This paper presents the design, analysis and performance evaluation of VRing, a novel application-layer multicast (ALM) protocol that establishes a virtual ring as an overlay network among the multicast group members in a self- organizing and distributed manner. VRing takes advantage of the inherent desirable property of a ring; namely, the degree of each node on the ring is O(1) (i.e., independent of the number of the multicast group members) and hence, the state maintained at each multicast group member is also O(1). This property significantly eases the key distribution process, as each member has exactly one predecessor and one successor. In order to reduce the routing delay and increase the survivability of the ring overlay network, we propose to form a spare ring overlay structure that improves connectivity among multicast group members. Furthermore, we also propose, and analytically study the performance of, a data delivery and duplicate suppression mechanism that makes use of both the original ring and the spare ring for forwarding multicast data packets to the multicast group members. We conduct simulations of both VRing and a hierarchical ALM protocol, NICE, using the J-Sim network simulator. Simulation results show that although VRing has a higher path stretch and a higher link stress than NICE, it incurs less control overhead, consumes less bandwidth, and provides lower average node degree than NICE. Furthermore, VRing achieves a higher (up to twice as much) average data delivery ratio in the presence of failures than NICE. The performance improvement is especially pronounced for larger multicast groups.