Salim Hariri

dblp:38/2282 · DBLP profile ↗
← Back
114ranked-venue papers
14as first author
21since 2021 · last 2026
0000-0003-3956-3401ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 45 · 10 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 40 · 15 since 2021Computer networks · 8 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 7 · 1 first-authorSecurity and privacy · 6 · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Ai/ml based detection and categorization of covert communication in IPv6 network
Mohammad Wali Ur Rahman, Yu-Zheng Lin, Carter Weeks, David Ruddell, Jeff Gabriellini, Bill Hayes, Salim Hariri, Pratik Satam, Edward V. Ziegler Jr
Cybersecur.7
2026 SDEC: Semantic Deep Embedded Clustering
abstract
The high dimensional and semantically complex nature of textual Big data presents significant challenges for text clustering, which frequently lead to suboptimal groupings when using conventional techniques like k-means or hierarchical clustering. This work presents Semantic Deep Embedded Clustering (SDEC), an unsupervised text clustering framework that combines an improved autoencoder with transformer-based embeddings to overcome these challenges. This novel method preserves semantic relationships during data reconstruction by combining Mean Squared Error (MSE) and Cosine Similarity Loss (CSL) within an autoencoder. Furthermore, a semantic refinement stage that takes advantage of the contextual richness of transformer embeddings is used by SDEC to further improve a clustering layer with soft cluster assignments and distributional loss. The capabilities of SDEC are demonstrated by extensive testing on five benchmark datasets:AG News, Yahoo! Answers, DBPedia, Reuters 2,andReuters 5. The framework not only outperformed existing methods with a clustering accuracy of 85.7% onAG Newsand set a new benchmark of 53.63% onYahoo! Answers, but also showed robust performance across other diverse text corpora. These findings highlight the significant improvements in accuracy and semantic comprehension of text data provided by SDEC's advances in unsupervised text clustering.
Mohammad Wali Ur Rahman, Ric Nevarez, Lamia Tasnim Mim, Salim Hariri
IEEE Trans. Big Data4
2025 A Multi-Phase Resilient Machine Learning Architecture Against Data Poisoning Attacks
abstract
Machine Learning (ML) systems are increasingly vulnerable to data poisoning attacks, which compromise reliability in critical infrastructures such as healthcare, electric grids, utility networks, and autonomous systems. Existing defenses largely focus on inference-time adversarial examples, yet remain insufficient to detect or mitigate poisoning attack that corrupts the training dataset and long-term decision-making process. To address this gap, we present a zero-trust, multi-phase architecture that secures both static (offline) and dynamic (online) training workflows. The architecture integrates asymmetric encryption, secret-sharing, diversity, redundancy, Moving Target Defense (MTD), decoy datasets, and fingerprint anonymization to reduce adversarial influence. Dataset integrity is ensured through a robust Proof of Integrity (PoI) mechanism combining hash chaining, rabin fingerprints, bloom filters, and digital signatures. A dual-controller design strengthens resilience: the Training-Phase Controller validates datasets and models through PoI before training, while the Operational-Phase Controller re-validates models and applies majority voting during inference. Together, these mechanisms ensure only integrity-verified data and models are used throughout the ML workflow. Analytical resilience modeling shows that the architecture significantly reduces attack success rates while maintaining efficiency.
Gizem Altintarla, Salim Hariri
AICCSA2
2025 Anomaly-based Intrusion Detection System for Ethernet/Industrial Protocol (ENIP)
abstract
Industrial control systems (ICS) are essential to industrial applications and national critical infrastructures (e.g., power, gas, and water grids, financial networks, etc.). ICSs networks used to be isolated and based on serial communication, modern ICS networks now commonly use Ethernet, reducing costs but significantly increasing their attack surface. In the first half of 2024 alone, nearly $25 \%$ of ICS engineering workstations reported attack attempts. EtherNet/IP (ENIP), a widely used protocol in ICS networks, adapts the Common Industrial Protocol (CIP) to Ethernet but lacks built-in security features like authentication and encryption. This paper presents an anomaly-based intrusion detection system (IDS) for ENIP. Our approach models protocol behavior using n-grams and applies machine learning to detect anomalies and classify attacks. We evaluated our method using data collected from an ICS testbed at the University of Arizona. The system was tested against a range of attacks, including data injection, I/O force, program download, and denial-of-service. Results show our system detects anomalies with up to 99% accuracy and classifies attacks with 83% accuracy.
Clarisa Grijalva-Lugo, Salim Hariri
AICCSA2
2025 Attack Classification Using Retrieval-Augmented Generation and Large Language Models
abstract
The exponential rise in security alerts across modern information systems presents a critical challenge for cybersecurity operations, frequently overwhelming analysts and hindering timely incident response. To address this, we propose an automated threat classification framework that leverages RetrievalAugmented Generation (RAG) in combination with Large Language Models (LLMs) to accurately interpret and categorize attack types. By combining real-time data ingestion with contextual retrieval and advanced natural language understanding, the system efficiently interprets alert data and categorizes threats to support incident response and decision-making. Experimental evaluations show that the proposed approach achieves a classification accuracy of 94%, demonstrating strong promise for realworld deployment in security operations centers. These results highlight the potential of integrating RAG-LLM based frameworks to significantly enhance the scalability and effectiveness of cybersecurity defenses.
Ivan Kawaminami, Mohammad Wali Ur Rahman, Salim Hariri
AICCSA4
2024 A 5G and Beyond Testbed for Cybersecurity Research and Education
abstract
The advent of 5G technology marks a pivotal advancement in mobile communications, enhancing broadband connectivity, enabling low-latency connections, and facilitating a broader range of diverse applications. Although advantageous, the introduction of 5G also introduces greater infrastructure complexity and increased cybersecurity vulnerabilities. This paper addresses these issues by developing a comprehensive 5G testbed for research and education purposes. The testbed integrates opensource software with physical hardware components to create a realistic environment for simulating and analyzing cyberattacks. Through various scenarios, including Denial of Service attacks and database exploits, we demonstrate the susceptibility of 5G core networks to these threats. Our findings reveal critical vulnerabilities in the Access and Mobility Management Function (AMF) and MySQL database, which can disrupt 5G network operations and compromise data integrity. The practical approach presented in this paper identify and mitigate 5G security threats provides valuable insights for enhancing the resilience of 5G/6G networks.
Ibrahim Almazyad, Safwan Elmadani, Salim Hariri
AICCSA3
2023 An Anomaly Behavior Analysis Framework for Securing Autonomous Vehicle Perception
abstract
As a rapidly growing cyber-physical platform, Autonomous Vehicles (AVs) are encountering more security challenges as their capabilities continue to expand. In recent years, adversaries are actively targeting the perception sensors of autonomous vehicles with sophisticated attacks that are not easily detected by the vehicles’ control systems. This paper proposes an Anomaly Behavior Analysis framework to detect perception system anomalies and sensor attacks against an autonomous vehicle. The framework relies on temporal features extracted from a physics-based autonomous vehicle behavior model to capture the normal behavior of vehicular perception in autonomous driving. By employing a combination of model-based techniques and machine learning algorithms, the proposed framework distinguishes between normal and abnormal vehicular perception behavior. As part of our experimental evaluation of the framework, a depth camera blinding attack experiment was performed on an autonomous vehicle testbed and an extensive dataset was generated. The effectiveness of the proposed framework has been validated using this real-world data and the dataset has been released for public access. To our knowledge, this dataset is the first of its kind and will serve as a valuable resource for the research community in evaluating their intrusion detection techniques effectively.
Murad Mehrab Abrar, Salim Hariri
AICCSA2
2023 Empowering Data Federation Security in Polystore Systems
abstract
Integrating data from multiple sources with different native data models can be a demanding task that requires significant manual effort. Polystore is a new federated database view designed to enable polyglot querying across diverse data models. This paper aims to discuss the most significant security challenges associated with data federation. We identify the key privacy risks hindering polystore technologies and highlight the gap between traditional data protection approaches and current security issues. Moreover, we present a reference architecture as an active solution to significantly improve data usage in compliance with upstream security policies. Access control is the most widely-accepted reference in the database community for dealing effectively with this type of problem. In this context, we propose an access control mechanism that increases the resilience of the Polystore through Moving Target Defense (MTD) concept. Our approach is intended to address the security focus on privacy risks associated with Polystore technologies, and to enhance their adoption in modern data-driven applications.
Juba Agoun, Juba Terras, Mohand-Said Hacid, Salim Hariri
AICCSA4
2023 Anomaly Behavior Analysis of Smart Water Treatment Facility Service: Design, Analysis, and Evaluation
abstract
The current trends toward the design and deployment of smart city services, including water services, improve quality, reliability and reduce operational costs. These advancements have led to the proliferation of ubiquitous connectivity to critical infrastructures. However, although smart sensors and Industrial Internet of Things (IIoTs) expedites rigorous monitoring and control, they exponentially increase vulnerabilities that can be exploited by cyberattacks. Therefore, development of advanced cybersecurity tools and resilience methods for smart city services are critically important because compromising these services can lead to disasters, accidents or even loss of life. To address the cybersecurity challenges facing smart city services, researchers need realistic testbeds to perform experiments, collect real-time data, and evaluate different security algorithms to protect smart critical infrastructure services. This paper presents a Water Treatment Facility Testbed (WTFT), a Cyber-Physical System (CPS) developed to enable experimentation with cybersecurity and resilient algorithms to deliver smart water services that can tolerate cyberattacks. Furthermore, an anomaly-based detection unit for water quality is implemented and our experimental results show a 96.8% F1-score, and a 98.3% accuracy with an attack detection latency under two seconds.
Ibrahim Almazyad, Sicong Shao, Salim Hariri, Hisham A. Kholidy
AICCSA3
2023 An Explainable Outlier Detection-based Data Cleaning Approach for Intrusion Detection
abstract
The effectiveness of machine learning (ML)-based intrusion detection systems (IDSs) for detecting widespread cyberattacks on critical infrastructure and government systems has been demonstrated in recent years. Nevertheless, with ML models becoming more complex, people can hardly understand their decisions. Further, most works on model explanations focus on analyzing the ML model itself. However, data cleaning is also vital in influencing the model’s detection behavior. On the other hand, data cleaning for ML-based IDSs is challenging because modern IDS datasets may contain outliers that affect the training stage. In this work, we propose an explainable data cleaning approach for intrusion detection, which can effectively perform explainable isolation forest-based outlier detection in the data preprocessing stage for intrusion detection. Through experiments on real-world network intrusion datasets, we evaluate the effectiveness of our approach. Experiment results demonstrate that eliminating outliers improves intrusion detection and that data cleaning using outlier detection is explainable.
Theodore Ha, Sicong Shao, Salim Hariri
AICCSA3
2023 Resilient Machine Learning (rML) Against Adversarial Attacks on Industrial Control Systems
abstract
Machine learning (ML) algorithms have been widely used in many critical automated systems, including as a technique in Dynamic Data Driven Applications Systems (DDDAS)-based methods and areas such as financial trading, autonomous vehicles, and intrusion detection systems. However, malicious adversaries have strong interests in manipulating the operations of machine learning algorithms to achieve their objectives of gaining financial, social, or political influence. Adversarial ML (AML) users can be classified based on their capabilities and goals into three types: Adversary who has full knowledge of the ML models and parameters (white-box scenario), partial knowledge of ML models (gray-box scenario), and one who does not have any knowledge and uses guessing techniques to figure out the ML model and its parameters (black-box scenario). In these scenarios, the adversaries attempt to maliciously manipulate the model/data either during training or testing. Defending against these AML attacks can be successful by following methods such as making the ML model robust, validating and verifying inputs and outputs, and changing the ML architecture. This paper presents a resilient machine learning (rML) against adversarial attacks by dynamically conducting feature space anonymization and model randomization in ML services such that the adversaries lack knowledge about the feature space and model used and consequently prevent them from maliciously manipulating the ML operations during the runtime. In our approach, the rML utilizes autoencoders as an anonymization technique for encoding feature space to minimize the effect of adversarial samples. The rML method is evaluated using the benchmarking Industrial Control Systems (ICS) data and the corresponding adversarial data generated using the Jacobian-based Saliency Map Attack (JSMA) method. The experiment demonstrated that the proposed approach can detect attacks targeting ICS and prevent adversarial attacks compromising ML models used to secure ICS.
Likai Yao, Sicong Shao, Salim Hariri
AICCSA3
2023 Machine Learning for Intrusion Detection: Stream Classification Guided by Clustering for Sustainable Security in IoT
abstract
The Internet of Things (IoT) has brought about unprecedented connectivity and convenience in our daily lives, but with this newfound interconnectedness comes the threat of cyber-attacks. With ever-increasing IoT devices being connected to the internet, securing IoT devices is becoming increasingly urgent. Machine learning (ML) is among the most popular techniques used by intrusion detection systems (IDS) to enhance their detection performance when securing IoT. However, a key obstacle of ML-based IDS for IoT is learning from nonstationary streaming data, also known as concept drift. One of the most challenging learning scenarios under concept drift is extreme verification latency (EVL), which occurs when only unlabeled nonstationary streaming data is available after a small set of initial labeled data. Stream Classification Algorithm Guided by Clustering (SCARGC) is an algorithm that can effectively deal with the nonstationary data streams in EVL scenarios. Applying an EVL implementation provides the capability of adapting to nonstationary environments within the IoT domain. The SCARGC model, as an integrated IoT intrusion detection system, allows for sustainable security as new threats are identified in this non-stationary environment. Hence, in this project, we develop an innovative IoT intrusion detection approach by natively integrating SCARGC and intrusion detection to address the EVL challenges to provide sustainable security as the model adapts to nonstationary environments. We evaluated the proposed approach on real-world IoT cybersecurity datasets. The results demonstrate the feasibility of the proposed approach, which can lead to the development of sophisticated intrusion detection systems for IoT.
Martin Manuel Lopez, Sicong Shao, Salim Hariri, Soheil Salehi
ACM Great Lakes Symposium on VLSI3
2023 Quantized Transformer Language Model Implementations on Edge Devices
abstract
Large-scale transformer-based models like the Bidi-rectional Encoder Representations from Transformers (BERT) are widely used for Natural Language Processing (NLP) applications, wherein these models are initially pre-trained with a large corpus with millions of parameters and then fine-tuned for a downstream NLP task. One of the major limitations of these large-scale models is that they cannot be deployed on resource- constrained devices due to their large model size and increased inference latency. In order to overcome these limitations, such large-scale models can be converted to an optimized FlatBuffer format, tailored for deployment on resource-constrained edge devices. Herein, we evaluate the performance of such FlatBuffer transformed MobileBERT models on three different edge devices, fine-tuned for Reputation analysis of English language tweets in the Rep Lab 2013 dataset. In addition, this study encompassed an evaluation of the deployed models, wherein their latency, performance, and resource efficiency were meticulously assessed. Our experiment results show that, compared to the original BERT large model, the converted and quantized MobileBERT models have 160x smaller footprints for a 4.1 % drop in accuracy while analyzing at least one tweet per second on edge devices. Furthermore, our study highlights the privacy-preserving aspect of TinyML systems as all data is processed locally within a serverless environment.
Mohammad Wali Ur Rahman, Murad Mehrab Abrar, Hunter Gibbons Copening, Salim Hariri, Sicong Shao, Pratik Satam, Soheil Salehi
ICMLA4
2022 Blockchain Based Methodology for Zero Trust Modeling and Quantification for 5G Networks
abstract
The 5th generation mobile network (5G) is designed with a new core architecture that makes it quite extensible. The components of the 5G core architecture are no longer physical standalone devices, but rather software processes run on commercial off-the-shelf (COTS) servers. The backbone of 5G is software-defined networking (SDN) and network function virtualization (NFV), and they both bring unprecedented flexibility to network and resource management. In this context, 5G logical networks can be created by partitioning a shared physical infrastructure, and each network can be customized and optimized for specific entity. This concept is known as 5G network slicing. Despite the tremendous benefits of network slicing, it also brings many unprecedented security challenges because of the dynamism and diversity of slice's structure. Therefore, establishing trust in the 5G ecosystem is a cornerstone for global adaptation and tackling security and privacy risks. In this paper, we focus on the trust aspect between the network slice stakeholders (i.e slice owners, users, slice resource providers, and service providers), and we propose a blockchain-based zero trust model that addresses threat models that are based on the lack of trust between the entities in a network slice. Our approach for zero trust modeling and quantification is based on direct evidence and indirect evidence and the use of smart contracts with blockchain to maintain the required trust values at runtime. We provide details on how to model and quantify the trust of all the stakeholders of a given network slice and how the blockchain smart contract can enforce the zero-trust requirements for all network slice stakeholders.
Safwan Elmadani, Salim Hariri, Sicong Shao
AICCSA2
2022 Toward An Experimental Federated 6G Testbed: A Federated Leaning Approach
abstract
With the development of the smart systems such as smart city, smart buildings, smart industries, the need for a highly reliable, scalable, and secure communications using high-data-rate and low latency networks such as 6G networks is increased. The artificial intelligence and machine learning (AI/ML) will be pervasive and of key relevance across the security technology stack and architecture in the 6G networks. Despite the advantages of the 6G networks, sophisticated cyberattacks can disrupt the operation of 6G critical infrastructures and associated services. In this paper, we present a novel methodology to create a federated cyber testbed as a service (FCTaaS) that can be offered as a ubiquitous cloud service. Due to the widespread usage of Machine Learning (ML) in critical decision processes of 5G/6G resource management and their applications, there is an exponential growth in cyberattacks to maliciously manipulate the ML algorithms and consequently influence their decision process in favor of the attackers. Currently, there are many isolated cyber testbeds; however, little research has focused on methods to automatically build a federated cyber testbed in general and especially in 6G testbeds. In this paper, we show how to use the FCTaaS services can be used to seamlessly compose a federated cyber testbed that allows researchers to experiment with and evaluate different algorithms to implement different algorithms to conduct data analytics, cybersecurity, and resilient algorithms. In particular, we will show how the FCTaaS can be used to develop highly efficient and accurate federated learning algorithms that can tolerate a wide range of attacks against ML algorithms such as data poisoning and ML model attacks.
Hisham A. Kholidy, Salim Hariri
AICCSA2
2022 A BERT-based Deep Learning Approach for Reputation Analysis in Social Media
abstract
Social media has become an essential part of the modern lifestyle, with its usage being highly prevalent. This has resulted in unprecedented amounts of data generated from users in social media, such as users' attitudes, opinions, interests, purchases, and activities across various aspects of their lives. Therefore, in a world of social media, where its power has shifted to users, actions taken by companies and public figures are subject to constantly being under scrutiny by influential global audiences. As a result, reputation management in social media has become essential as companies and public figures need to maintain their reputation to preserve their reputational capital. However, domain experts still face the challenge of lacking appropriate solutions to automate reliable online reputation analysis. To tackle this challenge, we proposed a novel reputation analysis approach based on the popular language model BERT (Bidirectional Encoder Representations from Transformers). The proposed approach was evaluated on the reputational polarity task using RepLab 2013 dataset. Compared to previous works, we achieved 5.8% improvement in accuracy, 26.9% improvement in balanced accuracy, and 21.8% improvement in terms of F-score.
Mohammad Wali Ur Rahman, Sicong Shao, Pratik Satam, Salim Hariri, Chris Padilla, Zoe Taylor, Carlos Nevarez
AICCSA4
2022 AI-based Arabic Language and Speech Tutor
abstract
In the past decade, we have observed a growing interest in using technologies such as artificial intelligence (AI), machine learning, and chatbots to provide assistance to language learners, especially in second language learning. By using AI and natural language processing (NLP) and chatbots, we can create an intelligent self-learning environment that goes beyond multiple-choice questions and/or fill in the blank exercises. In addition, NLP allows for learning to be adaptive in that it offers more than an indication that an error has occurred. It also provides a description of the error, uses linguistic analysis to isolate the source of the error, and then suggests additional drills to achieve optimal individualized learning outcomes. In this paper, we present our approach for developing an Artificial Intelligence-based Arabic Language and Speech Tutor (AI-ALST) for teaching the Moroccan Arabic dialect. The AI-ALST system is an intelligent tutor that provides analysis and assessment of students learning the Moroccan dialect at University of Arizona (UA). The AI-ALST provides a self-learned environment to practice each lesson for pronunciation training. In this paper, we present our initial experimental evaluation of the AI-ALST that is based on MFCC (Mel frequency cepstrum coefficient) feature extraction, bidirectional LSTM (Long Short-Term Memory), attention mechanism, and a cost-based strategy for dealing with class-imbalance learning. We evaluated our tutor on the word pronunciation of lesson 1 of the Moroccan Arabic dialect class. The experimental results show that the AI-ALST can effectively and successfully detect pronunciation errors and evaluate its performance by using$\boldsymbol{F}_{\mathbf{1}}$- score, accuracy, precision, and recall.
Sicong Shao, Saleem Alharir, Salim Hariri, Pratik Satam, Sonia Shiri, Abdessamad Mbarki
AICCSA3
2022 Energy-efficient and secure mobile fog-based cloud for the Internet of Things
Abdul Razaque, Yaser Jararweh, Bandar Alotaibi, Munif Alotaibi, Salim Hariri, Muder Almiani
Future Gener. Comput. Syst.5
2022 A Mobility-Aware Human-Centric Cyber-Physical System for Efficient and Secure Smart Healthcare
abstract
Cyber–physical systems (CPSs) have developed rapidly in recent years, contributing to an efficient integration between the cyber and physical worlds in intelligent and connected city environments. However, efficient mobility in a CPS is not well solved. Here, we present a prototype for a privacy-aware secure human-centric mobility-aware (SHM) model proposed and tested to analyze physical and human domains in IoT-based wireless sensor networks (WSNs). The proposed SHM model involves five modules: 1) sensor advertisements; 2) mobile sensor recruitment; 3) load balancing; 4) transmission guarantee; and 5) privacy with data-sharing phases. The proposed model is also validated using an accurate testing method that involves software and hardware tools and mathematical modeling to confirm secure communication. The model provides a tradeoff between energy efficiency and Quality-of-Service (QoS) requirements and compares the performance with other known models/protocols. Our testing process continued for four days, demonstrating that the SHM model provides compelling features of a secure CPS based on actual testing results. In practice, our model can be used in hospitals, as evident from validation in a real-life environment following the protocols.
Abdul Razaque, Fathi H. Amsaad 0001, Musbah Abdulgader, Bandar Alotaibi, Fawaz Alsolami 0001, Duisen Gulsezim, Saraju P. Mohanty, Salim Hariri
IEEE Internet Things J.8
2021 Multi-Layer Mapping of Cyberspace for Intrusion Detection
abstract
The ubiquity and vulnerability of computer applications make them ideal places for intrusion attacks that increase in intensity and complexity. Computer applications have a relationship with various networks, physical components, host devices, and users with different roles and requirements. Therefore, securing computer applications in such a complex and dynamic cyberspace is urgent and challenging. This paper attempts to tackle the challenges by proposing a Multi-Layer Abnormal Behaviors Analysis (MLABA) framework for intrusion detection associated with three layers (i.e., system, process, and network layers) in cyberspace for characterizing their normal operations and detect any abnormal behavior that might be triggered by malicious activities. The proposed technique was evaluated on several popular applications (i.e., Firefox, Opera, Chrome, and Ruby). The experimental results demonstrate the feasibility of MLABA framework that can detect the intrusion and abuse for applications.
Sicong Shao, Pratik Satam, Shalaka Satam, Khalid Al-Awady, Gregory Ditzler, Salim Hariri, Cihan Tunc
AICCSA6
2021 WIDS: An Anomaly Based Intrusion Detection System for Wi-Fi (IEEE 802.11) Protocol
abstract
Over the last few decades, the Internet has seen unprecedented growth, with over 4.57 billion active users as of July 2022, encompassing 59% of the global population. In recent years, we have seen an increase in mobile computing and the Internet of Things (IoT), allowing more users to communicate through the Internet using wireless devices. Modern Internet users use their wireless IoT devices for a wide variety of services that include cloud computing and storage, social networking, content services, online banking, shopping, to name a few. Moreover, with the omnipresence of IoT devices, wireless networks are used for services like device control, user authentication, etc. Wi-Fi is the network of choice for most of these wireless communications. Although Wi-Fi networks have improved over recent years, little has been done to secure Wi-Fi networks against attacks. In this article, we present a Wireless Intrusion Detection System (WIDS); an anomaly behavior analysis approach to detect attacks on Wi-Fi networks with high accuracy and low false alarms. In this approach, we model the normal behavior of the Wi-Fi protocol, using n-grams, and use machine learning models to classify Wi-Fi traffic flows as normal or malicious. We have extensively tested our approach on multiple datasets collected locally at the University of Arizona and AWID family of datasets. Our approach can successfully detect all attacks on Wi-Fi protocols with low false positives (0.0174) and a varying low rate of false negatives for different attacks.
Pratik Satam, Salim Hariri
IEEE Trans. Netw. Serv. Manag.2
2020 Multi-level Bluetooth Intrusion Detection System
abstract
Large scale deployment of IoT devices has made Bluetooth Protocol (IEEE 802.15.1) the wireless protocol of choice for close-range communications. Devices such as keyboards, smartwatches, headphones, computer mouse, and various wearable connecting devices use Bluetooth network for communication. Moreover, Bluetooth networks are widely used in medical devices like heart monitors, blood glucose monitors, asthma inhalers, and pulse oximeters. Also, Bluetooth has replaced cables for wire-free equipment in a surgical environment. In hospitals, devices communicate with one another, sharing sensitive and critical information over Bluetooth scatter-networks. Thus, it is imperative to secure the Bluetooth networks against attacks like Man in the Middle attack (MITM), eavesdropping attacks, and Denial of Service (DoS) attacks. This paper presents a Multi-Level Bluetooth Intrusion Detection System (ML-BIDS) to detect malicious attacks against Bluetooth devices. In the ML-IDS framework, we perform continuous device identification and authorization in Bluetooth networks following the zero-trust principle [ref]. The ML-BIDS framework includes an anomaly-based intrusion detection system (ABIDS) to detect attacks on the Bluetooth protocol. The ABIDS tracks the normal behavior of the Bluetooth protocol by comparing it with the Bluetooth protocol state machine. Bluetooth frame flows consisting of Bluetooth frames received over 10 seconds are split into n-grams to track the current state of the protocol in the state machine. We evaluated the performance of several machine learning algorithms like C4.5, Adaboost, SVM, Naive Bayes, Jrip, and Bagging to classify normal Bluetooth protocol flows from abnormal Bluetooth protocol flows. The ABIDS detects attacks on Bluetooth protocols with a precision of up to 99.6% and recall up to 99.6%. The ML-BIDS framework also performs whitelisting of the devices on the Bluetooth network to prevent unauthorized devices from connecting to the network. ML-BIDS uses a combination of the Bluetooth Address, mac address, and IP address to uniquely identify a Bluetooth device connecting to the network, and hence ensuring only authorized devices can connect to the Bluetooth network.
Shalaka Satam, Pratik Satam, Salim Hariri
AICCSA3
2020 Video Anomaly Detection using Pre-Trained Deep Convolutional Neural Nets and Context Mining
abstract
Anomaly detection is critically important for intelligent surveillance systems to detect in a timely manner any malicious activities. Many video anomaly detection approaches using deep learning methods focus on a single camera video stream with a fixed scenario. These deep learning methods use large-scale training data with large complexity. As a solution, in this paper, we show how to use pre-trained convolutional neural net models to perform feature extraction and context mining, and then use denoising autoencoder with relatively low model complexity to provide efficient and accurate surveillance anomaly detection, which can be useful for the resource-constrained devices such as edge devices of the Internet of Things (IoT). Our anomaly detection model makes decisions based on the high-level features derived from the selected embedded computer vision models such as object classification and object detection. Additionally, we derive contextual properties from the high-level features to further improve the performance of our video anomaly detection method. We use two UCSD datasets to demonstrate that our approach with relatively low model complexity can achieve comparable performance compared to the state-of-the-art approaches.
Chongke Wu, Sicong Shao, Cihan Tunc, Salim Hariri
AICCSA4
2020 Paralinguistic Classification of Mask Wearing by Image Classifiers and Fusion
Jeno Szep, Salim Hariri
INTERSPEECH2
2020 Dynamic power management for value-oriented schedulers in power-constrained HPC system
Nirmal Kumbhare, Ali Akoglu, Aniruddha Marathe, Salim Hariri, Ghaleb Abdulla
Parallel Comput.4
2020 A Value-Oriented Job Scheduling Approach for Power-Constrained and Oversubscribed HPC Systems
abstract
In this article, we investigate limitations in the traditional value-based algorithms for a power-constrained HPC system and evaluate their impact on HPC productivity. We expose the trade-off between allocating system-wide power budget uniformly and greedily under different system-wide power constraints in an oversubscribed system. We experimentally demonstrate that, under the tightest power constraint, the mean productivity of the greedy allocation is 38 percent higher than the uniform allocation whereas, under the intermediate power constraint, the uniform allocation has a mean productivity of 6 percent higher than the greedy allocation. We then propose a new algorithm that adapts its behavior to deliver the combined benefits of the two allocation strategies. We design a methodology with online retraining capability to create application-specific power-execution time models for a class of HPC applications. These models are used in predicting the execution time of an application on the available resources at the time of making scheduling decisions in the power-aware algorithms. We evaluate the proposed algorithm using emulation and simulation environments, and show that our adaptive strategy results in improving HPC resource utilization while delivering a mean productivity that is almost the same as the best performing algorithm across various system-wide power constraints.
Nirmal Kumbhare, Aniruddha Marathe, Ali Akoglu, Howard Jay Siegel, Ghaleb Abdulla, Salim Hariri
IEEE Trans. Parallel Distributed Syst.6
2019 Autonomic Resource Management for Power, Performance, and Security in Cloud Environment
abstract
High performance computing is widely used for large-scale simulations, designs and analysis of critical problems especially through the use of cloud computing systems nowadays because cloud computing provides ubiquitous, on-demand computing capabilities with large variety of hardware configurations including GPUs and FPGAs that are highly used for high performance computing. However, it is well known that inefficient management of such systems results in excessive power consumption affecting the budget, cooling challenges, as well as reducing reliability due to the overheating and hotspots. Furthermore, considering the latest trends in the attack scenarios and crypto-currency based intrusions, security has become a major problem for high performance computing. Therefore, to address both challenges, in this paper we present an autonomic management methodology for both security and power/performance. Our proposed approach first builds knowledge of the environment in terms of power consumption and the security tools' deployment. Next, it provisions virtual resources so that the power consumption can be reduced while maintaining the required performance and deploy the security tools based on the system behavior. Using this approach, we can utilize a wide range of secure resources efficiently in HPC system, cloud computing systems, servers, embedded systems, etc.
Farah Fargo, Olivier Franza, Cihan Tunc, Salim Hariri
AICCSA4
2019 One-Class Classification with Deep Autoencoder Neural Networks for Author Verification in Internet Relay Chat
abstract
Social networks are highly preferred to express opinions, share information, and communicate with others on arbitrary topics. However, the downside is that many cybercriminals are leveraging social networks for cyber-crime. Internet Relay Chat (IRC) is the important social networks which can grant the anonymity to users by allowing them to connect channels without sign-up process. Therefore, IRC has been the playground of hackers and anonymous users for various operations such as hacking, cracking, and carding. Hence, it is urgent to study effective methods which can identify the authors behind the IRC messages. In this paper, we design an autonomic IRC monitoring system, performing recursive deep learning for classifying threat levels of messages and develop a novel author verification approach with one-class classification with deep autoencoder neural networks. The experimental results show that our approach can successfully perform effective author verification for IRC users.
Sicong Shao, Cihan Tunc, Amany Al-Shawi, Salim Hariri
AICCSA4
2019 Automated Twitter Author Clustering with Unsupervised Learning for Social Media Forensics
abstract
Twitter is one of the key social media platforms, which is also used for cyber-crimes. Hence, monitoring and detecting the malicious activities of Twitter users is critically important for cybersecurity concerns around the globe since cybercriminals are heavily using Twitter for illegal purpose. It is increasingly common for cybercriminals signing up many accounts while masquerading different users for malicious behaviors. This fact has brought forward the issue of identifying the authors of Twitter accounts. In this paper, we propose a novel approach through a combination of feature extraction methods and then convert high dimensional data to kernel matrix for Twitter author clustering. The experimental results show that our approach can be used to effectively identify the groups among more than one hundred Twitter aliases even without knowing the number of authors.
Sicong Shao, Cihan Tunc, Amany Al-Shawi, Salim Hariri
AICCSA4
2019 Adaptive Power Reallocation for Value-Oriented Schedulers in Power-Constrained HPC
abstract
In the exascale era, HPC systems are expected to operate under different system-wide power-constraints. For such power-constrained systems, improving per-job flops-per-watt may not be sufficient to improve the total HPC productivity as more number of scientific applications with different compute intensities are migrating to the HPC systems. To measure HPC productivity for such applications, we utilize a monotonically decreasing time-dependent value function, called job-value, with each application. A job-value function represents the value of completing a job for an organization. We begin by exploring the trade-off between two commonly used static power allocation strategies (uniform and greedy) in a power-constrained oversubscribed system. We simulate a large-scale system and demonstrate that, at the tightest power constraint, the greedy allocation can lead to 30% higher productivity compared to the uniform allocation whereas, the uniform allocation can gain up to 6% higher productivity at the relaxed power constraint. We then propose a new dynamic power allocation strategy that utilizes power-performance models derived from offline data. We use these models for reallocating power from running jobs to newly arrived jobs to increase overall system utilization and productivity. In our simulation study, we show that compared to static allocation, the dynamic power allocation policy improves node utilization and job completion rates by 20% and 9%, respectively, at the tightest power constraint. Our dynamic approach consistently earns up to 8% higher productivity compared to the best performing static strategy under different power constraints.
Nirmal Kumbhare, Aniruddha Marathe, Ali Akoglu, Salim Hariri, Ghaleb Abdulla
PDCAT4
2019 Context aware intrusion detection for building automation systems
Zhiwen Pan, Salim Hariri
Comput. Secur.2
2019 Utility-based resource management in an oversubscribed energy-constrained heterogeneous environment executing parallel applications
Dylan Machovec, Bhavesh Khemka, Nirmal Kumbhare, Sudeep Pasricha, Anthony A. Maciejewski, Howard Jay Siegel, Ali Akoglu, Gregory A. Koenig, Salim Hariri, Cihan Tunc, Michael Wright, Marcia Hilton, Jendra Rambharos, Christopher Blandin, Farah Fargo, Ahmed Louri, Neena Imam
Parallel Comput.9
2019 Implementation of scalable bidomain-based 3D cardiac simulations on a graphics processing unit cluster
Ehsan Esmaili, Ali Akoglu, Salim Hariri, Talal Moukabary
J. Supercomput.3
2018 Malicious HTML File Prediction: A Detection and Classification Perspective with Noisy Data
abstract
Cybersecurity plays a critical role in protecting sensitive information and the structural integrity of networked systems. As networked systems continue to expand in numbers as well as in complexity, so does the threat of malicious activity and the necessity for advanced cybersecurity solutions. Furthermore, both the quantity and quality of available data on malicious content as well as the fact that malicious activity continuously evolves makes automated protection systems for this type of environment particularly challenging. Not only is the data quality a concern, but the volume of the data can be quite small for some of the classes. This creates a class imbalance in the data used to train a classifier; however, many classifiers are not well equipped to deal with class imbalance. One such example is detecting malicious HMTL files from static features. Unfortunately, collecting malicious HMTL files is extremely difficult and can be quite noisy from HTML files being mislabeled. This paper evaluates a specific application that is afflicted by these modern cybersecurity challenges: detection of malicious HTML files. Previous work presented a general framework for malicious HTML file classification that we modify in this work to use a χ2feature selection technique and synthetic minority oversampling technique (SMOTE). We experiment with different classifiers (i.e., AdaBoost, Gentle-Boost, RobustBoost, RusBoost, and Random Forest) and a pure detection model (i.e., Isolation Forest). We benchmark the different classifiers using SMOTE on a real dataset that contains a limited number of malicious files (40) with respect to the normal files (7,263). It was found that the modified framework performed better than the previous framework's results. However, additional evidence was found to imply that algorithms which train on both the normal and malicious samples are likely overtraining to the malicious distribution. We demonstrate the likely overtraining by determining that a subset of the malicious files, while suspicious, did not come from a malicious source.
Samuel Hess, Pratik Satam, Gregory Ditzler, Salim Hariri
AICCSA4
2018 Security Framework for IoT Cloud Services
abstract
The premise of the Internet of Things (IoT) is not only to connect computers and mobile devices, but also interconnect smart buildings, homes, and cities, as well as electrical and water grids, automobiles, and airplanes. IoT will lead to the development of a wide range of advanced information services that need to be processed in real-time and require data centers with large storage and computing power. The integration of IoT with Cloud Computing can bring not only the required computational power and storage capacity, but they enable IoT services to be pervasive, cost-effective, and can be accessed from anywhere using any device (mobile or stationary). However, IoT infrastructures and services will introduce grand security challenges due to the significant increase in the attack surface, complexity, heterogeneity and number of resources. In order to deal with such challenges, in this paper we introduce an IoT Framework to build trustworthy and secure IoT applications and services. The framework enables developers to consider security issues at all IoT levels and integrate security algorithms with the functions and services offered in each layer instead of considering security in an ad-hoc and afterthought manner. We show the applicability of our methodology to secure and protect IoT services at cloud level.
Cihan Tunc, Salim Hariri
AICCSA3
2018 Bluetooth Intrusion Detection System (BIDS)
abstract
With the rapid deployment of IOT devices, Bluetooth networks, which form Personal Area Networks(PAN), have become the wireless network of choice for small range/indoor communications networks. Bluetooth is widely used to deliver audio streams (e.g.: Bluetooth headphones, Music systems in cars), connecting peripherals devices to more powerful devices (e.g.: keyboards to computers), connecting wearable technology like smart watches, heart monitors and fitness trackers. It's imperative that Bluetooth networks (like other wireless networks) are secure against cyberattacks such as Man In The Middle Attacks(MITM), Denial of Service attacks(DoS), etc. Moreover, Bluetooth is used heavily in mobile devices/ sensors, and consequently they become sensitive to battery utilization attacks; this type of attacks requires the Bluetooth devices to be secure against different battery draining attacks. As a part of this paper we present an anomaly-based intrusion detection system for Bluetooth networks; Bluetooth IDS (BIDS). The BIDS use an n-gram based approach to characterize the normal behavior of the Bluetooth protocol. Smoothing techniques like Jelinek-Mercer smoothing was used to improve the machine learning algorithm used for detecting abnormal Bluetooth operations. Machine learning algorithms like C4.5, AdaBoostMl, SVM, Naïve Bayes, RIPPER, Bagging were used to build the behavior models for the Bluetooth protocol. The developed models had high accuracy with precision up to 99.6% and recall up to 99.6%.
Pratik Satam, Shalaka Satam, Salim Hariri
AICCSA3
2018 Autonomic Author Identification in Internet Relay Chat (IRC)
abstract
With the advances in Internet technologies and services, the social media has been gaining excessive popularity, especially because these technologies provide anonymity where they use nicknames to post their messages. Unfortunately, the anonymity feature has been exploited by the cyber-criminals to hide their identities and their operations. Hence, there is a growing interest in cybersecurity research domain to identify the authors of malicious messages and activities. Internet Relay Chat (IRC) channels are widely used to exchange messages and information among malicious users involved in cybercrimes. In this paper, we present an autonomic author identification technique based on personality profile and analysis of IRC messages. We first monitor the IRC channels using our autonomic bots and then create a personality profile for each targeted author. We demonstrate that personality analysis for author detection/identification is an efficient approach and has high detection rates.
Sicong Shao, Cihan Tunc, Amany Al-Shawi, Salim Hariri
AICCSA4
2018 Resilient service provisioning in cloud based data centers
Mahmoud Al-Ayyoub, Muneera Al-Quraan, Yaser Jararweh, Elhadj Benkhelifa, Salim Hariri
Future Gener. Comput. Syst.5
2017 IoT Security Framework for Smart Water System
abstract
The Internet of Things (IoT) will connect not only computers and mobile devices, but it will also interconnect smart buildings, homes, and cities. The IoT take advantage of the latest communication technologies in order to provide optimal and reliable services to Smart Cities (SC). The backbone of SC are the Critical Infrastructures such as the city's water system. In SC, the water system benefits from the development of automation and communication technologies to create smart environments which are more efficient in the use of the available resources; we call it Smart Water System (SWS). In this paper we present a multilayer architecture to integrate the SWS to the IoT, making it available from everywhere at any time. However, with the introduction of IoT we will be experiencing grand challenges to secure and protect its advanced information services due to the significant increase of the attack surface, complexity, heterogeneity, and number of interconnected resources. We also introduce an IoT Framework for SWSs to build trustworthy and secure applications and services. The framework enables developers to consider security issues at all IoT layers and integrate security algorithms with the functions and services offered in each layer instead of considering security in an ad-hoc and after thought manner. We show how this framework can be used to develop highly secure and trustworthy SWS services and how to apply our Anomaly Behavior Analysis methodology to secure and protect these services against any type of attacks.
Daniela Ibarra, Ashamsa Vijay, Salim Hariri
AICCSA4
2016 Just In Time Architecture (JITA) for dynamically composable data centers
abstract
Computer manufacturers, software developers, and service providers spend significant time and resources to ensure that they can optimally support one class of applications. However, they cannot cope with the dynamic and continuous changes in applications and workload types, and consequently their offered services become unstable, fragile, and cannot guarantee the required Quality of Service (QoS). Furthermore, it becomes prohibitively expensive to build data centers (DCs) that are optimized for fixed types of workloads and businesses or to scale up for accommodating new growth in heterogeneous workload demands. Consequently, it is critically important that the architecture of next generation DCs is dynamically customizable to support a wide range of application types or businesses under constrained resources. In this paper, we present some design concepts for our Just In Time Architecture (JITA), a novel data center design to overcome the composable DC challenges by dynamically interconnecting DC components into a virtual DC (VDC) that is optimized to the service level objectives for each class of applications. We present how we can use optical waveguide links to build a passive crossbar that directly interconnects all DC resources at the required throughput and latency.
Nirmal Kumbhare, Cihan Tunc, Salim Hariri, Ivan B. Djordjevic, Ali Akoglu, Howard Jay Siegel
AICCSA3
2016 Anomaly behavior analysis for building automation systems
abstract
Advanced networking technology and increasing information services have led to extensive interconnection between Building Automation Systems (BAS) communication protocols and Internet, which makes Fog computing service a potential solution for automation of building end devices. However, the connection to Internet and public networks increases significantly the risk of the BAS networks being attacked due mainly to the significant increase in the attack surface. In this paper, we present an anomaly based Intrusion Detection System (IDS) that combines context awareness and Cyber DNA techniques to detect network misbehavior from security and functionality perspectives. We developed runtime models for service interactions and functionality patterns by modeling the information that is continuously acquired from building assets into two novel data structures: Protocol Context Aware and sensor-DNA. Our IDS uses Anomaly Behavior Analysis techniques to accurately detect anomalous events triggered by cyber-attacks or any failure. A classification of detected attacks allow our IDS to automatically launch protective countermeasures. We evaluate our approach in the Smart Building testbed developed at the University of Arizona Center for Cloud and Autonomic Computing, by launching several cyber-attacks that exploit the generic vulnerabilities of BAS.
Zhiwen Pan, Salim Hariri
AICCSA3
2016 Anomaly behavior analysis of website vulnerability and security
abstract
The world wide web has grown exponentially over the previous decade in terms of its size that is currently over a billion sties, as well as the number of users. In fact, web usage has become pervasive to touch all aspects of our life, economy and education. These rapid advances have also significantly increase the vulnerabilities of websites that are being hacked on a daily basis. According to White Hat security's “2015 Website Security Statistics Report” more than 86% of all websites have one or more critical vulnerability and the likelihood of information leakage is 56%. With no effective website security measures in place, one can expect the website security to be even more critical. The main research goal of this paper is to overcome this challenge by presenting an online anomaly behavior analysis of websites (e.g., HTML files) to detect any malicious codes or pages that have been injected by web attacks. Our anomaly analysis approach utilizes feature selection, data mining, data analytics and statistical techniques to identify accurately the webpage contents that have been compromised or can be exploited by attacks such as phishing attacks, cross site scripting attacks, html injection attacks, malware insertion attacks, just to name a few. We have validated our approach on more than 10,000 files and showed that our approach can detect malicious HTML files with a true positive rate of 99% and a false positive rate of 0.8% for abnormal files.
Pratik Satam, Douglas Kelly, Salim Hariri
AICCSA3
2016 IoT Security Development Framework for building trustworthy Smart car services
abstract
The Internet of Things (IoT) will connect not only computers and mobile devices, but it will also interconnect Smart cars, buildings, homes, and cities, as well as electrical grids, gas, and water networks, automobiles, airplanes, etc. However, with the introduction of IoT, we will be experiencing grand challenges to secure and protect its advanced information services due to the significant increase of the attack surface, complexity, heterogeneity and number of interconnected resources. In this paper, we present an IoT Security Development Framework (ISDF) to build trustworthy and highly secure applications and services. The ISDF enables developers to consider security issues at all IoT layers and integrate security algorithms with the functions and services offered in each layer rather than considering security in an ad-hoc and after thought manner. We also show how this framework can be used to develop highly secure and trustworthy Vehicle Information and management Portal (VIMP) services and how to apply our Anomaly Behavior Analysis (ABA) methodology to secure and protect these services against any type of attacks.
Shalaka Satam, Salim Hariri, Clarisa Grijalva-Lugo, Helena Berkenbrock
ISI3
2015 Anomaly Behavior Analysis System for ZigBee in smart buildings
abstract
Smart Building (SB) exploits advances in information and communication technologies in order to provide the next generation of information and automation services that will significantly reduce operational costs and improve performance and efficiency. SB elements are typically interconnected using short range wireless communication technologies such as ZigBee, which is the most used wireless communication protocol for SBs. However, ZigBee protocol has multiple vulnerabilities that can be exploited by cyberattacks. In this paper, we present an Anomaly Behavior Analysis System (ABAS) for ZigBee protocol to be used in SBs. Our ABAS can detect both known and unknown ZigBee attacks with a high detection rate and low false alarms. Additionally, after detection, our system classifies the attack based on the impact, origin, and destination. We evaluate our approach by launching many attack scenarios such as DoS, Flooding, and Pulse DoS attacks, and then we compare our results with other intrusion detection systems such as secure HAN, signature IDS, and specification IDS.
Bilal Al Baalbaki, Cihan Tunc, Salim Hariri, Youssif B. Al-Nashif
AICCSA4
2015 DDSGA: A Data-Driven Semi-Global Alignment Approach for Detecting Masquerade Attacks
abstract
A masquerade attacker impersonates a legal user to utilize the user services and privileges. The semi-global alignment algorithm (SGA) is one of the most effective and efficient techniques to detect these attacks but it has not reached yet the accuracy and performance required by large scale, multiuser systems. To improve both the effectiveness and the performances of this algorithm, we propose the Data-Driven Semi-Global Alignment, DDSGA approach. From the security effectiveness view point, DDSGA improves the scoring systems by adopting distinct alignment parameters for each user. Furthermore, it tolerates small mutations in user command sequences by allowing small changes in the low-level representation of the commands functionality. It also adapts to changes in the user behaviour by updating the signature of a user according to its current behaviour. To optimize the runtime overhead, DDSGA minimizes the alignment overhead and parallelizes the detection and the update. After describing the DDSGA phases, we present the experimental results that show that DDSGA achieves a high hit ratio of 88.4 percent with a low false positive rate of 1.7 percent. It improves the hit ratio of the enhanced SGA by about 21.9 percent and reduces Maxion-Townsend cost by 22.5 percent. Hence, DDSGA results in improving both the hit ratio and false positive rates with an acceptable computational overhead.
Hisham A. Kholidy, Fabrizio Baiardi, Salim Hariri
IEEE Trans. Dependable Secur. Comput.3
2015 Wireless Anomaly Detection Based on IEEE 802.11 Behavior Analysis
abstract
Wireless communication networks are pervading every aspect of our lives due to their fast, easy, and inexpensive deployment. They are becoming ubiquitous and have been widely used to transfer critical information, such as banking accounts, credit cards, e-mails, and social network credentials. The more pervasive the wireless technology is going to be, the more important its security issue will be. Whereas the current security protocols for wireless networks have addressed the privacy and confidentiality issues, there are unaddressed vulnerabilities threatening their availability and integrity (e.g., denial of service, session hijacking, and MAC address spoofing attacks). In this paper, we describe an anomaly based intrusion detection system for the IEEE 802.11 wireless networks based on behavioral analysis to detect deviations from normal behaviors that are triggered by wireless network attacks. Our anomaly behavior analysis of the 802.11 protocols is based on monitoring the n-consecutive transitions of the protocol state machine. We apply sequential machine learning techniques to model the n-transition patterns in the protocol and characterize the probabilities of these transitions being normal. We have implemented several experiments to evaluate our system performance. By cross validating the system over two different wireless channels, we have achieved a low false alarm rate (<;0.1%). We have also evaluated our approach against an attack library of known wireless attacks and has achieved more than 99% detection rate.
Hamid Reza Alipour, Youssif B. Al-Nashif, Pratik Satam, Salim Hariri
IEEE Trans. Inf. Forensics Secur.4
2015 Parallel Simulation of Complex Evacuation Scenarios with Adaptive Agent Models
abstract
Simulation study on evacuation scenarios has gained tremendous attention in recent years. Two major research challenges remain along this direction: (1) how to portray the effect of individuals' adaptive behaviors under various situations in the evacuation procedures and (2) how to simulate complex evacuation scenarios involving huge crowds at the individual level due to the ultrahigh complexity of these scenarios. In this study, a simulation framework for general evacuation scenarios has been developed. Each individual in the scenario is modeled as an adaptable and autonomous agent driven by a weight-based decision-making mechanism. The simulation is intended to characterize the individuals' adaptable behaviors, the interactions among individuals, among small groups of individuals, and between the individuals and the environment. To handle the second challenge, this study adopts GPGPU to sustain massively parallel modeling and simulation of an evacuation scenario. An efficient scheme has been proposed to minimize the overhead to access the global system state of the simulation process maintained by the GPU platform. The simulation results indicate that the “adaptability” in individual behaviors has a significant influence on the evacuation procedure. The experimental results also exhibit the proposed approach's capability to sustain complex scenarios involving a huge crowd consisting of tens of thousands of individuals.
Dan Chen 0001, Lizhe Wang 0001, Albert Y. Zomaya, Minggang Dou, Jingying Chen 0001, Ze Deng, Salim Hariri
IEEE Trans. Parallel Distributed Syst.7
2014 A Network Protection Framework for DNP3 over TCP/IP protocol
abstract
The pervasive deployment of intelligent devices in the critical infrastructures sector and the high dependency of these devices on the Internet motivated attackers to target the communication and control protocols of these devices. DNP3 over TCP/IP is among those protocols that are widely used as communication and control protocols in critical infrastructures. Due to the facts that security was not part of the goals for designing the DNP3 and the incompetent of current protection systems, adversary can easily succeed in attacking DNP3 devices and network. In this paper, we present an Autonomic Network Protection Framework for DNP3 over TCP/IP that detects old attacks that cannot be prevented by the legacy DNP3 security devices as well as new attacks. The system's detection module is based on rule-based anomaly intrusion detection. We evaluated the effectiveness of the generated rules in detecting anomalies through both offline and online testing. Both the false positive and the false negative rates of our approach are quite low. In addition, we present a classification technique and an access control mechanism to provide autonomic network protection.
Salim Hariri, Youssif B. Al-Nashif
AICCSA2
2014 Anomaly based intrusion detection for Building Automation and Control networks
abstract
Advanced networking technology and increasing information services have led to extensive interconnection between Building Automation and Control (BAC) networks and Internet. The connection to Internet and public networks massively elevates the risk of the BAC networks being attacked. In this paper, we present a framework for a rule based anomaly detection of Building Automation and Control networks. We develop an anomaly based intrusion detection system to the building network by training the system with dataflows that are dynamically captured from the Fire Alarm System testbed using the BACnet Protocol Monitoring module. The rules acquired from the offline data mining procedure can detect attacks against the BACnet protocol with an extremely low false positive rate. We evaluate our approach by launching several attacks that exploit the generic vulnerabilities of the BACnet Protocol. A classification of detected attacks is introduced at the end.
Zhiwen Pan, Salim Hariri, Youssif B. Al-Nashif
AICCSA2
2014 A fictitious play-based response strategy for multistage intrusion defense systems
abstract
ABSTRACT The recent developments of advanced intrusion detection systems in the cyber security field provide opportunities to proactively protect the computer network systems and minimize the impacts of attackers on network operations. This paper is intended to assist the network defender find its best actions to defend against multistage attacks. The possible sequences of interactions between the attackers and the network defender are modeled as a two‐player non‐zero‐sum non‐cooperative dynamic multistage game with incomplete information. The players are assumed to be rational. They take turns in making decisions by considering previous and possible future interactions with the opponent and use Bayesian analysis after each interaction to update their knowledge about the opponents. We propose a Dynamic game tree‐based Fictitious Play (DFP) approach to describe the repeated interactive decisions of the players. Each player finds its best moves at its decision nodes of the game tree by using multi‐objective analysis. All possibilities are considered with their uncertain future interactions, which are based on learning of the opponent's decision process (including risk attitude and objectives). Instead of searching the entire game tree, appropriate future time horizons are dynamically determined for both players. In the DFP approach, the defender keeps tracking the opponent's actions, predicts the probabilities of future possible attacks, and then chooses its best moves. Thus, a new defense algorithm, called Response by DFP (RDFP), is developed. Numerical experiments show that this approach significantly reduces the damage caused by multistage attacks and it is also more efficient than other related algorithms. Copyright © 2013 John Wiley & Sons, Ltd.
Yi Luo 0008, Ferenc Szidarovszky, Youssif B. Al-Nashif, Salim Hariri
Secur. Commun. Networks4
2013 Autonomic Critical Infrastructure Protection (ACIP) system
abstract
The dependency of critical infrastructures on the Supervisory Control And Data Acquisition (SCADA) systems has increased rapidly in the last few years to perform remote monitoring and control services for a wide range of utilities such as power distribution, gas production, and waste water treatment. The trend toward operating the grid over IP networks using open standard protocols, and the growing number of attacks targeting critical infrastructure made the security of SCADA systems an important research issue. Most of the currently used SCADA communication protocols have no encryption, authentication, or authorization, which makes them vulnerable and easy target for cyber-attacks. This paper presents an Autonomic Critical Infrastructure Protection (ACIP) system that is based on anomaly-based intrusion detection and autonomic computing to secure the control functions and management tasks of critical infrastructure control systems with a little or no involvement from the users or administrators. We will show how we applied ACIP to the widely used Modbus communication protocol to securely transfer commands and data between RTUs and industrial control systems in smart grids.
Bilal Al Baalbaki, Youssif B. Al-Nashif, Salim Hariri, Douglas Kelly
AICCSA3
2012 Cardiac simulation on multi-GPU platform
Venkata Krishna Nimmagadda, Ali Akoglu, Salim Hariri, Talal Moukabary
J. Supercomput.3
2011 Application attack detection system (AADS): An anomaly based behavior analysis approach
abstract
Network security, especially application layer security has gained importance with the rapid growth of web-based applications. Anomaly based approaches that profile the network traffic and look for abnormalities are effective against zero-day attacks. The complex nature of the web traffic, availability of multiple applications, privacy concerns and its own limitations make the development of such anomaly-based systems difficult. This paper proposes a framework for application layer anomaly detection. The framework uses a multiple model approach to detect anomalies. The framework encompasses a dedicated training phase to model the specific network traffic and a detection phase that can be deployed in real time. The framework has been applied to HTTP application traffic and multiple models have been developed. The experimental evaluation results of the AADS using multiple attack vectors have achieved a detection rate of almost 100%. In addition, the AADS has a false positive rate of 0.03%.
Ram Prasad Viswanathan, Youssif B. Al-Nashif, Salim Hariri
AICCSA3
2010 Design and evaluation of a self-healing Kepler for scientific workflows
abstract
Kepler is a popular open source scientific workflow (SWF) as it simplifies the effort required to construct complex data flow models through a visual interface. As the complexity of the workflow applications that will run on heterogeneous distributed systems increases, fault management becomes a critical design issue for large scale scientific and engineering applications. Due to the long execution times of these applications, it is important that they are fault tolerant; i.e. the workflow application can recover gracefully from faults without the need to restart the application from the beginning. The current implementation of Kepler tool does not support fault tolerance or recovery mechanisms. In this paper, we extend the Kepler capabilities to support fault tolerant scientific workflow (FT-SWF) with a checkpoint mechanism where corrective measures are taken seamlessly in an autonomic manner whenever a fault is detected. To the best of our knowledge, this is the first approach on adding autonomic operations to Kepler. We have evaluated the FT-Kepler on a distributed application used by ecosystem researchers. We evaluated the performance of the workflow with hardware and software based fault scenarios in terms of execution time, recovery time, and the checkpoint mechanism overhead. The experimental evaluations indicate that the checkpoint mechanism adds negligible overhead to the total execution time of the workflow and as the fault rate increases, the number of checkpoints should be increased.
Arjun Hary, Ali Akoglu, Youssif B. Al-Nashif, Salim Hariri, Darrel Jenerette
HPDC4
2009 End-to-end mobility solution for vertical handoff between heterogeneous wireless networks
abstract
The last decade has seen explosive growth in the development of mobile applications. This has increased the demand on the wireless communication services. The capability to achieve wireless access anywhere, anytime, and anyplace has become common expectation as it provides significant flexibility and freedom in mobility. But to achieve global mobility in heterogeneous networks for any mobile device requires seamless connectivity using vertical handoff. Since none of the existing wireless frameworks provide practical solutions for vertical handoff. End-to-End Vertical Handoff (E2EVH) proposed in this paper offers a new concept to perform vertical handoff between heterogeneous wireless networks. To deliver network services without interruption, E2EVH present a novel design to monitor the network availability, it then picks the best accessible network for application layer. Since this approach relies only on existing technologies, deployed protocols and lightweight calculations, our approach can be easily implemented. In this paper, we present a proof-of-concept of E2EVH, and preliminary simulation results using OPNET Modeler 14.5. The results for different tested scenarios indicate the effectiveness of the proposed approach. Future research activities will integrate several additional wireless technologies that are presented and discussed in the paper.
Iyad Alkhayat, Salim Hariri
AICCSA3
2009 Accelerated discovery through integration of Kepler with data turbine for ecosystem research
abstract
There is a need for accelerated discovery cycles (ADCs) for integrating experimental and observational data to capture large-scale dynamic ecosystem complexity, to instantly process massive datasets, to test contrasting mechanistic models and to drive the next set of experiments. The overreaching objective is to enable ADCs by coupling advances in computational models and cyber-systems with the unique experimental infrastructure of Biosphere 2 (B2), a large-scale earth system science facility now under management by the University of Arizona. In the context of ADCs, there is a need for software development environment for modeling complex systems and a middleware for data streaming from the field into the models. Kepler is an open source tool that enables the end user to design scientific workflows in order to manage scientific data and perform complex analysis on the data. Ring buffered network bus (RBNB) data turbine is a middleware system that is used to integrate sensor-based environment observing systems with data processing systems. Currently the integration between Kepler and data turbine is limited to reading from the data turbine only. In ADC, multiple hypotheses are tested with different assimilation models. These models run on a distributed computing environment, therefore capability of simultaneous reads and writes to the data turbine is a necessity. In this paper we show how to integrate Kepler with RBNB data turbine to achieve this capability. We also exploit the open-source features of Kepler system and create customized processing models in order to accelerate and automate the experiments in ecosystems research. We describe in further details our implementation approach to enable future studies on Kepler and data turbine integration.
Yaser Jararweh, Arjun Hary, Youssif B. Al-Nashif, Salim Hariri, Ali Akoglu, Darrel Jenerette
AICCSA4
2009 A game theory based risk and impact analysis method for Intrusion Defense Systems
abstract
An enormous amount of functions in our everyday life became dependent on computer networks. Network attacks become more sophisticated and perplexing. Defending against multi-stage attacks is a challenging process in intrusion defense systems (IDS) due to their complexity. This paper presents a game theory method to analyze the risk and impact of multi-stage attacks in IDS. In this method, the interactions between the attacker and the administrator are modeled as a non-cooperative zero-sum multistage game and it is modeled as a minmax game tree where the attacker is the leader and the administrator is the follower. Alternating the actions between the administrator and the attacker forms the game tree, each of them will be allowed to play a single action at any given time. In this work, a new multi-stage attacker defender (MAD) algorithm is developed to help the administrator in defending against multi-stage attacks. The believes of the attacker and the administrator are updated based on the analysis of the life-cycle for the multi-stage attacks to reduce the horizon effect.
Yi Luo 0008, Ferenc Szidarovszky, Youssif B. Al-Nashif, Salim Hariri
AICCSA4
2009 Self-Protection against Attacks in an Autonomic Computing Environment
Guangzhi Qu, Osamah A. Rawashdeh, Salim Hariri
CAINE3
2009 An Adaptive Interleaving Technique for Memory Performance-per-Watt Management
abstract
With the increased complexity of platforms coupled with data centers' servers sprawl, power consumption is reaching unsustainable limits. Researchers have addressed data centers' performance-per-watt management at different hierarchies going from server clusters to servers to individual components within the server platform. This paper addresses performance-per-watt maximization of memory subsystems in a data center. Traditional memory power management techniques rely on profiling the utilization of memory modules and transitioning them to some low-power mode when they are sufficiently idle. However, fully interleaved memory presents an interesting research challenge because data striping across memory modules reduces the idleness of individual modules to warrant transitions to low-power states. In this paper, we present a novel technique for performance-per-watt maximization of interleaved memory by dynamically reconfiguring (expanding or contracting) the degree of interleaving to adapt to incoming workload. The reconfigured memory hosts the application's working set on a smaller set of modules in a manner that exploits the platform's memory hierarchy architecture. This creates the opportunity for the remaining memory modules to transition to low-power states and remain in those states for as long as the performance remains within given acceptable thresholds. The memory power expenditure is minimized subject to application memory requirements and end-to-end memory access delay constraints. This is formulated as a performance-per-watt maximization problem and solved using an analytical memory power and performance model. Our technique has been validated on a real server using SPECjbb benchmark and on a trace-driven memory simulator using SPECjbb and gcc memory traces. On the server, our techniques are shown to give about 48.8 percent (26.7 kJ) energy savings compared to traditional techniques measured at 4.5 percent. The maximum improvement in performance-per-watt was measured at 88.48 percent. The simulator showed 89.7 percent improvement in performance-per-watt compared to the best performing traditional technique.
Bithika Khargharia, Salim Hariri, Mazin S. Yousif
IEEE Trans. Parallel Distributed Syst.2
2008 Autonomic power and performance management of high-performance servers
abstract
With the increased complexity of platforms coupled with data centers' servers sprawl, power consumption is reaching unsustainable limits. Researchers have addressed data centers' power & performance management at different hierarchies going from server clusters to servers to individual components within the server. This paper presents a novel technique for autonomic power & performance management of a high-performance server platform that consists of multi-core processor and multi-rank memory subsystems. Both the processor and/or the memory subsystem are dynamically reconfigured (expanded or contracted) to suit the application resource requirements. The reconfigured platform creates the opportunity for power savings by transitioning any unused platform capacity (processor/memory) into low-power states for as long as the platform performance remains within given acceptable thresholds. The platform power expenditure is minimized subject to platform performance parameters, which is formulated as an optimization problem. Our experimental results show around 58.33% savings in power as compared to static power management techniques.
Bithika Khargharia, Salim Hariri, Wael Kdouh, Manal Houri, Hesham El-Rewini, Mazin S. Yousif
IPDPS2
2007 Self-Configuration of Network Security
abstract
The proliferation of networked systems and services along with their exponential growth in complexity and size has increased the control and management complexity of such systems and services by several orders of magnitude. As a result, management tools have failed to cope with and handle the complexity, dynamism, and coordination among network attacks. In this paper, we present a self-configuration approach to control and manage the security mechanisms of large scale networks. Self-configuration enables the system to automatically configure security system and change the configuration of its resources and their operational policies at runtime in order to manage the system security. Our self-configuration approach is implemented using two software modules: component management interface (CMI) to specify the configuration and operational policies associated with each component that can be a hardware resource or a software component; and component runtime manager (CRM) that manages the component operations using the policies defined in CMI. We have used the self-configuration framework to experiment with and evaluate different mechanisms and strategies to detect and protect against a wide range of network attacks.
Huoping Chen, Youssif B. Al-Nashif, Guangzhi Qu, Salim Hariri
EDOC4
2007 Self-optimization of Performance-per-Watt for Interleaved Memory Systems
Bithika Khargharia, Salim Hariri, Mazin S. Yousif
HiPC2
2007 Autonomic Power & Performance Management for Large-Scale Data Centers
abstract
With the rapid growth of servers and applications spurred by the Internet, the power consumption of servers has become critically important and must be efficiently managed. High energy consumption also translates into excessive heat dissipation which in turn, increases cooling costs and causes servers to become more prone to failure. This paper presents a theoretical and experimental framework and general methodology for hierarchical autonomic power & performance management in high performance distributed data centers. We optimize for power & performance (performance/watt) at each level of the hierarchy while maintaining scalability. We adopt mathematically-rigorous optimization approach to provide the application with the required amount of memory at runtime. This enables us to transition the unused memory capacity to a low power state. Our experimental results show a maximum performance/watt improvement of 88.48% compared to traditional techniques. We also present preliminary results of using game theory to optimize performance/watt at the cluster level of a data center. Our cooperative technique reduces the power consumption by 65% when compared to traditional techniques (min-min heuristic).
Bithika Khargharia, Salim Hariri, Ferenc Szidarovszky, Manal Houri, Hesham El-Rewini, Samee Ullah Khan, Ishfaq Ahmad 0001, Mazin S. Yousif
IPDPS2
2007 An evaluation scheme of adaptive configuration techniques
abstract
In this paper, we present a set of metrics (scalability, adaptability, overhead, latency, complexity, and effectiveness) to evaluate dynamic configuration techniques. We have applied these metrics to two real systems: remote management system and dynamic security configuration of networked systems. The evaluation results show that our approach can efficiently and dynamically manage system resources and network security with little overhead.
Huoping Chen, Salim Hariri
ASE2
2007 Anomaly-Based Behavior Analysis of Wireless Network Security
abstract
The exponential growth in wireless network faults, vulnerabilities, and attacks make the wireless local area network (WLAN) security management a challenging research area. Newer network cards implemented more security measures according to the IEEE recommendations [14]; but the wireless network is still vulnerable to denial of service attacks or to other traditional attacks due to existing wide deployment of network cards with well-known security vulnerabilities. The effectiveness of a wireless intrusion detection system (WIDS) relies on updating its security rules; many current WIDSs use static security rule settings based on expert knowledge. However, updating those security rules can be time-consuming and expensive. In this paper, we present a novel approach based on multi-channel monitoring and anomaly analysis of station localization, packet analysis, and state tracking to detect wireless attacks; we use adaptive machine learning and genetic search to dynamically set optimal anomaly thresholds and select the proper set of features necessary to efficiently detect network attacks. We present a self-protection system that has the following salient features: monitor the wireless network, generate network features, track wireless network state machine violations, generate wireless flow keys (WFK), and use the dynamically updated anomaly and misuse rules to detect complex known and unknown wireless attacks. To quantify the attack impact, we use the abnormality distance from the trained norm and multivariate analysis to correlate multiple selected features contributing to the final decision. We validate our wireless self protection system (WSPS) approach by experimenting with more than 20 different types of wireless attacks. Our experimental results show that the WSPS approach can protect from wireless network attacks with a false positive rate of 0.1209% and more than 99% detection rate.
Samer Fayssal, Salim Hariri, Youssif B. Al-Nashif, Guangzhi Qu
MobiQuitous2
2007 Anomaly-based Fault Detection System in Distributed System
abstract
One of the important design criteria for distributed systems and their applications is their reliability and robustness to hardware and software failures. The increase in complexity, inter connectedness, dependency and the asynchronous interactions between the components that include hardware resources (computers, servers, network devices), and software (application services, middleware, web services, etc.) makes the fault detection and tolerance a challenging research problem. In this paper, we present an innovative approach based on statistical and data mining techniques to detect faults (hardware or software) and also identify the source of the fault. In our approach, we monitor and analyze in realtime all the interactions between all the components of a distributed system. We used data mining and supervised learning techniques to obtain the rules that can accurately model the normal interactions among these components. Our anomaly analysis engine will immediately produce an alert whenever one or more of the interaction rules that capture normal operations is violated due to a software or hardware failure. We evaluate the effectiveness of our approach and its performance to detect software faults that we inject asynchronously, and compare the results for different noise level.
Byoung Uk Kim, Salim Hariri
SERA2
2006 An Innovative Self-Configuration Approach for Networked Systems and Applications
abstract
The increased complexity, heterogeneity and the dynamism of networked systems and services make current control and management tools to be ineffective in managing and securing such systems and services. A new paradigm to control and manage large-scale complex and dynamic networked systems is critically needed. In this paper, we present a new paradigm based on the principles of autonomic computing that can handle efficiently complexity, dynamism and uncertainty in networked systems and their applications. We have developed a general Component Management Interface (CMI) to enable autonomic behaviors and operations of any legacy resource or a software component. The CMI consists of four management ports: Configuration Port, Function Port, Control Port and Operation Port. We have successfully implemented the CMI in XML format and validated the effectiveness and performance of our approach to develop automated and self-configuring security patch deployment services.
Huoping Chen, Salim Hariri, Fahd Rasul
AICCSA2
2006 PARM: Physics Aware Runtime Manager for Large-scale Scientific and Engineering Applications
abstract
Choosing the ideal algorithms and solutions for a scientific application is difficult because of the heterogeneity and dynamism of the application execution phases at runtime. In this paper we present an autonomic programming framework that is capable of self-configuring and self-composing the application solution methods in order to exploit the heterogeneity and the dynamism of the application execution states. We focus our approach on partial differential equation (PDE) problems involving multiple computational phases that are defined in terms of their spatial and temporal characteristics. We have implemented a physics aware runtime manager (PARM) that periodically monitors and analyzes the spatial and temporal characteristics of the application to identify its current execution phase (state). Then PARM will determine an appropriate numerical schemes and algorithms that will most efficiently exploit the current state. Our preliminary results show a significant speedup can be achieved by using PARM
Yeliang Zhang, Salim Hariri, Jianwei Xiang, Jim Yeh
HPDC2
2005 Multivariate statistical analysis for network attacks detection
abstract
Summary form only given. Detection and self-protection against viruses, worms, and network attacks is urgently needed to protect network systems and their applications from catastrophic failures. Once a network component is infected by viruses, worms, or became a target of network attacks, its operational state shifts from normal to abnormal state. Online monitoring mechanism can collect important aspects of network traffic and host data (CPU utilization, memory usage, etc.), that can be effectively used to detect abnormal behaviors caused by attacks. In this paper, we develop an online multivariate analysis algorithm to analyze the behaviors of system resources and network protocols in order to proactively detect network attacks. We have validated an algorithm and showed how it can proactively detect accurately well-known attacks such as distributed denial of service, SQL slammer worm, and email spam attacks.
Guangzhi Qu, Salim Hariri, Mazin S. Yousif
AICCSA2
2005 Autonomic runtime manager for adaptive distributed applications
abstract
For adaptive distributed applications, the computational complexity associated with each computational region varies continuously and dramatically both in space and time throughout the life cycle of the application execution. Consequently, static scheduling techniques are inefficient for such applications. In this paper, we present an autonomic runtime manager (ARM) that uses the application spatial and temporal characteristics as well as resource status as the main criteria to self optimize the execution of distributed applications at runtime. We applied the ARM system to a wildfire simulation and our experimental results show that the performance of the wildfire simulation has been improved by 45% when compared with a static partitioning algorithm. We also evaluate the performance of ARM using two partitioning strategies: natural regions (NR) approach and a graph partitioning approach.
Jingmei Yang, Huoping Chen, Salim Hariri, Manish Parashar
HPDC3
2005 An efficient network intrusion detection method based on information theory and genetic algorithm
abstract
The Internet has been growing at an amazing rate and concurrent with the growth, the vulnerability of the Internet is also increasing. Though the Internet has been designed to withstand various forms of failure, the intrusion tools and attacks are becoming increasingly sophisticated, exposing the Internet to new threats. To make networked systems reliable and robust it becomes highly essential to develop on-line monitoring, analysis and quantification of the behavior of networks under a wide range of attacks and to recover from these attacks. In this paper, we present a hybrid method based on information theory and genetic algorithm to detect network attacks. Our approach uses information theory to filter the traffic data and thus reduce the complexity. We use a linear structure rule to classify the network behaviors into normal and abnormal behaviors. We apply our approach to the kdd99 benchmark dataset and obtain high detection rate of 99.25% as well as low false alarm rate of 1.66%.
Guangzhi Qu, Salim Hariri, Mazin S. Yousif
IPCCC3
2005 Quality-of-protection (QoP)-an online monitoring and self-protection mechanism
abstract
With increasing faults and attacks on the Internet infrastructure, there is an impending need to provide automatic techniques to detect and mitigate the impact of attacks on network services. Denial-of-service attacks have been successful in denying legitimate traffic access to its required resources because existing routing protocols treat the attacking traffic equally as any normal traffic. This paper presents a proactive network defense framework that can be integrated with existing quality-of-service (QoS) protocols to provide differentiated services to network traffic flows based on their distance from the normal behavior. We introduce a new metric that we refer to as abnormality distance (AD) metric that can be used to classify traffic into normal, probable normal, probable abnormal (suspicious traffic), and abnormal (attacking traffic). The AD metric can then be used in conjunction with any QoS protocol to give high priority to normal traffic and lower priority to abnormal traffic. We demonstrate through several examples, how our approach can dynamically detect attacks, quantify their impact, and how to reduce the impacts and recover from them.
Salim Hariri, Guangzhi Qu, R. Modukuri, Huoping Chen, Mazin S. Yousif
IEEE J. Sel. Areas Commun.1
2005 A New Dependency and Correlation Analysis for Features
abstract
The quality of the data being analyzed is a critical factor that affects the accuracy of data mining algorithms. There are two important aspects of the data quality, one is relevance and the other is data redundancy. The inclusion of irrelevant and redundant features in the data mining model results in poor predictions and high computational overhead. This paper presents an efficient method concerning both the relevance of the features and the pairwise features correlation in order to improve the prediction and accuracy of our data mining algorithm. We introduce a new feature correlation metric Q/sub Y/(X/sub i/,X/sub j/) and feature subset merit measure e(S) to quantify the relevance and the correlation among features with respect to a desired data mining task (e.g., detection of an abnormal behavior in a network service due to network attacks). Our approach takes into consideration not only the dependency among the features, but also their dependency with respect to a given data mining task. Our analysis shows that the correlation relationship among features depends on the decision task and, thus, they display different behaviors as we change the decision task. We applied our data mining approach to network security and validated it using the DARPA KDD99 benchmark data set. Our results show that, using the new decision dependent correlation metric, we can efficiently detect rare network attacks such as User to Root (U2R) and Remote to Local (R2L) attacks. The best reported detection rates for U2R and R2L on the KDD99 data sets were 13.2 percent and 8.4 percent with 0.5 percent false alarm, respectively. For U2R attacks, our approach can achieve a 92.5 percent detection rate with a false alarm of 0.7587 percent. For R2L attacks, our approach can achieve a 92.47 percent detection rate with a false alarm of 8.35 percent.
Guangzhi Qu, Salim Hariri, Mazin S. Yousif
IEEE Trans. Knowl. Data Eng.2
2003 Autonomia: an autonomic computing environment
abstract
The proliferation of Internet technologies, services and devices, have made the current networked system designs, and management tools incapable of designing reliable, secure networked systems and services. In fact, we have reached a level of complexity, heterogeneity, and a rapid change rate that our information infrastructure is becoming unmanageable and insecure. This had led researchers to consider alternative designs and management techniques that are based on strategies used by biological systems to deal with complexity, heterogeneity and uncertainty. The approach is referred to as autonomic computing. An autonomic computing system is the system that has the capabilities of being self-defining, self-healing, self-configuring, self-optimizing, etc. We present our approach to implement an autonomic computing infrastructure, Autonomia that provides dynamically programmable control and management services to support the development and deployment of smart (intelligent) applications. The Autonomia environment provides the application developers with all the tools required to specify the appropriate control and management schemes to maintain any quality of service requirement or application attribute/functionality (e.g., performance, fault, security, etc.) and the core autonomic middleware services to maintain the autonomic requirements of a wide range of network applications and services. We have successfully implemented a proof-of-concept prototype system that can support the self-configuring, self-deploying and self-healing of any networked application.
Xiangdong Dong, Salim Hariri, Lizhi Xue, Huoping Chen, S. Pavuluri
IPCCC2
2002 Adaptive Runtime Managementof SAMR Applications
Sumir Chandra, Shweta Sinha, Manish Parashar, Yeliang Zhang, Jingmei Yang, Salim Hariri
HiPC6
2002 Performance-Effective and Low-Complexity Task Scheduling for Heterogeneous Computing
abstract
Efficient application scheduling is critical for achieving high performance in heterogeneous computing environments. The application scheduling problem has been shown to be NP-complete in general cases as well as in several restricted cases. Because of its key importance, this problem has been extensively studied and various algorithms have been proposed in the literature which are mainly for systems with homogeneous processors. Although there are a few algorithms in the literature for heterogeneous processors, they usually require significantly high scheduling costs and they may not deliver good quality schedules with lower costs. In this paper, we present two novel scheduling algorithms for a bounded number of heterogeneous processors with an objective to simultaneously meet high performance and fast scheduling time, which are called the Heterogeneous Earliest-Finish-Time (HEFT) algorithm and the Critical-Path-on-a-Processor (CPOP) algorithm. The HEFT algorithm selects the task with the highest upward rank value at each step and assigns the selected task to the processor, which minimizes its earliest finish time with an insertion-based approach. On the other hand, the CPOP algorithm uses the summation of upward and downward rank values for prioritizing tasks. Another difference is in the processor selection phase, which schedules the critical tasks onto the processor that minimizes the total execution time of the critical tasks. In order to provide a robust and unbiased comparison with the related work, a parametric graph generator was designed to generate weighted directed acyclic graphs with various characteristics. The comparison study, based on both randomly generated graphs and the graphs of some real applications, shows that our scheduling algorithms significantly surpass previous approaches in terms of both quality and cost of schedules, which are mainly presented with schedule length ratio, speedup, frequency of best results, and average scheduling time metrics.
Haluk Topcuoglu, Salim Hariri, Min-You Wu
IEEE Trans. Parallel Distributed Syst.2
2001 An Adaptive Communication System for Heterogeneous Network Computing
abstract
In this paper, we present an architecture of an AdaptiveCommunication System (ACS) that provides applicationswith programmable communication, control, andmanagement services that can be adopted dynamicallyto maximize application performance at runtime. ACSsupports adaptive and scalable communication servicesthat select the appropriate multicast/broadcast algorithmsfor a given class of applications. These algorithms takeinto consideration both the application requirements andthe load of computing and communication systems.We overview the ACS architecture and then describe ourapproach to implement the ACS group communication services.We introduce two procedures (Resource Aware procedureand Application Aware procedure) to build the appropriatemulticast tree that takes into consideration both thecharacteristics and load conditions of machines as well asthe group communication patterns of a given application.We develop analytical techniques and new metric measuresto characterize and quantify the performance of a multicasttree. We also present our preliminary performance resultsthat show significant performance gain can be achievedfrom using ACS multicast algorithms.
Ilkyeun Ra, Salim Hariri, Cauligi S. Raghavendra
IPDPS2
2000 A Comparative Statistical Error Analysis of Neuronavigation Systems in a Clinical Setting
Hamid Reza Abbasi, Salim Hariri, Daniel H. Kim, John R. Adler Jr., Gary Steinberg, Ramin Shahidi
MICCAI2
2000 Design and analysis of a proactive application management system (PAMS)
abstract
Management of large-scale network-centric systems (NCS) and their applications is an extremely complex and challenging task due to factors such as centralized management architectures, lack of coordination and compatibility among heterogeneous network management systems, and the dynamic characteristics of networks and application bandwidth requirements, just to name a few. The goal of this research is to develop a hierarchical framework to achieve end-to-end intelligent proactive network management system that can be used to manage large-scale network-centric systems and their applications. This framework provides the ability to write management programs to manage any required function or property (performance, high assurance, fault, quality of service, etc.) of the network-centric systems and their applications during all the phases of their operations. Our ultimate objective is to consider the management of network-centric systems and applications starting from the design phase and forward rather than being afterthought process. In this paper, we present a framework to develop proactive and adaptive management services and an implementation of a proactive application management system (PAMS) based on that framework. Our implementation approach utilizes delegated mobile agents to implement the management functions required by any network-centric system and/or application. We also present experimental results and evaluation of the management services offered by the PAMS prototype.
Salim Hariri, Yoonhee Kim
NOMS1
2000 Interpretive Performance Prediction for Parallel Application Development
Manish Parashar, Salim Hariri
J. Parallel Distributed Comput.2
1998 A Multithreaded Message-Passing System for High-Performance Distributed Computing Applications
abstract
NYNET (ATM wide area network testbed in New York state) Communication System (NCS) is a multithreaded message passing system developed at Syracase University that provides high performance and flexible communication services over asynchronous transfer mode (ATM) based high performance distributed computing (HPDC) environments. NCS capitalizes on thread based programming model to overlap computations and communications, and develop a dynamic message passing environment with separate data and control paths. This leads to a flexible and adaptive message passing environment that can support multiple flow control, error control, and multicasting algorithms. We provide an overview of the NCS architecture and present how NCS point to point communication services are implemented. We also analyze the overhead incurred by using multithreading and compare the performance of NCS point to point communication primitives with those of other message passing systems such as p4, PVM, and MPI. Benchmarking results indicate that NCS shows comparable performance to other systems for small message sizes but outperforms other systems for large message sizes.
Sungyong Park, Joohan Lee, Salim Hariri
ICDCS3
1998 A framework for end-to-end proactive network management
abstract
Current advances in networking, computing, software and web technologies have led to an explosive growth in the development of networked applications. Management of large-scale networks and their applications is an extremely complex task due to factors such as centralized management architectures, lack of coordination and compatibility among heterogeneous network management systems, and dynamic characteristics of networks and application bandwidth requirements. We do need to develop an integrated network management paradigm that is proactive, scalable and robust. In this paper, we present a framework for end-to-end proactive management of global heterogeneous networks and their applications. Our framework consists of a three level hierarchy: Network and Protocol Management (NPM) Management Computing System (MCS), and Application Centric Management (ACM). The NPM layer addresses the issues of utilizing existing network management tools, abstracting their collected management information, and providing proactive management services to manage networks and protocols. The MCS layer addresses the core system management issues and provides system management services to enable the development of efficient proactive management of a wide range of network applications. The ACM layer addresses the issues required to develop application specific management techniques, and manage applications so they can meet their requirements in real-time.
Salim Hariri, Yoonhee Kim, K. Varshney, R. Kaminski, D. Hague, C. Maciag
NOMS1
1997 The Software Architecture of a Virtual Distributed Computing Environment
abstract
The requirements of grand challenge problems and the deployment of gigabit networks makes the network computing framework an attractive and cost effective computing environment with which to interconnect geographically distributed processing and storage resources. Our project, Virtual Distributed Computing Environment (VDCE), provides a problem-solving environment for high-performance distributed computing over wide area networks. VDCE delivers well-defined library functions that relieve end-users of tedious task implementations and also support reusability. In this paper we present the conceptual design of VDCE software architecture, which is defined in three modules: (a) the Application Editor, a user-friendly application development environment that generates the Application Flow Graph (AFG) of an application; (b) the Application Scheduler, which provides an efficient task-to-resource mapping of AFG; and (c) the VDCE Runtime System, which is responsible for running and managing application execution and monitoring the VDCE resources.
Haluk Topcuoglu, Salim Hariri, Wojtek Furmanski, Jon Valente, Ilkyeun Ra, Yoonhee Kim, Xue Bing, Baoqing Ye
HPDC2
1997 A Global Computing Environment for Networked Resources
abstract
Current advances in high-speed networks and WWW technologies have made network computing a cost-effective, high-performance computing alternative. New software tools are being developed to utilize efficiently the network computing environment. Our project, called Virtual Distributed Computing Environment (VDCE), is a high-performance computing environment that allows users to write and evaluate networked applications for different hardware and software configurations using a web interface. In this paper we present the software architecture of VDCE by emphasizing application development and specification, scheduling, and execution/runtime aspects.
Haluk Topcuoglu, Salim Hariri
ICPP2
1997 Efficient communication algorithms for ring multicomputers
abstract
In this article, we study the various communication algorithms on bidirectional ring multicomputers. We show how the three important communication functions (data distribution, data collection, and data broadcast) can be efficiently designed and implemented by reducing the propagation delay under point-to-point routing and blocking message passing assumptions.
Kok Kin Kee, Salim Hariri
J. Syst. Softw.2
1997 Editorial: Special Issue on High Performace Distributed Computing
Salim Hariri
J. Supercomput.1
1997 A High Performance Message-Passing System for Network of Workstations
Sungyong Park, Salim Hariri
J. Supercomput.2
1996 Software Fault Tolerance Using Dynamically Reconfigurable FPGAs
abstract
An emerging class of Field-Programmable Gate Arrays (FPGAs) permits partial reconfiguration of the device without disturbing the rest of the array-even while the device is operating. Dynamic device reconfiguration allows novel approaches to the migration of algorithms from software to hardware. New simulation tools are required in order to fully exploit the FPGA's versatility. We demonstrate how FPGA cells can be programmed and reprogrammed to provide a virtual FPGA that is much larger than the physical FPGA. In the context of dependable computing, our FPGA-based approach shows promise of significant performance gains over traditional software-intensive approaches. We apply this capability to the enhancement of software fault tolerance.
Kevin A. Kwiat, Warren H. Debany Jr., Salim Hariri
Great Lakes Symposium on VLSI3
1996 NYNET Communication System (NCS): A Multithreaded Message Passing Tool over ATM Network
abstract
Current advances in processor technology, and the rapid development of high speed networking technology, such as ATM, have made high performance network computing an attractive computing environment for large-scale high performance distributed computing (HPDC) applications. However, due to the communications overhead at the host-network interface, most of the HPDC applications are not getting the full benefit of high speed communication networks. This overhead can be attributed to the high cost of operating system calls, context switching, the use of inefficient communication protocols, and the coupling of data and control paths. We present an architecture and implementation for a low-latency, high-throughput message passing tool, that we refer to as the NYNET (ATM wide area network testbed in New York state) Communication System (NCS), which can support a variety of HPDC applications with different Quality of Services (QOS) requirements. NCS uses multithreading to provide efficient techniques that overlap computation and communication. NCS uses read/write trap routines to bypass traditional operating system calls. This reduces latency and avoids using inefficient communication protocols. By separating data and control paths, NCS eliminates unnecessary control transfers. This optimizes the data path and improves performance. Benchmarking results show that the performance of NCS is at least a factor of two better than the performance of corresponding p4 and PVM primitives.
Sungyong Park, Salim Hariri, Yoonhee Kim, J. Stuart Harris, Rajesh Yadav
HPDC2
1995 A Multithreaded Message Passing Environment for ATM LAN/WAN
abstract
Large scale High Performance Computing and Communication (HPCC) applications (e.g. Video-on-Demand, and HPDC) would require storage and processing capabilities which are beyond existing single computer systems. The current advances in networking technology (e.g. ATM) have made high performance network computing an attractive computing environment for such applications. However, using only high speed network is not sufficient to achieve high performance distributed computing environment unless some hardware and software problems have been resolved. These problems include the limited communication bandwidth available to the application, high overhead associated with context switching, redundant data copying during protocol processing and lack of support to overlap computation and communication at application level. In this paper, we propose a multithreaded message passing system for parallel/distributed processing that we refer to as NYNET communication system (NCS). NCS, being developed for NYNET (ATM wide area network testbed), is built on top of an ATM application programmer interface (API). The multithreaded environment allows applications to overlap computations and communications and provides a modular approach to support efficiently HPDC applications with different quality of service (QOS) requirements.
Rajesh Yadav, Rajashekar Reddy, Salim Hariri
HPDC3
1995 Software Tool Evaluation Methodology
abstract
The recent development of parallel and distributed computing software has introduced a variety of software tools that support several programming paradigms and languages. This variety of tools makes the selection of the best tool to run a given class of applications on a parallel or distributed system a non-trivial task that requires some investigation. We expect tool evaluation to receive more attention as the deployment and usage of distributed systems increases. In this paper, we present a multi-level evaluation methodology for parallel/distributed tools in which tools are evaluated from different perspectives. We apply our evaluation methodology to three message passing tools viz Express, p4, and PVM. The approach covers several important distributed systems platforms consisting of different computers (e.g., IBM-SP1, Alpha cluster, SUN workstations) interconnected by different types of networks (e.g., Ethernet, FDDI, ATM).
Salim Hariri, Sungyong Park, Rajashekar Reddy, Mahesh Subramanyan, Rajesh Yadav, Geoffrey C. Fox, Manish Parashar
ICDCS1
1995 Performance analysis of a high-speed dynamically reconfigurable LAN
abstract
We present the design of a dynamically reconfigurable switch that will be used to build a highspeed multi-link ring local area network. Using FPGAs technology, switch reconfigurability can be exploited to implement different interconnection topologies and support different application requirements. We present two approaches to analyze the multi-link ring network performance. In the first approach, we develop an analytical model that uses the M/M/n and M/D/n queuing systems to study the virtual channels access delay. In this approach, the virtual channel occupancy probabilities are found using an infinite state Markov model. In the second approach, we introduce an analytical model based on a finite state Markov model developed for analysing networks with virtual channels flow control. Simulation, using the OPNET tool, indicates that the second approach is more accurate in analyzing the behavior of the packet transfer time. Furthermore our performance analysis shows that the use of wormhole routing and virtual channel flow control improves the system throughput and decreases the packet transfer time.
Saad AlKasabi, Salim Hariri
LCN2
1995 Modeling a versatile FPGA for prototyping adaptive systems
abstract
Currently, the Computer-Aided Engineering (CAE) environments for designing Field-Programmable Gate Arrays (FPGAs) do not support the simulation of FPGA reprogrammability, hence prototyping of adaptive systems relies upon using the actual FPGAs. The FPGA architecture baselined an this paper, similar to a commercially-available FPGA as architecture, supports partial reconfiguration without disturbing the rest of the array. In this paper, we describe a modeling strategy for obtaining VHDL descriptions of versatile FPGAs so their dynamic behavior can be exhibited in advance of device procurement. An adaptive system using a versatile FPGA may also be prototyped with an emulation system whose FPGAs are architecturally different from the one requiring emulation. VHDL structural descriptions of the prototype's FPGA demonstrate the feasibility of transferring the model to the emulation system. We show how the generation of both the model and the simulation input capture the FPGA's full versatility.
Kevin A. Kwiat, Warren H. Debany Jr., Salim Hariri
RSP3
1995 Hierarchical Modeling of Availability in Distributed Systems
abstract
Distributed computing systems are attractive due to the potential improvement in availability, fault-tolerance, performance, and resource sharing. Modeling and evaluation of such computing systems is an important step in the design process of distributed systems. We present a two-level hierarchical model to analyze the availability of distributed systems. At the higher level (user level), the availability of the tasks (processes) is analyzed using a graph-based approach. At the lower level (component level), detailed Markov models are developed to analyze the component availabilities. These models take into account the hardware/software failures, congestion and collisions in communication links, allocation of resources, and the redundancy level. A systematic approach is developed to apply the two-level hierarchical model to evaluate the availability of the processes and the services provided by a distributed computing environment. This approach is then applied to analyze some of the distributed processes of a real distributed system, Unified Workstation Environment (UWE), that is currently being implemented at AT&T Bell Laboratories.>
Salim Hariri, Hasan B. Mutlu
IEEE Trans. Software Eng.1
1994 The Virtual Computing Environment
abstract
A network of supercomputers and high-performance workstations appears to be the only reasonable way to provide adequate computing resources for the Grand Challenge problems of the next century. Such a collection of computers and supporting software environments is called a virtual computing environment (VCE). The paper describes the motivation and goals of the VCE project, followed by a description of the system. The paper concentrates on the runtime aspects of the VCE, and concludes with a discussion of a small prototype system that has been built using the Isis distributed toolkit.>
Philip Rousselle, Paul T. Tymann, Salim Hariri, Geoffrey C. Fox
HPDC3
1994 A Concurrent Multi Target Tracker: Benchmarking and Portability
abstract
With the current advances in computing and network technology and software, the gap between parallel and distributed computing environment is gradually becoming narrower. Consequently, parallel programs run on parallel as well as distributed systems. However, programming and porting complex applications to such environment is challenging task and not well understood. In this paper, we use a concurrent multi target tracker as a running example to analyze and evaluate performance of two different parallel implementations on parallel and distributed systems. We have benchmarked both these implementations on different architectures that vary from a network of worksta-tions{SUN, IBM RS6000) to parallel computers (CM5, iPSC 860) using different parallel/distributed message passing tools{PVM, p4, EXPRESS).
Salim Hariri, Rajesh Yadav, Balaji Thiagarajan, Sungyong Park, Mahesh Subramanyan, Rajashekar Reddy, Geoffrey C. Fox
ICPP (3)1
1994 Efficient communication algorithms for pipeline multicomputers
abstract
We study the various communication algorithms on the pipeline multicomputer. We show how the three important communication functions (data distribution, data collection, and data broadcast) can be improved by reducing the propagation delay and using the right message size.>
Kok Kin Kee, Salim Hariri
SC2
1994 Interpreting the performance of HPF/Fortran 90D
abstract
We present a novel interpretive approach for accurate and cost effective performance prediction in a high performance computing environment, and describe the design of a source driven HPF/Fortran 90D performance prediction framework based on this approach. The performance prediction framework has been implemented as part of a HPF/Fortran 90D application development environment. A set of benchmarking kernels and application codes are used to validate the accuracy, utility, usability, and cost effectiveness of the performance prediction framework. The use of the framework for selecting appropriate compiler directives and for application performance debugging is demonstrated.>
Manish Parashar, Salim Hariri, Tomasz Haupt, Geoffrey C. Fox
SC2
1994 Communication system for high-performance distributed computing
abstract
Abstract With the current advances in computer and networking technology coupled with the availability of software tools for parallel and distributed computing, there has been increased interest in high‐performance distributed computing (HPDC). We envision that HPDC environments with supercomputing capabilities will be available in the near future. However, a number of issues have to be resolved before future network‐based applications can fully exploit the potential of the HPDC environment. In the paper we present an architecture for a high‐speed local area network and a communication system that provides HPDC applications with high bandwidth and low latency. We also characterize the message‐passing primitives required in HPDC applications and develop a communication protocol that implements these primitives efficiently.
Salim Hariri, J.-B. Park, Manish Parashar, Geoffrey C. Fox
Concurr. Pract. Exp.1
1993 A Message Passing Interface for Parallel and Distributed Computing
abstract
The proliferation of high performance workstations and the emergence of high speed networks have attracted a lot of interest in parallel and distributed computing (PDC). The authors envision that PDC environments with supercomputing capabilities will be available in the near future. However, a number of hardware and software issues have to be resolved before the full potential of these PDC environments can be exploited. The presented research has the following objectives: (1) to characterize the message-passing primitives used in parallel and distributed computing; (2) to develop a communication protocol that supports PDC; and (3) to develop an architectural support for PDC over gigabit networks.>
Salim Hariri, Jong Park, Fang-Kuo Yu, Manish Parashar, Geoffrey C. Fox
HPDC1
1993 An optical network interface unit for multichannel ring networks
abstract
The authors present an all-optical hypercube-based multichannel network, implemented on a ring topology, using wavelength division multiplexed channels. For a network of size N, only log/sub 2/N distinct channels are required. They design an optical network interface unit (ONIU), which employs free-space optics to perform routing and switching functions. The design eliminates the electronic bottleneck at intermediate nodes and is capable of performing high speed packet switching. ONIU can be reconfigured in the GHz range and provides the high bandwidth necessary to perform distributed and parallel computing in a local area network environment.>
Francis Reichmeyer, Salim Hariri, Wang Song, Kamal Jabbour
ICNP2
1993 High-performance distributed computing: Promises and challenges
Salim Hariri, Anljjan Varma
Concurr. Pract. Exp.1
1993 Design and Analysis of an Optical Communications Processor
Q. Wang Song, Salim Hariri, Alok N. Choudhary
J. Parallel Distributed Comput.2
1992 A Requirement Analysis for High Performance Distributed Computing over LANs
abstract
With the proliferation of high performance workstations and the current trend towards high speed communication networks. the cumulative computing power provided by a group of general purpose workstations is comparable to supercomputers. However a number of obstacles have to be overcome before the full potential of these network-based distributed systems can be exploited. This paper investigates the requirements of current workstation clusters interconnected by local area networks (LANs) which would allow them to be used as platforms for high performance distributed computing. The blocked LU decomposition of dense matrices is used as the running example in the presented study. Performance of this algorithm is measured on the iPSC/860 hypercube and on a set of homogeneous workstations (SUN SPARCstation 1+) interconnected by Ethernet. These measures are analyzed and a set of requirements are identified which would enable a network of workstations to deliver high performance distributed computing.>
Manish Parashar, Salim Hariri, A. Gaber Mohamed, Geoffrey C. Fox
HPDC2
1992 Design Methodology for Fault-Tolerant Systolic Array Architectures
Michael Ogbonna Esonu, Asim J. Al-Khalili, Salim Hariri
ICPP (2)3
1991 A hierarchical modeling of availability in distributed systems
abstract
A two-level hierarchical model is proposed to analyze the availability of distributed systems as perceived by their users. At the higher level (user level), the availability of the tasks (processes) is analyzed in terms of the availability of the system components. At the lower level (component level), detailed Markov models are developed to analyze the component availabilities. These models take into account the hardware/software failures, congestion and collisions in communication links, allocation of resources, and the redundancy level. Also presented is the availability analysis of some of the services provided by the unified workstation environment (UWE) currently being implemented at AT&T Bell Laboratories.>
Salim Hariri, Hasan B. Mutlu
ICDCS1
1991 Area Efficient Computing Structures for Concurrent Error Detection in Systolic Architectures
Michael Ogbonna Esonu, Asim J. Al-Khalili, Salim Hariri
ICPP (1)3
1990 Modeling Availability of Parallel Computers
Salim Hariri, A. Gaber Mohamed, Hasan B. Mutlu
ICPP (1)1
1990 Optical switching and routing architectures for fiber-optic computer communication networks
abstract
An optical interface message processor (OPTIMP) is proposed that exploits the high bandwidth, parallelism, multidimensional capability, and high storage density offered by optics. The most time consuming operations such as switching and routing in communication networks are performed in the optical domain in the proposed system. The design does not suffer from the optical/electrical conversion bottlenecks and can perform switching and routing in the range of gigabits/s. The source-destination (S-D) information from a message is first converted to the spatial domain. The routing table stores all S-D codes and the corresponding control codes for the switching module. Using a cylindrical system, the routing table is searched in parallel (single step) and control signals corresponding to the matched S-D row from the table are used to control the switching module. the switching module, based on the self electrooptical device array technology, can be reconfigured in the gigahertz range and provide high bandwidth.>
Alok N. Choudhary, Salim Hariri, Wang Song, Partha Banerjee, Sanjay Ranka
LCN2
1988 Reliability Analysis in Distributed Systems
abstract
Reliability of a distributed processing system is an important design parameter that can be described in terms of the reliability of processing elements and communication links and also of the redundancy of programs and data files. The traditional terminal-pair reliability does not capture the redundancy of programs and files in a distributed system. Two reliability measures are introduced: distributed program reliability, which describes the probability of successful execution of a program requiring cooperation of several computers, and distributed system reliability, which is the probability that all the specified distributed programs for the system are operational. These two reliability measures can be extended to incorporate the effects of user sites on reliability. An efficient approach based on graph traversal is developed to evaluate the proposed reliability measures.>
Cauligi S. Raghavendra, Viktor Prasanna 0001, Salim Hariri
IEEE Trans. Computers3
1987 SYREL: A Symbolic Reliability Algorithm Based on Path and Cutset Methods
abstract
Symbolic terminal reliability algorithms are important for analysis and synthesis of computer networks. In this paper, we present a simple and efficient algorithm, SYREL, to obtain compact terminal reliability expressions between a terminal pair of computers of complex networks. This algorithm incorporates conditional probability,, set theory, and Boolean algebra in a distinct approach in which most of the computations performed are directly executable Boolean operations. The conditibnal probability is used to avoid applying at each iteration the most time consuming step in reliability algorithms, which is making a set of events mutually exclusive. The algorithm has been implemented on a VAX 11/750 and can analyze fairly large networks with modest memory and time requirements.
Salim Hariri, Cauligi S. Raghavendra
IEEE Trans. Computers1
1986 Reliability Analysis in Distributed Systems
Salim Hariri, Cauligi S. Raghavendra, Viktor Prasanna 0001
ICDCS1
1986 Distributed Program Reliability Analysis
abstract
The reliability of distributed processing systems can be expressed in terms of the reliability of the processing elements that run the programs, the reliability of the processing elements holding the required files, and the reliability of the communication links used in file transfers. The authors introduce two reliability measures, namely distributed program reliability and distributed system reliability, to accurately model the reliability of distributed systems. The first measure describes the probability of successful execution of a distributed program which runs on some processing elements and needs to communicate with other processing elements for remote files, while the second measure describes the probability that all the programs of a given set can run successfully. The notion of minimal file spanning trees is introduced to efficiently evaluate these reliability measures. Graph theory techniques are used to systematically generate file spanning trees that provide all the required connections. The technique is general and can be used in a dynamic environment for efficient reliability evaluation.
Viktor Prasanna 0001, Salim Hariri, Cauligi S. Raghavendra
IEEE Trans. Software Eng.2
1985 Reliability Optimization in The Design of Distributed Systems
abstract
The reliability of a distributed system depends on the reliabilities of its communication links and computing elements, as well as on the distribution of its resources, such as programs and data files. A useful measure of reliability in distributed systems is the terminal reliability between a pair of nodes which is the probability that at least one communication path exists between these nodes. An interesting optimization problem is that of maximizing the terminal reliability between a pair of computing elements under a given budget constraint. Analytical techniques to solve this problem are applicable only to special forms of reliability expressions. In this paper, three iterative algorithms for terminal reliability maximization are presented. The first two algorithms require the computation of terminal reliability expressions, and are therefore efficient for only small networks. The third algorithm, which is developed for large distributed systems, does not require the computation of terminal reliability expressions; this algorithm maximizes approximate objective functions and gives accurate results. Several examples are presented to illustrate the approximate optimization algorithm and an estimation of the error involved is also given.
Cauligi S. Raghavendra, Salim Hariri
IEEE Trans. Software Eng.2