VLDB 2026 Research / reviewers in the wild / expert
Kahina Lazri
dblp:130/8462
· DBLP profile ↗
13ranked-venue papers
3as first author
6since 2021 · last 2024
0009-0003-7344-8113ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 5 · 2 since 2021Computer networks · 4 · 4 since 2021Security and privacy · 2 · 2 first-authorArtificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | B-Side: Binary-Level Static System Call IdentificationabstractSystem call filtering is widely used to secure programs in multi-tenant environments, and to sandbox applications in modern desktop software deployment and package management systems. Filtering rules are hard to write and maintain manually, hence generating them automatically is essential. To that aim, analysis tools able to identify every system call that can legitimately be invoked by a program are needed. Existing static analysis works lack precision because of a high number of false positives, and/or assume the availability of program/libraries source code - something unrealistic in many scenarios such as cloud production environments. Gaspard Thévenon, Kevin Nguetchouang, Kahina Lazri, Alain Tchana, Pierre Olivier |
Middleware | 3 |
| 2023 | Stateful InREC: Stateful In-Network Real Number Computation With Recursive FunctionsabstractThe current generation of Reconfigurable Match-Action Tables switches are highly programmable, able to support stateful operations and pipeline specifications using languages like P4. Nevertheless, these switches do not offer primitives to support real-valued operations on the data plane, thus requiring support from external servers or middle boxes to perform advanced operations. We introduce Stateful InREC, a system that extends the capabilities of programmable switches to support in-network real-valued operations using the IEEE half-precision floating point representation. Stateful InREC relies on decomposing real-valued functions into lookup tables taking into account the RMT model constraints to reach the right trade-off between accuracy and resource usage. It also supports state management for the computation of recursive function over time series. Stateful InREC prototype on Barefoot Tofino switches demonstrates the efficiency of Stateful InREC for in-network computation of different types of operations and its application for in-network logistic regression models used for classification problems. We also demonstrate the use of Stateful InREC to implement an ARIMA model on a Tofino switch for DDoS detection. Our evaluation of Stateful InREC shows that it is possible to implement complex in-network applications with high accuracy and low latency. Matthews Jose, Kahina Lazri, Jérôme François, Olivier Festor |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2022 | NetREC: Network-wide in-network REal-value ComputationabstractThe current generation of networks empowers the use of programmable switches whose behaviour can be defined using languages like P4. Nevertheless, these languages do not support network-wide deployment of stateful real-value functions. This paper presents NetREC, an extension of RMT programmable data planes designed to enable stateful real-value functions computation across multiple switches. NetREC first decomposes the real-value functions into a dependency graph of elementary operations that are distributed among the network. This distribution is carried out by dynamically generating and solving an integer linear program. We deploy a prototype of NetREC on a network of Tofino switches and demonstrate its capability of computing recursive real-value functions like exponential weighted moving average. Matthews Jose, Kahina Lazri, Jérôme François, Olivier Festor |
NetSoft | 2 |
| 2021 | InREC: In-network REal Number Computation
Matthews Jose, Kahina Lazri, Jérôme François, Olivier Festor |
IM | 2 |
| 2021 | Leveraging in-network real-value computation for home network device recognition
Matthews Jose, Kahina Lazri, Jérôme François, Olivier Festor |
IM | 2 |
| 2021 | BMC: Accelerating Memcached using Safe In-kernel Caching and Pre-stack Processing
Yoann Ghigoff, Julien Sopena, Kahina Lazri, Antoine Blin, Gilles Muller |
NSDI | 3 |
| 2019 | Virtual Network Functions Placement for Defense Against Distributed Denial of Service AttacksabstractInternational audience Sonia Haddad-Vanier, Céline Gicquel, Lila Boukhatem, Kahina Lazri, Paul Chaignon |
ICORES | 4 |
| 2019 | Toward an in-Kernel High Performance Key-Value Store ImplementationabstractThis work proposes to leverage the programming capabilities offered by eBPF with the high-performance of the XDP hook to execute KVS applications as kernel modules. With this design, the application is executed as a cache module in the kernel space. Our preliminary evaluation results show improvements of up to 30% of the number of processed get requests with UDP protocol. Moreover, this work discusses the eBPF limitations that prevent from full implementation of in-kernel KVS cache application. Kahina Lazri, Antoine Blin, Julien Sopena, Gilles Muller |
SRDS | 1 |
| 2018 | Anomaly detection and diagnosis for cloud services: Practical experiments and lessons learned
Carla Sauvanaud, Mohamed Kaâniche, Karama Kanoun, Kahina Lazri, Guthemberg Silvestre |
J. Syst. Softw. | 4 |
| 2017 | Understanding disruptive monitoring capabilities of programmable networksabstractThe design shift proposed by OpenFlow, with its simple stateless dataplane, initially contributed to the success of Software-Defined Networks. Its lack of state, however, prevents the implementation of many dataplane algorithms. Network applications must therefore offload stateful operations to the control plane, thereby increasing latency and limiting network scalability. Thus, recent research efforts centered on the addition of stateful properties to switches. In this paper, we discuss the impact of emerging programmable dataplane abstractions on network monitoring. In particular, we investigate the need for dataplane states in the design of scalable monitoring applications. We argue that these abstractions are ill-suited for software switches as they retain hardware-specific limitations. Furthermore, we analyse the impact of stateful dataplane designs on the control plane visibility of the network. Finally, we identify opportunities for improvement in the design of stateful software switches. Paul Chaignon, Kahina Lazri, Jérôme François, Olivier Festor |
NetSoft | 2 |
| 2016 | Anomaly Detection and Root Cause Localization in Virtual Network FunctionsabstractThe maturity of hardware virtualization has motivated Communication Service Providers (CSPs) to apply thisparadigm to network services. Virtual Network Functions (VNFs)result from this trend and raise new dependability challengesrelated to network softwarisation that are still not thoroughlyexplored. This paper describes a new approach to detect ServiceLevel Agreements (SLAs) violations and preliminary symptomsof SLAs violations. In particular, one other major objectiveof our approach is to help CSP administrators to identify theanomalous VM at the origin of the detected SLA violation, whichshould enable them to proactively plan for appropriate recoverystrategies. To this end, we make use of virtual machine (VM)monitoring data and perform both a per-VM and an ensembleanalysis. Our approach includes a supervised machine learningalgorithm as well as fault injection tools. The experimental testbedconsists of a virtual IP Multimedia Subsystem developed by theClearwater project. Experimental results show that our approachcan achieve high precision and recall, and low false alarm rateand can pinpoint the root anomalous VNF VM causing SLAviolations. It can also detect preliminary symptoms of highworkloads triggering SLA violations. Carla Sauvanaud, Kahina Lazri, Mohamed Kaâniche, Karama Kanoun |
ISSRE | 2 |
| 2013 | Reconsidering Intrusion Monitoring Requirements in Shared Cloud PlatformsabstractMulti-tenancy is the core feature that enables efficiency and cost effectiveness of cloud computing. However, it brings several new security concerns. Ensuring 'strong isolation' between co-localized tenants remains the most critical issue. This work aims at highlighting new attack strategies brought by the resource sharing paradigm in multi-tenant elastic IaaS Clouds in order to understand impacts of these attacks on the design of Intrusion Detection Systems in Cloud. The first part of this paper surveys the literature related to accepted vulnerabilities. Several Proofs of Concept are described and classified according to the results of the exploitation of these vulnerabilities. In the second part, we argue the existence of new attack strategies able to take advantage of the mechanisms which enable autonomic elasticity. These mechanisms are by nature sensitive to VMs resource consumption which can be easily manipulated by attacks. Finally, we give a representation of the presented vulnerabilities to engage a discussion on the limitations of pure user-centric security monitoring approaches for guaranteeing VM security. Kahina Lazri, Sylvie Laniepce, Jalel Ben-Othman |
ARES | 1 |
| 2013 | When Dynamic VM Migration Falls under the Control of VM UsersabstractSecurity of multi-tenancy in cloud platforms raises a growing interest since research has revealed that the sharing of resources constitutes a vector of vulnerability. In this paper, we examine how one can leverage the sharing of resources, through the manipulation of the amount of resources consumed by VMs, to abusively enforce the dynamic resource management system to trigger VM migrations. This causes waste of resources for the hosting infrastructure and affects performances of VMs. To demonstrate this cross-VM attack, we use VMware's Distributed Resource Scheduler (DRS) in charge of dynamic VM migration management. We perform a detailed analysis of the running of our experimentations by monitoring DRS details during the whole duration of the attack. We explore in various contexts the minimum amount of resources required for the attack to succeed. In our experimentation performed on small clusters, we observe higher vulnerability when the cluster gets larger and when DRS aggressiveness level gets higher. Finally, our experimentations show that the attack can be replayed several times to produce series of VM migrations. Kahina Lazri, Sylvie Laniepce, Jalel Ben-Othman |
CloudCom (1) | 1 |