VLDB 2026 Research / reviewers in the wild / expert
Daniel Hagimont
dblp:46/902
· DBLP profile ↗
56ranked-venue papers
6as first author
14since 2021 · last 2025
0000-0002-0978-2155ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 32 · 1 first-author · 12 since 2021Software engineering, systems software and programming languages · 10 · 3 first-author · 1 since 2021Security and privacy · 5 · 1 first-author · 1 since 2021Computer networks · 4 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | DISC: Backpressure Mitigation In Multi-tier Applications With Distributed Shared Connection
Brice Ekane, Djob Mvondo, Renaud Lachaize, Yérom-David Bromberg, Alain Tchana, Daniel Hagimont |
NSDI | 6 |
| 2025 | Virtual NVMe-Based Storage Function Framework With Fast I/O Request State ManagementabstractCurrent cloud environments provide numerous storage functions to virtual machines such as disk encryption, snapshotting, compression and so on. These functions are implemented using software stacks inside the hypervisor’s kernel, emulator, or as a userspace polling driver like SPDK. However, each stack brings its own limitations: Linux’s kernel I/O stack cannot easily integrate proprietary technologies such as Intel SGX, while SPDK requires significant changes in software development and tooling yet lacks the rich feature set of existing solutions like Linux LVM. To remedy these limitations, we introduce NVMetro, a high-performance storage framework for virtual machines based on the NVMe protocol. NVMetro provides multiple I/O paths that can be dynamically combined to fit the needs of each storage function. It links these paths together with an eBPF-based I/O router/classifier framework, as well as a userspace software stack for out-of-kernel I/O processing. We implemented three different storage functions with NVMetro and evaluated them under various workloads. Our results show that NVMetro approaches the performance of kernel-bypass solutions like SPDK while maintaining the compatibility and ease of use of in-kernel storage stacks. Tu Dinh Ngoc, Boris Teabe, Georges Da Costa, Daniel Hagimont |
IEEE Trans. Computers | 4 |
| 2024 | JITBULL: Securing JavaScript Runtime with a Go/No-Go Policy for JIT EngineabstractNowadays, most services are delivered through the web and thus heavily rely on JavaScript (JS). To accommodate the need for more performance, JS runtimes integrated Just-In-Time (JIT) compilation engines, which compile frequently-called portions of code for faster execution. To produce efficient machine code, the JIT applies complex optimization passes on the code in question. However, inadequate modeling of the side effects of these optimizations can introduce vulnerabilities in certain optimization passes. Such vulnerabilities are regularly discovered, and often have a high impact. Once a vulnerability is identified, it is eventually patched, but not without involving several steps (development, testing, release, user consent), leaving the system vulnerable for a relatively long period: the vulnerability window. We propose JITBULL, a solution that secures the JIT engines of JS runtimes during the vulnerability window by leveraging a vulnerability's demonstrator codes. To that end, JITBULL extracts the effects of JIT compiler optimization passes on said vulnerability demonstrator codes. For every subsequent JITed code, JITBULL compares the effects of its optimization passes with those on the demonstrator codes. If similarities are detected, JITBULL assumes that the currently executing script may be malicious and disables the related optimization passes, or if that's not possible, the whole JIT engine. We implemented JITBULL in Firefox's JS runtime (SpiderMonkey) and tested it against several known vulnerabilities with public demonstrator codes. Our results demonstrate that JITBULL consistently safeguards the JIT engine against exploitation by a variant of a known vulnerability. Moreover, we show that JITBULL exhibits a false positive rate of less than 5 % on the JS Octane benchmark suite, while causing an acceptable overhead of less than 20 %. Jean-Baptiste Decourcelle, Boris Teabe, Daniel Hagimont |
DSN | 3 |
| 2024 | Flexible NVMe Request Routing for Virtual MachinesabstractRecent advances in storage hardware have resulted in massive improvements in both I/O latency and throughput. However, existing storage virtualization tools either depend on a heavy and inefficient I/O stack that is not optimized for parallelism, or require a separate API that is difficult to manage and monitor. In this work, we introduce NVMetro, a solution based on the NVMe protocol that proposes a flexible choice between multiple I/O paths to ease the development of adaptive and performant virtual storage. NVMetro provides two components: (1) an intelligent I/O classification and routing framework powered by eBPF; and (2) an easy-to-use and performant API to assist the creation of userspace I/O functions within our framework. We demonstrate the benefits of NVMetro by implementing two virtual storage functions, and we evaluate them using various benchmarks. The obtained results show that NVMetro achieves a performance and scalability comparable to bleeding-edge, kernel-bypass technologies while retaining the flexibility of traditional OS-based storage APIs. Tu Dinh Ngoc, Boris Teabe, Georges Da Costa, Daniel Hagimont |
IPDPS | 4 |
| 2023 | Fast VM Replication on Heterogeneous Hypervisors for Robust Fault ToleranceabstractThe reliability of virtualization infrastructures in the face of availability issues is a long-standing problem. Current fault tolerance approaches such as live VM replication are effective at addressing external, accidental issues (e.g. hardware failures, power cuts, environmental disasters); however, against an active attacker exploiting zero-day denial-of-service (DoS) vulnerabilities in the hypervisor itself, these approaches do not address the root cause of said vulnerabilities, and therefore cannot protect against these issues. This is made more relevant by the prevalence of DoS vulnerabilities among many widely used hypervisors. Jean-Baptiste Decourcelle, Tu Dinh Ngoc, Boris Teabe, Daniel Hagimont |
Middleware | 4 |
| 2023 | Networking in next generation disaggregated datacentersabstractSummary Nowadays, datacenters lean on a computer‐centric approach based on monolithic servers which include all necessary hardware resources (mainly CPU, RAM, network, and disks) to run applications. Such an architecture comes with two main limitations: (1) difficulty to achieve full resource utilization and (2) coarse granularity for hardware maintenance. Recently, many works investigated a resource‐centric approach called disaggregated architecture where the datacenter is composed of self‐content resource boards interconnected using fast interconnection technologies, each resource board including instances of one resource type. The resource‐centric architecture allows each resource to be managed (maintenance, allocation) independently. LegoOS is the first work which studied the implications of disaggregation on the operating system, proposing to disaggregate the operating system itself. They demonstrated the suitability of this approach, considering mainly CPU and RAM resources. However, they did not study the implication of disaggregation on network resources. We reproduced a LegoOS infrastructure and extended it to support disaggregated networking. We show that networking can be disaggregated following the same principles, and that classical networking optimizations such as DMA, DDIO, or loopback can be reproduced in such an environment. Our evaluations show the viability of the approach and the potential of future disaggregated infrastructures. Brice Ekane, Alain Tchana, Daniel Hagimont, Boris Teabe, Noel De Palma |
Concurr. Comput. Pract. Exp. | 3 |
| 2023 | HyperTP: A unified approach for live hypervisor replacement in datacenters
Tu Dinh Ngoc, Boris Teabe, Alain Tchana, Gilles Muller, Daniel Hagimont |
J. Parallel Distributed Comput. | 5 |
| 2022 | CASY: A CPU Cache Allocation System for FaaS PlatformabstractFunction as a Service (FaaS) has become a key service in the cloud. It enables customers to conceive their appli-cation as a collection of minimal serverless functions interacting with each other. FaaS platforms abstract all the management complexity to the client. This emerging paradigm is also attractive because of its billing model. Clients are charged based on the execution time of functions, allowing finer-grained pricing. There-fore, executing functions as fast as possible is very important to lower the cost. Several research studies have investigated runtime optimization in FaaS environments, but none have explored CPU cache allocation. Indeed, CPU cache contention is a well-known issue in software and FaaS is not exempt from this issue. Various hardware improvements have been made to address the CPU cache partitioning problem. Among other things, Intel has implemented a new technology in their new processors that allows cache partitioning: Cache Allocation Technology (CAT). This technology allows allocating cache ways to processes, and the usage of the cache by each process will be limited to the allocated amount. In this paper, we propose CASY (CPU Cache Allocation SYstem), a system that performs CPU cache allocation for serverless functions using the Intel CAT technology. CASY uses machine learning to build a cache usage profile for functions and uses this profile to predict the cache requirements based on the function's input data. Because the CPU's cache size is small, CASY integrates an allocation algorithm which ensures that the cache loads are balanced on all cache ways. We implemented our system and integrated it into the Open Whisk FaaS platform. Our evaluations show a 11 % decrease in execution time for some serverless functions without degrading the performance of other functions. Armel Jeatsa, Boris Teabe, Daniel Hagimont |
CCGRID | 3 |
| 2022 | Optimized Resource Allocation on Virtualized Non-Uniform I/O ArchitecturesabstractNowadays, virtualization is a central element in data centers as it allows sharing server resources among multiple users across virtual machines (VM). These servers often follow a Non-Uniform Memory Access (NUMA) architecture, consisting of independent nodes with their own cache hierarchies and I/O controllers. In this work, we investigate the impact of such an architecture on network access. As network devices are typically connected to one particular NUMA node, this leads to a situation where device access on one node is faster than another. This phenomenon is called Non-Uniform I/O Access (NUIOA). This non-uniformity impacts the performance of I/O applications that are not executed on the correct NUMA node. In this paper, we are interested in NUIOA effects in virtualized environments. Our contribution in this work is twofold: 1) we thoroughly study the impact of NUIOA on application performance in VMs, and 2) we propose a resource allocation strategy for VMs that reduces the impact of NUIOA. We implemented our allocation strategy on the Xen hypervisor and carried out evaluations with well-known benchmarks to validate our strategy. The obtained results show that with our NUIOA allocation scheme, we can improve the performance of application in VMs by up to 20 % compared to common allocation strategies. Tu Dinh Ngoc, Boris Teabe, Daniel Hagimont, Georges Da Costa |
CCGRID | 3 |
| 2022 | FlexVF: Adaptive network device services in a virtualized environment
Brice Ekane, Tu Dinh Ngoc, Boris Teabe, Daniel Hagimont, Noel De Palma |
Future Gener. Comput. Syst. | 4 |
| 2022 | A Remote Memory Sharing System for Virtualized Computing InfrastructuresabstractResource management is a critical issue in today’s virtualized computing infrastructures. Consolidation is the main technique used to optimize such infrastructure. Regarding memory management, it allows gathering overloaded and underloaded VM on the same server so that memory can be mutualized. However, because of infrastructures constraints and complexity of managing multiple resources, consolidation can hardly optimize memory management. In this article, we propose to rely on a remote memory sharing for mutualizing memory. We implemented a system which monitors the working set of virtual machines, reclaims unused memory and makes it available (as a remote swap device) for virtual machines which need memory. Our evaluations with HPC and Big Data benchmarks demonstrate the effectiveness of this approach. We show that remote memory can improve the performance of a standard Spark benchmark by up the 17 percent with an average performance degradation of 1.5 percent (for the providing application). Aram Kocharyan, Brice Ekane, Boris Teabe, Giang Son Tran, Hrachya V. Astsatryan, Daniel Hagimont |
IEEE Trans. Cloud Comput. | 6 |
| 2021 | OFC: an opportunistic caching system for FaaS platformsabstractCloud applications based on the "Functions as a Service" (FaaS) paradigm have become very popular. Yet, due to their stateless nature, they must frequently interact with an external data store, which limits their performance. To mitigate this issue, we introduce OFC, a transparent, vertically and horizontally elastic in-memory caching system for FaaS platforms, distributed over the worker nodes. OFC provides these benefits cost-effectively by exploiting two common sources of resource waste: (i) most cloud tenants overprovision the memory resources reserved for their functions because their footprint is non-trivially input-dependent and (ii) FaaS providers keep function sandboxes alive for several minutes to avoid cold starts. Using machine learning models adjusted for typical function input data categories (e.g., multimedia formats), OFC estimates the actual memory resources required by each function invocation and hoards the remaining capacity to feed the cache. We build our OFC prototype based on enhancements to the OpenWhisk FaaS platform, the Swift persistent object store, and the RAM-Cloud in-memory store. Using a diverse set of workloads, we show that OFC improves by up to 82 % and 60 % respectively the execution time of single-stage and pipelined functions. Djob Mvondo, Mathieu Bacou, Kevin Nguetchouang, Lucien Ngale, Stéphane Pouget, Josiane Kouam, Renaud Lachaize, Jinho Hwang, Timothy Wood 0001, Daniel Hagimont, Noel De Palma, Bernabe Batchakui, Alain Tchana |
EuroSys | 10 |
| 2021 | Mitigating vulnerability windows with hypervisor transplantabstractThe vulnerability window of a hypervisor regarding a given security flaw is the time between the identification of the flaw and the integration of a correction/patch in the running hypervisor. Most vulnerability windows, regardless of severity, are long enough (several days) that attackers have time to perform exploits. Nevertheless, the number of critical vulnerabilities per year is low enough to allow an exceptional solution. This paper introduces hypervisor transplant, a solution for addressing vulnerability window of critical flaws. It involves temporarily replacing the current datacenter hypervisor (e.g., Xen) which is subject to a critical security flaw, by a different hypervisor (e.g., KVM) which is not subject to the same vulnerability. Tu Dinh Ngoc, Boris Teabe, Alain Tchana, Gilles Muller, Daniel Hagimont |
EuroSys | 5 |
| 2021 | (No)Compromis: paging virtualization is not a fatalityabstractNested/Extended Page Table (EPT) is the current hardware solution for virtualizing memory in virtualized systems. It induces a significant performance overhead due to the 2D page walk it requires, thus 24 memory accesses on a TLB miss (instead of 4 memory accesses in a native system). This 2D page walk constraint comes from the utilization of paging for managing virtual machine (VM) memory. This paper shows that paging is not necessary in the hypervisor. Our solution Compromis, a novel Memory Management Unit, uses direct segments for VM memory management combined with paging for VM's processes. This is the first time that a direct segment based solution is shown to be applicable to the entire VM memory while keeping applications unchanged. Relying on the 310 studied datacenter traces, the paper shows that it is possible to provision up to 99.99% of the VMs using a single memory segment. The paper presents a systematic methodology for implementing Compromis in the hardware, the hypervisor and the datacenter scheduler. Evaluation results show that Compromis outperforms the two popular memory virtualization solutions: shadow paging and EPT by up to 30% and 370% respectively. Boris Teabe, Peterson Yuhala, Alain Tchana, Fabien Hermenier, Daniel Hagimont, Gilles Muller |
VEE | 5 |
| 2020 | Fine-Grained Fault Tolerance for Resilient pVM-Based Virtual Machine MonitorsabstractVirtual machine monitors (VMMs) play a crucial role in the software stack of cloud computing platforms: their design and implementation have a major impact on performance, security and fault tolerance. In this paper, we focus on the latter aspect (fault tolerance), which has received less attention, although it is now a significant concern. Our work aims at improving the resilience of the "pVM-based" VMMs, a popular design pattern for virtualization platforms. In such a design, the VMM is split into two main components: a bare-metal hypervisor and a privileged guest virtual machine (pVM). We highlight that the pVM is the least robust component and that the existing fault-tolerance approaches provide limited resilience guarantees or prohibitive overheads. We present three design principles (disaggregation, specialization, and pro-activity), as well as optimized implementation techniques for building a resilient pVM without sacrificing end-user application performance. We validate our contribution on the mainstream Xen platform. Djob Mvondo, Alain Tchana, Renaud Lachaize, Daniel Hagimont, Noel De Palma |
DSN | 4 |
| 2020 | Cacol: A zero overhead and non-intrusive double caching mitigation system
Grégoire Todeschi, Boris Teabe, Alain Tchana, Daniel Hagimont |
Future Gener. Comput. Syst. | 4 |
| 2019 | When eXtended Para - Virtualization (XPV) Meets NUMAabstractThis paper addresses the problem of efficiently virtualizing NUMA architectures. The major challenge comes from the fact that the hypervisor regularly reconfigures the placement of a virtual machine (VM) over the NUMA topology. However, neither guest operating systems (OSes) nor system runtime libraries (e.g., Hotspot) are designed to consider NUMA topology changes at runtime, leading end user applications to unpredictable performance. This paper presents eXtended Para-Virtualization (XPV), a new principle to efficiently virtualize a NUMA architecture. XPV consists in revisiting the interface between the hypervisor and the guest OS, and between the guest OS and system runtime libraries (SRL) so that they can dynamically take into account NUMA topology changes. The paper presents a methodology for systematically adapting legacy hypervisors, OSes, and SRLs. We have applied our approach with less than 2k line of codes in two legacy hypervisors (Xen and KVM), two legacy guest OSes (Linux and FreeBSD), and three legacy SRLs (Hotspot, TCMalloc, and jemalloc). The evaluation results showed that XPV outperforms all existing solutions by up to 304%. Vo Quoc Bao Bui, Djob Mvondo, Boris Teabe, Kevin Jiokeng, Patrick Lavoisier Wapet, Alain Tchana, Gaël Thomas 0001, Daniel Hagimont, Gilles Muller, Noel De Palma |
EuroSys | 8 |
| 2019 | Nested Virtualization Without the NestabstractWith the increasing popularity of containers, managing them on top of virtual machines becomes a common practice, called nested virtualization. This paper presents BrFusion and Hostlo, two solutions that address each of two networking issues of nested virtualization: network virtualization duplication and virtual machine-bounded pod deployments. The first issue lengthens network packet paths while the second issue leads to resource fragmentation. For instance, in respect with the first issue, we measured a throughput degradation of about 68% and a latency increase of about 31% in comparison with a single networking layer. We prototype BrFusion and Hostlo in Linux KVM/QEMU, Docker and Kubernetes systems. The evaluation results show that BrFusion leads to the same performance as a single-layer virtualization deployment. Concerning Hostlo, the results show that more than 11% of cloud clients see their cloud utilization cost reduced by down to 40%. Mathieu Bacou, Grégoire Todeschi, Alain Tchana, Daniel Hagimont |
ICPP | 4 |
| 2019 | Memory flipping: a threat to NUMA virtual machines in the CloudabstractvNUMA is the most recent technology used by hypervisors to deal with Non Uniform Memory Access (NUMA) machines, which currently composed most datacenters. vNUMA consists in presenting to the virtual machine (VM) the initial mapping (at boot time) of its virtual resources to physical resources. By this way, all NUMA optimizations implemented by almost all VM’s OS (e.g. Linux) can become effective. However, in order to be effective itself, vNUMA imposes that the initial resource mapping of the VM should remain unchanged during the VM lifetime. Current hypervisors enforce this requirement by avoiding virtual resource migration (between different NUMA nodes, in the same machine), VM migration (between different machines), and memory ballooning.However, we found that memory flipping the most efficient network virtualization approach violates the above requirement. In other words, a VM which performs network operations leads the hypervisor implicitly performs memory page migrations. In this paper, we show that violating this requirement can degrade performance by up to 18%. We present two solutions which mitigate the issue. We prototype these solutions in Xen hypervisor, a popular open source hypervisor, which is widely used by Amazon Web Services. The evaluation results, performed with well known benchmarks, show that our two solutions are able to almost cancel the issue, while keeping memory flipping effective. Djob Mvondo, Boris Teabe, Alain Tchana, Daniel Hagimont, Noel De Palma |
INFOCOM | 4 |
| 2019 | Drowsy-DC: Data Center Power Management SystemabstractIn a modern data center (DC), a large majority of costs arise from energy consumption. The most popular technique used to mitigate this issue is virtualization and more precisely virtual machine (VM) consolidation. Although consolidation may increase server usage by about 5-10%, it is difficult to actually witness server loads greater than 50%. By analyzing the traces from our cloud provider partner, confirmed by previous research work, we have identified that some VMs have sporadic moments of data computation followed by large periods of idleness. These VMs often hinder the consolidation system which cannot further increase the energy efficiency of the DC. In this paper we propose a novel DC power management system called Drowsy-DC, which is able to identify the aforementioned VMs which have matching patterns of idleness. These VMs can thus be colocated on the same server so that their idle periods are exploited to put the server to a low power mode (suspend to RAM) until some data computation is required. While introducing a negligible overhead, our system is able to significantly improve any VM consolidation system; evaluations showed improvements up to 81% and more when compared to OpenStack Neat. Mathieu Bacou, Grégoire Todeschi, Alain Tchana, Daniel Hagimont, Baptiste Lepers, Willy Zwaenepoel |
IPDPS | 4 |
| 2019 | Closer: A New Design Principle for the Privileged Virtual Machine OSabstractIn most of today's virtualized systems (e.g., Xen), the hypervisor relies on a privileged virtual machine (pVM). The pVM accomplishes work both for the hypervisor (e.g., VM life cycle management) and for client VMs (I/O management). Usually, the pVM is based on a standard OS (Linux). This is source of performance unpredictability, low performance, resource waste, and vulnerabilities. This paper presents Closer, a principle for designing a suitable OS for the pVM. Closer consists in respectively scheduling and allocating pVM's tasks and memory as close to the involved client VM as possible. By revisiting Linux and Xen hypervisor, we present a functioning implementation of Closer. The evaluation results of our implementation show that Closer outperforms standard implementations. Djob Mvondo, Boris Teabe, Alain Tchana, Daniel Hagimont, Noel De Palma |
MASCOTS | 4 |
| 2019 | Preventing the propagation of a new kind of illegitimate apps
Patrick Lavoisier Wapet, Alain Tchana, Giang Son Tran, Daniel Hagimont |
Future Gener. Comput. Syst. | 4 |
| 2018 | Welcome to zombieland: practical and energy-efficient memory disaggregation in a datacenterabstractIn this paper, we propose an effortless way for disaggregating the CPU-memory couple, two of the most important resources in cloud computing. Instead of redesigning each resource board, the disaggregation is done at the power supply domain level. In other words, CPU and memory still share the same board, but their power supply domains are separated. Besides this disaggregation, we make the two following contributions: (1) the prototyping of a new ACPI sleep state (called zombie and noted Sz) which allows to suspend a server (thus save energy) while making its memory remotely accessible; and (2) the prototyping of a rack-level system software which allows the transparent utilization of the entire rack resources (avoiding resource waste). We experimentally evaluate the effectiveness of our solution and show that it can improve the energy efficiency of state-of-the-art consolidation techniques by up to 86%, with minimal additional complexity. Vlad Nitu, Boris Teabe, Alain Tchana, Canturk Isci, Daniel Hagimont |
EuroSys | 5 |
| 2017 | Dealing with Performance Unpredictability in an Asymmetric Multicore Processor Cloud
Boris Teabe, Patrick Lavoisier Wapet, Alain Tchana, Daniel Hagimont |
Euro-Par | 4 |
| 2017 | The lock holder and the lock waiter pre-emption problems: nip them in the bud using informed spinlocks (I-Spinlock)abstractIn native Linux systems, spinlock's implementation relies on the assumption that both the lock holder thread and lock waiter threads cannot be preempted. However, in a virtualized environment, these threads are scheduled on top of virtual CPUs (vCPU) that can be preempted by the hypervisor at any time, thus forcing lock waiter threads on other vCPUs to busy wait and to waste CPU cycles. This leads to the well-known Lock Holder Preemption (LHP) and Lock Waiter Preemption (LWP) issues. Boris Teabe, Vlad Nitu, Alain Tchana, Daniel Hagimont |
EuroSys | 4 |
| 2017 | Swift Birth and Quick Death: Enabling Fast Parallel Guest Boot and Destruction in the Xen HypervisorabstractThe ability to quickly set up and tear down a virtual machine is critical for today's cloud elasticity, as well as in numerous other scenarios: guest migration/consolidation, event-driven invocation of micro-services, dynamically adaptive unikernel-based applications, micro-reboots for security or stability, etc. Vlad Nitu, Pierre Olivier, Alain Tchana, Daniel Chiba, Antonio Barbalace, Daniel Hagimont, Binoy Ravindran |
VEE | 6 |
| 2017 | StopGap: elastic VMs to enhance server consolidationabstractSummary Virtualized cloud infrastructures (also known as IaaS platforms) generally rely on a server consolidation system to pack virtual machines (VMs) on as few servers as possible. However, an important limitation of consolidation is not addressed by such systems. Because the managed VMs may be of various sizes (small, medium, large, etc.), VM packing may be obstructed when VMs do not fit available spaces. This phenomenon leaves servers with a set of unused resources (‘holes’). It is similar to memory fragmentation, a well‐known problem in operating system domain. In this paper, we propose a solution which consists in resizing VMs so that they can fit with holes. This operation leads to the management of what we call elastic VMs and requires cooperation between the application level and the IaaS level, because it impacts management at both levels. To this end, we propose a new resource negotiation and allocation model in the IaaS, calledHRNM. We demonstrate HRNM's applicability through the implementation of a prototype compatible with two main IaaS managers (OpenStack and OpenNebula). By performing thorough experiments with SPECvirt_sc2010 (a reference benchmark for server consolidation), we show that the impact of HRNM on customer's application is negligible. Finally, using Google data center traces, we show an improvement of about 62.5% for the traditional consolidation engines. Copyright © 2017 John Wiley & Sons, Ltd. Vlad Nitu, Boris Teabe, Leon Fopa, Alain Tchana, Daniel Hagimont |
Softw. Pract. Exp. | 5 |
| 2016 | Billing system CPU time on individual VMabstractIn virtualized cloud hosting centers, a virtual machine (VM) is generally allocated a fixed computing capacity. The virtualization system schedules the VMs and guarantees that each VM capacity is provided and respected. However, a significant amount of CPU time is consumed by the underlying virtualization system, which generally includes device drivers (mainly network and disk drivers). In today's virtualization systems, this CPU time consumed is difficult to monitor and it is not charged to VMs. Such a situation can have important consequences for both clients and provider: performance isolation and predictability for the former and resource management (and especially consolidation) for the latter. In this paper, we propose a virtualization system mechanism which allows estimating the CPU time used by the virtualization system on behalf of VMs. Subsequently, this CPU time is charged to VMs, thus removing the two previous side effects. This mechanism has been implemented in Xen. Its benefits have been evaluated using reference benchmarks. Boris Teabe, Alain Tchana, Daniel Hagimont |
CCGrid | 3 |
| 2016 | Application-specific quantum for multi-core platform schedulerabstractScheduling has a significant influence on application performance. Deciding on a quantum length can be very tricky, especially when concurrent applications have various characteristics. This is actually the case in virtualized cloud computing environments where virtual machines from different users are colocated on the same physical machine. We claim that in a multi-core virtualized platform, different quantum lengths should be associated with different application types. We apply this principle in a new scheduler called AQL_Sched. We identified 5 main application types and experimentally found the best quantum length for each of them. Dynamically, AQL_Sched associates an application type with each virtual CPU (vCPU) and schedules vCPUs according to their type on physical CPU (pCPU) pools with the best quantum length. Therefore, each vCPU is scheduled on a pCPU with the best quantum length. We implemented a prototype of AQL_Sched in Xen and we evaluated it with various reference benchmarks (SPECweb2009, SPECmail2009, SPEC CPU2006, and PARSEC). The evaluation results show that AQL_Sched outperforms Xen's credit scheduler. For instance, up to 20%, 10% and 15% of performance improvements have been obtained with SPECweb2009, SPEC CPU2006 and PARSEC, respectively. Boris Teabe, Alain Tchana, Daniel Hagimont |
EuroSys | 3 |
| 2016 | Mitigating performance unpredictability in the IaaS using the Kyoto principle
Alain Tchana, Vo Quoc Bao Bui, Boris Teabe, Vlad Nitu, Daniel Hagimont |
Middleware | 5 |
| 2016 | Software consolidation as an efficient energy and cost saving solution
Alain Tchana, Noel De Palma, Ibrahim Safieddine, Daniel Hagimont |
Future Gener. Comput. Syst. | 4 |
| 2015 | VMcSim: A Detailed Manycore Simulator for Virtualized SystemsabstractDesigning a cloud infrastructure for HPC applications requires to correlate design choices for virtualization solutions, resources management strategies, and their implementation on specific hardware platforms. Such investigations can hardly be conducted without accurate simulation tools. This paper introduces VMcSim, the first micro architecture and virtualized many core simulation framework. VMcSim models a x86-based asymmetric many core micro architecture, including a virtualization layer which allows to model a hyper visor, a set of virtual machines with their virtual resources (CPU and memory), their operating system, and their applications. By simulating all the involved hardware and software layers, VMcSim outperforms other simulators. Simulation accuracy is evaluated through several benchmark (SPLASH-2). The simulator is demonstrated with the evaluation of virtual resources placement policies in multicore systems. Alain Tchana, Brice Ekane, Boris Teabe, Daniel Hagimont |
CLOUD | 4 |
| 2015 | Cooperative Resource Management in a IaaSabstractVirtualized IaaS generally rely on a server consolidation system to pack virtual machines (VMs) on as few servers as possible, for energy saving. However, two situations are not taken into account, and could enhance consolidation. First, since the managed VMs can be of various sizes (small, medium, large, etc.), VMs packing can be obstructed when sizes don't fit available spaces on servers. Therefore, we would need to "split" such VMs. Second, two VMs which host replicas of the same application server (for scalability) could be "fusion Ned" when they are located on the same physical server, in order to reduce virtualization overhead and VMs memory footprint. Split and fusion operations lead to the management of elastic VMs and requires cooperation between the application level and the provider level, as they impact management at both levels. In this paper, we propose a IaaS resource management system which implements elastic VMs based on split/fusion operations and cooperative management. We show its benefit with a set of experiments. Giang Son Tran, Alain Tchana, Daniel Hagimont, Noel De Palma |
AINA | 3 |
| 2015 | Software Consolidation as an Efficient Energy and Cost Saving Solution for a SaaS/PaaS Cloud Model
Alain Tchana, Noel De Palma, Ibrahim Safieddine, Daniel Hagimont, Bruno Diot, Nicolas Vuillerme |
Euro-Par | 4 |
| 2015 | Enforcing CPU allocation in a heterogeneous IaaS
Boris Teabe, Alain Tchana, Daniel Hagimont |
Future Gener. Comput. Syst. | 3 |
| 2014 | Elastic Message QueuesabstractToday's systems are often distributed, and connecting their different components can be challenging. Message-Oriented-Middleware (MOM) is a popular tool to insure simple and reliable communication. With the ever growing loads of today's applications, MOMs needs to be scalable. But as the load changes, static scalability often underuses the resources it requires. This paper presents an elastic message queuing system leveraging cloud's on-demand resource provisioning, which allows the use of just enough resources to handle the current load. We will detail when and how provisioning decisions are made, and show the result of our system's evaluation on Amazon EC2 public cloud. This work is based on Joram, an open-source JMS compliant MOM and is now part of its distribution on OW2 consortium's website. Ahmed El-Rheddane, Noel De Palma, Alain Tchana, Daniel Hagimont |
IEEE CLOUD | 4 |
| 2013 | DVFS Aware CPU Credit Enforcement in a Virtualized System
Daniel Hagimont, Christine Mayap Kamga, Laurent Broto, Alain Tchana, Noel De Palma |
Middleware | 1 |
| 2013 | Two levels autonomic resource management in virtualized IaaS
Alain Tchana, Giang Son Tran, Laurent Broto, Noel De Palma, Daniel Hagimont |
Future Gener. Comput. Syst. | 5 |
| 2012 | Self-Protection in a Clustered Distributed SystemabstractSelf-protection refers to the ability for a system to detect illegal behaviors and to fight-back intrusions with counter-measures. This article presents the design, the implementation, and the evaluation of a self-protected system which targets clustered distributed applications. Our approach is based on the structural knowledge of the cluster and of the distributed applications. This knowledge allows to detect known and unknown attacks if an illegal communication channel is used. The current prototype is a self-protected JEE infrastructure (Java 2 Enterprise Edition) with firewall-based intrusion detection. Our prototype induces low-performance penalty for applications. Noel De Palma, Daniel Hagimont, Fabienne Boyer, Laurent Broto |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2008 | Metamodeling Autonomic System Management Policies - Ongoing WorksabstractAutonomic computing is recognized as one of the most promising solution to address the increasingly complex task of distributed environments' administration. In this context, many projects relied on software components and architectures to organize such an autonomic management software. However, we observed that the interfaces of a component model are too low-level, difficult to use and still error prone. Therefore, we introduced higher-level languages for the modeling of deployment and management policies. These domain specific languages enhance simplicity and consistency of the policies. Our current work is to formally describe the metamodels and the semantics associated with these languages. Benoît Combemale, Laurent Broto, Alain Tchana, Daniel Hagimont |
COMPSAC | 4 |
| 2008 | Autonomic Management Policy Specification: From UML to DSML
Benoît Combemale, Laurent Broto, Xavier Crégut, Michel J. Daydé, Daniel Hagimont |
MoDELS | 5 |
| 2008 | Autonomic Management for Grid ApplicationsabstractDistributed software environments are increasingly complex and difficult to manage, as they integrate various legacy software with specific management interfaces. Moreover, the fact that management tasks are performed by humans leads to many configuration errors and low reactivity. This is particularly true in medium or large-scale grid infrastructures. To address this issue, we developed Jade, a middleware for self-management of distributed software environments. In this paper, we report on our experiments in using Jade for the management of grid applications. Mohammed Toure, Girma Berhe, Patricia Stolf, Laurent Broto, Noel De Palma, Daniel Hagimont |
PDP | 6 |
| 2006 | Autonomic Management of Clustered ApplicationsabstractDistributed software environments are increasingly complex and difficult to manage, as they integrate various legacy software with proprietary management interfaces. Moreover, the fact that management tasks are performed by humans leads to many configuration errors and low reactivity. This paper presents Jade, a middleware for self-management of distributed software environments. The main principle is to wrap legacy software pieces in components in order to provide a uniform management interface, thus allowing the implementation of management applications. Management applications are used to deploy distributed applications and to autonomously reconfigure them as required Sara Bouchenak, Noel De Palma, Daniel Hagimont, Christophe Taton |
CLUSTER | 3 |
| 2006 | Self-protection for Distributed Component-Based Applications
Benoit Claudel, Noel De Palma, Renaud Lachaize, Daniel Hagimont |
SSS | 4 |
| 2006 | Self-Sizing of Clustered DatabasesabstractDistributed software environments are increasingly difficult to manage. This paper presents a middleware for the development of self-manageable and autonomic systems. Preliminary experiments for automatically adapting a cluster of replicated databases according to QoS requirements are reported Christophe Taton, Sara Bouchenak, Noel De Palma, Daniel Hagimont, Sylvain Sicard |
WOWMOM | 4 |
| 2005 | Designing Self-adaptive Multimedia Applications Through Hierarchical Reconfiguration
Oussama Layaida, Daniel Hagimont |
DAIS | 2 |
| 2005 | Architecture-Based Autonomous Repair Management: An Application to J2EE ClustersabstractThis paper presents a component-based architecture for autonomous repair management in distributed systems, and a prototype implementation of this architecture, called JADE, which provides repair management for J2EE application server clusters. The JADE architecture features three major elements, which we believe to be of wide relevance for the construction of autonomic distributed systems: (1) a dynamically configurable, component-based structure that exploits the reflective features of the FRACTAL component model; (2) an explicit and configurable feedback control loop structure, that manifests the relationship between the managed system and repair management functions; (3) an original replication structure for the management subsystem itself which makes it fault-tolerant and self-healing. Sara Bouchenak, Fabienne Boyer, Sacha Krakowiak, Daniel Hagimont, Adrian Mos, Jean-Bernard Stefani, Noel De Palma, Vivien Quéma |
SRDS | 4 |
| 2004 | Experiences implementing efficient Java thread serialization, mobility and persistenceabstractAbstract Today, mobility and persistence are important aspects of distributed computing. They have many fields of use such as load balancing, fault tolerance and dynamic reconfiguration of applications. In this context, Java provides many useful mechanisms for the mobility of code via dynamic class loading, and the mobility or persistence of data via object serialization. However, Java does not provide any mechanism for the mobility/persistence of computation (i.e. threads). We designed and implemented a new mechanism, calledJava thread serialization, that is used to build thread mobility or thread persistence. Therefore, a running Java thread can, at an arbitrary state of its execution, migrate to a remote machine where it resumes its execution, or be checkpointed on disk for possible subsequent recovery. With our services, migrating a thread is simply performed by the call of ourgoprimitive, and checkpointing/recovering a thread is performed by the call of ourstoreandloadprimitives. Several projects have recently addressed the issue of Java thread serialization, e.g. Sumatra, Wasp, JavaGo, Brakes, JavaGoX, Merpati. Some of them have attempted to minimize the overhead incurred by the thread serialization mechanism on thread performance, but none of them has been able to completely avoid this overhead. We propose a generic Java thread serialization mechanism that does not impose any performance overhead on serialized threads. This is achieved thanks to the use of type inference and dynamic de‐optimization techniques. In this paper, we describe the design and implementation details of our thread serialization prototype in Sun Microsystems' JDK. We report on experiments conducted with our prototype, present a comparative performance evaluation of the main thread serialization techniques, and confirm the elimination of the performance overhead with our thread serialization mechanism. Copyright © 2003 John Wiley & Sons, Ltd. Sara Bouchenak, Daniel Hagimont, Sacha Krakowiak, Noel De Palma, Fabienne Boyer |
Softw. Pract. Exp. | 2 |
| 2002 | An Architectural Approach to Replication Configuration
Vania Marangozova-Martin, Daniel Hagimont |
OPODIS | 2 |
| 2000 | JCCap: Capability-based Access Control for Java Card
Daniel Hagimont, Jean-Jacques Vandewalle |
CARDIS | 1 |
| 1999 | A Performance Evaluation of the Mobile Agent ParadigmabstractThis paper presents a performance evaluation of the mobile agent paradigm in comparison to the client/server paradigm. This evaluation has been conducted on top of the Java environment, using respectively RMI, the Aglets mobile agents platform and a mobile agents prototype that we implemented. The measurements give the cost of the basic mechanisms involved in the implementation of a mobile agent platform, and a comparative evaluation of the two considered models (client/server and mobile agents) through two application scenarios. The results show that significant performance improvements can be obtained using mobile agents. Leila Ismail, Daniel Hagimont |
OOPSLA | 2 |
| 1997 | A Protection Scheme for Mobile Agents on Javaabstract: This paper describes a protection scheme for mobile agents implemented on a Java environment. In this scheme, access to objects is controlled by means of software capabilities that can be exchanged between mutually suspicious agents. Each agent defines the access control rules that must be enforced when interacting with other agents. An important advantage of the proposed scheme is that the definition of the protection policy of an agent (i.e. how access rights are granted to other agents) is completely separated from the application code of that agent. It is described in an extended Interface Definition Language (IDL) at the interface level, thus enforcing modularity and ease of expression. A prototype has been implemented and experiments with simple agent-based applications have shown the feasibility and the advantage of this method. 1 Introduction Protection is a crucial aspect of distributed computing, in particular when users co-operate using shared objects or shared programs. ... Daniel Hagimont, Leila Ismail |
MobiCom | 1 |
| 1996 | Hidden Software CapabilitiesabstractSoftware capabilities are a very convenient means to protect co-operating applications. They allow access rights to be dynamically exchanged between mutually suspicious interacting applications. However in all the proposed approaches, capabilities are made available at the programming language level, requiring application developers to wire protection definition in the application code, which is detrimental to both flexibility and reusability. We believe instead that capabilities should be hidden from the application programmer allowing protection definition and application code to be clearly separated. In this paper we propose a new protection model based on hidden software capabilities, in which protection definition is completely disjoined from the application code and described in an extended interface definition language (IDL). This allows to specify protection for existing modules and to easily change the protection policy of an application. This protection model can be integrated in a wide range of operating systems. We are currently implementing it in a single address space operating system based on distributed shared memory. Daniel Hagimont, Jacques Mossière, Xavier Rousset de Pina, Frederic Saunier |
ICDCS | 1 |
| 1996 | The Arias Distributed Shared Memory: An Overview
Pascal Dechamboux, Daniel Hagimont, Jacques Mossière, Xavier Rousset de Pina |
SOFSEM | 2 |
| 1994 | Protection in the Guide Object-Oriented Distributed System
Daniel Hagimont |
ECOOP | 1 |
| 1994 | Persistent Shared Object Support in the Guide System: Evaluation & Related WorkabstractThe purpose of the Guide project is to explore the use of shared objects for communication in a distributed system, especially for applications that require cooperative work. Since 1986, two prototypes have been implemented respectively on top of Unix (Guide-1) and Mach 3.0 (Guide-2). They have been used for the development of distributed cooperative applications, allowing us to validate or reject many design choices in the system. Daniel Hagimont, Pierre-Yves Chevalier, André Freyssinet, Sacha Krakowiak, Serge Lacourte, Jacques Mossière, Xavier Rousset de Pina |
OOPSLA | 1 |