VLDB 2026 Research / reviewers in the wild / expert
Alec Wolman
dblp:06/915
· DBLP profile ↗
45ranked-venue papers
1as first author
7since 2021 · last 2026
0009-0001-3484-7360ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 25 · 3 since 2021Systems, architecture and hardware · 10 · 2 since 2021Software engineering, systems software and programming languages · 9 · 1 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 3Security and privacy · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Lab to Fleet: Building and Deploying a Practical Rowhammer Defense in Cloud SoCs
Stefan Saroiu, Sujay Yadalam, Alec Wolman, Will Remaklus, Daniel S. Berger, Isaac H. Luna, Ishwar Agarwal, Jacob R. Lorch |
ISCA | 3 |
| 2023 | Accelerating Open RAN Research Through an Enterprise-scale 5G TestbedabstractOpen RAN is an emerging paradigm in mobile networks where the Radio Access Network (RAN) functions are disaggregated and virtualized on commodity servers. Despite the importance of Open RAN research, existing platforms often lack the fidelity and stability required to address a wide range of research problems. In response to this limitation, we have developed an enterprise-scale Open RAN testbed aimed at conducting state-of-the-art research in key areas that have received limited attention due to the lack of suitable platforms. In this poster, we provide an overview of the testbed we have created and examples of the research it has enabled, with the hope of catalyzing future open RAN research and innovation. Paramvir Bahl, Matthew Balkwill, Xenofon Foukas, Anuj Kalia, Daehyeok Kim, Manikanta Kotaru, Zhihua Lai, Sanjeev Mehrotra, Bozidar Radunovic, Stefan Saroiu, Connor Settle, Alec Wolman, Francis Y. Yan, Yongguang Zhang |
MobiCom | 13 |
| 2023 | Empowering Azure Storage with RDMA
Wei Bai 0001, Shanim Sainul Abdeen, Ankit Agrawal 0013, Krishan Kumar Attre, Paramvir Bahl, Ameya Bhagat, Gowri Bhaskara, Tanya Brokhman, Ahmad Cheema, Rebecca Chow, Jeff Cohen, Mahmoud Elhaddad, Vivek Ette, Igal Figlin, Daniel Firestone, Mathew George, Ilya German, Lakhmeet Ghai, Eric Green, Albert G. Greenberg, Randy Haagens, Matthew Hendel, Ridwan Howlader, Neetha John, Julia Johnstone, Tom Jolly, Greg Kramer, David Kruse, Erica Lan, Avi Levy, Marina Lipshteyn, Guohan Lu, Yuemin Lu, Xiakun Lu, Vadim Makhervaks, Ulad Malashanka, David A. Maltz, Ilias Marinos, Rohan Mehta, Sharda Murthi, Anup Namdhari, Aaron Ogus, Jitendra Padhye, Madhav Pandya, Douglas Phillips, Adrian Power, Suraj Puri, Shachar Raindel, Jordan Rhee, Anthony Russo, Maneesh Sah, Ali Sheriff, Chris Sparacino, Ashutosh Srivastava, Weixiang Sun, Nick Swanson, Fuhou Tian, Lukasz Tomczyk, Vamsi Vadlamuri, Alec Wolman, Joyce Yom, Yanzhao Zhang, Brian Zill |
NSDI | 66 |
| 2023 | Siloz: Leveraging DRAM Isolation Domains to Prevent Inter-VM RowhammerabstractToday's cloud DRAM lacks strong isolation primitives, highlighted by Rowhammer bit flips. Rowhammer poses an increasing threat to cloud security/reliability, given (1) DRAM activation rates in commodity and malicious workloads already exceed Rowhammer thresholds, and (2) thresholds are decreasing in newer DRAM. Deployed hardware mitigations remain vulnerable, turning cloud providers toward software defenses. However, existing defenses incur high performance or memory overhead or contain significant protection gaps. Kevin Loughlin, Jonah Rosenblum, Stefan Saroiu, Alec Wolman, Dimitrios Skarlatos 0002, Baris Kasikci |
SOSP | 4 |
| 2022 | MOESI-prime: preventing coherence-induced hammering in commodity workloadsabstractPrior work shows that Rowhammer attacks---which flip bits in DRAM via frequent activations of the same row(s)---are viable. Adversaries typically mount these attacks via instruction sequences that are carefully-crafted to bypass CPU caches. However, we discover a novel form of hammering that we refer to as coherence-induced hammering, caused by Intel's implementations of cache coherent non-uniform memory access (ccNUMA) protocols. We show that this hammering occurs in commodity benchmarks on a major cloud provider's production hardware, the first hammering found to be generated by non-malicious code. Given DRAM's rising susceptibility to bit flips, it is paramount to prevent coherence-induced hammering to ensure reliability and security in the cloud. Kevin Loughlin, Stefan Saroiu, Alec Wolman, Yatin A. Manerkar, Baris Kasikci |
ISCA | 3 |
| 2021 | Stop! Hammer time: rethinking our approach to rowhammer mitigationsabstractRowhammer attacks exploit electromagnetic interference among nearby DRAM cells to flip bits, corrupting data and altering system behavior. Unfortunately, DRAM vendors have opted for a blackbox approach to preventing these bit flips, exposing little information about in-DRAM mitigations. Despite vendor claims that their mitigations prevent Rowhammer, recent work bypasses these defenses to corrupt data. Further work shows that the Rowhammer problem is actually worsening in emerging DRAM and posits that system-level support is needed to produce adaptable and scalable defenses. Kevin Loughlin, Stefan Saroiu, Alec Wolman, Baris Kasikci |
HotOS | 3 |
| 2021 | MegaMind: a platform for security & privacy extensions for voice assistantsabstractVoice assistants raise serious security and privacy concerns because they use always-on microphones in sensitive locations (e.g., inside a home) and send audio recordings to the cloud for processing. The cloud transcribes these recordings and interprets them as user requests, and sometimes even shares these requests with third-party services. These steps may result in unintended or malicious voice data leaks and in unauthorized actions, such as a purchase. This paper presents MegaMind, a novel extensible platform that lets a user deploy security and privacy extensions locally on their voice assistant. MegaMind's extensions interpose on requests before sending them to the cloud and on responses before delivering them to the user. MegaMind's programming model enables writing powerful extensions with ease, such as one for secure conversations. Additionally, MegaMind protects against malicious extensions by providing two important guarantees, namely permission enforcement and non-interference. We implement MegaMind and integrate it with Amazon Alexa Service SDK. Our evaluation shows that MegaMind achieves a small conversation latency on platforms with adequate compute power, such as a Raspberry Pi 4 and an x86-based laptop. Seyed Mohammadjavad Seyed Talebi, Ardalan Amiri Sani, Stefan Saroiu, Alec Wolman |
MobiSys | 4 |
| 2020 | PrivateEye: Scalable and Privacy-Preserving Compromise Detection in the Cloud
Behnaz Arzani, Selim Ciraci, Stefan Saroiu, Alec Wolman, Jack W. Stokes, Geoff Outhred, Lechao Diwu |
NSDI | 4 |
| 2020 | Are We Susceptible to Rowhammer? An End-to-End Methodology for Cloud ProvidersabstractCloud providers are concerned that Rowhammer poses a potentially critical threat to their servers, yet today they lack a systematic way to test whether the DRAM used in their servers is vulnerable to Rowhammer attacks. This paper presents an endto-end methodology to determine if cloud servers are susceptible to these attacks. With our methodology, a cloud provider can construct worst-case testing conditions for DRAM.We apply our methodology to three classes of servers from a major cloud provider. Our findings show that none of the CPU instruction sequences used in prior work to mount Rowhammer attacks create worst-case DRAM testing conditions. To address this limitation, we develop an instruction sequence that leverages microarchitectural side-effects to "hammer" DRAM at a near-optimal rate on modern Intel Skylake and Cascade Lake platforms. We also design a DDR4 fault injector that can reverse engineer row adjacency for any DDR4 DIMM. When applied to our cloud provider's DIMMs, we find that DRAM rows do not always follow a linear map. Lucian Cojocar, Jeremie S. Kim, Minesh Patel, Lillian Tsai, Stefan Saroiu, Alec Wolman, Onur Mutlu |
SP | 6 |
| 2016 | MCDNN: An Approximation-Based Execution Framework for Deep Stream Processing Under Resource ConstraintsabstractWe consider applying computer vision to video on cloud-backed mobile devices using Deep Neural Networks (DNNs). The computational demands of DNNs are high enough that, without careful resource management, such applications strain device battery, wireless data, and cloud cost budgets. We pose the corresponding resource management problem, which we call Approximate Model Scheduling, as one of serving a stream of heterogeneous (i.e., solving multiple classification problems) requests under resource constraints. We present the design and implementation of an optimizing compiler and runtime scheduler to address this problem. Going beyond traditional resource allocators, we allow each request to be served approximately, by systematically trading off DNN classification accuracy for resource use, and remotely, by reasoning about on-device/cloud execution trade-offs. To inform the resource allocator, we characterize how several common DNNs, when subjected to state-of-the art optimizations, trade off accuracy for resource use such as memory, computation, and energy. The heterogeneous streaming setting is a novel one for DNN execution, and we introduce two new and powerful DNN optimizations that exploit it. Using the challenging continuous mobile vision domain as a case study, we show that our techniques yield significant reductions in resource usage and perform effectively over a broad range of operating conditions. Seungyeop Han, Haichen Shen, Matthai Philipose, Sharad Agarwal, Alec Wolman, Arvind Krishnamurthy |
MobiSys | 5 |
| 2016 | fTPM: A Software-Only Implementation of a TPM Chip
Himanshu Raj, Stefan Saroiu, Alec Wolman, Ronald Aigner, Jeremiah Cox, Paul England, Chris Fenner, Kinshuman Kinshumann, Jork Löser, Dennis Mattoon, Magnus Nyström, Rob Spiger, Stefan Thom, David Wooten |
USENIX Security Symposium | 3 |
| 2015 | Protecting Data on Smartphones and Tablets from Memory AttacksabstractSmartphones and tablets are easily lost or stolen. This makes them susceptible to an inexpensive class of memory attacks, such as cold-boot attacks, using a bus monitor to observe the memory bus, and DMA attacks. This paper describes Sentry, a system that allows applications and OS components to store their code and data on the System-on-Chip (SoC) rather than in DRAM. We use ARM-specific mechanisms originally designed for embedded systems, but still present in today's mobile devices, to protect applications and OS subsystems from memory attacks. Patrick Colp, James Gleeson 0001, Sahil Suneja, Eyal de Lara, Himanshu Raj, Stefan Saroiu, Alec Wolman |
ASPLOS | 8 |
| 2015 | dJay: enabling high-density multi-tenancy for cloud gaming servers with dynamic cost-benefit GPU load balancingabstractIn cloud gaming, servers perform remote rendering on behalf of thin clients. Such a server must deliver sufficient frame rate (at least 30fps) to each of its clients. At the same time, each client desires an immersive experience, and therefore the server should also provide the best graphics quality possible to each client. Statically provisioning time slices of the server GPU for each client suffers from severe underutilization because clients can come and go, and scenes that the clients need rendered can vary greatly in terms of GPU resource usage over time. Sergey Grizan, David Chu, Alec Wolman, Roger Wattenhofer |
SoCC | 3 |
| 2015 | Prime: a framework for co-located multi-device appsabstractEven though mobile devices are ubiquitous, the conceptually simple endeavor of using co-located devices for multi-user experiences is cumbersome. It may not even be possible when certain apps are not widely available. David Chu, Zengbin Zhang, Alec Wolman, Nicholas D. Lane |
UbiComp | 3 |
| 2015 | Kahawai: High-Quality Mobile Gaming Using GPU OffloadabstractThis paper presents Kahawai1, a system that provides high-quality gaming on mobile devices, such as tablets and smartphones, by offloading a portion of the GPU computation to server-side infrastructure. In contrast with previous thin-client approaches that require a server-side GPU to render the entire content, Kahawai uses collaborative rendering to combine the output of a mobile GPU and a server-side GPU into the displayed output. Compared to a thin client, collaborative rendering requires significantly less network bandwidth between the mobile device and the server to achieve the same visual quality and, unlike a thin client, collaborative rendering supports disconnected operation, allowing a user to play offline - albeit with reduced visual quality. Eduardo Cuervo Laffaye, Alec Wolman, Landon P. Cox, Kiron Lebeck, Ali Razeen, Stefan Saroiu, Madan Musuvathi |
MobiSys | 2 |
| 2015 | Outatime: Using Speculation to Enable Low-Latency Continuous Interaction for Mobile Cloud GamingabstractGaming on phones, tablets and laptops is very popular. Cloud gaming - where remote servers perform game execution and rendering on behalf of thin clients that simply send input and display output frames - promises any device the ability to play any game any time. Unfortunately, the reality is that wide-area network latencies are often prohibitive; cellular, Wi-Fi and even wired residential end host round trip times (RTTs) can exceed 100ms, a threshold above which many gamers tend to deem responsiveness unacceptable. Kyungmin Lee, David Chu, Eduardo Cuervo Laffaye, Johannes Kopf 0001, Yury Degtyarev, Sergey Grizan, Alec Wolman, Jason Flinn |
MobiSys | 7 |
| 2014 | Using ARM trustzone to build a trusted language runtime for mobile applicationsabstractThis paper presents the design, implementation, and evaluation of the Trusted Language Runtime (TLR), a system that protects the confidentiality and integrity of .NET mobile applications from OS security breaches. TLR enables separating an application's security-sensitive logic from the rest of the application, and isolates it from the OS and other apps. TLR provides runtime support for the secure component based on a .NET implementation for embedded devices. TLR reduces the TCB of an open source .NET implementation by a factor of $78$ with a tolerable performance cost. The main benefit of the TLR is to bring the developer benefits of managed code to trusted computing. With the TLR, developers can build their trusted components with the productivity benefits of modern high level languages, such as strong typing and garbage collection. Nuno Santos 0001, Himanshu Raj, Stefan Saroiu, Alec Wolman |
ASPLOS | 4 |
| 2014 | Zero-effort payments: design, deployment, and lessonsabstractThis paper presents Zero-Effort Payments (ZEP), a seamless mobile computing system designed to accept payments with no effort on the customer's part beyond a one-time opt-in. With ZEP, customers need not present cards nor operate smartphones to convey their identities. ZEP uses three complementary identification technologies: face recognition, proximate device detection, and human assistance. We demonstrate that the combination of these technologies enables ZEP to scale to the level needed by our deployments. Christopher Smowton, Jacob R. Lorch, David Molnar, Stefan Saroiu, Alec Wolman |
UbiComp | 5 |
| 2014 | Demo: Kahawai: high-quality mobile gaming using GPU offloadabstractNo abstract available. Eduardo Cuervo Laffaye, Alec Wolman, Landon P. Cox, Stefan Saroiu, Madan Musuvathi, Ali Razeen |
MobiSys | 2 |
| 2014 | Demo: DeLorean: using speculation to enable low-latency continuous interaction for mobile cloud gamingabstractNo abstract available. Kyungmin Lee, David Chu, Eduardo Cuervo Laffaye, Alec Wolman, Jason Flinn |
MobiSys | 4 |
| 2014 | cTPM: A Cloud TPM for Cross-Device Trusted Applications
Chen Chen 0013, Himanshu Raj, Stefan Saroiu, Alec Wolman |
NSDI | 4 |
| 2012 | Delusional boot: securing hypervisors without massive re-engineeringabstractThe set of virtual devices offered by a hypervisor to its guest VMs is a virtualization component ripe with security exploits -- more than half of all vulnerabilities of today's hypervisors are found in this codebase. This paper presents Min-V, a hypervisor that disables all virtual devices not critical to running VMs in the cloud. Of the remaining devices, Min-V takes a step further and eliminates all remaining functionality not needed for the cloud. Himanshu Raj, Shravan K. Rayanchu, Stefan Saroiu, Alec Wolman |
EuroSys | 5 |
| 2012 | Helping mobile apps bootstrap with fewer usersabstractA growing number of mobile apps are exploiting smartphone sensors to infer user behavior, activity, or context. Inference requires training using labeled ground truth data. Obtaining labeled data for new apps is a "chicken-egg" problem. Without a reasonable amount of labeled data, apps cannot provide any service. But until an app provides useful service it is not worth installing and has no opportunity to collect user data. This paper aims to address this problem. Our intuition is that even though users are different, they exhibit similar patterns on certain sensing dimensions. For instance, different users may walk and drive at different speeds, but certain speeds will indicate driving for all users. These common patterns could be used as "seeds" to model new users through semi-supervised learning. We prototype a technique to automatically extract the commonalities to seed personalized inference models for new users. We evaluate the proposed technique through example apps and real world data. Xuan Bao, Paramvir Bahl, Aman Kansal, David Chu, Romit Roy Choudhury, Alec Wolman |
UbiComp | 6 |
| 2012 | Poster: supporting collaborative sensing applicationsabstractMany context aware applications can benefit from using high-level sensing results with semantic meanings (e.g, busy/idle). This paper proposes a platform design that provides high-level "virtual sensor" abstractions and enables new virtual sensors to be bootstrapped from existing ones. Xuan Bao, Aman Kansal, Romit Roy Choudhury, Paramvir Bahl, David Chu, Alec Wolman |
MobiSys | 6 |
| 2012 | Software abstractions for trusted sensorsabstractWith the proliferation of e-commerce, e-wallet, and e-health smartphone applications, the need for trusted mobile applications is greater than ever. Unlike their desktop counterparts, many mobile applications rely heavily on sensor inputs. As a result, trust often requires authenticity and integrity of sensor readings. For example, applications may need trusted readings from sensors such as a GPS, camera, or microphone. Recent research has started to recognize the need for "trusted sensors", yet providing the right programming abstractions and system support for building mobile trusted applications is an open problem. Stefan Saroiu, Alec Wolman, Himanshu Raj |
MobiSys | 3 |
| 2010 | MAUI: making smartphones last longer with code offloadabstractThis paper presents MAUI, a system that enables fine-grained energy-aware offload of mobile code to the infrastructure. Previous approaches to these problems either relied heavily on programmer support to partition an application, or they were coarse-grained requiring full process (or full VM) migration. MAUI uses the benefits of a managed code environment to offer the best of both worlds: it supports fine-grained code offload to maximize energy savings with minimal burden on the programmer. MAUI decides at run-time which methods should be remotely executed, driven by an optimization engine that achieves the best energy savings possible under the mobile device's current connectivity constrains. In our evaluation, we show that MAUI enables: 1) a resource-intensive face recognition application that consumes an order of magnitude less energy, 2) a latency-sensitive arcade game application that doubles its refresh rate, and 3) a voice-based language translation application that bypasses the limitations of the smartphone environment by executing unsupported components remotely. Eduardo Cuervo Laffaye, Aruna Balasubramanian, Dae-ki Cho, Alec Wolman, Stefan Saroiu, Ranveer Chandra, Paramvir Bahl |
MobiSys | 4 |
| 2010 | Centrifuge: Integrated Lease Management and Partitioning for Cloud Services
Atul Adya, John Dunagan, Alec Wolman |
NSDI | 3 |
| 2010 | Volley: Automated Data Placement for Geo-Distributed Cloud Services
Sharad Agarwal, John Dunagan, Navendu Jain, Stefan Saroiu, Alec Wolman |
NSDI | 5 |
| 2010 | Stout: An Adaptive Interface to Scalable Cloud Storage
John McCullough, John Dunagan, Alec Wolman, Alex C. Snoeren |
USENIX ATC | 3 |
| 2010 | Dyson: An Architecture for Extensible Wireless LANs
Rohan Murty, Jitendra Padhye, Alec Wolman, Matt Welsh |
USENIX ATC | 3 |
| 2009 | Lockr: better privacy for social networksabstractToday's online social networking (OSN) sites do little to protect the privacy of their users' social networking information. Given the highly sensitive nature of the information these sites store, it is understandable that many users feel victimized and disempowered by OSN providers' terms of service. This paper presents Lockr, a system that improves the privacy of centralized and decentralized online content sharing systems. Lockr offers three significant privacy benefits to OSN users. First, it separates social networking content from all other functionality that OSNs provide. This decoupling lets users control their own social information: they can decide which OSN provider should store it, which third parties should have access to it, or they can even choose to manage it themselves. Such flexibility better accommodates OSN users' privacy needs and preferences. Second, Lockr ensures that digitally signed social relationships needed to access social data cannot be re-used by the OSN for unintended purposes. This feature drastically reduces the value to others of social content that users entrust to OSN providers. Finally, Lockr enables message encryption using a social relationship key. This key lets two strangers with a common friend verify their relationship without exposing it to others, a common privacy threat when sharing data in a decentralized scenario. Amin Tootoonchian, Stefan Saroiu, Yashar Ganjali, Alec Wolman |
CoNEXT | 4 |
| 2009 | BlueMonarch: a system for evaluating bluetooth applications in the wildabstractDespite Bluetooth's popularity, low cost, and low power requirements, Bluetooth applications remain remarkably unsophisticated. Although the research community and industry have designed games, cell-phone backup, and contextual advertising systems with Bluetooth, few such applications have been prototyped or evaluated on a large scale. Evaluating Bluetooth applications requires recruiting devices in the wild and developing robust software that can adapt to the heterogeneity of these devices. These requirements have limited both the number and the magnitude of the experiments with Bluetooth applications.This paper proposes BlueMonarch, a systemfor evaluating Bluetooth applications in the wild. BlueMonarch emulates a Bluetooth transfer to any device responding to Bluetooth Service Discovery requests; because many cell-phones, laptops, and PDAs in the wild respond to such probes, BlueMonarch enables quick prototyping of Bluetooth applications in the wild, to hundreds of unmodified Bluetooth devices. After we present the feasibility and accuracy of BlueMonarch, we use BlueMonarch to evaluate a content delivery system for Bluetooth. With BlueMonarch, we evaluated our system inside a mall and a subway system; we were able to send tens of megabytes of data to hundreds of Bluetooth devices in just a little over an hour. Timothy J. Smith, Stefan Saroiu, Alec Wolman |
MobiSys | 3 |
| 2009 | Bunker: A Privacy-Oriented Platform for Network Tracing
Andrew G. Miklas, Stefan Saroiu, Alec Wolman, Angela Demke Brown |
NSDI | 3 |
| 2008 | Itrustpage: a user-assisted anti-phishing toolabstractDespite the many solutions proposed by industry and the research community to address phishing attacks, this problem continues to cause enormous damage. Because of our inability to deter phishing attacks, the research community needs to develop new approaches to anti-phishing solutions. Most of today's anti-phishing technologies focus on automatically detecting and preventing phishing attacks. While automation makes anti-phishing tools user-friendly, automation also makes them suffer from false positives, false negatives, and various practical hurdles. As a result, attackers often find simple ways to escape automatic detection. Troy Ronda, Stefan Saroiu, Alec Wolman |
EuroSys | 3 |
| 2008 | An Architecture for Extensible Wireless LANs
Rohan Murty, Jitendra Padhye, Alec Wolman, Matt Welsh |
HotNets | 3 |
| 2008 | Designing High Performance Enterprise Wi-Fi Networks
Rohan Murty, Jitendra Padhye, Ranveer Chandra, Alec Wolman, Brian Zill |
NSDI | 4 |
| 2007 | Tamper Resistant Network Tracing
Andrew G. Miklas, Stefan Saroiu, Alec Wolman, Angela Demke Brown |
HotNets | 3 |
| 2007 | Wireless wakeups revisited: energy management for voip over wi-fi smartphonesabstractIP based telephony is rapidly gaining acceptance over traditional means of voice communication. Wireless LANs are also becoming ubiquitous due to their inherent ease of deployment and decreasing costs. In enterpriseWi-Fi environments, VoIP is a compelling application for devices such as smart phones with multiple wireless interfaces. However, the high energy consumption of Wi-Fi interfaces, especially when a device is idle,presents a significant barrier to the widespread adoption of VoIP over Wi-Fi.To address this issue, we present Cell2Notify, a practical and deployable energy management architecture that leverages the cellular radio on a smart phone to implement wakeup for the high-energy consumption Wi-Fi radio. We present detailed measurements of energy consumption on smart phone devices, and we show that Cell2Notify, can extend the battery lifetime of VoIPover Wi-Fi enabled smart phones by a factor of 1.7 to 6.4. Yuvraj Agarwal, Ranveer Chandra, Alec Wolman, Paramvir Bahl, Kevin Chin, Rajesh K. Gupta 0001 |
MobiSys | 3 |
| 2007 | A Location-Based Management System for Enterprise Wireless LANs
Ranveer Chandra, Jitendra Padhye, Alec Wolman, Brian Zill |
NSDI | 3 |
| 2006 | Enhancing the security of corporate Wi-Fi ntworks using DAIRabstractWe present a framework for monitoring enterprise wireless networks using desktop infrastructure. The framework is called DAIR, which is short for Dense Array of Inexpensive Radios. We demonstrate that the DAIR framework is useful for detecting rogue wireless devices (e.g., access points) attached to corporate networks, as well as for detecting Denial of Service attacks on Wi-Fi networks.Prior proposals in this area include monitoring the network via a combination of access points (APs), mobile clients, and dedicated sensor nodes. We show that a dense deployment of sensors is necessary to effectively monitor Wi-Fi networks for certain types of threats, and one can not accomplish this using access points alone. An ordinary, single-radio AP can not monitor multiple channels effectively, without adversely impacting the associated clients. Moreover, we show that a typical deployment of access points is not sufficiently dense to detect the presence of rogue wireless devices. Due to power constraints, mobile devices can provide only limited assistance in monitoring wireless networks. Deploying a dense array of dedicated sensor nodes is an expensive proposition.Our solution is based on two simple observations. First, in most enterprise environments, one finds plenty of desktop machines with good wired connectivity, and spare CPU and disk resources. Second, inexpensive USB-based wireless adapters are commonly available. By attaching these adapters to desktop machines, and dedicating the adapters to the task of monitoring the wireless network, we create a low cost management infrastructure. Paramvir Bahl, Ranveer Chandra, Jitendra Padhye, Lenin Ravindranath, Alec Wolman, Brian Zill |
MobiSys | 6 |
| 2004 | A Multi-Radio Unification Protocol for IEEE 802.11 Wireless NetworksabstractWe present a link layer protocol called the multi-radio unification protocol or MUP. On a single node, MUP coordinates the operation of multiple wireless network cards tuned to non-overlapping frequency channels. The goal of MUP is to optimize local spectrum usage via intelligent channel selection in a multihop wireless network. MUP works with standard-compliant IEEE 802.11 hardware, does not require changes to applications or higher-level protocols, and can be deployed incrementally. The primary usage scenario for MUP is a multihop community wireless mesh network, where cost of the radios and battery consumption are not limiting factors. We describe the design and implementation of MUP, and analyze its performance using both simulations and measurements based on our implementation. Our results show that under dynamic traffic patterns with realistic topologies, MUP significantly improves both TCP throughput and user perceived latency for realistic workloads. Atul Adya, Paramvir Bahl, Jitendra Padhye, Alec Wolman, Lidong Zhou |
BROADNETS | 4 |
| 2004 | FUSE: Lightweight Guaranteed Distributed Failure Notification
John Dunagan, Nicholas J. A. Harvey, Michael B. Jones, Dejan Kostic, Marvin Theimer, Alec Wolman |
OSDI | 6 |
| 2003 | An Evaluation of Scalable Application-Level Multicast Built Using Peer-To-Peer OverlaysabstractStructured peer-to-peer overlay networks such as CAN, Chord, Pastry, and Tapestry can be used to implement Internet-scale application-level multicast. There are two general approaches to accomplishing this: tree building and flooding. This paper evaluates these two approaches using two different types of structured overlay: 1) overlays which use a form of generalized hypercube routing, e.g., Chord, Pastry and Tapestry, and 2) overlays which use a numerical distance metric to route through a Cartesian hyperspace, e.g., CAN. Pastry and CAN are chosen as the representatives of each type of overlay. To the best of our knowledge, this paper reports the first head-to-head comparison of CAN-style versus Pastry-style overlay networks, using multicast communication workloads running on an identical simulation infrastructure. The two approaches to multicast are independent of overlay network choice, and we provide a comparison of flooding versus tree-based multicast on both overlays. Results show that the tree-based approach consistently outperforms the flooding approach. Finally, for tree-based multicast, we show that Pastry provides better performance than CAN. Miguel Castro 0001, Michael B. Jones, Anne-Marie Kermarrec, Antony I. T. Rowstron, Marvin Theimer, Helen J. Wang, Alec Wolman |
INFOCOM | 7 |
| 1999 | On the scale and performance of cooperative Web proxy cachingabstractWhile algorithms for cooperative proxy caching have been widely studied, little is understood about cooperativecaching performance in the large-scale World Wide Web environment. This paper uses both trace-based analysis and analytic modelling to show the potential advantages and drawbacks of inter-proxy cooperation. With our traces, we evaluate quantitatively the performance-improvement potential of cooperation between 200 small-organization proxies within a university environment, and between two largeorganization proxies handling 23,000 and 60,000 clients, respectively. With our model, we extend beyond these populations to project cooperative caching behavior in regions with millions of clients. Overall, we demonstrate that cooperative caching has performance benefits only within limited population bounds. We also use our model to examine the implications of future trends in Web-access behavior and traffic. 1 Introduction Cooperative caching -- the sharing and coordination of cache... Alec Wolman, Geoffrey M. Voelker, Nitin Sharma 0002, Neal Cardwell, Anna R. Karlin, Henry M. Levy |
SOSP | 1 |
| 1996 | The Structure and Performance of InterpretersabstractInterpreted languages have become increasingly popular due to demands for rapid program development, ease of use, portability, and safety. Beyond the general impression that they are "slow," however, little has been documented about the performance of interpreters as a class of applications.This paper examines interpreter performance by measuring and analyzing interpreters from both software and hardware perspectives. As examples, we measure the MIPSI, Java, Perl, and Tcl interpreters running an array of micro and macro benchmarks on a DEC Alpha platform. Our measurements of these interpreters relate performance to the complexity of the interpreter's virtual machine and demonstrate that native runtime libraries can play a key role in providing good performance. From an architectural perspective, we show that interpreter performance is primarily a function of the interpreter itself and is relatively independent of the application being interpreted. We also demonstrate that high-level interpreters' demands on processor resources are comparable to those of other complex compiled programs, such as gcc. We conclude that interpreters, as a class of applications, do not currently motivate special hardware support for increased performance. Theodore H. Romer, Dennis Lee 0001, Geoffrey M. Voelker, Alec Wolman, Wayne A. Wong, Jean-Loup Baer, Brian N. Bershad, Henry M. Levy |
ASPLOS | 4 |