VLDB 2026 Research / reviewers in the wild / expert
Nik Sultana
dblp:72/3034 · also Nikolai Sultana
· DBLP profile ↗
19ranked-venue papers
10as first author
11since 2021 · last 2025
0000-0002-8166-1200ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 5 first-author · 5 since 2021Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Patchwork: A Traffic Capture and Analysis Platform for Network Experiments on a Federated TestbedabstractToday's federated network testbeds enable experiments of unprecedented scale and detail, but only provide rudimentary primitives to capture an experiment's network traffic.Capturing and analyzing traffic is important for diagnosing and debugging research prototypes and for evaluating research, but today's testbed users divert and duplicate effort to craft custom solutions for their experiments.Building a general, reusable system is made more challenging by the autonomous structure of federated testbeds and by their high capacity links (requiring accelerated processing).This paper describes the design, implementation, and evaluation of Patchwork: a user-provided, open-source, capture and analysis platform that runs on the state-of-the-art FABRIC testbed.Patchwork works both for individual experiments and also for all experiments occurring simultaneously on FABRIC.To attain a general design, Patchwork itself runs as an experiment on FABRIC and did not require modifications to FABRIC.For scalability, Patchwork offloads logic to FPGA NICs on the testbed and uses DPDK.Patchwork has been used by individual FABRIC users and has been running on FABRIC for over a year to produce a testbed-wide analysis of how researchers are collectively using the testbed's network.This paper also presents that analysis and discusses implications for future research on measurement. Nishanth Shyamkumar, Hyunsuk Bang, Bjoern Sagstad, Prajwal Somendyapanahalli Venkateshmurthy, Sean Cummings, Nik Sultana |
IMC | 6 |
| 2025 | Experience Report: Using the FABRIC Testbed to teach a Graduate Computer Networking courseabstractThe curriculum for a graduate Computer Networking course in Computer Science typically includes activities that help students gain a variety of practical skills that complement the theoretical knowledge they learn during the course. These skills are developed through exercises that present students with scenarios in which they are to understand or cause specific communication behavior over a network. These exercises are constrained by the computer resources that students use for learning. Ideally those resources can be tuned to increase the fidelity of the network that a student is managing-and ultimately allow each student to fully control their own network. Alexander Wolosewicz, Prajwal Somendyapanahalli Venkateshmurthy, Nik Sultana |
SIGCSE (1) | 3 |
| 2024 | Shape-shifting Elephants: Multi-modal Transport for Integrated Research InfrastructureabstractData Acquisition (DAQ) workloads form an important class of scientific network traffic that by its nature (1) flows across different research infrastructure, including remote instruments and supercomputer clusters, (2) has ever-increasing throughput demands, and (3) has ever-increasing integration demands---for example, observations at one instrument could trigger a reconfiguration of another instrument. Today's DAQ transfers rely on UDP and (heavily tuned) TCP, but this is driven by convenience rather than suitability. The mismatch between Internet transport protocols and scientific workloads becomes more stark with the steady increase in link capacities, data generation, and integration across research infrastructure. Nik Sultana, Yatish Kumar, Chin Guok, Jim Kowalkowski, Michael Wang 0003 |
HotNets | 1 |
| 2023 | Towards In-Network Semantic Analysis: A Case Study involving Spam ClassificationabstractAnalyzing free-form natural language expressions “in the network”–that is, on programmable switches and smart NICs–would enable packet-handling decisions that are based on the textual content of flows. This analysis would support richer, latency-critical data services that depend on language analysis– such as emergency response, misinformation classification, customer support, and query-answering applications.But packet forwarding and processing decisions usually rely on simple analyses based on table look-ups that are keyed on well-defined (and usually fixed size) header fields. P4 is the state of the art domain-specific language for programming network equipment, but, to the best of our knowledge, analyzing freeform text using P4 has not yet been investigated. Although there is an increasing variety of P4-programmab1e commodity network hardware available, using P4 presents considerable technical challenges for text analysis since the language lacks loops and fractional datatypes.This paper presents the first Bayesian spam classifier written in P4 and evaluates it using a standard dataset. The paper contributes techniques for the tokenization, analysis, and classification of free-form text using P4, and investigates trade-offs between classification accuracy and resource usage. It shows how classification accuracy can be tuned between 69.1% and 90.4%, and how resource usage can be reduced to 6% by trading-off accuracy. It uses the spam filtering use-case to motivate the need for more research into in-network text analysis to enable future “semantic analysis” applications in programmable networks. Cyprien Gueyraud, Nik Sultana |
NOMS | 2 |
| 2022 | Towards Practical Application-level Support for Privilege SeparationabstractPrivilege separation (privsep) is an effective technique for improving software’s security, but privsep involves decomposing software into components and assigning them different privileges. This is often laborious and error-prone. This paper contributes the following for applying privsep to C software: (1) a portable, lightweight, and distributed runtime library that abstracts externally-enforced compartment isolation; (2) an abstract compartmentalization model of software for reasoning about privsep; and (3) a privsep-aware Clang-based tool for code analysis and semi-automatic software transformation to use the runtime library. The evaluation spans 19 compartmentalizations of third-party software and examines: Security: 4 CVEs in widely-used software were rendered unexploitable; Approximate Effort Saving: on average, the synthesis-to-annotation code ratio was greater than 11.9 (i.e., 10 × lines of code were generated for each annotation); and Overhead: execution-time overhead was less than 2%, and memory overhead was linear in the number of compartments. Nik Sultana, Henry Zhu, Ke Zhong, Zhilei Zheng, Ruijie Mao, Digvijaysinh Chauhan, Stephen Carrasquillo, Junyong Zhao, Lei Shi 0011, Nikos Vasilakis, Boon Thau Loo |
ACSAC | 1 |
| 2022 | Work in Progress paper: Experiment Planning for Heterogeneous Programmable NetworksabstractPrivate and publicly-funded cloud infrastructure and testbeds increasingly feature programmable network hardware. Programmable network cards and switches support the execution of increasingly-complex in-network programs that can operate independently of end-hosts to improve the network’s performance, resilience and utilisation. Reasoning about in-network programs, their placement, and workloads is needed to plan jobs on programmable networks. On programmable testbed networks, this reasoning feeds into resource allocation, fairness and reproducible research. But this reasoning is made challenging by the performance and resource diversity of hardware and by the failure modes that can arise in a distributed system.Flightplanner is currently the most comprehensive reasoning system for distributed and heterogeneous in-network programs but it uses a custom formalism and tool implementation, making it difficult to understand, extend, and scale.This paper describes Lightplanner, a generalisation of Flight-planner’s reasoning system that has been implemented on Prolog. It provides an executable formalisation in a well-understood logic. By relying on Prolog’s proof search, Lightplanner is 10 smaller than Flightplanner’s implementation in C++, making×it better suited for others to understand, extend, and scale. A benchmark of publicly-available in-network programs is used to evaluate Lightplanner against Flightplanner. Though the time overhead is slightly larger, Lightplanner can find better allocations than the original, more complex C++ implementation.Lightplanner is being incubated to plan experiments in a local programmable network testbed at Illinois Tech, and as a future step it will be extended to work across federated networks such as FABRIC. Nik Sultana |
DCOSS | 1 |
| 2022 | A case for remote attestation in programmable dataplanesabstractProgrammability is a double-edged sword. It can better tailor solutions to problems, optimize resource use, and inexpensively patch deployed equipment. But programmability can also be abused to undermine the security of hardware and that of its unwitting users. Remote Attestation (RA) is a class of techniques to provide integrity assurance to remote users of resources such as hardware, OSs and applications. It is used to establish well-defined trust relationships among mutually distrustful principals who provide, use or delegate remote resources. RA could benefit, for example, tenants of a data-center or users of IoT equipment such as health monitors. Nik Sultana, Deborah Shands, Vinod Yegneswaran |
HotNets | 1 |
| 2022 | Demo: The Hangar environment for Teaching and Research in Programmable NetworkingabstractThis demo presents Hangar, a VM-based environment that grew out of components that evolved over the last few years to support research and teaching into programmable networking. In addition to showing Hangar, the demo will discuss use-cases and requirements that were encountered when developing Hangar and its predecessors. Hangar is designed to provide an environment that is easy to update and use. It includes fully-scripted VM generation, packages frequently-used tools and minimizes dependencies, and provides a suite of examples. Nik Sultana |
ICNP | 1 |
| 2021 | Demo: Disaggregated DataplanesabstractModern programmable network hardware enables in-network computing-pushing increasingly-complex logic into the network to improve the performance, flexibility and reliability of network services. But the current network programming paradigm is constrained to programming a single network device at a time. The lack of support for in-network programs that use several and heterogeneous network hardware simultaneously constrains the scale and behaviour of in-network programs. Dataplane Disaggregation is a new paradigm that addresses this problem. It distributes computations across programmable network hardware including switches and smart NICs. This paradigm transforms a monolithic in-network program into a distributed system executing on possibly heterogeneous resources. The goal of this demo is to make an accessible presentation of Dataplane Disaggregation to the wider distributed systems community. This is intended to stimulate discussion on effective ways to program distributed and heterogeneous systems. Our demo is based on the Flightplan system prototype. Flightplan is open-source and comes with detailed documentation and support scripts, yet it requires some effort to set up and run. This impedes its study by others. Our demo runs completely in the browser and does not burden viewers with any installation effort at all. The technical contribution of this demo consists of a customised visualisation of Flightplan experiments. Moreover, the demo is well-suited to virtual events—as is being planned for ICDCS'21—since it can be run independently and asynchronously by viewers of the demo. This is especially helpful for viewers with slow or intermittent Internet connections. We make the demo's source code freely available online for use by others, including researchers who want to build similar demos. Heena Nagda, Rakesh Nagda, Nik Sultana, Boon Thau Loo |
ICDCS | 3 |
| 2021 | Flightplan: Dataplane Disaggregation and Placement for P4 Programs
Nik Sultana, John Sonchack, Hans Giesen, Isaac Pedisich, Nishanth Shyamkumar, Shivani Burad, André DeHon, Boon Thau Loo |
NSDI | 1 |
| 2021 | FDP: A Teaching and Demonstration Platform for NetworkingabstractRequesting https://www.wikipedia.org from your browser can start a small storm of exchanges between your device and name servers, caches and ultimately the Wikipedia servers. Data networking involves simple ideas---such as modular decomposition and path redundancy---that produce interesting behavior through the, sometimes subtle, interaction with one another. Through this interaction, networking is able to achieve amazing feats of reliability, availability, and planetary scale. But it is difficult to connect the big ideas---such as reliability---with how they work across different implementations, topologies and in the face of different levels of network disfunction. Making that leap typically requires time spent with unforgiving tools such as 'tcpdump' across several experiments. This is not helped by the hearty alphabet soup that is the set of protocols that one has to learn to begin to understand how networking really works. Heena Nagda, Rakesh Nagda, Swapneel Sheth, Nik Sultana, Boon Thau Loo |
SIGCSE | 4 |
| 2020 | FDP: a teaching and demo platform for SDNabstractThere are a wealth of good-quality open-source tools for teaching, learning about, and experimenting with P4-based SDN. But this tooling and its mode of distribution is geared towards usage at the level of "nuts and bolts", requiring effort to setup even for casual or inexperienced users, and does not give "big picture" insight into the network as the system executes. Our poster describes FDP, a portable platform that builds on existing tooling to enable end-to-end experimentation and zero-effort in-browser interactive visualization, which we envision can benefit teaching of P4-based SDN and research demonstration. Heena Nagda, Rakesh Nagda, Isaac Pedisich, Nik Sultana, Boon Thau Loo |
CoNEXT | 4 |
| 2019 | Trace-based Behaviour Analysis of Network ServersabstractAnalysing software and networks can be done using established tools, such as debuggers and packet analysers, but using established tools to analyse network software is difficult and impractical because of the sheer detail the tools present and the performance overheads they typically impose. This makes it difficult to precisely diagnose performance anomalies in network software to identify their causes (is it a DoS attack or a bug?) and determine what needs to be fixed.We present Flowdar: a practical tool for analysing software traces to produce intuitive summaries of network software behaviour by abstracting unimportant details and demultiplexing traces into different sessions' subtraces. Flowdar can use existing state-of-the-art tracing tools for lower overhead during trace gathering for offline analysis. Using Flowdar we can drill down when diagnosing performance anomalies without getting overwhelmed in detail or burdening the system being observed.We show that Flowdar can be applied to existing real-world software and can digest complex behaviour into an intuitive visualisation. Nik Sultana, Achala Rao, Zihao Jin, Pardis Pashakhanloo, Henry Zhu, Vinod Yegneswaran, Boon Thau Loo |
CNSM | 1 |
| 2019 | Hashtray: Turning the tables on Scalable Client Classification
Nik Sultana, Pardis Pashakhanloo, Zihao Jin, Achala Rao, Boon Thau Loo |
IM | 1 |
| 2017 | Emu: Rapid Prototyping of Networking Services
Nik Sultana, Salvator Galea, David Greaves, Marcin Wójcik, Jonny Shipton, Richard G. Clegg, Luo Mai, Pietro Bressana, Robert Soulé, Richard Mortier, Paolo Costa, Peter R. Pietzuch, Jon Crowcroft, Andrew W. Moore 0002, Noa Zilberman |
USENIX ATC | 1 |
| 2016 | FLICK: Developing and Running Application-Specific Network Services
Abdul Alim, Richard G. Clegg, Luo Mai, Lukas Rupprecht, Eric Seckler, Paolo Costa, Peter R. Pietzuch, Alexander L. Wolf, Nik Sultana, Jon Crowcroft, Anil Madhavapeddy, Andrew W. Moore 0002, Richard Mortier, Masoud Koleini, Luis Oviedo, Matteo Migliavacca, Derek McAuley |
USENIX ATC | 9 |
| 2015 | The Higher-Order Prover Leo-IIabstractLeo-II is an automated theorem prover for classical higher-order logic. The prover has pioneered cooperative higher-order-first-order proof automation, it has influenced the development of the TPTP THF infrastructure for higher-order logic, and it has been applied in a wide array of problems. Leo-II may also be called in proof assistants as an external aid tool to save user effort. For this it is crucial that Leo-II returns proof information in a standardised syntax, so that these proofs can eventually be transformed and verified within proof assistants. Recent progress in this direction is reported for the Isabelle/HOL system. Christoph Benzmüller, Nik Sultana, Lawrence C. Paulson, Frank Theiss |
J. Autom. Reason. | 2 |
| 2012 | Foundations of Logic-Based Trust ManagementabstractOver the last 15 years, many policy languages have been developed for specifying policies and credentials under the trust management paradigm. What has been missing is a formal semantics - in particular, one that would capture the inherently dynamic nature of trust management, where access decisions are based on the local policy in conjunction with varying sets of dynamically submitted credentials. The goal of this paper is to rest trust management on a solid formal foundation. To this end, we present a model theory that is based on Kripke structures for counterfactual logic. The semantics enjoys compositionality and full abstraction with respect to a natural notion of observational equivalence between trust management policies. Furthermore, we present a corresponding Hilbert-style axiomatization that is expressive enough for reasoning about a system's observables on the object level. We describe an implementation of a mechanization of the proof theory, which can be used to prove non-trivial meta-theorems about trust management systems, as well as analyze probing attacks on such systems. Our benchmark results show that this logic-based approach performs significantly better than the only previously available, ad-hoc analysis method for probing attacks. Moritz Y. Becker, Alessandra Russo, Nik Sultana |
IEEE Symposium on Security and Privacy | 3 |
| 2008 | Mechanical verification of refactoringsabstractIn this paper we describe the formal verification of refactorings for untyped and typed lambda-calculi. This verification is performed in the proof assistant Isabelle/HOL. Nik Sultana, Simon J. Thompson |
PEPM | 1 |