VLDB 2026 Research / reviewers in the wild / expert
Kamil Saraç
dblp:15/542
· DBLP profile ↗
57ranked-venue papers
6as first author
5since 2021 · last 2024
0000-0001-7018-5256ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 44 · 5 first-author · 4 since 2021Systems, architecture and hardware · 2Security and privacy · 2Artificial intelligence and machine learning · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | In-network Reinforcement Learning for Attack Mitigation using Programmable Data Plane in SDNabstractThe development of reinforcement learning (RL) algorithms has created a paradigm where the agents are trained to learn directly by observing the environment and learning policies to perform tasks autonomously. In the case of network environments, these agents can control and monitor the traffic as well as help preserve the confidentiality, integrity, and availability of resources and services in the network. In the case of software-defined networks (SDN), the centralized controller in the control plane has become the single point of failure for the entire network. Reactive routing in SDNs makes such networks vulnerable to denial-of-service (DoS) attacks that aim to overwhelm switch memory and the control channel between SDN switches and controllers. One potential solution to cope with such attacks is to use an intelligent mechanism to detect and block them with minimal performance overhead for the controller and control channel. In this work, we investigate the practicality and effectiveness of a reinforcement learning (RL) approach to cope with DoS attacks in SDN networks that utilize programmable switches. Assuming the existence of a reliable reward function, we demonstrate that an RL-based approach can successfully adapt to the changing nature of attack traffic to detect and mitigate attacks without overwhelming switch memory and the control channel in SDN. Aparna Ganesan, Kamil Saraç |
ICCCN | 2 |
| 2023 | A Scheme to Introduce New Reachability Domains on the InternetabstractToday’s Internet functions as a single reachability domain where every service hosted on it is reachable by everyone else on the Internet. In this paper, we propose introduction of more reachability domains on the Internet. Each reachability domain can be established atop the existing infrastructure and yet is capable of running in virtual isolation with the public Internet. We present some basic building blocks, discuss several implications, and present an example service architecture to enumerate potential benefits of the proposed scheme in this paper. Kamil Saraç |
IPCCC | 2 |
| 2022 | Attack Detection and Mitigation using Intelligent Data Planes in SDNsabstractDespite its significant advantages over distributed control in traditional networks, the centralized control used in software defined networks (SDN) introduces potential security vulnerabilities. The controller-switch bandwidth, flow tables in data plane switches, and the controller itself could become overwhelmed by potential denial of service attacks in SDN. In this work, we present a machine learning (ML) based approach to defend SDNs from such attacks. We use decision tree and logistic regression based ML models to identify decision boundaries at the controller site. We then translate these decision boundaries into range compressed match-action table rules. Next, we dynamically communicate these rules to the data plane switches using P4 language primitives enabling switches to filter out attack traffic without needing to consult with the SDN controller for each new packet. Our solution allows us to dynamically update the match-action rules based on the changing behavior of the attack traffic without causing any downtime for the data plane switches. Aparna Ganesan, Kamil Saraç |
GLOBECOM | 2 |
| 2021 | Poster: Private Internet: A Global End-to-End Service ModelabstractThe public Internet is a network of autonomously owned and operated networks. Outdated peering policies and lack of end-to-end performance guarantees are causing its ossification which have led large cloud and content providers to build their own global private backbone infrastructures. As much as these private backbones help eliminate public transit for content hosted across their networks, content hosted elsewhere is still carried over the public Internet. In this poster, we propose a model where these private backbone operators collaborate with the access-networks of content providers and consumers to implement end-to-end network services with better performance characteristics than the public Internet. We call the resulting end-to-end service domain as a "Private Internet". Kamil Saraç |
ICNP | 2 |
| 2021 | Mitigating Evasion Attacks on Machine Learning based NIDS Systems in SDNabstractToday, network-based intrusions are among the most prevalent security threats our networked systems face. In the case of software-defined networks (SDN), not only the connected devices and services but also the SDN controllers may be subjected to intrusion attempts. The advent of efficient and robust machine learning (ML) algorithms along with the availability of a large number of network datasets enabled the development of ML-based network intrusion detection systems (NIDS). Recent work has demonstrated that ML-based NIDS systems are vulnerable to evasion attacks where the adversary targets the ML classifier in the NIDS system to evade detection by performing various packet perturbations. In this work, we propose an approach to build robust ML based NIDS systems that use multiple ML classifiers trained with reduced feature sets. Our approach depends on a careful feature selection procedure based on Permutation Feature Importance, a wrapper based feature engineering method. Our evaluations on well-known datasets show that the proposed hybrid multi-classifier system is robust and performs well against the packet perturbation attacks considered in this work. Aparna Ganesan, Kamil Saraç |
NetSoft | 2 |
| 2020 | ZIDX: A Generic Framework for Random Access to BGP Records in Compressed MRT DatasetsabstractThis paper presents an approach, called ZIDX, to decompress a desired chunk of a GZIP compressed large data file without decompressing the prefix of the file. For a GZIP compressed data file that is sorted by an attribute, ZIDX also allows a user to implement random seek to the desired location in the compressed file to retrieve and decompress a desired data block. We use ZIDX to implement efficient search and retrieval of BGP routing data in GZIP compressed files stored locally or fetched over the public Internet (from the RIPE RIS BGP archival repository). Our evaluation results show that ZIDX incurs minimal storage overhead and provides significant time and bandwidth savings in retrieving BGP records of interest from GZIP compressed BGP data files stored both locally and remotely. Omer F. Ozarslan, Kamil Saraç |
ICCCN | 2 |
| 2016 | Estimating clustering coefficients via metropolis-hastings random walk and wedge sampling on large OSN graphsabstractWe propose estimators for popular clustering coefficient measures (1) network average clustering coefficient and (2) global clustering coefficient (aka transitivity). Unlike most of previous studies estimating clustering coefficients, we do not use independent vertex sampling as it is either unavailable or inefficient to implement in most Online Social Networks (OSNs). Instead, we propose estimators based on Metropolis-Hastings Random Walk (MHRW) and wedge sampling. We use several large scale OSN graphs to compare the accuracy of the proposed estimators with that of the existing alternatives. The evaluation results show that our estimator for transitivity generally outperforms the alternative RW-based estimator in most graphs. However, in general, the underlying graph structure and the studied characteristic has important effect in the estimation accuracy. Emrah Çem, Kamil Saraç |
IPCCC | 2 |
| 2016 | Heuristics for 2-coverage multi point relay problem in wireless ad hoc and sensor networksabstractMulti point relay (MPR) selection problem aims at improving energy efficiency by minimizing the number of relay nodes for a network wide broadcast operation in wireless ad hoc and sensor networks. If a relay node misses a broadcast packet, a large number of nodes reachable via this relay node may end up missing this broadcast packet. Therefore, improving broadcast reliability in an energy efficient way becomes an interesting task for those broadcast applications that benefit from an increased level of reliability. In this paper, we propose three incremental heuristics to select MPR nodes so as to provide 2-coverage to all 2-hop neighbors of a broadcasting node. Our heuristics are built on our former exact solution to 1-coverage MPR problem. Our simulation based evaluations show that the proposed heuristics can provide very good accuracy level for 2-coverage MPR problem. Partha De, Kamil Saraç, Ramaswamy Chandrasekaran |
WiOpt | 2 |
| 2016 | Estimation of structural properties of online social networks at the extreme
Emrah Çem, Kamil Saraç |
Comput. Networks | 2 |
| 2015 | Estimating the size and average degree of online social networks at the extremeabstractGiven the increasingly limiting nature of online social networks (OSNs), studying their structural characteristics under a limited data access model becomes important. In this study, we propose estimators for network size and average degree characteristics of OSNs. We sample an OSN graph using random neighbor API calls. A random neighbor API call returns only the id of a randomly selected neighbor of a given user. Although the existing estimators give good accuracy estimations for a given sample size, they are not applicable under the extremely limited data access model considered here. We conduct experiments on real world graphs to measure the performance of the proposed estimators. Emrah Çem, Kamil Saraç |
ICC | 2 |
| 2015 | An experimental study on inter-domain routing dynamics using IP-level path tracesabstractCommercial relationships between Autonomous Systems (ASes) regulate the inter-domain routing dynamics. Identifying these relationships and properly interpreting them can help understand inter-domain routing dynamics and explore routing anomalies where ASes are not following standard transit policies. Most studies in this domain use Border Gateway Protocol (BGP) data to study inter-domain routing dynamics. In this study, we use IP-level topology data to complement these studies. More specifically, we use traceroute tool to collect end-to-end path traces. Then, we map our data to an AS-level topology map. We do this mainly by using the existing BGP based topology maps and AS-level neighborhood data to come up with several new heuristics to identify false AS-level links and missing AS hops in our dataset. In addition, we infer relationships for those AS-level links in our IP-level data that do not appear in the existing BGP based topology maps. We evaluate the accuracy of our heuristics by comparing their findings to that of the existing state-of-the-art techniques. Finally, we use AS-level paths along with AS relationships dataset to infer potential inter-domain routing anomalies and classify them according to their suspected causes. Nazim Ahmed, Kamil Saraç |
LCN | 2 |
| 2015 | Graph Based Induction of unresponsive routers in Internet topologies
Hakan Kardes, Mehmet Hadi Gunes, Kamil Saraç |
Comput. Networks | 3 |
| 2014 | Measuring path divergence in the InternetabstractPath divergence refers to a situation where a path from source to an intermediate router on a source to destination path may not be a prefix of the source to destination path. Studying path divergence helps us understand various operational characteristics of the underlying network. In this paper, we perform an active measurement study to observe the magnitude, causes, and types of path divergence in the Internet. We observe that most path divergence cases occur due to load balancing routers but policy-based inter domain routing practices also contribute to divergence. We also observe that most routers causing path divergence are positioned in the backbone of the network but routers closer to the sources are causing more number of divergences. Our study combined with peering relationship data between neighboring domains can also point out potential routing anomaly cases in the inter domain routing process in the Internet. Finally, our techniques to trace to intermediate routers can explore new IP addresses, routers, Autonomous Systems (ASes) which can potentially help enrich topology mapping procedure and infer new peering relationships among ASes. Nazim Ahmed, Kamil Saraç |
IPCCC | 2 |
| 2014 | SKAIT: A parameterized key assignment scheme for confidential communication in resource constrained ad hoc wireless networks
Ramon Novales, Neeraj Mittal, Kamil Saraç |
Ad Hoc Networks | 3 |
| 2013 | Location matters: Eliciting responses to direct probesabstractIn this work, we propose techniques to attain visibility into an arbitrary Internet subnetwork that is responsive to indirect probes but not to direct probes. By probing the network from a small number of selected vantage points, we are able to collect information about network-layer topology which would otherwise be hidden from measurement due to rate limiting practices, security mechanisms, and routing dynamics. We investigate the reasons for differing visibility, and the required number and placement strategies of vantage points needed to collect topology information at a low cost. We demonstrate substantial improvement in global visibility as probed by the TraceNET path measurement tool when leveraging only five vantage points selected according to route similarity. Ethan Blanton, M. Engin Tozal, Kamil Saraç, Sonia Fahmy |
IPCCC | 3 |
| 2013 | Impact of sampling design in estimation of graph characteristicsabstractStudying structural and functional characteristics of large scale graphs (or networks) has been a challenging task due to the related computational overhead. Hence, most studies consult to sampling to gather necessary information to estimate various features of these big networks. On the other hand, using a best effort approach to graph sampling within the constraints of an application domain may not always produce accurate estimates. In fact, the mismatch between the characteristics of interest and the utilized network sampling methodology may result in incorrect inferences about the studied characteristics of the underlying system. In this study we empirically investigate the sources of information loss in a sampling process; identify the fundamental factors that need to be carefully considered in a sampling design; and use several synthetic and real world graphs to elaborately demonstrate the mismatch between the sampling design and graph characteristics of interest. Emrah Çem, M. Engin Tozal, Kamil Saraç |
IPCCC | 3 |
| 2013 | Adaptive Information Coding for Secure and Reliable Wireless Telesurgery Communications
M. Engin Tozal, Yongge Wang 0001, Ehab Al-Shaer, Kamil Saraç, Bhavani Thuraisingham, Bei-tseng Chu |
Mob. Networks Appl. | 4 |
| 2012 | Estimating Network Layer Subnet Characteristics via Statistical Sampling
M. Engin Tozal, Kamil Saraç |
Networking (1) | 2 |
| 2012 | Polynomial time solution to minimum forwarding set problem in wireless networks under disk coverage model
Mehmet Baysan, Kamil Saraç, Ramaswamy Chandrasekaran |
Ad Hoc Networks | 2 |
| 2011 | Subnet level network topology mappingabstractInternet topology at the network layer consists of routers and subnets, i.e., point-to-point or multi-access connections. Network measurement studies have focused on router level maps and derived characteristics of routers such as mean degree, degree distribution, clustering coefficient and betweenness. Considering the fact that subnets are also important building blocks of the Internet topology, this paper introduces a complementary view of network topologies named subnet level maps. Subnet level network topology maps represent subnets as vertices and depict routers as links connecting the vertices/subnets. Additionally, we introduce a tool, called exploreNET, for subnet discovery. Although ExploreNET is based on the same principals as our recent work traceNET [21], it differs from traceNET in its utilization in various domains. Particularly, it allows us discover the underlying subnet level topology map of a network rather than the map dictated by routing dynamics. Finally, we present an evaluation of exploreNET by using it to discover and analyze various subnet characteristics including degree distribution, capacity distribution and utilization for six geographically disperse public Internet Service Providers (ISPs). M. Engin Tozal, Kamil Saraç |
IPCCC | 2 |
| 2011 | Palmtree: An IP alias resolution algorithm with linear probing complexity
M. Engin Tozal, Kamil Saraç |
Comput. Commun. | 2 |
| 2010 | TraceNET: an internet topology data collectorabstractThis paper presents a network layer Internet topology collection tool called tracenet. Compared to traceroute, tracenet can collect a more complete topology information on an end-to-end path. That is, while traceroute returns a list of IP addresses each representing a router on a path, tracenet attempts to return all the IP addresses assigned to the interfaces on each visited subnetwork on the path. Consequently, the collected information (1) includes more IP addresses belonging to the traced path; (2) represents "being on the same LAN" relationship among the collected IP addresses; and (3) annotates the discovered subnets with their observed subnet masks. Our experiments on Internet2, GEANT, and four major ISP networks demonstrate promising results on the utility of tracenet for future topology measurement studies. M. Engin Tozal, Kamil Saraç |
Internet Measurement Conference | 2 |
| 2010 | SKAIT: A Parameterized Key Assignment Scheme for Wireless NetworksabstractIn this paper, we propose SKAIT, a parameterized symmetric key pre-distribution scheme that guarantees a secure and confidential channel between every pair of nodes in a wireless network. Parameterization enables control over the number of keys assigned to a node, and allows users to trade increased key space complexity for improved collusion resistance. We provide an analysis of the space complexity, time complexity, and collusion resistance, and we show that message exchange is secure against internal and external eavesdroppers. We also show via analysis and simulation that SKAIT possesses the ability to make efficient use of key storage capacities of at least 3 sqrt (n), and collusion resistance superior to that of two recently proposed schemes when the number of colluding nodes is small. Ramon Novales, Neeraj Mittal, Kamil Saraç |
ISPDC | 3 |
| 2010 | Characterizing link and path reliability in large-scale wireless sensor networksabstractReliable data transfer (RDT) is one of the key issues in wireless sensor networks (WSNs) and can be achieved by using link-level re-transmissions and multi-path routing. Another key issue is the scalability of WSNs. In this paper, we try to better understand and characterize/quantify the relationships between reliability and scalability, and identify possible design options for the future RDT protocols in large-scale WSNs. With this in mind, we first conducted actual experiments to characterize link reliability measures in an actual sensor network setting. We then used these measures and analyze how commonly used RDT mechanisms impact overall path reliability. In general, our analysis shows that the combination of link-level re-transmissions and multi-path routing is a viable solution in small-scale WSNs. However, due to the increased length of paths between sensor nodes and sinks in large-scale WSNs, it becomes costly to sustain the overall reliability at an acceptable level. Therefore, the future RDT protocols should focus on minimizing the path lengths using hierarchical structures in large-scale WSNs. It is also necessary to couple RDT protocols with routing protocols that can take link reliability measures into account. Turgay Korkmaz, Kamil Saraç |
WiMob | 2 |
| 2009 | A SIP Security Testing FrameworkabstractSession Initiation Protocol (SIP) has emerged as the predominant protocol for setting up, maintaining, and terminating Voice over Internet Protocol (VoIP) sessions. In spite of the security mechanisms that it offers, several attacks are being made on the SIP architecture. In this paper we take a proactive approach and highlight the importance of testing SIP from a security perspective. We first give a brief introduction to some of the most common attacks on SIP. We then describe a framework to effectively test several security aspects of a SIP network and thereby help mitigate such attacks. We also present a genetic algorithm that we developed and used to generate data in our fuzz testing. Finally, we present the results of some tests performed on popular SIP devices using our framework. Hemanth Srinivasan, Kamil Saraç |
CCNC | 2 |
| 2009 | ODON: An On-Demand Security Overlay for Mission-Critical ApplicationsabstractIn this paper we consider the construction of a large-scale, highly available and secure overlay network to enable mission-critical communication between emergency personnel at a disaster area and their coordinating agencies across the Internet. This network is designed to be secure against network-based failures and external attacks including denial of service (DoS) attacks. We design several protocols for the effective operation of the network, including protocols for user access verification and the establishment of session credentials between the user and the target server. We verify these protocols theoretically for their security and evaluate the overall performance of the system with a combination of simulation and implementation. Jinu Kurian, Ajay Kulkarni, Hai Trong Vu, Kamil Saraç |
ICCCN | 4 |
| 2009 | Analyzing Router Responsiveness to Active Measurement Probes
Mehmet Hadi Gunes, Kamil Saraç |
PAM | 2 |
| 2009 | Resolving IP aliases in building traceroute-based internet maps
Mehmet Hadi Gunes, Kamil Saraç |
IEEE/ACM Trans. Netw. | 2 |
| 2009 | A Polynomial Time Solution to Minimum Forwarding Set Problem in Wireless Networks under Unit Disk Coverage ModelabstractNetwork-wide broadcast (simply broadcast) is a frequently used operation in wireless ad hoc networks (WANETs). One promising practical approach for energy-efficient broadcast is to use localized algorithms to minimize the number of nodes involved in the propagation of the broadcast messages. In this context, the minimum forwarding set problem (MFSP) (also known as multipoint relay (MPR) problem) has received a considerable attention in the research community. Even though the general form of the problem is shown to be NP-complete, the complexity of the problem has not been known under the practical application context of ad hoc networks. In this paper, we present a polynomial time algorithm to solve the MFSP for wireless network under unit disk coverage model. We prove the existence of some geometrical properties for the problem and then propose a polynomial time algorithm to build an optimal solution based on these properties. To the best of our knowledge, our algorithm is the first polynomial time solution to the MFSP under the unit disk coverage model. We believe that the work presented in this paper will have an impact on the design and development of new algorithms for several wireless network applications including energy-efficient multicast, broadcast, and topology control protocols for WANETs and sensor networks. Mehmet Baysan, Kamil Saraç, Ramaswamy Chandrasekaran, Sergey Bereg |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2008 | A security framework for service overlay networks: Access controlabstractService overlay networks (SONs) have recently been proposed to support various value-added services including multicast, resilient routing, QoS support, and DoS resistant communication in the Internet. Access control plays an important role for various SON applications yet most SON proposals do not consider access control or assume that it is a pre-existing service. The lack of a proper access control mechanism may introduce security or efficiency problems for various SON applications. In this paper, we present a scalable, distributed access control scheme with very low state information required to be maintained at the SON nodes. Using this service, a SON access node can decide if an end userpsilas traffic should be accepted into the SON overlay for processing and forwarding towards its intended destination. We present our scheme and evaluate it via a combination of formal verification, security analysis, and an experimental evaluation work on its practicality. Jinu Kurian, Kamil Saraç |
BROADNETS | 2 |
| 2008 | Resolving Anonymous Routers in Internet Topology Measurement StudiesabstractInternet measurement studies utilize traceroute to collect path traces from the Internet. A router that does not respond to a traceroute query is referred to as an anonymous router and is represented by a '*' in the traceroute output. Anonymous router resolution refers to the task of identifying the occurrences of '*'s that belong to the same router in the underlying network. This task is an important step in building traceroute-based topology maps and obtaining an optimum solution is shown to be NP-complete. In this paper, we use a novel technique from graph data mining field to build an efficient solution. The results of our experiments on both synthetic and genuine topologies show a significant improvement in accuracy and effectiveness over the existing approaches. Mehmet Hadi Gunes, Kamil Saraç |
INFOCOM | 2 |
| 2008 | WORMEROS: A New Framework for Defending against Wormhole Attacks on Wireless Ad Hoc Networks
Hai Trong Vu, Ajay Kulkarni, Kamil Saraç, Neeraj Mittal |
WASA | 3 |
| 2008 | Variable power broadcast using local information in ad hoc networks
Avinash Chiganmi, Mehmet Baysan, Kamil Saraç, Ravi Prakash 0001 |
Ad Hoc Networks | 3 |
| 2008 | A More Practical Approach for Single-Packet IP Traceback using Packet Logging and MarkingabstractTracing IP packets to their origins is an important step in defending Internet against denial-of-service attacks. Two kinds of IP traceback techniques have been proposed as packet marking and packet logging. In packet marking, routers probabilistically write their identification information into forwarded packets. This approach incurs little overhead but requires large flow of packets to collect the complete path information. In packet logging, routers record digests of the forwarded packets. This approach makes it possible to trace a single packet and is considered more powerful. At routers forwarding large volume of traffic, the high storage overhead and access time requirement for recording packet digests introduce practicality problems. In this paper, we present a novel scheme to improve the practicality of log-based IP traceback by reducing its overhead on routers. Our approach makes an intelligent use of packet marking to improve scalability of log-based IP traceback. We use mathematical analysis and simulations to evaluate our approach. Our evaluation results show that, compared to the state-of-the-art log-based approach called hash-based IP traceback, our approach maintains the ability to trace single IP packet while reducing the storage overhead by half and the access time overhead by a factor of the number of neighboring routers. Chao Gong 0006, Kamil Saraç |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2007 | Provider Provisioned Overlay Networks and Their Utility in DoS DefenseabstractThe current overlay deployment model supports minimal or no involvement by ISPs in overlay deployment and operation. This model rules out a richer set of interactions between the native and overlay layers and therefore sacrifices the potential performance gains that can be realized through such interactions. In this paper, we present a new overlay deployment model (PON) where the ISPs are actively involved in the deployment and operation of overlay networks. Because of ISP involvement, the PON model can better support some of the more difficult overlay-based applications. The PON model also establishes a solid business model which provides incentives for the deployment of PON overlays. To demonstrate the utility of the PON model we consider one of the more difficult applications, denial of service (DoS) defense, and describe a PON overlay which provides DoS defense as a value-added service. We call this overlay FONet and describe the FONet architecture and its functional overview. Finally, we evaluate the FONet architecture in a controlled laboratory environment to illustrate its effectiveness in providing the DoS resistant services proposed. Jinu Kurian, Kamil Saraç |
GLOBECOM | 2 |
| 2007 | Inferring subnets in router-level topology collection studiesabstractInternet measurement studies require availability of representative topology maps. Depending on the map resolution (e.g., autonomous system level or router level), the procedure of collecting and processing an Internet topology map involves different tasks. In this paper, we present a new task, i.e., subnet inference, to advance the current state of the art in topology collection studies. Utilizing a technique to infer the subnet relations among the routers in the resulting topology map, we identify IP addresses that are connected over the same connection medium. We believe that the successful inclusion of subnet relations among the routers will yield topology maps that are closer, at the network layer, to the sampled segments of the Internet in router level topology measurement studies. Mehmet Hadi Gunes, Kamil Saraç |
Internet Measurement Conference | 2 |
| 2007 | Impact of Alias Resolution on Traceroute -Based Sample Network Topologies
Mehmet Hadi Gunes, Nicolas Sanchis Nielsen, Kamil Saraç |
PAM | 3 |
| 2007 | A measurement study on overhead distribution of value-added internet services
Mehmet Hadi Gunes, Sevcan Bilir, Kamil Saraç, Turgay Korkmaz |
Comput. Networks | 3 |
| 2006 | Toward a More Practical Marking Scheme for IP TracebackabstractProbabilistic packet marking (PPM) has been studied as a promising approach to realize IP traceback. In this paper, we propose a new PPM approach that improves the current state of the art in two practical directions: (I) it improves the efficiency and accuracy of IP traceback and (2) it provides incentives for ISPs to deploy IP traceback in their networks. Our PPM approach employs a new IP header encoding scheme to store the whole identification information of a router into a single packet. This eliminates the computation overhead and false positives due to router identification fragmentation. Our approach does not disclose the IP addresses of the routers having marked packets, thereby alleviating the ISP's security concern of disclosing network topology. Our approach is able to control the distribution of marking information. So it is suitable to be deployed as a value-added service which may create revenue for ISPs. Therefore our PPM approach improves the performance and practicability of IP traceback. Chao Gong 0006, Kamil Saraç |
BROADNETS | 2 |
| 2006 | Variable Power Broadcasting in Ad Hoc NetworksabstractNetwork wide broadcast is a frequently used operation in ad hoc networks and consumes significant amount of energy. Reducing the overall power consumption is extremely important in increasing the longevity of ad hoc networks. As a result, developing energy efficient broadcast operations becomes an important issue in ad hoc networks. In this paper, we propose an adaptive power broadcast algorithm that uses localized information in ad hoc networks. Our algorithm uses a novel technique to improve energy efficiency in network wide broadcast. Our simulation based comparisons show the superiority of our algorithm compared to other approaches. Avinash Chiganmi, Kamil Saraç, Ravi Prakash 0001 |
ICC | 2 |
| 2006 | Analytical IP Alias ResolutionabstractIP alias resolution is an important step in generating sample Internet topologies from collected path traces. Inaccuracies in IP alias resolution may significantly affect the characteristics of the resulting sample topologies. This in turn affects the accuracy of measurement results obtained using such topologies. Existing tools for alias resolution use an active probing approach. They induce significant traffic overhead into the network and critically depend on the participation of the routers. Recent studies have reported on the limited effectiveness of these approaches [1], [2]. In this paper, we present a novel approach, called Analytical Alias Resolver (AAR), for IP alias resolution. Given a set of path traces, AAR utilizes the common IP address assignment scheme to infer IP aliases from the collected path traces. AAR does not incur traffic overhead due to active probing for alias resolution. Our experimental evaluations on a set of collected Internet path traces show that, compared to existing approaches, AAR can detect significantly more number of IP aliases. Mehmet Hadi Gunes, Kamil Saraç |
ICC | 2 |
| 2006 | Defending Network-Based Services Against Denial of Service AttacksabstractOver the last decade, several value-added services have been proposed for deployment in the Internet. IP multicast is an example of such a service. IP multicast is a stateful service in that it requires routers to maintain state for forwarding multicast data toward receivers. This characteristic makes the service and its users vulnerable to denial-of-service (DoS) attacks. One type of attack aims to saturate the available buffer space for storing state information at the routers. A successful attack can prevent end systems from properly joining multicast groups. In this paper, we present a solution to state overload attacks; evaluate the overhead of the solution through a combination of simulation and implementation; and outline an incremental deployment strategy for its partial deployment. The evaluation results indicate that our solution improves the resistance of IP multicast to state overload attacks. Jinu Kurian, Kamil Saraç, Kevin C. Almeroth |
ICCCN | 2 |
| 2006 | Cluster based approaches for end-to-end complete feedback collection in multicastabstractIn this paper we study the end-to-end complete feedback collection (ECFC) problem in large scale multi-cast applications. We consider the case where each receiver is expected to send feedback in a timely manner without causing implosion at the source site. To address the scalability problem and improve timely feedback collection, we introduce the use of clustering algorithms for feedback collection. Our simulation based comparisons show that the clustering based approaches outperform the existing pure (without clustering) multi-round probabilistic and pure (without clustering) delayed feedback collection approaches both in terms of collection delay and message overhead Mehmet Baysan, Kamil Saraç |
IPCCC | 2 |
| 2006 | Load-balanced agent activation for value-added network services
Chao Gong 0006, Kamil Saraç, Ovidiu Daescu, Balaji Raghavachari, Raja Jothi |
Comput. Commun. | 2 |
| 2006 | Practical utilities for monitoring multicast service availability
Pavan Namburi, Kamil Saraç, Kevin C. Almeroth |
Comput. Commun. | 2 |
| 2005 | Single packet IP traceback in AS-level partial deployment scenarioabstractTracing IP packets to their sources, known as IP traceback, is an important task in defending against IP spoofing and DoS attacks. Log-based IP traceback technique is to log packets at routers in the network and then determine the network paths which packets traversed using data extraction techniques. The biggest advantage of log-based IP traceback is the potential to trace a single packet. Tracing a single packet in the Internet using log-based IP traceback involves cooperation among all autonomous systems (AS) traversed by the packet. The single packet traceback process may not reach the packet origin if some AS on the forwarding path does not support IP traceback. IP traceback mechanisms are deployed within each AS independently. It is not reasonable to assume all ASes begin to support the same IP traceback mechanism in a short period of time. In this paper, we study the effectiveness of log-based IP traceback in tracing a single packet under the environment where not every AS supports log-based IP traceback. We propose a scheme to conduct the single packet traceback process in AS-level partial deployment scenario. We evaluate the performance of single packet IP traceback in AS-level partial deployment scenario based on our scheme through simulation. Chao Gong 0006, Trinh Le, Turgay Korkmaz, Kamil Saraç |
GLOBECOM | 4 |
| 2005 | IP traceback based on packet marking and loggingabstractTwo main kinds of IP traceback techniques have been proposed in two dimensions: packet marking and packet logging. IP traceback based on packet marking is often referred to as probabilistic packet marking (PPM) approach where packets are probabilistically marked with partial path information as they are forwarded by routers. This approach incurs little overhead at routers. But due to its probabilistic nature, it can only determine the source of the traffic composed of a number of packets. IP traceback based on packet logging is often referred to as hash-based approach where routers compute and store digest for each forwarded packet. This approach can trace an individual packet to its source. However, the storage space requirement for packet digests and the access time requirement for recording packets commensurate with their arriving rate are prohibitive at routers with high speed links. We propose an IP traceback approach based on both packet marking and packet logging. Compared with the PPM approach, our approach is able to track individual packets. Compared with the hash-based approach, our approach incurs less storage overhead and less access time overhead at routers. Specifically, the storage overhead is reduced to roughly one half, and the access time requirement is decreased by a factor of the number of neighbor routers. Chao Gong 0006, Kamil Saraç |
ICC | 2 |
| 2005 | Intersection Characteristics of End-to-End Internet Paths and TreesabstractThis paper focuses on understanding the scale and the distribution of "state overhead'' (briefly load) that is incurred on the routers by various value-added network services, e.g., IP multicast and IP traceback. This understanding is essential to developing appropriate mechanisms and provisioning resources so that the Internet can support such value-added services in an efficient and scalable manner. We mainly consider the number of end-to-end paths or trees intersecting at a router to represent the amount of state overhead at that router. Hence, we analyze the router-level intersection characteristics of end-to-end Internet paths or trees to approximate the state overhead distribution in the Internet. For the reliability of our analysis, a representative, end-to-end router-level Internet map is essential. Although several maps are available, they are at best insufficient for our analysis. Therefore, in the first part of our work, we exert a measurement study to obtain a large size end-to-end router-level map conforming to our constraints. In the second part, we conduct various experiments using our map and shed some light on the scale and distribution of state overhead of value-added Internet services in both unicast and multicast environments. Sevcan Bilir, Kamil Saraç, Turgay Korkmaz |
ICNP | 2 |
| 2005 | Facilitating robust multicast group managementabstractMulticast is a key service for many audio and video applications, yet it continues to be a challenging Internet service to deploy. While much attention has been given to a number of problems associated with multicast, two closely related problems in particular have received almost no attention. First, there is essentially no host support for dealing with the variety of ways to join a multicast group, and second, there is a complete absence of group join success or failure feedback from the network. The lack of a straightforward way to robustly join a multicast group and then to know whether the join has been successful is possibly the biggest limitation for multicast application developers today. In this study we develop a robust solution to determine the existence and nature of multicast service in the network. We consider two options: (1) the use of existing protocol features to extract the required information, and (2) the introduction of new protocol extensions to directly query the network. Our results indicate that while a truly robust group join is possible only when there is network support, these additional changes are difficult to deploy. Our evaluation implements a proof-of-concept prototype to determine the existence and nature of the multicast service in the network. Avijit Sen Mazumder, Kevin C. Almeroth, Kamil Saraç |
NOSSDAV | 3 |
| 2005 | Application layer reachability monitoring for IP multicast
Kamil Saraç, Kevin C. Almeroth |
Comput. Networks | 1 |
| 2004 | Improving Energy Savings in Power Adaptive Broadcasting in MANETsabstractNetwork wide broadcast is a frequently used operation in mobile ad hoc networks (MANETs). Many unicast protocols including dynamic source routing (DSR) and ad hoc on-demand distance vector (AODV) protocol use broadcast to discover the unicast routes toward destinations. In addition, depending on the application, broadcast can be used to deliver actual data packets to all the nodes in the network. Nodes in MANETs work with limited battery power and the efficient utilization of this power is important for increasing the lifetime of the individual nodes as well as the overall network. As a result, it is important to utilize energy efficient algorithms in achieving network wide broadcast in MANETs. In this poster paper, the authors improve the energy efficiency in power adaptive broadcast using local information. In this proposal, the authors introduce an improved algorithm for deciding the transmission power level. The paper also attempts to further increase the energy savings by reducing the redundant transmission by including an efficient forward node set at the selection algorithm. Mehmet Baysan, Saipriya Gowdamachandran, Kamil Saraç |
BROADNETS | 3 |
| 2004 | Multicast session announcements on top of SSMabstractBefore having a multicast event, information about the event needs to be announced to prospective participants. In the current multicast service model, called any source multicast (ASM), it is achieved by exchanging this information on a well-known multicast group address. Researchers have developed SSM, as an alternative multicast model in response to problems with ASM. And therefore, the expectation is that SSM will soon replace ASM in the interdomain scale. Session announcements is inherently a many-to-many application. Support for this application on top of SSM is not a straight forward task. But, success of large scale multicast content distribution partly depends on the existence of a successful session announcements mechanism. In this paper we propose a mechanism to support multicast session announcements application on top of SSM. Pavan Namburi, Kamil Saraç |
ICC | 2 |
| 2004 | Tracetree: a scalable mechanism to discover multicast tree topologies in the internetabstractThe successful deployment of multicast in the Internet requires the availability of good network management solutions. Discovering multicast tree topologies is an important component of this task. Network managers can use topology information to monitor and debug potential multicast forwarding problems. In addition, the collected topology has several other uses, for example, in reliable multicast transport protocols, in multicast congestion control protocols, and in discovering network characteristics. We present a mechanism for discovering multicast tree topologies using the forwarding state in the network. We call our approach tracetree. First, we present the basic operation of tracetree. Then, we explore various issues related to its functionality (e.g., scalability, security, etc.). Next, we provide a detailed evaluation by comparing it to the currently available alternatives. Finally, we discuss a number of deployment issues. We believe that tracetree provides an efficient and scalable mechanism for discovering multicast tree topologies and therefore fills an important void in the area of multicast network management. Kamil Saraç, Kevin C. Almeroth |
IEEE/ACM Trans. Netw. | 1 |
| 2003 | SSM extensions: network layer support for multiple senders in SSMabstractSource specific multicast (SSM) provides native support for single sender multicast applications. Current proposals for supporting multiple sender applications on top of SSM includes using multiple SSM channels or using an application layer relay mechanism on top of SSM. These approaches have potential scalability or single point of failure problems, respectively. In this paper, we propose network layer extensions to SSM. Our extensions provide a convenient mechanism for SSM group owners to include additional senders in their multicast applications. We present our SSM extensions model and provide a detailed discussion on the protocol operation under various scenarios. We also examine the protocol performance by comparing it to alternative approaches on several performance metrics. With SSM Extensions, we introduce a small number of changes into the existing infrastructure and in return, provide an effective and efficient mechanism to support multiple-sender applications on top of SSM. Kamil Saraç, Pavan Namburi, Kevin C. Almeroth |
ICCCN | 1 |
| 2001 | Scalable techniques for discovering multicast tree topologyabstractThe IP multicast infrastructure has transitioned to a topology that now supports hierarchical routing. Multicast network monitoring and management have become key requirements necessary for providing robust multicast operation. Monitoring services help to identify potential problems such as protocol shortcomings, implementation bugs or configuration errors. This type of monnitoring often requires knowing the multicast tree topology. In this paper, we present a new approach, called tracetree, to discover tree topology in the source-to-receiver(s) direction using network forwarding state. We start with an overview of the problem. Then, we describe tracetree functionality including its request forwarding and response collection mechanisms. Next, we discuss a number of functional issues related to tracetree. Finally, we evaluate our technique by comparing it to a number of alternative approaches. We believe that our technique provides a scalable way of discovering a multicast tree's topology in realtime while requiring only marginal additional router functionality. Kamil Saraç, Kevin C. Almeroth |
NOSSDAV | 1 |
| 2000 | Monitoring Reachability in the Global Multicast InfrastructureabstractThe multicast infrastructure has transitioned to a topology that now supports hierarchical routing. Instead of a flat virtual topology originally called the Multicast Backbone (MBone) there now exists a hierarchy where routing information is exchanged between autonomous systems (ASes). In today's multicast infrastructure reachability problems are common. Unlike in the MBone, the possibility of limited connectivity between domains is now possible. We present a system called sdr-monitor. This tool collects session directory information from numerous places around the world and presents an application layer view of reachability. Using data collected over the last year, we present an analysis of long term reachability characteristics for the global multicast infrastructure. Our findings are that overall reachability is generally quite poor. However, having identified some of the reasons, we believe there is not a fundamental infrastructure problem, but rather protocol bugs and a lack of management tools. Kamil Saraç, Kevin C. Almeroth |
ICNP | 1 |
| 1998 | Iterated DFT Based Techniques for Join Size EstimationabstractNovel techniques based on the Discrete Fourier Transform are proposed to estimate the size of relations resulting from join operations. For the special case of self join the proposed algorithm gives the exact join size using logarithmic space. A generalization to compute the join of arbitrary relations is then used to develop two tree-based techniques that provide a spectrum of algorithms which interpolate storage requirements versus accuracy of the estimation obtained. Finally, we present experimental results to exhibit the effectiveness of our approach. 1 Kamil Saraç, Ömer Egecioglu, Amr El Abbadi |
CIKM | 1 |