Ali Raza 0003

dblp:28/9187-3 · DBLP profile ↗
← Back
12ranked-venue papers
6as first author
4since 2021 · last 2023
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 2 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Operating systems · 100%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Cloud and datacenter computing · 100%
Network and information security
1 paper
Web and mobile security · 44% Network security · 44% Authentication and access control · 13%
Computer networks
1 paper
Content delivery and video streaming · 100%

Topics — the 12 heaviest of 13, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Operating systems › kernel
kernel design
0.712023
Unikernel Linux (UKL) · EuroSys 2023
Operating systems › operating system design
library operating systems
0.712023
Unikernel Linux (UKL) · EuroSys 2023
Operating systems › kernel
linux kernel
0.712023
Unikernel Linux (UKL) · EuroSys 2023
Operating systems › operating system design
unikernel
0.712023
Unikernel Linux (UKL) · EuroSys 2023
Cloud and datacenter computing
cluster resource management and scheduling
0.412020
COSE: Configuring Serverless Functions using Statistical Learning · INFOCOM 2020
Cloud and datacenter computing
latency-cost tradeoff
0.412020
COSE: Configuring Serverless Functions using Statistical Learning · INFOCOM 2020
Cloud and datacenter computing
serverless computing
0.412020
COSE: Configuring Serverless Functions using Statistical Learning · INFOCOM 2020
Network security › protocol security › DNS security
domain abuse
0.312018
It's All in the Name: Why Some URLs are More Vulnerable to Typosquatting · INFOCOM 2018
Web and mobile security › web attacks
typosquatting
0.312018
It's All in the Name: Why Some URLs are More Vulnerable to Typosquatting · INFOCOM 2018
Content delivery and video streaming › caching
web caching
0.212015
Extreme Web Caching for Faster Web Browsing · SIGCOMM 2015
Cloud and datacenter computing
virtualization
0.212023
Unikernel Linux (UKL) · EuroSys 2023
Authentication and access control
user authentication
0.112018
It's All in the Name: Why Some URLs are More Vulnerable to Typosquatting · INFOCOM 2018

Methods — techniques the papers use, named apart from their topics

statistical learning · 0.4bayesian optimization · 0.4typographical model · 0.3cross-validation · 0.3
YearPublicationVenuePosition
2023 Unikernel Linux (UKL)
abstract
This paper presents Unikernel Linux (UKL), a path toward integrating unikernel optimization techniques in Linux, a general purpose operating system. UKL adds a configuration option to Linux allowing for a single, optimized process to link with the kernel directly, and run at supervisor privilege. This UKL process does not require application source code modification, only a re-link with our, slightly modified, Linux kernel and glibc. Unmodified applications show modest performance gains out of the box, and developers can further optimize applications for more significant gains (e.g. 26% throughput improvement for Redis). UKL retains support for co-running multiple user level processes capable of communicating with the UKL process using standard IPC. UKL preserves Linux's battle-tested codebase, community, and ecosystem of tools, applications, and hardware support. UKL runs both on bare-metal and virtual servers and supports multi-core execution. The changes to the Linux kernel are modest (1250 LOC).
Ali Raza 0003, Thomas Unger, Matthew Boyd, Eric B. Munson, Parul Sohal, Ulrich Drepper, Daniel Bristot de Oliveira, Larry Woodman, Renato Mancuso 0001, Jonathan Appavoo, Orran Krieger
EuroSys1
2023 Configuration and Placement of Serverless Applications Using Statistical Learning
abstract
In the last decade, serverless computing emerged as a new compelling paradigm for the deployment of cloud applications and services. It represents an evolution of cloud computing with a simplified programming model, that aims to abstract away most operational concerns. Running serverless applications requires users to configure multiple parameters, such as memory, CPU, cloud provider,etc. While relatively simpler, configuring such parameters correctly while minimizing cost and meeting delay constraints is not trivial. In this paper, we present COSE, a framework that uses Bayesian Optimization to find the optimal resource configuration and placement for functions in a serverless application. COSE uses statistical learning techniques to intelligently collect samples and predict the cost and execution time of a serverless function across unseen configuration values. Our framework uses the predicted cost and execution time on available locations to select the “best” configuration parameters and placement for running a serverless application while satisfying customer objectives. We evaluate COSE on AWS Lambda with real-world applications consisting of multiple functions (both linear chains and service graphs), where we successfully found optimal/near-optimal configurations. We also evaluate COSE over a wide range of simulated distributed cloud environments that confirm the efficacy of our approach.
Ali Raza 0003, Nabeel Akhtar, Vatche Isahagian, Abraham Matta
IEEE Trans. Netw. Serv. Manag.1
2021 LIBRA: An Economical Hybrid Approach for Cloud Applications with Strict SLAs
abstract
Function-as-a-Service (FaaS) has recently emerged to reduce the deployment cost of running cloud applications compared to Infrastructure-as-a-Service (IaaS). FaaS follows a serverless “pay-as-you-go” computing model; it comes at a higher cost per unit of execution time but typically application functions experience lower provisioning time (startup delay). IaaS requires the provisioning of Virtual Machines, which typically suffer from longer cold-start delays that cause higher queuing delays and higher request drop rates. We present LIBRA, a balanced (hybrid) approach that leverages both VM-based and serverless resources to efficiently manage cloud resources for the applications. LIBRA closely monitors the application demand and provisions appropriate VM and serverless resources such that the running cost is minimized and Service-Level Agreements are met. Unlike state of the art, LIBRA not only hides VM cold-start delays, and hence reduces response time, by leveraging serverless, but also directs a low-rate bursty portion of the demand to serverless where it would be less costly than spinning up new VMs. We evaluate LIBRA on real traces in a simulated environment as well as on the AWS commercial cloud. Our results show that LIBRA outperforms other resource-provisioning policies, including a recent hybrid approach - LIBRA achieves more than 85% reduction in SLA violations and up to 53% cost savings.
Ali Raza 0003, Zongshun Zhang, Nabeel Akhtar, Vatche Isahagian, Abraham Matta
IC2E1
2021 Managing Chains of Application Functions Over Multi-Technology Edge Networks
abstract
Next-generation networks are expected to provide higher data rates and ultra-low latency in support of demanding applications, such as virtual and augmented reality, robots and drones, etc. To meet these stringent requirements of applications, edge computing constitutes a central piece of the solution architecture wherein functional components of an application can be deployed over the edge network to reduce bandwidth demand over the core network while providing ultra-low latency communication to users. In this article, we provide solutions to resource orchestration and management for applications over a virtualized client-edge-server infrastructure. We investigate the problem of optimal placement of pipelines of application functions (virtual service chains) and the steering of traffic through them, over a multi-technology edge network model consisting of both wired and wireless millimeter-wave (mmWave) links. This problem is NP-hard. We provide a comprehensive “microscopic” binary integer program to model the system, along with a heuristic that is one order of magnitude faster than optimally solving the problem. Extensive evaluations demonstrate the benefits of orchestrating virtual service chains (by distributing them over the edge network) compared to a baseline “middlebox” approach in terms of overall admissible virtual capacity. Moreover, we observe significant gains when deploying a small number of mmWave links that complement the Wire physical infrastructure in high node density networks.
Nabeel Akhtar, Abraham Matta, Ali Raza 0003, Leonardo Goratti, Torsten Braun, Flavio Esposito
IEEE Trans. Netw. Serv. Manag.3
2020 COSE: Configuring Serverless Functions using Statistical Learning
abstract
Serverless computing has emerged as a new compelling paradigm for the deployment of applications and services. It represents an evolution of cloud computing with a simplified programming model, that aims to abstract away most operational concerns. Running serverless functions requires users to configure multiple parameters, such as memory, CPU, cloud provider, etc. While relatively simpler, configuring such parameters correctly while minimizing cost and meeting delay constraints is not trivial. In this paper, we present COSE, a framework that uses Bayesian Optimization to find the optimal configuration for serverless functions. COSE uses statistical learning techniques to intelligently collect samples and predict the cost and execution time of a serverless function across unseen configuration values. Our framework uses the predicted cost and execution time, to select the "best" configuration parameters for running a single or a chain of functions, while satisfying customer objectives. In addition, COSE has the ability to adapt to changes in the execution time of a serverless function. We evaluate COSE not only on a commercial cloud provider, where we successfully found optimal/near-optimal configurations in as few as five samples, but also over a wide range of simulated distributed cloud environments that confirm the efficacy of our approach.
Nabeel Akhtar, Ali Raza 0003, Vatche Isahagian, Abraham Matta
INFOCOM2
2019 Unikernels: The Next Stage of Linux's Dominance
abstract
Unikernels have demonstrated enormous advantages over Linux in many important domains, causing some to propose that the days of Linux's dominance may be coming to an end. On the contrary, we believe that unikernels' advantages represent the next natural evolution for Linux, as it can adopt the best ideas from the unikernel approach and, along with its battle-tested codebase and large open source community, continue to dominate. In this paper, we posit that an upstreamable unikernel target is achievable from the Linux kernel, and, through an early Linux unikernel prototype, demonstrate that some simple changes can bring dramatic performance advantages.
Ali Raza 0003, Parul Sohal, James Cadden, Jonathan Appavoo, Ulrich Drepper, Orran Krieger, Renato Mancuso 0001, Larry Woodman
HotOS1
2018 It's All in the Name: Why Some URLs are More Vulnerable to Typosquatting
abstract
Typosquatting is a blackhat practice that relies on human error and low-cost domain registrations to hijack legitimate traffic from well-established websites. The technique is typically used for phishing, driving traffic towards competitors or disseminating indecent or malicious content and as such remains a concern for businesses. We take a fresh new look at this well-studied phenomenon to explore why some URLs are more vulnerable to typing mistakes than others. We explore the relationship between human hand anatomy, keyboard layouts and typing mistakes using various URL datasets. We create an extensive user-centric typographical model and compute a Hardness Quotient (likelihood of mistyping) for each URL using a quantitative measure for finger and hand effort. Furthermore, our model predicts the most likely typos for each URL which can then be defensively registered. Cross-validation against actual URL and DNS datasets suggests that this is a meaningful and effective defense mechanism.
Rashid Tahir, Ali Raza 0003, Jehangir Kazi, Fareed Zaffar, Chris Kanich, Matthew Caesar 0001
INFOCOM2
2018 Using SGX-Based Virtual Clones for IoT Security
abstract
Widespread permeation of IoT devices into our daily lives has created a diverse spectrum of security and privacy concerns unique to the IoT ecosystem. Conventional host and network security mechanisms fail to address these issues due to resource constraints, ad-hoc network models and vendor-centric data collection and sharing policies. Hence, there is a need to redesign the IoT infrastructure to secure both the device and the data. To this end, we propose a design where users are in the driving seat, devices are less exposed and data sharing models are flexible and fine-grained. Our proposal comprises hardware-secured data banks based on Intel Software Guard Extensions (SGX) to house the data in clouds without the need to trust the cloud provider. Virtual clones (shadows) of devices running on top of these data banks serve as competent proxies of actual IoT devices hiding away device weaknesses. The proposed infrastructure is scalable and robust and serves as a good first step for the community to build on and improve.
Rashid Tahir, Ali Raza 0003, Fareed Zaffar, Faizan Ul Ghani, Mubeen Zulfiqar
NCA2
2017 An Anomaly Detection Fabric for Clouds Based on Collaborative VM Communities
abstract
The vast attack surface of clouds presents a challenge in deploying scalable and effective defenses. Traditional security mechanisms, which work from inside the VM fail to provide strong protection as attackers can bypass them easily. The only available option is to provide security from the layer below the VM i.e., the hypervisor. Previous works that attempt to secure VMs from "outside" either incur substantial space or compute overheads making them slow and impractical or require modifications to the OS or the application codebase. To address these issues, we propose an anomaly detection fabric for clouds based on system call monitoring, which compresses the stream of system calls at their source making the system scalable and near real-time. Our system requires no modifications to the guest OS or the application making it ideal for the data center setting. Additionally, for robust and early detection of threats, we leverage the notion of VM/container communities that share information about attacks in their early stages to provide immunity to the entire deployment. We make certain aspects of the system flexible so that vendors can tune metrics to offer customized protection to clients based on their workload types. Detailed evaluation on a prototype implementation on KVM substantiates our claims.
Rashid Tahir, Matthew Caesar 0001, Ali Raza 0003, Mazhar Naqvi, Fareed Zaffar
CCGrid3
2017 xCache: Rethinking Edge Caching for Developing Regions
abstract
End-users in emerging markets experience poor web performance due to a combination of three factors: high server response time, limited edge bandwidth and the complexity of web pages. The absence of cloud infrastructure in developing regions and the limited bandwidth experienced by edge nodes constrain the effectiveness of conventional caching solutions for these contexts. This paper describes the design, implementation and deployment of xCache, a cloud-managed Internet caching architecture that aims to proactively profile popular web pages and maintain the liveness of popular content at software defined edge caches to enhance the cache hit rate with minimal bandwidth overhead. xCache uses a Cloud Controller that continuously analyzes active cloud-managed web pages and derives an object-group representation of web pages based on the objects of a page. Using this object-group representation, xCache computes a bandwidth-aware utility measure to derive the most valuable configuration for each edge cache. Our preliminary real-world deployment across university campuses in three developing regions demonstrates its potential compared to conventional caching by improving cache hit rates by about 15%. Our evaluations of xCache have also shown that it can be applied in conjunction with other web optimizations solutions like Shandian, and can improve page load times by more than 50%.
Ali Raza 0003, Yasir Zaki, Thomas Pötsch, Jay Chen, Lakshminarayanan Subramanian
ICTD1
2015 Extreme Web Caching for Faster Web Browsing
abstract
Modern web pages are very complex; each web page consists of hundreds of objects that are linked from various servers all over the world. While mechanisms such as caching reduce the overall number of end-to-end requests saving bandwidth and loading time, there is still a large portion of content that is re-fetched -- despite not having changed. In this demo, we present Extreme Cache, a web caching architecture that enhances the web browsing experience through a smart pre-fetching engine. Our extreme cache tries to predict the rate of change of web page objects to bring cacheable content closer to the user.
Ali Raza 0003, Yasir Zaki, Thomas Pötsch, Jay Chen, Lakshminarayanan Subramanian
SIGCOMM1
2013 Low-Carb: Reducing energy consumption in operational cellular networks
abstract
Electricity costs are a significant fraction of a cellular network's operations costs. We present Low-Carb, a practical scheme to decrease electrical energy consumption in operational cellular networks by coupling Base Transceiver Station (BTS) power savings with call hand-off—two features commonly used by cellular operators. Motivated by the practical observation that most callers are in the vicinity of multiple BTSs, Low-Carb presents and solves an optimization problem, allowing calls to hand-off from one BTS to another so that BTS power savings can be applied to a maximal number of BTSs throughout the cellular network. We use BTS locations and traffic volume data from a large live GSM network to evaluate the power savings possible using our proposed approach in Low-Carb. Our results indicate that for a GSM 1800 network operator with 7000 sites in an urban setting, a total of up to 35.36 MWh may be saved annually. This is at least 9.8% better than the energy savings obtained by just using BTS power savings alone. Other cellular operators can use the Low-Carb formulation with their own network data to estimate the electricity savings they may achieve on their networks.
Muhammad Ghufran Ilyas, Ghufran Baig, Mubashir Adnan Qureshi, Qurrat-Ul-Ain Nadeem, Ali Raza 0003, Munaf Qazi, Bilal A. Rassool
GLOBECOM5