VLDB 2026 Research / reviewers in the wild / expert
Liron Schiff
dblp:23/4283
· DBLP profile ↗
17ranked-venue papers
2as first author
5since 2021 · last 2026
0009-0009-0531-7414ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 2 first-author · 3 since 2021Systems, architecture and hardware · 3Security and privacy · 2Theory of computation · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GenCC: Heterogeneous Network Congestion Control using LLMsabstractCongestion control protocols regulate sending rates to optimize application performance and network utilization. In heterogeneous networks, however, applications often have different and conflicting performance objectives, making the design of suitable utility functions a challenging task that traditionally requires extensive mathematical analysis and experimental validation. Neta Rozen Schiff, Liron Schiff, Stefan Schmid 0001 |
SIGCOMM | 2 |
| 2024 | Dynamic Probabilistic Reliable BroadcastabstractA public ledger is a tamperproof sequence of data that can be read and augmented by everyone. Public ledgers have innumerable and compelling uses. They can secure, in plain sight, all kinds of transactions ---such as titles, sales, and payments--- in the exact order in which they occur. Public ledgers not only curb corruption, but also enable very sophisticated applications ---such as cryptocurrencies and smart contracts. They stand to revolutionize the way a democratic society operates. As currently implemented, however, they scale poorly and cannot achieve their potential. Algorand is a truly democratic and efficient way to implement a public ledger. Unlike prior implementations based on proof of work, it requires a negligible amount of computation, and generates a transaction history that will not "fork" with overwhelmingly high probability. Algorand is based on (a novel and super fast) message-passing Byzantine agreement. For concreteness, we shall describe Algorand only as a money platform. João Paulo Bezerra, Veronika Anikina, Petr Kuznetsov, Liron Schiff, Stefan Schmid 0001 |
OPODIS | 4 |
| 2022 | Renaissance: A self-stabilizing distributed SDN control plane using in-band communications
Marco Canini, Iosif Salem, Liron Schiff, Elad Michael Schiller, Stefan Schmid 0001 |
J. Comput. Syst. Sci. | 3 |
| 2021 | Macchiato: Importing Cache Side Channels to SDNsabstractSince caches are shared and coherent, a memory access of one process may evict from the cache another process' memory block with an address mapped to the same cache line. This property is exploited by several attacks to form side channels. We show that MAC learning in Software Defined Networks (SDNs) has a similar property in the sense that a MAC address discovered by one network device may be revoked by the discovery of the same address at another switch. This allows us to implement Macchiato, a covert channel for SDNs between any two network devices (including hosts); prior SDN covert channels required at least one malicious switch. We evaluate a prototype implementation of Macchiato and discuss how methods to improve the performance of cache side channels (such as deep neural networks) can also be used in Macchiato. Amir Sabzi, Liron Schiff, Kashyap Thimmaraju, Andreas Blenk, Stefan Schmid 0001 |
ANCS | 2 |
| 2021 | Preacher: Network Policy Checker for Adversarial EnvironmentsabstractPrivate networks are typically assumed to be trusted as security mechanisms are usually deployed on hosts and the data plane is managed in-house. The increasing number of attacks on network devices, and recent reports on backdoors, forces us to revisit existing security assumptions and demands new approaches to detect malicious activity. This paper presents Preacher, a runtime network policy checker, which leverages a secure, redundant and adaptive sample distribution scheme that allows us to provably detect and localize adversarial switches or routers trying to reroute, mirror, drop, inject, or modify packets (i.e., header and/or payload) even under collusion. The analysis performed by Preacher is highly parallelizable. We show that emerging programmable networks provide an ideal vehicle to detect suspicious network activity. Furthermore, we analytically and empirically evaluate the effectiveness of our approach in different adversarial settings, report on a proof-of-concept implementation using ONOS, and provide insights into the resource and performance overheads of Preacher. Kashyap Thimmaraju, Liron Schiff, Stefan Schmid 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2019 | Preacher: Network Policy Checker for Adversarial EnvironmentsabstractPrivate networks are typically assumed to be trusted as security mechanisms are usually deployed on hosts and the data plane is managed in-house. The increasing number of attacks on network devices, and recent reports on backdoors, forces us to revisit existing security assumptions and demands new approaches to detect malicious activity. This paper presents Preacher, a runtime network policy checker, which leverages a secure, redundant and adaptive sample distribution scheme that allows us to provably detect adversarial switches or routers trying to reroute, mirror, drop, inject, or modify packets (i.e., header and/or payload) even under collusion. Additionally, the analysis performed by Preacher is highly parallelizable. We show that emerging programmable networks provide an ideal vehicle to detect suspicious network activity. Furthermore, we analytically and empirically evaluate the effectiveness of our approach in different adversarial settings, report on a proof-of-concept implementation using ONOS, and provide insights into the resource and performance overheads of Preacher. Kashyap Thimmaraju, Liron Schiff, Stefan Schmid 0001 |
SRDS | 2 |
| 2018 | Renaissance: A Self-Stabilizing Distributed SDN Control PlaneabstractBy introducing programmability, automated verification, and innovative debugging tools, Software-Defined Networks (SDNs) are poised to meet the increasingly stringent dependability requirements of today's communication networks. However, the design of fault-tolerant SDNs remains an open challenge. This paper considers the design of dependable SDNs through the lenses of self-stabilization - a very strong notion of fault-tolerance. In particular, we develop algorithms for an in-band and distributed control plane for SDNs, called Renaissance, which tolerates a wide range of (concurrent) controller, link, and communication failures. Our self-stabilizing algorithms ensure that after the occurrence of an arbitrary combination of failures, (i) every non-faulty SDN controller can eventually reach any switch in the network within a bounded communication delay (in the presence of a bounded number of concurrent failures) and (ii) every switch is managed by at least one non-faulty controller. We evaluate Renaissance through a rigorous worst-case analysis as well as a prototype implementation (based on OVS and Floodlight), and we report on our experiments using Mininet. Marco Canini, Iosif Salem, Liron Schiff, Elad Michael Schiller, Stefan Schmid 0001 |
ICDCS | 3 |
| 2018 | Detecting heavy flows in the SDN match and action model
Yehuda Afek, Anat Bremler-Barr, Shir Landau Feibish, Liron Schiff |
Comput. Networks | 4 |
| 2018 | The show must go on: Fundamental data plane connectivity services for dependable SDNs
Michael Borokhovich, Clement Rault, Liron Schiff, Stefan Schmid 0001 |
Comput. Commun. | 3 |
| 2017 | Outsmarting Network Security with SDN TeleportationabstractSoftware-defined networking is considered a promising new paradigm, enabling more reliable and formally verifiable communication networks. However, this paper shows that the separation of the control plane from the data plane, which lies at the heart of Software-Defined Networks (SDNs), introduces a new vulnerability which we call teleportation. An attacker (e.g., a malicious switch in the data plane or a host connected to the network) can use teleportation to transmit information via the control plane and bypass critical network functions in the data plane (e.g., a firewall), and to violate security policies as well as logical and even physical separations. This paper characterizes the design space for teleportation attacks theoretically, and then identifies four different teleportation techniques. We demonstrate and discuss how these techniques can be exploited for different attacks (e.g., exfiltrating confidential data at high rates), and also initiate the discussion of possible countermeasures. Generally, and given today's trend toward more intent-based networking, we believe that our findings are relevant beyond the use cases considered in this paper. Kashyap Thimmaraju, Liron Schiff, Stefan Schmid 0001 |
EuroS&P | 2 |
| 2017 | A Self-Organizing Distributed and In-Band SDN Control PlaneabstractAdopting distributed control planes is critical towards ensuring high availability and fault-tolerance of dependable Software-Defined Networks (SDNs). However, designing and bootstrapping a distributed SDN control plane is a challenging task, especially if to be done in-band, without a dedicated control network, and without relying on legacy networking protocols. One of the most appealing and powerful notions of fault-tolerance is self-organization and this paper discusses the possibility of self-organizing algorithms for in-band control planes. Marco Canini, Iosif Salem, Liron Schiff, Elad Michael Schiller, Stefan Schmid 0001 |
ICDCS | 3 |
| 2015 | ORange: Multi Field OpenFlow based Range ClassifierabstractConfiguring range based packet classification rules in network switches is crucial to all network core functionalities, such as firewalls and routing. However, OpenFlow, the leading management protocol for SDN switches, lacks the interface to configure range rules directly and only provides mask based rules, named flow entries. In this work we present, ORange, the first solution to multi dimensional range classification in OpenFlow. Our solution is based on paradigms used in state of the art non-OpenFlow classifiers and is designed in a modular fashion allowing future extensions and improvements. We consider switch space utilization as well as atomic updates functionality, and in the network context we provide flow consistency even if flows change their entrance point to the network during policy updates, a property we name cross-entrance consistency. Our scheme achieves remarkable results and is easy to deploy. Liron Schiff, Yehuda Afek, Anat Bremler-Barr |
ANCS | 1 |
| 2015 | Sampling and Large Flow Detection in SDNabstractNo abstract available. Yehuda Afek, Anat Bremler-Barr, Shir Landau Feibish, Liron Schiff |
SIGCOMM | 4 |
| 2014 | Reclaiming the Brain: Useful OpenFlow Functions in the Data PlaneabstractSoftware-defined networks (SDNs) have the potential to radically simplify the network management by providing a programmatic interface to a logically centralized controller. However, outsourcing the management to the software controller comes at a price, and good tradeoffs have to be found between the benefits of a fine-grained control and its costs. In this paper, we show that OpenFlow, the predominant SDN protocol, allows to implement powerful functions "in the south", i.e., in the data plane. Our approach, called SmartSouth, can be used to reduce interactions with the control plane as well as to make the network more robust. Moreover, while rendering the data plane "smarter", SmartSouth only relies on the standard OpenFlow match-action paradigm; thus, the data plane functions remain formally verifiable---a key benefit of SDN. To demonstrate the potential of SmartSouth, we discuss four basic applications: (1) topology snapshot, (2) anycast, (3) blackhole- and (4) critical node detection. Liron Schiff, Michael Borokhovich, Stefan Schmid 0001 |
HotNets | 1 |
| 2014 | Recursive design of hardware priority queues
Yehuda Afek, Anat Bremler-Barr, Liron Schiff |
Comput. Networks | 3 |
| 2013 | Recursive design of hardware priority queuesabstractA recursive and fast construction of an n elements priority queue from exponentially smaller hardware priority queues and size n RAM is presented. All priority queue implementations to date either require O (log n) instructions per operation or exponential (with key size) space or expensive special hardware whose cost and latency dramatically increases with the priority queue size. Hence constructing a priority queue (PQ) from considerably smaller hardware priority queues (which are also much faster) while maintaining the O(1) steps per PQ operation is critical. Here we present such an acceleration technique called the Power Priority Queue (PPQ) technique. Specifically, an n elements PPQ is constructed from 2k-1 primitive priority queues of size k√n (k=2,3,...) and a RAM of size n, where the throughput of the construct beats that of a single, size n primitive hardware priority queue. For example an n elements PQ can be constructed from either three √n or five 3√n primitive H/W priority queues. Yehuda Afek, Anat Bremler-Barr, Liron Schiff |
SPAA | 3 |
| 2008 | Impossibility of a Quantum Speed-Up with a Faulty Oracle
Oded Regev 0001, Liron Schiff |
ICALP (1) | 2 |