VLDB 2026 Research / reviewers in the wild / expert
Hassan Habibi Gharakheili
dblp:139/2729
· DBLP profile ↗
51ranked-venue papers
8as first author
24since 2021 · last 2025
0000-0002-9333-7635ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 38 · 7 first-author · 16 since 2021Security and privacy · 5 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Unveiling Behavioral Transparency of Protocols Communicated by IoT Networked AssetsabstractBehavioral transparency for Internet-of-Things (IoT) networked assets involves two distinct yet interconnected tasks: (a) characterizing device types by discerning the patterns exhibited in their network traffic, and (b) assessing vulnerabilities they introduce to the network. While identifying communication protocols, particularly at the application layer, plays a vital role in effective network management, current methods are, at best, ad-hoc. Accurate protocol identification and attribute extraction from packet payloads are crucial for distinguishing devices and discovering vulnerabilities. This paper makes three contributions: (1) We process a public dataset to construct specific packet traces pertinent to six standard protocols (TLS, HTTP, DNS, NTP, DHCP, and SSDP) of ten commercial IoT devices. We manually analyze TLS and HTTP flows, highlighting their characteristics and parameters. We make our data publicly available; (2) We develop a common model to describe protocol signatures that help with the systematic analysis of protocols even when communicated through non-standard port numbers; and, (3) We evaluate the efficacy of our data models for the six protocols, which constitute approximately 97% of our dataset. Our data models, except for SSDP in 0.3% of Amazon Echo’s flows, produce no false positives for protocol detection. We draw insights into how various IoT devices behave, and adherence to best practices across those protocols by applying these models to our IoT traces. Savindu Wannigama, Arunan Sivanathan, Ayyoob Hamza, Hassan Habibi Gharakheili |
WoWMoM | 4 |
| 2024 | Secure Energy Efficiency Fairness Maximization in Backscatter Throughput Constrained UAV-Assisted Data CollectionabstractCollecting reliable data over extended areas in rural environments for surveillance purposes requires low-cost and effective technologies. This paper proposes a backscattering data collection system that uses unmanned aerial vehicles (UAVs) to overcome wireless coverage challenges in rural areas. The proposed system provides physical-layer security during autonomous data collection, and we optimize the UAV’s trajectory to manage data leakage while taking into account the limited battery of the UAV. Specifically, we aim to maximize the ratio of secrecy across all tags to the UAV’s power consumption while considering constraints such as the UAV’s maximum speed, secrecy rate fairness among the tags and energy budget of the UAV. Since the problem is non-convex, we apply convex transformation by relaxing certain constraints to obtain a locally optimal trajectory with low complexity. We evaluate the performance of our proposed optimization scheme by comparing it with relevant benchmarks and quantify its complexity through simulations. Jiawang Zeng, Deepak Mishra 0001, Hassan Habibi Gharakheili, Aruna Seneviratne |
ICASSP | 3 |
| 2024 | UAV Operation Time Minimization for Wireless-Powered Data CollectionabstractEmploying unmanned aerial vehicles (UAVs) for data collection is crucial in facilitating autonomous monitoring applications within wireless sensor networks (WSNs). To enable sustainable WSNs, wireless powering of ground nodes (GNs) from a flying UAV is a promising technique. However, to maximize utility, we need to smartly allocate the limited resources of UAVs. To this end, we propose jointly optimizing the UAV’s trajectory and time allocation per GN to reduce operation time. We first formulate a non-convex optimization problem for data collection that minimizes operation time while satisfying the sum throughput and time constraint. Thereafter, we develop a methodology that decouples the original problem into two sub-problems: time allocation and trajectory planning. Here, the former is solved in semi-closed form, while a genetic algorithm is employed to solve the latter. Simulations confirm the efficiency of our proposed model and unveil an up to 30% improvement in operation time compared to the existing benchmarks. Deepak Mishra 0001, Hassan Habibi Gharakheili, Derrick Wing Kwan Ng |
ICASSP | 3 |
| 2024 | Realizing Open and Decentralized Marketplace for Exchanging Data of Expected IoT BehaviorsabstractAs data marketplaces become popular in different domains, this paper proposes creating a special marketplace focused on IoT cybersecurity. The goal is to openly share knowledge about IoT devices’ behavior, using structured data formats like Manufacturer Usage Description (MUD) files. To make this work1, we employ technologies like blockchain and smart contracts to build a practical and secure foundation for sharing and accessing important information about how IoT devices should behave on the network. Our contributions are two-fold. (1) We develop a smart contract on the Ethereum blockchain with five concrete functions that realize the essential features of an effective marketplace for sharing data related to the expected behaviors of IoT devices. (2) We implement a prototype of our marketplace in a private chain environment—our codes are publicly released. We demonstrate how effectively our marketplace functions through experiments involving MUD files from consumer IoT devices. Our marketplace enables suppliers and consumers to share MUD data on the Ethereum blockchain for under a hundred dollars, promoting accessibility and participation. Minzhao Lyu, Hassan Habibi Gharakheili |
NOMS | 3 |
| 2024 | Quantification Over Time
Feiyu Li, Hassan Habibi Gharakheili, Gustavo Batista |
ECML/PKDD (5) | 2 |
| 2024 | Efficient IoT Traffic Inference: From Multi-view Classification to Progressive MonitoringabstractMachine learning-based techniques have proven to be effective in Internet-of-Things (IoT) network behavioral inference. Existing works developed data-driven models based on features from network packets and/or flows, but mainly in a static and ad-hoc manner, without adequately quantifying their gains versus costs. In this article, we develop a generic architecture that comprises two distinct inference modules in tandem, which begins with IoT network behavior classification followed by continuous monitoring. In contrast to prior relevant works, our generic architecture flexibly accounts for various traffic features, modeling algorithms, and inference strategies. We argue quantitative metrics are required to systematically compare and efficiently select various traffic features for IoT traffic inference. This article 1 makes three contributions: (1) For IoT behavior classification, we identify four metrics, namely, cost, accuracy, availability, and frequency, that allow us to characterize and quantify the efficacy of seven sets of packet-based and flow-based traffic features, each resulting in a specialized model. By experimenting with traffic traces of 25 IoT devices collected from our testbed, we demonstrate that specialized-view models can be superior to a single combined-view model trained on a plurality of features by accuracy and cost. We also develop an optimization problem that selects the best set of specialized models for a multi-view classification. (2) For monitoring the expected IoT behaviors, we develop a progressive system consisting of one-class clustering models (per IoT class) at three levels of granularity. We develop an outlier detection technique on top of the convex hull algorithm to form custom-shape boundaries for the one-class models. We show how progression helps with computing costs and the explainability of detecting anomalies. (3) We evaluate the efficacy of our optimally selected classifiers versus the superset of specialized classifiers by applying them to our IoT traffic traces. We demonstrate how the optimal set can reduce the processing cost by a factor of six with insignificant impacts on the classification accuracy. Also, we apply our monitoring models to a public IoT dataset of benign and attack traces and show they yield an average true-positive rate of 94% and a false-positive rate of 5%. Finally, we publicly release our data (training and testing instances of classification and monitoring tasks) and code for convex hull-based one-class models. Arman Pashamokhtari, Gustavo Batista, Hassan Habibi Gharakheili |
ACM Trans. Internet Things | 3 |
| 2023 | Programmable Active Scans Controlled by Passive Traffic Inference for IoT Asset CharacterizationabstractThe proliferation of Internet-of-things (IoT) assets has expanded the attack surface of enterprise networks exposed to malicious actors. Therefore, obtaining visibility into connected assets and their behavioral characteristics is increasingly becoming essential to security teams in better managing their network and connected assets. Scheduled vulnerability scans are widely used by enterprises to manage traditional information technology (IT) assets. However, resource-constraint IoT assets may not always withstand disruptive active scans. Passive traffic inference tools have recently emerged for continuous network detection and response capabilities that can be safely applied to IoT and IT networks. Both active and passive approaches come with advantages and limitations in the insights they provide versus measurement and computing costs. This paper attempts to systematically and dynamically leverage the combined capabilities offered by these two approaches. Our contributions are twofold. (1) We highlight capabilities (richness of insights, response time, and temporal utility) and quantity costs (overhead traffic and computing resources) across five active scanning tools (open-source and commercial) and a commercial passive inference tool by applying them to our testbed consisting of 12 commercial IoT devices; and, (2) We develop “pScan”, a programmable packet emitter with open APIs that is dynamically controlled to perform contextualized scans on target IoT assets via SNMP, mDNS, and SSDP packets, as well as banner grabbing and custom probing via TCP connections. We show on our testbed how pScan integrated with the commercial passive inference tool helps to maximize the insights into the characteristics of IoT assets and their utility at significantly reduced costs. We contribute pScan as open source. Hugo Sullivan, Arunan Sivanathan, Ayyoob Hamza, Hassan Habibi Gharakheili |
NOMS | 4 |
| 2023 | PEDDA: Practical and Effective Detection of Distributed Attacks on enterprise networks via progressive multi-stage inference
Minzhao Lyu, Hassan Habibi Gharakheili, Vijay Sivaraman |
Comput. Networks | 2 |
| 2023 | Combining Stochastic and Deterministic Modeling of IPFIX Records to Infer Connected IoT Devices in Residential ISP NetworksabstractResidential Internet service providers (ISPs) today have limited device-level visibility into subscriber houses, primarily due to the network address translation (NAT) technology. The continuous growth of “unmanaged” consumer Internet of Things (IoT) devices combined with the rise of work-from-home makes home networks attractive targets to sophisticated cyber attackers. Volumetric attacks sourced from a distributed set of vulnerable IoT devices can impact ISPs by deteriorating the performance of their network, or even making them liable for being a carrier of malicious traffic. This article explains how ISPs can employ IP Flow Information eXport (IPFIX), a flow-level telemetry protocol available on their network, to infer connected IoT devices and ensure their cyber health without making changes to home networks. Our contributions are threefold: 1) we analyze more than nine million IPFIX records of 26 IoT devices collected from a residential testbed over three months and identify 28 flow features pertinent to their network activity that characterize the network behavior of IoT devices—we release our IPFIX records as open data to the public; 2) we train a multiclass classifier on stochastic attributes of IPFIX flows to infer the presence of certain IoT device types in a home network with an average accuracy of 96%. On top of the machine learning (ML) model, we develop a trust metric to track network activity of detected devices over time; and 3) finally, we develop deterministic models (DTs) of specific and shared cloud services consumed by IoTs, yielding an average accuracy of 92%. We show a combination of stochastic and DTs mitigates false positives in 75% of incidents at the expense of an average 7% reduction in true positives. Arman Pashamokhtari, Norihiro Okui, Yutaka Miyake, Masataka Nakahara, Hassan Habibi Gharakheili |
IEEE Internet Things J. | 5 |
| 2023 | Dynamic Inference From IoT Traffic Flows Under Concept Drifts in Residential ISP NetworksabstractMillions of vulnerable consumer IoT devices in home networks are the enabler for cyber crimes putting user privacy and Internet security at risk. Internet service providers (ISPs) are best poised to mitigate risks by automatically inferring active IoT devices per household and notifying users of vulnerable ones. Developing a scalable inference method that can perform robustly across thousands of home networks is a nontrivial task. This article focuses on the challenges of developing and applying data-driven inference models when labeled data of device behaviors is limited and the distribution of data changes across time and space domains (concept drifts). Our contributions are fourfold: 1) we collect and analyze more than six million network traffic flows of 24 types of consumer IoT devices from 12 real homes over six weeks to highlight the challenge of temporal and spatial concept drifts in network behaviors of IoT devices—we publicly release our training and testing instances data; 2) we analyze the performance of two inference strategies, namely global inference (a model trained on a combined set of all labeled data from training homes) and contextualized inference (several models each trained on the labeled data from a training home) in the presence of concept drifts; 3) to manage concept drifts, we develop a method that dynamically applies the “best” model (from a set) to network traffic of unseen homes during the testing phase, yielding better performance in a fifth of scenarios when the labels are available for the testing data (ideal but unrealistic settings); and 4) we develop a method to automatically select the best model without needing labels of unseen data (a realistic inference) and show that it can achieve 94% of the ideal model’s accuracy. Arman Pashamokhtari, Norihiro Okui, Masataka Nakahara, Ayumu Kubota, Gustavo Batista, Hassan Habibi Gharakheili |
IEEE Internet Things J. | 6 |
| 2023 | Enterprise DNS Asset Mapping and Cyber-Health Tracking via Passive Traffic AnalysisabstractThe Domain Name System (DNS) is a critical service that enables domain names to be converted to IP addresses (or vice versa); consequently, it is generally permitted through enterprise security systems (e.g.,firewalls) with little restriction. This has exposed organizational networks to DDoS, exfiltration, and reflection attacks, inflicting significant financial and reputational damage. Large organizations with loosely federated IT departments (e.g.,Universities and Research Institutes) often are not fully aware of all their DNS assets and vulnerabilities, let alone the attack surface they expose to the outside world. In this paper, we address the “DNS blind spot” by developing methods to passively analyze live DNS traffic, identify organizational DNS assets, and monitor their health on a continuous basis. Our contributions are threefold. First, we perform a comprehensive analysis of all DNS traffic in two large organizations (a University Campus and a Government Research Institute) for over a month, and identify key behavioral profiles for various asset types such as recursive resolvers, authoritative name servers, and mixed DNS servers. Second, we develop an unsupervised clustering method that classifies enterprise DNS assets using the behavioral attributes identified, and demonstrate that our method successfully classifies over 100 DNS assets across the two organizations. Third, our method continuously tracks various health metrics across the organizational DNS assets and identifies several instances of improper configuration, data exfiltration, DDoS, and reflection attacks. We believe the passive analysis methods in this paper can help enterprises monitor organizational DNS health in an automated and risk-free manner. Minzhao Lyu, Hassan Habibi Gharakheili, Craig Russell, Vijay Sivaraman |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2022 | Learning-Based Detection of Malicious Hosts by Analyzing Non-Existent DNS ResponsesabstractDNS Water Torture attack is a type of DDoS attack on authoritative DNS servers and/or open resolvers, whereby the victim is bombarded with random non-existent domains (NXDs) DNS requests, exhausting their entire resources. A famous example of this attack was launched by Mirai botnet on Dyn DNS architecture in 2016. Researchers have proposed solutions to detect these attacks; however, they predominantly apply static thresholds to the count of NXD responses. This method can result in high false positives and needs to be customized to the traffic pattern of victim DNS servers, making it practically challenging for adoption at the source of potential attacks. This paper aims to detect possibly infected hosts of a university campus network that take part in this specific type of DNS-based attacks. Our contributions are threefold: (1) We analyze 120 days' worth of DNS traffic collected from the border of a large university campus network to draw insights into the characteristics of non-existent domain (NXD) responses from incoming DNS packets. We discuss how malicious NXDs differ from benign ones and highlight two attack scenarios based on their requested domain names; (2) We develop a method using multi-staged iForest models to detect malicious internal hosts based on the attributes of their DNS activity; (3) We evaluate the efficacy of our proposed method by applying it to live DNS data streams in our university campus network. We show how our models can detect infected hosts that generate high-volume and low-volume distributed non-existent DNS queries with more than 99% accuracy of correctly classifying legitimate hosts. Jawad Ahmed, Hassan Habibi Gharakheili, Vijay Sivaraman |
GLOBECOM | 2 |
| 2022 | Know Thy Lag: In-Network Game Detection and Latency Measurement
Sharat Chandra Madanapalli, Hassan Habibi Gharakheili, Vijay Sivaraman |
PAM | 2 |
| 2022 | PicP-MUD: Profiling Information Content of Payloads in MUD Flows for IoT DevicesabstractThe Manufacturer Usage Description (MUD) standard aims to reduce the attack surface for IoT devices by locking down their behavior to a formally-specified set of network flows (access control entries). Formal network behaviors can also be systematically and rigorously verified in any operating environment. Enforcing MUD flows and monitoring their activity in real-time can be relatively effective in securing IoT devices; however, its scope is limited to endpoints (domain names and IP addresses) and transport-layer protocols and services. Therefore, misconfigured or compromised IoTs may conform to their MUD-specified behavior but exchange unintended (or even malicious) contents across those flows. This paper develops PicP-MUD with the aim to profile the information content of packet payloads (whether unencrypted, encoded, or encrypted) in each MUD flow of an IoT device. That way, certain tasks like cyber-risk analysis, change detection, or selective deep packet inspection can be performed in a more systematic manner. Our contributions are twofold: (1) We analyze over 123K network flows of 6 transparent (e.g., HTTP), 11 encrypted (e.g., TLS), and 7 encoded (e.g., RTP) protocols, collected in our lab and obtained from public datasets, to identify 17 statistical features of their application payload, helping us distinguish different content types; and (2) We develop and evaluate PicP-MUD using a machine learning model, and show how we achieve an average accuracy of 99% in predicting the content type of a flow. Arman Pashamokhtari, Arunan Sivanathan, Ayyoob Hamza, Hassan Habibi Gharakheili |
WoWMoM | 4 |
| 2022 | Classifying and tracking enterprise assets via dual-grained network behavioral analysis
Minzhao Lyu, Hassan Habibi Gharakheili, Vijay Sivaraman |
Comput. Networks | 2 |
| 2022 | AdIoTack: Quantifying and refining resilience of decision tree ensemble inference models against adversarial volumetric attacks on IoT networks
Arman Pashamokhtari, Gustavo Batista, Hassan Habibi Gharakheili |
Comput. Secur. | 3 |
| 2022 | Combining Device Behavioral Models and Building Schema for Cybersecurity of Large-Scale IoT InfrastructureabstractModern buildings are increasingly getting connected by adopting a range of IoT devices and applications from video surveillance and lighting to people counting and access control. It has been shown that rich connectivity can make building networks more exposed to cyberattacks and, hence, difficult to manage. Currently, there is no systematic approach for evaluating or enforcing cybersecurity of building systems with a large number of heterogeneous IoT devices. In this article, we aim to enhance cybersecurity of a large-scale IoT infrastructure by formally capturing the expected behavior of the system using the static profile of devices’ intended usage, buildings information, and network configurations (predeployment) along with dynamic diagnosis (post-deployment) of network activity using machine-learning models. Our contributions are threefold: 1) we develop a tool that automatically generates a formal ontology of network communications for a connected infrastructure by taking a description of buildings (in the form of Brick schema), device network behavior (in the form of manufacturer usage description (MUD) specifications, MUD profile), and network configurations (address, port, and VLAN) as inputs. We contribute our tool as opensource, and apply it to a subset of our university smart campus testbed, covering 20 IoT devices of three types deployed in seven different buildings. We translate the formal model into network flow rules and enforce them to the network at runtime using programmable networking techniques; 2) we, then, measure the network activity of device-specific flow rules and diagnose their health using a set of trained anomaly detection models (one-class classifiers) each corresponding to a particular type of device and specific building location, and demonstrate how our method detects attacks with reasonable accuracy of 92.5%; and (3) finally, we demonstrate three types of location-defined network policies (deployment, administrative, and organizational) that can be verified by this formal model. Ayyoob Hamza, Hassan Habibi Gharakheili, Trevor Pering, Vijay Sivaraman |
IEEE Internet Things J. | 2 |
| 2022 | Understanding and Reducing HVAC Power Consumption Post-Evacuation Events in Commercial BuildingsabstractBuildings are required to follow standard operational procedures during emergency evacuation. In addition to people evacuating the building, one of the recommended steps during a fire evacuation is to shut down the air handling units (AHUs) of the heating, ventilation, and air conditioning (HVAC) system to prevent smoke from spreading in the building via the air ducts. Shutting down the AHU will inevitably cut-off cooling, resulting in internal temperatures rising steeply particularly on hot days. This phenomenon imposes considerable power demand on the HVAC to rapidly cool the building down during reoccupation. In this article, we study the energy implications of post-evacuation scenarios. Our contributions are threefold: 1) we quantify power excursion caused in 43 evacuation events across 14 buildings of a university campus using a data-driven building thermal model. We show evacuations during summer season can result in power consumption up to 150% above the power demand threshold; 2) we develop a method to reschedule planned evacuations in order to eliminate the power excursions while adhering to building evacuation standards; and 3) we develop a formal optimization framework to minimize the energy costs during planned and emergency evacuations without compromising the desired thermal comfort temperatures by intelligently cooling the building post evacuation. This is the first study to understand and reduce the HVAC power consumption associated with building evacuation events. Iresha Pasquel Mohottige, Hassan Habibi Gharakheili, Arun Vishwanath, Salil S. Kanhere, Vijay Sivaraman |
IEEE Internet Things J. | 2 |
| 2022 | Monetizing Parking IoT Data via Demand Prediction and Optimal Space SharingabstractTransportation is undergoing significant change due to advances in automotive technologies, such as electric and autonomous cars and transportation paradigms, such as car and ridesharing. Coupled with the rapid prevalence of IoT devices, this provides an opportunity for many organizations with large on-premise parking spaces, to better utilize this space, reduce energy footprint, and monetize data generated by IoT systems. This article outlines our efforts to instrument our University’s multistorey parking lot with IoT sensors to monitor real-time usage, and develop a novel dynamic space allocation framework that allows campus manager to redimension the car park to accommodate both car sharing and existing private car users. Our first contribution describes experiences and challenges in measuring car park usage on the university campus and removing noise in the collected data. Our second contribution analyzes data collected during 15 months and draws insights into usage patterns. Our third contribution employs machine learning algorithms to forecast future car park demand in terms of arrival and departure rates, with a mean absolute error of 4.58 cars per hour for a 5-day prediction horizon. Finally, our fourth contribution develops an optimal method for partitioning car park space that aids campus managers in generating revenue from shared cars with minimal impact on private car users. Thanchanok Sutjarittham, Hassan Habibi Gharakheili, Salil S. Kanhere, Vijay Sivaraman |
IEEE Internet Things J. | 2 |
| 2022 | Verifying and Monitoring IoTs Network Behavior Using MUD ProfilesabstractIoT devices are increasingly being implicated in cyber-attacks, raising community concern about the risks they pose to critical infrastructure, corporations, and citizens. In order to reduce this risk, the IETF is pushing IoT vendors to develop formal specifications of the intended purpose of their IoT devices, in the form of a Manufacturer Usage Description (MUD), so that their network behavior in any operating environment can be locked down and verified rigorously. This article aims to assist IoT manufacturers in developing and verifying MUD profiles, while also helping adopters of these devices to ensure they are compatible with their organizational policies and track device network behavior using their MUD profile. Our first contribution is to develop a tool that takes the traffic trace of an arbitrary IoT device as input and automatically generates the MUD profile for it. We contribute our tool as open source, apply it to 28 consumer IoT devices, and highlight insights and challenges encountered in the process. Our second contribution is to apply a formal semantic framework that not only validates a given MUD profile for consistency, but also checks its compatibility with a given organizational policy. We apply our framework to representative organizations and selected devices, to demonstrate how MUD can reduce the effort needed for IoT acceptance testing. Finally, we show how operators can dynamically identify IoT devices using known MUD profiles and monitor their behavioral changes in their network. Ayyoob Hamza, Dinesha Ranathunga, Hassan Habibi Gharakheili, Theophilus Benson, Matthew Roughan, Vijay Sivaraman |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | ReCLive: Real-Time Classification and QoE Inference of Live Video Streaming ServicesabstractSocial media, professional sports, and video games are driving rapid growth in live video streaming, on platforms such as Twitch and YouTube Live. Live streaming experience is very susceptible to short-time-scale network congestion since client playback buffers are often no more than a few seconds. Unfortunately, identifying such streams and measuring their QoE for network management is challenging, since content providers largely use the same delivery infrastructure for live and video-on-demand (VoD) streaming, and packet inspection techniques (including SNI/DNS query monitoring) cannot always distinguish between the two. In this paper, we design and develop ReCLive: a machine learning method for live video detection and QoE measurement based on network-level behavioral characteristics. Sharat Chandra Madanapalli, Alex Mathai, Hassan Habibi Gharakheili, Vijay Sivaraman |
IWQoS | 3 |
| 2021 | Inferring Connected IoT Devices from IPFIX Records in Residential ISP NetworksabstractResidential ISPs today have limited device-level visibility into subscriber houses, primarily due to network address translation (NAT) technology. The continuous growth of "unmanaged" consumer IoT devices combined with the rise of work-from-home makes home networks attractive targets for cyber-attacks. Volumetric attacks sourced from a distributed set of vulnerable IoT devices can impact ISPs by deteriorating the performance of their network, or even making them liable for being a carrier of malicious traffic. This paper explains how ISPs can employ IPFIX (IP Flow Information eXport), a flow-level telemetry protocol available on their network, to infer connected IoT devices and ensure their cyber health without making changes to home networks. Our contributions are threefold: (1) We analyze near three million IPFIX records of 26 IoT devices collected from a residential testbed over three months and identify 28 features, pertinent to their network activity and services, that characterize the network behavior of IoT devices – we release our IPFIX records as open data to the public; (2) We develop a multi-class classifier to infer the presence of certain IoT device types in a home network from NATed IPFIX records. We also develop a Trust metric to track network activity of detected devices over time; and, (3) We evaluate the efficacy of our inferencing method by applying the trained classifier to IPFIX traces which yields an average accuracy of 96% in detecting device types. By computing a temporal measure of trust per each device, we highlight (on our testbed) a permanent behavioral change in third of devices as well as some intermittent behavioral changes in others. Arman Pashamokhtari, Norihiro Okui, Yutaka Miyake, Masataka Nakahara, Hassan Habibi Gharakheili |
LCN | 5 |
| 2021 | Optimal Witnessing of Healthcare IoT Data Using Blockchain Logging ContractabstractVerification of data generated by wearable sensors is increasingly becoming of concern to health service providers and insurance companies. These devices are typically vulnerable to a wide range of cybersecurity attacks, attempting to manipulate sensing data. Most of these disastrous attacks would remain undetected since neither healthcare servers nor Internet-of-Things (IoT) sensors are aware of the existence of attackers in the middle of communication. Thus, there is a need for a verification framework that various authorities can request a verification service for the local network data of a target IoT device. In this article, we leverage blockchain as a distributed platform to realize an on-demand verification scheme. This allows authorities to automatically transact with connected devices for witnessing services. A public request is made for witness statements on the data of a target IoT that is transmitted on its local network, and subsequently, devices (in close vicinity of the target IoT) offer witnessing service. Our contributions are threefold: 1) we develop a system architecture based on blockchain and smart contract that enables authorities to dynamically avail a verification service for data of a subject device from a distributed set of witnesses which are willing to provide (in a privacy-preserving manner) their local wireless measurement in exchange of monetary return; 2) we then develop a method to optimally select witnesses in such a way that the verification error is minimized subject to monetary cost constraints; and 3) finally, we evaluate the efficacy of our scheme using real Wi-Fi session traces collected from a five-storeyed building with more than thirty access points, representative of a hospital. According to the current pricing schedule of the Ethereum public blockchain, our scheme enables healthcare authorities to verify data transmitted from a typical wearable device with the verification error of the order 0.01% at cost of less than $ 2 for 1-hr witnessing service. Mohammad Hossein Chinaei, Hassan Habibi Gharakheili, Vijay Sivaraman |
IEEE Internet Things J. | 2 |
| 2021 | Hierarchical Anomaly-Based Detection of Distributed DNS Attacks on Enterprise NetworksabstractDomain Name System (DNS) is a critical service for enterprise operations, and is often made openly accessible across firewalls. Malicious actors use this fact to attack organizational DNS servers, or use them as reflectors to attack other victims. Further, attackers can operate with little resources, can hide behind open recursive resolvers, and can amplify their attack volume manifold. The rising frequency and effectiveness of DNS-based DDoS attacks make this a growing concern for organizations. Solutions available today, such as firewalls and intrusion detection systems, use combinations of black-lists of malicious sources and thresholds on DNS traffic volumes to detect and defend against volumetric attacks, which are not robust to attack sources that morph their identity or adapt their rates to evade detection. We propose a method for detecting distributed DNS attacks that uses a hierarchical graph structure to track DNS traffic at three levels of host, subnet, and autonomous system (AS), combined with machine learning that identifies anomalous behaviors at various levels of the hierarchy. Our method can detect distributed attacks even with low rates and stealthy patterns. Our contributions are three-fold: (1) We analyze real DNS traffic over a week (nearly 400M packets) from the edges of two large enterprise networks to highlight various types of incoming DNS queries and the behavior of malicious entities generating query scans and floods; (2) We develop a hierarchical graph structure to monitor DNS activity, identify key attributes, and train/tune/evaluate anomaly detection models for various levels of the hierarchy, yielding more than 99% accuracy at each level; and (3) We apply our scheme to a month's worth of DNS data from the two enterprises and compare the results against blacklists and firewall logs to demonstrate its ability in detecting distributed attacks that might be missed by legacy methods while maintaining a decent real-time performance. Minzhao Lyu, Hassan Habibi Gharakheili, Craig Russell, Vijay Sivaraman |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | Detecting Behavioral Change of IoT Devices Using Clustering-Based Network Traffic ModelingabstractThe Internet of Things (IoT) is increasingly becoming a major challenge for network administrators to manage connected devices and sensors ranging from smart lights to smoke alarms and security cameras, at scale. IoT devices use an extensive variety of firmware and provide little (or no) access for the management of their operating systems and configurations. Operators of the IoT infrastructure, therefore, need to employ traffic classification models (trained by historical data) to automatically detect their assets on the network and ensure the health of devices against cyber attacks by monitoring their network behavior. On the other hand, IoT manufacturers often automatically perform firmware upgrades from cloud servers to devices that are operational in the field. This can potentially lead to a change of device behavior which makes it difficult for network operators to maintain classification models (incorporating changes without retraining the entire model). In this article, we develop a modular device classification architecture that allows operators to automatically detect IoT devices by their network activity and dynamically accommodate legitimate changes in assets (either addition of new device profile or upgrade of existing profiles). Our contributions are threefold: 1) we identify key traffic attributes that can be obtained from flow-level network telemetry to characterize the behavior of various IoT device types. We develop an unsupervised one-class clustering method for each device to detect their normal network behavior; 2) we tune device-specific clustering models and use them to classify IoT devices from their network traffic in real time. We enhance our classification by developing methods for automatic conflict resolution and noise filtering; and 3) we evaluate the efficacy of our scheme by applying it to traffic traces (benign and attack) from ten real IoT devices and demonstrate its ability to detect behavioral changes with an overall accuracy of more than 94%. Arunan Sivanathan, Hassan Habibi Gharakheili, Vijay Sivaraman |
IEEE Internet Things J. | 2 |
| 2020 | Monitoring Enterprise DNS Queries for Detecting Data Exfiltration From Internal HostsabstractEnterprise networks constantly face the threat of valuable and sensitive data being stolen by cyber-attackers. Sophisticated attackers are increasingly exploiting the Domain Name System (DNS) service for exfiltrating data as well as maintaining tunneled command and control communications for malware. This is because DNS traffic is usually allowed to pass through enterprise firewalls without deep inspection or state maintenance, thereby providing a covert channel for attackers to encode low volumes of data without fear of detection. This paper develops and evaluates a real-time mechanism for detecting exfiltration and tunneling of data over DNS. Unlike prior solutions that operate off-line or in the network core, ours works in real-time at the enterprise edge. Our first contribution is to collect and analyze real DNS traffic from two organizations (a large University and a mid-sized Government Research Institute) over several days and extract numerous stateless attributes of DNS messages that can distinguish malicious from legitimate queries. Our second contribution is to develop, tune, and train a machine-learning algorithm to detect anomalies in DNS queries using a benign dataset of top rank primary domains. To achieve this, we have used 14 days-worth of DNS traffic from each organization. For our third contribution, we implement our scheme on live 10 Gbps traffic streams from the network borders of the two organizations, inject more than three million malicious DNS queries generated by two exfiltration tools, and show that our solution can identify them with high accuracy. We compare our solution with the two-class classifier used in prior work. We draw insights into anomalous DNS queries of two enterprise networks by their anomaly scores, the trace of query count over time, enterprise hosts querying them, and TTL and Type fields of their corresponding responses. Our tools and datasets are made available to the public for validation and further research. Jawad Ahmed, Hassan Habibi Gharakheili, Qasim Raza, Craig Russell, Vijay Sivaraman |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | Managing IoT Cyber-Security Using Programmable Telemetry and Machine LearningabstractCyber-security risks for Internet of Things (IoT) devices sourced from a diversity of vendors and deployed in large numbers, are growing rapidly. Therefore, management of these devices is becoming increasingly important to network operators. Existing network monitoring technologies perform traffic analysis using specialized acceleration on network switches, or full inspection of packets in software, which can be complex, expensive, inflexible, and unscalable. In this paper, we use SDN paradigm combined with machine learning to leverage the benefits of programmable flow-based telemetry with flexible data-driven models to manage IoT devices based on their network activity. Our contributions are three-fold: (1) We analyze traffic traces of 17 real consumer IoT devices collected in our lab over a six-month period and identify a set of traffic flows (per-device) whose time-series attributes computed at multiple timescales (from a minute to an hour) characterize the network behavior of various IoT device types, and their operating states (i.e., booting, actively interacted with user, or being idle); (2) We develop a multi-stage architecture of inference models that use flow-level attributes to automatically distinguish IoT devices from non-IoTs, classify individual types of IoT devices, and identify their states during normal operations. We train our models and validate their efficacy using real traffic traces; and (3) We quantify the trade-off between performance and cost of our solution, and demonstrate how our monitoring scheme can be used in operation for detecting behavioral changes (firmware upgrade or cyber attacks). Arunan Sivanathan, Hassan Habibi Gharakheili, Vijay Sivaraman |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2019 | Real-Time Detection of DNS Exfiltration and Tunneling from Enterprise Networks
Jawad Ahmed, Hassan Habibi Gharakheili, Qasim Raza, Craig Russell, Vijay Sivaraman |
IM | 2 |
| 2019 | Demo Abstract: A Tool to Detect and Visualize Malicious DNS Queries for Enterprise Networks
Jawad Ahmed, Hassan Habibi Gharakheili, Qasim Raza, Craig Russell, Vijay Sivaraman |
IM | 2 |
| 2019 | Modeling and Monitoring Wi-Fi Calling Traffic in Enterprise Networks Using Machine LearningabstractMany enterprise campuses have poor signal coverage indoors from one or more mobile operators, and thus are increasingly embracing carrier Wi-Fi calling services, allowing their users to make and receive mobile phone calls over the enterprise Wi-Fi connection. Mobile carriers employ IPSec tunnels to secure user calls and messages that traverse untrusted enterprise networks and possibly the public Internet. These encrypted connections from user handsets are seen as potential security threats in enterprise networks. In this paper, we develop a machine learning-based system for monitoring encrypted traffic of IPSec tunnels on the network to distinguish Wi-Fi calling traffic from anomalies. Our contributions are as follows: (1) We analyze traffic traces consisting of carrier Wi-Fi calls made over four mobile networks to highlight network behavioral characteristics of this enterprise application. We develop a set of models using one-class and multi-class classification algorithms to determine if Wi-Fi calling application is present on the IPSec tunnel (if so, to classify its state), otherwise generate a notification to block the non Wi-Fi calling flow, and (2) We evaluate the efficacy of our system in detecting real calls and their states (initiation, heartbeat, and actual call) as well as raising true alarms in case of anomalous traffic. Sharat Chandra Madanapalli, Arunan Sivanathan, Hassan Habibi Gharakheili, Vijay Sivaraman, Santosh Patil, Byju Pularikkal |
LCN | 3 |
| 2019 | Inferring IoT Device Types from Network Behavior Using Unsupervised ClusteringabstractThe Internet-of-Things (IoT) is increasingly becoming a major challenge for network administrators to monitor and manage connected devices and sensors, ranging from smart-lights to smoke-alarms and security-cameras. In addition to new device offerings, manufacturers tend to automatically perform firmware upgrade from their cloud servers to change functionalities of existing devices that are operational in the field. This makes it difficult to re-train device classification models in order to capture legitimate changes dynamically. In this paper, we develop a modular device classification architecture that allows us to dynamically accommodate legitimate changes in network IoT assets, either addition of a new device type or upgrades of existing types, without replacing the entire set of models. Our contributions are twofold: (1) We identify key traffic attributes that can be obtained from flow-level network telemetry to characterize individual IoT devices. We develop an unsupervised one-class clustering method for each device to detect its normal network behavior. (2) We tune individual device-specific clustering models and use them to classify IoT devices in real-time. We enhance our classification by developing methods for automatic conflict resolution and noise filtering. We evaluate the efficacy of our scheme by applying it to traffic traces of ten real IoT devices, and demonstrate its ability to achieve overall accuracy of more than 94%. Arunan Sivanathan, Hassan Habibi Gharakheili, Vijay Sivaraman |
LCN | 2 |
| 2019 | Mapping an Enterprise Network by Analyzing DNS Traffic
Minzhao Lyu, Hassan Habibi Gharakheili, Craig Russell, Vijay Sivaraman |
PAM | 2 |
| 2019 | Measuring and Modeling Car Park Usage: Lessons Learned from a Campus Field-TrialabstractTransportation is undergoing significant change due to the growth of ride-sharing, electric cars, car-sharing, and self-driving cars. Organizations that have significant real-estate dedicated to on-premise employee car parking are therefore looking to adapt the use of this space, motivated by the opportunity to become greener, improve sharing, and pursue new revenue opportunities. In this paper, we outline our experiences from instrumenting, measuring, and analyzing car-park usage in our University's multi-storey parking lot, and building a model that explores its use for multiple purposes in the near future. Our specific contributions are as follows: (1)We begin by describing experiences and challenges in measuring car-park usage on our campus and cleaning the collected data; (2)We analyze data collected over 23 weeks (covering teaching and non-teaching periods)and draw insights into the usage patterns, including occupancy patterns by times-of-day and days-of-week, and identifying various user groups based on attributes such as arrival time and duration of stay; (3)We develop a queuing model to optimize the use of parking space for generating revenue from shared cars with minimal impact on private car users. We believe our study guides campus managers wanting to generate more value from their existing parking resources. Thanchanok Sutjarittham, Gary Chen, Hassan Habibi Gharakheili, Vijay Sivaraman, Salil S. Kanhere |
WOWMOM | 3 |
| 2019 | Experiences With IoT and AI in a Smart Campus for Optimizing Classroom UsageabstractIncreasing demand for university education is putting pressure on campuses to make better use of their real-estate resources. Evidence indicates that enrollments are rising, yet attendance is falling due to diverse demands on student time and easy access to online content. This paper outlines our efforts to address classroom under-utilization in a real university campus arising from the gap between enrollment and attendance. We do so by instrumenting classrooms with Internet of Things (IoT) sensors to measure real-time usage, using AI to predict attendance, and performing optimal allocation of rooms to courses so as to minimize space wastage. Our first contribution undertakes an evaluation of several IoT sensing approaches for measuring class occupancy, and comparing them in terms of cost, accuracy, privacy, and ease of deployment/operation. Our second contribution instruments nine lecture halls of varying capacity across campus, collects and cleans live occupancy data spanning about 250 courses over two sessions, and draws insights into attendance patterns, including identification of canceled lectures and class tests, while also releasing our data openly to the public. Our third contribution is to use AI techniques for predicting classroom attendance, applying them to real data, and accurately predicting future attendance with an root-mean-square error as low as 0.16. Our final contribution is to develop an optimal allocation of classes to rooms based on predicting attendance rather than enrollment, resulting in over 10% savings in room costs with very low risk of room overflows. Thanchanok Sutjarittham, Hassan Habibi Gharakheili, Salil S. Kanhere, Vijay Sivaraman |
IEEE Internet Things J. | 2 |
| 2019 | Classifying IoT Devices in Smart Environments Using Network Traffic CharacteristicsabstractThe Internet of Things (IoT) is being hailed as the next wave revolutionizing our society, and smart homes, enterprises, and cities are increasingly being equipped with a plethora of IoT devices. Yet, operators of such smart environments may not even be fully aware of their IoT assets, let alone whether each IoT device is functioning properly safe from cyber-attacks. In this paper, we address this challenge by developing a robust framework for IoT device classification using traffic characteristics obtained at the network level. Our contributions are fourfold. First, we instrument a smart environment with 28 different IoT devices spanning cameras, lights, plugs, motion sensors, appliances, and health-monitors. We collect and synthesize traffic traces from this infrastructure for a period of six months, a subset of which we release as open data for the community to use. Second, we present insights into the underlying network traffic characteristics using statistical attributes such as activity cycles, port numbers, signalling patterns, and cipher suites. Third, we develop a multi-stage machine learning based classification algorithm and demonstrate its ability to identify specific IoT devices with over 99 percent accuracy based on their network activity. Finally, we discuss the trade-offs between cost, speed, and performance involved in deploying the classification framework in real-time. Our study paves the way for operators of smart environments to monitor their IoT assets for presence, functionality, and cyber-security without requiring any specialized devices or protocols. Arunan Sivanathan, Hassan Habibi Gharakheili, Franco Loi, Adam Radford, Chamith Wijenayake, Arun Vishwanath, Vijay Sivaraman |
IEEE Trans. Mob. Comput. | 2 |
| 2019 | iTeleScope: Softwarized Network Middle-Box for Real-Time Video Telemetry and ClassificationabstractVideo continues to dominate network traffic, yet operators today have poor visibility into the number, duration, and resolutions of the video streams traversing their domain. Current monitoring approaches are inaccurate, expensive, or unscalable, as they rely on statistical sampling, middle-box hardware, or packet inspection software. We present iTelescope, the first intelligent, inexpensive, and scalable softwarized network middle-box solution for identifying and classifying video flows in realtime. Our solution is novel in combining dynamic flow rules with telemetry and machine learning, and is built on commodity OpenFlow switches and open-source software. We develop a fully functional system, train it in the lab using multiple machine learning algorithms, and validate its performance to show over 95% accuracy in identifying and classifying video streams from many providers, including YouTube and Netflix. Lastly, we conduct tests to demonstrate its scalability to tens of thousands of concurrent streams, and deploy it live on a campus network serving several hundred real users. Our traffic monitoring system gives unprecedented fine-grained real-time visibility of video streaming performance to operators of enterprise and carrier networks at very low cost. Hassan Habibi Gharakheili, Minzhao Lyu, Yu Wang 0131, Himal Kumar, Vijay Sivaraman |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2019 | Enhancing Security Management at Software-Defined Exchange PointsabstractDistributed Denial-of-Service (DDoS) attacks continue to escalate in size and scale, and there is growing need for security management at network-level that can restrict a service to a geography (aka geo-blocking) and prevent the victim's IP address from being faked (aka IP-spoof protection). The former reduces the attack surface on the victim, while the latter reduces liability on the organization from which the attack originates. Unfortunately, these solutions are hard to implement in today's networks, requiring expensive hardware appliances and/or manual configuration. This was exemplified in the recent attack on the Australian government census website, which had to be brought down for weeks in order for security configurations to be applied. In this paper, we first argue that an Internet Exchange Point (IXP) is an appropriate place for managing security of an enterprise, and then design, implement, and evaluate a geo-blocking and IP-spoofing protection solution for a Software Defined IXP. Our first contribution is to define a grammar for operators to specify their high-level security intents, and a compiler that automatically synthesizes these to low-level flow rules for insertion to the interconnect fabric. Our second contribution is to develop a mixed integer linear program optimization framework for distributing flow rules across switches with limited table size, while minimizing carriage costs of malicious and extraneous traffic. Finally, we evaluate the cost benefits of our scheme via simulation of a large IXP network, and demonstrate its practical utility in blocking attacks via implementation over the open-source ONOS controller and experimentation in an SDN testbed. Himal Kumar, Hassan Habibi Gharakheili, Craig Russell, Vijay Sivaraman |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2018 | A tool to access and visualize classroom attendance data from a smart campus: demo abstractabstractThis demo presents our web-tool to access and visualize student attendance data obtained from instrumenting a pilot set of classrooms with people counting sensors in a large university campus in Sydney, Australia. We showcase two aspects: (1) how to access and process our open data-set containing time-stamped occupancy counts for 9 lecture rooms of varying size in which over 250 courses are conducted over a 12-week semester; and (2) visualizing occupancy at multiple spatial (per-room and per-course) and temporal (over a day, week, or semester) granularities, enabling new insights into student attendance and room usage patterns. Thanchanok Sutjarittham, Hassan Habibi Gharakheili, Salil S. Kanhere, Vijay Sivaraman |
IPSN | 2 |
| 2018 | Data-driven monitoring and optimization of classroom usage in a smart campusabstractStudent enrollments world-wide are increasing each year, while lecture attendance continues to fall, due to diverse demands on student time and easy access to online content. The resulting underutilization of classrooms entails cost penalties, especially in campuses where real-estate is at a premium. This paper outlines our efforts to instrument a University campus with sensors to measure classroom attendance, in a cost-effective and scalable manner without endangering student privacy. We begin by undertaking a lab evaluation of several approaches to measuring class occupancy, and compare them in terms of cost, accuracy, and ease of deployment and operation. We then instrument 9 lecture halls of varying capacity across campus, collect and clean live data on occupancy spanning about 250 courses over 12 weeks during session, and draw insights into attendance patterns, including identification of canceled lectures and class tests; our occupancy data is released openly to the public. Lastly, we show how classroom allocation can be optimized based on attendance rather than enrollments, resulting in potential savings of 52% in room costs. Thanchanok Sutjarittham, Hassan Habibi Gharakheili, Salil S. Kanhere, Vijay Sivaraman |
IPSN | 2 |
| 2018 | Real-time detection, isolation and monitoring of elephant flows using commodity SDN systemabstractOperators of enterprise and carrier networks in-creasingly require real-time visibility into traffic patterns in their network, so they can do better resource management (congestion detection, dynamic routing, capacity scheduling) and security protection (detection of intrusions and volumetric attacks). Of particular interest are elephant flows that transfer large volumes, since they demand most resources and can inflict most damage. Today's techniques for detecting and monitoring elephant flows are based on software-based packet analysis or hardware-based inspection, which are either unscalable or expensive. In this paper we design, implement, and evaluate an SDN-based solution that is scalable (to tens of Gigabits-per-second) and inexpensive (built using commodity OpenFlow switches). We first develop a system architecture that judiciously combines software packet inspection with hardware flow-table counters to identify and monitor heavy flows. We then use real traffic traces taken from a campus network to tune our algorithm parameters for desired trade-off between software load and hardware table size. Finally, we prototype our solution on a commodity OpenFlow hardware switch together with open-source controller and packet inspection software, and demonstrate operation at 10Gbps in a real campus network. Sharat Chandra Madanapalli, Minzhao Lyu, Himal Kumar, Hassan Habibi Gharakheili, Vijay Sivaraman |
NOMS | 4 |
| 2018 | Responsive high throughput congestion control for interactive applications over SDN-enabled networks
Aous Thabit Naman, Yu Wang 0131, Hassan Habibi Gharakheili, Vijay Sivaraman, David S. Taubman |
Comput. Networks | 3 |
| 2017 | Quantifying the reflective DDoS attack capability of household IoT devicesabstractDistributed Denial-of-Service (DDoS) attacks are increasing in frequency and volume on the Internet, and there is evidence that cyber-criminals are turning to Internet-of-Things (IoT) devices such as cameras and vending machines as easy launchpads for large-scale attacks. This paper quantifies the capability of consumer IoT devices to participate in reflective DDoS attacks. We first show that household devices can be exposed to Internet reflection even if they are secured behind home gateways. We then evaluate eight household devices available on the market today, including lightbulbs, webcams, and printers, and experimentally profile their reflective capability, amplification factor, duration, and intensity rate for TCP, SNMP, and SSDP based attacks. Lastly, we demonstrate reflection attacks in a real-world setting involving three IoT-equipped smart-homes, emphasising the imminent need to address this problem before it becomes widespread. Minzhao Lyu, Daniel Sherratt, Arunan Sivanathan, Hassan Habibi Gharakheili, Adam Radford, Vijay Sivaraman |
WISEC | 4 |
| 2017 | Enabling Fast and Slow Lanes for Content Providers Using Software Defined NetworkingabstractResidential broadband consumption is growing rapidly, increasing the gap between Internet service provider (ISP) costs and revenues. Meanwhile, proliferation of Internet-enabled devices is congesting access networks, degrading end-user experience, and affecting content provider monetization. In this paper, we propose a new model whereby the content provider explicitly signals fast- and slow-lane requirements to the ISP on a per-flow basis, using open APIs supported through software defined networking (SDN). Our first contribution is to develop an architecture that supports this model, presenting arguments on why this benefits consumers (better user experience), ISPs (two-sided revenue), and content providers (fine-grained control over peering arrangement). Our second contribution is to evaluate our proposal using a real trace of over 10 million flows to show that video flow quality degradation can be nearly eliminated by the use of dynamic fast-lanes, and web-page load times can be hugely improved by the use of slow-lanes for bulk transfers. Our third contribution is to develop a fully functional prototype of our system using open-source SDN components (Openflow switches and POX controller modules) and instrumented video/file-transfer servers to demonstrate the feasibility and performance benefits of our approach. Our proposal is a first step towards the long-term goal of realizing open and agile access network service quality management that is acceptable to users, ISPs, and content providers alike. Hassan Habibi Gharakheili, Vijay Sivaraman, Tim Moors, Arun Vishwanath, John Matthews, Craig Russell |
IEEE/ACM Trans. Netw. | 1 |
| 2016 | Managing home routers from the cloud using Software Defined NetworkingabstractSoftware Defined Networking (SDN) is increasingly being applied to the management and orchestration of data center networks, wide-area networks, and enterprise networks. In this work we demonstrate the benefits of cloud-based SDN management of home routers. We install open-source firmware (OpenWRT and OpenVSiwtch) on off-the-shelf gateways, and deliver new services to consumers via our software in the cloud. Our service allows users to see their household devices and respective bandwidth usage in real-time, impose a download quota on a per-device basis, and impose time-based parental controls on specific household devices. By removing control from the home gateway to the cloud, we show that new services can be delivered rapidly via easy-to-use interfaces suitable for technically unsophisticated users. Hassan Habibi Gharakheili, Luke Exton, Vijay Sivaraman |
CCNC | 1 |
| 2016 | SDN APIs and Models for Two-Sided Resource Management in Broadband Access NetworksabstractAccess networks, largely based on DSL or cable links, continue to be the bandwidth bottleneck between device-rich households and high-speed core networks, causing frustration for both end-users and content service providers (CSPs). In this paper, we advocate that the scarce bandwidth resource on the access link be managed jointly, under software control, by the Internet service provider (ISP), consumer, and CSP. Our first contribution is to develop software defined networking (SDN) APIs for bandwidth control at fine-grain (per-flow) by the CSP and at coarse-grain (per-device) by the consumer, and highlight the benefits of such an architecture for all entities. Second, we develop an economic model to guide the ISP in determining bandwidth allocation that balances the needs of the CSP against those of the consumer, and demonstrate its utility via simulation of trace data comprising over 10 million flows. Finally, we prototype our system using commodity home routers and open-source SDN platforms, and conduct experiments in a campus-scale network to demonstrate how our scheme permits proactive and reactive improvement in end-user experience. Hassan Habibi Gharakheili, Vijay Sivaraman, Arun Vishwanath, Luke Exton, John Matthews, Craig Russell |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2015 | Broadband fast-lanes with two-sided control: Design, evaluation, and economicsabstractEnhancing quality-of-service (QoS) for specific traffic streams by assigning them to "fast-lanes" on the broadband Internet service is a subject of intense ongoing debate. While Internet Service Providers (ISPs) have clear economic imperatives for fast-lanes paid by content service providers (CSPs), proponents of net-neutrality argue that consumer interest will be ignored in the selection of traffic thus prioritized. In this paper we propose a new solution in which ISP fast-lanes have "two-sided" control, i.e. by both consumers and CSPs. Our contributions are two-fold: (1) We develop an architecture in which ISP-operated fast-lanes can be controlled at fine-grain (per-flow) by the CSP and at coarse-grain (per-device) by the consumer, and argue why we think such an architecture can meet the needs of all three parties; and (2) We develop an economic model to guide the ISP in determining fast-lane allocation that balances the needs of the CSP against those of the consumer, and evaluate our model via simulation of trace data comprising over 10 million flows. Hassan Habibi Gharakheili, Vijay Sivaraman, Arun Vishwanath, Luke Exton, John Matthews, Craig Russell |
IWQoS | 1 |
| 2015 | Network-level security and privacy control for smart-home IoT devicesabstractThe increasing uptake of smart home appliances, such as lights, smoke-alarms, power switches, baby monitors, and weighing scales, raises privacy and security concerns at unprecedented scale, allowing legitimate and illegitimate entities to snoop and intrude into the family's activities. In this paper we first illustrate these threats using real devices currently available in the market. We then argue that as more such devices emerge, the attack vectors increase, and ensuring privacy/security of the house becomes more challenging. We therefore advocate that device-level protections be augmented with network-level security solutions, that can monitor network activity to detect suspicious behavior. We further propose that software defined networking technology be used to dynamically block/quarantine devices, based on their network activity and on the context within the house such as time-of-day or occupancy-level. We believe our network-centric approach can augment device-centric security for the emerging smart-home. Vijay Sivaraman, Hassan Habibi Gharakheili, Arun Vishwanath, Roksana Boreli, Olivier Mehani |
WiMob | 2 |
| 2015 | Comparing edge and host traffic pacing in small buffer networks
Hassan Habibi Gharakheili, Arun Vishwanath, Vijay Sivaraman |
Comput. Networks | 1 |
| 2014 | Personalizing the home network experience using cloud-based SDNabstractHome networks are becoming increasingly rich in devices and applications, but continue to share the broadband link in a neutral way. We believe the time is ripe to personalize the home network experience, allowing a household to differentiate its users (e.g. father's laptop prioritized over kid's iPad) and services (e.g. video streaming prioritized over downloading). In this paper we argue that SDN provides a way to automate self-customization by households, while cloud-based delivery simplifies subscriber management. We develop an architecture comprising a cloud-based front-end portal and SDN-based back-end APIs, and show how these can be used by the subscriber to improve streaming-video (YouTube) quality and video conferencing (Skype) experience, and to permit device-specific parental controls (e.g. Facebook access). We prototype and validate our solution in a platform comprising the Floodlight controller and OVS switches. Lastly, we evaluate our solutions via experiments of realistic scenarios to quantify the benefits in terms of improved quality of experience and new features for the user. Hassan Habibi Gharakheili, Jacob Bass, Luke Exton, Vijay Sivaraman |
WoWMoM | 1 |
| 2013 | Virtualizing the access network via open APIsabstractResidential broadband consumption is growing rapidly, increasing the gap between ISP costs and revenues. Meanwhile, proliferation of Internet-enabled devices is congesting access networks, frustrating end-users and content providers. We propose that ISPs virtualize access infrastructure, using open APIs supported through SDN, to enable dynamic and controlled sharing amongst user streams. Content providers can programmatically provision capacity to user devices to ensure quality of experience, users can match the degree of virtualization to their usage pattern, and ISPs can realize per-stream revenues by slicing their network resources. Using video streaming and bulk transfers as examples, we develop an architecture that specifies the interfaces between the ISP, content provider, and user. We propose an algorithm for optimally allocating network resources, leveraging bulk transfer time elasticity and access path space diversity. Simulations using real traces show that virtualization can reduce video degradation by over 50%, for little extra bulk transfer delay. Lastly, we prototype our system and validate it in a test-bed with real video streaming and file transfers. Our proposal is a first step towards the long-term goal of realizing open and agile access network service quality management that is acceptable to users, ISPs and content providers alike. Vijay Sivaraman, Tim Moors, Hassan Habibi Gharakheili, Dennis Ong, John Matthews, Craig Russell |
CoNEXT | 3 |
| 2013 | Edge versus host pacing of TCP traffic in small buffer networks
Hassan Habibi Gharakheili, Arun Vishwanath, Vijay Sivaraman |
Networking | 1 |