Supratik Bhattacharyya

dblp:15/369 · DBLP profile ↗
← Back
21ranked-venue papers
4as first author
0since 2021 · last 2008
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 19 · 4 first-authorSystems, architecture and hardware · 2Security and privacy · 1Software engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
16 papers
Network measurement and analytics · 34% Routing and switching · 28% Internet architecture and protocols · 13%
Network and information security
2 papers
Network security · 100%

Topics — the 30 heaviest of 34, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network measurement and analytics
traffic characterization
0.232008
Internet traffic behavior profiling for network security monitoring · IEEE/ACM Trans. Netw. 2008
Profiling internet backbone traffic: behavior models and applications · SIGCOMM 2005
A pragmatic definition of elephants in internet backbone traffic · Internet Measurement Workshop 2002
Routing and switching
inter-domain routing
0.122005
Measuring the Shared Fate of IGP Engineering and Interdomain Traffic · ICNP 2005
The impact of BGP dynamics on intra-domain traffic · SIGMETRICS 2004
Routing and switching › adaptive routing
deflection routing
0.122005
Measuring the Shared Fate of IGP Engineering and Interdomain Traffic · ICNP 2005
An approach to alleviate link overload as observed on an IP backbone · INFOCOM 2003
Network measurement and analytics
traffic matrix estimation
0.122004
The impact of BGP dynamics on intra-domain traffic · SIGMETRICS 2004
Traffic matrix estimation: existing techniques and new directions · SIGCOMM 2002
Network security
traffic analysis
0.112008
Internet traffic behavior profiling for network security monitoring · IEEE/ACM Trans. Netw. 2008
Network security › traffic analysis
traffic profiling
0.112008
Internet traffic behavior profiling for network security monitoring · IEEE/ACM Trans. Netw. 2008
Network management and operations › fault management
fault diagnosis
0.122008
Characterization of Failures in an IP Backbone Network · INFOCOM 2004
Characterization of failures in an operational IP backbone network · IEEE/ACM Trans. Netw. 2008
Internet architecture and protocols
multicast
0.132003
Efficient rate-controlled bulk data transfer using multiple multicast groups · IEEE/ACM Trans. Netw. 2003
Efficient Rate-Controlled Bulk Data Transfer Using Multiple Multicast Groups · INFOCOM 1998
Reliable Multicast Transport Protocol (RMTP) · IEEE J. Sel. Areas Commun. 1997
Network measurement and analytics › internet measurement
routing measurement
0.112005
Measuring the Shared Fate of IGP Engineering and Interdomain Traffic · ICNP 2005
Network security › intrusion detection and prevention › intrusion detection
anomaly detection
0.112005
Profiling internet backbone traffic: behavior models and applications · SIGCOMM 2005
Internet architecture and protocols › wide area network
backbone network
0.012004
Characterization of Failures in an IP Backbone Network · INFOCOM 2004
Routing and switching › routing protocol
BGP routing dynamics
0.012004
The impact of BGP dynamics on intra-domain traffic · SIGMETRICS 2004
Network management and operations › failure analysis
failure classification
0.012004
Characterization of Failures in an IP Backbone Network · INFOCOM 2004
Transport protocols and congestion control › congestion management
multicast congestion control
0.021999
The Loss Path Multiplicity Problem in Multicast Congestion Control · INFOCOM 1999
Efficient Rate-Controlled Bulk Data Transfer Using Multiple Multicast Groups · INFOCOM 1998
Routing and switching › routing protocol
intra-domain routing
0.012003
An approach to alleviate link overload as observed on an IP backbone · INFOCOM 2003
Network measurement and analytics
traffic measurement
0.012003
An approach to alleviate link overload as observed on an IP backbone · INFOCOM 2003
Network measurement and analytics › heavy hitter detection
elephant flow detection
0.012002
A pragmatic definition of elephants in internet backbone traffic · Internet Measurement Workshop 2002
Network management and operations › failure analysis
network failure analysis
0.012002
Analysis of link failures in an IP backbone · Internet Measurement Workshop 2002
Transport protocols and congestion control
rate control
0.022003
Efficient Rate-Controlled Bulk Data Transfer Using Multiple Multicast Groups · INFOCOM 1998
Efficient rate-controlled bulk data transfer using multiple multicast groups · IEEE/ACM Trans. Netw. 2003
Network management and operations › network security management
security monitoring
0.012008
Internet traffic behavior profiling for network security monitoring · IEEE/ACM Trans. Netw. 2008
Transport protocols and congestion control › window-based congestion control
AIMD
0.011999
The Loss Path Multiplicity Problem in Multicast Congestion Control · INFOCOM 1999
Network optimization and economics › fairness
max-min fairness
0.011999
The Loss Path Multiplicity Problem in Multicast Congestion Control · INFOCOM 1999
Transport protocols and congestion control
end-to-end congestion control
0.011998
A Class of End-to-End Congestion Control Algorithms for the Internet · ICNP 1998
Internet architecture and protocols › multicast
reliable multicast
0.011997
Reliable Multicast Transport Protocol (RMTP) · IEEE J. Sel. Areas Commun. 1997
Transport protocols and congestion control › retransmission schemes
selective retransmission
0.011997
Reliable Multicast Transport Protocol (RMTP) · IEEE J. Sel. Areas Commun. 1997
Data mining
clustering
0.012005
Profiling internet backbone traffic: behavior models and applications · SIGCOMM 2005
Routing and switching › traffic engineering
link weight optimization
0.012003
An approach to alleviate link overload as observed on an IP backbone · INFOCOM 2003
Routing and switching › routing algorithms
shortest path routing
0.012003
An approach to alleviate link overload as observed on an IP backbone · INFOCOM 2003
Network measurement and analytics
statistical inference
0.012002
Traffic matrix estimation: existing techniques and new directions · SIGCOMM 2002
Transport protocols and congestion control
transport layer
0.011998
A Class of End-to-End Congestion Control Algorithms for the Internet · ICNP 1998

Methods — techniques the papers use, named apart from their topics

traffic profiling · 0.2information-theoretic techniques · 0.2data mining · 0.2measurement study · 0.1simulation · 0.1optimization · 0.1analysis · 0.1packet trace correlation · 0.0measurement · 0.0BGP routing table analysis · 0.0
YearPublicationVenuePosition
2008 Characterization of failures in an operational IP backbone network
Athina Markopoulou, Gianluca Iannaccone, Supratik Bhattacharyya, Chen-Nee Chuah, Yashar Ganjali, Christophe Diot
IEEE/ACM Trans. Netw.3
2008 Internet traffic behavior profiling for network security monitoring
Kuai Xu, Zhi-Li Zhang, Supratik Bhattacharyya
IEEE/ACM Trans. Netw.3
2007 A Real-Time Network Traffic Profiling System
abstract
This paper presents the design and implementation of a real-time behavior profiling system for high-speed Internet links. The profiling system uses flow-level information from continuous packet or flow monitoring systems, and uses data mining and information-theoretic techniques to automatically discover significant events based on the communication patterns of end-hosts. We demonstrate the operational feasibility of the system by implementing it and performing extensive benchmarking of CPU and memory costs using a variety of packet traces from OC-48 links in an Internet backbone network. To improve the robustness of this system against sudden traffic surges such as those caused by denial of service attacks or worm outbreaks, we propose a simple yet effective filtering algorithm. The proposed algorithm successfully reduces the CPU and memory cost while maintaining high profiling accuracy.
Kuai Xu, Feng Wang 0002, Supratik Bhattacharyya, Zhi-Li Zhang
DSN3
2007 IGP link weight assignment for operational Tier-1 backbones
Antonio Nucci, Supratik Bhattacharyya, Nina Taft, Christophe Diot
IEEE/ACM Trans. Netw.2
2006 Connectionless port scan detection on the backbone
abstract
Considerable research has been done on detecting and blocking portscan activities that are typically conducted by infected hosts to discover other vulnerable hosts. However, the focus has been on enterprise gateway-level intrusion detection systems where the traffic volume is low and network configuration information is readily available. This paper investigates the effectiveness of existing portscan detection algorithms in the context of a large transit backbone network and proposes a new algorithm that meets the demands of aggregated high speed backbone traffic. Specifically, we evaluate two existing approaches - the portscan detection algorithm in SNORT, and a modified version of the TRW algorithm that is a part of the intrusion detection tool BRO. We then propose a new approach, TAPS, which uses sequential hypothesis testing to detect hosts that exhibit abnormal access patterns in terms of destination hosts and destination ports. We perform a comparative analysis of these three approaches using real backbone packet traces, and find that TAPS exhibits the best performance in terms of catching the maximum number of true scanners and yielding the least number of false positives. We have a working implementation of TAPS on our monitoring platform. Further implementation optimizations using bloom filters are identified and discussed.
Avinash Sridharan, Supratik Bhattacharyya
IPCCC3
2005 Measuring the Shared Fate of IGP Engineering and Interdomain Traffic
abstract
Typically, each autonomous system (AS) tunes its local IS-IS or OSPF metrics without any coordination with other ASes. Such local optimizations can lead to sub-optimal end-to-end network performance, as suggested by the performance enhancements achieved by some overlay routing projects. We study the interaction of local IGP engineering in an ISP network with interdomain routing policies. Specifically, (a) how does hot-potato routing (the BGP policy of choosing the closest egress) influence the selection of IGP link metrics? and (b) how does traffic to neighboring ASes shift due to changes in the local AS's IGP link metrics? In our measurement study, we find that the hot-potato routing policy interacts significantly with IGP engineering -ignoring this interaction resulted in metrics sub-optimal by as much as 20% of link utilization. Further, the impact on neighboring ASes depends on peering locations and policies, and as much as 25% of traffic to a neighboring AS can shift the exit point. Such interdomain shifts can be detrimental to the performance of neighboring ASes. We rely on the actual measured network topology, IGP metrics, traffic matrix and delay bounds. Even though our results are specific to a single ISP, they show significant interaction between local IGP engineering and interdomain routing policies, and thus motivate further work on global network optimization and coordination among ISPs.
Sharad Agarwal, Antonio Nucci, Supratik Bhattacharyya
ICNP3
2005 Profiling internet backbone traffic: behavior models and applications
abstract
Recent spates of cyber-attacks and frequent emergence of applications affecting Internet traffic dynamics have made it imperative to develop effective techniques that can extract, and make sense of, significant communication patterns from Internet traffic data for use in network operations and security management. In this paper, we present a general methodology for building comprehensive behavior profiles of Internet backbone traffic in terms of communication patterns of end-hosts and services. Relying on data mining and information-theoretic techniques, the methodology consists of significant cluster extraction, automatic behavior classification and structural modeling for in-depth interpretive analyses. We validate the methodology using data sets from the core of the Internet. The results demonstrate that it indeed can identify common traffic profiles as well as anomalous behavior patterns that are of interest to network operators and security analysts.
Kuai Xu, Zhi-Li Zhang, Supratik Bhattacharyya
SIGCOMM3
2004 An AS-level study of Internet path delay characteristics
abstract
According to conventional wisdom, links connecting different autonomous systems (AS) are the performance bottlenecks in the core of the Internet. The paper presents an empirical evaluation of delays across inter-AS links using hop-limited active probes. The measurements cover a diverse set of Internet paths starting from locations within three large transit Internet service providers (ISPs). We find that most inter-AS links on the Internet paths covered by this study do not contribute significantly to end-to-end delays. The few exceptions are long-haul links with large propagation delays. Furthermore, the delay estimates are fairly stable across days, making it possible for ISPs to choose inter-domain paths or perform traffic engineering based on delay measurement feedback. Our observations also suggest that a very large component of the end-to-end delay for the measured paths usually occurs within a single AS.
Amgad Zeitoun, Chen-Nee Chuah, Supratik Bhattacharyya, Christophe Diot
GLOBECOM3
2004 Characterization of Failures in an IP Backbone Network
abstract
We analyze IS-IS routing updates from sprint's IP network to characterize failures that affect IP connectivity. Failures are first classified based on probable causes such as maintenance activities, router-related and optical layer problems. Key temporal and spatial characteristics of each class are analyzed and, when appropriate, parameterized using well-known distributions. Our results indicate that 20% of all failures is due to planned maintenance activities. Of the unplanned failures, almost 30% are shared by multiple links and can be attributed to router-related and optical equipment-related problems, while 70% affect a single link at a time. Our classification of failures according to different causes reveals the nature and extent of failures in today's IP backbones. Furthermore, our characterization of the different classes can be used to develop a probabilistic failure model, which is important for various traffic engineering problems.
Athina Markopoulou, Gianluca Iannaccone, Supratik Bhattacharyya, Chen-Nee Chuah, Christophe Diot
INFOCOM3
2004 Service availability: a new approach to characterize IP backbone topologies
abstract
Traditional SLAs, defined by average delay or packet loss, often camouflage the instantaneous performance perceived by end-users. We define a set of metrics for service availability to quantify the performance of IP backbone networks and capture the impact of routing dynamics on packet forwarding. Given a network topology and its link weights, we propose a novel technique to compute the associated service availability by taking into account transient routing dynamics and operational conditions, such as BGP table size and traffic distributions. Even though there are numerous models for characterizing topologies, none of them provide insights on the expected performance perceived by end customers. Our simulations show that the amount of service disruption experienced by similar networks (i.e., with similar intrinsic properties such as average out-degree or network diameter) could be significantly different, making it imperative to use new metrics for characterizing networks. In the second part of the paper, we derive goodness factors based on service availability viewed from three perspectives: ingress node (from one node to many destinations), link (traffic traversing a link), and network-wide (across all source-destination pairs). We show how goodness factors can be used in various applications and describe our numerical results.
Ram Keralapura, Chen-Nee Chuah, Gianluca Iannaccone, Supratik Bhattacharyya
IWQoS4
2004 The impact of BGP dynamics on intra-domain traffic
abstract
Recent work in network traffic matrix estimation has focused on generating router-to-router or PoP-to-PoP (Point-of-Presence) traffic matrices within an ISP backbone from network link load data. However, these estimation techniques have not considered the impact of inter-domain routing changes in BGP (Border Gateway Protocol) . BGP routing changes have the potential to introduce significant errors in estimated traffic matrices by causing traffic shifts between egress routers or PoPs within a single backbone network. We present a methodology to correlate BGP routing table changes with packet traces in order to analyze how BGP dynamics affect traffic fan-out within a large "tier-1" network. Despite an average of 133 BGP routing updates per minute, we find that BGP routing changes do not cause more than 0.03% of ingress traffic to shift between egress PoPs. This limited impact is mostly due to the relative stability of network prefixes that receive the majority of traffic -- 0.05% of BGP routing table changes affect intra-domain routes for prefixes that carry 80% of the traffic. Thus our work validates an important assumption underlying existing techniques for traffic matrix estimation in large IP networks.
Sharad Agarwal, Chen-Nee Chuah, Supratik Bhattacharyya, Christophe Diot
SIGMETRICS3
2003 An approach to alleviate link overload as observed on an IP backbone
abstract
Shortest path routing protocols may suffer from congestion due to the use of a single shortest path between a source and a destination. The goal of our work is to first understand how links become overloaded in an IP backbone, and then to explore if the routing protocol, -either in its existing form, or in some enhanced form could be made to respond immediately to overload and reduce the likelihood of its occurrence. Our method is to use extensive measurements of Sprint's backbone network, measuring 138 links between September 2000 and June 2001. We find that since the backbone is designed to be overprovisioned, link overload is rare, and when it occurs, 80% of the time it is caused due to link failures. Furthermore, we find that when a link is overloaded, few (if any) other links in the network are also overloaded. This suggests that deflecting packets to less utilized alternate paths could be an effective method for tackling overload. We analytically derive the condition that a network, which has multiple equal length shortest paths between every pair of nodes (as is common in the highly meshed backbone networks) can provide for loop-free deflection paths if all the link weights are within a ratio 1 + 1/(d- I) of each other; where d is the diameter of the network. Based on our measurements, the nature of the backbone topology and the careful use of link weights, we propose a deflection routing algorithm to tackle link overload where each node makes local decisions. Simulations suggest that this can be a simple and efficient way to overcome link overload, without requiring any changes to the routing protocol.
Sundar Iyer, Supratik Bhattacharyya, Nina Taft, Christophe Diot
INFOCOM2
2003 Efficient rate-controlled bulk data transfer using multiple multicast groups
abstract
Controlling the rate of bulk data multicast to a large number of receivers is difficult, due to the heterogeneity among the end systems' capabilities and their available network bandwidth. If the data transfer rate is too high, some receivers will lose data, and retransmissions will be required. If the data transfer rate is too slow, an inordinate amount of time will be required to transfer the data. In this paper, we examine an approach toward rate-controlled multicast of bulk data in which the sender uses multiple multicast groups to transmit data at different rates to different subgroups of receivers. We present simple algorithms for determining the transmission rate associated with each multicast channel, based on static resource constraints, e.g., network bandwidth bottlenecks. Transmission rates are chosen so as to minimize the average time needed to transfer data to all receivers. Analysis and simulation are used to show that our policies for rate selection perform well for large and diverse receiver groups and make efficient use of network bandwidth. Moreover, we find that only a small number of multicast groups are needed to reap most of the possible performance benefits.
Supratik Bhattacharyya, James F. Kurose, Don Towsley, Ramesh Nagarajan
IEEE/ACM Trans. Netw.1
2002 Analysis of link failures in an IP backbone
abstract
Today's IP backbones are provisioned to provide excellent performance in terms of loss, delay and availability. However, performance degradation and service disruption are likely in the case of failure, such as fiber cuts, router crashes, etc. In this paper, we investigate the occurence of failures in Sprint's IP backbone and their potential impact on emerging services such as Voice-over-IP (VoIP). We first examine the frequency and duration of failure events derived from IS-IS routing updates collected from three different points in the Sprint IP backbone. We observe that link failures occur as part of everyday operation, and the majority of them are short-lived (less than 10 minutes). We also discuss various statistics such as the distribution of inter-failure time, distribution of link failure durations, etc. which are essential for constructing a realistic link failure model. Next, we present an analysis of routing and service reconvergence time during a controlled link failure scenario in our backbone. Our results indicate that disruption to packet forwarding after link failures depends not only on routing protocol dynamics, but also on the design of routers' architectures and control planes. Thus our results offer insights into two basic components for defining network-wide availability, which we consider a more appropriate metric for service-level agreements to support emerging applications.
Gianluca Iannaccone, Chen-Nee Chuah, Richard Mortier, Supratik Bhattacharyya, Christophe Diot
Internet Measurement Workshop4
2002 A pragmatic definition of elephants in internet backbone traffic
abstract
No abstract available.
Konstantina Papagiannaki, Nina Taft, Supratik Bhattacharyya, Patrick Thiran, Kavé Salamatian, Christophe Diot
Internet Measurement Workshop3
2002 Traffic matrix estimation: existing techniques and new directions
abstract
Very few techniques have been proposed for estimating traffic matrices in the context of Internet traffic. Our work on POP-to-POP traffic matrices (TM) makes two contributions. The primary contribution is the outcome of a detailed comparative evaluation of the three existing techniques. We evaluate these methods with respect to the estimation errors yielded, sensitivity to prior information required and sensitivity to the statistical assumptions they make. We study the impact of characteristics such as path length and the amount of link sharing on the estimation errors. Using actual data from a Tier-1 backbone, we assess the validity of the typical assumptions needed by the TM estimation techniques. The secondary contribution of our work is the proposal of a new direction for TM estimation based on using choice models to model POP fanouts. These models allow us to overcome some of the problems of existing methods because they can incorporate additional data and information about POPs and they enable us to make a fundamentally different kind of modeling assumption. We validate this approach by illustrating that our modeling assumption matches actual Internet data well. Using two initial simple models we provide a proof of concept showing that the incorporation of knowledge of POP features (such as total incoming bytes, number of customers, etc.) can reduce estimation errors. Our proposed approach can be used in conjunction with existing or future methods in that it can be used to generate good priors that serve as inputs to statistical inference techniques.
Alberto Medina, Nina Taft, Kavé Salamatian, Supratik Bhattacharyya, Christophe Diot
SIGCOMM4
2001 A novel loss indication filtering approach for multicast congestion control
Supratik Bhattacharyya, Don Towsley, James F. Kurose
Comput. Commun.1
1999 The Loss Path Multiplicity Problem in Multicast Congestion Control
abstract
An important concern for source-based multicast congestion control algorithms is the loss path multiplicity (LPM) problem that arises because a transmitted packet can be lost on one or more of the many end-to-end paths in a multicast tree. Consequently, if a multicast source's transmission rate is regulated according to loss indications from receivers, the rate may be completely throttled as the number of loss paths increases. In this paper, we analyze a family of additive increase multiplicative decrease congestion control algorithms and show that, unless careful attention is paid to the LPM problem, the average session bandwidth of a multicast session may be reduced drastically as the size of the multicast group increases. This makes it impossible to share bandwidth in a max-min fair manner among unicast and multicast sessions. We show that max-min fairness can be achieved however if every multicast session regulates its rate according to the most congested end-to-end path in its multicast tree. We present an idealized protocol for tracking the most congested path under changing network conditions, and use simulations to illustrate that tracking the most congested path is indeed a promising approach.
Supratik Bhattacharyya, Don Towsley, James F. Kurose
INFOCOM1
1998 A Class of End-to-End Congestion Control Algorithms for the Internet
abstract
We formulate end-to-end congestion control as a global optimization problem. Based on this formulation, a class of minimum cost flow control (MCFC) algorithms for adjusting session rates or window sizes is proposed. Significantly, we show that these algorithms can be implemented at the transport layer of an IP network and can provide certain fairness properties and user priority options without requiring non-FIFO switches. Two algorithm versions are discussed. A coarse version is geared towards implementation in the current Internet, relying on the end-to-end packet loss observations as an indication of congestion. A more complete version anticipates an Internet where sessions can solicit explicit congestion information through a concise probing mechanism. We show that TCP congestion control, after some modification, may be treated as a special case of the MCFC algorithms.
S. Jamaloddin Golestani, Supratik Bhattacharyya
ICNP2
1998 Efficient Rate-Controlled Bulk Data Transfer Using Multiple Multicast Groups
abstract
Controlling the rate of bulk data multicast to a large number of receivers is difficult due to the heterogeneity among the end-systems' capabilities and their available network bandwidth. If the data transfer rate is too high, some receivers will lose data, and retransmissions will be required. If the data transfer rate is too low, an inordinate amount of time will be required to transfer the data. In this paper, we examine an approach towards rate-controlled multicast of bulk data in which the sender uses multiple multicast groups to transmit data at different rates to different sub-groups of receivers. We present simple algorithms for determining the transmission rate associated with each multicast channel, based on static resource constraints, e.g., network bandwidth bottlenecks. Transmission rates are chosen so as to minimize the average time needed to transfer data to all receivers. Analysis and simulation are used to show that our policies for rate selection perform well for large and diverse receiver groups and make efficient use of network bandwidth. Moreover, we find that only a small number of multicast groups are needed to reap most of the possible performance benefits.
Supratik Bhattacharyya, James F. Kurose, Don Towsley, Ramesh Nagarajan
INFOCOM1
1997 Reliable Multicast Transport Protocol (RMTP)
abstract
This paper presents the design, implementation, and performance of a reliable multicast transport protocol (RMTP). The RMTP is based on a hierarchical structure in which receivers are grouped into local regions or domains and in each domain there is a special receiver called a designated receiver (DR) which is responsible for sending acknowledgments periodically to the sender, for processing acknowledgment from receivers in its domain, and for retransmitting lost packets to the corresponding receivers. Since lost packets are recovered by local retransmissions as opposed to retransmissions from the original sender, end-to-end latency is significantly reduced, and the overall throughput is improved as well. Also, since only the DRs send their acknowledgments to the sender, instead of all receivers sending their acknowledgments to the sender, a single acknowledgment is generated per local region, and this prevents acknowledgment implosion. Receivers in RMTP send their acknowledgments to the DRs periodically, thereby simplifying error recovery. In addition, lost packets are recovered by selective repeat retransmissions, leading to improved throughput at the cost of minimal additional buffering at the receivers. This paper also describes the implementation of RMTP and its performance on the Internet.
Sanjoy Paul, Krishan K. Sabnani, John C.-H. Lin, Supratik Bhattacharyya
IEEE J. Sel. Areas Commun.4