Hugo Sadok

dblp:222/2437 · DBLP profile ↗
← Back
10ranked-venue papers
5as first author
7since 2021 · last 2024
0000-0002-2464-1465ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 BBQ: A Fast and Scalable Integer Priority Queue for Hardware Packet Scheduling
Nirav Atre, Hugo Sadok, Justine Sherry
NSDI2
2023 Of Apples and Oranges: Fair Comparisons in Heterogenous Systems Evaluation
abstract
Accelerators, such as GPUs, SmartNICs and FPGAs, are common components of research systems today. This paper focuses on the question of how to fairly compare these systems. This is challenging because it requires comparing systems that use different hardware, e.g., two systems that use two different types of accelerators, or comparing a system that uses an accelerator with one that does not. We argue that fair evaluation in this case requires reporting not just performance, but also the cost of competing systems. We discuss what cost metrics should be used, and propose general principles for incorporating cost in research evaluations.
Hugo Sadok, Aurojit Panda, Justine Sherry
HotNets1
2023 Ensō: A Streaming Interface for NIC-Application Communication
Hugo Sadok, Nirav Atre, Daniel S. Berger, James C. Hoe, Aurojit Panda, Justine Sherry
OSDI1
2022 SurgeProtector: mitigating temporal algorithmic complexity attacks using adversarial scheduling
abstract
Denial-of-Service (DoS) attacks are the bane of public-facing network deployments. Algorithmic complexity attacks (ACAs) are a class of DoS attacks where an attacker uses a small amount of adversarial traffic to induce a large amount of work in the target system, pushing the system into overload and causing it to drop packets from innocent users. ACAs are particularly dangerous because, unlike volumetric DoS attacks, ACAs don't require a significant network bandwidth investment from the attacker Today, network functions (NFs) on the Internet must be designed and engineered on a case-by-case basis to mitigate the debilitating impact of ACAs. Further, the resulting designs tend to be overly conservative in their attack mitigation strategy, limiting the innocent traffic that the NF can serve under common-case operation.
Nirav Atre, Hugo Sadok, Erica Chiang, Weina Wang 0001, Justine Sherry
SIGCOMM2
2021 We need kernel interposition over the network dataplane
abstract
Kernel-bypass networking, which allows applications to circumvent the kernel and interface directly with NIC hardware, is one of the main tools for improving application network performance. However, allowing applications to circumvent the kernel makes it impossible to use tools (e.g., tcpdump) or impose policies (e.g., QoS and filters) that need to interpose on traffic sent by different applications running on a host. This makes maintainability and manageability a challenge for kernel-bypass applications. In response, we propose Kernel On-Path Interposition (KOPI), in which traditional kernel data-plane functionality is retained but implemented in a fully programmable SmartNIC. We hypothesize that KOPI can support the same tools and policies as the kernel stack while retaining the performance benefits of kernel bypass.
Hugo Sadok, Valerie Choung, Nirav Atre, Daniel S. Berger, James C. Hoe, Aurojit Panda, Justine Sherry
HotOS1
2021 Don't Yank My Chain: Auditable NF Service Chaining
Guyue Liu, Hugo Sadok, Anne Kohlbrenner, Bryan Parno, Vyas Sekar, Justine Sherry
NSDI2
2021 Stateful DRF: Considering the Past in a Multi-Resource Allocation
abstract
The multi-resource allocation problem arises in different scenarios. Different mechanisms have been proposed to fairly divide multiple resources, most notably, Dominant Resource Fairness (DRF). Even though DRF satisfies several desirable properties, it considers fairness only in the static setting. We propose Stateful DRF (SDRF), an extension of DRF that looks at past allocations and enforces fairness in the long run while keeping the fundamental properties of DRF. We prove that SDRF is strategyproof, since users cannot manipulate the system by misreporting their demands; incentivizes sharing, because no user is better off if resources are equally partitioned; and is efficient, as no allocation can be improved without decreasing another. In SDRF, users' priorities change over time. To avoid recalculating priorities at every task scheduling decision, we also propose Live Tree, a data structure that keeps elements with predictable time-varying priorities ordered. We implement SDRF on Mesos and run it in a real cluster. Moreover, we conduct large-scale simulations based on Google cluster traces of 30 million tasks over one month. Results show that SDRF reduces users' waiting time on average. This improves fairness, by increasing the number of completed tasks for users with lower demands, with negligible impact on high-demand users.
Hugo Sadok, Miguel Elias M. Campista, Luís Henrique Maciel Kosmalski Costa
IEEE Trans. Computers1
2020 Achieving 100Gbps Intrusion Prevention on a Single Server
Hugo Sadok, Nirav Atre, James C. Hoe, Vyas Sekar, Justine Sherry
OSDI2
2018 A Case for Spraying Packets in Software Middleboxes
abstract
The standard approach adopted by software middleboxes to use multiple cores has long been to direct packets to cores at flow granularity. This, however, has significant shortcomings. First, it is inefficient, since it cannot use all cores when there is a small number of concurrent flows---which happens frequently. Second, asymmetry in flow distribution causes unfairness even with a larger number of flows. Yet, the current trend of higher-speed links and core-richer CPUs only aggravates these problems. In this paper, we propose a natural alternative: that middleboxes should direct packets to cores at a finer granularity. Our system, Sprayer, solves the fundamental problems of per-flow solutions and addresses the new challenges of handling shared flow state that come with packet spraying. Sprayer builds on the observation that most middleboxes only update flow state when connections start or finish; ensuring that all control packets from the same TCP connection are processed in the same core. We show that, when compared to the per-flow alternative, Sprayer significantly improves fairness and seamlessly uses the entire capacity, even when there is a single flow.
Hugo Sadok, Miguel Elias M. Campista, Luís Henrique Maciel Kosmalski Costa
HotNets1
2018 Building an IaaS cloud with droplets: a collaborative experience with OpenStack
Rodrigo De Souza Couto, Hugo Sadok, Pedro Cruz 0001, Felipe A. F. da Silva, Tatiana Sciammarella, Miguel Elias M. Campista, Luís Henrique Maciel Kosmalski Costa, Pedro B. Velloso, Marcelo G. Rubinstein
J. Netw. Comput. Appl.2