VLDB 2026 Research / reviewers in the wild / expert
Jorge Crichigno
dblp:57/4032
· DBLP profile ↗
58ranked-venue papers
12as first author
35since 2021 · last 2026
0000-0002-6705-5300ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 39 · 11 first-author · 23 since 2021Security and privacy · 4 · 3 since 2021Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Accelerating Anomaly Detection in Industrial Control Systems Using SmartNICs and DPDKabstractIndustrial Control Systems (ICS) are critical infrastructures that integrate physical processes with programmable logic controllers (PLCs), human–machine interfaces (HMIs), and network communication. Given their dual exposure to cyber and physical threats, continuous monitoring is essential to ensure reliability and safety. A key requirement of ICS is maintaining low latency, as delays can desynchronize control loops and compromise system stability.This paper presents a hybrid detection framework that combines sensor-level time-series fault analysis with flow-based network anomaly detection for Modbus/TCP-based ICS. The framework leverages an NVIDIA BlueField-3 SmartNIC to offload machine-learning inference and sequential signal processing directly to the network interface using DPDK. The proposed system employs cumulative sum (CUSUM) and exponentially weighted moving average (EWMA) techniques to extract features for a multilayer perceptron (MLP) classifier, which identifies normal and faulty sensor behavior with high per-device accuracy. Network flow statistics are also analyzed to detect cyberattacks targeting the ICS infrastructure. Experimental results show sub–1 μs average inference latency for binary classification and an average of 5 μs per 32-packet burst on the BlueField-3 SmartNIC. Sergio Elizalde, Samia Choueiri, Ali Mazloum, Elie F. Kfoury, Jorge Crichigno |
CCNC | 6 |
| 2026 | A Testbed to Evaluate Next-Generation Security Solutions in Cyber-Physical Systems using Hardware AccelerationabstractAt the core of modern manufacturing systems lie Cyber-Physical Systems (CPS) that prioritize operational continuity over security, resulting in a rising number of cyberattacks targeting critical infrastructures. This paper presents a work-in-progress testbed that modernizes Smart Manufacturing Systems (SMS) by integrating Domain-Specific Accelerators (DSAs)—Data Processing Units (DPUs) and Programmable Data Plane (PDP) switches—to strengthen Operational Technology (OT) security without compromising availability or reliability. These accelerators provide fine-grained visibility, real-time anomaly detection, and efficient policy enforcement at line rate. Preliminary results show that accelerator-based applications outperform CPU-based implementations by several orders of magnitude. Demonstrated use cases include a DPU that performs memory inspection via Direct Memory Access (DMA) to detect injected anomalies and a PDP that implements inline detection using pre-trained Machine Learning (ML) models. With low processing overhead, the system also enables continuous telemetry collection for digital-twin generation without disrupting critical operations. The testbed, deployed on the South Carolina Cloud (SC Cloud), offers remote access for developing and evaluating next-generation CPS and OT security applications. Ali AlSabeh, Ali Mazloum, Elie F. Kfoury, Ramy F. Harik, Thorsten Wuest, Jorge Crichigno |
CCNC | 7 |
| 2026 | Design and Deployment of a Testbed for SmartNIC and Programmable Data Plane ExperimentationabstractThis paper presents the design and deployment of a virtualized testbed that facilitates experimentation and instruction in programmable network systems. The platform integrates Smart Network Interface Cards (SmartNICs), Programmable Data Plane (PDP) switches, and the Data Plane Development Kit (DPDK), within a cloud-based orchestration framework to reproduce high-performance, real-world networking scenarios. It supports line-rate processing, enabling real-time applications such as telemetry, encrypted traffic inspection, and malware detection. Through a series of use cases, we demonstrate how the testbed enables advanced experimentation by offloading infrastructure functions to the data plane, achieving low latency, high throughput, and high scalability. The system also provides users with guided labs for learners and is accessible via NETLAB+ for remote use. Future work includes federation with national-scale infrastructures such as FABRIC to broaden access and support multi-institutional collaboration. Samia Choueiri, Ali Mazloum, Sergio Elizalde, Amith GSPN, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno |
CCNC | 8 |
| 2026 | Real-Time Encrypted Traffic Classification with P4-DPDK
Amith Gorthi Srinivasa Prabhakara Narasimha, Ali Mazloum, Samia Choueiri, Sergio Elizalde, Elie F. Kfoury, Jorge Crichigno |
ICC | 6 |
| 2025 | Detection and Mitigation of Volumetric DDoS Attacks using Adaptive Rate-Limiting in P4-DPDKabstractDistributed Denial of Service (DDoS) attacks are increasingly targeting network environments. This paper presents a high-performance, adaptive system for detecting and mitigating volumetric DDoS attacks using P4-DPDK. The proposed system operates entirely in the user space, leveraging multicore CPUs and SmartNICs to process traffic at line rate while enabling flexible and efficient control plane operations. DDoS detection is implemented in a linear prediction model that forecasts traffic based on historical observations and dynamically adjusts ratelimiting thresholds. The hyperparameters for the model are tuned using an optimization algorithm. The system is evaluated on the FABRIC testbed and tested using real traffic traces. Experimental results demonstrate robust mitigation against diverse attack types, effective adaptation to real-world traffic, and reduced packet loss under high-throughput conditions approaching 100 Gbps, compared to Suricata-DPDK implementations. Samia Choueiri, Ali Mazloum, Sergio Elizalde, Elie F. Kfoury, Jorge Crichigno |
GLOBECOM | 5 |
| 2025 | Toward Fingerprinting Encrypted C2 Traffic in the Data Planeabstract• Transport Layer Security (TLS) is the dominant protocol that enables users to securely interact with the Internet. • Threat actors are using TLS to bypass traditional cybersecurity defenses like firewalls and intrusion detection systems. • Modern malware attacks are hiding behind TLS secure channels. • Many malware families that infect users receive malicious instructions from the command and control (C2) server. • As the communication between malware and the C2 server is encrypted, it can easily bypass modern security appliances that rely on deep packet inspection (DPI). • In response to this threat, this project aims at utilizing ML to identify encrypted C2 communication. • The project implements a distributed ML model over two hardware accelerators. • The system achieves 99.3% detection accuracy with a microsecond-level processing latency. Ali Mazloum, Elie F. Kfoury, Ali AlSabeh, Jorge Crichigno |
GLOBECOM | 5 |
| 2025 | Real-Time Flow Statistics Collection Using RDMA and P4 Programmable Data PlanesabstractMeasuring network traffic in real time is essential for applications such as traffic profiling, anomaly detection, resource allocation, and network performance improvement. As network speeds and traffic volumes increase, traditional solutions (e.g., NetFlow, sFlow, Zeek) face challenges in processing and summarizing traffic efficiently, often leading to incomplete measurements. This paper introduces a system that summarizes network traffic and provides per-flow measurements in real time by leveraging P4 Programmable Data Planes (PDPs). The system computes per-flow traffic statistics directly in the data plane at line rate. The statistics are then transmitted to a server using the low-latency, high-throughput RDMA over Converged Ethernet (RoCEv2) protocol. On the server, worker threads process the received reports and update a global data structure that maintain the flows. The system was implemented and tested using an Intel Tofino-based PDP and an RDMA-capable SmartNIC (NVIDIA BlueField-2). Experiments on real packet traces show that the system is capable of analyzing traffic at scale without compromising the accuracy of the measurements, outperforming traditional Network Security Monitors (NSMs). Elie F. Kfoury, Ali Mazloum, Ali AlSabeh, Jorge Crichigno |
ICC | 5 |
| 2025 | Domain Name Security Inspection at Line Rate: Tls Sni Extraction in the Data Plane Using P4 and DpdkabstractA widely adopted approach to monitor HTTPS traffic leverages the Server Name Identification (SNI) extension of TLS. Generally, the hostname is transferred in plain text over the SNI field and Deep Packet Inspection (DPI) is used to parse the TLS header and extract the hostname. However, DPI is often performed on general-purpose processors and utilizes the kernel of the operating system, which results in an overhead to the network, especially under high traffic loads. To this end, this paper proposes offloading the identification of SNI hostnames to the data plane using P4 and the Data Plane Development Kit (DPDK). In the proposed system, a P4 Programmable Data Plane (PDP) switch is the first line of defense where most of the TLS traffic is processed. DPDK is the second line of defense which processes all TLS packets that require processing capabilities beyond what the P4 PDP switch provides. To support line rate pattern matching on the hostname, the DPDK application is offloaded to a SmartNIC, leveraging its Regex engine. Experiments on various recent and public datasets from different regions and platforms reveal that the P4 switch is capable of parsing 85%99 % of hostnames. Furthermore, performance analysis shows that the P4 switch and the DPDK application, respectively, inspect a hostname in around 1 microsecond ($\mu \mathrm{s}$) and$7 \mu ~\mathrm{s}$, achieving an order of magnitude improvement over solution running on general-purpose processors. Ali Mazloum, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno |
ICC | 4 |
| 2025 | Enabling Line-Rate TLS SNI Inspection in P4 Programmable Data PlanesabstractWith the increasing adoption of the HyperText Transfer Protocol Secure (HTTPS), organizations face new challenges in monitoring traffic to defend against attacks and enforce security policies, such as filtering malicious websites. One widely used technique to monitor HTTPS is by scrutinizing the hostname in the Server Name Identification (SNI) extension during the Transport Layer Security (TLS) handshake. Parsing the SNI typically involves Deep Packet Inspection (DPI), often performed on general-purpose processors, which can create bottlenecks and significantly impact network throughput. In response, this paper introduces a novel framework for parsing and identifying SNI hostnames in the data plane at line-rate using P4. Evaluation results on recent publicly available datasets from various regions and platforms demonstrate that our framework can successfully parse 85%-99% of hostnames in P4. Furthermore, performance analysis reveals that the proposed data plane solution can inspect the hostname in approximately 1 microsecond (μ s), representing orders of magnitude improvement over solutions running on Central Processing Units (CPUs). Ali AlSabeh, Ali Mazloum, Elie F. Kfoury, Jorge Crichigno, Hala Strohmier Berry |
NOMS | 4 |
| 2025 | Performance Evaluation of Stateless Firewalling: Host-Based, SmartNIC, and P4 SwitchabstractIn modern data centers, traditional software-based firewalls often struggle to keep up with the growing demands for robust security. One adopted approach to improve the packet processing efficiency is through software acceleration techniques like the Data Plane Development Kit (DPDK), which significantly enhances the performance of software-based firewalls. Another approach is to offload the firewall functionalities to the hardware either using the new generation of Network Interface Cards (SmartNICs) or by using P4 Programmable Data Plane (PDP) switches. SmartNICs integrate dedicated processing units optimized to efficiently handle networking tasks, including security. P4 PDP switches enable custom packet processing in the data plane, allowing security applications to run at line rates within the network. This study compares the performance of stateless firewalls implemented using nftables (host-based), DPDK (host-based), DOCA Flow and OvS hardware (SmartNIC-based), and P4 (PDP-based). It evaluates the achievable throughput and processing latency for the five implementations under different testing scenarios. It also compares the CPU utilization of the host-based implementations. The results demonstrate that while the software acceleration technique significantly enhances host-side performance, SmartNIC-based and PDP-based firewalls provide a superior performance over all software-based implementations. Sergio Elizalde, Ali Mazloum, Samia Choueiri, Elie F. Kfoury, Jorge Crichigno |
NOMS | 5 |
| 2025 | Real-Time Congestion Control Algorithm Identification with P4 Programmable SwitchesabstractThe classification of Congestion Control Algorithms (CCAs) is vital in current networks, where increasing traffic demands and dynamic conditions challenge their stability and performance. CCAs play a fundamental role in managing congestion, balancing throughput, minimizing latency, and reducing packet loss to ensure reliable data transmission across diverse scenarios. Despite their importance, accurately identifying the CCA in use remains a challenging task; critical for optimizing resource allocation and enhancing Quality of Service (QoS). This paper presents a framework that leverages P4-programmable switches for real-time extraction of key traffic metrics, including queuing delay, interarrival time, queue depth, RTT, and sending rate. These metrics are analyzed using a Random Forest classifier to predict the CCA in use with high accuracy. Extensive experiments in a controlled network environment, featuring a bottleneck link and flows utilizing CCAs such as Cubic, Reno, BBR, and Vegas, validate the effectiveness of our approach. Andrés García-López, Elie F. Kfoury, Jorge Crichigno, Jaime Galán-Jiménez |
NOMS | 4 |
| 2025 | Improving flow fairness in non-programmable networks using P4-programmable Data Planes
Elie F. Kfoury, Ali Mazloum, Jorge Crichigno |
Comput. Networks | 4 |
| 2025 | Security applications in P4: Implementation and lessons learned
Ali Mazloum, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno |
Comput. Networks | 4 |
| 2025 | A survey on security applications with SmartNICs: Taxonomy, implementations, challenges, and future trendsabstractOver the last decade, network applications have grown exponentially, demanding high-speed interconnects. Unfortunately, chip manufacturers are approaching the upper limits of silicon-based computing with slow improvements in computational performance and energy efficiency. This trend has forced the industry to shift paradigms, moving from monolithic architectures to heterogeneous, domain-specific designs. Moreover, the ever-evolving threats compromise digital services and demand more scalable and flexible solutions to ensure service continuity in production networks. Smart Network Interface Cards (SmartNICs) are a product of this new paradigm, integrating domain-specific engines and general-purpose cores to offload various network infrastructure tasks, including those related to security. This paper provides a comprehensive overview of SmartNICs, with a particular focus on their role in strengthening network defenses. It introduces SmartNIC technology and presents a taxonomy of security applications offloaded to SmartNICs, categorized into Intrusion Detection and Prevention Systems (IDS/IPS), defenses against volumetric attacks, and data confidentiality mechanisms. Additionally, the paper explores vulnerabilities associated with adopting SmartNICs in the cloud, examining the threat model and reviewing proposed remediations in the literature. Finally, it discusses challenges and future trends in SmartNIC security applications, highlighting current initiatives and open research areas. Sergio Elizalde, Ali AlSabeh, Ali Mazloum, Samia Choueiri, Elie F. Kfoury, Jorge Crichigno |
J. Netw. Comput. Appl. | 7 |
| 2025 | Enhancing visibility on a science DMZ with P4-perfSONARabstractThe Science Demilitarized Zone (Science DMZ) is a specialized network designed to facilitate the transfer of large-scale scientific data. One of the key elements of the Science DMZ is perfSONAR, an active performance measurement device that monitors end-to-end paths over multiple domains. Although versatile, perfSONAR faces limitations such as restricted visibility of events and coarse-grained measurements. This paper proposes a scheme that integrates P4 programmable data plane (PDP) switches with perfSONAR. P4 PDP switches are passively installed and operate on real-time traffic copies, providing flexibility to collect fine-grained custom measurements and report events in the data plane. This integration enables perfSONAR to collect per-flow granular statistics of actual traffic, identify a broader range of networking issues, and enhance visibility while reducing the overhead of active tests. Additionally, the scheme uses an adaptive linear prediction (LP) model that dynamically adjusts the rate of reports sent from the P4 PDP switch to perfSONAR, minimizing the storage and processing needed for the latter. Experimental results show that the system reduces the number of reports by a factor of five while maintaining a small and configurable relative mean error (RME). Ali Mazloum, Elie F. Kfoury, Ali AlSabeh, Jorge Crichigno |
J. Netw. Comput. Appl. | 5 |
| 2024 | Scalable Heavy Hitter Detection: A DPDK-based Software Approach with P4 IntegrationabstractIdentifying heavy hitters is vital for applications like Denial of Service (DoS) detection and traffic engineering. Current solutions fall into hardware or software categories. Hardware solutions (e.g., P4 programmable data plane switches) offer high performance but require adding hardware, which may not be ideal for virtualized environments (e.g., cloud). Software solutions are cost-effective and flexible but suffer from performance issues due to the packet processing overhead in the Operating System (OS) kernel. This paper presents a scalable heavy hitter detection algorithm in the software, bypassing the kernel using the Data Plane Development Kit (DPDK). The Count-min Sketch (CMS) data structure is used to estimate the frequency of packets per flow. The system is implemented in P4 and deployed on the P4-DPDK target running on CPU cores. The experiments analyzed the impact of various parameters such as the packet size distribution, the number of CPU cores, and the number of hash functions, on the performance and the accuracy of the detection. The system's performance is further evaluated through comparison with another DPDK-based approach for heavy hitter detection. The results show accurate identification of heavy hitters and improved performance, even at a high traffic rate approaching 100Gbps. Samia Choueiri, Ali Mazloum, Elie F. Kfoury, Jorge Crichigno |
GLOBECOM | 4 |
| 2024 | Enabling Fairness in Flow Allocation using P4-programmable Data PlanesabstractThis paper presents a system designed to enhance Transmission Control Protocol (TCP) fairness by rebalancing router queues and reducing the impact of Round-Trip Time (RTT) unfairness. The proposed system utilizes a P4-programmable Data Plane (PDP) to process a copy of the traffic from the link between two non-programmable routers. The PDP measures the throughput and calculates the RTT of competing flows in the data plane. Then, the control plane generates the rules to be implemented in a non-programmable router that will allocate flows in different queues to isolate their dynamics. The limits for each queue result from the Jenks optimization algorithm. This approach ensures that flows with similar characteristics share the same queue.The results demonstrate that the system efficiently identifies and segregates flows into multiple queues, thereby enforcing fairness among competing flows and enhancing the Flow Completion Time (FCT). The experiments were executed on traffic provided by Measurement and Analysis on the WIDE Internet (MAWI). The system effectively rebalances queues and dynamically redistributes underutilized bandwidth independently of the design principles of the transport protocol. Furthermore, the results show that the system effectively mitigates the effects of bufferbloat and successfully detects and reduces the impact of protocol abuses at the network layer. Elie F. Kfoury, Ali Mazloum, Jorge Crichigno |
GLOBECOM | 4 |
| 2024 | Reducing the Impact of RTT Unfairness using P4-Programmable Data PlanesabstractThis paper presents a system that mitigates the Round-trip Time (RTT) unfairness issue in non-programmable networks using P4-programmable data planes. In traditional loss-based congestion control algorithms (CCAs), RTT unfairness occurs when the flows with shorter RTTs obtain higher bandwidth shares with respect to the flows with longer RTTs. This behavior occurs due to the faster recovery period that flows with shorter RTTs experience after a loss event. On the other hand, more recent CCAs, such as the Bottleneck Bandwidth and Round-trip Time (BBR), present the opposite behavior, where the flows with longer RTTs achieve higher throughput than the ones with shorter RTTs. In this paper, the proposed system employs a P4-programmable data plane to monitor the RTT of flows traversing a non-programmable router at line rate using passive taps. The P4-programmable data plane analyzes the RTT of each flow, sub-sequently segregating them into different queues. This separation is aimed at minimizing the interaction between flows with varying RTTs. Results show that implementing flow separation improves the fairness of long flows, reduces the RTT of individual flows allocated in different queues, and improves the Flow Completion Times (FCTs) of short flows. P4, RTT unfairness, Transmission Control Protocol (TCP), Congestion Control Algorithm (CCA), Bottleneck Bandwidth and Round-trip Time (BBR). Elie F. Kfoury, Jorge Crichigno, Gautam Srivastava 0001 |
ICC | 3 |
| 2024 | perfSONAR: Enhancing Data Collection through Adaptive SamplingabstractperfSONAR IS a tool used to monitor and troubleshoot problems in high-speed networks such as Science Demilitarized Zones (DMZs). It is essential to validate that data transfers are performing as expected. However, perfSONAR suffers from the trade-off between the measurement accuracy and the overhead induced by its active testsThis paper presents a scheme that offloads the traffic monitoring to a programmable data plane (PDP) switch. The scheme integrates a PDP switch with perfSONAR, where the switch continuously collects network measurements (e.g., latency, throughput, packet loss rate) and periodically reports the measurements to the perfSONAR archiver. This integration significantly enhances the granularity, visibility, and troubleshooting capabilities of perfSONAR. Additionally, the scheme automates the reporting period according to the variability of the monitored measurements, which eliminates the need of human intervention observed in today’s networks. In contrast to traditional schemes that report all measurements, the proposed approach uses the Linear Prediction (LP) method to only report the samples that reveal a variation on the measurements. Experimental results show that the system reduces the number of reports by five times under stable network conditions and sustains a relative mean error (RME) below 0.06. Ali Mazloum, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno |
NOMS | 4 |
| 2024 | Machine learning controller for data rate management in science DMZ networks
Christian Vega Caicedo, Elie F. Kfoury, Jorge E. Pezoa, Miguel E. Figueroa, Jorge Crichigno |
Comput. Networks | 6 |
| 2024 | Evaluating TCP BBRv3 performance in wired broadband networks
Elie F. Kfoury, Jorge Crichigno, Gautam Srivastava 0001 |
Comput. Commun. | 3 |
| 2024 | On DGA Detection and Classification Using P4 Programmable Switches
Ali AlSabeh, Kurt Friday, Elie F. Kfoury, Jorge Crichigno, Elias Bou-Harb |
Comput. Secur. | 4 |
| 2024 | P4BS: Leveraging Passive Measurements From P4 Switches to Dynamically Modify a Router's Buffer SizeabstractThe performance of networked applications can be dramatically impacted by the size of the buffer at the bottleneck router. Shallow buffers may increase packet losses and decrease link utilization, while deep buffers may increase the queueing delays for latency-sensitive flows. Operators nowadays configure large buffers statically without considering the characteristics of flows or dynamic traffic patterns. This paper presents P4BS, a system that dynamically modifies the buffer size of a legacy router. P4BS leverages programmable switches as passive instruments to measure various metrics that are vital when deciding on buffer size. The measured metrics include the number of long-lived flows and their round-trip times, the packet loss rates, and the queueing delays. Using these measurements, the programmable switch sequentially searches for a buffer size that minimizes the queueing delays and the packet loss rates. The system was implemented on a Tofino hardware switch and the system was tested on a wide range of network scenarios. The results show improvements in the quality of service of various applications including Web browsing, video streaming, and voice over IP. Elie F. Kfoury, Jorge Crichigno, Elias Bou-Harb |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | Effective DGA Family Classification Using a Hybrid Shallow and Deep Packet Inspection Technique on P4 Programmable SwitchesabstractDomain Generation Algorithms (DGAs) are one of the most effective strategies for malware to obtain a connection with the adversary's Command and Control (C2) server. Moreover, the growing number of DGA families makes it increasingly challenging for defense strategies to promptly identify the DGA family behind a given compromise. State-of-the-art high-dimensional DGA detection models perform poorly in such multiclass classification scenarios because their domain name-based features fail to distinguish between DGA families. To this extent, this paper proposes a novel framework that harnesses the flexibility, per-packet granularity, and Terabits per second (Tbps) processing capabilities of P4 Programmable Data Plane (PDP) switches to swiftly and accurately classify DGA families. In particular, the P4 PDP switch is leveraged to extract a combination of unique network heuristics and domain name features through shallow and Deep Packet Inspection (DPI) with minimal throughput reduction. Such collected features cannot be tracked on commodity hardware without significantly degrading the throughput in high-speed networks, nor on traditional layer 2/3 switches due to their limited and fixed functionalities. We crawled hundreds of Gigabytes (GBs) of malware samples from different sources to obtain instances of 50 DGA families and show that the proposed approach can promptly classify each family with high accuracy. Such a reliable multiclass classification enables the immediate halting of malicious communications while allowing network operators to initiate appropriate mitigation, incident management, and provisioning strategies. Ali AlSabeh, Kurt Friday, Jorge Crichigno, Elias Bou-Harb |
ICC | 3 |
| 2023 | P4CCI: P4-Based Online TCP Congestion Control Algorithm Identification for Traffic SeparationabstractCongestion Control Algorithms (CCAs) regulate the sending rates of hosts to avoid congestion in the network. Studies have shown that when flows belonging to different CCAs coexist on the same link, their shares on that link are significantly different. If the CCAs of active flows can be determined on live traffic, then flows belonging to the same CCA can be allocated into a dedicated queue. Unfortunately, identifying the CCA at line rate is not straightforward since the CCA is not advertised in the header fields of a packet. Moreover, with Gigabits per second (Gbps) traffic crossing a network, analyzing each packet to infer the CCA is not possible, especially with general-purpose CPUs. This paper proposes P4CCI, a system that detects the CCA of a flow at line rate by leveraging Programmable Data Planes (PDP). The PDP computes and extracts the flow's bytes-in-flight and sends them to a Deep Learning model for classification. Once classified, the flows are allocated into dedicated queues based on their CCA type. The system was implemented and tested on real hardware that uses Intel's Tofino ASIC. The experiments were executed on traffic provided by CAIDA. Results show that P4CCI can detect the CCAs with high accuracy. Furthermore, the performance of the network is greatly improved when the flows are separated by their CCAs. Elie F. Kfoury, Jorge Crichigno, Elias Bou-Harb |
ICC | 2 |
| 2023 | Data-Centric Machine Learning Approach for Early Ransomware Detection and AttributionabstractResearchers have proposed a wide range of ransomware detection and analysis schemes. However, most of these efforts have focused on older families targeting Windows 7/8 systems. Hence there is a critical need to develop efficient solutions to tackle the latest threats, many of which may have relatively fewer samples to analyze. This paper presents a machine learning (ML) framework for early ransomware detection and attribution. The solution pursues a data-centric approach which uses a minimalist ransomware dataset and implements static analysis using portable executable (PE) files. Results for several ML classifiers confirm strong performance in terms of accuracy and zero-day threat detection. Aldin Vehabovic, Hadi Zanddizari, Nasir Ghani, Farooq Shaikh, Elias Bou-Harb, Morteza Safaei Pour, Jorge Crichigno |
NOMS | 7 |
| 2023 | A survey on network simulators, emulators, and testbeds used for research and education
Elie F. Kfoury, Jorge Crichigno, Gautam Srivastava 0001 |
Comput. Networks | 3 |
| 2023 | A Survey on Rerouting Techniques with P4 Programmable Data Plane Switches
Ali Mazloum, Elie F. Kfoury, Jorge Crichigno |
Comput. Networks | 4 |
| 2023 | An Architecture That Enables Cross-Chain Interoperability for Next-Gen Blockchain SystemsabstractBlockchain technology is crucial for cutting-edge demands and aligns with the trend toward decentralized architecture. Interoperability between private and public blockchain technology can revolutionize digital record-keeping and enable automation. Traditional database systems saw major developments when application programming interfaces (APIs) and data were used across centralized entities. For blockchain technology, the natural evolution would be to facilitate communication and data exchange between private and public blockchain technologies, potentially revolutionizing digital record-keeping for future automation. Our research tests this interoperability in real-world scenarios and explores smart city elements and use-cases for application in the next generation of blockchain systems. Darshan M, Matthieu Amet, Gautam Srivastava 0001, Jorge Crichigno |
IEEE Internet Things J. | 4 |
| 2022 | Enabling P4 Hands-on Training in an Academic CloudabstractThis paper describes a cloud infrastructure and virtual laboratories on P4 programmable data plane switches. P4 programmable data planes emerged as a technology that enables innovation in networking. P4 is a programming language used to describe how network packets are processed. This paper explains an entry-level training library on P4. The virtual laboratories introduce the learner to P4 and data plane concepts by providing step-by-step guides and exercises. The virtual laboratories are hosted in the Academic Cloud, a distributed platform that manages and orchestrates computing resources. Additionally, the paper describes a work in progress of P4 virtual laboratories that uses Intel Tofino switches. Lastly, the paper discusses the use of the Academic Cloud as a network testbed. Elie F. Kfoury, Jorge Crichigno |
DCOSS | 3 |
| 2022 | INC: In-Network Classification of Botnet Propagation at Line Rate
Kurt Friday, Elie F. Kfoury, Elias Bou-Harb, Jorge Crichigno |
ESORICS (1) | 4 |
| 2022 | A Learning Methodology for Line-Rate Ransomware Mitigation with P4 Switches
Kurt Friday, Elias Bou-Harb, Jorge Crichigno |
NSS | 3 |
| 2022 | A survey on security applications of P4 programmable switches and a STRIDE-based vulnerability assessment
Ali AlSabeh, Joseph Khoury, Elie F. Kfoury, Jorge Crichigno, Elias Bou-Harb |
Comput. Networks | 4 |
| 2022 | A survey on TCP enhancements using P4-programmable devices
Elie F. Kfoury, Jorge Crichigno, Gautam Srivastava 0001 |
Comput. Networks | 3 |
| 2021 | Dynamic Router's Buffer Sizing using Passive Measurements and P4 Programmable SwitchesabstractThe router's buffer size imposes significant impli-cations on the performance of the network. Network operators nowadays configure the router's buffer size manually and stati-cally. They typically configure large buffers that fill up and never go empty, increasing the Round-trip Time (RTT) of packets significantly and decreasing the application performance. Few works in the literature dynamically adjust the buffer size, but are implemented only in simulators, and therefore cannot be tested and deployed in production networks with real traffic. Previous work suggested setting the buffer size to the Bandwidth-delay Product (BDP) divided by the square root of the number of long flows. Such formula is adequate when the RTT and the number of long flows are known in advance. This paper proposes a system that leverages programmable switches as passive instruments to measure the RTT and count the number of flows traversing a legacy router. Based on the measurements, the programmable switch dynamically adjusts the buffer size of the legacy router in order to mitigate the unnecessary large queuing delays. Results show that when the buffer is adjusted dynamically, the RTT, the loss rate, and the fairness among long flows are enhanced. Additionally, the Flow Completion Time (FCT) of short flows sharing the queue is greatly improved. The system can be adopted in campus, enterprise, and service provider networks, without the need to replace legacy routers. Elie F. Kfoury, Jorge Crichigno, Elias Bou-Harb, Gautam Srivastava 0001 |
GLOBECOM | 2 |
| 2020 | Exploiting Ransomware Paranoia For Execution PreventionabstractRansomware attacks cost businesses more than $75 billion/year, and it is predicted to cost $6 trillion/year by 2021. These numbers demonstrate the havoc produced by ransomware on a large number of sectors and urge security researches to tackle it. Several ransomware detection approaches have been proposed in the literature that interchange between static and dynamic analysis. Recently, ransomware attacks were shown to fingerprint the execution environment before they attack the system to counter dynamic analysis. In this paper, we exploit the behavior of contemporary ransomware to prevent its attack on real systems and thus avoid the loss of any data. We explore a set of ransomware-generated artifacts that are launched to sniff the surrounding. Furthermore, we design, develop, and evaluate an approach that monitors the behavior of a program by intercepting the called Windows APIs. Consequently, we determine in real-time if the program is trying to inspect its surrounding before the attack, and abort it immediately prior to the initiation of any malicious encryption or locking. Through empirical evaluations using real and recent ransomware samples, we study how ransomware and benign programs inspect the environment. Additionally, we demonstrate how to prevent ransomware with a low false positive rate. We make the developed approach available to the research community at large through GitHub to strongly promote cyber security defense operations and for wide-scale evaluations and enhancements. Ali AlSabeh, Haïdar Safa, Elias Bou-Harb, Jorge Crichigno |
ICC | 4 |
| 2020 | Offloading Media Traffic to Programmable Data Plane SwitchesabstractAccording to estimations, approximately 80% of Internet traffic represents media traffic. Much of it is generated by end users communicating with each other (e.g., voice, video sessions). A key element that permits the communication of users that may be behind Network Address Translation (NAT) is the relay server. This paper presents a scheme for offloading media traffic from relay servers to programmable switches. The proposed scheme relies on the capability of a P4 switch with a customized parser to de-encapsulate and process packets carrying media traffic. The switch then applies multiple switch actions over the packets. As these actions are simple and collectively emulate a relay server, the scheme is capable of moving relay functionality to the data plane operating at terabits per second. Performance evaluations show that the proposed scheme not only produces optimal results regarding Quality of Service (QoS) parameters (no packet loss, minimum delay, negligible delay variation, high Mean Opinion Score) but also scales much better than current solutions. Evaluations conducted with up to 35Gbps of media traffic or its equivalent of 400,000 simultaneous G.711 media sessions (limited only by the traffic generator rather than by the switch) show an ideal operation of the switch-based solution (using$\sim \text{l}$% of the switching capacity). In contrast, a relay server with a modern CPU model used for evaluations can process up to 900 simultaneous G.711 media sessions per core. Elie F. Kfoury, Jorge Crichigno, Elias Bou-Harb |
ICC | 2 |
| 2020 | Towards a Unified In-Network DDoS Detection and Mitigation StrategyabstractDistributed Denial of Service (DDoS) attacks have terrorized our networks for decades, and with attacks now reaching 1.7 Tbps, even the slightest latency in detection and subsequent remediation is enough to bring an entire network down. Though strides have been made to address such maliciousness within the context of Software Defined Networking (SDN), they have ultimately proven ineffective. Fortunately, P4 has recently emerged as a platform-agnostic language for programming the data plane and in turn allowing for customized protocols and packet processing. To this end, we propose a first-of-a-kind P4-based detection and mitigation scheme that will not only function as intended regardless of the size of the attack, but will also overcome the vulnerabilities of SDN that have characteristically been exploited by DDoS. Moreover, it successfully defends against the broad spectrum of currently relevant attacks while concurrently emphasizing the Quality of Service (QoS) of legitimate end-users and overall SDN functionality. We demonstrate the effectiveness of the proposed scheme using a software programmable P4-switch, namely, the Behavorial Model version 2 (BMv2), showing its ability to withstand a variety of DDoS attacks in real-time via three use cases that can be generalized to most contemporary attack vectors. Specifically, the results substantiate that the mechanism herein is orders of magnitude faster than traditional polling techniques (e.g., NetFlow or sFlow) while minimizing the impact on benign traffic. We concur that the approach's design particularities facilitate seamless and scalable deployments in high-speed networks requiring line-rate functionality, in addition to being generic enough to be integrated into viable network topologies. Kurt Friday, Elie F. Kfoury, Elias Bou-Harb, Jorge Crichigno |
NetSoft | 4 |
| 2020 | An emulation-based evaluation of TCP BBRv2 Alpha for wired broadband
Elie F. Kfoury, Jorge Crichigno, Elias Bou-Harb |
Comput. Commun. | 3 |
| 2020 | On data-driven curation, learning, and analysis for inferring evolving internet-of-Things (IoT) botnets in the wild
Morteza Safaei Pour, Antonio Mangino, Kurt Friday, Matthias Rathbun, Elias Bou-Harb, Farkhund Iqbal, Sagar Samtani, Jorge Crichigno, Nasir Ghani |
Comput. Secur. | 8 |
| 2019 | Shared-risk-aware Design for Survivable Migration in SDN EnvironmentsabstractIn this paper, we propose a heterogeneous risk-aware Software-Defined Networking (SDN) migration method for designing survivable networks in the face of multiple correlated failures. The migration method, which is implemented in one shot, specifies how many nodes of each SDN implementation are needed, and where such nodes must be located, in order to yield an SDN migrated network with maximal survivability, when multiple correlated failures impact the entire network connectivity. We formulated the survivable SDN migration problem through integer optimization, where the proposed cost function assesses the survivability of the migrated network in terms of the number of connected components after a failure. The numerical results calculated over test networks show the capability of migration method to provide survivable SDN topologies, which trade-off the heterogeneity in the SDN implementations and the number of shared risks. Yasmany Prieto, Christian Vega Caicedo, Jorge E. Pezoa, Jorge Crichigno |
CCNC | 4 |
| 2019 | A Flow-Based Entropy Characterization of a NATed Network and Its Application on Intrusion DetectionabstractThis paper presents a flow-based entropy characterization of a small/medium-sized campus network that uses network address translation (NAT). Although most networks follow this configuration, their entropy characterization has not been previously studied. Measurements from a production network show that the entropies of flow elements (external IP address, external port, campus IP address, campus port) and tuples have particular characteristics. Findings include: i) entropies may widely vary in the course of a day. For example, in a typical weekday, the entropies of the campus and external ports may vary from below 0.2 to above 0.8 (in a normalized entropy scale 0-1). A similar observation applies to the entropy of the campus IP address; ii) building a granular entropy characterization of the individual flow elements can help detect anomalies. Data shows that certain attacks produce entropies that deviate from the expected patterns; iii) the entropy of the 3-tuple {external IP, campus IP, campus port} is high and consistent over time, resembling the entropy of a uniform distribution's variable. A deviation from this pattern is an encouraging anomaly indicator; iv) strong negative and positive correlations exist between some entropy time-series of flow elements. Jorge Crichigno, Elie F. Kfoury, Elias Bou-Harb, Nasir Ghani, Yasmany Prieto, Christian Vega Caicedo, Jorge E. Pezoa, David Torres |
ICC | 1 |
| 2019 | Green Communication Protocol with GeolocationabstractGreen communications is the practice of selecting energy efficient communications, networking technologies and products. This process is followed by minimizing resource use whenever possible in all branches of communications. In this day and age, green communication is vital to the footprint we leave on this planet as we move into a completely digital age. One such communication tool is Message Queue Transport Telemetry or MQTT which is an open source publisher/subscriber standard for M2M (Machine to Machine) communication. It is well known for its low energy and bandwidth footprint and thus makes it highly suitable for Green Internet of Things (IoT) messaging situations where power usage is at a premium or in mobile devices such as phones, embedded computers or microcontrollers. It is a perfect tool for the green communication age upon us and more specifically Green IoT. One problem however with the original MQTT protocol is that it is lacking the ability to broadcast geolocation. In today's age of IoT however, it has become more pertinent to have geolocation as part of the protocol. In this paper, we add geolocation to the MQTT protocol and offer a revised version, which we call MQTTg. We describe the protocol here and show where we are able to embed geolocation successfully. We also offer a early glimpse into an Android OS application we are developing for Open Source use. Gautam Srivastava 0001, Andrew Fisher 0002, Jorge Crichigno |
VTC Spring | 4 |
| 2018 | A Machine Learning Model for Classifying Unsolicited IoT Devices by Observing Network TelescopesabstractThe Internet of Things [IoT] promises to revolutionize the way we interact with our surroundings. Smart cars, smart cities, smart homes are now being realized with the help of various embedded devices that operate with little to no human interaction. However these embedded devices bring forth a plethora of security challenges as most manufacturers still assign higher importance to the three Ps (prototyping, production and performance) than security. This inherent flaw has manifested itself in the form of various Denial of Service (DoS) attacks orchestrated with the help of unsolicited IoT devices on the Internet. We are even seeing massive throughputs without the need for amplifications affecting large scale infrastructures on the Internet. Thus, understanding the nature of these attacks and quickly identifying infected devices becomes imperative to combat this situation. In this paper we present a model to classify unsolicited IoT devices in enterprises using machine learning (ML). Namely IP header information from darknet data is collected for analysis. We then consider multiple supervised ML algorithms to classify these Layer 3 headers. We evaluate these algorithms and compare their performances in terms of accurately identifying activities of malicious IoT devices on the Internet. Our results show that Random Forest and Gradient Boosting have high recall and precision scores whereas NaiveBayes has the worst performance. We believe our model can be used by enterprises as a part of their intrusion detection system to quickly identify infected IoT devices within their own environment as well as identify scanning activities directed towards them. Farooq Shaikh, Elias Bou-Harb, Jorge Crichigno, Nasir Ghani |
IWCMC | 3 |
| 2017 | A first empirical look on internet-scale exploitations of IoT devicesabstractTechnological advances and innovative business models led to the modernization of the cyber-physical concept with the realization of the Internet of Things (IoT). While IoT envisions a plethora of high impact benefits in both, the consumer as well as the control automation markets, unfortunately, security concerns continue to be an afterthought. Several technical challenges impede addressing such security requirements, including, lack of empirical data related to various IoT devices in addition to the shortage of actionable attack signatures. In this paper, we present what we believe is a first attempt ever to comprehend the severity of IoT maliciousness by empirically characterizing the magnitude of Internet-scale IoT exploitations. We draw upon unique and extensive darknet (passive) data and develop an algorithm to infer unsolicited IoT devices which have been compromised and are attempting to exploit other Internet hosts. We further perform correlations by leveraging active Internet-wide scanning to identify and report on such IoT devices and their hosting environments. The generated results indicate a staggering 11 thousand exploited IoT devices that are currently in the wild. Moreover, the outcome pinpoints that IoT devices embedded deep in operational Cyber-Physical Systems (CPS) such as manufacturing plants and power utilities are the most compromised. We concur that such results highlight the wide-spread insecurities of the IoT paradigm, while the actionable generated inferences are postulated to be leveraged for prompt mitigation as well as to facilitate IoT forensic investigations using real empirical data. Mario Galluscio, Nataliia Neshenko, Elias Bou-Harb, Yongliang Huang, Nasir Ghani, Jorge Crichigno, Georges Kaddoum |
PIMRC | 6 |
| 2017 | Post-failure repair for cloud-based infrastructure services after disasters
Mahsa Pourvali, Cicek Cavdar, Khaled B. Shaban, Jorge Crichigno, Nasir Ghani |
Comput. Commun. | 4 |
| 2016 | Overlay network scheduling design
Khaled B. Shaban, Mahmoud A. Khodeir, Jorge Crichigno, Samee Ullah Khan, Nasir Ghani |
Comput. Commun. | 5 |
| 2013 | Routing in MPLS networks with probabilistic failuresabstractWe present a routing scheme for MPLS networks with probabilistic failures. Our routing scheme simultaneously maximizes the expected satisfied demand and minimizes the maximum link utilization of the network. Our approach is novel in that it is the first to jointly address the traffic engineering and the routing through reliable paths problems. In addition to the optimal routing algorithm, we present a lower complexity heuristic algorithm based on Linear Programming and Yen's algorithm. Finally, numerical results are presented to demonstrate the effectiveness of both our optimal and heuristic algorithms. Jorge Crichigno, Joud S. Khoury, Nasir Ghani |
ICC | 1 |
| 2011 | Throughput Optimization in Multihop Wireless Networks with Multipacket Reception and Directional AntennasabstractRecent advances in the physical layer have enabled the simultaneous reception of multiple packets by a node in wireless networks. We address the throughput optimization problem in wireless networks that support multipacket reception (MPR) capability. The problem is modeled as a joint routing and scheduling problem, which is known to be NP-hard. The scheduling subproblem deals with finding the optimal schedulable sets, which are defined as subsets of links that can be scheduled or activated simultaneously. We demonstrate that any solution of the scheduling subproblem can be built with \vert E\vert + 1 or fewer schedulable sets, where \vert E\vert is the number of links of the network. This result is in contrast with previous works that stated that a solution of the scheduling subproblem is composed of an exponential number of schedulable sets. Due to the hardness of the problem, we propose a polynomial time scheme based on a combination of linear programming and approximation algorithm paradigms. We illustrate the use of the scheme to study the impact of design parameters on the performance of MPR-capable networks, including the number of transmit interfaces, the beamwidth, and the receiver range of the antennas. Jorge Crichigno, Min-You Wu, Sudharman K. Jayaweera, Wei Shu |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2010 | Dynamic Routing Optimization in WDM NetworksabstractWe present a multi-objective optimization approach for joint throughput optimization and traffic engineering, where the routing request of traffic arrives one-by-one. We provide an Integer Linear Program (ILP) that simultaneously i) maximizes the aggregate throughput, ii) minimizes the resource consumption, and iii) minimizes the maximum link utilization. We study the impact of optimizing the three different objectives simultaneously in dynamic environments, and show that better solutions than those of mono-objective approaches can be obtained. Because of the complexity of the ILP, we also propose another ILP with reduced complexity, and study its performance and the optimality gap between it and optimal solutions. Jorge Crichigno, Nasir Ghani, Joud S. Khoury, Wei Shu, Min-You Wu |
GLOBECOM | 1 |
| 2010 | Throughput Optimization and Traffic Engineering in WDM Networks Considering Multiple MetricsabstractThroughput optimization and traffic engineering in Wavelength-Division Multiplexing (WDM) networks are usually treated as mono-objective optimization problems. In this paper, we provide a multi-objective Integer Linear Program (ILP) for the joint throughput optimization and traffic engineering problem. By simultaneously i) maximizing the throughput, ii) minimizing the resource consumption, and iii) balancing the traffic load, we demonstrate that better solutions than those of mono-objective approaches are obtained. We also present a distributed heuristic algorithm, which upper-bounds the per-route resource consumption and maximizes the throughput. Simulation results validate the proposed model and heuristic algorithm. Additionally, we present an ILP formulation for another well-known problem such as routing and wavelength assignment (RWA), and discuss the impact of modeling it as a multi-objective problem. Jorge Crichigno, Wei Shu, Min-You Wu |
ICC | 1 |
| 2010 | Minimum Length Scheduling in Single-Hop Multiple Access Wireless NetworksabstractWe address the minimum length scheduling problem in wireless networks, where each transmitter has a finite amount of data to deliver to a common receiver node (e.g., base station). In contrast with previous works that model wireless channels according to the Protocol or Physical model of interference, this paper studies the scheduling problem in multiple access (multi-access) networks. In this kind of network, the receiver node can decode multiple transmissions simultaneously if the transmission rates of concurrent transmitters lie inside the capacity region of the receiver node. We propose a linear programming model that minimizes the schedule length. The model incorporates the capacity region of multiple access channels into scheduling decisions, such that the sum of the transmission rates of simultaneous transmitters is maximized. Because of the high-complexity of the model, we also present a heuristic algorithm, whose performance is extensively evaluated and compared with the optimal solutions. Jorge Crichigno, Min-You Wu, Wei Shu |
ICC | 1 |
| 2010 | Maximizing Throughput in Wireless Multi-Access Channel NetworksabstractRecent advances in the physical layer have enabled the simultaneous reception of multiple packets by a node in wireless networks. In this paper, we present a generalized model for the throughput optimization problem in multi-hop wireless networks that support multi-packet reception (MPR) capability. The model incorporates the multi-access channel, which accurately accounts for the achievable capacity of links used by simultaneous packet transmissions. The problem is modeled as a joint routing and scheduling problem. The scheduling subproblem deals with finding the optimal schedulable sets, which are defined as subsets of links that can be scheduled or activated simultaneously. We demonstrate that any solution of the scheduling subproblem can be built with |E| + 1 or fewer schedulable sets, where |E| is the number of links of the network. This result contrasts with a conjecture that states that a solution of the scheduling subproblem, in general, is composed of an exponential number of schedulable sets. Due to the hardness of the problem, we propose a polynomial time scheme based on a combination of linear programming and greedy paradigms. The scheme guarantees the operation of links at maximum aggregate capacity, where the sum of the capacity of the links is maximized and the multi-access channel is fully exploited. Jorge Crichigno, Min-You Wu, Sudharman K. Jayaweera, Wei Shu |
WCNC | 1 |
| 2009 | Throughput optimization in wireless networks with multi-packet reception and directional antennasabstractRecent advances in the physical layer have enabled the simultaneous reception of multiple packets by a node in wireless networks. In this paper, we present a generalized model for the throughput optimization problem in wireless networks that support multi-packet reception (MPR) capability. Our model directly accounts for nodes with multiple transmitter antennas, which can be directional or omni-directional. We divide the problem into two subproblems: routing and scheduling. Due to the hardness of the scheduling subproblem, we propose a polynomial time heuristic based on a combination of greedy and linear programming paradigms. We use the devised scheme to study the impact of several design parameters on the performance of MPR-capable networks, including the number of interfaces, the beamwidth and the receiver range of the antennas. Numerical results demonstrate the effectiveness and the generality of the scheme, and permit us to draw valuable conclusions about MPR-capable networks. Jorge Crichigno, Min-You Wu, Wei Shu |
WCNC | 1 |
| 2009 | A joint routing and scheduling scheme for wireless networks with multi-packet reception and directional antennasabstractIn this paper, we present a linear programming formulation for the throughput optimization problem in wireless networks that support multi-packet reception (MPR) capability. The formulation takes into account the use of both directional and omni-directional antennas as well as the use of multiple transmitter interfaces per node. The joint routing and scheduling problem is decoupled into routing and scheduling subproblems. We show that the scheduling subproblem is intractable, and propose a polynomial time scheduling algorithm to solve it. We further demonstrate that, for certain type of networks, the completion time of the scheduling algorithm is at most two times the completion time of the the optimal scheduler, which is unknown. We use the proposed scheme for a preliminary study of several design parameters on the performance of MPR-capable networks, including the number of interfaces, the MPR capability and the beamwidth of the antennas. Jorge Crichigno, Min-You Wu, Joud S. Khoury, Wei Shu |
WOWMOM | 1 |
| 2008 | A Dynamic Programming Approach for Routing in Wireless Mesh NetworksabstractThe routing problem in wireless mesh networks is concerned with finding "good" source-destination paths. It generally faces multiple objectives to be optimized, such as i) path capacity, which accounts for the bits per second that can be sent along the path connecting the source to the destination node, and ii) end-to-end delay. This paper presents the mesh routing algorithm (MRA), a dynamic programming approach to compute high-capacity paths while simultaneously bounding the end-to-end delay. The proposed algorithm also provides the option of routing through multiple link-disjoint paths, such that the amount of traffic through each path is proportional to its capacity. Simulation results show that MRA outperforms other common techniques in terms of path capacity, while at the same time bounding the end-to-end delay to a desired value. Jorge Crichigno, Joud S. Khoury, Min-You Wu, Wei Shu |
GLOBECOM | 1 |
| 2008 | Protocols and architectures for channel assignment in wireless mesh networks
Jorge Crichigno, Min-You Wu, Wei Shu |
Ad Hoc Networks | 1 |
| 2004 | Multiobjective Multicast Routing Algorithm for Traffic EngineeringabstractThis work presents a new version of a multiobjective multicast routing algorithm (MMA) for traffic-engineering, based on the strength Pareto evolutionary algorithm (SPEA), which simultaneously optimizes the maximum link utilization, the cost of the tree, the maximum end-to-end delay and the average delay. In this way, a set of optimal solutions, known as Pareto set, is calculated in only one run, without a priori restrictions. Simulation results show that MMA is able to find Pareto optimal solutions. They also show that for dynamic multicast routing, where the traffic requests arrive one after another, MMA outperforms other known algorithms. Jorge Crichigno, Benjamín Barán |
ICCCN | 1 |