to find an optimal feature set and determine the influence of different features Sebastian Zander, Thuy T. T. Nguyen, Grenville J. Armitage |
LCN | 3 |
| 2005 | Experimental validation of the random waypoint mobility model through a real world mobility trace for large geographical areasabstractUser mobility models are used in simulations of mobile communications systems to study characteristics of network performance. One of the models which is in common use is the Random Waypoint Model (RWP). The RWP is a simple mobility model based on random destinations, speeds and pause times. The RWP is often criticised as not representing how humans actually move. Paradoxically, validation against real mobility data is seen as being difficult due to the impracticalities of obtaining real mobility data.We give details of a real world user movement trace from which we obtained data about one individual's destinations, travel routes, average speed and rest times whilst moving throughout a city-wide area. We present results from this real life data and use it to validate some of the key characteristics of the RWP. In this paper we consider the RWP as a model of user mobility in networks that cater for a large geographical area - such as a city. Andres Rojas, Philip Branch, Grenville J. Armitage |
MSWiM | 3 |
| 2005 | A traffic model for the Xbox game Halo 2abstractThis paper analyses the traffic characteristics of, and proposes a traffic model for, the Xbox game Halo 2. Our goal is to help players and network providers to estimate the amount of traffic caused by the game and the impact on access links or provider networks. It also enables other researchers to use a realistic Halo 2 traffic model in network simulations. We focus on the following characteristics: bandwidth, packet rate and distribution of packet inter-arrival times and packet lengths. We compare the results with a previous analysis of Halo 1 and find some major differences - the client packet rate has been reduced, packet sizes have no longer a single fixed value per game and the mean packet size has decreased (so Halo 2 requires less bandwidth). Finally we develop traffic simulation models for Halo 2 and compare them against the experimentally obtained data. Sebastian Zander, Grenville J. Armitage |
NOSSDAV | 2 |
| 2004 | Experimentally derived interactions between TCP traffic and service quality over DOCSIS cable linksabstractWe study the effect of upstream (US) and downstream (DS) rate caps and DOCSIS media access on the end-to-end performance of broadband IP services that share a typical home-access 'cable Internet' link. Our experimental study measures the performance of actual DOCSIS equipment in a typical network configuration. We observe that modestly long lived data transfers in the DS direction can create substantial latency spikes (over 100 ms) in the shared DOCSIS segment, even when the DS rate cap is one or two megabits per second. Such spikes can have a big impact on delay-sensitive applications, such as voice over IP (VoIP), online games and interactive streaming video that may be sharing the DOCSIS link. We also experimentally characterize the impact of US and DS bandwidth asymmetry, MTU sizes, and TCP window sizes in achieving maximum performance over DOCSIS links. Thuy T. T. Nguyen, Grenville J. Armitage |
GLOBECOM | 2 |
| 1997 | IP Multicasting over ATM NetworksabstractThe Internet protocol (IP) multicast model involves a combination of intrasubnet and intersubnet multicast mechanisms. Technologies supporting a given subnet are expected to have native mechanisms for supporting intrasubnet forwarding of packets sent to multicast destinations. Multicast routers attach to subnets and provide intersubnet forwarding of multicast packets, using interdomain multicast routing protocols developed by the Internet Engineering Task Force (IETF). Unfortunately, ATM networks based on UNI 3.0 or UNI 3.1 signaling service do not provide the native multicast support expected by IP. This has led the IETF to develop the "MARS model"-a fairly complex mechanism for emulating intrasubnet multicast support required when running IPs over ATMs. This paper takes a high level look at the IP multicast service, examines the limitations of the ATM point-to-multipoint virtual channel service, and describes the major architectural points of the MARS model. Grenville J. Armitage |
IEEE J. Sel. Areas Commun. | 1 |
| 1993 | Using the common LAN to introduce ATM connectivityabstractA method for using LAN technologies to transport asynchronous transfer mode (ATM) cells is outlined. B-ISDN service requirements are broken into three groups, i.e., high speed media, multimedia interfaces, and service control software. Compression techniques for bandwidth intensive services are discussed. It is argued that these services may be provided using sub-Mb/s ATM links. The ATM concept is shown to be independent of the physical layer, allowing low-speed services to be implemented and utilized before high speed links are in place. An architecture is described where a LAN/fiber gateway switches cells between an external B-ISDN fiber and an in-house Ethernet based ATM network. Grenville J. Armitage, Keith M. Adams |
LCN | 1 |