Xitao Wen

dblp:117/4406 · DBLP profile ↗
← Back
11ranked-venue papers
4as first author
0since 2021 · last 2017
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 1 first-authorSystems, architecture and hardware · 3 · 3 first-authorSecurity and privacy · 2 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
6 papers
Datacenter networks · 51% Software-defined and programmable networks · 17% Network management and operations · 14%

Topics — the 11 heaviest of 12, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Datacenter networks
optical datacenter network
0.842017
Toward A Scalable, Fault-Tolerant, High-Performance Optical Data Center Architecture · IEEE/ACM Trans. Netw. 2017
WaveCube: A scalable, fault-tolerant, high-performance optical data center architecture · INFOCOM 2015
OSA: An Optical Switching Architecture for Data Center Networks With Unprecedented Flexibility · IEEE/ACM Trans. Netw. 2014
Optical networks › optical switch
optical switch architecture
0.322014
OSA: An Optical Switching Architecture for Data Center Networks With Unprecedented Flexibility · IEEE/ACM Trans. Netw. 2014
OSA: An Optical Switching Architecture for Data Center Networks with Unprecedented Flexibility · NSDI 2012
Network management and operations › fault management
fault diagnosis
0.312017
RuleScope: Inspecting Forwarding Faults for Software-Defined Networking · IEEE/ACM Trans. Netw. 2017
Software-defined and programmable networks
SDN data plane
0.312017
RuleScope: Inspecting Forwarding Faults for Software-Defined Networking · IEEE/ACM Trans. Netw. 2017
Software-defined and programmable networks › SDN data plane
SDN forwarding
0.212016
Is every flow on the right track?: Inspect SDN forwarding with RuleScope · INFOCOM 2016
Datacenter networks
data center network topology
0.212015
WaveCube: A scalable, fault-tolerant, high-performance optical data center architecture · INFOCOM 2015
Datacenter networks › data center network topology
fault-tolerant topology
0.212015
WaveCube: A scalable, fault-tolerant, high-performance optical data center architecture · INFOCOM 2015
Internet architecture and protocols
network topology
0.212014
OSA: An Optical Switching Architecture for Data Center Networks With Unprecedented Flexibility · IEEE/ACM Trans. Netw. 2014
Network management and operations
network verification
0.222017
RuleScope: Inspecting Forwarding Faults for Software-Defined Networking · IEEE/ACM Trans. Netw. 2017
Is every flow on the right track?: Inspect SDN forwarding with RuleScope · INFOCOM 2016
Datacenter networks
bisection bandwidth
0.112015
WaveCube: A scalable, fault-tolerant, high-performance optical data center architecture · INFOCOM 2015
Optical networks
optical switching
0.012012
OSA: An Optical Switching Architecture for Data Center Networks with Unprecedented Flexibility · NSDI 2012

Methods — techniques the papers use, named apart from their topics

probe packets · 0.5incremental algorithms · 0.3troubleshooting algorithms · 0.2multi-pathing · 0.2dynamic link bandwidth allocation · 0.2
YearPublicationVenuePosition
2017 Toward A Scalable, Fault-Tolerant, High-Performance Optical Data Center Architecture
abstract
Optical data center networks (DCNs) are becoming increasingly attractive due to their technological strengths compared with the traditional electrical networks. However, existing optical DCNs are either hard to scale, vulnerable to single point of failure, or provide limited network bisection bandwidth for many practical data center workloads. To this end, we present WaveCube, a scalable, fault-tolerant, high-performance optical DCN architecture. To scale, WaveCube removes MEMS,1a potential bottleneck, from its design. WaveCube is fault-tolerant, since it does not have single point of failure and there are multiple node-disjoint parallel paths between any pair of top-of-rack switches. WaveCube delivers high performance by exploiting multi-pathing and dynamic link bandwidth along the path. For example, our evaluation results show that, in terms of network bisection bandwidth, WaveCube outperforms prior optical DCNs by up to 400% and is 70%-85% of the ideal non-blocking network (ı.e., theoretical upper bound) under both realistic and synthetic traffic patterns. WaveCube's performance degrades gracefully under failures-it drops 20% even with 20% links cut. WaveCube also holds promise in practice-its wiring complexity is orders of magnitude lower than Fattree, BCube, and c-Through at scale, and its power consumption is 35% of them.
Kai Chen 0005, Xitao Wen, Yan Chen 0004, Yong Xia 0007, Chengchen Hu, Qunfeng Dong
IEEE/ACM Trans. Netw.2
2017 RuleScope: Inspecting Forwarding Faults for Software-Defined Networking
abstract
Software-defined networking (SDN) promises unprecedentedly flexible network management but it is susceptible to forwarding faults. Such faults originate from data-plane rules with missing faults and priority faults. Yet existing fault detection ignores priority faults, because they are not discovered on commercial switches until recently. In this paper, we present RuleScope, a more comprehensive solution for inspecting SDN forwarding. RuleScope offers a series of accurate and efficient algorithms for detecting and troubleshooting rule faults. They inspect forwarding behavior using customized probe packets to exercise data-plane rules. The detection algorithm exposes not only missing faults but also priority faults and the troubleshooting algorithm uncover actual forwarding states of data-plane flow tables. Both of them help track real-time forwarding status and benefit reliable network monitoring. Furthermore, toward fast inspection of dynamic networks, we propose incremental algorithms for rapidly evolving network policies to amortize detection and troubleshooting overhead without sacrificing accuracy. Experiments with our prototype on the Ryu SDN controller and Pica8 P-3297 switch show that the RuleScope achieves accurate fault detection on 320-entry flow tables with a cost of 1500+ probe packets within 16 s.
Xitao Wen, Kai Bu, Yan Chen 0004, Li Erran Li, Xue Leng
IEEE/ACM Trans. Netw.1
2016 SDNShield: Reconciliating Configurable Application Permissions for SDN App Markets
abstract
The OpenFlow paradigm embraces third-party development efforts, and therefore suffers from potential attacks that usurp the excessive privileges of control plane applications (apps). Such privilege abuse could lead to various attacks impacting the entire administrative domain. In this paper, we present SDNShield, a permission control system that helps network administrators to express and enforce only the minimum required privileges to individual controller apps. SDNShield achieves this goal through (i) fine-grained SDN permission abstractions that allow accurate representation of app behavior boundary, (ii) automatic security policy reconciliation that incorporates security policies specified by administrators into the requested app permissions, and (iii) a lightweight thread-based controller architecture for controller/app isolation and reliable permission enforcement. Through prototype implementation, we verify its effectiveness against proof-of-concept attacks. Performance evaluation shows that SDNShield introduces negligible runtime overhead.
Xitao Wen, Yan Chen 0004, Chengchen Hu, Yi Wang 0004, Bin Liu 0001
DSN1
2016 RuleTris: Minimizing Rule Update Latency for TCAM-Based SDN Switches
abstract
Software-dehned network (SDN) is deemed to enable more dynamic management of data center networks that promptly respond to network events with changes in network policies. Although the SDN controller architecture is increasingly optimized for swift policy updates, the data plane, especially the prevailing TCAM-based flow tables on physical SDN switches, remains unoptimized for fast rule updates, and is gradually becoming the primary bottleneck along the policy update pipeline. In this paper, we present RuleTris, the hrst SDN update optimization framework that minimizes rule update latency for TCAM-based switches. RuleTris employs the dependency graph (DAG) as the key abstraction to minimize the update latency. RuleTris efhciently obtains the DAGs with novel dependency preserving algorithms that incrementally build rule dependency along with the compilation process. Then, in the guidance of the DAG, RuleTris optimizes the rule updates in TCAM to avoid unnecessary entry moves, which are the main cause of TCAM update inefhciency. We prove that RuleTris generates TCAM updates with the minimum number of TCAM entry moves. In evaluation, RuleTris achieves a median of <;12ms and 90-percentile of <;15ms the end-to-end per-rule update latency on our hardware prototype, outperforming the state-of-the-art composition compiler CoVisor by ~20 times.
Xitao Wen, Yan Chen 0004, Li Erran Li, Kai Bu, Chengchen Hu
ICDCS1
2016 Is every flow on the right track?: Inspect SDN forwarding with RuleScope
abstract
Software-Defined Networking (SDN) promises un-precedentedly flexible network management but it is susceptible to forwarding faults. Such faults originate from data-plane rules with missing faults and priority faults. Yet existing fault detection ignores priority faults because they are not discovered on commercial switches until recently. In this paper, we present RuleScope, a more comprehensive solution for inspecting SDN forwarding. RuleScope offers a series of accurate and efficient algorithms for detecting and troubleshooting rule faults. They inspect forwarding behavior using customized probe packets to exercise data-plane rules. The detection algorithm exposes not only missing faults but also priority faults. Beyond simply detecting rule faults, the troubleshooting algorithms uncover actual data-plane flow tables. They help track real-time forwarding status and benefit reliable network monitoring. We explore various techniques for enhancing algorithm efficiency without sacrificing inspection accuracy. Experiments with our prototype on the Ryu SDN controller and Pica8 P-3297 switch show that RuleScope achieves accurate and efficient forwarding inspection with limited bandwidth and packet-switching overhead.
Kai Bu, Xitao Wen, Yan Chen 0004, Li Erran Li
INFOCOM2
2015 WaveCube: A scalable, fault-tolerant, high-performance optical data center architecture
abstract
Optical data center networks (DCNs) are becoming increasingly attractive due to their technological strengths compared to traditional electrical networks. However, prior optical DCNs are either hard to scale, vulnerable to single point of failure, or provide limited network bisection bandwidth for many practical DCN workloads. To this end, we present WaveCube, a scalable, fault-tolerant, high-performance optical DCN architecture. To scale, WaveCube removes MEMS1, a potential bottleneck, from its design. Wave-Cube is fault-tolerant since it does not have single point of failure and there are multiple node-disjoint parallel paths between any pair of Top-of-Rack (ToR) switches. WaveCube delivers high performance by exploiting multi-pathing and dynamic link bandwidth along the path. Our extensive evaluation results show that WaveCube outperforms previous optical DCNs by up to 400% and delivers network bisection bandwidth that is 70%–85% of an ideal non-blocking network under both realistic and synthetic traffic patterns. WaveCube's performance degrades gracefully under failures — it drops 20% even with 20% links cut. WaveCube also holds promise in practice — its wiring complexity is orders of magnitude lower than Fattree, BCube and c-Through at large scale, and its power consumption is 35% of them.
Kai Chen 0005, Xitao Wen, Yan Chen 0004, Yong Xia 0007, Chengchen Hu, Qunfeng Dong
INFOCOM2
2014 VirtualKnotter: Online virtual machine shuffling for congestion resolving in virtualized datacenter
Shihong Zou, Xitao Wen, Kai Chen 0005, Yan Chen 0004, Yong Xia 0007, Chengchen Hu
Comput. Networks2
2014 OSA: An Optical Switching Architecture for Data Center Networks With Unprecedented Flexibility
abstract
A detailed examination of evolving traffic characteristics, operator requirements, and network technology trends suggests a move away from nonblocking interconnects in data center networks (DCNs). As a result, recent efforts have advocated oversubscribed networks with the capability to adapt to traffic requirements on-demand. In this paper, we present the design, implementation, and evaluation of OSA, a novel Optical Switching Architecture for DCNs. Leveraging runtime reconfigurable optical devices, OSA dynamically changes its topology and link capacities, thereby achieving unprecedented flexibility to adapt to dynamic traffic patterns. Extensive analytical simulations using both real and synthetic traffic patterns demonstrate that OSA can deliver high bisection bandwidth (60%-100% of the nonblocking architecture). Implementation and evaluation of a small-scale functional prototype further demonstrate the feasibility of OSA.
Kai Chen 0005, Ankit Singla, Atul Singh, Kishore Ramachandran, Lei Xu 0017, Yueping Zhang, Xitao Wen, Yan Chen 0004
IEEE/ACM Trans. Netw.7
2012 Virtual browser: a virtualized browser to sandbox third-party JavaScripts with enhanced security
abstract
Third party JavaScripts not only offer much richer features to the web and its applications but also introduce new threats. These scripts cannot be completely trusted and executed with the privileges given to host web sites. Due to incomplete virtualization and lack of tracking all the data flows, all existing approaches without native sandbox support can secure only a subset of third party JavaScripts, and they are vulnerable to attacks encoded in non-standard HTML/-JavaScript (browser quirks) as these approaches will parse third party JavaScripts independently at server side without considering client-side non-standard parsing quirks. At the same time, native sandboxes are vulnerable to attacks based on unknown native JavaScript engine bugs.
Yinzhi Cao, Zhichun Li, Vaibhav Rastogi, Yan Chen 0004, Xitao Wen
AsiaCCS5
2012 VirtualKnotter: Online Virtual Machine Shuffling for Congestion Resolving in Virtualized Datacenter
abstract
Our measurements on production data center traffic together with recently reported results suggest that data center networks suffer from long-lived congestion caused by core network over subscription and unbalanced workload placement. In contrast to traditional traffic engineering approaches that optimize flow routing, in this paper, we explore the opportunity to address the continuous congestion via optimizing VM placement in virtualized data centers. To this end, we present Virtual Knotter, an efficient online VM placement algorithm to reduce congestion with controllable VM migration traffic as well as low time complexity. Our evaluation with both real and synthetic traffic patterns shows that Virtual Knotter performs close to the baseline algorithm in terms of link unitization, with only 5%-10% migration traffic of the baseline algorithm. Furthermore, Virtual Knotter decreases link congestion time by 53% for the production data center traffic.
Xitao Wen, Kai Chen 0005, Yan Chen 0004, Yong Xia 0007, Chengchen Hu
ICDCS1
2012 OSA: An Optical Switching Architecture for Data Center Networks with Unprecedented Flexibility
Kai Chen 0005, Ankit Singla, Atul Singh, Kishore Ramachandran, Lei Xu 0017, Yueping Zhang, Xitao Wen, Yan Chen 0004
NSDI7