Stefan Saroiu

dblp:17/3782 · DBLP profile ↗
← Back
43ranked-venue papers
4as first author
7since 2021 · last 2026
0009-0007-1318-1719ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 23 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 8 · 2 first-author · 4 since 2021Systems, architecture and hardware · 6 · 1 first-author · 2 since 2021Security and privacy · 4 · 1 since 2021Human-computer interaction and ubiquitous computing · 4Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
YearPublicationVenuePosition
2026 From Lab to Fleet: Building and Deploying a Practical Rowhammer Defense in Cloud SoCs
Stefan Saroiu, Sujay Yadalam, Alec Wolman, Will Remaklus, Daniel S. Berger, Isaac H. Luna, Ishwar Agarwal, Jacob R. Lorch
ISCA1
2023 Accelerating Open RAN Research Through an Enterprise-scale 5G Testbed
abstract
Open RAN is an emerging paradigm in mobile networks where the Radio Access Network (RAN) functions are disaggregated and virtualized on commodity servers. Despite the importance of Open RAN research, existing platforms often lack the fidelity and stability required to address a wide range of research problems. In response to this limitation, we have developed an enterprise-scale Open RAN testbed aimed at conducting state-of-the-art research in key areas that have received limited attention due to the lack of suitable platforms. In this poster, we provide an overview of the testbed we have created and examples of the research it has enabled, with the hope of catalyzing future open RAN research and innovation.
Paramvir Bahl, Matthew Balkwill, Xenofon Foukas, Anuj Kalia, Daehyeok Kim, Manikanta Kotaru, Zhihua Lai, Sanjeev Mehrotra, Bozidar Radunovic, Stefan Saroiu, Connor Settle, Alec Wolman, Francis Y. Yan, Yongguang Zhang
MobiCom10
2023 Siloz: Leveraging DRAM Isolation Domains to Prevent Inter-VM Rowhammer
abstract
Today's cloud DRAM lacks strong isolation primitives, highlighted by Rowhammer bit flips. Rowhammer poses an increasing threat to cloud security/reliability, given (1) DRAM activation rates in commodity and malicious workloads already exceed Rowhammer thresholds, and (2) thresholds are decreasing in newer DRAM. Deployed hardware mitigations remain vulnerable, turning cloud providers toward software defenses. However, existing defenses incur high performance or memory overhead or contain significant protection gaps.
Kevin Loughlin, Jonah Rosenblum, Stefan Saroiu, Alec Wolman, Dimitrios Skarlatos 0002, Baris Kasikci
SOSP3
2023 "My face, my rules": Enabling Personalized Protection Against Unacceptable Face Editing
abstract
Today, face editing is widely used to refine/alter photos in both professional and recreational settings. Yet it is also used to modify (and repost) existing online photos for cyberbullying. Our work considers an important open question: 'How can we support the collaborative use of face editing on social platforms while protecting against unacceptable edits and reposts by others?' This is challenging because, as our user study shows, users vary widely in their definition of what edits are (un)acceptable. Any global filter policy deployed by social platforms is unlikely to address the needs of all users, but hinders social interactions enabled by photo editing. Instead, we argue that face edit protection policies should be implemented by social platforms based on individual user preferences. When posting an original photo online, a user can choose to specify the types of face edits (dis)allowed on the photo. Social platforms use these per-photo edit policies to moderate future photo uploads, i.e., edited photos containing modifications that violate the original photo's policy are either blocked or shelved for user approval. Realizing this personalized protection, however, faces two immediate challenges: (1) how to accurately recognize specific modifications, if any, contained in a photo; and (2) how to associate an edited photo with its original photo (and thus the edit policy). We show that these challenges can be addressed by combining highly efficient hashing based image search and scalable semantic image comparison, and build a prototype protector (Alethia) covering nine edit types. Evaluations using IRB-approved user studies and data-driven experiments (on 839K face photos) show that Alethia accurately recognizes edited photos that violate user policies and induces a feeling of protection to study participants. This demonstrates the initial feasibility of personalized face edit protection. We also discuss current limitations and future directions to push the concept forward.
Zhujun Xiao, Jenna Cryan, Yuanshun Yao, Yi Hong Gordon Cheo, Yuanchao Shu, Stefan Saroiu, Ben Y. Zhao, Haitao Zheng 0001
Proc. Priv. Enhancing Technol.6
2022 MOESI-prime: preventing coherence-induced hammering in commodity workloads
abstract
Prior work shows that Rowhammer attacks---which flip bits in DRAM via frequent activations of the same row(s)---are viable. Adversaries typically mount these attacks via instruction sequences that are carefully-crafted to bypass CPU caches. However, we discover a novel form of hammering that we refer to as coherence-induced hammering, caused by Intel's implementations of cache coherent non-uniform memory access (ccNUMA) protocols. We show that this hammering occurs in commodity benchmarks on a major cloud provider's production hardware, the first hammering found to be generated by non-malicious code. Given DRAM's rising susceptibility to bit flips, it is paramount to prevent coherence-induced hammering to ensure reliability and security in the cloud.
Kevin Loughlin, Stefan Saroiu, Alec Wolman, Yatin A. Manerkar, Baris Kasikci
ISCA2
2021 Stop! Hammer time: rethinking our approach to rowhammer mitigations
abstract
Rowhammer attacks exploit electromagnetic interference among nearby DRAM cells to flip bits, corrupting data and altering system behavior. Unfortunately, DRAM vendors have opted for a blackbox approach to preventing these bit flips, exposing little information about in-DRAM mitigations. Despite vendor claims that their mitigations prevent Rowhammer, recent work bypasses these defenses to corrupt data. Further work shows that the Rowhammer problem is actually worsening in emerging DRAM and posits that system-level support is needed to produce adaptable and scalable defenses.
Kevin Loughlin, Stefan Saroiu, Alec Wolman, Baris Kasikci
HotOS2
2021 MegaMind: a platform for security & privacy extensions for voice assistants
abstract
Voice assistants raise serious security and privacy concerns because they use always-on microphones in sensitive locations (e.g., inside a home) and send audio recordings to the cloud for processing. The cloud transcribes these recordings and interprets them as user requests, and sometimes even shares these requests with third-party services. These steps may result in unintended or malicious voice data leaks and in unauthorized actions, such as a purchase. This paper presents MegaMind, a novel extensible platform that lets a user deploy security and privacy extensions locally on their voice assistant. MegaMind's extensions interpose on requests before sending them to the cloud and on responses before delivering them to the user. MegaMind's programming model enables writing powerful extensions with ease, such as one for secure conversations. Additionally, MegaMind protects against malicious extensions by providing two important guarantees, namely permission enforcement and non-interference. We implement MegaMind and integrate it with Amazon Alexa Service SDK. Our evaluation shows that MegaMind achieves a small conversation latency on platforms with adequate compute power, such as a Raspberry Pi 4 and an x86-based laptop.
Seyed Mohammadjavad Seyed Talebi, Ardalan Amiri Sani, Stefan Saroiu, Alec Wolman
MobiSys3
2020 PrivateEye: Scalable and Privacy-Preserving Compromise Detection in the Cloud
Behnaz Arzani, Selim Ciraci, Stefan Saroiu, Alec Wolman, Jack W. Stokes, Geoff Outhred, Lechao Diwu
NSDI3
2020 Are We Susceptible to Rowhammer? An End-to-End Methodology for Cloud Providers
abstract
Cloud providers are concerned that Rowhammer poses a potentially critical threat to their servers, yet today they lack a systematic way to test whether the DRAM used in their servers is vulnerable to Rowhammer attacks. This paper presents an endto-end methodology to determine if cloud servers are susceptible to these attacks. With our methodology, a cloud provider can construct worst-case testing conditions for DRAM.We apply our methodology to three classes of servers from a major cloud provider. Our findings show that none of the CPU instruction sequences used in prior work to mount Rowhammer attacks create worst-case DRAM testing conditions. To address this limitation, we develop an instruction sequence that leverages microarchitectural side-effects to "hammer" DRAM at a near-optimal rate on modern Intel Skylake and Cascade Lake platforms. We also design a DDR4 fault injector that can reverse engineer row adjacency for any DDR4 DIMM. When applied to our cloud provider's DIMMs, we find that DRAM rows do not always follow a linear map.
Lucian Cojocar, Jeremie S. Kim, Minesh Patel, Lillian Tsai, Stefan Saroiu, Alec Wolman, Onur Mutlu
SP5
2019 enClosure: Group Communication via Encounter Closures
abstract
New applications enabled by personal smart devices and the Internet-of-Things (IoT) require communication in the context of periods of spatial co-location. Examples of this encounter-based communication (EbC) include social exchange among individuals who shared an experience, and interaction among personal and IoT devices that provide location-based services. Existing EbC systems are limited to communication among participants that share a direct encounter. This paper is inspired by two insights: (1) encounters also enable group communication among devices connected by paths in the encounter graph that is contextual, spontaneous, secure, and does not require users to reveal identifying or linkable information; and (2) addressing communication partners using encounter closures subject to causal, spatial, and temporal constraints enables powerful new forms of group communication. We present the design of enClosure, a service providing group communication based on encounter closures for mobile and IoT applications, and a prototype implementation for Android and the Microsoft Embedded Social Cloud platform. Using real-world traces, we show that enClosure provides a privacy-preserving, secure platform for a wide range of group communication applications ranging from connecting attendees of a large event and virtual guest books to disseminating health risk warnings, lost-and-found, and tracing missing persons.
Lillian Tsai, Roberta De Viti, Matthew Lentz, Stefan Saroiu, Bobby Bhattacharjee, Peter Druschel
MobiSys4
2019 enClosure: Group Communication via Encounter Closures
abstract
New applications enabled by personal smart devices and the Internet-of-Things (IoT) require communication in the context of an encounter (a period of spatial co-location). However, existing encounter-based communication (EbC) systems are limited to communication among participants that share a direct encounter. This work is inspired by two insights: (1) encounters also enable group communication among devices connected by paths in the encounter graph that is contextual, spontaneous, secure, and privacy-preserving; and (2) addressing communication partners using encounter closures subject to causal, spatial, and temporal constraints enables powerful new forms of group communication. We present the design of enClosure, a service providing group communication based on encounter closures for mobile and IoT applications, and a prototype implementation for Android and the Microsoft Embedded Social Cloud platform. Using real-world traces, we show that enClosure provides a privacy-preserving, secure platform for a wide range of group communication applications ranging from connecting attendees of a large event to disseminating health risk warnings and tracing missing persons.
Lillian Tsai, Roberta De Viti, Matthew Lentz, Stefan Saroiu, Bobby Bhattacharjee, Peter Druschel
MobiSys4
2016 fTPM: A Software-Only Implementation of a TPM Chip
Himanshu Raj, Stefan Saroiu, Alec Wolman, Ronald Aigner, Jeremiah Cox, Paul England, Chris Fenner, Kinshuman Kinshumann, Jork Löser, Dennis Mattoon, Magnus Nyström, Rob Spiger, Stefan Thom, David Wooten
USENIX Security Symposium2
2015 Protecting Data on Smartphones and Tablets from Memory Attacks
abstract
Smartphones and tablets are easily lost or stolen. This makes them susceptible to an inexpensive class of memory attacks, such as cold-boot attacks, using a bus monitor to observe the memory bus, and DMA attacks. This paper describes Sentry, a system that allows applications and OS components to store their code and data on the System-on-Chip (SoC) rather than in DRAM. We use ARM-specific mechanisms originally designed for embedded systems, but still present in today's mobile devices, to protect applications and OS subsystems from memory attacks.
Patrick Colp, James Gleeson 0001, Sahil Suneja, Eyal de Lara, Himanshu Raj, Stefan Saroiu, Alec Wolman
ASPLOS7
2015 Kahawai: High-Quality Mobile Gaming Using GPU Offload
abstract
This paper presents Kahawai1, a system that provides high-quality gaming on mobile devices, such as tablets and smartphones, by offloading a portion of the GPU computation to server-side infrastructure. In contrast with previous thin-client approaches that require a server-side GPU to render the entire content, Kahawai uses collaborative rendering to combine the output of a mobile GPU and a server-side GPU into the displayed output. Compared to a thin client, collaborative rendering requires significantly less network bandwidth between the mobile device and the server to achieve the same visual quality and, unlike a thin client, collaborative rendering supports disconnected operation, allowing a user to play offline - albeit with reduced visual quality.
Eduardo Cuervo Laffaye, Alec Wolman, Landon P. Cox, Kiron Lebeck, Ali Razeen, Stefan Saroiu, Madan Musuvathi
MobiSys6
2014 Using ARM trustzone to build a trusted language runtime for mobile applications
abstract
This paper presents the design, implementation, and evaluation of the Trusted Language Runtime (TLR), a system that protects the confidentiality and integrity of .NET mobile applications from OS security breaches. TLR enables separating an application's security-sensitive logic from the rest of the application, and isolates it from the OS and other apps. TLR provides runtime support for the secure component based on a .NET implementation for embedded devices. TLR reduces the TCB of an open source .NET implementation by a factor of $78$ with a tolerable performance cost. The main benefit of the TLR is to bring the developer benefits of managed code to trusted computing. With the TLR, developers can build their trusted components with the productivity benefits of modern high level languages, such as strong typing and garbage collection.
Nuno Santos 0001, Himanshu Raj, Stefan Saroiu, Alec Wolman
ASPLOS3
2014 Zero-effort payments: design, deployment, and lessons
abstract
This paper presents Zero-Effort Payments (ZEP), a seamless mobile computing system designed to accept payments with no effort on the customer's part beyond a one-time opt-in. With ZEP, customers need not present cards nor operate smartphones to convey their identities. ZEP uses three complementary identification technologies: face recognition, proximate device detection, and human assistance. We demonstrate that the combination of these technologies enables ZEP to scale to the level needed by our deployments.
Christopher Smowton, Jacob R. Lorch, David Molnar, Stefan Saroiu, Alec Wolman
UbiComp4
2014 Demo: Kahawai: high-quality mobile gaming using GPU offload
abstract
No abstract available.
Eduardo Cuervo Laffaye, Alec Wolman, Landon P. Cox, Stefan Saroiu, Madan Musuvathi, Ali Razeen
MobiSys4
2014 cTPM: A Cloud TPM for Cross-Device Trusted Applications
Chen Chen 0013, Himanshu Raj, Stefan Saroiu, Alec Wolman
NSDI3
2012 Delusional boot: securing hypervisors without massive re-engineering
abstract
The set of virtual devices offered by a hypervisor to its guest VMs is a virtualization component ripe with security exploits -- more than half of all vulnerabilities of today's hypervisors are found in this codebase. This paper presents Min-V, a hypervisor that disables all virtual devices not critical to running VMs in the cloud. Of the remaining devices, Min-V takes a step further and eliminates all remaining functionality not needed for the cloud.
Himanshu Raj, Shravan K. Rayanchu, Stefan Saroiu, Alec Wolman
EuroSys4
2012 Software abstractions for trusted sensors
abstract
With the proliferation of e-commerce, e-wallet, and e-health smartphone applications, the need for trusted mobile applications is greater than ever. Unlike their desktop counterparts, many mobile applications rely heavily on sensor inputs. As a result, trust often requires authenticity and integrity of sensor readings. For example, applications may need trusted readings from sensors such as a GPS, camera, or microphone. Recent research has started to recognize the need for "trusted sensors", yet providing the right programming abstractions and system support for building mobile trusted applications is an open problem.
Stefan Saroiu, Alec Wolman, Himanshu Raj
MobiSys2
2012 An Operating System for the Home
Colin Dixon, Ratul Mahajan, Sharad Agarwal, A. J. Bernheim Brush, Bongshin Lee, Stefan Saroiu, Paramvir Bahl
NSDI6
2012 Policy-Sealed Data: A New Abstraction for Building Trusted Cloud Services
Nuno Santos 0001, Rodrigo Rodrigues 0001, Krishna P. Gummadi, Stefan Saroiu
USENIX Security Symposium4
2011 Home automation in the wild: challenges and opportunities
abstract
Visions of smart homes have long caught the attention of researchers and considerable effort has been put toward enabling home automation. However, these technologies have not been widely adopted despite being available for over three decades. To gain insight into this state of affairs, we conducted semi-structured home visits to 14 households with home automation. The long term experience, both positive and negative, of the households we interviewed illustrates four barriers that need to be addressed before home automation becomes amenable to broader adoption. These barriers are high cost of ownership, inflexibility, poor manageability, and difficulty achieving security. Our findings also provide several directions for further research, which include eliminating the need for structural changes for installing home automation, providing users with simple security primitives that they can confidently configure, and enabling composition of home devices.
A. J. Bernheim Brush, Bongshin Lee, Ratul Mahajan, Sharad Agarwal, Stefan Saroiu, Colin Dixon
CHI5
2010 The home needs an operating system (and an app store)
abstract
We argue that heterogeneity is hindering technological innovation in the home---homes differ in terms of their devices and how those devices are connected and used. To abstract these differences, we propose to develop a home-wide operating system. A HomeOS can simplify application development and let users easily add functionality by installing new devices or applications. The development of such an OS is an inherently inter-disciplinary exercise. Not only must the abstractions meet the usual goals of being efficient and easy to program, but the underlying primitives must also match how users want to manage and secure their home. We describe the preliminary design of HomeOS and our experience with developing applications for it.
Colin Dixon, Ratul Mahajan, Sharad Agarwal, A. J. Bernheim Brush, Bongshin Lee, Stefan Saroiu, Paramvir Bahl
HotNets6
2010 MAUI: making smartphones last longer with code offload
abstract
This paper presents MAUI, a system that enables fine-grained energy-aware offload of mobile code to the infrastructure. Previous approaches to these problems either relied heavily on programmer support to partition an application, or they were coarse-grained requiring full process (or full VM) migration. MAUI uses the benefits of a managed code environment to offer the best of both worlds: it supports fine-grained code offload to maximize energy savings with minimal burden on the programmer. MAUI decides at run-time which methods should be remotely executed, driven by an optimization engine that achieves the best energy savings possible under the mobile device's current connectivity constrains. In our evaluation, we show that MAUI enables: 1) a resource-intensive face recognition application that consumes an order of magnitude less energy, 2) a latency-sensitive arcade game application that doubles its refresh rate, and 3) a voice-based language translation application that bypasses the limitations of the smartphone environment by executing unsupported components remotely.
Eduardo Cuervo Laffaye, Aruna Balasubramanian, Dae-ki Cho, Alec Wolman, Stefan Saroiu, Ranveer Chandra, Paramvir Bahl
MobiSys5
2010 Volley: Automated Data Placement for Geo-Distributed Cloud Services
Sharad Agarwal, John Dunagan, Navendu Jain, Stefan Saroiu, Alec Wolman
NSDI4
2010 Glasnost: Enabling End Users to Detect Traffic Differentiation
Marcel Dischinger, Massimiliano Marcon, Saikat Guha 0002, Krishna P. Gummadi, Ratul Mahajan, Stefan Saroiu
NSDI6
2009 Lockr: better privacy for social networks
abstract
Today's online social networking (OSN) sites do little to protect the privacy of their users' social networking information. Given the highly sensitive nature of the information these sites store, it is understandable that many users feel victimized and disempowered by OSN providers' terms of service. This paper presents Lockr, a system that improves the privacy of centralized and decentralized online content sharing systems. Lockr offers three significant privacy benefits to OSN users. First, it separates social networking content from all other functionality that OSNs provide. This decoupling lets users control their own social information: they can decide which OSN provider should store it, which third parties should have access to it, or they can even choose to manage it themselves. Such flexibility better accommodates OSN users' privacy needs and preferences. Second, Lockr ensures that digitally signed social relationships needed to access social data cannot be re-used by the OSN for unintended purposes. This feature drastically reduces the value to others of social content that users entrust to OSN providers. Finally, Lockr enables message encryption using a social relationship key. This key lets two strangers with a common friend verify their relationship without exposing it to others, a common privacy threat when sharing data in a decentralized scenario.
Amin Tootoonchian, Stefan Saroiu, Yashar Ganjali, Alec Wolman
CoNEXT2
2009 BlueMonarch: a system for evaluating bluetooth applications in the wild
abstract
Despite Bluetooth's popularity, low cost, and low power requirements, Bluetooth applications remain remarkably unsophisticated. Although the research community and industry have designed games, cell-phone backup, and contextual advertising systems with Bluetooth, few such applications have been prototyped or evaluated on a large scale. Evaluating Bluetooth applications requires recruiting devices in the wild and developing robust software that can adapt to the heterogeneity of these devices. These requirements have limited both the number and the magnitude of the experiments with Bluetooth applications.This paper proposes BlueMonarch, a systemfor evaluating Bluetooth applications in the wild. BlueMonarch emulates a Bluetooth transfer to any device responding to Bluetooth Service Discovery requests; because many cell-phones, laptops, and PDAs in the wild respond to such probes, BlueMonarch enables quick prototyping of Bluetooth applications in the wild, to hundreds of unmodified Bluetooth devices. After we present the feasibility and accuracy of BlueMonarch, we use BlueMonarch to evaluate a content delivery system for Bluetooth. With BlueMonarch, we evaluated our system inside a mall and a subway system; we were able to send tens of megabytes of data to hundreds of Bluetooth devices in just a little over an hour.
Timothy J. Smith, Stefan Saroiu, Alec Wolman
MobiSys2
2009 Bunker: A Privacy-Oriented Platform for Network Tracing
Andrew G. Miklas, Stefan Saroiu, Alec Wolman, Angela Demke Brown
NSDI2
2008 Itrustpage: a user-assisted anti-phishing tool
abstract
Despite the many solutions proposed by industry and the research community to address phishing attacks, this problem continues to cause enormous damage. Because of our inability to deter phishing attacks, the research community needs to develop new approaches to anti-phishing solutions. Most of today's anti-phishing technologies focus on automatically detecting and preventing phishing attacks. While automation makes anti-phishing tools user-friendly, automation also makes them suffer from false positives, false negatives, and various practical hurdles. As a result, attackers often find simple ways to escape automatic detection.
Troy Ronda, Stefan Saroiu, Alec Wolman
EuroSys2
2008 CILoS: a CDMA indoor localization system
abstract
CILoS is an indoor localization system based on CDMA mobile phone signal fingerprinting. CDMA networks vary their transmission power to accommodate fluctuations in network load. This affects signal intensity and therefore limits the practicality of traditional fingerprinting approaches based on receiver signal strength (RSSI) measurements. Instead, CILoS uses fingerprints of signal delay that are robust to cell resizing. We demonstrate that CILoS achieves a median accuracy of 5 meters, and compares favourably to RSSI fingerprinting systems. We highlight the significance of wide fingerprints, constructed through scanning multiple channels, for achieving high localization accuracy. We also show that our system can accurately differentiate between floors of a multifloor building.
Waqas ur Rehman, Eyal de Lara, Stefan Saroiu
UbiComp3
2008 Satellitelab: adding heterogeneity to planetary-scale network testbeds
abstract
Planetary-scale network testbeds like PlanetLab and RON have become indispensable for evaluating prototypes of distributed systems under realistic Internet conditions. However, current testbeds lack the heterogeneity that characterizes the commercial Internet. For example, most testbed nodes are connected to well-provisioned research networks, whereas most Internet nodes are in edge networks.
Marcel Dischinger, Andreas Haeberlen, Ivan Beschastnikh, Krishna P. Gummadi, Stefan Saroiu
SIGCOMM5
2007 Tamper Resistant Network Tracing
Andrew G. Miklas, Stefan Saroiu, Alec Wolman, Angela Demke Brown
HotNets2
2007 Exploiting Social Interactions in Mobile Systems
Andrew G. Miklas, Kiran K. Gollu, Kelvin K. W. Chan, Stefan Saroiu, Krishna P. Gummadi, Eyal de Lara
UbiComp4
2007 Characterizing residential broadband networks
abstract
A large and rapidly growing proportion of users connect to the Internet via residential broadband networks such as Digital Subscriber Lines (DSL) and cable. Residential networks are often the bottleneck in the last mile of today's Internet. Their characteristics critically affect Internet applications, including voice-over-IP, online games, and peer-to-peer content sharing/delivery systems. However, to date, few studies have investigated commercial broadband deployments, and rigorous measurement data that characterize these networks at scale are lacking. In this paper, we present the first large-scale measurement study of major cable and DSL providers in North America and Europe. We describe and evaluate the measurement tools we developed for this purpose. Our study characterizes several properties of broadband networks, including link capacities, packet round-trip times and jitter, packet loss rates, queue lengths, and queue drop policies. Our analysis reveals important ways in which residential networks differ from how the Internet is conventionally thought to operate. We also discuss the implications of our findings for many emerging protocols and systems, including delay-based congestion control (e.g., PCP) and network coordinate systems (e.g., Vivaldi).
Marcel Dischinger, Andreas Haeberlen, Krishna P. Gummadi, Stefan Saroiu
Internet Measurement Conference4
2006 Monarch: a tool to emulate transport protocol flowsover the internet at large
abstract
This paper proposes Monarch, a novel tool that accurately emulates transport protocol flows from an end host controlled by its user to any other Internet host that responds to simple TCP, UDP, or ICMP packet probes. Since many Internet hosts and routers respond to such probes, Monarch can evaluate transport protocols, such as TCP Reno, TCP Vegas, and TCP Nice, over a large and diverse set of Internet paths. Current approaches to evaluating these protocols need control over both end hosts of an Internet path. Consequently, they are limited to a small number of paths between nodes in testbeds like PlanetLab, RON or NIMI. Monarch's ability to evaluate transport protocols with minimal support from the destination host enables many new measurement studies. We show the feasibility of using Monarch for three example studies: (a) understanding transport protocol behavior over network paths that are less explored by the research community, such as paths to cable and DSL hosts, (b) investigating the relative performance of different transport protocol designs, such as TCP Vegas and TCP Reno, and (c) testing protocol implementations under a wide range of experimental conditions.
Andreas Haeberlen, Marcel Dischinger, Krishna P. Gummadi, Stefan Saroiu
Internet Measurement Conference4
2004 Measurement and Analysis of Spyware in a University Environment
Stefan Saroiu, Steve D. Gribble, Henry M. Levy
NSDI1
2003 Measurement, modeling, and analysis of a peer-to-peer file-sharing workload
abstract
Peer-to-peer (P2P) file sharing accounts for an astonishing volume of current Internet traffic. This paper probes deeply into modern P2P file sharing systems and the forces that drive them. By doing so, we seek to increase our understanding of P2P file sharing workloads and their implications for future multimedia workloads. Our research uses a three-tiered approach. First, we analyze a 200-day trace of over 20 terabytes of Kazaa P2P traffic collected at the University of Washington. Second, we develop a model of multimedia workloads that lets us isolate, vary, and explore the impact of key system parameters. Our model, which we parameterize with statistics from our trace, lets us confirm various hypotheses about file-sharing behavior observed in the trace. Third, we explore the potential impact of locality-awareness in Kazaa.Our results reveal dramatic differences between P2P file sharing and Web traffic. For example, we show how the immutability of Kazaa's multimedia objects leads clients to fetch objects at most once; in contrast, a World-Wide Web client may fetch a popular page (e.g., CNN or Google) thousands of times. Moreover, we demonstrate that: (1) this "fetch-at-most-once" behavior causes the Kazaa popularity distribution to deviate substantially from Zipf curves we see for the Web, and (2) this deviation has significant implications for the performance of multimedia file-sharing systems. Unlike the Web, whose workload is driven by document change, we demonstrate that clients' fetch-at-most-once behavior, the creation of new objects, and the addition of new clients to the system are the primary forces that drive multimedia workloads such as Kazaa. We also show that there is substantial untapped locality in the Kazaa workload. Finally, we quantify the potential bandwidth savings that locality-aware P2P file-sharing architectures would achieve.
Krishna P. Gummadi, Richard J. Dunn, Stefan Saroiu, Steve D. Gribble, Henry M. Levy, John Zahorjan
SOSP3
2003 Measuring and analyzing the characteristics of Napster and Gnutella hosts
Stefan Saroiu, Krishna P. Gummadi, Steve D. Gribble
Multim. Syst.1
2002 King: estimating latency between arbitrary internet end hosts
abstract
The ability to estimate network latencies between arbitrary Internet end hosts would enable new measurement studies and applications, such as investigating routing path inefficiencies on a wide-scale or constructing topologically sensitive overlay networks. In this paper we present King, a tool that accurately and quickly estimates the latency between arbitrary end hosts by using recursive DNS queries in a novel way. Compared to previous approaches, King has several advantages. Unlike IDMaps, King does not require the deployment of additional infrastructure, and unlike GNP, King does not require end hosts to agree upon a set of reference points. Unlike both IDMaps and GNP, King's estimates are based on direct online measurements rather than offline extrapolation. Because King uses existing DNS infrastructure, King scales naturally both in terms of the number of hosts that can be measured and in terms of the number of hosts performing measurements.After describing the techniques used in King, we present an extensive evaluation and analysis of the accuracy and consistency of our tool. Specifically, our evaluation shows that the accuracy of King is significantly better than the accuracy of IDMaps, and that King tends to preserve order among its latency estimates. Finally, we describe a variety of measurement studies and applications that could benefit from our tool, and present results from one such measurement study.
Krishna P. Gummadi, Stefan Saroiu, Steve D. Gribble
Internet Measurement Workshop2
2002 An Analysis of Internet Content Delivery Systems
Stefan Saroiu, Krishna P. Gummadi, Richard J. Dunn, Steve D. Gribble, Henry M. Levy
OSDI1
2000 Self-Organizing Data Sharing Communities with SAGRES
abstract
No abstract available.
Zachary G. Ives, Alon Y. Halevy, Jayant Madhavan, Rachel Pottinger, Stefan Saroiu, Igor Tatarinov, Shiori Betzler, Ewa Jaslikowska, Jing Su 0002, Wai Tak Theodora Yeung
SIGMOD Conference5