VLDB 2026 Research / reviewers in the wild / expert
Nurefsan Sertbas Bülbül
dblp:271/5407 · also Nurefsan Sertbas
· DBLP profile ↗
8ranked-venue papers
6as first author
6since 2021 · last 2024
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 4 first-author · 5 since 2021Security and privacy · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Transparent TSN for Agnostic End-hosts via P4-based Traffic Characterization at SwitchesabstractMission-critical networks currently face a transition from legacy network protocols to advanced time-sensitive networking (TSN) standards. TSN guarantees reliable and deterministic communication using off-the-shelf Ethernet equipment. However, end-hosts must be TSN-aware and may pose security risks by arbitrarily over-allocating resources. Integrating central instances like a software-defined networking (SDN) controller into TSN networks to streamline network management presents a promising solution. This raises concerns regarding latency in communication between switches and the controller, as well as among switches themselves. To address this, we propose an approach that renders TSN transparent to end-hosts, eliminating the need for their involvement in resource reservations. We embed packet processing logic in P4-enabled TSN switches to characterize network traffic intelligently. This enables switches to allocate network resources autonomously and adjust real-time traffic handling mechanisms. Leveraging P4 storage structures introduces statefulness for traffic characterization computing within the inherently stateless P4 language. Our experiments demonstrate that our P4-enhanced switches require a minimal 0.014 MB of switch memory to distinguish between periodic and non-periodic traffic with an 80% precision while incurring a mere 0.2 ms forwarding latency per packet. Cornelia Brülhart, Nurefsan Sertbas Bülbül, Nils Ole Tippenhauer, Mathias Fischer 0001 |
LCN | 2 |
| 2023 | Preemptive DoS attacks on Time Sensitive NetworksabstractTime-sensitive networking (TSN) is a promising technology for real-time communication in industrial and automotive networks. One of its key features is frame preemption, which allows high-priority traffic to interrupt the transmission of low-priority traffic, thereby reducing the delay of high-priority critical traffic. However, the deterministic nature of TSN frame preemption also makes it vulnerable to denial of service (DoS) attacks, which can severely impact flow quality of service (QoS) by increasing delays and packet loss. In this paper, we introduce the concept of preemptive DoS attacks and evaluate their impact on TSN QoS performance. We describe a strategy that attackers can use to estimate the preemption scheme configured in the switch and then demonstrate how an active attacker can use this information to degrade TSN QoS. Our simulation results indicate that even a single attacker can significantly deteriorate the QoS of TSN traffic. It is important to address this vulnerability in TSN and develop countermeasures to prevent preemptive DoS attacks from occurring. Nurefsan Sertbas Bülbül, Mathias Fischer 0001 |
GLOBECOM | 1 |
| 2022 | Reinforcement Learning assisted Routing for Time Sensitive NetworksabstractRecent developments in real-time critical systems pave the way for different application scenarios such as Industrial IoT with various quality-of-service (QoS) requirements. The most critical common feature of such applications is that they are sensitive to latency and jitter. Thus, it is desired to perform flow placements strategically considering application requirements due to limited resource availability. In this paper, path computation for time-sensitive networks is investigated while satisfying individual end-to-end delay requirements of critical traffic. The problem is formulated as a mixed-integer linear program (MILP) which is NP-hard with exponentially increasing computational complexity as the network size expands. To solve the MILP with high efficiency, we propose a reinforcement learning (RL) algorithm that learns the best routing policy by continuously interacting with the network environment. The proposed learning algorithm determines the variable action set at each decision-making state and captures different execution times of the actions. The reward function in the proposed algorithm is carefully designed for meeting individual flow deadlines. Simulation results indicate that the proposed reinforcement learning algorithm can produce near-optimal flow allocations (close by ~1.5 %) and scales well even with large topology sizes. Nurefsan Sertbas Bülbül, Mathias Fischer 0001 |
GLOBECOM | 1 |
| 2022 | Towards SDN-based Dynamic Path Reconfiguration for Time Sensitive NetworkingabstractFuture networks will need to support a large number of low-latency flows. In time-sensitive networks (TSN), paths for data flows are usually established at startup time of an application and remain untouched until the flow ends. There is no way to migrate existing flows easily to alternative paths without inducing significant additional delay or wasting resources. Therefore, the resource-utilization of TSN might degrade over time leading to a sub-optimal flow assignment. In this paper we address this problem by combining Software-defined Networking (SDN) that provides better control on network flows with TSN to be able to seamlessly migrate time-sensitive flows. We propose a SDN-based dynamic path reconfiguration algorithm for accommodating TSN flows and formulate it as optimization problem. By exploiting the control plane’s global view, we evaluate different dynamic path configuration strategies under deterministic communication requirements. Our simulation results indicate that reconfiguring the flow assignments from time to time can improve the latency of time-sensitive flows and can increase the number of flows embedded in the network in worst-case scenarios. Nurefsan Sertbas Bülbül, Doganalp Ergenç, Mathias Fischer 0001 |
NOMS | 1 |
| 2021 | Mitigation of IPv6 Router Spoofing Attacks with P4abstractThe IPv6 protocol will sooner or later replace IPv4 to cope with an exponentially increasing number of connected devices. Some of the most significant functions of IPv6 networks are network discovery, maintenance, and routing mechanisms to promote auto-configuration of the network with less manual effort. Network Discovery Protocol (NDP) is an important protocol in IPv6 to identify the relationships between different neighboring devices in a network. However, it is also subject to spoofing and man-in-the-middle attacks. This paper implements an attack detection and mitigation strategy called Router Advertisement Guard (RA-Guard) in P4 to defend IPv6 networks against router spoofing attacks directly on the data plane. In contrast to very few proprietary RA-Guard implementations with limited details, we consider different scenarios to exploit IPv6 packet structure and publish our implementation open-source. The experiments show that our P4-based implementation can detect and mitigate spoofing attacks leveraging RA-Guard together with its control plane extensions. Moritz Mönnich, Nurefsan Sertbas Bülbül, Doganalp Ergenç, Mathias Fischer 0001 |
ANCS | 2 |
| 2021 | SDN-based Self-Configuration for Time-Sensitive IoT NetworksabstractThe convergence of Information Technology (IT) and Industrial Operations Technology (OT) results in efficient network management solutions for automotive and industrial automation environments. However, configuring real-time Ethernet networks while maintaining the desired QoS is challenging due to the dynamic nature of OT networks and the high number of configuration parameters. This paper introduces a Software-Defined Network (SDN)-based self-configuration framework for the time-sensitive networks (TSNs). Unlike standard TSN, we remove end-host-related dependencies and put streams initially on default paths to extract traffic characteristics by monitoring network traffic at edge switches. Communicated to a central SDN controller, these characteristics allow moving streams to optimal paths while maintaining hard real-time guarantees, for which we also formulate an optimization problem. According to the results, although the proposed approach increases the average delay of critical frames by less than 1%, a certain level of real-time guarantee can be provided without prior knowledge of the streams. Nurefsan Sertbas Bülbül, Doganalp Ergenç, Mathias Fischer 0001 |
LCN | 1 |
| 2020 | SDN/NFV-based DDoS Mitigation via PushbackabstractDistributed Denial of Service (DDoS) attacks aim at bringing down or decreasing the availability of services for their legitimate users, by exhausting network or server resources. It is difficult to differentiate attack traffic from legitimate traffic as the attack can come from distributed nodes that additionally might spoof their IP addresses. Traditional DoS mitigation solutions fail to defend all kinds of DoS attacks and huge DoS attacks might exceed the processing capacity of routers and firewalls easily. The advent of Software-defined Networking (SDN) and Network Function Virtualization (NFV) has brought a new perspective for network defense. Key features of such technologies like global network view and flexibly positionable security functionality can be used for mitigating DDoS attacks. In this paper, we propose a collaborative DDoS attack mitigation scheme that uses SDN and NFV. We adopt a machine learning algorithm from related work to derive accurate patterns describing DDoS attacks. Our experimental results indicate that our framework is able to differentiate attack and legitimate traffic with high accuracy and in near-realtime. Furthermore, the derived patterns can be used to create OpenFlow (OF) or Firewall rules that can be pushed back into the direction of the attack origin for more efficient and distributed filtering. Nurefsan Sertbas Bülbül, Mathias Fischer 0001 |
ICC | 1 |
| 2018 | Attribute Based Content Security and Caching in Information Centric IoTabstractInformation-centric networking (ICN) is a Future Internet paradigm which uses named information (data objects) instead of host-based end-to-end communications. In-network caching is a key pillar of ICN. Basically, data objects are cached in ICN routers and retrieved from these network elements upon availability when they are requested. It is a particularly promising networking approach due to the expected benefits of data dissemination efficiency, reduced delay and improved robustness for challenging communication scenarios in IoT domain. From the security perspective, ICN concentrates on securing data objects instead of ensuring the security of end-to-end communication link. However, it inherently involves the security challenge of access control for content. Thus, an efficient access control mechanism is crucial to provide secure information dissemination. In this work, we investigate Attribute Based Encryption (ABE) as an access control apparatus for information centric IoT. Moreover, we elaborate on how such a system performs for different parameter settings such as different numbers of attributes and file sizes. Nurefsan Sertbas Bülbül, Samet Aytaç, Orhan Ermis, Fatih Alagöz, Gürkan Gür |
ARES | 1 |