VLDB 2026 Research / reviewers in the wild / expert
Kalman Graffi
dblp:61/5614 · also Kálmán György Graffi
· DBLP profile ↗
50ranked-venue papers
14as first author
4since 2021 · last 2024
0000-0003-1708-6835ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 25 · 7 first-authorSystems, architecture and hardware · 7 · 4 first-author · 1 since 2021Security and privacy · 4 · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-authorArtificial intelligence and machine learning · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Uncovering CWE-CVE-CPE Relations with Threat Knowledge GraphsabstractSecurity assessment relies on public information about products, vulnerabilities, and weaknesses. So far, databases in these categories have rarely been analyzed in combination. Yet, doing so could help predict unreported vulnerabilities and identify common threat patterns. In this article, we propose a methodology for producing and optimizing a knowledge graph that aggregates knowledge from common threat databases (CVE, CWE, and CPE). We apply the threat knowledge graph to predict associations between threat databases, specifically between products, vulnerabilities, and weaknesses. We evaluate the prediction performance both in closed world with associations from the knowledge graph and in open world with associations revealed afterward. Using rank-based metrics (i.e., Mean Rank, Mean Reciprocal Rank, and Hits@N scores), we demonstrate the ability of the threat knowledge graph to uncover many associations that are currently unknown but will be revealed in the future, which remains useful over different time periods. We propose approaches to optimize the knowledge graph and show that they indeed help in further uncovering associations. We have made the artifacts of our work publicly available. Zhenpeng Shi, Nikolay Matyunin, Kalman Graffi, David Starobinski |
ACM Trans. Priv. Secur. | 3 |
| 2022 | TargetFuzz: Using DARTs to Guide Directed Greybox FuzzersabstractSoftware development is a continuous and incremental process. Developers continuously improve their software in small batches rather than in one large batch. The high frequency of small batches makes it essential to use effective testing methods that detect bugs under limited testing time. To this end, researchers propose directed greybox fuzzing (DGF) which aims to generate test cases towards stressing certain target sites. Different from the coverage-based greybox fuzzing (CGF) which aims to maximize code coverage in the whole program, the goal of DGF is to cover potentially buggy code regions (e.g., a recently modified program region). While prior works improve several aspects of DGF (such as power scheduling, input prioritization, and target selection), little attention has been given to improving the seed selection process. Existing DGF tools use seed corpora mainly tailored for CGF (i.e., a set of seeds that cover different regions of the program). We observe that using CGF-based corpora limits the bug-finding capability of a directed greybox fuzzer. To mitigate this shortcoming, we propose TargetFuzz, a mechanism that provides a DGF tool with a target-oriented seed corpus. We refer to this corpus as DART corpus, which contains only 'close' seeds to the targets. This way, DART corpus guides DGF to the targets, thereby exposing bugs even under limited fuzzing time. Evaluations on 34 real bugs show that AFLGo (a state-of-the-art directed greybox fuzzer), when equipped with DART corpus, finds 10 additional bugs and achieves $4.03x speedup, on average, in the time-to-exposure compared to a generic CGF-based corpus. Sadullah Canakci, Nikolay Matyunin, Kalman Graffi, Ajay Joshi, Manuel Egele |
AsiaCCS | 3 |
| 2022 | Batched Differentially Private Information Retrieval
Kinan Dak Albab, Rawane Issa, Mayank Varia, Kalman Graffi |
USENIX Security Symposium | 4 |
| 2021 | LibreSocial: A peer-to-peer framework for online social networksabstractSummary Distributed online social networks (DOSNs) were first proposed to solve the problem of privacy, security, and scalability. A significant amount of research was undertaken to offer viable DOSN solutions that were capable of competing with the existing centralized OSN applications such as Facebook, LinkedIn, and Instagram. This research led to the emergence of the use of peer‐to‐peer (P2P) networks as a possible solution, upon which several OSNs such as LifeSocial.KOM, Safebook, PeerSoN among others were based. In this article, we define the basic requirements for an P2P OSN. We then revisit one of the first P2P‐based OSNs, LifeSocial.KOM, that is now called LibreSocial, which evolved in the past years to address the challenges of running a completely decentralized social network. Over the course of time, several essential new technologies have been incorporated within LibreSocial for better functionalities. In this article we describe the architecture and each individual component of LibreSocial and point out how LibreSocial meets the basic requirements for a fully functional distributed OSN. Kalman Graffi, Newton Masinde |
Concurr. Comput. Pract. Exp. | 1 |
| 2020 | Caching Structures for Distributed Data Management in P2P-based Social NetworksabstractDistributed applications require novel solutions to tackle problems that arise due to the scarcity of resources such as bandwidth, memory and processing power. One of these challenges is seen in distributed data management. The challenge is the two part problem of ensuring that the content is valid when accessed and updating it immediately when changed. This is especially difficult when considering P2P-based distributed online social networks, which aim to build reliable, secure social networking platforms on top of often unreliable and unse-cure devices. In this paper, we propose three selection strategies, random, trend and social score, for a social caching mechanism. They consider the social interaction patterns in the social network. We implement and evaluate them in a DHT-based distributed online social networks called LibreSocial and show that the social score is the best strategy. Further we implement the social caching solution and also show that when used in combination with the existing caching solution almost all requests can be serviced via cache while retaining the consistency of data during updates. Newton Masinde, Moritz Kanzler, Kalman Graffi |
ISNCC | 3 |
| 2019 | Implementing Enterprise Resource Planning Systems in the Cloud: Challenges and SolutionsabstractsCloud computing for Enterprise resource planning (ERP) provides solutions to the difficulties encountered by conventional ERP systems. This research investigates the accompanying issues of implementing ERP systems using Cloud computing, and introduces solutions to these issues including Service level agreement (SLA), standardization, and customers' resistance. The issues are investigated through an exploratory study and proposed solutions are introduced, and then validated based on specifications from the Cloud Security Alliance. The results of this research are simplified assembling of issues, best practices, and specifications toward implementing ERP in the cloud. The research results include: SLA is a necessary contract, but it is not sufficient, as more auditing and checking procedures must be added to the SLA to assure availability and security of offered services. Moreover, bigger providers do not welcome a standard for ERP in the cloud, and they might get convinced by standardizing only the core part of ERP in the cloud. Finally, there are different views about the potential resistance toward ERP in the cloud, but increasing the customers' awareness and confident in the cloud ERP systems could help overcoming this resistance. The results of this work should help the market and researchers getting better understanding of the market view towards ERP in the cloud, and the chances of promoting it. Ahmad Rabay'a, Kalman Graffi |
ISNCC | 2 |
| 2018 | Minicamp: Middleware for Incomplete Participation in Structured Peer-to-Peer Monitoring ProtocolsabstractIn order to provide a certain level of quality to the users of a peer-to-peer network, the network's status needs to be monitored in the first place. In this paper, we tackle the problem of monitoring peer-to-peer networks with structured monitoring solutions with the constraint of incomplete participation of the nodes in the monitoring process. We propose a middleware overlay which operates between the common p2p overlay aiming at routing and resolving lookups and a monitoring overlay aiming to obtain and disseminate statistics on the network. Our solution covers an assignment, maintenance and probing scheme to build up a common global view for all nodes in the common p2p overlay. Evaluation shows a high precision for the assignment and probing scheme in the presence of only a fraction of the nodes in the network contributing to the monitoring. Andreas Disterhöft, Kalman Graffi |
AINA | 2 |
| 2018 | Time and Space in Android-Based Opportunistic NetworksabstractMobile devices like smartphones or other smart objects can create Opportunistic Networks with intermittent node contacts due to their wireless technology and their user's social behavior. In disaster, emergency and censorship situations, or if simply no internet connection is available, Opportunistic Networking can be used to connect devices to each other. We attempt to improve our Android-based network and take a look at time modification and buffer management issues. Syncing the time is a known problem due to the probable lack of a connection to the internet. Since the devices are user-controlled, changes in time have to be noticed and time differences between devices have to be exchanged. Also, we take a look at the special buffer which is not reserved entirely for the network but is shared with all applications on the device. For this paper, we developed functionality in form of multiple libraries to detect time changes and possible storage shortages on the devices, to synchronize time for our network, and to remove messages in a system in which there is not only one buffer but multiple virtual ones that belong to different applications. We conduct tests which detect when the Android system begins to notify about storage congestion and starts deleting buffer content. With these results, our libraries can improve the drop and queue policies that have to react before user data is deleted. Andre Ippisch, Tobias Kuper, Kalman Graffi |
AINA | 3 |
| 2018 | Optimal Replication Based on Optimal Path Hops for Opportunistic NetworksabstractOpportunistic Networks are highly mobile networks which may lack a reliable path between some source and destination. Therefore, this type of network uses Store, Carry and Forward and delivers messages based on hop-by-hop routing. Epidemic is the simplest routing protocol for Opportunistic Networks, as it replicates messages to all encountered nodes. For messages spread by Epidemic replication, we study and analyze the trade-off between the messages' delivery ratio, delay, and overhead. We consider that all members of the network, at any given time, know the amount of relay nodes that pass the message and each message carrier knows the amount of infected nodes that already have acquired the message. We address the problem of deriving the optimal closed-loop control for the replication strategy in our network. We draft this issue as a controlled, discrete-time and finite-state Markov Chain with an All Hops Optimal Path formulation. In real life scenarios, however, due to the intermittent correspondence in Opportunistic Networks the nodes do not have insight of the network's global state. We try to solve this issue by obtaining an Ordinary Differential Equation approximation of the Markov Chain for the replication process of messages. Furthermore, our model considers All Hops Optimal Path as network graph analysis for the optimally controlled replication. Lastly, we present the performance evaluation of these replication control conditions in finite networks. Our results show that this proposed Optimal Replication Based on Optimal Path Hops performs better than the omni-directional and contact-based Epidemic routing replication. Andre Ippisch, Salem Sati, Kalman Graffi |
AINA | 3 |
| 2018 | Search Algorithms for Distributed Data Structures in P2P NetworksabstractThe search problem in distributed systems has been evaluated and various proposals have been made to solve them. The problem is particularly pronounced when considering P2P networks, because the different types of P2P network topologies used to dictate the search mechanisms that are used. Specifically, search mechanisms may be key-based, as in structured P2P networks that use distributed data structures such as Distributed Hash Tables (DHTs), Sets, Links, and Trees, or keyword-based for unstructured P2P networks. Online systems today utilize metadata to support search algorithms. Metadata searches are trivial in unstructured networks but are a challenge to the structured networks because of the distributed data structures (DDS). This work proposes to introduce algorithms that support metadata searches in structured P2P networks that utilize DHT overlays. DDSs are introduced into the system as storage layers that support complex data structures. We show that this can be done and searching can be achieved with acceptable performance. Raed Al-Aaridhi, Iakov Dlikman, Newton Masinde, Kalman Graffi |
ISNCC | 4 |
| 2017 | CapSearch: Capacity-Based Search in Highly Dynamic Peer-to-Peer NetworksabstractIn times of greatly heterogeneous devices, e.g. smart phones vs. desktop PCs, and their users participating in various types of networks new scenarios appear. These scenarios include peer-to-peer networks participants providing their capacities in order to operate this system. In case of weaker participants, which temporarily do not have enough capacities to contribute their share to the network, get overloaded. In a different case, participants may delegate a certain job to another participant, which is capable for this job. In this paper we propose a fast and reliable indexing and search mechanism for participants' capacities. We focus on a churn-resilient structure using a kd-tree with logical nodes in order to be capable of highly dynamic node capacities. Evaluation shows our approach is able to find nearly 60% of all nodes and over 80% of a certain number k of all nodes in big range queries, while keeping the false positive rate close to zero. Andreas Disterhöft, Kalman Graffi |
AINA | 2 |
| 2017 | Infrastructure Mode Based Opportunistic Networks on Android DevicesabstractOpportunistic Networks are delay-tolerant mobile networks with intermittent node contacts in which data is transferred with the store-carry-forward principle. Owners of smartphones and smart objects form such networks due to their social behaviour. Opportunistic Networking can be used in remote areas with no access to the Internet, to establish communication after disasters, in emergency situations or to bypass censorship, but also in parallel to familiar networking. In this work, we create a mobile network application that connects Android devices over Wi-Fi, offers identification and encryption, and gathers information for routing in the network. The network application is constructed in such a way that third party applications can use the network application as network layer to send and receive data packets. We create secure and reliable connections while maintaining a high transmission speed, and with the gathered information about the network we offer knowledge for state of the art routing protocols. We conduct tests on connectivity, transmission range and speed, battery life and encryption speed and show a proof of concept for routing in the network. Andre Ippisch, Kalman Graffi |
AINA | 2 |
| 2017 | Device to device communication in mobile Delay Tolerant networksabstractAvailable smartphones and smart objects can use short range connections like Wi-Fi and Bluetooth as a communication technique to exchange information with nearby devices. Those techniques are used in cases of absent end-to-end connection such as in Delay Tolerant or Opportunistic Networks. The study of message transmission processes and contact information in such networks has gained more attention nowadays, where contact information and message transfer have a great impact on Store-Carry-Forward routing decisions. The performance of routing mechanisms is measured based on bandwidth utilization and energy consumption regarding the delivery ratio. Therefore, in this paper we present a study framework to formulate the message propagation process in addition to contact information with a view on energy consumption. The study gives a detailed expression of contact information such as contact probability based on node density and transmission range in a bounded area. Furthermore, the message exchange process as element of channel utilization and energy consumption will be studied. Based on our simulation experiment results we evaluate the influence of various parameters on each other and finally on the system performance. Andre Ippisch, Salem Sati, Kalman Graffi |
DS-RT | 3 |
| 2017 | Access control for secure distributed data structures in Distributed Hash TablesabstractPeer-To-Peer (P2P) networks open up great possibilities for intercommunication, collaborative and social projects like file sharing, communication protocols or social networks while offering advantages over the conventional Client-Server model of computing pattern. Such networks counter the problems of centralized servers such as that P2P networks can scale to millions without additional costs. In previous work, we presented Distributed Data Structure (DDS) which offers a middle-ware scheme for distributed applications. This scheme builds on top of DHT (Distributed Hash Table) based P2P overlays, and offers distributed data storage services as a middle-ware it still needs to address security issues. The main objective of this paper is to investigate possible ways to handle the security problem for DDS, and to develop a possibly reusable security architecture for access control for secure distributed data structures in P2P networks without depending on trusted third parties. Raed Al-Aaridhi, Ahmed Yuksektepe, Kalman Graffi |
LANMAN | 3 |
| 2017 | Minicamp: Prototype for Partial Participation in Structured Peer-to-Peer Monitoring ProtocolsabstractQuality of service and quality of experience are of increasingly interest for successful communication network applications, particularly for decentralized networks, such as peer-to-peer (p2p) networks. They need sophisticated monitoring mechanisms to be able to adapt the system's parameters to maintain a certain level of quality of service. In the literature, several well-studied approaches, classified as structured monitoring overlays, have been proposed. To the best known of the authors, these do not tackle the problem of partial participation. With Minicamp we propose a middleware which operates between the p2p overlay and the monitoring overlay and creates the opportunity to run monitoring services on just a subset of all nodes. These nodes gather and disseminate monitoring data of the whole system which is achieved by probing the subset of participating nodes. Evaluations reveal high precision for the probing scheme even when facing low participation rates. Andreas Disterhöft, Kalman Graffi |
LCN | 2 |
| 2017 | Moving measurements: Measuring network characteristics of mobile cellular networks on the move
Norbert Goebel, Tobias Krauthoff, Kalman Graffi, Martin Mauve |
Comput. Commun. | 3 |
| 2017 | SkyEye: A tree-based peer-to-peer monitoring approach
Kalman Graffi, Andreas Disterhöft |
Pervasive Mob. Comput. | 1 |
| 2016 | Privacy-Preserving Data Allocation in Decentralized Online Social NetworksabstractDistributed Online Social Networks (DOSNs) have been recently proposed as an alternative to centralized solutions to allow a major control of the users over their own data. Since there is no centralized service provider which decides the term of service, the DOSNs infrastructure exploits users’ devices to take on the online social network services. In this paper, we propose a data allocation strategy for DOSNs which exploits the privacy policies of the users to increase the availability of the users’ contents without diverging from their privacy preferences. A set of replicas of the profile’s content of a user U are stored on the devices of other users who are entitled to access the profile according to U’s privacy policies. The experimental results obtained from the simulations on traces taken from a real social network show the effectiveness of our approach. Andrea De Salve, Paolo Mori, Laura Ricci, Raed Al-Aaridhi, Kalman Graffi |
DAIS | 5 |
| 2016 | Coupled simulation of mobile cellular networks, road traffic and V2X applications using tracesabstractThe development and evaluation of Vehicle-to-X (V2X) applications using mobile cellular networks by means of field tests is time consuming and expensive. Simulations can speed up the development and largely reduce evaluation costs. However, due to the complex nature of the network involved, it is quite difficult to be certain that the results obtained using simulation will actually match the observable behaviour in the real world. In this paper, we introduce a novel trace-based simulation environment for V2X applications using mobile cellular networks. It employs real world measurement traces as a basis and thus avoids many uncertainties of other simulation approaches. Norbert Goebel, Raphael Bialon, Martin Mauve, Kalman Graffi |
ICC | 4 |
| 2016 | The State of Simulation Tools for P2P Networks on Mobile Ad-Hoc and Opportunistic NetworksabstractDuring the Arab spring and other states of political turbulences, the access to selected servers of large communication sites and even the country-wide internet infrastructure has often been affected by enforced censorship and limited the possible communication tools. In order to overcome this censorship a full mobile decentralized network seems to be a viable option. Even though, through the strong dynamism in this decentralized mobile network, future threats, namely intermittent connectivity, changing topologies, and unreliable end nodes may occur. To handle these threats and to provide the desired functionality, self-organized protocols are necessary. This paper presents a survey on the current status of simulation tools for peer-to-peer (P2P), Opportunistic Networks (OppNet), and Mobile Ad Hoc Networks (MANET) with the aim to identify a suitable evaluation tool that is capable for combining these three networks and for simulating decentralized mobile networks. This combination will allow us to create a fully decentralized and self-organized system which cannot be blocked e.g. through the influences of political parties. Ahmad Cheraghi, Tobias Amft, Salem Sati, Philipp Hagemeister, Kalman Graffi |
ICCCN | 5 |
| 2016 | Analysis of Buffer Management Policies for Opportunistic NetworksabstractOpportunistic Networks are a subclass of delay tolerant networks, which aims at wireless data delivery in severely partitioned networks. Messages are routed on a best effort basis. If nodes cannot forward messages due to missing connectivity, the messages are buffered according to a queue policy, and scheduled for transmission once there is a connection again. In case of congestion, nodes drop messages based on a drop policy. The scheduling and the drop policy form together the buffer management policy, which has an impact on routing performance. Although a multitude of different policies exist, there has not yet been a comprehensive study regarding routing performance, which compares all possible policies against each other. In this paper, we conduct this comprehensive study and investigate the impact of the various parameters a message has, namely the arrival time, replication count, number of relayed nodes, time to live and message size, on the performance of the routing in an opportunistic network. In specific, this paper analyzes epidemic routing with 121 different policies and compares them in terms of delivery ratio, overhead and latency in three use cases. Evaluation shows the strengths and weaknesses of the various buffer management policies and highlights, that there is not one policy that is always to recommend. This study will help to create dynamic buffer management policies, which adapt to the given network characteristics and select suitable parameters to prioritize. Salem Sati, Christopher Probst, Kalman Graffi |
ICCCN | 3 |
| 2016 | Sets, lists and trees: Distributed data structures on distributed hash tablesabstractDistributed hash tables and unstructured peer-to-peer overlay networks allow to store, search and retrieve single data elements. While this is useful for simple applications such as file sharing, for future sophisticated applications more sophisticated distributed data structures should be supported. In order to build, for example, architectures for distributed online social networks or distributed computing graphs, more advances data structures such as sets, lists of sorted trees should be supported by the peer-to-peer storage overlay with convenient access to the entries. Taking, for example, the set of albums in a distributed online social network. This set consists of a set of albums consist of sets of images, which themselves have each a list of comments. Using distributed data structures for sets, lists or trees in a distributed hash table allow to easily build sophisticated applications. In this paper, we present and evaluate a concept for such distributed data structures in peer-to-peer networks. In the evaluation, we show that all elements of each distributed data structure is successfully stored and retrieved and that the approach comes with low overhead and delay. Raed Al-Aaridhi, Kalman Graffi |
IPCCC | 2 |
| 2016 | Convex Hull Watchdog: Mitigation of Malicious Nodes in Tree-Based P2P Monitoring SystemsabstractMonitoring the global state in peer-to-peer networks through decentralized mechanisms allows targeted optimization and improvement of the peer-to-peer network. However, malicious nodes could aim to distort the process of gathering the global state through monitoring. In this paper we propose DOMiNo, a security solution for tree-based peer-to-peer monitoring mechanisms. It passively listens to incoming events, e.g. data, and rates its suspiciousness based on outlier detection, structural verification and sanity check mechanisms. For our main objective, which is to limit the monitoring error of the desired global view, we performed an extensive evaluation. Evaluation shows tolerance with normal fluctuations but effective filtering of outliers, that severely influence the global view. As our watchdog solution operates passively, we do not add any costs nor create new surface for attacks to the monitoring system. Andreas Disterhöft, Kalman Graffi |
LCN | 2 |
| 2016 | Implementing Forward and Drop Policies for Improving PRoPHET's Routing PerformanceabstractRouting protocols for delay tolerant network are designed to operate in an environment where there is no stable end to end path. The DTN research has focused primarily on the performance of routing protocols that build on a Store-Carry-Forward manner without consideration of a physical buffer limitation. Therefore, the need of a message sorting and drop policy according to priorities is very critical and favorable in such restricted environments. In this paper, we present effective forward and drop policies to improve the performance of the PRoPHET routing protocol. These forward and drop policies are applied on the PRoPHET version 2 routing protocol, which is currently commonly used as routing protocol for practical implementations of DTN middlewares. In this paper, we propose a stopping rule for the forward strategy in PRoPHET together with a dynamic drop policy. By this, we optimize the routing performance based on reducing the number of relayed messages while keeping a desired delivery ratio. To further improve the resource conservation, we propose new rules for message forwarding when encountering nodes. A forwarding error approximation is used to give the optimal threshold of the forwarding decision. In addition, we propose a dynamic drop policy which considers delay and overhead of the message based on multiple parameters. Simulation results show that the PRoPHET protocol with our new forward and drop policies gives better performance improvement in terms of relayed messages. Salem Sati, Christopher Probst, Kalman Graffi |
MSN | 3 |
| 2016 | Systematic evaluation of peer-to-peer systems using PeerfactSim.KOMabstractSummary Comparative evaluations of peer‐to‐peer protocols through simulations are a viable approach to judge the performance and costs of the individual protocols in large‐scale networks. In order to support this work, we present the peer‐to‐peer system simulator PeerfactSim.KOM, which we extended over the last years. PeerfactSim.KOM comes with an extensive layer model to support various facets and protocols of peer‐to‐peer networking. In this article, we describe PeerfactSim.KOM and show how it can be used for detailed measurements of large‐scale peer‐to‐peer networks. We enhanced PeerfactSim.KOM with a fine‐grained analyzer concept, with exhaustive automated measurements and gnuplot generators as well as a coordination control to evaluate sets of experiment setups in parallel. Thus, by configuring all experiments and protocols only once and starting the simulator, all desired measurements are performed, analyzed, evaluated, and combined, resulting in a holistic environment for the comparative evaluation of peer‐to‐peer systems. An immediate comparison of different configurations and overlays under different aspects is possible directly after the execution without any manual post‐processing. Copyright © 2015 John Wiley & Sons, Ltd. Matthias Feldotto, Kalman Graffi |
Concurr. Comput. Pract. Exp. | 2 |
| 2016 | DiDuSoNet: A P2P architecture for distributed Dunbar-based social networks
Barbara Guidi, Tobias Amft, Andrea De Salve, Kalman Graffi, Laura Ricci |
Peer-to-Peer Netw. Appl. | 4 |
| 2015 | FRoDO: Friendly routing over dunbar-based overlaysabstractCentralized Online Social Networks (OSNs) have become the main communication channel in both the personal and the business domain. A current trend for developing OSN services is towards the distribution of the social network infrastructure by using P2P architectures as basis for Distributed Online Social Networks (DOSNs). One of the main challenges of DOSNs comes from guaranteeing privacy and protection of private data. In previous work [18], we proposed a Dunbar-based approach to preserve data availability in DOSNs. Using Dunbar's circles of intimacy a certain level of trust is ensured which bases on the users confidence in their friends. Now, to achieve privacy and anonymity, we focus on the incorporation of social contacts into existing Peer-to-Peer Overlays and show that a naive integration of social links into existing Overlays like Chord and Pastry is not satisfactory. In order to address drawbacks of the naive approach we introduce goLLuM, a general solution which can be used on top of existing structured and unstructured P2P networks. Our protocol enables to route messages via friendly nodes only, even if only few friends per node exist. By using synthetic models and real-data traces for the representation of friendship relationships we highlight the drawbacks of the naive solution and show the functionality of goLLuM. Tobias Amft, Barbara Guidi, Kalman Graffi, Laura Ricci |
LCN | 3 |
| 2015 | Protected chords in the web: secure P2P framework for decentralized online social networksabstractOnline social networks have emerged as a main tool to communicate in the Internet. While centralized solutions are prone to censorship, privacy violations and unwanted marketing of the users data, decentralized solutions, e.g. based on p2p technology, promise to overcome these limitations. One major shortcoming is the need to install additional software, which is progressively not accepted by users which are used to web-based applications. In this paper, we present how WebRTC can be used to implement an installation-free, fully decentralized online social network. With WebRTC, standard browsers can communicate directly, which allows to construct PKI secured p2p overlays with replicated and access-controlled, reliable storage. Evaluation shows that our approach is scalable in terms of the number of users and complies with performance requirements stated to today's social networks. Andreas Disterhöft, Kalman Graffi |
P2P | 2 |
| 2014 | Data aggregation in VANETs a generalized framework for channel load adaptive schemesabstractOne of the main communication challenges in vehicle-to-x communication is scalability. With increasing number of communication nodes the wireless channel must not get congested especially if a large amount of sensor data has to be forwarded over multiple nodes to a data processing application. This challenge can be solved by reducing the data load through data aggregation. This work introduces a framework for data aggregation as a decentralized congestion control mechanism on the application layer. This framework can be used to flexibly design aggregation schemes that adaptively adjust the generated data load depending on the overall channel load. Three basic aggregation schemes with different complexity and resulting data precision were developed within this framework and they are discussed in this paper. Performance evaluations show that the aggregation schemes are able to adapt to given channel load thresholds within seconds and deliver optimal data quality even in traffic jam situations. Josef Jiru, Lars Bremer, Kalman Graffi |
LCN | 3 |
| 2014 | HSkip+: A self-stabilizing overlay network for nodes with heterogeneous bandwidthsabstractIn this paper we present and analyze HSkip+, a self-stabilizing overlay network for nodes with arbitrary heterogeneous bandwidths. HSkip+ has the same topology as the Skip+ graph proposed by Jacob et al. (2009) but its self-stabilization mechanism significantly outperforms the self-stabilization mechanism proposed for Skip+. Also, the nodes are now ordered according to their bandwidths and not according to their identifiers. Various other solutions have already been proposed for overlay networks with heterogeneous bandwidths, but they are not self-stabilizing. In addition to HSkip+ being self-stabilizing, its performance is on par with the best previous bounds on the time and work for joining or leaving a network of peers of logarithmic diameter and degree and arbitrary bandwidths. Also, the dilation and congestion for routing messages is on par with the best previous bounds for such networks, so that HSkip+ combines the advantages of both worlds. Our theoretical investigations are backed by simulations demonstrating that HSkip+ is indeed performing much better than Skip+ and working correctly under high churn rates. Matthias Feldotto, Christian Scheideler, Kalman Graffi |
P2P | 3 |
| 2013 | Symbiotic coupling of P2P and cloud systems: The Wikipedia caseabstractCloud computing offers high availability, dynamic scalability, and elasticity requiring only very little administration. However, this service comes with financial costs. Peer-to-peer systems, in contrast, operate at very low costs but cannot match the quality of service of the cloud. This paper focuses on the case study of Wikipedia and presents an approach to reduce the operational costs of hosting similar websites in the cloud by using a practical peer-to-peer approach. The visitors of the site are joining a Chord overlay, which acts as first cache for article lookups. Simulation results show, that up to 72% of the article lookups in Wikipedia could be answered by other visitors instead of using the cloud. Lars Bremer, Kalman Graffi |
ICC | 2 |
| 2013 | Continuous Gossip-Based Aggregation through Dynamic Information AgingabstractExisting solutions for gossip-based aggregation in peer-to-peer networks use epochs to calculate a global estimation from an initial static set of local values. Once the estimation converges system- wide, a new epoch is started with fresh initial values. Long epochs result in precise estimations based on old measurements and short epochs result in imprecise aggregated estimations. In contrast to this approach, we present in this paper a continuous, epoch-less approach which considers fresh local values in every round of the gossip-based aggregation. By using an approach for dynamic information aging, inaccurate values and values from left peers fade from the aggregation memory. Evaluation shows that the presented approach for continuous information aggregation in peer-to-peer systems monitors the system performance precisely, adapts to changes and is lightweight to operate. Vitaliy Rapp, Kalman Graffi |
ICCCN | 2 |
| 2013 | Hash-Based File Content Identification Using Distributed Systems
York Yannikos, Jonathan Schluessler, Martin Steinebach, Christian Winter 0001, Kalman Graffi |
IFIP Int. Conf. Digital Forensics | 5 |
| 2013 | Bootstrapping skynet: Calibration and autonomic self-control of structured peer-to-peer networksabstractPeer-to-peer systems scale to millions of nodes and provide routing and storage functions with best effort quality. In order to provide a guaranteed quality of the overlay functions, even under strong dynamics in the network with regard to peer capacities, online participation and usage patterns, we propose to calibrate the peer-to-peer overlay and to autonomously learn which qualities can be reached. For that, we simulate the peer-to-peer overlay systematically under a wide range of parameter configurations and use neural networks to learn the effects of the configurations on the quality metrics. Thus, by choosing a specific quality setting by the overlay operator, the network can tune itself to the learned parameter configurations that lead to the desired quality. Evaluation shows that the presented self-calibration succeeds in learning the configuration-quality interdependencies and that peer-to-peer systems can learn and adapt their behavior according to desired quality goals. Timo Klerx, Kalman Graffi |
P2P | 2 |
| 2011 | LifeSocial.KOM: A secure and P2P-based solution for online social networksabstractThe phenomenon of online social networks reaches millions of users in the Internet nowadays. In these, users present themselves, their interests and their social links which they use to interact with other users. We present in this paper LifeSocial.KOM, a p2p-based platform for secure online social networks which provides the functionality of common online social networks in a totally distributed and secure manner. It is plugin-based, thus extendible in its functionality, providing secure communication and access-controlled storage as well as monitored quality of service, addressing the needs of both, users and system providers. The platform operates solely on the resources of the users, eliminating the concentration of crucial operational costs for one provider. In a testbed evaluation, we show the feasibility of the approach and point out the potential of the p2p paradigm in the field of online social networks. Kalman Graffi, Christian Gross 0001, Dominik Stingl, Daniel Hartung, Aleksandra Kovacevic 0001, Ralf Steinmetz |
CCNC | 1 |
| 2011 | PeerfactSim.KOM: A P2P system simulator - Experiences and lessons learnedabstractResearch on peer-to-peer (p2p) and distributed systems needs evaluation tools to predict and observe the behavior of protocols and mechanisms in large scale networks. PeerfactSim.KOM [1] is a simulator for large scale distributed/p2p systems aiming at the evaluation of interdependencies in multi-layered p2p systems. The simulator is written in Java, is event-based and mainly used in p2p research projects. The main development of PeerfactSim.KOM started in 2005 and is driven since 2006 by the project "QuaP2P", which aims at the systematic improvement and benchmarking of p2p systems. Further users of the simulator are working in the project "On-the-fly Computing" aiming at researching p2p-based service oriented architectures. Both projects state severe requirements on the evaluation of multi-layered and large-scale distributed systems. We describe the architecture of PeerfactSim.KOM supporting these requirements in Section II, present the workflow, selected experiences and lessons learned in Section III and conclude the overview in Section IV. Kalman Graffi |
Peer-to-Peer Computing | 1 |
| 2011 | A security framework for wireless mesh networksabstractAbstract The class of Wireless Mesh Networks (WMN) supports an ample set of applications including wireless community networks, radio access networks in rural or metropolitan areas, or wireless backbones for factory/process automation. Guaranteeing security is crucial for within these application scenarios. While contemporary wireless technologies, such as the IEEE 802.16 or the IEEE 802.11s standard, provide the basic protocol mechanisms for mesh networking, they lack in comprehensive security mechanisms. Additionally, novel security features of the above standards such as per‐link encryption break existing security solutions that rely on overhearing of the wireless channel. We close this gap by developing a holistic approach toward securing WMNs with particular focus on the network layer. We perform a threat analysis and then develop solutions (1) guaranteeing the integrity and authenticity of routing messages, (2) to locally and globally detect misbehavior of nodes in forwarding data or routing messages even for settings that do not allow for overhearing the channel, and (3) to dynamically manage reputation of nodes throughout the network. The combination of these building blocks enables to provide for secure, self‐organizing WMNs. As a proof‐of‐concept, we tailor and implement our solutions for the setting of a realistic IEEE 802.16 mesh network; we discuss the protection achieved and assess selected performance trade‐offs for the developed mechanisms. Copyright © 2010 John Wiley & Sons, Ltd. Parag S. Mogre, Kalman Graffi, Matthias Hollick, Ralf Steinmetz |
Wirel. Commun. Mob. Comput. | 2 |
| 2010 | Towards a P2P Cloud: Reliable Resource Reservations in Unreliable P2P SystemsabstractThe peer-to-peer paradigm shows the potential to provide the same functionality and quality like client/server based systems, but with much lower costs. However, the resources, e.g. storage space, CPU power and online time, provided by the peers are unreliable due to churn. In order to enable churn resistant reliable services using the resources in p2p systems, we propose in this paper a distributed mechanism termed P3R3O.KOM. The mechanism allows to reserve, monitor and use resources provided by the unreliable p2p system and maintains long-term resource reservations through controlled redundant resource provision. Evaluation shows that using KAD measurements on the prediction of the lifetime of peers allows for 100% successful reservations under churn with very low traffic overhead. This approach marks a first step for the building of a reliable p2p-based SOA and future p2p-based clouds. Kalman Graffi, Dominik Stingl, Christian Gross 0001, Aleksandra Kovacevic 0001, Ralf Steinmetz |
ICPADS | 1 |
| 2010 | LifeSocial.KOM: A P2P-Based Platform for Secure Online Social NetworksabstractOnline social networks with millions of users are very popular nowadays. They provide a platform for the users to present themselves and to interact with each other. In this paper, we present a totally distributed platform for social online networks based on the p2p paradigm, called LifeSocial.KOM. It provides the same functionality as common online social networks, while distributing the operational load on all participating nodes. LifeSocial.KOM is plugin-based and extendible, provides secure communication and user-based data access control and integrates a monitoring component which allows the users and operators to observe the quality of the distributed system. Kalman Graffi, Christian Gross 0001, Patrick Mukherjee, Aleksandra Kovacevic 0001, Ralf Steinmetz |
Peer-to-Peer Computing | 1 |
| 2009 | Underlay awareness in P2P systems: Techniques and challengesabstractPeer-to-peer (P2P) applications have recently attracted a large number of Internet users. Traditional P2P systems however, suffer from inefficiency due to lack of information from the underlay, i.e. the physical network. Although there is a plethora of research on underlay awareness, this aspect of P2P systems is still not clearly structured. In this paper, we provide a taxonomic survey that outlines the different steps for achieving underlay awareness. The main contribution of this paper is presenting a clear picture of what underlay awareness is and how it can be used to build next generation P2P systems. Impacts of underlay awareness and open research issues are also discussed. Osama Abboud, Aleksandra Kovacevic 0001, Kalman Graffi, Konstantin Pussep, Ralf Steinmetz |
IPDPS | 3 |
| 2009 | Practical security in p2p-based social networksabstractThe peer-to-peer paradigm is used in more and more advanced applications. One of the next areas that promise a success for the p2p paradigm lies in the upcoming trend of social networks. However, several security issues have to be solved in p2p-based social network platforms. We present in this paper a practical solution that establishes a trust infrastructure, enables authenticated and secure communication between users in the social network and provides personalized, fine grained data access control. We implemented our solution in a p2p based platform for social networks and show that the solution is practical and lightweight both in time consumption and traffic overhead. Kalman Graffi, Patrick Mukherjee, Burkhard Menges, Daniel Hartung, Aleksandra Kovacevic 0001, Ralf Steinmetz |
LCN | 1 |
| 2009 | Monitoring and Management of Structured Peer-to-Peer SystemsabstractThe peer-to-peer paradigm shows the potential to provide the same functionality and quality like client/server based systems, but with much lower costs. In order to control the quality of peer-to-peer systems, monitoring and management mechanisms need to be applied. Both tasks are challenging in large-scale networks with autonomous, unreliable nodes. In this paper we present a monitoring and management framework for structured peer-to-peer systems. It captures the live status of a peer-to-peer network in an exhaustive statistical representation. Using principles of autonomic computing, a preset system state is approached through automated system re-configuration in the case that a quality deviation is detected. Evaluation shows that the monitoring is very precise and lightweight and that preset quality goals are reached and kept automatically. Kalman Graffi, Dominik Stingl, Julius Rückert, Aleksandra Kovacevic 0001, Ralf Steinmetz |
Peer-to-Peer Computing | 1 |
| 2008 | SkyEye.KOM: An Information Management Over-Overlay for Getting the Oracle View on Structured P2P SystemsabstractIn order to ease the development and maintenance of more complex P2P applications, which combine multiple P2P functionality (e.g. streaming and dependable storage), we suggest to extend structured P2P systems with a dedicated information management layer. This layer is meant to generate statistics on the whole P2P system and to enable capacity-based peer search, which helps the individual functionality layers in the P2P application to find suitable peers for layer-specific role assignment. We present in this paper SkyEye.KOM, an information management layer applicable on DHTs, which fulfills these desired functionality. SkyEye.KOM builds an over-overlay, which is scalable by leveraging the underlying DHT, easy to deploy as simple add-on to existing DHTs and efficient as it needs O(log N) hops per query and to place peer-specific information network wide accessible. Evaluation shows that SkyEye.KOM has a good query performance and that the costs for maintaining the over-overlay are very low. Kalman Graffi, Aleksandra Kovacevic 0001, Ralf Steinmetz |
ICPADS | 1 |
| 2008 | Towards Benchmarking of Structured Peer-to-Peer Overlays for Network Virtual EnvironmentsabstractNetwork virtual environments (NVE) are an evolving trend combining millions of users in an interactive community. A distributed NVE platform promises to lower the administration costs and to benefit from research done in the peer-to-peer (p2p) domain. In order to reuse existing mature p2p overlays for NVEs, a comparative evaluation has to be done in the same environment (e.g. resources of peers, peer behavior, churn, etc.), using appropriate test cases (scenarios) and observing relevant performance metrics. In this paper we present a benchmarking approach for p2p overlays in the context of NVEs. We define related quality attributes, scenarios, and metrics and use them to evaluate Chord and Kademlia as most popular p2p overlays and assess their suitability to NVE. Aleksandra Kovacevic 0001, Kalman Graffi, Sebastian Kaune, Christof Leng, Ralf Steinmetz |
ICPADS | 2 |
| 2008 | A Distributed Platform for Multimedia CommunitiesabstractOnline community platforms and multimedia content delivery are merging in recent years. Current platforms like Facebook and YouTube are client-server based which result in high administration costs for the provider. In contrast to that peer-to-peer systems offer scalability and low costs, but are limited in their functionality.In this paper we present a framework for peer-to-peer based multimedia online communities. We identified the key challenges for this new application of the peer-to-peer paradigm and built a plugin based, easily extendible and multi-functional framework. Further, we identified distributed linked lists as valuable data structure to implement the user profiles, friend lists, groups, photo albums and more. Our framework aims at providing the functionality of common online community platforms combined with the multimedia delivery capabilities of modern peer-to-peer systems, e.g. direct multimedia delivery and access to a distributed multimedia pool. Kalman Graffi, Sergey Podrajanski, Patrick Mukherjee, Aleksandra Kovacevic 0001, Ralf Steinmetz |
ISM | 1 |
| 2008 | Load balancing for multimedia streaming in heterogeneous peer-to-peer systemsabstractMultimedia streaming of mostly user generated content is an ongoing trend, not only since the upcoming of Last.fm and YouTube. A distributed decentralized multimedia streaming architecture can spread the (traffic) costs to the user nodes, but requires to provide for load balancing and consider the heterogeneity of the participating nodes. We propose a DHT-based information gathering and analyzing architecture which controls the streaming request assignment in the system and thoroughly evaluate it in comparison to a distributed stateless strategy. We evaluated the impact of the key parameters in the allocation function which considers the capabilities of the nodes and their contribution to the system. Identifying the quality-bandwidth tradeoffs of the information gathering system, we show that with our proposed system a 53% better load balancing can be reached and the efficiency of the system is significantly improved. Kalman Graffi, Sebastian Kaune, Konstantin Pussep, Aleksandra Kovacevic 0001, Ralf Steinmetz |
NOSSDAV | 1 |
| 2007 | Detection of Colluding Misbehaving Nodes in Mobile Ad Hoc and Wireless Mesh NetworksabstractUbiquitous network connectivity and mobile communications have recently attracted remarkable attention. Wireless multihop networks such as Mobile Ad hoc Networks or Wireless Mesh Networks have been proposed to cater to the arising needs. Various security challenges persist, esp. because these networks build on the premise of node cooperation. Secure routing protocols and mechanisms to detect routing misbehavior in the direct neighborhood exist; however, collusion of misbehaving nodes has not been adequately addressed yet. We presentLeakDetector, a mechanism to detect colluding malicious nodes in wireless multihop networks. In combination with proactive secure multipath routing algorithms,LeakDetectorenables the calculation of the packet-loss ratio for the individual nodes. We perform an experimental analysis, which shows the excellent detection quality ofLeakDetector. Kalman Graffi, Parag S. Mogre, Matthias Hollick, Ralf Steinmetz |
GLOBECOM | 1 |
| 2007 | ECHoP2P: Emergency call handling over peer-to-peer overlaysabstractThe impact of the peer-to-peer paradigm increases both in research and in industry. Still, serious applications for P2P-based systems are rare. On the other hand, Emergency Call Handling (ECH) is (or will be) a mandatory function for VoIP services. In this paper we investigate international legal and technical requirements of ECH and present ECHoP2P, a solution that fulfills these requirements. Based on Globase.KOM and HiPNOS.KOM, ECHoP2P provides the functionality to determine the closest and (geographically) responsible Emergency Station to a calling peer. Further, Emergency Calls are processed with highest priority in the overlay, so that quality of service guarantees are given. We evaluated ECHoP2P thoroughly and present the quality and costs analysis, identified tradeoffs and effects of optimization parameters. ECHoP2P provides a fully evaluated solution for Emergency Call Handling and for further location-aware applications. Kalman Graffi, Aleksandra Kovacevic 0001, Kyra Wulffert, Ralf Steinmetz |
ICPADS | 1 |
| 2007 | Overlay Bandwidth Management: Scheduling and Active Queue Management of Overlay FlowsabstractPeer-to-peer and mobile networks gained significant attention of both research community and industry. Applying the peer-to-peer paradigm in mobile networks lead to several problems regarding the bandwidth demand of peer-to-peer networks. Time-critical messages are delayed and delivered unacceptably slow. In addition to this, scarce bandwidth is wasted on messages of less priority. Therefore, the focus of this paper is on bandwidth management issues at the overlay layer and how they can be solved. We present HiPNOS.KOM, a priority based scheduling and active queue management system. It guarantees better QoS for higher prioritized messages in upper network layers of peerto- peer systems. Evaluation using the peer-to-peer simulator PeerfactSim.KOM shows that HiPNOS.KOM brings significant improvement in Kademlia in comparison to FIFO and Drop-Tail, strategies that are used nowadays on each peer. User initiated lookups have in Kademlia 24% smaller operation duration when using HiPNOS.KOM. Kalman Graffi, Konstantin Pussep, Sebastian Kaune, Aleksandra Kovacevic 0001, Nicolas Liebau, Ralf Steinmetz |
LCN | 1 |
| 2007 | AntSec, WatchAnt, and AntRep: Innovative Security Mechanisms for Wireless Mesh NetworksabstractWireless mesh networks (WMNs) build on user nodes to form the network's routing infrastructure. In particular, the correct forwarding behaviour of each intermediate node on a multihop path from a source node to a destination node is crucial for the functioning of the mesh network. However, current secure routing solutions and misbehaviour detection mechanisms are not sufficient and are mostly inapplicable in mesh networks based on state-of-the-art wireless technology. In particular, hop- by-hop per-link encryption mechanisms break solutions that are based on the overhearing of the wireless channel, which leads to severe problems in the presence of misbehaving nodes. We present AntSec, WatchAnt, and AntRep, which together address the above security gap. AntSec guarantees integrity and authenticity of routing messages, WatchAnt detects misbehaviour in forwarding data messages as well as routing messages and in addition is able to cope with per-link encryption at the MAC layer. AntRep is a reputation management system and helps take punitive action against misbehaving nodes. AntSec, WatchAnt, and AntRep are well suited for WMNs with a quasi-static network topology. Through a thorough evaluation we show the improved routing performance of AntSec working together with WatchAnt and AntRep. Parag S. Mogre, Kalman Graffi, Matthias Hollick, Ralf Steinmetz |
LCN | 2 |