VLDB 2026 Research / reviewers in the wild / expert
Ang Chen 0001
dblp:59/146-1
· DBLP profile ↗
71ranked-venue papers
8as first author
41since 2021 · last 2026
0009-0003-8326-8124ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 37 · 4 first-author · 21 since 2021Security and privacy · 11 · 5 since 2021Software engineering, systems software and programming languages · 8 · 2 first-author · 6 since 2021Databases, data management, data science and information retrieval · 8 · 1 first-author · 4 since 2021Systems, architecture and hardware · 7 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TetriServe: Efficiently Serving Mixed DiT Workloads
Runyu Lu, Shiqi He, Wenxuan Tan, Shenggui Li, Jeff J. Ma, Ang Chen 0001, Mosharaf Chowdhury |
ASPLOS (2) | 7 |
| 2026 | Secure Vickrey Auctions for Online Advertising
Archit Bhatnagar, Yunming Xiao, Ang Chen 0001, Amrita Roy Chowdhury 0001 |
NSDI | 3 |
| 2026 | A Composable Emulation Framework for Whitebox Switches
Congcong Miao, Xianneng Zou, Chuwen Zhang, Qihang Liu, Zhijie Yan, Yanke Zhang, Yong Jiang 0001, Qiao Xiang, Xin Jin 0008, Zili Meng, Ang Chen 0001 |
NSDI | 12 |
| 2026 | XFir: Accelerating New-Flow Setup on Host Servers of a Large Cloud NetworkabstractIn today's cloud networks, host servers widely deploy Data Processing Units (DPUs) as network accelerators under the "Sep-Path" paradigm. However, as server capabilities scale with increasing CPU cores and network bandwidth, the software slow path (executed on a DPU's CPU) has become a critical bottleneck for workloads with high new-flow rates. Meanwhile, new-flow setup logic on host servers must continuously evolve to meet diverse and changing customer demands, making flexibility a key requirement alongside performance. To address this gap, we present XFir, the first hardware-accelerated new-flow setup system for cloud host servers that delivers high CPS throughput while preserving sufficient flexibility. XFir leverages a next-generation DPU equipped with a Cloud Network co-Processor (CNP) to execute the host server's new-flow setup logic. XFir redesigns the host-server flow-setup datapath and table layout, optimizes LPM lookups, and introduces CPU-CNP collaboration mechanisms to further improve performance and reliability. Our evaluation shows that XFir achieves over 776K new-flow CPS on a single host server with 11.7μs slow-path latency. Compared to prior work (Fornax), XFir achieves 4.8x CPS and reduces latency by 69.2%. Moreover, XFir is cost-effective to deploy, requiring only a single DPU per host. Overall, XFir improves new-flow throughput while maintaining development flexibility at low financial cost. Shihan Lin, Shunqiao Jiang, Chao Pei, Jian Zhao 0006, Wenjun Wu 0001, Lijun Zhuang, Qingmin Liu, Heng Yu 0005, Yibo Huang 0005, Yifei Zhu 0001, Yunming Xiao, Ang Chen 0001, Linghe Kong, Congcong Miao |
SIGCOMM | 16 |
| 2026 | CubeTrace: Microscopic Network Tracing for Heterogeneous Cloud Gateways
Yunming Xiao, Yinchao Yang, Jiaqi Zheng 0001, Xuqian Li, Dongbo Gu, Jun Zhang 0014, Miantao Wan, Chao Pei, Chen Tian 0001, Mingwei Xu 0001, Ang Chen 0001, Congcong Miao |
SIGCOMM | 11 |
| 2026 | Dorado: Scaling SmartNIC Session Tables on Commodity DDRs
Heng Yu 0005, Jiajun Liang, Baozeng Zhang, Guozhi Lin, Xinyi Zhang 0004, Jian Zhao 0006, Ziyue Zhai, Chao Pei, Jilong Wang 0001, Gaogang Xie, Ang Chen 0001, Congcong Miao |
SIGCOMM | 14 |
| 2025 | Exposing RDMA NIC Resources for Software-Defined SchedulingabstractPeer Reviewed Yibo Huang 0005, Yiming Qiu 0001, Yunming Xiao, Archit Bhatnagar, Sylvia Ratnasamy, Ang Chen 0001 |
APNet | 6 |
| 2025 | SQUiD: Synthesizing Relational Databases from Unstructured TextabstractRelational databases are central to modern data management, yet most data exists in unstructured forms like text documents.To bridge this gap, we leverage large language models (LLMs) to automatically synthesize a relational database by generating its schema and populating its tables from raw text.We introduce SQUiD, a novel neurosymbolic framework that decomposes this task into four stages, each with specialized techniques.Our experiments show that SQUiD consistently outperforms baselines across diverse datasets.Our code and datasets are publicly available at Mushtari Sadia, Zhenning Yang, Yunming Xiao, Ang Chen 0001, Amrita Roy Chowdhury 0001 |
EMNLP | 4 |
| 2025 | Remote Direct Code ExecutionabstractWe propose remote direct code execution (RDX), which elevates the power of RDMA from memory access to code execution. We target runtime extension frameworks such as Wasm filters, BPF programs, and UDF functions, where RDX enables an agentless architecture that unlocks capabilities such as fast extension injection, update consistency guarantees, and minimal resource contention. We outline the roadmap for RDX around a new CodeFlow abstraction, encompassing programming remote extensions, exposing management stubs, remotely validating and JIT compiling code, seamlessly linking code to local context, managing remote extension state, and synchronizing code to targets. The case studies and initial results demonstrate the feasibility of RDX and its potential to spark the next wave of RDMA innovations. Yibo Huang 0005, Yiming Qiu 0001, Daqian Ding, Patrick Tser Jern Kon, Yiwen Zhang 0008, Yuzhou Mao, Archit Bhatnagar, Mosharaf Chowdhury, Srini Devadas, Jiarong Xing, Ang Chen 0001 |
HotNets | 11 |
| 2025 | A Case for Learned Cloud EmulatorsabstractCreating and maintaining cloud infrastructure via "DevOps programs" is essential to using the cloud. However, developing and testing the DevOps programs requires resource provisioning in the cloud, which is time-consuming and costly. Cloud emulators seek to enable high velocity development by emulating cloud-level APIs to DevOps programs, enabling frictionless testing locally without going through the cloud. However, developing these emulators today is tedious and error-prone: engineers need to digest extensive documentation, and hand-craft emulation logic for each service and service interactions. We make a case for a fundamentally different approach: to "learn" emulation logic from cloud documentation via automated code synthesis. We observe that this task is particularly amenable to AI automation, and that we can constrain the code generation using principled abstractions for accurate synthesis at scale. We report our preliminary findings and discuss new opportunities that our approach will enable. check Archit Bhatnagar, Yiming Qiu 0001, Sarah McClure, Sylvia Ratnasamy, Ang Chen 0001 |
HotNets | 5 |
| 2025 | Unlocking ECMP Programmability for Precise Traffic Control
Yunming Xiao, Weizhen Dang, Xiang Li 0223, Zekun He, Jilong Wang 0001, Aleksandar Kuzmanovic, Ang Chen 0001, Congcong Miao |
NSDI | 10 |
| 2025 | Guest Editorial: Special Issue on Zero Trust for Next-Generation Networking
Moayad Aloqaily, Qian Zhang 0001, Martin Andreoni, Michele Nogueira Lima, Xiaojiang Du, Ang Chen 0001 |
IEEE J. Sel. Areas Commun. | 6 |
| 2024 | Enoki: High Velocity Linux Kernel Scheduler DevelopmentabstractKernel task scheduling is important for application performance, adaptability to new hardware, and complex user requirements. However, developing, testing, and debugging new scheduling algorithms in Linux, the most widely used cloud operating system, is slow and difficult. We developed Enoki, a framework for high velocity development of Linux kernel schedulers. Enoki schedulers are written in safe Rust, and the system supports live upgrade of new scheduling policies into the kernel, userspace debugging, and bidirectional communication with applications. A scheduler implemented with Enoki achieved near identical performance (within 1% on average) to the default Linux scheduler CFS on a wide range of benchmarks. Enoki is also able to support a range of research schedulers, specifically the Shinjuku scheduler, a locality aware scheduler, and the Arachne core arbiter, with good performance. Samantha Miller, Anirudh Kumar, Tanay Vakharia, Ang Chen 0001, Danyang Zhuo, Thomas E. Anderson |
EuroSys | 4 |
| 2024 | Occam: A Programming System for Reliable Network ManagementabstractThe complexity of large networks makes their management a daunting task. State-of-the-art network management tools use workflow systems for automation, but they do not adequately address the substantial challenges in operation reliability. This paper presents Occam, a programming system that simplifies the development of reliable network management tasks. We leverage the fact that most modern network management systems are backed with a source-of-truth database, and thus customize database techniques to the context of network management. Occam exposes an easy-to-use programming model for network operators to express the key management logic, while shielding them from reliability concerns, such as operational conflicts and task atomicity. Instead, the Occam runtime provides these reliability guardrails automatically. Our evaluation demonstrates Occam's effectiveness in simplifying management tasks, minimizing network vulnerable time and assisting with failure recovery. Jiarong Xing, Kuo-Feng Hsu, Yiting Xia, Yan Cai 0018, Ying Zhang 0022, Ang Chen 0001 |
EuroSys | 7 |
| 2024 | IaC-Eval: A Code Generation Benchmark for Cloud Infrastructure-as-Code ProgramsabstractInfrastructure-as-Code (IaC), an important component of cloud computing, allows the definition of cloud infrastructure in high-level programs. However, developing IaC programs is challenging, complicated by factors that include the burgeoning complexity of the cloud ecosystem (e.g., diversity of cloud services and workloads), and the relative scarcity of IaC-specific code examples and public repositories. While large language models (LLMs) have shown promise in general code generation and could potentially aid in IaC development, no benchmarks currently exist for evaluating their ability to generate IaC code. We present IaC-Eval, a first step in this research direction. IaC-Eval's dataset includes 458 human-curated scenarios covering a wide range of popular AWS services, at varying difficulty levels. Each scenario mainly comprises a natural language IaC problem description and an infrastructure intent specification. The former is fed as user input to the LLM, while the latter is a general notion used to verify if the generated IaC program conforms to the user's intent; by making explicit the problem's requirements that can encompass various cloud services, resources and internal infrastructure details. Our in-depth evaluation shows that contemporary LLMs perform poorly on IaC-Eval, with the top-performing model, GPT-4, obtaining a pass@1 accuracy of 19.36%. In contrast, it scores 86.6% on EvalPlus, a popular Python code generation benchmark, highlighting a need for advancements in this domain. We open-source the IaC-Eval dataset and evaluation framework at https://github.com/autoiac-project/iac-eval to enable future research on LLM-based IaC code generation. Patrick Tser Jern Kon, Yiming Qiu 0001, Weijun Fan, Owen Park, George Elengikal, Yuxin Kang, Ang Chen 0001, Mosharaf Chowdhury, Myungjin Lee, Xinyu Wang 0006 |
NeurIPS | 11 |
| 2024 | In-Network Address Caching for Virtual NetworksabstractPacket routing in virtual networks requires virtual-to-physical address translation. The address mappings are updated by a single party, i.e., the network administrator, but they are read by multiple devices across the network when routing tenant packets. Existing approaches face an inherent read-write performance tradeoff: they either store these mappings in dedicated gateways for fast updates at the cost of slower forwarding or replicate them at end-hosts and suffer from slow updates. Lior Zeno, Ang Chen 0001, Mark Silberstein |
SIGCOMM | 2 |
| 2024 | Unearthing Semantic Checks for Cloud Infrastructure-as-Code ProgramsabstractCloud infrastructures are increasingly managed by Infrastructure-as-Code (IaC) frameworks (e.g., Terraform). IaC frameworks enable cloud users to configure their resources in a declarative manner, without having to directly work with low-level cloud API calls. However, with today's IaC tooling, IaC programs that pass the compilation phase may still incur errors at deployment time, resulting in significant disruption. We observe that this stems from a fundamental semantic gap between IaC-level programs and cloud-level requirements---even a syntactically-correct IaC program may violate cloud-level expectations. To bridge this gap, we develop Zodiac, a tool that can unearth IaC-level semantic checks on cloud-level requirements. It provides an automated pipeline to mine these checks from online IaC repositories and validate them using deployment-based testing. We have applied Zodiac to Terraform resources offered by Microsoft Azure---a leading IaC framework and a leading cloud vendor---where it found 500+ semantic checks where violation would produce deployment failures. With these checks, we have identified 200+ buggy Terraform projects and helped fix errors within official Azure provider usage examples. Yiming Qiu 0001, Patrick Tser Jern Kon, Ryan Beckett, Ang Chen 0001 |
SOSP | 4 |
| 2024 | NetShuffle: Circumventing Censorship with Shuffle Proxies at the EdgeabstractNetShuffle is a censorship resistance system that offers "shuffle proxies," where regular proxy services (e.g., HTTPS proxies, Tor bridges) are decoupled from their addresses via continuous in-network change. This makes shuffle proxies significantly more difficult to block compared to their traditional counterparts, because the network locations are now in constant flux. NetShuffle is also designed to engage a new class of support base—edge networks—which have received scant attention from existing work. NetShuffle uses emerging programmable switches to provide the shuffle, while staying otherwise transparent to services and clients, enabling it to be applied as a drop-in network appliance to help promote Internet freedom. We have prototyped NetShuffle in testbed environments and operated it seamlessly on a slice of a live campus network for more than a month, showing that it provides network shuffles in a way that is transparent and incurs negligible overheads. Patrick Tser Jern Kon, Aniket Gattani, Dhiraj Saharia, Diogo Barradas, Ang Chen 0001, Micah Sherr, Benjamin E. Ujcich |
SP | 6 |
| 2024 | SpotProxy: Rediscovering the Cloud for Censorship Circumvention
Patrick Tser Jern Kon, Sina Kamali, Jinyu Pei, Diogo Barradas, Ang Chen 0001, Micah Sherr, Moti Yung |
USENIX Security Symposium | 5 |
| 2023 | Templating Shuffles
Qizhen Zhang 0001, Jiacheng Wu 0001, Ang Chen 0001, Vincent Liu 0001, Boon Thau Loo |
CIDR | 3 |
| 2023 | Simplifying Cloud Management with Cloudless ComputingabstractCloud computing has transformed the IT industry, but managing cloud infrastructures remains a difficult task. We make a case for putting today's management practices, known as "Infrastructure-as-Code," on a firmer ground via a principled design. We call this end goal Cloudless Computing: it aims to simplify cloud infrastructure management tasks by supporting them "as-a-service," analogous to serverless computing that relieves users of the burden of managing server instances. By assisting tenants with these tasks, cloud resources will be presented to their users more readily without the undue burden of complex control. We describe the research problems by examining the typical lifecycle of today's cloud infrastructure management, and identify places where a cloudless approach will advance the state of the art. Yiming Qiu 0001, Patrick Tser Jern Kon, Jiarong Xing, Yibo Huang 0005, Xinyu Wang 0006, Peng Huang 0005, Mosharaf Chowdhury, Ang Chen 0001 |
HotNets | 9 |
| 2023 | Synthesizing Runtime Programmable Switch Updates
Yiming Qiu 0001, Ryan Beckett, Ang Chen 0001 |
NSDI | 3 |
| 2023 | Unleashing SmartNIC Packet Processing Performance in P4abstractSmartNICs are on the rise as a packet processing platform, with the trend towards a uniform P4 programming model. However, unleashing SmartNIC packet processing performance in P4 is a formidable task. Traditional SmartNIC optimizations rely on low-level program tuning, but P4 abstractions operate at one level above. At the same time, today's P4 optimizations primarily focus on resource packing rather than performance tuning. We develop Pipeleon, an automated performance optimization framework for P4 programmable SmartNICs. We introduce techniques that are tailored to the performance characteristics of SmartNICs, and further leverage dynamic workload patterns for profile-guided optimization. Pipeleon pinpoints program hotspots at the P4 level and computes runtime optimization plans to specialize the program layout based on the latest profile. We have prototyped Pipeleon and applied it to optimize two popular P4 SmartNICs---Nvidia BlueField2 and Netronome Agilio CX---as well as a software SmartNIC emulator extended based on BMv2. Our results show that Pipeleon significantly improves SmartNIC packet processing performance in realistic scenarios. Jiarong Xing, Yiming Qiu 0001, Kuo-Feng Hsu, Songyuan Sui, Khalid Manaa, Omer Shabtai, Yonatan Piasetzky, Matty Kadosh, Arvind Krishnamurthy, T. S. Eugene Ng, Ang Chen 0001 |
SIGCOMM | 11 |
| 2023 | Remote Direct Memory Introspection
Jiarong Xing, Yibo Huang 0005, Danyang Zhuo, Srini Devadas, Ang Chen 0001 |
USENIX Security Symposium | 6 |
| 2022 | Symbolic Distillation for Learned TCP Congestion ControlabstractRecent advances in TCP congestion control (CC) have achieved tremendous success with deep reinforcement learning (RL) approaches, which use feedforward neural networks (NN) to learn complex environment conditions and make better decisions. However, such ``black-box'' policies lack interpretability and reliability, and often, they need to operate outside the traditional TCP datapath due to the use of complex NNs. This paper proposes a novel two-stage solution to achieve the best of both worlds: first to train a deep RL agent, then distill its (over-)parameterized NN policy into white-box, light-weight rules in the form of symbolic expressions that are much easier to understand and to implement in constrained environments. At the core of our proposal is a novel symbolic branching algorithm that enables the rule to be aware of the context in terms of various network conditions, eventually converting the NN policy into a symbolic tree. The distilled symbolic rules preserve and often improve performance over state-of-the-art NN policies while being faster and simpler than a standard neural network. We validate the performance of our distilled symbolic rules on both simulation and emulation environments. Our code is available at https://github.com/VITA-Group/SymbolicPCC. S. P. Sharan, Wenqing Zheng, Kuo-Feng Hsu, Jiarong Xing, Ang Chen 0001, Zhangyang Wang |
NeurIPS | 5 |
| 2022 | RDC: Energy-Efficient Data Center Network Congestion Relief with Topological Reconfigurability at the Edge
Dingming Wu 0002, Sushovan Das, Afsaneh Rahbar, Ang Chen 0001, T. S. Eugene Ng |
NSDI | 5 |
| 2022 | Closed-loop Network Performance Monitoring and Diagnosis with SpiderMon
Xinyu Crystal Wu, Praveen Tammana, Ang Chen 0001, T. S. Eugene Ng |
NSDI | 4 |
| 2022 | Runtime Programmable Switches
Jiarong Xing, Kuo-Feng Hsu, Matty Kadosh, Alan Lo, Yonatan Piasetzky, Arvind Krishnamurthy, Ang Chen 0001 |
NSDI | 7 |
| 2022 | Optimizing Data-intensive Systems in Disaggregated Data Centers with TELEPORTabstractRecent proposals for the disaggregation of compute, memory, storage, and accelerators in data centers promise substantial operational benefits. Unfortunately, for resources like memory, this comes at the cost of performance overhead due to the potential insertion of network latency into every load and store operation. This effect is particularly felt by data-intensive systems due to the size of their working sets, the frequency at which they need to access memory, and the relatively low computation per access. This performance impairment offsets the elasticity benefit of disaggregated memory. This paper presents TELEPORT, a compute pushdown framework for data-intensive systems that run on disaggregated architectures; compared to prior work on compute pushdown, TELEPORT is unique in its efficiency and flexibility. We have developed optimization prin- ciples for several popular systems including a columnar in-memory DBMS, a graph processing system, and a MapReduce system. The evaluation results show that using TELEPORT to push down simple operators improves the performance of these systems on state-of-the-art disaggregated OSes by an order of magnitude, thus fully exploiting the elasticity of disaggregated data centers. Qizhen Zhang 0001, Xinyi Chen 0004, Sidharth Sankhe, Zhilei Zheng, Ke Zhong, Sebastian Angel, Ang Chen 0001, Vincent Liu 0001, Boon Thau Loo |
SIGMOD Conference | 7 |
| 2022 | Bedrock: Programmable Network Support for Secure RDMA Systems
Jiarong Xing, Kuo-Feng Hsu, Yiming Qiu 0001, Ziyang Yang, Ang Chen 0001 |
USENIX Security Symposium | 6 |
| 2022 | Shufflecast: An Optical, Data-Rate Agnostic, and Low-Power Multicast Architecture for Next-Generation Compute ClustersabstractAn optical circuit-switched network core has the potential to overcome the inherent challenges of a conventional electrical packet-switched core of today’s compute clusters. As optical circuit switches (OCS) directly handle the photon beams without any optical-electrical-optical (O/E/O) conversion and packet processing, OCS-based network cores have the following desirable properties: a) agnostic to data-rate, b) negligible/zero power consumption, c) no need of transceivers, d) negligible forwarding latency, and e) no need for frequent upgrade. Unfortunately, OCS can only provide point-to-point (unicast) circuits. They do not have built-in support for one-to-many (multicast) communication, yet multicast is fundamental to a plethora of data-intensive applications running on compute clusters nowadays. In this paper, we propose Shufflecast, a novel optical network architecture for next-generation compute clusters that can support high-performance multicast satisfying all the properties of an OCS-based network core. Shufflecast leverages small fanout, inexpensive, passive optical splitters to connect the Top-of-rack (ToR) switch ports, ensuring data-rate agnostic, low-power, physical-layer multicast. We thoroughly analyze Shufflecast’s highly scalable data plane, light-weight control plane, and graceful failure handling. Further, we implement a complete prototype of Shufflecast in our testbed and extensively evaluate the network. Shufflecast is more power-efficient than the state-of-the-art multicast mechanisms. Also, Shufflecast is more cost-efficient than a conventional packet-switched network. By adding Shufflecast alongside an OCS-based unicast network, an all-optical network core with the aforementioned desirable properties supporting both unicast and multicast can be realized. Sushovan Das, Afsaneh Rahbar, Xinyu Crystal Wu, Ang Chen 0001, T. S. Eugene Ng |
IEEE/ACM Trans. Netw. | 6 |
| 2021 | Probabilistic profiling of stateful data planes for adversarial testingabstractRecently, there is a flurry of projects that develop data plane systems in programmable switches, and these systems perform far more sophisticated processing than simply deciding a packet's next hop (i.e., traditional forwarding). This presents challenges to existing network program profilers, which are developed primarily to handle stateless forwarding programs. Qiao Kang, Jiarong Xing, Yiming Qiu 0001, Ang Chen 0001 |
ASPLOS | 4 |
| 2021 | High Velocity Kernel File Systems with Bento
Samantha Miller, Kaiyuan Zhang 0001, Ryan Jennings, Ang Chen 0001, Danyang Zhuo, Thomas E. Anderson |
FAST | 5 |
| 2021 | MXDAG: A Hybrid Abstraction for Emerging ApplicationsabstractEmerging distributed applications, such as microservices, machine learning, big data analysis, consist of both compute and network tasks. DAG-based abstraction primarily targets compute tasks and has no explicit network-level scheduling. In contrast, Coflow abstraction collectively schedules network flows among compute tasks but lacks the end-to-end view of the application DAG. Because of the dependencies and interactions between these two types of tasks, it is sub-optimal to only consider one of them. We argue that co-scheduling of both compute and network tasks can help applications towards the globally optimal end-to-end performance. However, none of the existing abstractions can provide fine-grained information for co-scheduling. We propose MXDAG, an abstraction to treat both compute and network tasks explicitly. It can capture the dependencies and interactions of both compute and network tasks leading to improved application performance. Sushovan Das, Xinyu Crystal Wu, Ang Chen 0001, T. S. Eugene Ng |
HotNets | 5 |
| 2021 | A Vision for Runtime Programmable NetworksabstractOur community has made significant progress in developing programmable network infrastructure, starting from the control plane and expanding to the data plane. As a latest trend, network devices are becoming runtime programmable while serving live traffic. This allows for reprogramming of individual device programs at fine-grained timescales to add or remove network functions. Many applications and services, however, need control over a combination of devices, including end host stacks, NICs, and switches, to accomplish their goals. We lay out our vision for runtime programmable networks, building upon device-level features to provide live, network-wide, runtime reprogramming. A whole-stack approach is needed with new programming models, compiler support, and network management abstractions. We outline a research agenda as a call to arms to the community. Jiarong Xing, Yiming Qiu 0001, Kuo-Feng Hsu, Matty Kadosh, Alan Lo, Aditya Akella, Thomas E. Anderson, Arvind Krishnamurthy, T. S. Eugene Ng, Ang Chen 0001 |
HotNets | 11 |
| 2021 | An incremental path towards a safer OS kernelabstractLinux has become the de-facto operating system of our age, but its vulnerabilities are a constant threat to service availability, user privacy, and data integrity. While one might scrap Linux and start over, the cost of that would be prohibitive due to Linux's ubiquitous deployment. In this paper, we propose an alternative, incremental route to a safer Linux through proper modularization and gradual replacement module by module. We lay out the research challenges and potential solutions for this route, and discuss the open questions ahead. Jialin Li 0001, Samantha Miller, Danyang Zhuo, Ang Chen 0001, Jon Howell, Thomas E. Anderson |
HotOS | 4 |
| 2021 | Toward reconfigurable kernel datapaths with learned optimizationsabstractToday's computing systems pay a heavy "OS tax", as kernel execution accounts for a significant amount of resource footprint. This is not least because today's kernels abound with hardcoded heuristics that are designed with unstated assumptions, which rarely generalize well for diversifying applications and device technologies. Yiming Qiu 0001, Thomas E. Anderson, Yingyan (Celine) Lin, Ang Chen 0001 |
HotOS | 5 |
| 2021 | Automated SmartNIC Offloading Insights for Network FunctionsabstractThe gap between CPU and networking speeds has motivated the development of SmartNICs for NF (network functions) offloading. However, offloading performance is predicated upon intricate knowledge about SmartNIC hardware and careful hand-tuning of the ported programs. Today, developers cannot easily reason about the offloading performance or the effectiveness of different porting strategies without resorting to a trial-and-error approach. Yiming Qiu 0001, Jiarong Xing, Kuo-Feng Hsu, Qiao Kang, Ming Liu 0027, Srinivas Narayana, Ang Chen 0001 |
SOSP | 7 |
| 2021 | Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive Adversaries
Jiarong Xing, Ang Chen 0001 |
USENIX Security Symposium | 3 |
| 2021 | Rearchitecting In-Memory Object Stores for Low LatencyabstractLow latency is increasingly critical for modern workloads, to the extent that compute functions are explicitly scheduled to be co-located with their in-memory object stores for faster access. However, the traditional object store architecture mandates that clients interact with the server via inter-process communication (IPC). This poses a significant performance bottleneck for low-latency workloads. Meanwhile, in many important emerging AI workloads, such as parallel tree search and reinforcement learning, all the worker processes accessing the object store belong to a single user. We design Lightning, an in-memory object store rearchitected for modern, low-latency workloads in a single-user, multi-process setting. Lightning departs from the traditional design by adopting a shared memory model, enabling clients to directly access the object store without IPC boundary. Instead, client isolation is achieved by a novel integration of Intel Memory Protect Keys (MPK) hardware, transaction logging, and formal verification. Our evaluations show that Lightning outperforms state-of-the-art in-memory object stores by up to 9.0x on five standard NoSQL workloads and up to 4.5x in scaling up a Python tree search program. Lightning improves the throughput of a popular reinforcement learning framework that uses an in-memory object store for data sharing by up to 40%. Danyang Zhuo, Kaiyuan Zhang 0001, Zhuohan Li 0001, Siyuan Zhuang, Stephanie Wang, Ang Chen 0001, Ion Stoica |
Proc. VLDB Endow. | 6 |
| 2021 | Enabling Performant, Flexible and Cost-Efficient DDoS Defense With Programmable SwitchesabstractDistributed Denial-of-Service (DDoS) attacks have become a critical threat to the Internet. Due to the increasing number of vulnerable Internet of Things (IoT) devices, attackers can easily compromise a large set of nodes and launch high-volume DDoS attacks from the botnets. State-of-the-art DDoS defenses, however, have not caught up with the fast development of the attacks. Middlebox-based defenses can achieve high performance with specialized hardware; however, these defenses incur a high cost, and deploying new defenses typically requires a device upgrade. On the other hand, software-based defenses are highly flexible, but software-based packet processing leads to high performance overheads. In this article, we propose Poseidon, a system that addresses these limitations in today's DDoS defenses. It leverages emerging programmable switches, which can be reconfigured in the field without additional hardware upgrades. Users of Poseidon can specify their defense strategies in a modular fashion in the form of a set of defense primitives; this can be further customized easily for each network and extended to include new defenses. Poseidon then maps the defense primitives to run on programmable switches-and when necessary, on server software-for effective defense. When attacks change, Poseidon can reconfigure the underlying defense primitives to respond to the new attack patterns. Evaluations using our prototype demonstrate that Poseidon can effectively defend against high-volume attacks, easily support customization of defense strategies, and adapt to dynamic attacks with low overheads. Menghao Zhang 0001, Chang Liu 0021, Mingwei Xu 0001, Ang Chen 0001, Hongxin Hu, Guofei Gu, Qi Li 0002 |
IEEE/ACM Trans. Netw. | 6 |
| 2020 | Rethinking Data Management Systems for Disaggregated Data Centers
Qizhen Zhang 0001, Yifan Cai 0001, Sebastian Angel, Vincent Liu 0001, Ang Chen 0001, Boon Thau Loo |
CIDR | 5 |
| 2020 | Clara: Performance Clarity for SmartNIC OffloadingabstractThe gap between CPU and networking speeds has motivated the development of SmartNICs for near-network processing. Recent work has shown that many network functions can benefit from SmartNIC offloading, but identifying the best porting strategy requires hand-tuning and workload-specific optimizations. The developer has no easy way to understand the ported performance beforehand Yiming Qiu 0001, Qiao Kang, Ming Liu 0027, Ang Chen 0001 |
HotNets | 4 |
| 2020 | Poseidon: Mitigating Volumetric DDoS Attacks with Programmable Switches
Menghao Zhang 0001, Chang Liu 0021, Ang Chen 0001, Hongxin Hu, Guofei Gu, Qi Li 0002, Mingwei Xu 0001 |
NDSS | 5 |
| 2020 | Contra: A Programmable System for Performance-aware Routing
Kuo-Feng Hsu, Ryan Beckett, Ang Chen 0001, Jennifer Rexford, David Walker 0001 |
NSDI | 3 |
| 2020 | Check before You Change: Preventing Correlated Failures in Service Updates
Ennan Zhai, Ang Chen 0001, Ruzica Piskac, Mahesh Balakrishnan 0001, Bingchuan Tian, Haoliang Zhang |
NSDI | 2 |
| 2020 | Programmable In-Network Security for Context-aware BYOD Policies
Qiao Kang, Lei Xue 0001, Adam Morrison 0003, Ang Chen 0001, Xiapu Luo |
USENIX Security Symposium | 5 |
| 2020 | NetWarden: Mitigating Network Covert Channels while Preserving Performance
Jiarong Xing, Qiao Kang, Ang Chen 0001 |
USENIX Security Symposium | 3 |
| 2020 | Understanding the Effect of Data Center Resource Disaggregation on Production DBMSsabstractResource disaggregation is a new architecture for data centers in which resources like memory and storage are decoupled from the CPU, managed independently, and connected through a high-speed network. Recent work has shown that although disaggregated data centers (DDCs) provide operational benefits, applications running on DDCs experience degraded performance due to extra network latency between the CPU and their working sets in main memory. DBMSs are an interesting case study for DDCs for two main reasons: (1) DBMSs normally process data-intensive workloads and require data movement between different resource components; and (2) disaggregation drastically changes the assumption that DBMSs can rely on their own internal resource management. We take the first step to thoroughly evaluate the query execution performance of production DBMSs in disaggregated data centers. We evaluate two popular open-source DBMSs (MonetDB and PostgreSQL) and test their performance with the TPC-H benchmark in a recently released operating system for resource disaggregation. We evaluate these DBMSs with various configurations and compare their performance with that of single-machine Linux with the same hardware resources. Our results confirm that significant performance degradation does occur, but, perhaps surprisingly, we also find settings in which the degradation is minor or where DDCs actually improve performance. Qizhen Zhang 0001, Yifan Cai 0001, Xinyi Chen 0004, Sebastian Angel, Ang Chen 0001, Vincent Liu 0001, Boon Thau Loo |
Proc. VLDB Endow. | 5 |
| 2019 | Accelerated Service Chaining on a Single Switch ASICabstractNetwork functions and service function chaining are prevalent in cloud and ISP networks. In traditional software-based solutions, scaling up the capacity of these functions requires a large number of server cores. However, edge clouds are severely resource-constrained in terms of space, power, and budget, so traditional methods incur a high cost. We present Dejavu, a system that can offload a service chain to a programmable switch to achieve high performance and resource efficiency. Our system can compose multiple network functions into a single program that preserves the original chaining requirements, and exploit features of the switch ASIC to efficiently deploy the composed program on a single switch. Dingming Wu 0002, Ang Chen 0001, T. S. Eugene Ng, Haiyong Wang |
HotNets | 2 |
| 2019 | Architecting Programmable Data Plane Defenses into the Network with FastFlexabstractThis paper is motivated by the ever increasing scale and diversity of attacks that are best handled by the network infrastructure. FastFlex builds upon recent progress, which has developed a variety of network defenses in programmable data planes, and takes this trend one step further: it aims to develop architectural support for these defenses as a first-class citizen. We envision that the network architecture would support these defenses as naturally as it does routing---as the network routes traffic end-to-end, it also turns the defenses on and off as needed for attack mitigation. We propose a key abstraction: the multimode data plane. Normally, it operates under optimal configurations computed by centralized control, but upon attacks, it performs distributed mode changes entirely in data plane for mitigation. Mixed-vector attacks would trigger co-existing modes at different regions of the network, and attacks that rapidly change would be met with equally fast mode adaptations. We sketch this vision, discuss the opportunities and challenges it involves, and present a use case on link-flooding defense. Jiarong Xing, Ang Chen 0001 |
HotNets | 3 |
| 2019 | DataEther: Data Exploration Framework For EthereumabstractEthereum is the largest blockchain platform supporting smart contracts with the second biggest market capitalization. Ethereum data can yield many useful insights because of the large volume of transactions, accounts and blocks as well as the popular applications developed as smart contracts. Studying Ethereum data can also reveal many new attacks to the platform and its smart contracts. Unfortunately, it is non-trivial to systematically explore Ethereum because it involves massive heterogeneous data, which are produced and stored in different ways. Although a few recent studies report some interesting observations about Ethereum, they are limited by their data acquisition methods which cannot provide comprehensive and precise data. In this paper, to fill the gap, we propose DataEther, a systematic and high-fidelity data exploration framework for Ethereum by exploiting its internal mechanisms. Besides supporting the analyses in existing studies, DataEther further empowers users to explore unknown phenomena and obtain in-depth understandings. We first describe how we tackle the challenging issues in developing DataEther, and then use four data-centric applications to demonstrate its usage and report many new observations. Ting Chen 0002, Jiachi Chen, Xiaosong Zhang 0001, Zihao Li 0001, Yufei Zhang 0002, Xiapu Luo, Ang Chen 0001, Shifang Deng |
ICDCS | 8 |
| 2019 | NETHCF: Enabling Line-rate and Adaptive Spoofed IP Traffic FilteringabstractIn this paper, we design NETHCF, a line-rate in-network system for filtering spoofed traffic. NETHCF leverages the opportunity provided by programmable switches to design a novel defense against spoofed IP traffic, and it is highly efficient and adaptive. One key challenge stems from the restrictions of the computational model and memory resources of programmable switches. We address this by decomposing the HCF system into two complementary components-one component for the data plane and another for the control plane. We also aggregate the IP-to-Hop-Count (IP2HC) mapping table for efficient memory usage, and design adaptive mechanisms to handle end-to-end routing changes, IP popularity changes, and network activity dynamics. We have built a prototype on a hardware Tofino switch, and our evaluation demonstrates that NETHCF can achieve line-rate and adaptive traffic filtering with low overheads. Menghao Zhang 0001, Chang Liu 0021, Ang Chen 0001, Guofei Gu, Hai-Xin Duan |
ICNP | 5 |
| 2019 | Total Recall: Persistence of Passwords in Android
Ang Chen 0001, Dan S. Wallach |
NDSS | 2 |
| 2019 | Zeno: Diagnosing Performance Problems with Temporal Provenance
Ang Chen 0001, Linh T. X. Phan |
NSDI | 2 |
| 2019 | Optimizing Declarative Graph Queries at Large ScaleabstractThis paper presents GraphRex, an efficient, robust, scalable, and easy-to-program framework for graph processing on datacenter infrastructure. To users, GraphRex presents a declarative, Datalog-like interface that is natural and expressive. Underneath, it compiles those queries into efficient implementations. A key technical contribution of GraphRex is the identification and optimization of a set of global operators whose efficiency is crucial to the good performance of datacenter-based, large graph analysis. Our experimental results show that GraphRex significantly outperforms existing frameworks---both high- and low-level---in scenarios ranging across a wide variety of graph workloads and network conditions, sometimes by two orders of magnitude. Qizhen Zhang 0001, Akash Acharya, Simran Arora, Ang Chen 0001, Vincent Liu 0001, Boon Thau Loo |
SIGMOD Conference | 5 |
| 2018 | DeDoS: Defusing DoS with Dispersion Oriented SoftwareabstractThis paper presents DeDoS, a novel platform for mitigating asymmetric DoS attacks. These attacks are particularly challenging since even attackers with limited resources can exhaust the resources of well-provisioned servers. DeDoS offers a framework to deploy code in a highly modular fashion. If part of the application stack is experiencing a DoS attack, DeDoS can massively replicate only the affected component, potentially across many machines. This allows scaling of the impacted resource separately from the rest of the application stack, so that resources can be precisely added where needed to combat the attack. Our evaluation results show that DeDoS incurs reasonable overheads in normal operations, and that it significantly outperforms standard replication techniques when defending against a range of asymmetric attacks. Henri Maxime Demoulin, Tavish Vaidya, Isaac Pedisich, Bob DiMaiolo, Jingyu Qian, Yuankai Zhang 0001, Ang Chen 0001, Andreas Haeberlen, Boon Thau Loo, Linh T. X. Phan, Micah Sherr, Clay Shields, Wenchao Zhou |
ACSAC | 8 |
| 2018 | An Historical Analysis of the SEAndroid Policy EvolutionabstractAndroid adopted SELinux's mandatory access control (MAC) mechanisms in 2013. Since then, billions of Android devices have benefited from mandatory access control security policies. These policies are expressed in a variety of rules, maintained by Google and extended by Android OEMs. Over the years, the rules have grown to be quite complex, making it challenging to properly understand or configure these policies. Bumjin Im, Ang Chen 0001, Dan S. Wallach |
ACSAC | 2 |
| 2017 | Data Provenance at Internet Scale: Architecture, Experiences, and the Road Ahead
Ang Chen 0001, Andreas Haeberlen, Boon Thau Loo, Wenchao Zhou |
CIDR | 1 |
| 2017 | One Primitive to Diagnose Them All: Architectural Support for Internet DiagnosticsabstractToday, network operators are increasingly playing the role of part-time detectives: they must routinely diagnose intricate problems and malfunctions, e.g., routing or performance issues, and they must often perform forensic investigations of past misbehavior, e.g., intrusions or cybercrimes. However, the current Internet architecture offers little direct support for them. A variety of solutions have been proposed, but each solution tends to address only one specific problem. Moreover, each solution proposes a different fix that is incompatible with the others, which complicates deployment. Ang Chen 0001, Andreas Haeberlen, Wenchao Zhou, Boon Thau Loo |
EuroSys | 1 |
| 2017 | Automated Bug Removal for Software-Defined Networks
Ang Chen 0001, Andreas Haeberlen, Wenchao Zhou, Boon Thau Loo |
NSDI | 2 |
| 2016 | Dispersing Asymmetric DDoS Attacks with SplitStackabstractThis paper presents SplitStack, an architecture targeted at mitigating asymmetric DDoS attacks. These attacks are particularly challenging, since attackers can use a limited amount of resources to trigger exhaustion of a particular type of system resource on the server side. SplitStack resolves this by splitting the monolithic stack into many separable components called minimum splittable units (MSUs). If part of the application stack is experiencing a DDoS attack, SplitStack massively replicates just the affected MSUs, potentially across many machines. This allows scaling of the impacted resource separately from the rest of the application stack, so that resources can be precisely added where needed to combat the attack. We validate SplitStack via a preliminary case study, and show that it outperforms naive replication in defending against asymmetric attacks. Ang Chen 0001, Akshay Sriraman, Tavish Vaidya, Yuankai Zhang 0001, Andreas Haeberlen, Boon Thau Loo, Linh T. X. Phan, Micah Sherr, Clay Shields, Wenchao Zhou |
HotNets | 1 |
| 2016 | The Good, the Bad, and the Differences: Better Network Diagnostics with Differential ProvenanceabstractIn this paper, we propose a new approach to diagnosing problems in complex distributed systems. Our approach is based on the insight that many of the trickiest problems are anomalies. For instance, in a network, problems often affect only a small fraction of the traffic (e.g., perhaps a certain subnet), or they only manifest infrequently. Thus, it is quite common for the operator to have “examples” of both working and non-working traffic readily available – perhaps a packet that was misrouted, and a similar packet that was routed correctly. In this case, the cause of the problem is likely to be wherever the two packets were treated differently by the network. Ang Chen 0001, Andreas Haeberlen, Wenchao Zhou, Boon Thau Loo |
SIGCOMM | 1 |
| 2015 | Differential Provenance: Better Network Diagnostics with Reference EventsabstractIn this paper, we propose a new approach to diagnosing problems in complex networks. Our approach is based on the insight that many of the trickiest problems are anomalies -- they affect only a small fraction of the traffic (e.g., perhaps a certain subnet), or they only manifest infrequently. Thus, it is quite common for the network operator to have "examples" of both working and non-working traffic readily available -- perhaps a packet that was misrouted, and a similar packet that was routed correctly. In this case, the cause of the problem is likely to be wherever the two packets were treated differently by the network. Ang Chen 0001, Andreas Haeberlen, Wenchao Zhou, Boon Thau Loo |
HotNets | 1 |
| 2015 | Automated Network Repair with Meta ProvenanceabstractWhen debugging an SDN application, diagnosing the problem is merely the first step -- the operator must still implement a solution that works, and that does not cause new problems elsewhere. However, most existing SDN debuggers focus exclusively on identifying the problem and offer the network operator little or no help with finding an effective fix. Finding a fix is challenging because the number of potential repairs can be enormous. Ang Chen 0001, Andreas Haeberlen, Wenchao Zhou, Boon Thau Loo |
HotNets | 2 |
| 2015 | Fault Tolerance and the Five-Second Rule
Ang Chen 0001, Hanjun Xiao, Andreas Haeberlen, Linh T. X. Phan |
HotOS | 1 |
| 2014 | Detecting Covert Timing Channels with Time-Deterministic Replay
Ang Chen 0001, W. Brad Moore, Hanjun Xiao, Andreas Haeberlen, Linh T. X. Phan, Micah Sherr, Wenchao Zhou |
OSDI | 1 |
| 2013 | An efficient approach to multi-level route analytics
Ang Chen 0001, Edmond W. W. Chan, Xiapu Luo, Waiting W. T. Fok, Rocky K. C. Chang |
IM | 1 |
| 2013 | Peer-assisted content distribution in Akamai netsessionabstractContent distribution systems have traditionally adopted one of two architectures: infrastructure-based content delivery networks (CDNs), in which clients download content from dedicated, centrally managed servers, and peer-to-peer CDNs, in which clients download content from each other. The advantages and disadvantages of each architecture have been studied in great detail. Recently, hybrid, or 'peer-assisted', CDNs have emerged, which combine elements from both architectures. The properties of such systems, however, are not as well understood. Mingchen Zhao, Paarijaat Aditya, Ang Chen 0001, Yin Lin, Andreas Haeberlen, Peter Druschel, Bruce M. Maggs, Bill Wishon, Miroslav Ponec |
Internet Measurement Conference | 3 |
| 2013 | SGor: Trust graph based onion routing
Peng Zhou 0002, Xiapu Luo, Ang Chen 0001, Rocky K. C. Chang |
Comput. Networks | 3 |
| 2011 | TRIO: measuring asymmetric capacity with three minimum round-trip timesabstractMeasuring network path capacity is an important capability to many Internet applications. But despite over ten years of effort, the capacity measurement problem is far from being completely solved. This paper addresses the problem of measuring network paths of asymmetric capacity without requiring the remote node's control or overwhelming the bottleneck link. We first show through analysis and measurement that the current packet-dispersion methods, due to the packet size limitations, can only measure up to a certain degree of capacity asymmetry. Second, we propose TRIO that removes the limitation by using round-trip times (RTTs). TRIO cleverly exploits two types of probes to obtain three minimum RTTs to compute bothforward and reverse capacities, and another minimum RTT for measurement validation. We validate TRIO's accuracy and versatility on a testbed and the Internet, and develop a system to measure path capacity from the server or user side. Edmond W. W. Chan, Ang Chen 0001, Xiapu Luo, Ricky K. P. Mok, Weichao Li 0001, Rocky K. C. Chang |
CoNEXT | 2 |