Dimitrios P. Pezaros

dblp:49/1051 · also Dimitrios Pezaros, Dimitris Pezaros · DBLP profile ↗
← Back
91ranked-venue papers
5as first author
32since 2021 · last 2026
0000-0003-0939-378XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 61 · 4 first-author · 20 since 2021Systems, architecture and hardware · 8 · 1 since 2021Security and privacy · 5 · 4 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Towards Decarbonised Mobility: Beam Blockage Impacts in 5G-Driven Digital Twin-enabled Intelligent Transport Systems
abstract
Road transport accounts for approximately 75% of emissions within the transportation sector, highlighting the need not only for cleaner vehicles but also for intelligent, connected infrastructure. Cyber-physical infrastructure (CPI) enables emerging technologies such as intelligent transport systems (ITS) and digital twins (DT), providing a foundation for enhanced planning, decision-making, and real-time optimisation. The effectiveness of DT-enabled ITS depends on reliable, low-latency communication networks like 5G and beyond, which face challenges such as beam blockage due to urban mobility and obstructions. To address this challenge, we propose a configurable simulation framework that models realistic urban scenarios, including connected autonomous vehicles (CAVs) dynamics, traffic congestion, and roadside units (RSUs) deployment strategies. Through three case studies, we examine the influence of traffic density, RSU height, and RSU count on beam blockage events and received signal strength (RSS). Our findings highlight key trade-offs: while taller RSUs reduce beam blockages, they incur greater propagation losses; likewise, denser RSU deployments improve connectivity up to a point, beyond which additional units result in marginal improvements. These insights provide practical guidance for designing resilient, low-latency communication infrastructures and highlight the need for intelligent, adaptive solutions to proactively mitigate blockage events in real time for sustainable and time-sensitive ITS applications.
Mohammad Al-Quraan, Runze Cheng, Stefanos Evripidou, Xicheng Li, Philip Greening, David Flynn, Muhammad Ali Imran 0001, Dimitrios P. Pezaros, Ahmad Taha
ICC8
2026 Securing Smart Grids against PSSE FDI attacks
abstract
Cyberattacks such as false data injection (FDI) attack have increased substantially following the digitalization of electric power and energy systems (EPES) and smart grids (SGs). Resilient protection measures are necessitated for these critical infrastructures due to the direct, immediate, and serious effects of FDI, such as generators tripping, transmission lines overloading, and cascading blackouts that cause equipment damage, financial losses, and threat to life. In this paper, we present a deep learning-enabled (DL) in-network FDI attack mitigation strategy using extended berkley packet filtering (eBPF)-based network programmability. Complex algorithms must be approximated to reduced instruction set when implementing cybersecurity solutions in eBPF, however, these approximations lead to precision losses. We present an architecture that integrates non-BPF deep leaning-based network functions into the eBPF data processing pipeline. For an EPES use case, we test the architecture on a proof-of-concept. A stealthy and sparse FDI attack is modelled on the power state system estimations (PSSE). To counter these attacks, we propose a feasible feature extraction and a robust detection and mitigation mechanism. In comparison to the legacy operational technology software-defined networking (OTSDN), performance evaluation reveals a reduction in detection latency of 54.6% and accuracy of up to 99% and F1–score of 0.93. In compliance with society’s growing reliance on the electricity grid network’s continuity, the proposed methodology mitigates disruptive impacts of FDI attacks in a timely manner.
Tahira Mahboob, Filip Holík, Awais Aziz Shah, Dimitrios P. Pezaros
ICC4
2026 Not all who wander are lost: Industrial Network Topology Inference via Tomography Probing
abstract
Understanding the topology of, and interconnectivity within a computer network is fundamental to enabling security, optimising performance, and ensuring digital resilience. This is particularly challenging in the context of Industrial Control Systems (ICS) where networks use alternative topological structures and comprise legacy equipment that is often poorly documented. In this paper, we investigate how network tomography techniques can be used to achieve topology inference in ICS environments. Topology inference through network tomography enables the network topology to be identified without direct monitoring of the internal network elements, making it a promising technique for use in ICS networks which can be difficult to monitor due to being highly physically distributed or difficult to access. Through experimental analysis of active measurement techniques, we evaluate Round Trip Time (RTT) probes and the efficacy of different inference algorithms such as Rooted Neighbour Joining and Maximum Likelihood Tree to achieve topology discovery. The results highlight that existing topology inference approaches achieve average accuracies between 59.7% and 88.6%. Furthermore, we identify that topology structure has the greatest impact on inference accuracy, with PLC vendor and traffic volumes providing lower variation in performance.
Robert Molloy, Marco M. Cook, Dimitrios P. Pezaros
ICC3
2026 Charon: Stratified Priority Sampling for Differentiated Per-Flow Measurement in High-Speed Networks
abstract
Per-flow measurement of priority-heterogeneous traffic underpins cloud service-level agreement (SLA) enforcement, anomaly detection, and distributed AI training in high-speed networks, yet remains challenging in the fast L1/L2-cache memory regime where high-priority flows are vastly outnumbered. We propose Charon, a priority-aware sketch that replaces the structural separation used by prior methods with stratified admission sampling: a single, online-adaptive, parameter-free rule decides whether each packet is admitted to the sketch. Across multiple real-world traces, Charon achieves more than 2× higher detection accuracy for high-priority flows than the best baseline and up to four orders of magnitude lower average error than state-of-the-art priority-aware sketches, with the gap widening as memory tightens, at high processing throughput. The implementation on the industry-grade Tofino switch further demonstrates low resource utilization.
Weihe Li, Xicheng Li, Dimitrios P. Pezaros, Paul Patras
SIGCOMM3
2026 Organisational cybersecurity challenges in digital twin development: A critical analysis and research directions
abstract
In the past decade, Digital Twins (DTs) have emerged as a key enabler of industry digitalisation. As digital representations of physical objects and processes, DTs integrate a range of technologies to support applications from process monitoring to policymaking. However, increased system integration expands their attack surface, heightening cybersecurity risks. Efforts to integrate DTs into larger ecosystems have further intensified these concerns. Cybersecurity is inherently a socio-technical challenge influenced by various organisational and governance considerations. However, cybersecurity research on DTs has remained predominantly technical. As such, the current understanding of how organisational cybersecurity challenges emerge in DT contexts is limited. This work addresses this gap through a critical analysis of literature, examining how cybersecurity is conceptualised in DT implementation and the extent to which organisational cybersecurity challenges are addressed. Our analysis demonstrates that cybersecurity is widely acknowledged as a challenge in DT implementation. Nevertheless, most research offers limited in-depth analysis of specific cybersecurity challenges in real-world contexts. When addressed, cybersecurity was primarily framed around confidentiality and privacy, while other elements including data integrity and system availability are overlooked. Where cybersecurity has been the primary focus, works have been overwhelmingly technical, overlooking organisational complexities that affect cybersecurity in practice. This highlights a clear gap in understanding of how organisational cybersecurity challenges emerge in DTs. We conclude by outlining an agenda for future research to support more effective and secure approaches to DT implementation.
Stefanos Evripidou, Xicheng Li, Mohammad Al-Quraan, Runze Cheng, Ahmad Taha, Muhammad Ali Imran 0001, David Flynn, Dimitrios P. Pezaros
Comput. Secur.8
2026 With Power comes Responsibility: Attack Synthesis for Industrial Control Systems using Large Language Models
abstract
Large Language Models (LLM) such as ChatGPT, Meta AI, and Google Gemini have become highly accessible and ubiquitous across a wide range of applications, including speech synthesis, code generation, and media content creation. Recent research indicates that an alternative motivation for such tools is to rapidly develop malware to conduct cyber attacks. In this article, we investigate how generative LLM tools can be used to synthesise cyber-attacks targeting Industrial Control Systems (ICS). We introduce a methodology that uses LLMs to generate attack techniques based on the MITRE attack framework to target a variety of Programmable Logic Controllers (PLC) models from by different industrial vendors. We investigate the capability of five leading off-the-shelf LLMs by providing different levels of attacker context to enhance the generation. Through a comprehensive evaluation of the generated code and the resulting LLM outputs, we demonstrate that current general-purpose LLMs are capable of identifying the necessary steps required to synthesise attacks that can manipulate the operations of real PLCs. We highlight that the success of LLM-generated PLC cyberattacks depends on the level of target context initially provided, emphasising the importance of mitigating early-stage reconnaissance attacks in OT environments.
Marco M. Cook, Andrei Stoica, Awais Aziz Shah, Dimitrios P. Pezaros
ACM Trans. Priv. Secur.4
2025 Personalizing Low-Rank Bayesian Neural Networks Via Federated Learning
abstract
To support real-world decision-making, it is crucial for models to be well-calibrated, i.e., to assign reliable confidence estimates to their predictions. Uncertainty quantification is particularly important in personalized federated learning (PFL), as participating clients typically have small local datasets, making it difficult to unambiguously determine optimal model parameters. Bayesian PFL (BPFL) methods can potentially enhance calibration, but they often come with considerable computational and memory requirements due to the need to track the variances of all the individual model parameters. Furthermore, different clients may exhibit heterogeneous uncertainty levels owing to varying local dataset sizes and distributions. To address these challenges, we propose LR-BPFL, a novel BPFL method that learns a global deterministic model along with personalized low-rank Bayesian corrections. To tailor the local model to each client’s inherent uncertainty level, LR-BPFL incorporates an adaptive rank selection mechanism. We evaluate LR-BPFL across a variety of datasets, demonstrating its advantages in terms of calibration, accuracy, as well as computational and memory requirements. The code is available at \url{https://github.com/Bernie0115/LR-BPFL.}
Dongzhu Liu, Osvaldo Simeone, Guanchu Wang, Dimitrios P. Pezaros, Guangxu Zhu
AISTATS5
2025 Online Model Checking for Anomaly Detection in Industrial Control Systems
abstract
Cyber attacks on Industrial Control Systems (ICSs) are becoming increasingly sophisticated, undermining the ability of these systems to manage critical processes and compromising the availability of key public infrastructure. Detecting system anomalies is an important element in the identification of cyber attacks, allowing the rapid deployment of crucial incident-response activities. In this paper, we introduce a novel anomaly detection approach that integrates SPIN model checking into ICS environments to detect anomalies in live system data. Our approach uses the application code extracted from Programmable Logic Controllers (PLCs) to generate the dynamic system model, requiring only a small amount of test data to validate their design. We evaluate our approach by generating models using a representative physical hydroelectric dam testbed containing real PLCs. These models are used to analyse synthetic data containing potential irregularities that could occur within the dam as a result of false data injection attacks. Our approach was shown to identify anomalies and verify normal system behaviour. Our evaluation shows that the models achieved high performance while maintaining explainability and delivering metrics of 99.99% precision, 99.05% recall, a 99.52% F1-score, and 99.05% accuracy.
Douglas Fraser, Alice Miller 0001, Marco M. Cook, Dimitrios P. Pezaros
iFM4
2025 An eBPF-Based Programmable Network Architecture for OT Digital Resilience Use-Cases
abstract
BPF has enabled, among other use-cases, highly scalable network softwarization via a fully programmable data plane architecture. Previous approaches such as software-defined networking (SDN) and P4 offered some degree of programmability, but required specialized target devices tailored mostly for high-performance data center environments. With eBPF, more complex network functions can be supported even on smaller form factor and lower capacity devices, making it a suitable network softwarization framework for Operation Technology (OT) networks. In our previous work, we introduced BPFabric a platform, protocol and language-independent SDN architecture leveraging a single eBPF program for the data plane implementation. In this work, we modify the original BPFabric architecture by adding an eBPF execution engine pipeline which supports network function chaining and allows sequencing of eBPF programs to achieve complex network functionality. Additionally, we add the application layer which hosts high-level services and provides network visualization and control via a northbound interface. We demonstrate the new architecture on a use-case of an OT network topology composed of programmable devices with various resilience eBPF functions managed by a single controller. The results show architecture flexibility in dynamic function orchestration while being fully transparent from OT devices and causing minimum performance overhead.
Filip Holík, Simon Jouet, Dimitrios P. Pezaros
ISCC3
2025 Dataplane-Only DNS Caching in P4
abstract
Programmable data planes have been widely used for traffic manipulation at a fine granularity within the constraints of onboard resources. Caching clear-text DNS traffic (Do53) in campus networks is a natural use case for in-network acceleration since more than 99.84% of the top 10 k queried domains can be fitted into a 64-byte field, according to recent (May 2024) Cisco statistics. In this paper, we introduce an in-network DNS cache layer implemented using P4, which leverages register space to store cache entries and manage insertions and updates entirely within the data plane, thereby avoiding communication overhead with the switch-local control plane. Our research shows that the proposed solution achieves superior performance, particularly in tail latency measurements when compared to the conventional Dnsmasq implementation prevalent in network devices and Linux distributions.
Xicheng Li, Dimitrios P. Pezaros
ISCC2
2025 xMem: A CPU-Based Approach for Accurate Estimation of GPU Memory in Deep Learning Training Workloads
Jiabo Shi, Dimitrios P. Pezaros, Yehia El-khatib
Middleware2
2025 Artefact Provenance Graphs for Anomaly Inference in Industrial Control Systems
Marco M. Cook, Dimitrios P. Pezaros
SEC (1)2
2025 Guest Editorial: Edge-Intelligence for Real-Time Computer Vision in 6G
Guodong Zhao 0001, Changyang She, Hao Su 0001, Dusit Niyato, Simon See, Dimitrios P. Pezaros
IEEE J. Sel. Areas Commun.6
2024 In-network real-time flow classification using hierarchical decision trees
abstract
In-network computing has emerged as a promising approach to offload ML-related functionality from servers to network devices, leveraging the advanced capabilities of programmable network devices and expressive data plane programming languages such as P4. By implementing ML models in the data plane, we can achieve high throughput and low latency inference, reducing server loads, and enhancing response times.This work proposes a novel hierarchical deployment for Decision Tree models (HDT) within the network data plane, designed for real-time flow classification of the network traffic. The hierarchical structure breaks down a complex classification into multiple levels each one refining the classification progressively.Our results demonstrate the feasibility and efficiency of executing Hierarchical Decision Tree models in the network data plane, achieving high performance in classifying a 12-class classification scenario. The HDT performs better in the data plane by 26% compared to a flat Decision Tree implementation and 12% compared to a flat Random Forest implementation.
Teodor Karkashina, Awais Aziz Shah, Dimitrios P. Pezaros
CNSM3
2023 Towards Latency-aware vNF Placement on Heterogeneous Hosts at the Network Edge
abstract
In this paper, we investigate the optimal placement of vNFs over the distributed edge network while considering the heterogeneity of packet processing elements. Unlike previous efforts in this domain, our proposed hybrid placement scheme places vNFs on user space hosts and the network data plane to efficiently minimise end-to-end path latency and achieve faster service delivery. We formulate and solve the Hybrid vNF Placement Problem as a linear integer programming (ILP) problem and propose a hybrid placement heuristic algorithm (HYPHA), which performs an incremental placement of vNFs on heterogeneous hosts to find a near-optimal solution to the problem quickly. We evaluated our proposed solution using a simulation of real-world network topology with realistic latency conditions. We show that leveraging the fast packet processing speed of the network data plane in conjunction with abundant user space resources for vNF placement yields minimal overall end-to-end latency and fulfils the placement of a diverse set of vNF requests to speed up service delivery. Also, our results show that HYPHA can obtain near-optimal vNF mapping while incurring fewer latency threshold violations set by network operators.
Haruna Umar Adoga, Dimitrios P. Pezaros
GLOBECOM2
2023 Tracking IoT P2P Botnet Loaders in the Wild
abstract
Evidently, centralised botnets are nowadays considered as easy targets for take-down efforts by law enforcement and computer security researchers. Hence, malicious actors transitioned towards the implementation of Peer-to-Peer (P2P) IoT botnets such to solidify their infrastructures, avoid single points of failure and further evade back tracking. Consequently, due to the highly distributed persona of modern P2P botnets, the detection of critical nodes to aid for the effective capturing of emerging threat vectors in such setups evolved into a challenging task. In this work, we conduct a novel 24-month longitudinal study based on real Internet measurements from globally distributed honeypots focusing on propagation trends of P2P IoT botnets. In order to achieve this, we develop graph-based centrality metrics to attribute AS-level connectivity characteristics to botnet and malware propagation as well as relating AS-level tolerance for botnet malware hosts we refer to as loaders. In general, we argue that the proposed methodology and outcomes of the herein study, can significantly benefit security experts and network operators towards the design of mitigation measures against present and future P2P botnets.
Hatem A. Almazarqi, Mathew Woodyard, Troy Mursch, Dimitrios P. Pezaros, Angelos K. Marnerides
ICC4
2023 PLCPrint: Fingerprinting Memory Attacks in Programmable Logic Controllers
abstract
Programmable Logic Controllers (PLCs) constitute the functioning basis of Industrial Control Systems (ICS) and hence are often a focal point for attackers to exploit. Previous attacks have seen PLC memory maliciously altered in order to disrupt the underlying physical process. Different types of memory attack can cause a similar impact on the PLC’s operation and result in indistinguishable physical manifestations. Consequently, delays in triaging attacks through digital forensic practices can induce significant financial loss, physical damage to the infrastructure, and degradation of safety. In this work, we propose PLCPrint, a novel vendor-independent fingerprinting approach that utilises PLC memory artefacts to perform detection and classification of memory attacks. PLCPrint uses PLC memory register mapping, a novel method exploiting the relationship between PLC registers and memory artefacts including the PLC application code. Through this, registers are assigned a Mapping Condition (MC) to indicate how they exist within the PLC memory artefacts. We evaluate the performance of PLCPrint over realistic emulations conducted at a real testbed emulating water filtration and distribution. Through PLCPrint we depict how MC deviations are utilised within supervised learning schemes such as to adequately classify PLC memory attacks with high accuracy performance. In general, we demonstrate that PLCPrint fills the gap in the context of attack technique triaging since this has been a missing element within current ICS forensics schemes.
Marco M. Cook, Angelos K. Marnerides, Dimitrios P. Pezaros
IEEE Trans. Inf. Forensics Secur.3
2022 Scalable Data Plane Caching for Kubernetes
abstract
Computation offloading to the programmable data plane enabled the acceleration of key-value stores which offer coordination services for large-scale data centres. Previous research reduced the response latency of key-value requests by half through deploying the store in the programmable data plane. In this work, we examine Kubernetes’ central store, etcd, as a candidate for deployment in data plane. We discuss performance and scalability limitations existing in the default architecture of Kubernetes and how these can be alleviated through data plane offloading. Moreover, we investigate previous design decisions of in-network caching mechanisms that led to increased traffic generation and latency. We propose a new in-network key-value store platform that maintains strong consistency and fault-tolerance while improving performance and scalability over the state-of-the-art.
Stefanos Sagkriotis, Dimitrios P. Pezaros
CNSM2
2022 Macroscopic Analysis of IoT Botnets
abstract
The adoption of the IoT by modern sociotechnical systems in synergy with the rapid deployment of insecure IoT devices and services has transformed the cyber-threat landscape. Thus, the vast majority of cyberattacks are underpinned by the orchestration of compromised IoT devices that are globally distributed and controlled through carefully designed IoT botnets. Contrary to conventional belief, cybersecurity vectors instrumented by such botnets are not always uniformly distributed across Internet Autonomous Systems (ASes). By virtue of network structural characteristics imposed by each individual Autonomous System (AS) as well as the diversity in terms of AS-level cybersecurity policies, the spatiotemporal manifestation of IoT botnets differs. In this work, we provide a novel measurement study that empirically quantifies AS tolerance of IoT botnet propagation in the global IPv4 Internet. We assess and correlate measurements gathered by globally distributed honeypots, Internet regional registries and IP blacklists for a 15-month period and observe more than 3.2M malicious events triggered by IoT botnets spanning 9.5K ASes. Our work demonstrates that ASes connected to a low number of providers are prone to embrace a high portion of malicious activities. Hence, we provide evidence on concentrated botnet activities and determine the effectiveness of widely used IP blacklists. In general, this study contributes towards empowering knowledge on large-scale cyber-attacks as being crucial for the composition of next generation data-driven cybersecurity defence applications.
Hatem A. Almazarqi, Mathew Woodyard, Troy Mursch, Dimitrios P. Pezaros, Angelos K. Marnerides
GLOBECOM4
2022 Scale-friendly In-network Coordination
abstract
The programmability of modern network devices has led to innovative research in the area of in-network computing, i.e., offloading certain computations to the programmable data plane. Key-value stores, which offer coordination services for many large-scale data centres, benefited from this technological advancement. Previous research reduced the response latency of key-value requests by half through deploying the store in the programmable data plane. In this work, we identify previous design decisions that have led to increased traffic generation and latency for in-network coordination services. We have developed a new in-network key-value store platform that maintains strong consistency and fault-tolerance, while improving performance and scalability over the state-of-the-art. We have designed and implemented the platform in P4, and analysed the optimisations that unlock these performance improvements. Our evaluation shows a reduction of up to orders of magnitude in latency and significant improvements in throughput. We obtain up to nine times higher throughput for scenarios with multiple participating nodes, indicative of the superior scalability the platform can offer.
Stefanos Sagkriotis, Dimitrios P. Pezaros
GLOBECOM2
2022 Anomaly Diagnosis in Cyber-Physical Systems
abstract
Cyber-Physical Systems (CPS) constitute the operational basis for a number of critical national infrastructure (CNI) sectors including but not limited to manufacturing, smart electrical grids and water utilities, where programmable networked systems enable physical processes. Programmable Logic Controllers (PLCs) play a vital role in this by controlling CPS processes and consequently have become a primary target for cyber attacks that aim to disrupt CPS. By contrast with conventional networked setups, the operational and safety-critical importance of PLCs introduce challenges for CNI operators on empirically determining if an incident is a cyber-attack or a system fault as both occurrences can display similar outputs on the physical process. Moreover, existing anomaly detection techniques explicit to PLCs primarily give indication of an incident rather than attempting to categorise what the incident is. In this paper, we introduce a novel PLC anomaly diagnosis framework defined by a two-stage identification and classification approach based on novelty detection. Through the use of PLC run-time and network communication data generated by physical processes on a representational CPS testbed, we achieve an average of 99.35% on anomaly profiling accuracy and highlight the distinctions between system faults and cyber-attacks. In general, we demonstrate a practical approach that can be adopted by next generation CPS cyber defence tools.
Marco M. Cook, Cory Paterson, Angelos K. Marnerides, Dimitrios P. Pezaros
ICC4
2022 On the Performance Benefits of Heterogeneous Virtual Network Function Execution Frameworks
abstract
As the adoption of softwarized network functions (NFs) keeps growing, we evaluate the performance benefits of SDN-aware data-plane implementations when compared to diverse acceleration and process-based NFV frameworks. Typical network functions have been implemented using four alternative frameworks scenarios, an SDN-aware software switch (data-plane), a virtual machine (VM), a Data-Plane Development Kit (DPDK) NF, and a containerized NF. Results from our experiments show that the data-plane NF implementation yields much higher bandwidth and packets per second (pps) rates. The bandwidth obtained is 14% more than the user-space scenario while retaining CPU utilization. The DPDK NFs in our evaluation can process packets at a much higher rate for 64B packets, on a single CPU core, which is 7 times higher than the containerized NF implementations, also tied to a single core. Our results also show the performance gains from deploying virtual network functions on heterogeneous frameworks.
Haruna Umar Adoga, Yehia El-khatib, Dimitrios P. Pezaros
NetSoft3
2022 Revisiting the Classics: Online RL in the Programmable Dataplane
abstract
Data-driven networking is becoming more capable and widely researched, partly driven by the efficacy of Deep Reinforcement Learning (DRL) algorithms. Yet the complexity of both DRL inference and learning force these tasks to be pushed away from the dataplane to hosts, harming latency-sensitive applications. Online learning of such policies cannot occur in the dataplane, despite being useful techniques when problems evolve or are hard to model.We present OPaL—On Path Learning—the first work to bring online reinforcement learning to the dataplane. OPaL makes online learning possible in constrained SmartNIC hardware by returning to classical RL techniques—avoiding neural networks. Our design allows weak yet highly parallel SmartNIC NPUs to be competitive against commodity x86 hosts, despite having fewer features and slower cores. Compared to hosts, we achieve a 21 × reduction in 99.99thtail inference times to 34 µs, and 9.9 × improvement in online throughput for real-world policy designs. In-NIC execution eliminates PCIe transfers, and our asynchronous compute model ensures minimal impact on traffic carried by a co-hosted P4 dataplane. OPaL’s design scales with additional resources at compile-time to improve upon both decision latency and throughput, and is quickly reconfigurable at runtime compared to reinstalling device firmware.
Kyle A. Simpson, Dimitrios P. Pezaros
NOMS2
2022 Dynamic UPF placement and chaining reconfiguration in 5G networks
abstract
Network function virtualization (NFV) and multi-access edge computing (MEC) have become two crucial pillars in developing 5G and beyond networks. NFV promises cost-saving and fast revenue generation through dynamic instantiation and the scaling of virtual network functions (VNFs) according to time-varying service demands. Additionally, MEC provides considerable reductions in network response time and backhaul traffic since network functions and server applications can be deployed close to users. Nevertheless, the placement and chaining of VNFs at the network edge is challenging due to numerous aspects and attendant trade-offs. This paper addresses the problem of dynamic user plane function placement and chaining reconfiguration (UPCR) in a MEC environment to cope with user mobility while guaranteeing cost reductions and acceptable quality of service (QoS). The problem is formalized as a multi-objective integer linear programming model to minimize multiple cost components involved in the UPCR procedure. We propose a heuristic algorithm called dynamic priority and cautious UPCR (DPC-UPCR) to reduce the solution time complexity. Additionally, we devise a scheduler mechanism based on optimal stopping theory to determine the best reconfiguration time according to instantaneous values of latency violations and a pre-established QoS threshold. Our detailed simulation results evidence the efficiency of the proposed approaches. Specifically, the DPC-UPCR provides near-optimal solutions, within 15% of the optimum in the worst case, in significantly shorter times than the mathematical model. Moreover, the proposed scheduling method outperforms two scheduler baseline solutions regarding the number of reconfiguration events and QoS levels.
Irian Leyva-Pupo, Cristina Cervello-Pastor, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros
Comput. Networks4
2022 Guest Editors' Introduction: Special Section on Smart Management of Future Softwarized Networks
abstract
Network softwarization is one of the key enablers of the future Internet evolution, also supporting the road from the fifth generation (5G) to the next-generation communication systems, namely 6G, with their main objective of bringing hyper-connected experience to every corner of society.
Giovanni Schembra, Wolfgang Kellerer, Christian Jacquenet, Noriaki Kamiyama, Barbara Martini, Rafael Pasquini, Dimitrios P. Pezaros, Roberto Riggio, Hongke Zhang, Mohamed Faten Zhani, Thomas Zinner
IEEE Trans. Netw. Serv. Manag.7
2021 Online RL in the programmable dataplane with OPaL
abstract
Reinforcement learning (RL) is a key tool in data-driven networking for learning to control systems online. While recent research has shown how to offload machine learning tasks to the dataplane (reducing processing latency), online learning remains an open challenge unless the model is moved back to a host CPU, harming latency-sensitive applications. Our poster introduces OPaL---On Path Learning---the first work to bring online reinforcement learning to the dataplane. OPaL makes online learning possible in SmartNIC/NPU hardware by returning to classical RL techniques---avoiding neural networks. This simplifies update logic, enabling online learning, and benefits well from the parallelism common to SmartNICs. We show that our implementation on Netronome SmartNIC hardware offers concrete latency improvements over host execution.
Kyle A. Simpson, Dimitrios P. Pezaros
CoNEXT2
2021 Profiling IoT Botnet Activity in the Wild
abstract
Undoubtedly, the Internet of Things (IoT) contributes significantly to daily mission-critical processes underpinning a number of socio-technical systems. Conversely, its rapid adoption has extensively broadened the cyber-threat landscape by virtue of low-cost IoT devices that are manufactured and deployed with minimal security. Evidently, vulnerable IoT devices are utilised by attackers to participate into Internet-wide botnets in order to instrument large-scale cyber-attacks and disrupt critical Internet services. Since the 2016 outbreak of the first IoT Mirai botnet there has been a continuous evolution of Mirai-like variants. Tracking these botnets is challenging due to their varying structural characteristics, and also due to the fact that malicious actors continuously adopt new evasion and propagation strategies. This work provides a new measurement study highlighting specific behavioural properties of Mirai-like botnets in terms of their propagation. We provide a comprehensive analysis conducted on real Cyber Threat Intelligence (CTI) feeds gathered for a period of 7 months from globally distributed attack honeypots and pinpoint the evolutionary port scanning patterns, targeted vulnerabilities and preferred services pursued by Mirai-like botnets. We identify the most frequently active Mirai-like malware binaries and we are the first to report the evolution of a new, P2P-based variant. In parallel, we provide evidence related to the lack of vendor-specific patching through highlighting unpatched vulnerabilities. Moreover, we pinpoint the inadequacy of widely used IP blacklisting databases to timely list malicious IP addresses. Thus, arguing in fair of integrating honeypot information from diverse Internet vantage points within the design of next generation botnet defence mechanisms.
Hatem A. Almazarqi, Angelos K. Marnerides, Troy Mursch, Mathew Woodyard, Dimitrios P. Pezaros
GLOBECOM5
2021 Optimized Contextual Data Offloading in Mobile Edge Computing
Ibrahim Alghamdi, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros
IM3
2021 Towards QoS-aware Provisioning of Chained Virtual Security Services in Edge Networks
Mircea Iordache, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros
IM3
2021 TSMF: Network Latency Estimation using Matrix Factorization and Time Series Forecasting
abstract
The ability to accurately estimate end-to-end network latencies is extremely important for many services, from overlay network formation to Edge computing and 5G. Research in Network Coordinate Systems (NCS) has over the years focused on providing such estimates while conserving network resources by avoiding excessive probing. However, Internet latencies are inherently unstable and estimates produced by existing NCS's are shown to quickly become obsolete. In this paper, we devise TSMF, a novel NCS method based on an ensemble of Time-Series Forecasting and Matrix Factorization (MF). Fusing the two approaches results in a model that takes advantage of the low-rank structure of end-to-end latencies and temporal correlations with past measurements. In addition, TSMF can forecast future end-to-end latencies which has been impossible using existing NCS approaches. Our results demonstrate that TSMF outperforms Euclidean and MF-based NCS's with up to 6× less relative error in predicting end-to-end latencies. We also demonstrate the accuracy of TSMF in forecasting future end-to-end latencies, and its consequent suitability for services such as web-service recommendation.
Fotis Savva, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros
Networking3
2021 Data quality-aware task offloading in Mobile Edge Computing: An Optimal Stopping Theory approach
Ibrahim Alghamdi, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros
Future Gener. Comput. Syst.3
2021 Guest Editors Introduction: Special Issue on Advanced Management of Softwarized Networks
abstract
The Softwarization of networks is enabled by the SDN (Software-Defined Networking), NV (Network Virtualization), and NFV (Network Function Virtualization) paradigms, and offers many advantages for network operators, service providers and data-center providers. Given the strong interest in both industry and academia in the softwarization of telecommunication networks and cloud computing infrastructures, a series of special issues was established in IEEE Transactions on Network and Service Management, which aims at the timely publication of recent innovative research results on the management of softwarized networks.
Wolfgang Kellerer, Giovanni Schembra, Jinho Hwang, Noriaki Kamiyama, Joon-Myung Kang, Barbara Martini, Rafael Pasquini, Dimitrios P. Pezaros, Hongke Zhang, Mohamed Faten Zhani, Thomas Zinner
IEEE Trans. Netw. Serv. Manag.8
2020 Seiðr: Dataplane Assisted Flow Classification Using ML
abstract
Real-time, high-speed flow classification is fundamental for network operation tasks, including reactive and proactive traffic engineering, anomaly detection and security enhancement. Existing flow classification solutions, however, do not allow operators to classify traffic based on fine-grained, temporal dynamics due to imprecise timing, often rely on sampled data, or only work with low traffic volumes and rates. In this paper, we present Seior, a classification solution that: (i) uses precision timing, (ii) has the ability to examine every packet on the network, (iii) classifies very high traffic volumes with high precision. To achieve this, Seior exploits the data aggregation and timestamping functionality of programmable dataplanes. As a concrete example, we present how Seior can be used together with Machine Learning algorithms (such as CNN, k-NN) to provide accurate, real-time and high-speed TCP congestion control classification, separating TCP BBR from its predecessors with over 88-96% accuracy and F1-score of 0.864-0.965, while only using 15.5 MiB of memory in the dataplane.
Kyle A. Simpson, Richard Cziva, Dimitrios P. Pezaros
GLOBECOM3
2020 In-Network Placement of Security VNFs in Multi-Tenant Data Centers
abstract
Middleboxes are typically hardware-accelerated appliances such as firewalls, Proxies, WAN optimizers, and NATs that play an important role in service provisioning over today’s Data Centers. We focus on the placement of virtualised security services in multi-tenant Data Centers. Customised security services are provided to tenants as software VNF modules collocated with switches in the network. Our placement formulation satisfies the allocation constraints while maintaining efficient management of the infrastructure resources. We propose a Constraint Programming (CP) formulation and a CPLEX implementation. We also formulate a heuristic-based algorithm to solve larger instances of the placement problem. Extensive evaluation of the algorithms has been conducted, demonstrating that the VNF approach provides more than 50% reduction in resource consumption compared to other heuristic algorithms.
Abeer Ali, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros
ISCC3
2020 Dynamic Scheduling and Optimal Reconfiguration of UPF Placement in 5G Networks
abstract
Multi-access Edge Computing (MEC) is a key technology in the road to 5G and beyond networks. Significant reductions in both latency and backhaul traffic can be achieved by placing server applications, and network functions at the network edge. However, this implies new challenges for their dynamic placement and management. In this paper, we tackle the problem of dynamic placement reconfiguration of 5G User Plane Functions (UPFs) in a MEC ecosystem to adapt to changes in user locations while ensuring QoS and network operator expenditures reduction. In this vein, an Integer Linear Programming (ILP) solution is proposed to determine the optimal UPF placement configuration (e.g., number of UPFs and user-UPF mapping) by considering several cost components along with service requirements. Moreover, a scheduling technique based on Optimal Stopping Theory (OST) is presented to decide the optimal reconfiguration time according to instantaneous values of latency violations and established QoS thresholds. Extensive simulation results demonstrate their effectiveness, achieving significant improvements in metrics such as number of re-computation events, reconfiguration costs, and number of latency violations over time.
Irian Leyva-Pupo, Cristina Cervello-Pastor, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros
MSWiM4
2020 Performance analysis of single board computer clusters
abstract
The past few years have seen significant developments in Single Board Computer (SBC) hardware capabilities. These advances in SBCs translate directly into improvements in SBC clusters. In 2018 an individual SBC has more than four times the performance of a 64-node SBC cluster from 2013. This increase in performance has been accompanied by increases in energy efficiency (GFLOPS/W) and value for money (GFLOPS/$). We present systematic analysis of these metrics for three different SBC clusters composed of Raspberry Pi 3 Model B, Raspberry Pi 3 Model B+ and Odroid C2 nodes respectively. A 16-node SBC cluster can achieve up to 60 GFLOPS, running at 80 W. We believe that these improvements open new computational opportunities, whether this derives from a decrease in the physical volume required to provide a fixed amount of computation power for a portable cluster; or the amount of compute power that can be installed given a fixed budget in expendable compute scenarios. We also present a new SBC cluster construction form factor named Pi Stack; this has been designed to support edge compute applications rather than the educational use-cases favoured by previous methods. The improvements in SBC cluster performance and construction techniques mean that these SBC clusters are realising their potential as valuable developmental edge compute devices rather than just educational curiosities.
Philip James Basford, Steven J. Ossont, Colin Perkins, Tony Garnock-Jones, Fung Po Tso 0001, Dimitrios P. Pezaros, Robert Mullins 0001, Eiko Yoneki, Jeremy Singer, Simon J. Cox 0001
Future Gener. Comput. Syst.6
2020 Per-Host DDoS Mitigation by Direct-Control Reinforcement Learning
abstract
DDoS attacks plague the availability of online services today, yet like many cybersecurity problems are evolving and non-stationary. Normal and attack patterns shift as new protocols and applications are introduced, further compounded by burstiness and seasonal variation. Accordingly, it is difficult to apply machine learning-based techniques and defences in practice. Reinforcement learning (RL) may overcome this detection problem for DDoS attacks by managing and monitoring consequences; an agent's role is to learn to optimise performance criteria (which are always available) in an online manner. We advance the state-of-the-art in RL-based DDoS mitigation by introducing two agent classes designed to act on a per-flow basis, in a protocol-agnostic manner for any network topology. This is supported by an in-depth investigation of feature suitability and empirical evaluation. Our results show the existence of flow features with high predictive power for different traffic classes, when used as a basis for feedback-loop-like control. We show that the new RL agent models can offer a significant increase in goodput of legitimate TCP traffic for many choices of host density.
Kyle A. Simpson, Simon Rogers, Dimitrios P. Pezaros
IEEE Trans. Netw. Serv. Manag.3
2020 Transition to SDN is HARMLESS: Hybrid Architecture for Migrating Legacy Ethernet Switches to SDN
abstract
Software-Defined Networking (SDN) offers a new way to operate, manage, and deploy communication networks and to overcome many long-standing problems of legacy networking. However, widespread SDN adoption has not occurred yet due to the lack of a viable incremental deployment path and the relatively immature present state of SDN-capable devices on the market. While continuously evolving software switches may alleviate the operational issues of commercial hardware-based SDN offerings, namely lagging standards-compliance, performance regressions, and poor scaling, they fail to match the cost-efficiency and port density. In this paper, we propose HARMLESS, a new SDN switch design that seamlessly adds SDN capability to legacy network gear, by emulating the OpenFlow switch OS in a separate software switch component. This way, HARMLESS enables a quick and easy leap into SDN, combining the rapid innovation and upgrade cycles of software switches with the port density and cost-efficiency of hardware-based appliances into a fully dataplane-transparent and vendor-neutral solution. HARMLESS incurs an order of magnitude smaller initial expenditure for an SDN deployment than existing turnkey vendor SDN solutions while, at the same time, yields matching, or even better, data plane performance for smaller enterprises.
Levente Csikor, Mark Szalay, Gábor Rétvári, Gergely Pongrácz, Dimitrios P. Pezaros, László Toka
IEEE/ACM Trans. Netw.5
2019 Tuple space explosion: a denial-of-service attack against a software packet classifier
abstract
Efficient and highly available packet classification is fundamental for various security primitives. In this paper, we evaluate whether the de facto Tuple Space Search (TSS) packet classification algorithm used in popular software networking stacks such as the Open vSwitch is robust against low-rate denial-of-service attacks. We present the Tuple Space Explosion (TSE) attack that exploits the fundamental space/time complexity of the TSS algorithm.
Levente Csikor, Dinil Mon Divakaran, Min Suk Kang, Attila Korösi, Balázs Sonkoly, Dávid Haja, Dimitrios P. Pezaros, Stefan Schmid 0001, Gábor Rétvári
CoNEXT7
2019 On the Optimality of Task Offloading in Mobile Edge Computing Environments
abstract
Mobile Edge Computing (MEC) has emerged as new computing paradigm to improve the QoS of users' applications. A challenge in MEC is computation (task/data) offloading, whose goal is to enhance the mobile devices' capabilities to face the requirements of new applications. Computation offloading faces the challenges of where and when to offload data to perform computing (analytics) tasks. In this paper, we tackle this problem by adopting the principles of Optimal Stopping Theory contributing with two time-optimized sequential decision making models. A performance evaluation is provided using real world data sets compared with baseline deterministic and stochastic models. The results show that our approach optimizes such decision in single user and competitive users scenarios.
Ibrahim Alghamdi, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros
GLOBECOM3
2019 BIDS: Bio-Inspired, Collaborative Intrusion Detection for Software Defined Networks
abstract
With network attacks becoming more sophisticated and unpredictable, detecting their onset and mitigating their effects in an automated manner become increasingly challenging. Lightweight and agile detection mechanisms that are able to detect zero-day attacks are in great need. High true-negative rate and low false-positive rate are the most important indicators for a intrusion detection system. In this paper, we exploit the logically-centralised view of Software-Defined Networking (SDN) to increase true-negative rate and lower false-positive rate in a intrusion detection system based on the Artificial Immune System (AIS). We propose the use of an antibody fuser in the controller to merge and fuse the mature antibody sets trained in the individual switches and turn the real intrusion records each switch has seen into antibodies. Our results show that both the false-positive rate and true-negative rate experience significant improvement with the number of local antibody sets fused grows, consuming less cpu usage overhead. A peak improvement can reach over 80% when antibody sets from all switches are taken into consideration.
Qianru Zhou, Dimitrios P. Pezaros
ICC2
2019 Energy Usage Profiling for Virtualized Single Board Computer Clusters
abstract
With Network Function Virtualization (NFV) platforms gaining ground, we question the combination of NFV and Single Board Computers (SBCs) in terms of compatibility, reliability, and energy consumption. A mini cluster of SBCs is used to develop a scalable and resilient energy monitoring application. The application is employed to discover the energy demands of a NFV platform in modern SBCs, and build the energy profile of the devices and the deployed services. We use the results and the added knowledge from building the application to strengthen the argument that SBC clusters can support virtualized service deployment. This evidence, alongside the rich gamut of characteristics that SBCs hold, proves that they are a viable option for edge components of a fog network. Our results show that running different virtualised processes offers added functionality, resilience and scalability without heavily sacrificing energy consumption.
Stefanos Sagkriotis, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros
ISCC3
2019 Knowledge-centric Analytics Queries Allocation in Edge Computing Environments
abstract
The Internet of Things involves a huge number of devices that collect data and deliver them to the Cloud. The processing of data at the Cloud is characterized by increased latency in providing responses to analytics queries defined by analysts or applications. Hence, Edge Computing (EC) comes into the scene to provide data processing close to the source. The collected data can be stored in edge devices and queries can be executed there to reduce latency. In this paper, we envision a case where entities located in the Cloud undertake the responsibility of receiving analytics queries and decide on the most appropriate edge nodes for queries execution. The decision is based on statistical signatures of the datasets of nodes and the statistical matching between statistics and analytics queries. Edge nodes regularly update their statistical signatures to support such decision process. Our performance evaluation shows the advantages and the shortcomings of our proposed schema in edge computing environments.
Stefanos Sagkriotis, Kostas Kolomvatsos, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros, Stathes Hadjiefthymiades
ISCC4
2019 High-performance, platform-independent DDoS detection for IoT ecosystems
abstract
Most Distributed Denial of Service (DDoS) detection and mitigation strategies for Internet of Things (IoT) are based on a remote cloud server or purpose-built middlebox executing complex intrusion detection methods, that impose stringent scalability and performance requirements on the IoT due to the vast amounts of traffic and devices to be handled. In this paper, we present an edge-based detection scheme using BPFabric, a high-speed, programmable data-plane switch architecture, and lightweight network functions to execute upstream anomaly detection. The proposed detection scheme ensures fast detection of DDoS attacks originated from IoT devices, while guaranteeing minimum resource usage and processing overhead. Our solution was compared against two widespread coarse-grained detection techniques, showing detection delays under 5ms, an overall accuracy of 93 - 95% and a bandwidth overhead of less than 1%.
Alejandro Santoyo-González, Cristina Cervello-Pastor, Dimitrios P. Pezaros
LCN3
2018 On the Optimality of Virtualized Security Function Placement in Multi-Tenant Data Centers
abstract
Security and service protection against cyber attacks remain among the primary challenges for virtualized, multi-tenant Data Centres (DCs), for reasons that vary from lack of resource isolation to the monolithic nature of legacy middleboxes. Although security is currently considered a property of the underlying infrastructure, diverse services require protection against different threats and at timescales which are on par with those of service deployment and elastic resource provisioning. We address the resource allocation problem of deploying customised security services over a virtualized, multi-tenant DC. We formulate the problem in Integral Linear Programming (ILP) as an instance of the NP-hard variable size variable cost bin packing problem with the objective of maximising the residual resources after allocation. We propose a modified version of the Best Fit Decreasing algorithm (BFD) to solve the problem in polynomial time and we show that BFD optimises the objective function up to 80% more than other algorithms.
Abeer Ali, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros
ICC3
2018 Dynamic, Latency-Optimal vNF Placement at the Network Edge
abstract
Future networks are expected to support low-latency, context-aware and user-specific services in a highly flexible and efficient manner. One approach to support emerging use cases such as, e.g., virtual reality and in-network image processing is to introduce virtualized network functions (vNF)s at the edge of the network, placed in close proximity to the end users to reduce end-to-end latency, time-to-response, and unnecessary utilisation in the core network. While placement of vNFs has been studied before, it has so far mostly focused on reducing the utilisation of server resources (i.e., minimising the number of servers required in the network to run a specific set of vNFs), and not taking network conditions into consideration such as, e.g., end-to-end latency, the constantly changing network dynamics, or user mobility patterns. In this paper, we formulate the Edge vNF placement problem to allocate vNFs to a distributed edge infrastructure, minimising end-to-end latency from all users to their associated vNFs. We present a way to dynamically re-schedule the optimal placement of vNFs based on temporal network-wide latency fluctuations using optimal stopping theory. We then evaluate our dynamic scheduler over a simulated nation-wide backbone network using real-world ISP latency characteristics. We show that our proposed dynamic placement scheduler minimises vNF migrations compared to other schedulers (e.g., periodic and always-on scheduling of a new placement), and offers Quality of Service guarantees by not exceeding a maximum number of latency violations that can be tolerated by certain applications.
Richard Cziva, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros
INFOCOM3
2018 Analytical Hierarchy Process Multi-Metric Objective Function for RPL
abstract
IPv6 Routing Protocol for Low Power and Lossy Networks (RPL), is based on building an acyclic graph where an Objective Function (OF) is responsible for selecting the preferred parent during Destination Oriented Directed Acyclic Graph (DODAG) construction. In this paper, we propose a new multi-metric OF based on Analytical Hierarchy Processes decision masking algorithm. AHP-OF, combines a set of routing metrics aiming to provide the best routing decision for RPL to satisfy the different application requirements for LLN s such as reliable applications, real time applications and highly available applications. Here we focus on the theoretical aspect of AHP-OF, and finally we evaluate the performance of AHP-OF compared to other OFs using Cooja simulator.
Walaa Alayed, Lewis M. Mackenzie, Dimitrios P. Pezaros
NCA3
2018 Next generation single board clusters
abstract
Until recently, cluster computing was too expensive and too complex for commodity users. However the phenomenal popularity of single board computers like the Raspberry Pi has caused the emergence of the single board computer cluster. This demonstration will present a cheap, practical and portable Raspberry Pi cluster called Pi Stack. We will show pragmatic custom solutions to hardware issues, such as power distribution, and software issues, such as remote updating. We also sketch potential use cases for Pi Stack and other commodity single board computer cluster architectures.
Jeremy Singer, Herry Herry, Philip James Basford, Wajdi Hajji, Colin Perkins, Fung Po Tso 0001, Dimitrios P. Pezaros, Robert Mullins 0001, Eiko Yoneki, Simon J. Cox 0001, Steven J. Ossont
NOMS7
2018 Internet traffic characterisation: Third-order statistics & higher-order spectra for precise traffic modelling
abstract
Undoubtedly, the characterisation of network traffic flows is vitally important in understanding the dynamics of Internet traffic and in appropriately dimensioning network resources for network and systems management. The vast majority of modelling techniques developed for volume-based traffic profiling (based on packet and/byte counts) imply the statistical assumptions of stationarity, Gaussianity and linearity, which are often taken for granted without being explicitly validated. In this paper, we demonstrate that such properties are often not applicable due to the high fluctuations in Internet traffic, and should therefore be validated first before they are assumed. We employ Time-Frequency (TF) representations and the Hinich algorithms for validating these three modelling assumptions on real backbone and edge network traces. We show by conducting a passive, offline statistical analysis on real operational network traffic traces from both backbone and edge links that link traffic is extremely dynamic irrespective of the level of aggregation and that model characteristics vary. Subsequently, we propose the use of a representative of higher order spectra, the bispectrum, to act as a particularly suitable method for volume-based traffic profiling due to its ability to adapt to different underlying statistical assumptions, as opposed to ARIMA timeseries models that have been typically used in the literature. We demonstrate that the bispectrum, a signal processing tool that has so far been used in the area of image processing and acoustic signals, can be exploited to accurately characterise traffic volumes per transport protocol, and can therefore contribute to fine-grained network operations tasks such as application classification and anomaly detection.
Angelos K. Marnerides, Dimitrios P. Pezaros, David Hutchison 0001
Comput. Networks2
2018 Commodity single board computer clusters and their applications
abstract
Current commodity Single Board Computers (SBCs) are sufficiently powerful to run mainstream operating systems and workloads. Many of these boards may be linked together, to create small, low-cost clusters that replicate some features of large data center clusters. The Raspberry Pi Foundation produces a series of SBCs with a price/performance ratio that makes SBC clusters viable, perhaps even expendable. These clusters are an enabler for Edge/Fog Compute, where processing is pushed out towards data sources, reducing bandwidth requirements and decentralizing the architecture. In this paper we investigate use cases driving the growth of SBC clusters, we examine the trends in future hardware developments, and discuss the potential of SBC clusters as a disruptive technology. Compared to traditional clusters, SBC clusters have a reduced footprint, are low-cost, and have low power requirements. This enables different models of deployment—particularly outside traditional data center environments. We discuss the applicability of existing software and management infrastructure to support exotic deployment scenarios and anticipate the next generation of SBC. We conclude that the SBC cluster is a new and distinct computational deployment paradigm, which is applicable to a wider range of scenarios than current clusters. It facilitates Internet of Things and Smart City systems and is potentially a game changer in pushing application logic out towards the network edge.
Steven J. Ossont, Philip James Basford, Colin Perkins, Herry Herry, Fung Po Tso 0001, Dimitrios P. Pezaros, Robert Mullins 0001, Eiko Yoneki, Simon J. Cox 0001, Jeremy Singer
Future Gener. Comput. Syst.6
2018 An Inter-Domain Collaboration Scheme to Remedy DDoS Attacks in Computer Networks
abstract
Distributed denial-of-service (DDoS) attacks continue to trouble network operators and service providers, and with increasing intensity. Effective response to DDoS can be slow (because of manual diagnosis and interaction) and potentially self-defeating (as indiscriminate filtering accomplishes a likely goal of the attacker), and this is the result of the discrepancy between the service provider's flow-based, application-level view of traffic and the network operator's packet-based, network-level view and limited functionality. Furthermore, a network required to take action may be in an autonomous system (AS) several AShops away from the service, so it has no direct relationship with the service on whose behalf it acts. This paper presents Antidose, a means of interaction between a vulnerable peripheral service and an indirectly related AS that allows the AS to confidently deploy local filtering with discrimination under the control of the remote service. We implement the core filtering mechanism of antidose, and provide an analysis of it to demonstrate that conscious attacks against the mechanism will not expose the AS to additional attacks. We present a performance evaluation to show that the mechanism is operationally feasible in the emerging trend of operators' willingness to increase the programmability of their hardware with SDN technologies such as OpenFlow, as well as to act to mitigate attacks on downstream customers.
Steven Simpson, Noor-ul-Hassan Shirazi, Angelos K. Marnerides, Simon Jouet, Dimitrios P. Pezaros, David Hutchison 0001
IEEE Trans. Netw. Serv. Manag.5
2017 On the Latency Benefits of Edge NFV
abstract
Next-generation networks are expected to support low-latency, context-aware and user-specific services in a highly flexible and efficient manner. Proposed applications include high-definition, low-latency video streaming, remote surgery, as well as applications for tactile Internet, virtual or augmented reality that demand network side data processing (such as image recognition, transformation or head/eye motion aware rendering). One approach to support these use cases is to introduce virtualized network services at the edge of the network, in close proximity of the end users to reduce end-to-end latency, time-to-response and unnecessary utilization of the core network, while providing flexibility for resource allocation. While many research projects including our previous work on Glasgow Network Functions have proposed running virtual network functions (vNF)s at the network edge, a latency-optimal placement allocation has not been presented before for the network edge and therefore the impact on user-to-vNF latency has not been investigated. In this paper, we formulate a simple vNF placement problem that minimizes end-to-end latency from users to their network functions. We have implemented the problem using Integer Linear Programming (ILP) with the Gurobi solver, and evaluated it with a real topology of a network provider. We use our solution to compare two vNF deployment scenarios over an emulation of a national backbone network: a two-tier edge deployment and a cloud-only deployment. We show that, in our example, using edge servers can deliver up to 70% improvement in user-to-vNF latency.
Richard Cziva, Dimitrios P. Pezaros
ANCS2
2017 BPFabric: Data Plane Programmability for Software Defined Networks
abstract
In its current form, OpenFlow, the de facto implementation of SDN, separates the network's control and data planes allowing a central controller to alter the match-action pipeline using a limited set of fields and actions. To support new protocols, forwarding logic, telemetry, monitoring or even middlebox-like functions the currently available programmability in SDN is insufficient. In this paper, we introduce BPFabric, a platform, protocol, and language-independent architecture to centrally program and monitor the data plane. BPFabric leverages eBPF, a platform and protocol independent instruction set to define the packet processing and forwarding functionality of the data plane. We introduce a control plane API that allows data plane functions to be deployed on-the-fly, reporting events of interest and exposing network internal state to the centralised controller. We present a raw socket and DPDK implementation of the design, the former for large-scale experimentation using environment such as Mininet and the latter for high-performance low-latency deployments. We show through examples that functions unrealisable in OpenFlow can leverage this flexibility while achieving similar or better performance to today's static design.
Simon Jouet, Dimitrios P. Pezaros
ANCS2
2017 Distributed network anomaly detection on an event processing framework
abstract
Network Intrusion Detection Systems (NIDS) are an integral part of modern data centres to ensure high availability and compliance with Service Level Agreements (SLAs). Currently, NIDS are deployed on high-performance, high-cost middleboxes that are responsible for monitoring a limited section of the network. The fast increasing size and aggregate throughput of modern data centre networks have come to challenge the current approach to anomaly detection to satisfy the fast growing compute demand. In this paper, we propose a novel approach to distributed intrusion detection systems based on the architecture of recently proposed event processing frameworks. We have designed and implemented a prototype system using Apache Storm to show the benefits of the proposed approach as well as the architectural differences with traditional systems. Our system distributes modules across the available devices within the network fabric and uses a centralised controller for orchestration, management and correlation. Following the Software Defined Networking (SDN) paradigm, the controller maintains a complete view of the network but distributes the processing logic for quick event processing while performing complex event correlation centrally. We have evaluated the proposed system using publicly available data centre traces and demonstrated that the system can scale with the network topology while providing high performance and minimal impact on packet latency.
Atanas Pamukchiev, Simon Jouet, Dimitrios P. Pezaros
CCNC3
2017 A programmable SDN+NFV-based architecture for UAV telemetry monitoring
abstract
The explosive growth in the worldwide use of Unmanned Aerial Vehicles (UAVs) has raised a critical concern with respect to the adequate management of their ad hoc network configuration as required by their mobility management process. As UAVs migrate among ground control stations, associated network services, routing and operational control must also rapidly migrate to ensure a seamless transition. In this paper, we present a novel, lightweight and modular architecture which supports high mobility and situational-awareness through the application of Software Defined Networking (SDN) and Network Function Virtualization (NFV) principles on top of the UAV infrastructure. By combining SDN+NFV programmability we can achieve a robust migration of UAV-related network services, such as network monitoring and anomaly detection as well as smooth UAV migration that confronts high mobility requirements. The proposed container-based monitoring and anomaly detection Network Functions (NFs) as employed within our architecture can be tuned to specific UAV types providing operators better insight during live, high-mobility deployments. We evaluate our architecture against telemetry from over 80 flights from a scientific research UAV infrastructure showing our ability to tune and detect emerging challenges.
Kyle J. S. White, Ewen Denney, Matt D. Knudson, Angelos K. Marnerides, Dimitrios P. Pezaros
CCNC5
2017 Resource-aware placement of softwarised security services in cloud data centers
abstract
Virtualizing middleboxes as software for Cloud tenants can eliminate the monolithic processing and static deployment of legacy middleboxes and provide an efficient provisioning for security services. However, inefficient managing of the virtualized security services can reduce the gains of Cloud deployment. We propose a resources-efficient placement of the security functions in the infrastructure of a three-tier Cloud DC by modifying the Best-Fit Decreasing algorithm to solve the problem while satisfying the placement resources and traffic constraints.
Abeer Ali, Christos Anagnostopoulos 0001, Dimitrios P. Pezaros
CNSM3
2017 End-Host Driven Troubleshooting Architecture for Software-Defined Networking
abstract
The high variability in traffic demands, the advanced networking services at various layers (e.g., load-balancers), and the steady penetration of SDN technology and virtualization make the crucial network troubleshooting tasks ever more challenging over multi-tenant environments. Service degradation is first realized by the users and, as being the only one having visibility to many relevant information (e.g., connection details) required for accurate and timely problem resolution, the infrastructure layer is often forced upon continuous monitoring resulting in wasteful resource management, not to mention the long time frames. In this paper, we propose an End-host-Driven Troubleshooting architecture (EDT), where users are able to share the application-specific connection details with the infrastructure to accelerate the identification of root causes of performance degradation, and to avoid the need for always-on, resource-intensive, and network-wide monitoring. Utilizing EDT, we provide some essential tools for real end-to-end trace routing (PTR), identifying packet losses, and carry out hop-by- hop latency measurements (HEL). In contrast to existing proposals, PTR traces the practical production traffic without the need of crafted probe packets by means of careful tagging mechanisms and additional ephemeral capturing flow rules. Besides involving negligible data plane deterioration, in certain cases PTR can drastically reduce the time needed to find a traversed path compared to existing solutions. Finally, by means of individual network functions, HEL measures the latency of each link along the found path without involving the controller into the calculation, hence resulting in significant reduction of control plane overhead.
Levente Csikor, Dimitrios P. Pezaros
GLOBECOM2
2017 Distributed, multi-level network anomaly detection for datacentre networks
abstract
Over the past decade, numerous systems have been proposed to detect and subsequently prevent or mitigate security vulnerabilities. However, many existing intrusion or anomaly detection solutions are limited to a subset of the traffic due to scalability issues, hence failing to operate at line-rate on large, high-speed datacentre networks. In this paper, we present a two-level solution for anomaly detection leveraging independent execution and message passing semantics. We employ these constructs within a network-wide distributed anomaly detection framework that allows for greater detection accuracy and bandwidth cost saving through attack path reconstruction. Experimental results using real operational traffic traces and known network attacks generated through the Pytbull IDS evaluation framework, show that our approach is capable of detecting anomalies in a timely manner while allowing reconstruction of the attack path, hence further enabling the composition of advanced mitigation strategies. The resulting system shows high detection accuracy when compared to similar techniques, at least 20% better at detecting anomalies, and enables full path reconstruction even at small-to-moderate attack traffic intensities (as a fraction of the total traffic), saving up to 75% of bandwidth due to early attack detection.
Mircea Iordache, Simon Jouet, Angelos K. Marnerides, Dimitrios P. Pezaros
ICC4
2017 Experimental evaluation of SDN-controlled, joint consolidation of policies and virtual machines
abstract
Middleboxes (MBs) are ubiquitous in modern data centre (DC) due to their crucial role in implementing network security, management and optimisation. In order to meet network policy's requirement on correct traversal of an ordered sequence of MBs, network administrators rely on static policy based routing or VLAN stitching to steer traffic flows. However, dynamic virtual server migration in virtual environment has greatly challenged such static traffic steering. In this paper, we design and implement Sync, an efficient and synergistic scheme to jointly consolidate network policies and virtual machines (VMs), in a readily deployable Mininet environment. We present the architecture of Sync framework and open source its code. We also extensively evaluate Sync over diverse workload and policies. Our results show that in an emulated DC of 686 servers, 10k VMs, 8k policies, and 100k flows, Sync processes a group of 900 VMs and 10 VMs in 634 seconds and 4 seconds respectively.
Wajdi Hajji, Fung Po Tso 0001, Lin Cui 0001, Dimitrios P. Pezaros
ISCC4
2017 Uncertainty-driven ensemble forecasting of QoS in Software Defined Networks
abstract
Software Defined Networking (SDN) is the key technology for combining networking and Cloud solutions to provide novel applications. SDN offers a number of advantages as the existing resources can be virtualized and orchestrated to provide new services to the end users. Such a technology should be accompanied by powerful mechanisms that ensure the end-to-end quality of service at high levels, thus, enabling support for complex applications that satisfy end users needs. In this paper, we propose an intelligent mechanism that agglomerates the benefits of SDNs with real-time “Big Data” forecasting analytics. The proposed mechanism, as part of the SDN controller, supports predictive intelligence by monitoring a set of network performance parameters, forecasting their future values, and deriving indications on potential service quality violations. By treating the performance measurements as time-series, our mechanism employs a novel ensemble forecasting methodology to estimate their future values. Such predictions are fed to a Type-2 Fuzzy Logic system to deliver, in real-time, decisions related to service quality violations. Such decisions proactively assist the SDN controller for providing the best possible orchestration of the virtualized resources. We evaluate the proposed mechanism w.r.t. precision and recall metrics over synthetic data.
Kostas Kolomvatsos, Christos Anagnostopoulos 0001, Angelos K. Marnerides, Qiang Ni, Stathes Hadjiefthymiades, Dimitrios P. Pezaros
ISCC6
2017 PLAN: Joint Policy- and Network-Aware VM Management for Cloud Data Centers
abstract
Policies play an important role in network configuration and therefore in offering secure and high performance services especially over multi-tenant Cloud Data Center (DC) environments. At the same time, elastic resource provisioning through virtualization often disregards policy requirements, assuming that the policy implementation is handled by the underlying network infrastructure. This can result in policy violations, performance degradation and security vulnerabilities. In this paper, we define PLAN, a PoLicy-Aware and Network-aware VM management scheme to jointly consider DC communication cost reduction through Virtual Machine (VM) migration while meeting network policy requirements. We show that the problem is NP-hard and derive an efficient approximate algorithm to reduce communication cost while adhering to policy constraints. Through extensive evaluation, we show that PLAN can reduce topology-wide communication cost by 38 percent over diverse aggregate traffic and configuration policies.
Lin Cui 0001, Fung Po Tso 0001, Dimitrios P. Pezaros, Weijia Jia 0001, Wei Zhao 0001
IEEE Trans. Parallel Distributed Syst.3
2016 Synergistic policy and virtual machine consolidation in cloud data centers
abstract
In modern Cloud Data Centers (DC)s, correct implementation of network policies is crucial to provide secure, efficient and high performance services for tenants. It is reported that the inefficient management of network policies accounts for 78% of DC downtime, challenged by the dynamically changing network characteristics and by the effects of dynamic Virtual Machine (VM) consolidation. While there has been significant research in policy and VM management, they have so far been treated as disjoint research problems. In this paper, we explore the simultaneous, dynamic VM and policy consolidation, and formulate the Policy-VM Consolidation (PVC) problem, which is shown to be NP-Hard. We then propose Sync, an efficient and synergistic scheme to jointly consolidate network policies and virtual machines. Extensive evaluation results and a testbed implementation of our controller show that policy and VM migration under Sync significantly reduces flow end-to-end delay by nearly 40%, and network-wide communication cost by 50% within few seconds, while adhering strictly to the requirements of network policies.
Lin Cui 0001, Richard Cziva, Fung Po Tso 0001, Dimitrios P. Pezaros
INFOCOM4
2016 OTCP: SDN-managed congestion control for data center networks
abstract
TCP suffers from incast collapse in data center networks when used with partition aggregate workloads due to inadequate congestion control parameters. This causes poor application performance by under-utilizing the network, and can be one of the limiting factors in low-latency, high-throughput environments. To resolve this, we present Omniscient TCP (OTCP), a Software Defined Networking (SDN) approach to compute environment-specific congestion control parameters based on centrally available network properties. Through experimental evaluation in Mininet, we show up to 12x and 31x reduction in Flow Completion Time (FCT) at the mean and 95th percentile, an 8x FCT improvement on highly congested networks when combined with DCTCP [1], as well as improved fairness and reduced end-to-end latency.
Simon Jouet, Colin Perkins, Dimitrios P. Pezaros
NOMS3
2016 Roaming Edge vNFs using Glasgow Network Functions
abstract
While the network edge is becoming more important for the provision of customized services in next generation mobile networks, current NFV architectures are unsuitable to meet the increasing future demand. They rely on commodity servers with resource-hungry Virtual Machines that are unable to provide the high network function density and mobility requirements necessary for upcoming wide-area and 5G networks.
Richard Cziva, Simon Jouet, Dimitrios P. Pezaros
SIGCOMM3
2016 Network and server resource management strategies for data centre infrastructures: A survey
abstract
The advent of virtualisation and the increasing demand for outsourced, elastic compute charged on a pay-as-you-use basis has stimulated the development of large-scale Cloud Data Centres (DCs) housing tens of thousands of computer clusters. Of the significant capital outlay required for building and operating such infrastructures, server and network equipment account for 45 and 15% of the total cost, respectively, making resource utilisation efficiency paramount in order to increase the operators’ Return-on-Investment (RoI). In this paper, we present an extensive survey on the management of server and network resources over virtualised Cloud DC infrastructures, highlighting key concepts and results, and critically discussing their limitations and implications for future research opportunities. We highlight the need for and benefits of adaptive resource provisioning that alleviates reliance on static utilisation prediction models and exploits direct measurement of resource utilisation on servers and network nodes. Coupling such distributed measurement with logically centralised Software Defined Networking (SDN) principles, we subsequently discuss the challenges and opportunities for converged resource management over converged ICT environments, through unifying control loops to globally orchestrate adaptive and load-sensitive resource provisioning.
Fung Po Tso 0001, Simon Jouet, Dimitrios P. Pezaros
Comput. Networks3
2016 SDN-Based Virtual Machine Management for Cloud Data Centers
abstract
Software-defined networking (SDN) is an emerging paradigm to logically centralize the network control plane and automate the configuration of individual network elements. At the same time, in cloud data centers (DCs), although network and server resources are collocated and managed by a single administrative entity, disjoint control mechanisms are used for their respective management. In this paper, we propose a unified server-network resource management for such converged information and communication technology (ICT) environments. We present a SDN-based orchestration framework for live virtual machine (VM) management that exploits temporal network information to migrate VMs and minimize the network-wide communication cost of the resulting traffic dynamics. A prototype implementation is presented, and a cloud DC testbed is used to evaluate the impact of diverse orchestration algorithms. Our live VM management has been shown to reduce the network-wide communication cost, especially for the high-cost and congestion-prone core and aggregation layers of the DC. Our results show an increase in network-wide throughput by over six times, as well as over 70% communication cost reduction by migrating less than 50% of the VMs.
Richard Cziva, Simon Jouet, David Stapleton, Fung Po Tso 0001, Dimitrios P. Pezaros
IEEE Trans. Netw. Serv. Manag.5
2015 Arbitrary packet matching in OpenFlow
abstract
OpenFlow has emerged as the de facto control protocol to implement Software-Defined Networking (SDN). In its current form, the protocol specifies a set of fields on which it matches packets to perform actions, such as forwarding, discarding or modifying specific protocol header fields at a switch. The number of match fields has increased with every version of the protocol to extend matching capabilities, however, it is still not flexible enough to match on arbitrary packet fields which limits innovation and new protocol development with OpenFlow. In this paper, we argue that a fully flexible match structure is superior to continuously extending the number of fields to match upon. We use Berkeley Packet Filters (BPF) for packet classification to provide a protocol-independent, flexible alternative to today's OpenFlow fixed match fields. We have implemented a prototype system and evaluated the performance of the proposed match scheme, with a focus on the time it takes to execute and the memory required to store different match filter specifications. Our prototype implementation demonstrates that line-rate arbitrary packet classification can be achieved with complex BPF programs.
Simon Jouet, Richard Cziva, Dimitrios P. Pezaros
HPSR3
2015 Stable infrastructure-based routing for Intelligent Transportation Systems
abstract
Intelligent Transportation Systems (ITSs) have been instrumental in reshaping transportation towards safer roads, seamless logistics, and digital business-oriented services under the umbrella of smart city platforms. Undoubtedly, ITS applications will demand stable routing protocols that not only focus on Inter-Vehicle Communications but also on providing a fast, reliable and secure interface to the infrastructure. In this paper, we propose a novel stable infrastructure-based routing protocol for urban VANETs. It enables vehicles proactively to maintain fresh routes towards Road-Side Units (RSUs) while reactively discovering routes to nearby vehicles. It builds routes from highly stable connected intersections using a selection policy which uses a new intersection stability metric. Simulation experiments performed with accurate mobility and propagation models have confirmed the efficiency of the new protocol and its adaptability to continuously changing network status in the urban environment.
Gubran Al-Kubati, Ahmed Yassin Al-Dubai, Lewis M. Mackenzie, Dimitrios P. Pezaros
ICC4
2015 Policy-Aware Virtual Machine Management in Data Center Networks
abstract
Policies play an important role in network configuration and, therefore, in offering secure and high performance services, especially over multi-tenant Cloud Data Center (DC) environments. At the same time, elastic resource provisioning through virtualization often disregards policy requirements, assuming that the policy implementation is handled by the underlying network infrastructure. In this paper, we define PLAN, a Policy-Aware virtual machine management scheme to jointly consider DC communication cost reduction through Virtual Machine (VM) migration while meeting network policy requirements.
Lin Cui 0001, Fung Po Tso 0001, Dimitrios P. Pezaros, Weijia Jia 0001, Wei Zhao 0001
ICDCS3
2015 Container-based network function virtualization for software-defined networks
abstract
Today's enterprise networks almost ubiquitously deploy middlebox services to improve in-network security and performance. Although virtualization of middleboxes attracts a significant attention, studies show that such implementations are still proprietary and deployed in a static manner at the boundaries of organisations, hindering open innovation. In this paper, we present an open framework to create, deploy and manage virtual network functions (NF)s in OpenFlow-enabled networks. We exploit container-based NFs to achieve low performance overhead, fast deployment and high reusability missing from today's NFV deployments. Through an SDN northbound API, NFs can be instantiated, traffic can be steered through the desired policy chain and applications can raise notifications. We demonstrate the systems operation through the development of exemplar NFs from common Operating System utility binaries, and we show that container-based NFV improves function instantiation time by up to 68% over existing hypervisor-based alternatives, and scales to one hundred co-located NFs while incurring sub-millisecond latency.
Richard Cziva, Simon Jouet, Kyle J. S. White, Dimitrios P. Pezaros
ISCC4
2014 Using Programmable Data Networks to Detect Critical Infrastructure Challenges
Kyle J. S. White, Dimitrios P. Pezaros, Christopher W. Johnson 0001
CRITIS2
2014 Scalable Traffic-Aware Virtual Machine Management for Cloud Data Centers
abstract
Virtual Machine (VM) management is a powerful mechanism for providing elastic services over Cloud Data Centers (DC)s. At the same time, the resulting network congestion has been repeatedly reported as the main bottleneck in DCs, even when the overall resource utilization of the infrastructure remains low. However, most current VM management strategies are traffic-agnostic, while the few that are traffic-aware only concern a static initial allocation, ignore bandwidth oversubscription, or do not scale. In this paper we present S-CORE, a scalable VM migration algorithm to dynamically reallocate VMs to servers while minimizing the overall communication footprint of active traffic flows. We formulate the aggregate VM communication as an optimization problem and we then define a novel distributed migration scheme that iteratively adapts to dynamic traffic changes. Through extensive simulation and implementation results, we show that S-CORE achieves significant (up to 87%) communication cost reduction while incurring minimal overhead and downtime.
Fung Po Tso 0001, Eleni Kavvadia, Dimitrios P. Pezaros
ICDCS4
2014 Efficient road topology based broadcast protocol for VANETs
abstract
Intelligent Transportation Systems have been instrumental in reshaping transportation towards safer roads, seamless logistics, and digital business-oriented services under the umbrella of smart city platforms. Broadcasting transmission is an essential operational technique that serves a broad range of applications which demand different restrictive QoS provisioning levels. Although broadcast communication has been investigated widely in highway vehicular networks, it is undoubtedly still a challenge in the urban environment due to the obstacles. In this paper, we propose the Road-Topology based Broadcast Protocol (RTBP) is proposed, a distance and contention-based forwarding scheme suitable for both urban and highway vehicular environments. RTBP aims at assigning the highest forwarding priority to a car, called a mobile repeater, having the greatest capability to send the packet in multiple directions. Realistic experimental environments are used to test the performance against well-known protocols. The results show that RTBP can reduce latency, increase reachability and save system resources.
Gubran Al-Kubati, Ahmed Yassin Al-Dubai, Lewis M. Mackenzie, Dimitrios P. Pezaros
WCNC4
2014 A two-level Markov model for packet loss in UDP/IP-based real-time video applications targeting residential users
abstract
The packet loss characteristics of Internet paths that include residential broadband links are not well understood, and there are no good models for their behaviour. This complicates the design of real-time video applications targeting home users, since it is difficult to choose appropriate error correction and concealment algorithms without a good model for the types of loss observed. Using measurements of residential broadband networks in the UK and Finland, we show that existing models for packet loss, such as the Gilbert model and simple hidden Markov models, do not effectively model the loss patterns seen in this environment. We present a new two-level Markov model for packet loss that can more accurately describe the characteristics of these links, and quantify the effectiveness of this model. We demonstrate that our new packet loss model allows for improved application design, by using it to model the performance of forward error correction on such links.
Martin Ellis, Dimitrios P. Pezaros, Theodore Kypraios, Colin Perkins
Comput. Networks2
2013 Implementing Scalable, Network-Aware Virtual Machine Migration for Cloud Data Centers
abstract
Virtualization has been key to the success of Cloud Computing through the on-demand allocation of shared hardware resources to Virtual Machines (VM)s. However, the network-agnostic placement of VMs over the underlying network topology can itself be a factor of performance degradation by causing congestion at the core layers of the infrastructure where bandwidth is heavily oversubscribed. In this paper, we design and implement S-CORE, a scalable live VM migration scheme to dynamically reallocate VMs to servers while minimizing the overall communication footprint of active traffic flows. We evaluate S- CORE over diverse aggregate load and coordination policies. Our results show that it can achieve up to a 87% communication cost reduction with a limited number of migration rounds, and can be easily accommodated within commodity hardware and hypervisor architectures. The associated memory, CPU, and network overhead are also minimum under typical Cloud Data Center workloads.
Fung Po Tso 0001, Gregg Hamilton, Dimitrios P. Pezaros
IEEE CLOUD4
2013 Internet traffic classification using energy time-frequency distributions
abstract
We present a fundamentally new approach to classify application flows based on the mapping of aggregate transport-layer volume information onto the Time-Frequency (TF) plane. We initially show that the volume persona (i.e. counts of packets and bytes) of traffic flows at the transport layer exhibits highly non-stationary characteristics, hence rendering many typical classification methods inapplicable. By virtue of this constraint, we present a novel application classification method based on the Cohen energy TF distributions for such highly non-stationary signals. We have used the Rényi information to measure the distinct complexity of any given application signal, and to subsequently construct a robust training model for every application protocol within our scheme. The effectiveness of our approach is demonstrated using real backbone and edge link network traces captured in US and Japan. Our results show that for the majority of applications, aggregate volume-based classification can reach up to 96% accuracy, while considering significantly less features in comparison with existing approaches.
Angelos K. Marnerides, Dimitrios P. Pezaros, David Hutchison 0001
ICC2
2013 Longer Is Better: Exploiting Path Diversity in Data Center Networks
abstract
Data Center (DC) networks exhibit much more centralized characteristics than the legacy Internet, yet they are operated by similar distributed routing and control algorithms that fail to exploit topological redundancy to deliver better and more sustainable performance. Multipath protocols, for example, use node-local and heuristic information to only exploit path diversity between shortest paths. In this paper, we use a measurement-based approach to schedule flows over both shortest and non-shortest paths based on temporal network-wide utilization. We present the Baatdaat flow scheduling algorithm which uses spare DC network capacity to mitigate the performance degradation of heavily utilized links. Results show that Baatdaat achieves close to optimal Traffic Engineering by reducing network-wide maximum link utilization by up to 18% over Equal-Cost Multi-Path (ECMP) routing, while at the same time improving flow completion time by 41% - 95%.
Fung Po Tso 0001, Gregg Hamilton, Rene Weber, Colin Perkins, Dimitrios P. Pezaros
ICDCS5
2013 Measurement-based TCP parameter tuning in cloud data centers
abstract
TCP congestion control has been a native part of all modern Operating System implementations where parameters are initialized assuming an underlying high Bandwidth Delay Product (BDP) environment. However, the significantly lower BDP in Data Centre (DC) networks makes such conservative transport-layer parameters together with deep-buffered switches and bursty traffic a factor of performance degradation, eventually leading to throughput incast collapse. In this paper, we propose a Software Defined Networking (SDN) approach to tune TCP initial window and retransmission timers for newly created flows based on a network-wide view created by aggregating known characteristics and temporal measurements at a central controller. Through simulation, we show the detrimental effect static TCP parameters have on mice flows and demonstrate the benefits of network-aware per-flow tuning. We show that the average latency under bursty traffic can be improved by a factor of eight, and that flow start and completion times can be improved by a factor of two and five, respectively.
Simon Jouet, Dimitrios P. Pezaros
ICNP2
2013 Baatdaat: Measurement-based flow scheduling for cloud data centers
abstract
Software-Defined Networking (SDN) allows for efficient network-wide Traffic Engineering through the logical centralization of the control plane over individual switches that perform packet forwarding independently. Such abstraction is particularly suitable for Data Center (DC) networks that need to react to fluctuating traffic dynamics over short timescales. In this paper, we propose a low-cost, SDN-based system that exposes the temporal network-wide utilization through direct measurement, rather than estimation. We then present the Baatdaat1flow scheduling algorithm which uses spare DC network capacity to mitigate the performance degradation of heavily utilized links. Results show that Baatdaat achieves close to optimal Traffic Engineering by reducing network-wide maximum link utilization by up to 18% over ECMP, while at the same time improving flow completion time by as much as 41% - 95% for different types of flows.
Fung Po Tso 0001, Dimitrios P. Pezaros
ISCC2
2013 Improving Data Center Network Utilization Using Near-Optimal Traffic Engineering
abstract
Equal cost multiple path (ECMP) forwarding is the most prevalent multipath routing used in data center (DC) networks today. However, it fails to exploit increased path diversity that can be provided by traffic engineering techniques through the assignment of nonuniform link weights to optimize network resource usage. To this extent, constructing a routing algorithm that provides path diversity over nonuniform link weights (i.e., unequal cost links), simplicity in path discovery and optimality in minimizing maximum link utilization (MLU) is nontrivial. In this paper, we have implemented and evaluated the Penalizing Exponential Flow-spliTing (PEFT) algorithm in a cloud DC environment based on two dominant topologies, canonical and fat tree. In addition, we have proposed a new cloud DC topology which, with only a marginal modification of the current canonical tree DC architecture, can further reduce MLU and increase overall network capacity utilization through PEFT routing.
Fung Po Tso 0001, Dimitrios P. Pezaros
IEEE Trans. Parallel Distributed Syst.2
2012 Modelling packet loss in RTP-based streaming video for residential users
abstract
Packet loss is a major problem for real-time Internet applications. Markov models of packet loss are often used to develop and evaluate the performance of these applications. Despite their wide use, these models have not been validated in terms of how well they capture the loss conditions experienced by residential Internet users. We evaluate the accuracy of common packet loss models using traces of IPTV-like traffic measured on residential ADSL and Cable links, and find that these models are insufficient to capture the observed packet loss patterns. We introduce a new type of model, incorporating packet delay information, and show improved accuracy over previous models.
Martin Ellis, Dimitrios P. Pezaros, Theodore Kypraios, Colin Perkins
LCN2
2012 BSense: A Flexible and Open-Source Broadband Mapping Framework
Giacomo Bernardi, Damon Fenacci, Mahesh K. Marina, Dimitrios P. Pezaros
Networking (1)4
2012 User-level data center tomography
abstract
Measurement and inference in data centers present a set of opportunities and challenges distinct from the Internet domain. Existing toolsets may be perturbed or be mislead by issues related to virtualization. Yet, while equally confronted by scale, data centers are relatively homogenous and symmetric. We believe these may be attributes to be exploited. However, data is required to better evaluate our hypotheses. Therefore, we introduce our efforts to gather data using a single framework from which we can launch tests of our choosing. Our observations reinforce recent claims, but indicate changes in the network. They also reveal additional obfuscations stemming from virtualization.
Neil Alexander Twigg, Marwan Fayed, Colin Perkins, Dimitrios P. Pezaros, Fung Po Tso 0001
SIGCOMM4
2011 End-to-end and network-internal measurements of real-time traffic to residential users
abstract
Little performance data currently exists for streaming high-quality Internet video to residential users. Data on streaming performance will provide valuable input to the design of new protocols and applications, such as congestion control and error-correction schemes, and sizing playout buffers in video receivers. This paper presents measurements of streaming real-time UDP traffic to a number of residential users, and discusses the basic characteristics of the data.
Martin Ellis, Colin Perkins, Dimitrios P. Pezaros
MMSys3
2011 Low-Overhead End-to-End Performance Measurement for Next Generation Networks
abstract
Internet performance measurement is commonly perceived as a high-cost control-plane activity and until now it has tended to be implemented on top of the network's forwarding operation. Consequently, measurement mechanisms have often had to trade relevance and accuracy over non-intrusiveness and cost effectiveness. In this paper, we present the software implementation of an in-line measurement mechanism that uses native structures of the Internet Protocol version 6 (IPv6) stack to piggyback measurement information on data-carrying traffic as this is routed between two points in the network. We carefully examine the overhead associated with both the measurement process and the measurement data, and we demonstrate that direct two-point measurement has minimal impact on throughput and on system processing load. The results of this paper show that adequately engineered measurement mechanisms that exploit selective processing do not compromise the network's forwarding efficiency, and can be deployed in an always-on manner to reveal the true performance of network traffic over small timescales.
Dimitrios P. Pezaros, Mickaël Hoerdt, David Hutchison 0001
IEEE Trans. Netw. Serv. Manag.1
2010 Autonomic diagnosis of anomalous network traffic
abstract
Network traffic abnormalities pose one of the greatest threats for networked environments. Autonomic communications offer a solution: it should be possible to design network mechanisms that behave adaptively and respond to any anomalous phenomenon that threatens normal network behaviour. In this paper we present the design of an adaptive anomaly detection component that has been built as part of an autonomic network system. We have implemented an entropy estimator to predict the onset of anomalous traffic behaviour within an autonomic resilience framework, and a Supervised Naive Bayesian classifier which synergistically empower the core properties of self-adaptation, self-learning and self-protection for next generation networks. Being part of an always-on, automated measurement and control infrastructure, such mechanism enforces the adaptive system reaction to suboptimal network operation and its subsequent restoration, while requiring minimal static (re)configuration and operator intervention.
Angelos K. Marnerides, David Hutchison 0001, Dimitrios P. Pezaros
WOWMOM3
2010 High-speed, in-band performance measurement instrumentation for next generation IP networks
Dimitrios P. Pezaros, Konstantinos Georgopoulos, David Hutchison 0001
Comput. Networks1
2008 Detection and mitigation of abnormal traffic behaviour in autonomic networked environments
abstract
Autonomic network environments are required to be resilient. Resilience is defined as the ability for a network to provide and maintain an acceptable level of service in the face of various challenges to normal operation [1]. Traffic abnormalities are a great challenge and it is vital for any network to be supported by resilient mechanisms in order to detect and mitigate such events. In this document we present our measurement-based resilience architecture and we argue that the correct combination of already proposed theoretical methodologies and mechanisms present in our architecture compose a powerful defence mechanism that satisfies autonomic properties such as self-protection and self-optimization. In addition we refer to our intentions of testing our proposed architecture within the ANA project [2] in order to justify our hypothesis.
Angelos K. Marnerides, Dimitrios P. Pezaros, David Hutchison 0001
CoNEXT2
2007 On the Long-Range Dependent Behaviour of Unidirectional Packet Delay of Wireless Traffic
abstract
In contrast to aggregate inter-packet metrics that quantify the arrival processes of aggregate traffic at a single point in the network, intraflow end-to-end per-packet performance metrics assess the level of service quality experienced by certain traffic types while routed over a network path. Consequently, while the former is influenced by the superimposition of a large number of concurrent ON/OFF sources, the latter mainly depends on the specific transport mechanisms employed by individual flows in conjunction with the temporal resource contention along the end-to-end path. In this paper, we have used a ubiquitous measurement technique to assess the unidirectional end-to-end delay characteristics experienced by diverse sets of IPv6 flows routed over heterogeneous wireless network configurations. We analysed numerous traces to find that, when viewed as time series data, often exhibit long-range dependence manifested by Hurst parameter estimates greater than 0.5. Our results suggest that the end-to-end packet delay can be bursty across multiple time scales even at the microflow level, implying high performance variability during sufficiently long-lived application sessions. We anticipate that the quantification of such intraflow phenomena can enable applications to optimise and adjust their operation in the face of potential performance degradation.
Dimitrios P. Pezaros, Manolis Sifalakis, David Hutchison 0001
GLOBECOM1
2004 Service quality measurements for IPv6 inter-networks
abstract
Measurement-based performance evaluation of network traffic is becoming very important, especially for networks trying to provide differentiated levels of service quality to the different application flows. The nonidentical response of flows to the different types of network-imposed performance degradation raises the need for ubiquitous measurement mechanisms, able to measure numerous performance properties, and being equally applicable to different applications and transports. This paper presents a new measurement mechanism, facilitated by the steady introduction of IPv6 in network nodes and hosts, which exploits native features of the protocol to provide support for performance measurements at the network (IP) layer. IPv6 Extension Headers have been used to carry the triggers involving the measurement activity and the measurement data in-line with the payload data itself, providing a high level of probability that the behaviour of the real user traffic flows is observed. End-to-end one-way delay, jitter, loss, and throughput have been measured for applications operating on top of both reliable and unreliable transports, over different-capacity IPv6 network configurations. We conclude that this technique could form the basis for future Internet measurements that can be dynamically deployed where and when required in a multiservice IP environment.
Dimitrios P. Pezaros, David Hutchison 0001, Robert D. Gardner, Joseph S. Sventek
IWQoS1
2004 In-line service measurements: an IPv6-based framework for traffic evaluation and network operations
abstract
The ability to measure, monitor and control the service quality experienced by network traffic is becoming increasingly important as multiple traffic types are aggregated onto IP networks. Assessing the real-time performance of the application flows is an essential requirement for network operations and service management, as well as for identifying how the different traffic types and transports interact and behave, when they are carried over the end-to-end Internet infrastructure. This paper introduces a novel measurement technique for assessing the performance of IPv6 network flows. By exploiting IPv6 extension headers, measurement triggers and the instantaneous measurement indications are carried in the same packets as the payload data itself. providing a high level of probability that the behaviour of the real user traffic flows is being observed. The measurement mechanism is applied at the network layer and provides for a generic technique able to measure any type of traffic without depending on particular transports or on specific measurement architectures. A prototype implementation of this technique is also described and evaluated by measuring performance properties of application flows over different-capacity IPv6 environments. End-to-end delay and jitter of video streams have been measured, as well as the goodput for services operating on top of reliable transport. This measurement technique can be the basis for low-overhead, scalable, transparent and reliable measurement of individual and aggregate network flows, and can be dynamically deployed where and when required in a multi-service IP environment.
Dimitrios P. Pezaros, David Hutchison 0001, Joseph S. Sventek, Robert D. Gardner
NOMS (1)1