Mays F. Al-Naday

dblp:136/9640 · DBLP profile ↗
← Back
16ranked-venue papers
6as first author
11since 2021 · last 2026
0000-0002-2439-5620ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Flocky: Decentralized Intent-Based Edge Orchestration Using Open Application Model
abstract
Continuum computing has emerged as a paradigm to improve various aspects of service orchestration by offloading computation from the cloud to the network edge. However, edge orchestration poses two significant challenges compared to cloud computing. On one hand, cloud software scheduling algorithms make suboptimal decisions when applied to the network edge, as edge devices and networks are more hetereogeneous than cloud data centers, and orchestration requires different parameters. On the other hand, most orchestration platforms assume highly centralized cloud data centers, with each server running many easily migrated software instances, whereas edge devices have limited hardware capabilities and migration of tasks between devices is significantly slower than in the cloud. As a result, there is a need for a decentralized orchestration platform that allows scheduling algorithms to take into account a wide variety of device properties and deployment requirements in placement decisions. This article presents Flocky, a decentralized device discovery and service orchestration framework based on Open Application Model (OAM), to address this gap. The architecture of Flocky is elaborated, showing how OAM enables flexible intent modeling in the edge, and combined with a Gossip-like algorithm allows individual edge devices to discover devices in their neighborhoods, map their capabilities, and optimally deploy parts of applications to individual nodes. Evaluation shows Flocky to be highly scalable and mainly dependent on local node density, with nodes discovering over 97% of their viable neighbours on average within two discovery rounds, while using 84% less memory than a centralized orchestrator such as Kubernetes.
Tom Goethals, Merlijn Sebrechts, Mays F. Al-Naday, Filip De Turck, Bruno Volckaert
IEEE Trans. Serv. Comput.3
2025 Idempotency in Service Mesh: For Resiliency of Fog-Native Applications in Multi-Domain Edge-to-Cloud Ecosystems
abstract
Resilient operation of cloud-native applications is a critical requirement to service continuity, and to fostering trust in the cloud paradigm. So far, service meshes have been offering resiliency to a subset of failures. But, they fall short in achieving idempotency for HTTP POST requests. In fact, their current resiliency measures may escalate the impact of a POST request failure. Besides, the current tight control over failures - within central clouds - is being threatened by the growing distribution of applications across heterogeneous clouds. Namely, in moving towards a fog-native paradigm of applications. This renders achieving both idempotency and request satisfaction for POST microservices a non-trivial challenge. To address this challenge, we propose a novel, two-pattern, resiliency solution: Idempotency and Completer. The first is an idempotency management system that enables safe retries, following transient network/infrastructure failure. While the second is a FaaS-based completer system that enables automated resolution of microservice functional failures. This is realised through systematic integration and application of developer-defined error solvers. The proposed solution has been implemented as a fog-native service, and integrated over example service mesh Consul. The solution is evaluated experimentally, and results show considerable improvement in user satisfaction, including 100% request completion rate. The results further illustrate the scalability of the solution and benefit in closing the current gap in service mesh systems.
Matthew Whitaker, Bruno Volckaert, Mays F. Al-Naday
CLOSER3
2025 Intelligent Anomaly Detection for Context-Oriented Data Brokerage Systems
Rawaa Al-Wani, Mays F. Al-Naday
IoTBDS2
2025 A Comprehensive Benchmark of Flannel CNI in SDN/Non-SDN Enabled Cloud-Native Environments
abstract
The emergence of cloud computing has driven advancements in software virtualization, particularly microservice containerization. This in turn led to the development of Container Network Interfaces (CNIs) such as Flannel to connect microservices over a network. Despite their objective to provide connectivity, CNIs have not been adequately benchmarked when containers are connected over an external network. This creates uncertainty about the operation reliability of CNIs in distributed edge-cloud ecosystems. Given the multitude of available CNIs and the complexity of comparing different ones, this paper focuses on the widely adopted CNI, Flannel. It proposes the design of novel benchmarks of Flannel across external networks, Software Defined Networking (SDN)-based and non-SDN, characterizing two of the key backend types of Flannel: User Datagram Protocol (UDP) and Virtual Extensible LAN (VXLAN). Unlike existing benchmarks, this study analysis the overhead introduced by the external network and the impact of network disruptions. The paper outlines the systematic approach to benchmarking a set of Key Performance Indicators (KPIs), including: speed, latency and throughput. A variety of network disruptions have been induced to analyse their impact on these KPIs, including: delay, packet loss, and packet corruption. The results show that VXLAN consistently outperforms UDP, offering superior bandwidth with efficient resource consumption, making it more suitable for production environments. In contrast, the UDP backend is suitable for real-time video streaming applications due to its higher data rate and lower jitter, though it requires higher resource utilization. Moreover, the results show less variation in KPIs over SDN, compared to non-SDN. The benchmark data are made publicly available in an open-source repository, enabling researchers to replicate the experiments, and potentially extend the study to other CNIs. This work contributes to the network management domain by providing an extensive benchmark study on container networking highlighting the main advantages and disadvantages of current technologies.
José Santos 0001, Bibin V. Ninan, Bruno Volckaert, Filip De Turck, Mays F. Al-Naday
IEEE Trans. Netw. Serv. Manag.5
2024 Warrens: Decentralized Connectionless Tunnels for Edge Container Networks
abstract
In recent years, workload containerisation has been extended to the edge, bringing with it the need for flexible overlay networking. However, current container networking solutions are generally designed for the cloud, aimed at relatively static clusters with centralized generation of container subnet addresses and assigning them to nodes. Added to that existing tunneling solutions, such as Virtual Private Networks (VPN), also have centralized components. Conversely, the network edge is geo-dispersed and has a volatile topology,with edge nodes typically hidden behind routers, in private networks. To enable large-scale networking at the edge, there is need for decentralized self-management of container network addresses and overlay tunnels. This manuscript presents Warrens, a framework for fully decentralized and self-organizing cloud-edge container networks. Warrens enables communication between edge nodes in different private networks by enabling connectionless tunnels, supported by decentralized self-assignment of container IP addresses, with the assignment scheme minimizing address conflict to a negligible level. Warrens has been implemented in two variants using kernel-level eBPF for processing speed, and user-level Golang for wider compatibility. Warrens is shown to be highly scalable compared to a typical VPN solution, and performance evaluations demonstrate it can handle a full network load on both x64 devices and a Raspberry Pi with$\approx 0.5\%$to 5% total CPU load, depending on traffic direction and protocols used.
Tom Goethals, Mays F. Al-Naday, Bruno Volckaert, Filip De Turck
IEEE Trans. Netw. Serv. Manag.2
2023 Federated Scheduling of Fog-Native Applications Over Multi-Domain Edge-to-Cloud Ecosystem
abstract
Fog computing is emerging as geo-distributed and connected edge-to-cloud ecosystems, spanning multiple domains operated by different entities. Consequently, fog-compatible applications need to support distributed operations and decentralized management. This promoted the adoption of the microservices architecture, to facilitate application modularity and autonomy. Transitioning to fog-native applications, i.e., running distributed microservice workflows over multiple domains, is a challenging endeavor. On one hand, distributing workflows require awareness of the intents and dependencies of microservices, as this may impact the supply of data and the perceived Quality of Service (QoS). On the other hand, the variant capacities and energy supply, coupled with limited information-sharing across fog autonomies, hinders the prospect of end-to-end optimization. To tackle such problems, we propose a novel federate optimisation algorithm for multi-domain scheduling of fog-native microservice workflows. The algorithm incorporates workflow intents in decision-making by combining Bender's decomposition with Alternating Direction Method of Multipliers (ADMM) to provide optimized workflow placement, mapping, routing and admission. The performance of the algorithm is evaluated analytically and compared to state-of-the-art intent-based ADMM (iADMM). The results show performance trade-offs with the proposed iBADMM (direct), with the latter improving the fraction of workflow greenness by ≈ 15%.
Mays F. Al-Naday, Vasileios Karagiannis, Tom De Block, Bruno Volckaert
CNSM1
2023 Service-Based, Multi-Provider, Fog Ecosystem With Joint Optimization of Request Mapping and Response Routing
abstract
Digital transformation is increasingly reliant onservice-based operations in fog networks. The latter is a geo-dispersed form of the cloud, extending resources closer to end-users for improved privacy and reduced latency. The dispersion leverages diversity of compute-network capacities and energy prices, while promotes the coexistence of multiple providers. This drives variation in operational cost, coupled with limited information sharing across providers. Consequently, there is a critical need for an orchestration solution that preserves autonomy and optimizes operational cost across domains, while meeting service requirements. This paper proposes a novel service-based fog management and network orchestrator (sbMANO), which utilizes service metadata in enabling multi-provider resource management. The sbMANO is empowered with a novel optimization algorithm for service-based joint request mapping and response routing. The algorithm acts on partial information and preserves the edge for delay-critical services. The performance of the algorithm is evaluated analytically fordelay-awareanddelay-agnosticvariants. The results show that both achieve near-optimal performance in maximizing user satisfaction with minimum operational cost. Furthermore, the delay-aware variant outperforms the agnostic counterpart, with higher user satisfaction and lower operational cost.
Mays F. Al-Naday, Nikolaos Thomos, Jiejun Hu, Bruno Volckaert, Filip De Turck, Martin J. Reed
IEEE Trans. Serv. Comput.1
2022 Intent-based Decentralized Orchestration for Green Energy-aware Provisioning of Fog-native Workflows
abstract
The cloud native paradigm is emerging as a pathway to developing applications for intrinsic operation on the cloud. This prompted application modularity, leveraging the adoption of the microservices architecture. Meanwhile, fog computing is emerging as a geo-dispersed cloud, bringing services closer to the end-user for localization and improved responsiveness. Transitioning to fog-native applications, i.e. managing microservice workflows over the fog, is a non-trivial challenge. On one hand, engineering workflows require awareness of the dependencies across microservices, as they impact the perceived quality of service. On the other hand, the heterogeneity of capacities, energy prices and supply, introduce challenges that can negate the sought advantages of the fog. This work proposes a novel algorithm based on Alternating Direction Method of Multipliers for intent-based workflow mapping and admission, iADMM. The performance of the algorithm is evaluated analytically and experimentally and compared to a baseline compute-network cost minimization alternative. Evaluation results show that iADMM achieves near optimal decisions in minimizing operational costs without violating workflow intents.
Mays F. Al-Naday, Tom Goethals, Bruno Volckaert
CNSM1
2022 A Dynamic Service Trading in a DLT-Assisted Industrial IoT Marketplace
abstract
With the increasing demand for digitalization and participation in Industry 4.0, new challenges have emerged concerning the market of digital services to compensate for the lack of processing, computation, and other resources within Industrial Internet of Things (IIoTs). At the same time, the complexity of interplay among stakeholders has grown in size, granularity, and variation of trust. In this paper, we consider an IIoT resource market with heterogeneous buyers such as manufacturer owners. The buyers interact with the resource supplier dynamically with specific resource demands. This work introduces a broker between the supplier and the buyers, equipped with Distributed Ledger Technologies (DLT) providing a service for market security and trustworthiness. We first model the DLT-assisted IIoT market analytically to determine an offline solution and understand the selfish interactions among different entities (buyers, supplier, broker). Considering the non-cooperative heterogeneous buyers in the dynamic market, we then follow an independent learners framework to determine an online solution. In particular, the decision-making procedures of buyers are modeled as a Partially Observable Markov Decision Process which is solved using independent Q-learning. We evaluate both the offline and online solutions with analytical simulations, and the results show that the proposed approaches successfully maximize players’ satisfaction. The results further demonstrate that independent Q-learners achieve equilibrium in a dynamic market even without the availability of complete information and communication, and reach a better solution compared to that of centralized Q-learning.
Jiejun Hu, Martin J. Reed, Nikolaos Thomos, Mays F. Al-Naday, Kun Yang 0001
IEEE Trans. Netw. Serv. Manag.4
2021 Flexible Semantic-based Data Networking for IoT Domains
abstract
The rapid adoption of the Internet of Things (IoT) as a means for digital transformation is sketching a new landscape of heterogeneous data and distributed, machine learning-based, applications. The intertwine of the two combined with the varying availability of data, generated in different parts of the domain, raises the need to exchange bulks of relevant data on demand across application(s) points. Data relevance escalates the role of semantics in identifying and locating suitable data; particularly at the network layer, to provide efficient mapping of data supply and demand. This paper proposes a semantic-based data networking framework, for managed IoT domains, embracing principles of information-centric networking without restrictions on the routing function. Managed semantics are used to provide flexible (label-based) data addressing scheme and a scalable semantic locator function, designed as an overlay network of distributed instances that can be realized on top of any routing or forwarding solution. Nonetheless, we outline different routing solutions and their suitability to such scenarios, to then draw a recommendation of the most suitable underlying routing fabric. We evaluate our framework over an example IoT domain of the Pervasive Nation (PN), Ireland national IoT network. Through our example, we show that the number of managed semantics in such a domain can be vastly smaller than that expected on an Internet scale. We analyze our semantic aggregation scheme over the example PN network, and show the high flexibility in mapping data while maintaining a small state in the semantic locator function.
Mays F. Al-Naday, Irene Macaluso
HPSR1
2021 Securing SDN-Controlled IoT Networks Through Edge Blockchain
abstract
The Internet of Things (IoT) connected by software-defined networking (SDN) promises to bring great benefits to cyber-physical systems. However, the increased attack surface offered by the growing number of connected vulnerable devices and separation of SDN control and data planes could overturn the huge benefits of such a system. This article addresses the vulnerability of the trust relationship between the control and data planes. To meet this aim, we propose an edge computing-based Blockchain as a Service (BaaS), enabled by an external BaaS provider. The proposed solution provides verification of inserted flows through an efficient, edge-distributed, blockchain solution. We study two scenarios for the blockchain reward purpose: 1) information symmetry, in which the SDN operator has direct knowledge of the real effort spent by the BaaS provider and 2) information asymmetry, in which the BaaS provider controls the exposure of information regarding spent effort. The latter yields the so-called “moral hazard,” where the BaaS may claim higher than actual effort. We develop a novel mathematical model of the edge BaaS solution and propose an innovative algorithm of a fair reward scheme based on game theory that takes into account moral hazard. We evaluate the viability of our solution through analytical simulations. The results demonstrate the ability of the proposed algorithm to maximize the joint profits of the BaaS and SDN operator, i.e., maximizing the social welfare.
Jiejun Hu, Martin J. Reed, Nikolaos Thomos, Mays F. Al-Naday, Kun Yang 0001
IEEE Internet Things J.4
2019 Anchor Free IP Mobility
abstract
Efficient mobility management techniques are critical in providing seamless connectivity and session continuity between a mobile node and the network during its movement. However, current mobility management solutions generally require a central entity in the network core, tracking IP address movement, and anchoring traffic from source to destination through point-to-point tunnels. Intuitively, this approach suffers from scalability limitations as it creates bottlenecks in the network, due to sub-optimal routing via the anchor point. This is often termed “dog-leg” routing. Meanwhile, alternative anchorless, solutions are not feasible due to the current limitations of the IP semantics, which strongly tie addressing information to location. In contrast, this paper introduces a novel anchorless mobility solution that overcomes these limitations by exploiting a new path-based forwarding fabric together with emerging mechanisms from information-centric networking. These mechanisms decouple the end-system IP address from the path based data forwarding to eliminate the need for anchoring traffic through the network core; thereby, allowing flexible path calculation and service provisioning. Furthermore, by eliminating the limitation of routing via the anchor point, our approach reduces the network cost compared to anchored solutions through bandwidth saving while maintaining comparable handover delay. The proposed solution is applicable to both cellular and large-scale wireless LAN networks that aim to support seamless handover in a single operator domain scenario. The solution is modeled as a Markov-chain which applies a topological basis to describe mobility. The validity of the proposed Markovian model was verified through simulation of both random walk mobility on random geometric networks and trace information from a large-scale, city wide data set. Evaluation results illustrate a significant reduction in the total network traffic cost by 45 percent or more when using the proposed solution, compared to Proxy Mobile IPv6.
Mohammed Al-Khalidi, Nikolaos Thomos, Martin J. Reed, Mays F. Al-Naday, Dirk Trossen
IEEE Trans. Mob. Comput.4
2017 Seamless handover in IP over ICN networks: A coding approach
abstract
Seamless connectivity plays a key role in realizing QoS-based delivery in mobile networks. However, current handover mechanisms hinder the ability to meet this target, due to the high ratio of handover failures, packet loss and service interruption. These challenges are further magnified in Heterogeneous Cellular Networks (HCN) such as Advanced Long Term Evolution (LTE-Advanced) and LTE in unlicensed spectrum (LTE-LAA), due to the variation in handover requirements. Although mechanisms, such as Fast Handover for Proxy Mobile IPv6 (PFMIPv6), attempt to tackle these issues; they come at a high cost with sub-optimal outcomes. This primarily stems from various limitations of existing IP core networks. In this paper we propose a novel handover solution for mobile networks, exploiting the advantages of a revolutionary IP over Information-Centric Networking (IP-over-ICN) architecture in supporting flexible service provisioning through anycast and multicast, combined with the advantages of random linear coding techniques in eliminating the need for retransmissions. Our solution allows coded traffic to be disseminated in a multicast fashion during handover phase from source directly to the destination(s), without the need for an intermediate anchor as in exiting solutions; thereby, overcoming packet loss and handover failures, while reducing overall delivery cost. We evaluate our approach with an analytical and simulation model showing significant cost reduction compared to PFMIPv6.
Mohammed Al-Khalidi, Nikolaos Thomos, Martin J. Reed, Mays F. Al-Naday, Dirk Trossen
ICC4
2017 Information-Centric Multilayer Networking: Improving Performance Through an ICN/WDM Architecture
abstract
Information-centric networking (ICN) facilitates content identification in networks and offers parametric representation of content semantics. This paper proposes an ICN/WDM network architecture that uses these features to offer superior network utilization, in terms of performance and power consumption. The architecture introduces an ICN publish/subscribe communication approach to the wavelength layer, whereby content is aggregated according to its popularity rank into wavelength-size groups that can be published and subscribed to by multiple nodes. Consequently, routing and wavelength assignment (RWA) algorithms benefit from anycast to identify multiple sources of aggregate content and allow optimization of the source selection of light paths. A power-aware algorithm, maximum degree of connectivity, has been developed with the objective of exploiting this flexibility to address the tradeoff between power consumption and network performance. The algorithm is also applicable to IP architectures, albeit with less flexibility. Evaluation results indicate the superiority of the proposed ICN architecture, even when utilizing conventional routing methods, compared with its IP counterpart. The results further highlight the performance improvement achieved by the proposed algorithm, compared with the conventional RWA methods, such as shortest-path first fit.
Mays F. Al-Naday, Nikolaos Thomos, Martin J. Reed
IEEE/ACM Trans. Netw.1
2016 Stateless multicast switching in software defined networks
abstract
Multicast data delivery can significantly reduce traffic in operators' networks, but has been limited in deployment due to concerns such as the scalability of state management. This paper shows how multicast can be implemented in contemporary software defined networking (SDN) switches, with less state than existing unicast switching strategies, by utilising a Bloom Filter (BF) based switching technique. Furthermore, the proposed mechanism uses only proactive rule insertion, and thus, is not limited by congestion or delay incurred by reactive controller-aided rule insertion. We compare our solution against common switching mechanisms such as layer-2 switching and MPLS in realistic network topologies by modelling the TCAM state sizes in SDN switches. The results demonstrate that our approach has significantly smaller state size compared to existing mechanisms and thus is a multicast switching solution for next generation networks.
Martin J. Reed, Mays F. Al-Naday, Nikolaos Thomos, Dirk Trossen, George P. Petropoulos, Spiros Spirou
ICC2
2014 Quality of service in an information-centric network
abstract
QoS provisioning is one of the key challenges facing current as well as future Internet architectures. Its dependency on content recognition does not allow a straightforward support of QoS in the IP, host-centric, model. In contrast, Information-Centric Networking (ICN) offers native content identification in the network, which can be exploited to develop a common, elegant, framework for supporting QoS-based delivery. Therefore, ICN may naturally overcome many of the cumbersome fixes and limitations of today's solutions. In this work, we exploit the flexibility in semantic representation offered by ICN to present a flexible and scalable ICN-based QoS model. Our model defines QoS requirements as information items that can be linked to the content at various aggregation levels, independent of the communication approach. Therefore, it can be applied uniformly to various network types and hierarchies. Furthermore, our model offers enhanced traffic treatment as well as resource utilization while significantly reducing the overhead on the network.
Mays F. Al-Naday, Andreas Bontozoglou, Vassilios G. Vassilakis, Martin J. Reed
GLOBECOM1