VLDB 2026 Research / reviewers in the wild / expert
Jun Bi
dblp:79/3662
· DBLP profile ↗
128ranked-venue papers
9as first author
11since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 102 · 4 first-authorSystems, architecture and hardware · 10 · 2 first-author · 7 since 2021Security and privacy · 5Software engineering, systems software and programming languages · 5 · 2 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | QiMeng-Tensify: Scaling Up Tensor Computation Optimization via Architecture-Aware LLM-Guided MCTS
Shouyang Dong, Jun Bi, Yuanbo Wen 0001, Xiyue Yu, Jianxing Xu, Guanglin Xu, Ling Li 0001, Xuehai Zhou, Tianshi Chen 0002, Qi Guo 0001 |
ISCA | 2 |
| 2026 | FlashAttention-T: Towards Fully Tensorized Attention by Exploiting Tensor-Vector ParallelismabstractThe attention mechanism is central to modern deep learning, particularly in large language models (LLMs), but suffers from quadratic computational complexity. To accelerate attention computation on GPUs, fused attention techniques (e.g., FlashAttention) consolidate the matrix multiplication (GEMM) and softmax computations into a single kernel. However, these operations remain computationally decoupled: the GEMM leverages high-performance tensor units (Tensor Cores), while the softmax executes on slower vector units (CUDA cores). This imbalance induces severe vector intervals—periods where tensor units sit idle awaiting vector unit completion—significantly underutilizing tensor units. Furthermore, ongoing hardware advancements delivering faster tensor units exacerbate this bottleneck. Jianxing Xu, Yuanbo Wen 0001, Jun Bi, Ruibai Xu, Guanglin Xu, Rui Zhang 0040, Wei Li 0008, Ling Li 0001, Tianshi Chen 0002, Qi Guo 0001, Yunji Chen |
PPoPP | 3 |
| 2025 | Mosaic: Exploiting Instruction-Level Parallelism on Deep Learning Accelerators with iTex TessellationabstractDeep learning has achieved great success in numerous application areas at the cost of high computational complexity. To meet the ever-increasing computational demand, commodity hardware platforms (e.g., CPUs and GPUs) offer abundant computing resources including scalar, vector, and tensor units for deep learning that could execute in parallel. However, existing top-down tiling-based deep learning compilers often generate a homogeneous mapping from the given tensor computation task to hardware arithmetic instructions, failing to utilize different computing units simultaneously to achieve higher performance. Jianxing Xu, Yuanbo Wen 0001, Ruibai Xu, Tingfeng Ruan, Jun Bi, Rui Zhang 0040, Xinkai Song, Yifan Hao 0001, Xing Hu 0001, Zidong Du, Chongqing Zhao, Jiang Jie, Qi Guo 0001 |
ASPLOS (2) | 6 |
| 2025 | QiMeng-NeuComBack: Self-Evolving Translation from IR to Assembly CodeabstractCompilers, while essential, are notoriously complex systems that demand prohibitively expensive human expertise to develop and maintain. The recent advancements in Large Language Models (LLMs) offer a compelling new paradigm: Neural Compilation, which could potentially simplify compiler development for new architectures and facilitate the discovery of innovative optimization techniques. However, several critical obstacles impede its practical adoption. Firstly, a significant lack of dedicated benchmarks and robust evaluation methodologies hinders objective assessment and tracking of progress in the field. Secondly, systematically enhancing the reliability and performance of LLM-generated assembly remains a critical challenge. Addressing these challenges, this paper introduces NeuComBack, a novel benchmark dataset specifically designed for IR-to-assembly compilation. Leveraging this dataset, we first define a foundational Neural Compilation workflow and conduct a comprehensive evaluation of the capabilities of recent frontier LLMs on Neural Compilation, establishing new performance baselines. We further propose a self-evolving prompt optimization method that enables LLMs to iteratively evolve their internal prompt strategies by extracting insights from prior self-debugging traces, thereby enhancing their neural compilation capabilities.
Experiments demonstrate that our method significantly improves both the functional correctness and the performance of LLM-generated assembly code. Compared to baseline prompts, the functional correctness rates improved from 44% to 64% on x86_64 and from 36% to 58% on aarch64, respectively. More significantly, among the 16 correctly generated x86_64 programs using our method, 14 (87.5%) surpassed clang-O3 performance. These consistent improvements across diverse architectures (x86_64 and aarch64) and program distributions (NeuComBack L1 and L2) validate our method's superiority over conventional approaches and its potential for broader adoption in low-level neural compilation. Hainan Fang, Yuanbo Wen 0001, Jun Bi, Tonghui He, Yanlin Tang, Jiaming Guo, Rui Zhang 0040, Qi Guo 0001, Yunji Chen |
NeurIPS | 3 |
| 2025 | QiMeng-Xpiler: Transcompiling Tensor Programs for Deep Learning Systems with a Neural-Symbolic Approach
Shouyang Dong, Jun Bi, Jiaming Guo, Jianxing Xu, Ruibai Xu, Xinkai Song, Yifan Hao 0001, Ling Li 0001, Xuehai Zhou, Tianshi Chen 0002, Qi Guo 0001, Yunji Chen |
OSDI | 2 |
| 2025 | Efficient and Fast High-Performance Library Generation for Deep Learning AcceleratorsabstractThe widespread adoption of deep learning accelerators (DLAs) underscores their pivotal role in improving the performance and energy efficiency of neural networks. To fully leverage the capabilities of these accelerators, exploration-based library generation approaches have been widely used to substantially reduce software development overhead. However, these approaches have been challenged by issues related to sub-optimal optimization results and excessive optimization overheads. In this paper, we proposeHeronto generate high-performance libraries of DLAs in an efficient and fast way. The key is automatically enforcing massive constraints through the entire program generation process and guiding the exploration with an accurate pre-trained cost model.Heronrepresents the search space as a constrained satisfaction problem (CSP) and explores the space via evolving the CSPs. Thus, the sophisticated constraints of the search space are strictly preserved during the entire exploration process. The exploration algorithm has the flexibility to engage in space exploration using either online-trained models or pre-trained models. Experimental results demonstrate thatHeronaveragely achieves 2.71$\times$speedup over three state-of-the-art automatic generation approaches. Also, compared to vendor-provided hand-tuned libraries,Heronachieves a 2.00$\times$speedup on average. When employing a pre-trained model,Heronachieves 11.6$\times$compilation time speedup, incurring a minor impact on execution time. Jun Bi, Yuanbo Wen 0001, Xiaqing Li, Yongwei Zhao 0001, Enshuai Zhou, Xing Hu 0001, Zidong Du, Ling Li 0001, Huaping Chen 0001, Tianshi Chen 0002, Qi Guo 0001 |
IEEE Trans. Computers | 1 |
| 2023 | Heron: Automatically Constrained High-Performance Library Generation for Deep Learning AcceleratorsabstractDeep Learning Accelerators (DLAs) are effective to improve both performance and energy efficiency of compute-intensive deep learning algorithms. A flexible and portable mean to exploit DLAs is using high-performance software libraries with well-established APIs, which are typically either manually implemented or automatically generated by exploration-based compilation approaches. Though exploration-based approaches significantly reduce programming efforts, they fail to find optimal or near-optimal programs from a large but low-quality search space because the massive inherent constraints of DLAs cannot be accurately characterized. Jun Bi, Qi Guo 0001, Xiaqing Li, Yongwei Zhao 0001, Yuanbo Wen 0001, Enshuai Zhou, Xing Hu 0001, Zidong Du, Ling Li 0001, Huaping Chen 0001, Tianshi Chen 0002 |
ASPLOS (3) | 1 |
| 2023 | BALTO: fast tensor program optimization with diversity-based active learning
Jun Bi, Xiaqing Li, Qi Guo 0001, Rui Zhang 0040, Yuanbo Wen 0001, Xing Hu 0001, Zidong Du, Xinkai Song, Yifan Hao 0001, Yunji Chen |
ICLR | 1 |
| 2023 | Lifecycle Cost Optimization for Electric Bus Systems With Different Charging Methods: Collaborative Optimization of Infrastructure Procurement and Fleet SchedulingabstractBattery electric buses (BEBs) have been regarded as effective options for sustainable mobility while their promotion is highly affected by the total cost associated with their entire life cycle from the perspective of urban transit agencies. In this research, we develop a collaborative optimization model for the lifecycle cost of BEB system, considering both overnight and opportunity charging methods. This model aims to jointly optimize the initial capital cost and use-phase operating cost by synchronously planning the infrastructure procurement and fleet scheduling. In particular, several practical factors, such as charging pattern effect, battery downsizing benefits, and time-of-use dynamic electricity price, are considered to improve the applicability of the model. A hybrid heuristic based on the tabu search and immune genetic algorithm is customized to effectively solve the model that is reformulated as the bi-level optimization problem. A numerical case study is presented to demonstrate the model and solution method. The results indicate that the proposed optimization model can help to reduce the lifecycle cost by 7.77% and 6.64% for overnight and opportunity charging systems, respectively, compared to the conventional management strategy. Additionally, a series of simulations for sensitivity analysis are conducted to further evaluate the key parameters and compare their respective life cycle performance. The policy implications for BEB promotion are also discussed. Chaoru Lu, Jun Bi, Qiuyue Sai, Xiaobo Qu 0002 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2022 | NetEC: Accelerating Erasure Coding Reconstruction With In-Network AggregationabstractIn distributed storage systems, Erasure Coding (EC) is a crucial technology to enable high data availability. By downloading parity data from survived machines, EC can reconstruct lost data with much lower storage overheads than data replication. However, this reduction in storage cost comes at the expense of extra performance problems:low reconstruction rate,high degraded read latency, andhigh host CPU utilization. Our analysis shows that these performance problems are deeply rooted in thehost-basedEC processing. To resolve these problems, we present NetEC, an in-network accelerating framework that fully offloads EC to the new generation programmable switching ASICs. We propose Explicit Buffer Size Notification (EBSN) to constrain decoding buffer usage, and design an on-switch one-to-many TCP proxy to integrate EBSN with TCP. We also design two parallel Galois Field (GF) offloading methods—table lookup and bitmatrix methods—to maximize parsable bytes. We implement NetEC on programmable switches and integrate it with HDFS. Extensive evaluations show that NetEC improves the reconstruction rate by 2.7x-6.8x, reduces the degraded read latency significantly, and removes the host CPU overhead completely. We also emulate multi-rack scenarios and show that NetEC is able to support$\sim$∼GB/s reconstruction rate and tens of concurrent tasks. Yi Qiao, Menghao Zhang 0001, Yu Zhou 0008, Han Zhang 0009, Mingwei Xu 0001, Jun Bi, Jilong Wang 0001 |
IEEE Trans. Parallel Distributed Syst. | 7 |
| 2021 | Octans: Optimal Placement of Service Function Chains in Many-Core SystemsabstractNetwork Function Virtualization (NFV) offers service delivery flexibility and reduces overall costs by running service function chains (SFCs) on commodity servers with many cores. Existing solutions for placing SFCs in one server treat all CPU cores as equal and allocate isolated CPU cores to network functions (NFs). However, advanced servers often adopt Non-Uniform Memory Access (NUMA) architecture to improve the scalability of many-core systems. CPU cores are grouped into nodes, incurring performance degradation due to cross-node memory access and intra-node resource contention. Our evaluation shows that randomly selecting cores to place NFs in an SFC could suffer from 39.2 percent lower throughput comparing to an optimal placement solution. In this article, we propose Octans, an NFV orchestrator to achieve maximum aggregate throughput of all SFCs in many-core systems. Octans first formulates the optimization problem as a Non-Linear Integer Programming (NLIP) Model. Then we identify the key factor for problem solving as evaluating the throughput drop of an NF caused by other NFs in the same SFC or different SFCs, i.e., performance drop index, and propose a formal and accurate prediction model based on system level performance metrics. Finally, we propose two online algorithms to quickly find near-optimal placement solutions for one-time and incremental deployment. Extensive evaluation on a prototype implementation shows that Octans significantly improves the aggregate throughput comparing to two state-of-the-art placement solutions by 27.1 ~ 45.2 percent for one-time deployment and by 20.9 ~ 38.1 percent for incremental deployment, with very low prediction errors. Moreover, Octans could quickly find a near-optimal placement solution with tiny optimality gap. Heng Yu 0005, Zhilong Zheng, Junxian Shen, Congcong Miao, Chen Sun 0005, Hongxin Hu, Jun Bi, Jilong Wang 0001 |
IEEE Trans. Parallel Distributed Syst. | 7 |
| 2020 | NetView: Towards On-Demand Network-Wide Telemetry in the Data CenterabstractNetwork telemetry is to collect information (e.g., hop latency, throughput) from network devices. Network-wide telemetry is critical for operators to understand the quality of network performance and to diagnose on-going failures. The state-of-the-art telemetry approaches are far from ideal as they are unable to fully satisfy diverse requirements of operators, specifically for on-demand, full coverage, and scalable telemetry. In this paper, we provide a new framework of network telemetry for data center networks, called NetView. NetView can support various telemetry applications and frequencies on demand, monitoring each device via proactively sending dedicated probes. Technically, NetView leverages source routing to forward probes, achieving full coverage. Besides, a series of probe generation algorithms largely reduce probe number, providing high scalability. The evaluation shows that NetView reduces the bandwidth occupancy by more than two orders of magnitude compared with Pingmesh and INT-path, and conducts network-wide telemetry for large-scale data center network using only one vantage server, without bringing about resources bottleneck. Yunsenxiao Lin, Yu Zhou 0008, Zhengzheng Liu, Yangyang Wang 0001, Mingwei Xu 0001, Jun Bi, Ying Liu 0024 |
ICC | 7 |
| 2020 | SmartChain: Enabling High-Performance Service Chain Partition between SmartNIC and CPUabstractSmart Network Interface Cards (SmartNICs) have been widely used to accelerate software-based network functions (NFs). However, from the scope of a service chain, a careless selection of NFs to offload onto SmartNIC could severely degrade the performance due to frequent communications between CPU and SmartNIC. In this paper, we present SmartChain, a high performance and efficient framework that achieves optimal partition of service chains between SmartNIC and CPU. SmartChain consists of two logical steps. First, SmartChain analyzes the suitability of elements in a chain to run on SmartNIC to exploit its high performance. Besides, SmartChain also ensures the dependencies between elements. Second, as our key novelty, SmartChain models the service chain latency and resource constraints, and solves the partition problem with 0-1 integer linear programming. We implement a SmartChain prototype based on Netronome SmartNIC. Evaluation results show that when used in real world cases, SmartChain could reduce the service chain latency by up to 87% with throughput maintained compared with strawman solutions. Shuhe Wang, Zili Meng, Chen Sun 0005, Minhu Wang, Mingwei Xu 0001, Jun Bi, Tong Yang 0003, Qun Huang 0001, Hongxin Hu |
ICC | 6 |
| 2020 | Martini: Bridging the Gap between Network Measurement and Control Using Switching ASICsabstractAdvanced network management systems, including network measurement and traffic control, rely on a remote controller to make control decisions. However, this approach incurs a long control loop of a few seconds to minutes. Even if we switch to switch-local controller, the latency is still tens of milliseconds and is unacceptable for many latency-sensitive tasks. In this paper, we propose Martini, a general framework that supports measurement-based timely control. The key idea is to perform measurement, control decision, and control entirely in the switch data plane. This could shorten the control loop of management tasks that require timely control based on only locally measured statistics in the switch. First, Martini introduces a set of primitives to describe management tasks. Next, Martini provides an innovative network-wide task placement mechanism to exploit resources of all switches to accommodate massive management tasks. Finally, Martini provides a code library and a compiler to support measurement and control on a state-of-the-art switching ASIC. Evaluation results show that Martini can effectively support a wide range of fine-timescale management tasks such as microburst detection and fast load balancing by reducing the control loop from seconds to nanoseconds. Shuhe Wang, Chen Sun 0005, Zili Meng, Minhu Wang, Jiamin Cao, Mingwei Xu 0001, Jun Bi, Qun Huang 0001, Masoud Moshref, Tong Yang 0003, Hongxin Hu, Gong Zhang 0001 |
ICNP | 7 |
| 2020 | FlexMesh: Flexibly Chaining Network Functions on Programmable Data Planes at Runtime
Yu Zhou 0008, Jun Bi, Cheng Zhang 0012, Mingwei Xu 0001, Jinaping Wu |
Networking | 2 |
| 2020 | NetView: Towards on-demand network-wide telemetry in the data center
Yunsenxiao Lin, Yu Zhou 0008, Zhengzheng Liu, Yangyang Wang 0001, Mingwei Xu 0001, Jun Bi, Ying Liu 0024 |
Comput. Networks | 7 |
| 2020 | VMS: Load Balancing Based on the Virtual Switch Layer in Datacenter NetworksabstractThere have been many load balancing solutions for datacenter networks. Almost all of them require modifications to the network fabric or/and virtual machines. Recently, the virtual switch layer becomes an ideal location for datacenter operators to deal with the load balancing problem. In this paper, we propose Virtual Multi-channel Scatter (VMS), a packet-level load balancing design in the virtual switch layer. VMS scatters packets in one TCP flow to several different forwarding paths (channels). VMS has several noteworthy properties. First, VMS is low cost and transparent to tenants. It can be deployed when the datacenter operators do not attempt to change the network fabric or cannot control the transport protocol inside VMs. Second, by employing window-based channel selection, VMS is adaptive to network congestion and topology asymmetry. Third, VMS works well with Generic Segmentation Offload/Generic Receive Offload (GRO/GSO) mechanism in the Linux kernel, unlike other packet-level load balancing schemes. Finally, VMS can also be offloaded to SmartNIC to reduce CPU overhead further. Our evaluations show that VMS achieves comparable performance to the ideal packet-level scheme in normal cases and well handles topology asymmetries, while only modifies the virtual switch layer. In the symmetric topology, VMS achieves up to 47% and 22% better flow completion time (FCT) than Equal Cost MultiPath (ECMP) and the best-of-breed flowlet-level CONGA. When there is topology asymmetry, VMS outperforms the ideal packet-level scheme and CONGA by up to $3.0\times $ and $1.4\times $ respectively. Further, the overhead of VMS is tolerable. Jun Bi, Zhaogeng Li, Yu Zhou 0008, Yangyang Wang 0001 |
IEEE J. Sel. Areas Commun. | 2 |
| 2020 | HyperSight: Towards Scalable, High-Coverage, and Dynamic Network Monitoring QueriesabstractPerforming fine-grained and real-time network monitoring is the core logic of various data center operation applications, such as traffic engineering, network troubleshooting, and anomaly detecting. However, the state-of-the-art network monitoring solutions either fall short of completely detecting all network incidents (i.e., congestion), yielding limited monitoring coverage, or introduce large overheads, yielding limited scalability. In this paper, we present HyperSight, a network traffic monitor with both high coverage and low overheads. The key idea of HyperSight is to monitor networks at the behavior level via tracking packet behavior changes. HyperSight proposes three designs for behavior-level monitoring. First, to facilitate expressing various network monitoring tasks, HyperSight presents a declarative query language based on the streaming processing model. Second, HyperSight proposes Bloom Filter Queue (BFQ), a memory-efficient algorithm to empower in-network capability for monitoring packet behavior changes. BFQ can be implemented on commodity programmable switches. Third, to support dynamic deployment and execution of packet behavior change monitoring tasks without interrupting on-service switches, HyperSight proposes virtual BFQ to support dynamic query compilation. We build a prototype of HyperSight and deploy it on commodity programmable switches. Evaluation results show that HyperSight supports a wide range of network event queries and can monitor over 99% packet behavior changes while keeping remarkably low overheads. Yu Zhou 0008, Jun Bi, Tong Yang 0003, Kai Gao 0001, Jiamin Cao, Yangyang Wang 0001, Cheng Zhang 0012 |
IEEE J. Sel. Areas Commun. | 2 |
| 2020 | Prophet: Toward Fast, Error-Tolerant Model-Based Throughput Prediction for Reactive Flows in DC NetworksabstractAs modern network applications (e.g., large data analytics) become more distributed and can conduct application-layer traffic adaptation, they demand better network visibility to better orchestrate their data flows. As a result, the ability to predict the available bandwidth for a set of flows has become a fundamental requirement of today's networking systems. While there are previous studies addressing the case of non-reactive flows, the prediction for reactive flows, e.g., flows managed by TCP congestion control algorithms, still remains an open problem. In this paper, we take the first step to solving this problem in a data center network. To address both theoretical and practical challenges, we introduce a novel learning-based prediction system based on the NUM model, with two key techniques named fast factor learning (FFL) and efficient flow sampling. We adopt novel techniques to overcome practical concerns such as scalability, convergence and unknown system parameters. A system, Prophet, is proposed leveraging the emerging technologies of Software Defined Networking (SDN) to realize the model. Evaluations demonstrate that our solution achieves significant accuracy in a wide range of settings. Kai Gao 0001, Yang Richard Yang, Jun Bi |
IEEE/ACM Trans. Netw. | 4 |
| 2019 | Bubble: Lightweight Core Sharing in NFVabstractMany researches have revealed the requirement of enabling multiple network functions (NFs) to share a CPU core in Network Function Virtualization (NFV) to support fine-grained NF models, efficient resource utilization, and chain consolidation. However, these works usually enable core sharing via kernel-level threads, which incurs significant performance degradation. In this paper, we present Bubble to enable lightweight core sharing in NFV. Bubble leverages user-level threads to eliminate the performance overhead introduced by kernel-level thread scheduling. Bubble is designed to satisfy unique requirements in NFV by providing accurate and low-overhead scheduling, in support of on- demand resource allocation, and accurate NF load measurement. Evaluations over a Bubble prototype implementation demonstrate that Bubble can improve the performance by 1.6Ã- to 6.2Ã- for co-located NFs and by 3.7Ã- to 68.8Ã- for a consolidated Service Function Chain (SFC) in a core against two state- of-the-art solutions. Haiping Wang 0002, Zhilong Zheng, Chen Sun 0005, Jun Bi |
GLOBECOM | 4 |
| 2019 | CoFilter: A High-Performance Switch-Accelerated Stateful Packet Filter for Bare-Metal ServersabstractAs one of the most critical cloud services, Bare-metal Servers introduce stringent performance requirements on data center networks (DCN). Stateful packet filter is an integral DCN component of ensuring connection security for bare-metal servers. However, the off-the-shelf hardware-based and software-based stateful packet filters either are prohibitively costly for cloud DCNs or introduce significant performance bottlenecks. In this paper, we present CoFilter, which employs cheap programmable switches to accelerate the stateful packet filter for bare-metal servers. CoFilter consists of two key designs. First, to support complex stateful packet filtering logic in programmability-limited switching ASICs, CoFilter partitions the stateful packet filtering logic between programmable ASICs and switch CPU. Most packets are directly processed in switching ASICs to achieve high performance, while only a small number of packets go to switch CPU for connection tracking. Second, to track massive connections with constrained hardware memory, CoFilter employs hash to compress connection states and provides an efficient settlement for hash collisions. We build a prototype of CoFilter and evaluate it on the Tofino switch under various data center traffic traces with real-world flow distribution. The evaluation shows that CoFilter largely outperforms NetFilter, i.e., forwarding packets at line rate (13x throughput of NetFilter), keeping packet delay at 1us, and freeing a significant quantity of CPU cores. Furthermore, CoFilter presents great scalability and accommodates over ten million connections with only 16MB SRAM. Jiamin Cao, Ying Liu 0024, Yu Zhou 0008, Chen Sun 0005, Yangyang Wang 0001, Jun Bi |
ICCCN | 6 |
| 2019 | A Generic Technique for Sketches to Adapt to Different Counting RangesabstractSketch is a compact data structure for network measurements. To achieve fast speed, it needs to be held in the on-chip memory (SRAM), which is very small. To enable the sketch fit into the on-chip memory, the product of counter size and number of counters must be below a certain limit. If we use small counters, e.g., 8 bits, some counters will overflow. If we use large counters, e.g., 16 bits per counter, the total number of counters will be small, each counter will be shared by more flows, leading to poor accuracy. To address this issue, we propose a generic technique: self-adaptive counters (SA Counter). When the value of the counter is small, it works as a normal counter. When the value of the counter is large, we increment it using a predefined probability, so as to represent a large value. Moreover, in SA Counter, the probability decreases when the value increases. This technique can significantly improve the accuracy of sketches. To verify the effectiveness of SA Counter, we apply SA Counter to three typical sketches, and conduct extensive experiments on one real dataset and one synthetic dataset. Experimental results show that, compared with the state-of-the-art, sketches using SA Counter improve the accuracy by up to 13.6 times. Tong Yang 0003, Xilai Liu, Peng Liu 0047, Lun Wang 0001, Jun Bi, Xiaoming Li 0001 |
INFOCOM | 6 |
| 2019 | Octans: Optimal Placement of Service Function Chains in Many-Core SystemsabstractNetwork Function Virtualization (NFV) has the potential to offer service delivery flexibility and reduce overall costs by running service function chains (SFCs) on commodity servers with many cores. Existing solutions for placing SFCs in one server treat all CPU cores as equal and allocate isolated CPU cores to different network functions (NFs). However, advanced servers often adopt Non-Uniform Memory Access (NUMA) architecture to improve the scalability of many-core systems. CPU cores are grouped into nodes, incurring performance bottleneck due to cross-node memory access and intra-node resource contention. Our evaluation shows that randomly selecting cores to place NFs in an SFC could suffer from 39.2% lower throughput comparing to an optimal placement solution. In this paper, we propose Octans, an NFV orchestrator to achieve maximum aggregate throughput of all SFCs in many-core systems. Octans first formulates the optimization problem as a Non-Linear Integer Programming (NLIP) model. Then we identify the key factor for problem solving as evaluating the throughput drop of an NF caused by other NFs in the same SFC or different SFCs, i.e. performance drop index, and propose a formal and precise prediction model based on system level performance metrics. Finally, we propose an efficient heuristic algorithm to quickly find near-optimal placement solutions. We have implemented a prototype of Octans. Extensive evaluation shows that Octans significantly improves the aggregate throughput comparing to two state-of the-art placement mechanisms by 26.7%~51.8%, with very low prediction errors of SFC performance (an average deviation of 2.6%). Moreover, Octans could quickly find a near-optimal placement solution with tiny optimality gap (1.2%~3.5%). Zhilong Zheng, Jun Bi, Heng Yu 0005, Haiping Wang 0002, Chen Sun 0005, Hongxin Hu |
INFOCOM | 2 |
| 2019 | P4Tester: efficient runtime rule fault detection for programmable data planesabstractP4 and programmable data planes bring significant flexibility to network operation but are inevitably prone to various faults. Some faults, like P4 program bugs, can be verified statically, while some faults, like runtime rule faults, only happen to running network devices, and they are hardly possible to handle before deployment. Existing network testing systems can troubleshoot runtime rule faults via injecting probes, but are insufficient for programmable data planes due to large overheads or limited fault coverage. In this paper, we propose P4Tester, a new network testing system for troubleshooting runtime rule faults on programmable data planes. First, P4Tester proposes a new intermediate representation based on Binary Decision Diagram, which enables efficient probe generation for various P4-defined data plane functions. Second, P4Tester offers a new probe model that uses source routing to forward probes. This probe model largely reduces rule fault detection overheads, i.e. requiring only one server to generate probes for large networks and minimizing the number of probes. Moreover, this probe model can test all table rules in a network, achieving full fault coverage. Evaluation based on real-world data sets indicates that P4Tester can efficiently check all rules in programmable data planes, generate 59% fewer probes than ATPG and Pronto, be faster than ATPG by two orders of magnitude, and troubleshoot multiple rule faults within one second on BMv2 and Tofino. Yu Zhou 0008, Jun Bi, Yunsenxiao Lin, Yangyang Wang 0001, Zhaowei Xi, Jiamin Cao, Chen Sun 0005 |
IWQoS | 2 |
| 2019 | VNE-TD: A virtual network embedding algorithm based on temporal-difference learning
Jun Bi, Athanasios V. Vasilakos, Qilin Fan |
Comput. Networks | 2 |
| 2019 | MicroNF: An Efficient Framework for Enabling Modularized Service Chains in NFVabstractThe modularization of service function chains (SFCs) in network function virtualization (NFV) could introduce significant performance overhead and resource efficiency degradation due to introducing frequent packet transfer and consuming much more hardware resources. In response, we exploit the reusability, lightweightness, and individual scalability features of elements in modularized SFCs (MSFCs) and propose MicroNF, an efficient framework for MSFC in NFV. MicroNF addresses the performance overhead and resource efficiency problems in three ways. First, MicroNF graph constructor reuses the processing results of elements from different NFs and reconstructs the MSFC after modularization to shorten the chain latency. Second, optimized placer pays attention to the problem of which elements to consolidate and provides a performance-aware placement algorithm to place MSFCs compactly and optimize the global packet transfer cost. Third, MicroNF individual scaler innovatively introduces a push-aside scaling up strategy to avoid degrading performance and taking up new CPU cores. To support MSFC reusing and consolidation, MicroNF also designs a high-performance infrastructure to efficiently forwarding packets with consistency ensured and to automatically scheduling elements with fairness ensured when the elements are consolidated on the CPU core. Our evaluation results show that MicroNF achieves significant performance improvement and efficient resource utilization on several metrics. Zili Meng, Jun Bi, Haiping Wang 0002, Chen Sun 0005, Hongxin Hu |
IEEE J. Sel. Areas Commun. | 2 |
| 2019 | Tripod: Towards a Scalable, Efficient and Resilient Cloud GatewayabstractCloud gateways are fundamental components of a cloud platform, where various network functions (e.g., L4/L7 load balancing, network address translation, stateful firewall, and SYN proxy) are deployed to process millions of connections and billions of packets. Providing high-performance and failure-resilient packet processing with a scalable traffic management mechanism is crucial to ensuring the quality of service of a cloud provider, and hence is of great importance. Many network functions nowadays are implemented in software with commodity servers for low cost and high flexibility. However, existing software-based network function frameworks oftentimes provide part of these features, while cannot satisfy all three requirements above simultaneously. To address these issues, in this paper, we introduce TRIPOD, a novel network function framework specialized for cloud gateways. Having identified the fundamental limitations of loosely coupling traffic, processing logic and state, TRIPOD jointly manages these three elements with the unique characteristics of cloud gateways, which is enabled by a simple, efficient traffic processing mechanism, and a high performance state management service. Adopting several effective techniques and optimizations, TRIPOD is able to achieve scalable traffic management (<;100 flow rules for even ~Tbps traffic), high performance (reducing 40% of latency compared with state of the art) and failure resilience (similar packet/connection loss rate compared to state of the art), with reasonable overheads (less than 10% of the workload traffic) even under an extremely heavy traffic, making it a good fit for cloud gateways. Menghao Zhang 0001, Jun Bi, Kai Gao 0001, Yi Qiao, Zhaogeng Li, Hongxin Hu |
IEEE J. Sel. Areas Commun. | 2 |
| 2019 | HyperVDP: High-Performance Virtualization of the Programmable Data PlaneabstractWith the advent of P4-specific programmable data plane (PDP), network functions (NFs) can be offloaded into the PDP to achieve high performance guaranteed by hardware. Meanwhile, CPU powers consumed by NFs can be released to user applications. However, as more and more NFs can be offloaded, several problems rooted inside the PDP severely hinder it from facilitating this offloading trend. 1) The existing PDP provides the exclusive data plane abstraction where different NFs cannot operate the same data plane. 2) The PDP is hardly able to deploy NFs in a “hitless” manner. In this paper, we propose HyperVDP as a high-performance data plane hypervisor to provision non-exclusive abstraction and uninterrupted reconfigurability on the P4-specific PDP. To achieve virtualization, we design several innovative techniques to equally express functions of all programmable elements in the P4-specific PDP. We implement the prototype of HyperVDP on different target platforms, and evaluate different target-based prototypes by comparing with their counterparts. Results show that BMv2-target HyperVDP averagely prevails over its counterpart 2.5× in performance and 4× in resource efficiency. DPDK-target HyperVDP performs comparably to its counterparts while offering virtualization features which neither of its counterparts could provide. Cheng Zhang 0012, Jun Bi, Yu Zhou 0008 |
IEEE J. Sel. Areas Commun. | 2 |
| 2019 | An Objective-Driven On-Demand Network Abstraction for Adaptive ApplicationsabstractRevealing an abstract view of the network is essential for the new paradigm of developing network-aware adaptive applications that can fully leverage the available computation and storage resources and achieve better business values. In this paper, we introduce ONV, a novel abstraction of flow-based on-demand network view. The ONV models network views as linear constraints on network-related variables in application-layer objective functions, and provides “equivalent” network views that allow applications to achieve the same optimal objectives as if they have the global information. We prove the lower bound for the number of links contained in an equivalent network view, and propose two algorithms to effectively calculate on-demand equivalent network views. We evaluate the efficacy and the efficiency of our algorithms extensively with real-world topologies. Evaluations demonstrate that the ONV can simplify the network up to 80% while maintaining an equivalent view of the network. Even for a large network with more than 25 000 links and a request containing 3000 flows, the result can be effectively computed in less than 1 min on a commodity server. Kai Gao 0001, Qiao Xiang, Xin Wang 0036, Yang Richard Yang, Jun Bi |
IEEE/ACM Trans. Netw. | 5 |
| 2019 | P4DB: On-the-Fly Debugging for Programmable Data PlanesabstractWhile extending network programmability to a more considerable extent, P4 raises the difficulty of detecting and locating bugs, e.g., P4 program bugs and missed table rules, in runtime. These runtime bugs, without prompt disposal, can ruin the functionality and performance of networks. Unfortunately, the absence of efficient debugging tools makes runtime bug troubleshooting intricate for operators. This paper is devoted to on-the-fly debugging of runtime bugs for programmable data planes. We propose P4DB, a general debugging platform that empowers operators to debug P4 programs in three levels of visibility with rich primitives. By P4DB, operators can use the watch primitive to quickly narrow the debugging scope from the network level or the device level to the table level, then use the break and next primitives to decompose match-action tables and finely locate bugs. We implement a prototype of P4DB and evaluate the prototype on two widely-used P4 targets. On the software target, P4DB merely introduces a small throughput penalty (1.3% to 13.8%) and a little delay increase (0.6% to 11.9%). Notably, P4DB almost introduces no performance overhead on Tofino, the hardware P4 target. Yu Zhou 0008, Jun Bi, Cheng Zhang 0012, Bingyang Liu, Zhaogeng Li, Yangyang Wang 0001, Mingli Yu |
IEEE/ACM Trans. Netw. | 2 |
| 2018 | GEN: A GPU-Accelerated Elastic Framework for NFVabstractNetwork Function Virtualization (NFV) has the potential to enhance service delivery flexibility and reduce overall costs by provisioning software-based service function chains (SFCs) on commodity hardware. However, we observe that existing CPU-based SFC solutions cannot achieve both high performance and high elasticity simultaneously. To address such a critical challenge, we seek beyond CPU and exploit the capability of Graphics Processing Unit (GPU) to support NFV. We propose GEN, a GPU-based high performance and elastic framework for NFV. As opposed to pipeline-based SFCs in existing GPU-based NFV systems, GEN proposes to support RTC-based SFCs to improve processing performance. Meanwhile, GEN offers great elasticity of network function (NF) scaling up and down by allocating a different number of fine-grained GPU threads to an NF during runtime. We have implemented a prototype of GEN. Preliminary evaluation results demonstrate that GEN improves performance with RTC-based SFCs, and supports adaptive, precise, and fast NF scaling for NFV. Zhilong Zheng, Jun Bi, Chen Sun 0005, Heng Yu 0005, Hongxin Hu, Zili Meng, Shuhe Wang, Kai Gao 0001 |
APNet | 2 |
| 2018 | CoCo: Compact and Optimized Consolidation of Modularized Service Function Chains in NFVabstractThe modularization of Service Function Chains (SFCs) in Network Function Virtualization (NFV) could introduce significant performance overhead and resource efficiency degradation due to introducing frequent packet transfer and consuming much more hardware resources. In response, we exploit the lightweight and individually scalable features of elements in Modularized SFCs (MSFCs) and propose CoCo, a compact and optimized consolidation framework for MSFC in NFV. CoCo addresses the above problems in two ways. First, CoCo Optimized Placer pays attention to the problem of which elements to consolidate and provides a performance-aware placement algorithm to place MSFCs compactly and optimize the global packet transfer cost. Second, CoCo Individual Scaler innovatively introduces a push-aside scaling up strategy to avoid degrading performance and taking up new CPU cores. To support MSFC consolidation, CoCo also provides an automatic runtime scheduler to ensure fairness when elements are consolidated on CPU core. Our evaluation results show that CoCo achieves significant performance improvement and efficient resource utilization. Zili Meng, Jun Bi, Haiping Wang 0002, Chen Sun 0005, Hongxin Hu |
ICC | 2 |
| 2018 | USTR: A High-Performance Traffic Engineering Approach for the Failed LinkabstractTraffic Engineering for Failure Recovery (TEFR) optimizes the rerouted traffic during network failure. Using Linear Program (LP) to solve this optimization problem is too computationally intensive. Thus, we propose a novel Universal Single-link Traffic Rerouting (USTR) approach based on the maximum flow method. Having the same level of optimality as LP, USTR has a lower time complexity by orders of magnitude than LP, so that all the links in network can be protected. Since it is the first time to use maximum flow method to solve the traffic rerouting problem, we rigorously prove the correctness and the complexity of USTR. We evaluate USTR on real network topologies with thousands of links and nodes, and the running time is quite acceptable. Specifically, we use SDN to implement a prototype of USTR on the OpenDaylight (ODL) controller which works in OpenFlow, MPLS and IP networks. Anmin Xu, Jun Bi, Baobao Zhang, Tianran Xu |
ICDCS | 2 |
| 2018 | NetVision: Towards Network Telemetry as a ServiceabstractIn-band Network Telemetry (INT) can provide fine-grained and accurate device-level telemetry metrics. Nonetheless, INT can track only a small ratio of devices and links and embedding telemetry data into normal packets brings high overhead and high operation complexity. Hence, we present NetVision, a powerful proactive network telemetry platform with high coverage and high scalability. Zhengzheng Liu, Jun Bi, Yu Zhou 0008, Yangyang Wang 0001, Yunsenxiao Lin |
ICNP | 2 |
| 2018 | Grus: Enabling Latency SLOs for GPU-Accelerated NFV SystemsabstractGraphics Processing Unit (GPU) has been recently exploited as a hardware accelerator to improve the performance of Network Function Virtualization (NFV). However, GPU-accelerated NFV systems suffer from significant latency variation when multiple network functions (NFs) are co-located in the same machine, which prevents operators from supporting latency Service Level Objectives (SLOs). Existing research efforts to address this problem can only guarantee a limited number of SLOs with very low resource utilization efficiency. In this paper, we present the Grus framework to support latency SLOs in GPU-accelerated NFV systems. Grus thoroughly analyzes the sources of latency variation and proposes three design principles: (1) dynamic batch size setting is needed to bound packet batching latency in CPU; (2) a reordering mechanism for data transfer over PCI-E is required to guarantee the stalling time; and (3) maximizing concurrency in GPU is necessary to avoid NF execution waiting time. Guided by the principles, Grus consists of two logical layers including an infrastructure layer and a scheduling layer. The infrastructure layer is equipped with an in-CPU Reorder-able Worker Pool that could adjust batching size and packet transfer order, and in-GPU Controllable Concurrent Executors to provide maximized concurrency. The scheduling layer runs a heuristic algorithm to perform accurate and fast scheduling to guarantee SLOs based on our prediction models. We have implemented a prototype of Grus. Extensive evaluations demonstrate that Grus can significantly reduce latency variation and satisfy 4.5 × more SLO terms than state-of-the-art solutions. Zhilong Zheng, Jun Bi, Haiping Wang 0002, Chen Sun 0005, Heng Yu 0005, Hongxin Hu, Kai Gao 0001 |
ICNP | 2 |
| 2018 | KeySight: Troubleshooting Programmable Switches via Scalable High-Coverage Behavior TrackingabstractThe rise of programmable switches and P4 brings much flexibility to networks, but this flexibility comes with increased risks of bugs. Diagnosing these bugs is essential for network operation but is non-trivial. A potential approach is to track packet behaviors through postcards, but existing tools either generate substantial postcards (limited scalability) or only track a small proportion of packet behaviors (low coverage). In this paper, we present KeySight, a platform that troubleshoots programmable switches with high scalability and high coverage. The key idea is based on the Packet Equivalence Class (PEC) abstraction that aggregates packets with identical behaviors and generates one postcard per behavior. The PEC abstraction minimizes the number of postcards while tracking all packet behaviors. We design novel algorithms to analyze PECs of P4 programs and to implement the PEC abstraction on programmable switches. We deploy KeySight on Tofino and SmartNIC, and evaluate it against 80 P4 programs and real packet traces of over 5TB. Results show that in the premise of overseeing over 99.9% packet behaviors, KeySight reduces the number of postcards by one to two orders of magnitude when comparing with NetSight. Yu Zhou 0008, Jun Bi, Tong Yang 0003, Kai Gao 0001, Cheng Zhang 0012, Jiamin Cao, Yangyang Wang 0001 |
ICNP | 2 |
| 2018 | Prophet: Fast Accurate Model-Based Throughput Prediction for Reactive Flow in DC NetworksabstractAs modern network applications (e.g., large data analytics) become more distributed and can conduct application-layer traffic adaptation, they demand better network visibility to better orchestrate their data flows. As a result, the ability to predict the available bandwidth for a set of flows has become a fundamental requirement of today's networking systems. While there are previous studies addressing the case of non-reactive flows, the prediction for reactive flows, e.g., flows managed by TCP congestion control algorithms, still remains an open problem. In this paper, we identify three challenges in providing throughput prediction for reactive flows: throughput dynamics, heterogeneous reactive control mechanisms, and source-constrained flows. Based on a previous theoretical model, we introduce a novel learning-based prediction system with a key component named fast factor learning (FFL) model. We adopt novel techniques to overcome practical concerns such as scalability, convergence and unknown system parameters. A system, Prophet, is proposed leveraging the emerging technologies of Software Defined Networking (SDN) to realize the model. Evaluations demonstrate that our solution achieves significant accuracy in a wide range of settings. Kai Gao 0001, Yang Richard Yang, Jun Bi |
INFOCOM | 4 |
| 2018 | B-Cache: A Behavior-Level Caching Framework for the Programmable Data PlaneabstractBy enabling operators to program behaviors of the packet processing pipeline, P4, a domain-specific language, unleashes new opportunities for offloading network functions onto the programmable data plane (PDP) and enhancing network performance. However, recent research shows that as P4 programs and the corresponding packet processing pipeline grow in size and complexity, the performance of the PDP will decrease significantly, which compromises the programmability and flexibility brought by P4. To overcome this performance degradation, we propose B-Cache, a general behavior-level caching framework for both stateful and stateless behaviors on the PDP. The basic idea of B-Cache is to compile packet processing behaviors that were once distributed across multiple tables into one synthetic cache table, thus guarantee the performance on various P4 targets. Our experiment results indicate that B-Cache comparably yields significant performance benefits including a 49% delay decrease and a 200% throughput increase on the software target, and a 60% throughput increase on the hardware target. Cheng Zhang 0012, Jun Bi, Yu Zhou 0008, Keyao Zhang, Zijun Ma |
ISCC | 2 |
| 2018 | OFM: Optimized Flow Migration for NFV Elasticity ControlabstractNetwork Function Virtualization (NFV) together with Software Defined Networking (SDN) offers the potential for enhancing service delivery flexibility and reducing overall costs. Based on the capability of dynamic creation and destruction of network function (NF) instances, NFV provides great elasticity in NF control, such as NF scaling out, scaling in, load balancing, etc. To realize NFV elasticity control, network traffic flows need to be redistributed across NF instances. However, deciding which flows are suitable for migration is a critical problem for efficient NFV elasticity control. In this paper, we propose to build an innovative flow migration controller, OFM Controller, to achieve optimized flow migration for NFV elasticity control. We identify the trigger conditions and control goals for different situations, and carefully design models and algorithms to address three major challenges including buffer overflow avoidance, migration cost calculation, and effective flow selection for migration. We implement the OFM Controller on top of NFV and SDN environments. Our evaluation results show that OFM Controller is efficient to support optimized flow migration in NFV elasticity control. Chen Sun 0005, Jun Bi, Zili Meng, Hongxin Hu |
IWQoS | 2 |
| 2018 | Control Plane Reflection Attacks in SDNs: New Attacks and Countermeasures
Menghao Zhang 0001, Lei Xu 0024, Jun Bi, Guofei Gu, Jiasong Bai |
RAID | 4 |
| 2018 | Enabling NFV Elasticity Control With Optimized Flow MigrationabstractNetwork function virtualization (NFV) together with software defined networking (SDN) offers the potential for enhancing service delivery flexibility and reducing overall costs. Based on the capability of dynamic creation and destruction of network function (NF) instances, NFV provides great elasticity in NF control, such as NF scaling out, scaling in, and load balancing. To realize NFV elasticity control, network traffic flows need to be redistributed across NF instances. However, deciding which flows are suitable for migration is a critical problem for efficient NFV elasticity control. In this paper, we propose to build an innovative flow migration controller, OFM controller, to achieve optimized flow migration for NFV elasticity control. We identify the trigger conditions and control goals for different situations, and carefully design models and algorithms to address three major challenges including buffer overflow avoidance, migration cost calculation, and effective flow selection for migration. We implement the OFM controller on top of NFV and SDN environments. Our evaluation results show that OFM controller is efficient to support optimized flow migration in NFV elasticity control. Chen Sun 0005, Jun Bi, Zili Meng, Tong Yang 0003, Hongxin Hu |
IEEE J. Sel. Areas Commun. | 2 |
| 2017 | HyperV: A High Performance Hypervisor for Virtualization of the Programmable Data PlaneabstractP4 is a domain specific language designed to define the behavior of a programmable data plane. It facilitates offloading hardware-suitable Network Functions (NFs) to a data plane. Consequently, NFs can maximally benefit from high performance of hardware devices, meanwhile more CPU power can be reserved for user applications. However, since the programmable data plane provides an NF with an exclusive network context, different NFs cannot operate on the same data plane simultaneously. Besides, it is hardly possible to dynamically reconfigure programmable network devices without interrupting the operation of a data plane. Therefore, we propose HyperV, a high performance hypervisor for virtualization of a P4 specific data plane, to provide both non-exclusive and uninterrupted features.We implemented HyperV based on a P4-BMv2 target and a DPDK target respectively. Then we evaluated BMv2-target HyperV by comparing with Hyper4, a recently proposed hypervisor, and evaluated DPDK- target HyperV by comparing with PISCES and Open vSwitch. Results show that BMv2- target HyperV averagely prevails over Hyper4 2.5x in performance while reducing resource usage by 4x. DPDK-target HyperV performs comparably to Open vSwitch and PISCES, with the worst case of a throughput penalty in less than 7\%, while providing a powerful capability of virtualization which neither of them provides. Cheng Zhang 0012, Jun Bi, Yu Zhou 0008, Abdul Basit Dogar |
ICCCN | 2 |
| 2017 | VMS: Traffic balancing based on virtual switches in datacenter networksabstractThere have been many traffic balancing solutions for datacenter networks. All of them require modifications to the network fabric or/and virtual machines. In this paper, we propose Virtual Multi-channel Scatter (VMS), a new traffic balancing solution in datacenter networks. VMS works in the virtual switches between the network fabric and virtual machines. It can be deployed by datacenter operators at a relatively low cost without extra restrictions to virtual machine users. VMS scatters packets in one TCP flow to several different forwarding paths. It employs an adaptive path selection based on the virtual window size of different paths. We implemented VMS based on OVS. Our evaluation demonstrates that VMS improves traffic balancing very well, and the performance of VMS is approximate to MPTCP in almost all the cases, while only modifies virtual switches. Further, the overhead of VMS is tolerable. Zhaogeng Li, Jun Bi, Abdul Basit Dogar, Chengwei Qin |
ICNP | 2 |
| 2017 | P4DB: On-the-fly debugging of the programmable data planeabstractWhile extending network programmability to a larger degree, P4 also raises the risks of incurring runtime bugs after the deployment of P4 programs. These runtime bugs, if not handled promptly and properly, can ruin the functionality and performance of networks. Unfortunately, the absence of runtime debuggers makes troubleshooting of P4 program bugs challenging and intricate for operators. This paper is devoted to the on-the-fly debugging of runtime bugs in P4-enabled networks. We propose P4DB, a general debugging platform that empowers operators to debug P4 programs in three levels of visibility by provisioning operator-friendly primitives. By P4DB, operators can use the watch primitive to quickly narrow the debugging scope from network level or device level to table level, then use the break and next primitives to decompose the match-action table into three steps and troubleshoot the runtime bugs step by step. We implemented a prototype of P4DB and evaluated the performance in terms of the data plane, control plane and control channel. On P4-specific programmable data plane, P4DB merely introduces a small throughput penalty (1.3%~13.8%) and imposes a little-increased delay (0.6%~11.9%). Cheng Zhang 0012, Jun Bi, Yu Zhou 0008, Bingyang Liu, Zhaogeng Li, Abdul Basit Dogar, Yangyang Wang 0001 |
ICNP | 2 |
| 2017 | EAalo: Enhanced coflow scheduling without prior knowledge in a datacenter networkabstractCoflow scheduling without prior knowledge has been proposed recently. However, the previous solution, Aalo, has two problems: it does not explicitly control the flow rate; it assumes the network is ideally non-blocking (with perfect traffic balancing and no oversubscription). In this paper, we show the performance loss caused by the above two problems. We propose EAalo to cope with the problems. It has three enhancements to Aalo: per-flow bandwidth enforcement, centralized traffic balancing and oversubscription adaption. We evaluate EAalo with simulations. The simulation results show that EAalo has much better performance than Aalo. It can speed up coflow completion by up to 11%, 17% and 19% in non-blocking networks, networks without oversubscription and networks with 2:1 oversubscription respectively. Zhaogeng Li, Jun Bi |
ISCC | 2 |
| 2017 | NOVA: Towards on-demand equivalent network view abstraction for network optimizationabstractAs many applications today migrate to distributed computing and cloud platforms, their user experience depends heavily on network performance. Software Defined Networking (SDN) makes it possible to obtain a global view of the network, introducing the new paradigm of developing adaptive applications with network views. A naive approach of realizing the paradigm, such as distributing the whole network view to applications, is not practical due to scalability and privacy concerns. Existing approaches providing network abstractions are limited to special cases, such as bottlenecks exist only at networks edges, resulting in potentially suboptimal or infeasible decisions. In this paper, we introduce a novel, on-demand network abstraction service that provides an abstract network view supporting not only accurate end-to-end QoS metrics, which satisfy the requirements of many peer-to-peer applications, but also multi-flow correlation, which is essential for bandwidth-sensitive applications containing many flows to conduct global network optimization. We prove that our abstract view is equivalent to the original network view, in the sense that applications can make the same optimal decision as with the complete information. Our evaluations demonstrate that the abstraction guarantees feasibility and optimality for network optimizations and protects the network service providers' privacy. Our evaluations also show that the service can be implemented efficiently; for example, for an extreme large network with 30,000 links and abstraction requests containing 3,000 flows, an abstract network view can be computed in less than one second. Kai Gao 0001, Qiao Xiang, Xin Wang 0036, Yang Richard Yang, Jun Bi |
IWQoS | 5 |
| 2017 | Failure Inference for shortening traffic DetoursabstractTo speed up the recovery from network failures, an extensive list of methods have been proposed. Many failurerecovery methods are proposed based on tunneling or marking, which increase the packet processing burden on routers and consume extra bandwidth. With neither tunneling nor marking, existing methods guarantee recovery from any singlelink failure if a detour for the failed link exists, but they generate long traffic detours that will degrade the network performance, and even increase the operational cost, which is undesirable to network operators. Therefore, in this paper, we propose a Failure Inference approach to shortening Traffic Detours named as FITD, which works in OSPF/IS-IS networks. FITD does not use explicit failure notification, and can infer which link fails based on traffic information. FITD guarantees recovery from any single-link failure if a detour for the failed link exists. In particular, for networks with symmetric link weights, FITD guarantees to generate shortest detours for any single-link failure. Anmin Xu, Jun Bi, Baobao Zhang, Shuhe Wang |
IWQoS | 2 |
| 2017 | NFP: Enabling Network Function Parallelism in NFVabstractSoftware-based sequential service chains in Network Function Virtualization (NFV) could introduce significant performance overhead. Current acceleration efforts for NFV mainly target on optimizing each component of the sequential service chain. However, based on the statistics from real world enterprise networks, we observe that 53.8% network function (NF) pairs can work in parallel. In particular, 41.5% NF pairs can be parallelized without causing extra resource overhead. In this paper, we present NFP, a high performance framework, that innovatively enables network function parallelism to improve NFV performance. NFP consists of three logical components. First, NFP provides a policy specification scheme for operators to intuitively describe sequential or parallel NF chaining intents. Second, NFP orchestrator intelligently identifies NF dependency and automatically compiles the policies into high performance service graphs. Third, NFP infrastructure performs light-weight packet copying, distributed parallel packet delivery, and load-balanced merging of packet copies to support NF parallelism. We implement an NFP prototype based on DPDK in Linux containers. Our evaluation results show that NFP achieves significant latency reduction for real world service chains. Chen Sun 0005, Jun Bi, Zhilong Zheng, Heng Yu 0005, Hongxin Hu |
SIGCOMM | 2 |
| 2017 | A tool for tracing network data plane via SDN/OpenFlow
Yangyang Wang 0001, Jun Bi, Keyao Zhang |
Sci. China Inf. Sci. | 2 |
| 2017 | HYPER: A Hybrid High-Performance Framework for Network Function VirtualizationabstractNetwork function virtualization (NFV) offers the potential for both enhancing service delivery flexibility and reducing overall costs by virtualizing network functions that are traditionally implemented in dedicated hardware. However, the flexibility of NFV comes with considerable compromises since virtual machine carried functions could introduce significant performance overhead. In this paper, we present a novel high-performance framework called HYPER, which combines programmable hardware infrastructure and traditional software infrastructure in NFV to achieve both high performance and flexibility for supporting virtualized network functions (VNFs). In HYPER, we design a mediator layer to hide underlying infrastructure heterogeneity from the NFV orchestrator to simplify VNF management. In addition, we design a SLA-aware service chaining algorithm in HYPER to leverage the benefits of the hybrid infrastructure to fulfill both functional and performance requirements from service subscribers (or tenants). To optimize resource utilization efficiency, we also introduce a performance-aware VNF placement algorithm in HYPER, which accommodates both resource and performance requirements in placing VNFs. We implement HYPER in a testbed based on OpenStack and ONetCard. Experimental results show that HYPER reduces the forwarding latency of a service chain by 40% to 67% compared with data plane development kit -based implementation, while maintaining the flexibility of VNF management. Chen Sun 0005, Jun Bi, Zhilong Zheng, Hongxin Hu |
IEEE J. Sel. Areas Commun. | 2 |
| 2017 | A SDN-Based Framework for Fine-Grained Inter-domain Routing Diversity
Yangyang Wang 0001, Jun Bi, Keyao Zhang |
Mob. Networks Appl. | 2 |
| 2017 | Security of Cached Content in NDNabstractIn Named-Data Networking (NDN), content is cached in network nodes and served for future requests. This property of NDN allows attackers to inject poisoned content into the network and isolate users from valid content sources. Since a digital signature is embedded in every piece of content in NDN architecture, poisoned content is discarded if routers perform signature verification; however, if every content is verified by every router, it would be overly expensive to do. In our preliminary work, we have suggested a content verification scheme that minimizes unnecessary verification and favors already verified content in the content store, which reduces the verification overhead by as much as 90% without failing to detect every piece of poisoned content. Under this scheme, however, routers are vulnerable to verification attack, in which a large amount of unverified content is accessed to exhaust system resources. In this paper, we carefully look at the possible concerns of our preliminary work, including verification attack, and present a simple but effective solution. The proposed solution mitigates the weakness of our preliminary work and allows this paper to be deployed for real-world applications. Dohyung Kim 0005, Jun Bi, Athanasios V. Vasilakos, Ikjun Yeom |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | SDPA: Toward a Stateful Data Plane in Software-Defined NetworkingabstractAs the prevailing technique of software-defined networking (SDN), open flow introduces significant programmability, granularity, and flexibility for many network applications to effectively manage and process network flows. However, open flow only provides a simple “match-action” paradigm and lacks the functionality of stateful forwarding for the SDN data plane, which limits its ability to support advanced network applications. Heavily relying on SDN controllers for all state maintenance incurs both scalability and performance issues. In this paper, we propose a novel stateful data plane architecture (SDPA) for the SDN data plane. A co-processing unit, forwarding processor (FP), is designed for SDN switches to manage state information through new instructions and state tables. We design and implement an extended open flow protocol to support the communication between the controller and FP. To demonstrate the practicality and feasibility of our approach, we implement both software and hardware prototypes of SDPA switches, and develop a sample network function chain with stateful firewall, domain name system (DNS) reflection defense, and heavy hitter detection applications in one SDPA-based switch. Experimental results show that the SDPA architecture can effectively improve the forwarding efficiency with manageable processing overhead for those applications that need stateful forwarding in SDN-based networks. Chen Sun 0005, Jun Bi, Haoxian Chen 0001, Hongxin Hu, Zhilong Zheng, Shuyong Zhu, Chenghui Wu |
IEEE/ACM Trans. Netw. | 2 |
| 2016 | ORSAP: Abstracting routing state on demandabstractProviding an interface for network applications to access network state, Software-Defined Networking (SDN) northbound API protocol is the foundation for the development of programmable networks with adaptive applications. However, with the growing network scale and applications' need for routing state at multi-domain level, feeding complete routing states to applications would jeopardize their scalability and network providers' privacy. Thus a good routing state abstraction is needed, which must be on-demand so that different applications can receive customized abstract state suiting their needs. Moreover, it must be minimal and equivalent, i.e., containing all the necessary information for applications to make decisions as the complete state does with no redundancy. Current routing state abstractions are not on-demand, and adopt extreme aggregation approaches (e.g., the big switch) to provide a minimal abstraction with the price of severe information loss. For instance, bottleneck links shared between flows are concealed, leading applications to make sub-optimal decisions. In this paper, we design ORSAP, the first on-demand routing state abstraction protocol, through which network applications can describe their demands while Internet service providers can provide the on-demand minimal equivalent routing state accordingly. ORSAP ensures applications' scalability, protects network providers' privacy, and significantly reduces the traffic to disseminate the information. Experiments show that with ORSAP and the abstraction engine we introduced in this paper, one can achieve a state abstraction ratio of up to 60% with an extremely low computation time even with large networks and complex application queries. Kai Gao 0001, Chen Gu, Qiao Xiang, Xin Wang 0036, Yang Richard Yang, Jun Bi |
ICNP | 6 |
| 2016 | NeSMA: Enabling network-level state-aware applications in SDNabstractAs the de facto data plane technique of Software-Defined Networking (SDN), OpenFlow introduces significant programmability to enable innovative network applications. However, the simple OpenFlow data plane only maintains flow-level counters and lacks an efficient mechanism to manage network-level states, which limits its support for advanced state-aware applications. Regularly pulling whole state information from the data plane to the controller might incur untimely response to important network-level states such as CPU exhaustion, switch overload, etc and cause unnecessary traffic. To address above challenges, we introduce a novel Network-level State Management Architecture (NeSMA) to efficiently support advanced network-level state-aware applications by exploiting the opportunity of SDN central control. The data plane could be configured to check state regularly and report to the controller when triggered by state transitions. We design both sequential and parallel composition methods to deal with complex network-level states in NeSMA. To demonstrate the feasibility of our approach, we implement a software prototype of NeSMA, based on which we develop a data-center flow scheduling application. Experimental results show that NeSMA can process network-level states with low network resource consumption and high scalability without compromising packet forwarding efficiency. Chen Sun 0005, Jun Bi, Hongxin Hu, Zhilong Zheng |
ICNP | 2 |
| 2016 | FAST: A Simple Programming Abstraction for Complex State-Dependent SDN ProgrammingabstractHandling state dependencies is a major challenge in modern SDN programming, but existing frameworks do not provide sufficient abstractions nor tools to address this challenge. In this paper, we propose a novel, high-level programming abstraction and implement the *Function Automation SysTem (FAST)*. With the two key features, i.e., *automated state dependency tracking* and *efficient re-execution scheduling*, we demonstrate that FAST substantially simplifies state-dependent SDN programming and boosts the performance. Kai Gao 0001, Chen Gu, Qiao Xiang, Yang Richard Yang, Jun Bi |
SIGCOMM | 5 |
| 2016 | Source Address Validation in Software Defined NetworksabstractIn this paper, we present the preliminary design and implementation of SDN-SAVI, an SDN application that enables SAVI functionalities in SDN networks. In this proposal, all the functionalities are implemented on the controller without modifying SDN switches. To enforce SAVI on packets in the data plane, the controller installs binding tables in switches using existing SDN techniques, such as OpenFlow. With SDN-SAVI, a network administrator can now enforce SAVI in her network by merely integrating a module on the controller, rather than purchasing SAVI-capable switches and replacing legacy ones. Bingyang Liu, Jun Bi, Yu Zhou 0008 |
SIGCOMM | 2 |
| 2016 | SLA-NFV: an SLA-aware High Performance Framework for Network Function VirtualizationabstractWe propose SLA-NFV, a Service Level Agreement (SLA) aware framework, for building high-performance NFV, focusing on fulfilling SLAs of service subscribers (or tenants). SLA-NFV leverages a hybrid infrastructure with both software and programmable hardware to enhance NFV’s capability with respect to various SLAs. Evaluations show that a hybrid service chain could reduce latency by up to 60% compared with a pure soft- ware service chain. Chen Sun 0005, Jun Bi, Zhilong Zheng, Hongxin Hu |
SIGCOMM | 2 |
| 2016 | Software-Defined Mobility Support in IP NetworksabstractA large number of solutions have been proposed to support mobility in IP networks including original Mobile IP, its derivatives and several newly proposed protocols. However, these solutions often show drawbacks in terms of triangle routing, handoff inefficiency, heavy signaling overhead, etc. when handling diversified mobility scenarios. In this paper, we argue that these problems can be addressed by an adaptive mobility solution based on software-defined networks (SDN). We discuss why SDN helps to solve the problems in current IP mobility protocols and give our design and algorithm to demonstrate how they are solved. We show performance benefits of the SDN-based proposal comparing with existing solutions by making evaluations based on real network topologies. We also implement our proposal using Mininet and experiment on it to prove that it is not only theoretically but also practically feasible to realize software defined mobility support in IP networks. You Wang 0004, Jun Bi |
Comput. J. | 2 |
| 2016 | Differentiated forwarding and caching in named-data networking
Yusung Kim 0001, Jun Bi, Ikjun Yeom |
J. Netw. Comput. Appl. | 3 |
| 2016 | CPHR: In-Network Caching for Information-Centric Networking With Partitioning and Hash-RoutingabstractRecently, research on Information-Centric Networking (ICN) has flourished, which attempts to shift from the current host-oriented Internet architecture to an information-oriented one. The built-in caching capability is a typical feature of ICN. In this paper, in order to fully exploit the built-in caching capability of ICN, we propose a collaborative in-network caching scheme with Content-space Partitioning and Hash-Routing, which is named as CPHR. By intelligently partitioning the content space and assigning partitions to caches, CPHR is able to constrain the path stretch incurred by hash-routing. We formulate the problem of assigning partitions to caches into an optimization problem of maximizing the overall hit ratio and propose a heuristic algorithm to solve it. We also formulate the partitioning proportion problem into a min-max linear optimization problem to balance cache workloads. By simulations with both the characteristics of real Internet traffic and traces of peer-to-peer (P2P) traffic, we show the necessity of collaborative caching since the en-route caching mode cannot yield a considerable overall hit ratio with practical cache size. It is shown as well that CPHR can significantly increase the overall hit ratio by up to about 100% with the practical cache policy Least Recently Used (LRU) while the overhead incurred is acceptable in terms of propagation latency and load on links. Jun Bi, Athanasios V. Vasilakos |
IEEE/ACM Trans. Netw. | 2 |
| 2016 | A multi-anchoring approach in mobile IP networksabstractAbstract Many recent mobility solutions, including derivatives of the well‐known Mobile IP as well as emerging protocols employed by future Internet architectures, propose to realize mobility management by distributing anchoring nodes (Home Agents or other indirection agents) over the Internet. One of their main goals is to address triangle routing by optimizing routes between mobile nodes and correspondent nodes. Thus, a key component of such proposals is the algorithm to select proper mobility anchoring nodes for mobile nodes. However, most current solutions adopt a single‐anchoring approach, which means each mobile node attaches to a sole mobility anchor at one time. In this paper, “we argue that the single‐anchoring approach has drawbacks when facing various mobility scenarios. Then, we offer a novel multi‐anchoring approach that allows each mobile node to select an independent mobility anchor for each correspondent node. We show that in most cases our proposal gains more performance benefits with an acceptable additional cost by evaluation based on real network topologies. For the cases that lead to potential high cost, we also provide a lightweight version of our solution which aims to preserve most performance benefits while keeping a lower cost. At last, we demonstrate how our proposal can be integrated into current Mobile IP networks. Copyright © 2017 John Wiley & Sons, Ltd. You Wang 0004, Jun Bi, Xiaoke Jiang |
Wirel. Commun. Mob. Comput. | 2 |
| 2015 | OpenRouteFlow: Enable Legacy Router as a Software-Defined Routing Service for Hybrid SDNabstractHybrid SDN is an important direction for the evolution of SDN. It is one of the challenges to be addressed for hybrid SDN to open the legacy router and enable the routing view as a software defined routing service. In this paper, OpenRouteFlow is presented, which opens legacy routing protocols and flow sampling information as a routing view service for network applications by software update. OpenRouteFlow tries to realize the decoupling of network visualization and network control. It provides path-oriented and traffic-oriented subscription and publication services for different scenarios of network control. In a hybrid network consisted of OpenFlow switches and legacy routers, OpenRouteFlow is able to map OpenFlow control rules into ACL or RIB in order to support flexible software defined capacities in legacy routers. Jun Bi |
ICCCN | 2 |
| 2015 | MLV: A Multi-dimension Routing Information Exchange Mechanism for Inter-domain SDNabstractSoftware Defined Networking (SDN) separates the tightly coupled network control and data forwarding functions. During the past years, it has been applied in all kinds of intra-domain networks, such as enterprise networks, data centers and content provider networks. However, it is a big challenge to extend SDN to inter-domain networks. In this paper, we extend the advantage of SDN to an inter-domain network federation to improve the Internet routing flexibility. To achieve this goal, we propose a Multi-dimension Link Vector network view exchange mechanism (MLV) to exchange the fine-grained inter-domain routing information and enable programmable inter-domain routing. MLV can support flexible inter-domain routing control by exchanging multiple fields of the IP header. Based on MLV, innovations in inter-domain routing can be deployed as applications over SDN controllers. In order to validate the MLV design, we analyzed its performance with BGP-derived Internet AS topology. Finally, we implemented a prototype of MLV and tested it on an internationally collaborative inter-domain SDN testbed. Ze Chen 0006, Jun Bi, Yonghong Fu, Yangyang Wang 0001, Anmin Xu |
ICNP | 2 |
| 2015 | SDPA: Enhancing Stateful Forwarding for Software-Defined NetworkingabstractAs the prevailing technique of Software-Defined Networking (SDN), OpenFlow introduces significant programmability, granularity and flexibility for many network applications to effectively manage and process network flows. However, OpenFlow only provides a simple "match-action" paradigm and lacks the function of stateful forwarding for SDN data plane, which limits it to support advanced network applications. Heavily relying on SDN controllers for all state maintenance incurs both scalability and performance issues. In this paper, we propose a novel Stateful Data Plane Architecture (SDPA) for SDN data plane. A co-processing unit, Forwarding Processor (FP), is designed for SDN switches to manage state information through new instructions and state tables. We design and implement an extended OpenFlow protocol to implement the communication between the controller and FP. To demonstrate the practicality and feasibility of our approach, we implement both software and hardware prototypes of SDPA switches, and develop a sample network function chain with stateful firewall, DNS reflection attack defense and NAT applications in one SDPA-based switch. Experimental results show that the SDPA architecture can effectively improve the forwarding efficiency with manageable processing overhead for those applications that need stateful forwarding in SDN-based networks. Shuyong Zhu, Jun Bi, Chen Sun 0005, Chenhui Wu, Hongxin Hu |
ICNP | 2 |
| 2015 | DISCS: A DIStributed Collaboration System for Inter-AS Spoofing DefenseabstractIP spoofing is prevalently used in DDoS attacks for anonymity and amplification, making them harder to prevent. Combating spoofing attacks requires the collaboration of different autonomous systems (ASes). Existing methods either lack flexibility in collaboration or require centralized control in the inter-AS environment. In this paper, we propose a Distributed Collaboration System (DISCS) for inter-AS spoofing defense, which allows ASes to flexibly collaborate in spoofing defense in a distributed manner. Each DISCS-enabled AS implements four defense functions. When a victim AS is under a spoofing attack, it can request other ASes to execute the most appropriate defense functions. We present the distributed and flexible control plane design and the backward compatible and incrementally deployable data plane design for both IPv4 and IPv6. We evaluate DISCS with theoretical proof and simulations using real Internet data. The results show that DISCS has strong deployment incentives, high effectiveness, minimal false positives, modest resource consumption and strong security. Bingyang Liu, Jun Bi |
ICPP | 2 |
| 2015 | Hybrid SDN architecture to integrate with legacy control and management plane: An experiences-based studyabstractThe application of SDN and OpenFlow in a production network will face the challenges of integration with legacy routers and legacy control and management protocols. Our contribution is to preserve distributed basic functions in legacy network devices and improve central control on complex functions with OpenFlow. This paper describes a refactoring process of an intra-AS source address validation from a traditional network application to an OpenFlow-based one. It shows practical solutions about introducing OpenFlow into a commercial router by fireware updating without device hardware modification, extending OpenFlow for routing notification and packets sampling to integrate with legacy control protocols, extending an OpenFlow controller to receive and forward routing status and packets sampling messages for external control. Jun Bi, Peiyao Xiao, Xiuli Zheng |
IM | 2 |
| 2015 | An inter-AS path vector filter: towards elimination of false negativesabstractIP spoofing based attacks remains a serious and open security problem due to the fact that the current Internet implements no source address authentication mechanisms. A series of anti-spoofing practices have long been proposed while their actual implementation seems far from satisfactory. Route based filters were extensively studied in the design of Inter-AS source address validation methods. Traditional route based filters only use route direction information to establish filtering rules, causing inherited fake negatives. A novel inter-AS filter based on route path vector is proposed to reduce or even eliminate such fake negatives in this article. We name the filter IPVF (Inter-AS Path Vector Filter), which utilizes the route information of both path and distance, exhibits measurable increase in performance and incurs acceptable additional bandwidth cost. Moreover, traditional route based filtering rules is easy to be deduced by attackers. Since the filtering rules of IPVF could change over time by setting parameters, its actual improvement in performance could be exponentially increased. Zhou Zhang 0008, Ying Liu 0024, Gang Ren 0003, Jun Bi |
LANMAN | 5 |
| 2015 | Scalable and efficient file sharing in information-centric networking
Ikjun Yeom, Jun Bi, Yusung Kim 0001 |
J. Netw. Comput. Appl. | 3 |
| 2015 | Design and Implementation of a Software-Defined Mobility Architecture for IP Networks
You Wang 0004, Jun Bi, Keyao Zhang |
Mob. Networks Appl. | 2 |
| 2015 | WEBridge: west-east bridge for distributed heterogeneous SDN NOSes peeringabstractAbstract Large networks are often partitioned by the network operators into several smaller networks when deploying software‐defined networks (SDNs). Additionally, a dedicated network operating system (NOS) is deployed for each of these SDNs. Each NOS can learn the local network view that enables control of how data packets are forwarded within its network. Controlling the flow of data packets in an entire network requires each NOS to have a global network view to determine the next NOS hop. Hence, NOSes are required to share or exchange reachability and topological information. How such information is efficiently exchanged has not been well addressed so far, especially in the case of multi‐vendor NOSes. This paper proposes a west–east bridge mechanism for distributed heterogeneous NOSes to cooperate in enterprise/data center/intra‐autonomous system networks. We propose to simplify physical networks into virtual networks and only exchange the simplified virtual network information to construct the global network view. To achieve a resilient peer‐to‐peer control plane of distributed heterogeneous NOSes, we propose a “maximum connection degree”‐based connection algorithm. Considering the security issue, we adopt controller identity authentication. We implement the west–east bridge and analyze the performance obtained: about 100% of enterprises and data centers, and about 99.5% of autonomous systems can adopt to this solution. The deployment in three SDNs (CERNET, Internet2, and CSTNET) proves the feasibility. Copyright © 2014 John Wiley & Sons, Ltd. Pingping Lin, Jun Bi, Yangyang Wang 0001 |
Secur. Commun. Networks | 2 |
| 2015 | Passive IP Traceback: Disclosing the Locations of IP Spoofers From Path BackscatterabstractIt is long known attackers may use forged source IP address to conceal their real locations. To capture the spoofers, a number of IP traceback mechanisms have been proposed. However, due to the challenges of deployment, there has been not a widely adopted IP traceback solution, at least at the Internet level. As a result, the mist on the locations of spoofers has never been dissipated till now. This paper proposes passive IP traceback (PIT) that bypasses the deployment difficulties of IP traceback techniques. PIT investigates Internet Control Message Protocol error messages (named path backscatter) triggered by spoofing traffic, and tracks the spoofers based on public available information (e.g., topology). In this way, PIT can find the spoofers without any deployment requirement. This paper illustrates the causes, collection, and the statistical results on path backscatter, demonstrates the processes and effectiveness of PIT, and shows the captured locations of spoofers through applying PIT on the path backscatter data set. These results can help further reveal IP spoofing, which has been studied for long but never well understood. Though PIT cannot work in all the spoofing attacks, it may be the most useful mechanism to trace spoofers before an Internet-level traceback system has been deployed in real. Guang Yao, Jun Bi, Athanasios V. Vasilakos |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | A Hybrid Hierarchical Control Plane for Flow-Based Large-Scale Software-Defined NetworksabstractThe decoupled architecture and the fine-grained flow-control feature limit the scalability of a flow-based software-defined network (SDN). In order to address this problem, some studies construct a flat control plane architecture; others build a hierarchical control plane architecture to improve the scalability of an SDN. However, the two kinds of structure still have unresolved issues: A flat control plane structure cannot solve the superlinear computational complexity growth of the control plane when the SDN scales to a large size, and the centralized abstracted hierarchical control plane structure brings a path stretch problem. To address these two issues, we propose Orion, a hybrid hierarchical control plane for large-scale networks. Orion can effectively reduce the computational complexity of an SDN control plane by several orders of magnitude. We also design an abstracted hierarchical routing method to solve the path stretch problem. Furthermore, we propose a hierarchical fast reroute method to illustrate how to achieve fast rerouting in the proposed hybrid hierarchical control plane. Orion is implemented to verify the feasibility of the hybrid hierarchical approach. Finally, we verify the effectiveness of Orion from both the theoretical and experimental aspects. Yonghong Fu, Jun Bi, Ze Chen 0006, Kai Gao 0001, Baobao Zhang, Guangxu Chen |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2015 | Guest Editors' Introduction: Special Issue on Efficient Management of SDN/NFV-Based Systems - Part IabstractThe articles in this special section focus on the evolution of software defined networking; network virtualization; and network function virtualization. Filip De Turck, Raouf Boutaba, Prosper Chemouil, Jun Bi, Cédric Westphal |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2015 | Guest Editors' Introduction: Special issue on efficient management of SDN/NFV-based systems - Part IIabstractIn Part I of the special issue, the main reported research contributions were: efficient resource allocation and management of softwarized network functions, design of highperformance platforms to allow network function virtualization on commodity machines, and enabling efficient collaboration between providers in softwarized networks. From the twenty six submitted papers, four papers had been selected for Part I of the special issue. An additional set of four more papers have been accepted for this Part II, after a thorough revision by the authors to take into account the detailed comments from the reviewers. The four selected papers in Part II of the special address three very important topics for the efficient management of Software-Defined Networking/Virtualized Network Functions-based (SDN/NFV-based) telecommunication systems: (i) optimizations to flow-based software-defined networks to address the scalability and energy consolidation requirements, (ii) programming abstractions in wireless software-defined networks, and (iii) improved network virtualization to more efficiently support latency sensitive applications. Filip De Turck, Raouf Boutaba, Prosper Chemouil, Jun Bi, Cédric Westphal |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2014 | A solution for IP mobility support in software defined networksabstractA large number of solutions have been proposed to support mobility in IP networks including original Mobile IP, its derivatives and several newly proposed protocols. However, these solutions have drawbacks in different aspects including triangle routing, handover inefficiency, heavy signaling overhead, etc. In this paper, we argue that these problems can be addressed based on Software Defined Networks (SDN). We discuss why SDN helps to solve the problems in current IP mobility protocols and give our algorithms to demonstrate how the problems are solved. We also present an Openflow-based protocol design to realize our idea. We show performance benefits of our protocol comparing with existing IP mobility protocols through implementation and experiments on Mininet. You Wang 0004, Jun Bi |
ICCCN | 2 |
| 2014 | Performing software defined route-based IP spoofing filtering with SEFAabstractIP spoofing is a well-known security threat on the Internet. Though there have been a number of spoofing prevention mechanisms, due the diversity of networks and management objectives, the operators may prefer a framework which enables easy installation and modification of the IP spoofing prevention solution, rather than a single mechanism. In this article, a lightweight and efficient framework for route-based IP spoofing filtering, named SEFA, is proposed. Through providing a collective view of the network and decoupling the filtering rule generation from network devices, SEFA enables easily installation of spoofing filtering application. SEFA mainly resolves the challenge that how to build network abstraction without taking full controllability. SEFA has been implemented based on slightly modifying commercial routers and an open source controller. Based on experiments, SEFA is found to be able to reduce the overhead and the latency of filtering rule generation and installation, while keeping off the complexity and latency of generating forwarding rules by the controller. Guang Yao, Jun Bi, Peiyao Xiao, Duanqi Zhou |
ICCCN | 2 |
| 2014 | LAS: An effective anti-spoofing method using existing informationabstractIn today's Internet, users can send packets with forged source IP addresses, called IP Spoofing, which causes many severe problems to the Internet, especially the security problem. Extensive methods have been proposed to prevent IP spoofing. One category of anti-spoofing methods is extra-information-based. The other category of anti-spoofing methods is existing-information-based. The existing-information-based anti-spoofing methods are much easier to deploy than the extra-information-based ones. Thus, we focus on the existing-information-based anti-spoofing methods in this paper. However, the existing existing-information-based anti-spoofing methods perform poorly on preventing IP spoofing. Therefore, in this paper we propose a new existing-information-based anti-spoofing method, named Link-state-based Anti-Spoofing (LAS), which works in a link-state-protocol-based network. LAS provides good effectiveness on preventing IP spoofing as our simulation results show that even if LAS is only deployed on 10% of routers in a link-state-protocol-based network, 80%~99% of spoofing cases in the network can be prevented in general. Baobao Zhang, Jun Bi |
ICCCN | 2 |
| 2014 | Orion: A Hybrid Hierarchical Control Plane of Software-Defined Networking for Large-Scale NetworksabstractThe decoupled architecture and the fine-grained flow control feature of SDN limit the scalability of SDN network. In order to address this problem, some studies construct the flat control plane architecture, other studies build the hierarchical control plane architecture to improve the scalability of SDN. However, the two kinds of structure still have unresolved issues: the flat control plane structure can not solve the super-linear computational complexity growth of the control plane when SDN network scales to large size, the centralized abstracted hierarchical control plane structure brings path stretch problem. To address the two issues, we propose Orion, a hybrid hierarchical control plane for large-scale networks. Orion can effectively reduce the computational complexity growth of SDN control plane from super-linear to linear. Meanwhile, we design an abstracted hierarchical routing method to solve the path stretch problem. Further, Orion is implemented to verify the feasibility of the hybrid hierarchical approach. Finally, we verify the effectiveness of Orion both from the theoretical and experimental aspects. Yonghong Fu, Jun Bi, Kai Gao 0001, Ze Chen 0006, Bin Hao |
ICNP | 2 |
| 2014 | What benefits does NDN have in supporting mobilityabstractInspired by forwarding hint and previous IP mobility solutions, we adopt forwarding hint, which intent to solve scalability problem, to support producer mobility. In this paper, we point out how those new elements, such as cache, content-oriented security, content-centric data transmission, benefit mobility. We implement a prototype to analyze the benefits that NDN has in supporting mobility. Our analysis and evaluation conclude that during mapping updating delay following mobility, only popular contents can get benefits from caching while unpopular contents gain little. What's more, only if the content is able to be accessed by partial consumers, caching would amplify the benefits and extend receivers to the rest of consumers, which has significant contribution during routing convergence or mapping updating delay after mobility happens. Xiaoke Jiang, Jun Bi, You Wang 0004 |
ISCC | 2 |
| 2014 | Joint allocation and scheduling of network resource for multiple control applications in SDNabstractThe network resource allocation in SDN for control applications is becoming a key problem in the near future because of the conflict between the need of the flow-level flexibility control and the limited capacity of flow table. Based on the analysis of the difference of the definition of network resource between SDN and traditional IP network, the idea of the integrated allocation of link bandwidth and flow table for multiple control applications in SDN is proposed in this paper. Furthermore, a price-based joint allocation model of network resource in SDN is built by introducing the price for each of the resources, which can get the proportional fair allocation of link bandwidth and the minimum global delay at the same time. We have also designed a popular flow scheduling policy based on the proportional fair allocation of link bandwidth in order to achieve the minimum global delay. A flow scheduling module has been implemented and evaluated in Floodlight, named virtual forwarding space (VFS). VFS can not only implement the fair allocation of link bandwidth and minimum delay flow scheduling in data plane but also accelerate packet forwarding by looking up flow cache in control plane. Jun Bi |
NOMS | 2 |
| 2014 | Flowinsight: decoupling visibility from operability in SDN data planeabstractNo abstract available. Guang Yao, Jun Bi |
SIGCOMM | 3 |
| 2014 | CTE: cost-effective intra-domain traffic engineeringabstractNo abstract available. Baobao Zhang, Jun Bi, Fred Baker |
SIGCOMM | 2 |
| 2014 | To what extent could ILNP optimize handover efficiencyabstractIn this paper, we focus on handover efficiency of Identifier-Locator Network Protocol (ILNP), which is a lightweight mobility solution. Our goal is to improve the handover performance of ILNP without introducing large changes and additional costs to the protocol. We first give a general algorithm for handover optimization of such host-based mobility protocols. Then we analyze the algorithm to find out to what extent we could optimize ILNP. Evaluation results show that the algorithm is efficient in reducing signaling overhead and handover latency in some cases while infeasible in other cases. Be guided by the evaluation results, we propose design of an ILNP extension called ILNP+. We also make simulations based on real user mobility models to demonstrate the feasibility of our proposal. You Wang 0004, Jun Bi |
WCNC | 2 |
| 2014 | Toward Incentivizing Anti-Spoofing DeploymentabstractIP spoofing-based flooding attacks are a serious and open security problem on the current Internet. The best current antispoofing practices have long been implemented in modern routers. However, they are not sufficiently applied due to the lack of deployment incentives, i.e., an autonomous system (AS) can hardly gain additional protection by deploying them. In this paper, we propose mutual egress filtering (MEF), a novel antispoofing method, which provides continuous deployment incentives. The MEF is implemented on the AS border routers using access control lists (ACLs). It drops an outbound packet whose source address does not belong to the local AS if the packet is related to a spoofing attack against other MEF-enabled ASes. By this means, only the deployers of the MEF can gain protection, whereas nondeployers cannot free ride. As more ASes deploy MEF, deployment incentives become higher. We present the system design of MEF, and propose an optimal prefix compression algorithm to compact the ACL into the routers' limited hardware resource. With theoretical analysis and simulations with real Internet data, our evaluation results show that MEF is the only method that achieves monotonically increasing deployment incentives for all types of spoofing attacks, and the system design is lightweight and practical. The prefix compression algorithm advances the state-of-the-art by generalizing the functionalities and reducing the overhead in both time and space. Bingyang Liu, Jun Bi, Athanasios V. Vasilakos |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2013 | Towards a Cooperative Mechanism Based Distributed Source Address FilteringabstractWhile making the Internet totally trustworthy is intractable, making as trustworthy as possible is a crucial problem. Within this landscape, authentication of the IP source address remains one important topic in need of further study. However, most source address validation methods are difficult to implement in practice because of deployment difficulties. This research designs an efficient inter-domain distributed source address validation solution (CatchIt). By employing a novel routing choice notification scheme, CatchIt makes the deployed ASes intelligent by allowing them cooperate to acquire the valid incoming path information of packets. With such knowledge, the deployed ASes can accurately authenticate the source address without the need for any modifications to the de facto routing protocol and packet structure. Moreover, CatchIt helps the deployed ASes proactively and quickly filter spoofed packets before they imperil the network. CatchIt also avoids any false positive, even under partial deployment. Our evaluation also shows that CatchIt is effective and accurate when catching spoofed packets while incurring a low overhead; CatchIt maintains an early deploy and rapidly benefit incremental deployment incentive mechanism. Jun Bi |
ICCCN | 2 |
| 2013 | Refining IP-to-AS Mappings for AS-Level TracerouteabstractIt is of great significance for network operators and researchers to obtain accurate AS-level traceroute paths, for which mapping IP addresses to correct AS numbers is critical. Thus, there have been a lot of efforts to improve the original IP-to-AS mapping table, which was extracted from BGP routing tables. One of these efforts is called pair matching, which refines the original mapping table by maximizing the number of matched pairs of traceroute and BGP AS paths. However, the existing pair-matching-based methods refine the original IP-to-AS mapping table only with the prefix granularity, i.e., IP addresses in the same /24 prefix are mapped to the same AS or the same set of ASes, which does not fit reality. In this paper, we attempt to refine the IP-to-AS mapping table with the IP address granularity, i.e., allowing IP addresses in the same prefix to be mapped to different ASes. The results show that our fine-grained method can produce a more accurate IP-to-AS mapping table. In addition, this paper also provides a better understanding for the pair-matching-based methods. Baobao Zhang, Jun Bi, Yangyang Wang 0001, Yu Zhang 0036 |
ICCCN | 2 |
| 2013 | HTTP-CCN gateway: Adapting HTTP protocol to Content Centric NetworkabstractCCN is one of the future Internet architecture. However, the lack of real traffic becomes an obstacle to advanced CCN researches. HTTP, as an content-oriented application-layer protocol working over current Internet, is similar to CCN in many aspects. In this demo, we try to convert HTTP traffic into CCN traffic with HTTP-CCN gateway. Although HTTP is not equivalent to CCN, we can design carefully to make the conversion correct in most situations. The gateway will introduce real traffic into CCN testbed to support CCN researches. Our demonstration will show how to use this gateway. Zhaogeng Li, Jun Bi |
ICNP | 2 |
| 2013 | On the cascading failures of multi-controllers in Software Defined NetworksabstractIn this paper, a potential threat to reliability of Software Defined Networking (SDN) is disclosed: the cascading failures of controllers. Current SDN designs have widely utilized multiple controllers and the load of a failed controller can be redistributed to the other controllers. However, simply utilizing multiple controllers cannot protect SDN networks from a single point of failure: the load of the controllers which carry the load of the failed controller can exceed the capacity of them, and then cascading failures of controllers will happen. In this article, at first we propose a model for such failures and present simulation results based on the model. Strategies for initial load balance and load redistribution after failure are designed to prevent such failures. The simulation result shows the strategies can significantly increase the resistance of SDN networks to cascading failures. Guang Yao, Jun Bi, Luyi Guo |
ICNP | 2 |
| 2013 | RPFP: IP fast reroute with providing complete protection and without using tunnelsabstractIn today's IP network, if a link or router fails, packets that traverse the failed link or router will be lost until the network re-converges even if there exists another path bypassing the failure. We call such a single failure a valid single failure. Therefore the IETF published a framework called IP Fast ReRoute (IPFRR) which aims to provide protection against such valid single failures before the network re-converges. Based on the IPFRR framework, a lot of methods have been proposed. One category of IPFRR methods is IP-tunnel-based. The IP-tunnel-based IPFRR methods impose extra cost such as the encapsulation cost, on the traffic delivery. In this paper we focus on the otber category of IPFRR methods, no-tunnel-based IPFRR methods, which do not impose any extra cost on the traffic delivery. However, the existing no-tunnel-based IPFRR methods cannot provide complete protection against all the valid single failures. Therefore in this paper we propose a new kind of no-tunnel-based IPERR method named with RPFP which can provide complete protection against all the valid single failures. Baobao Zhang, Jun Bi |
IWQoS | 3 |
| 2013 | GRS: Global Resolution Service for mobility support in the InternetabstractAs it becomes a common need to support mobility in the Internet, there is a growing trend towards providing a general mobility management function in the protocol stack by resolving identifiers of mobile nodes to their locations. However, current mechanisms have drawbacks in both performance and functionality, especially when they are partially deployed. In this paper, we propose a Global Resolution Service (GRS) offered by Resolution Service Providers (RSP), which resolves identifiers in a flexible way according to diverse mobility scenarios. Simulation results show the advantages of our approach compared to existing solutions in terms of both flexibility and deployability. You Wang 0004, Jun Bi |
LCN | 2 |
| 2013 | Interest set mechanism to improve the transport of named data networkingabstractIn this paper, we proposal an Interest Set mechanism which aggregate similar Interest packets from same flow to one packet to improve the efficient of transport of NDN. The trick here is to reset lifetime of corresponding PIT entry in the immediate routers every time when valid Data packet is passed by. This mechanism covers the time and space uncertainty of data generating, reduce the cost of maintaining the pipeline and improve the transport of NDN. Xiaoke Jiang, Jun Bi |
SIGCOMM | 2 |
| 2013 | Seamless interworking of SDN and IPabstractNo abstract available. Pingping Lin, Jonathan Hart, Umesh Krishnaswamy, Tetsuya Murakami, Masayoshi Kobayashi, Ali Al-Shabibi, Kuang-Ching Wang, Jun Bi |
SIGCOMM | 8 |
| 2013 | Collaborative caching based on hash-routing for information-centric networkingabstractNo abstract available. Jun Bi |
SIGCOMM | 2 |
| 2013 | Making intra-domain traffic engineering resistant to failuresabstractNo abstract available. Baobao Zhang, Jun Bi |
SIGCOMM | 2 |
| 2013 | VASE: Filtering IP spoofing traffic with agility
Guang Yao, Jun Bi, Peiyao Xiao |
Comput. Networks | 2 |
| 2012 | On Performance of Cache Policy in Information-Centric NetworkingabstractInformation-Centric Networking is (ICN) gaining increasingly concerns, as an important direction of the future Internet architecture research. To study the impacts of various cache policies on overall performance of ICN network, we formulate the in- network caching problem of ICN into Mixed-Integer Linear Programming problem. Furthermore, we infer that frequency-based cache policies like LFU are supposed to perform well by analyzing the properties of optimal cache assignment, which is corroborated by our simulation results. We attempt to explore the impact of the distance between cache and the original content on cache policy performance by posing a novel cache policy named LB (Least Benefit), which takes into account the distance factor besides frequency. Through extensive simulations under various scenarios and configurations, we find that the performance gain brought by LB is limited in comparison to that of LFU, which implies that more sophisticated cache policies involving the distance factor should be considered to improve LFU. Our simulation results also show that, under a reasonable setting of cache size and request pattern, the average hops to get content can be reduced significantly by nearly 50% in comparison to that of the scenario without in- network caching. Jun Bi |
ICCCN | 2 |
| 2012 | Towards an Aggregation-Aware Internet RoutingabstractInternet is composed of a large amount of autonomous systems (ASes). Border Gateway Protocol (BGP) is the de facto standard used to connect these ASes and exchange reachability information between them. The global BGP routing table size in default free zone (DFZ) grows fast due to many factors including IP address allocation, multihoming, and traffic engineering, etc. Increasing prefix fragments consume more memory space and computational capacity in network forwarding devices. It has been known that the Internet has a potential routing scalability issue along with large address space (e.g., IPv6) deployment in the future. Route aggregation is a practical approach to reduce route entries. In this paper, we propose an innovation based on BGP, named Aggregation-aware Inter-Domain Routing (AIDR). It takes advantage of the redundant paths to the same destination in the Internet, and takes route aggregation into account in route selection to get more aggregation for forwarding table (FIB). We give a detailed analysis and evaluation on the effect of AIDR using the public BGP traces from RouteViews and RIPE. It shows that AIDR can produce aggregated FIBs of size roughly 20%~36% of the original routing table size with allowing 2.0 AS path stretch, and 25%~40% without AS path tretch. Yangyang Wang 0001, Jun Bi |
ICCCN | 2 |
| 2012 | TUNOS: A novel SDN-oriented networking operating systemabstractSoftware defined networking (SDN) has been a promising network architecture to improve the openness of network and the diversity of protocols. Network operating system (NOS) in SDN is a key component for the abstraction of infrastructure and feature-rich protocols, which provide a general control plane and a unified protocol operating view. SDN-oriented NOS design requires not only the control shift from the specific network functions and vendor-dependent implementation in a traditional control plane to a general control functions, but also the extension of abstraction from computing process in a computer operating system to forwarding operation. To address this, we present a novel network operating system-TUNOS from the view of device control capacities and network control capacities. For the purpose of scalability, robustness, flexibility and high-performance, TUNOS provides open device management, cognitive network status, global network view, virtual forwarding space, and APP context management. General network control APIs are designed for user-friendly network programming. Jun Bi, Hongyu Hu |
ICNP | 2 |
| 2012 | A content provider mobility solution of named data networkingabstractIn this paper, we proposal an content provider mobility solution of Named Data Networking (NDN) [1]. Here content provider means the host of NDN network which provide content originally. We add a Locator are to the Interest packet [2]. Mapping System also introduced into the network, which maps identifier to locator. The original name is used as identifier. Thus, matching lookup in Content Store (CS) and Pending Interest Table (PIT) employs identifier, while forwarding lookup in Forwarding Information Base (FIB) employs locator. In reality, Mapping System should be a DNS-like distributed system, so the record updating has time latency. It's hard to solve provider mobility when there is no explicit "where" information, that's why locator is imported in NDN, however, "where" still serves as the secondary information of the network. Xiaoke Jiang, Jun Bi, You Wang 0004, Pingping Lin, Zhaogeng Li |
ICNP | 2 |
| 2012 | Umbrella: A routing choice feedback based distributed inter-domain anti-spoofing solutionabstractThe authentication of the IP source address remains one of the most important steps in making the Internet as trustworthy as possible. With existing anti-spoofing solutions, deployed ASes lack cooperation when exchanging routing decisions and disseminations. In general, this makes anti-spoofing mechanisms inefficient and does not adapt to incremental deployment. By introducing routing choice feedback, we propose a distributed inter-domain anti-spoofing solution (Umbrella). In Umbrella, the deployed ASes can acquire approximate global routing choice information. Our approach offers gains in efficiency through the verification of the packets forwarding path and the construction of dynamically spoofing packets filter. Our experimental analysis of Umbrella shows it to be both effective and incrementally deployable. Jun Bi |
ICNP | 2 |
| 2012 | VCP: A virtualization cloud platform for SDN intra-domain production networkabstractSoftware Defined Networking (SDN) is considered as a promising method to re-construct the architecture of Internet. At present, the programs of network protocols are mixed together in SDN controller. However, in the production network, an isolated network environment with private resources is needed for each network protocol running on the same SDN controller. It is therefore necessary to design a practical virtualization cloud platform on the SDN network operating system (NOS). In this paper, we introduce a virtualization cloud platform for SDN production network. A prototype is implemented and two cases are performed to show the feasibility and the effectiveness of our proposed framework. Pingping Lin, Jun Bi, Hongyu Hu |
ICNP | 2 |
| 2012 | Global Resolution Service for mobility support in the internetabstractResolution from identifiers to locators serves as a key component of mapping-based mobility solutions. In this paper we address the weakness of current resolution methods in supporting diverse mobility scenarios and propose a Global Resolution Service offered by Resolution Service Providers. We present a preliminary design and simulation, and results show that our approach is able to provide better resolution service compared to existing solutions in terms of performance. You Wang 0004, Jun Bi, Chenghui Peng |
ICNP | 2 |
| 2012 | AFEC: A method of aggregating forwarding equivalence classes based on overlapped pathsabstractThe traditional IP routing protocols transfer traffic only according to destination, which is not fine-grained enough to satisfy the significant demands of quality-of-service (QoS) and traffic engineering, so fine-grained flow control techniques, such as Multiprotocol Label Switching (MPLS) [1], emerge. MPLS is the most widely used technique to do fine-grained flow control. Baobao Zhang, Jun Bi |
ICNP | 2 |
| 2012 | A Multi-fence Countermeasure Based Inter-domain Source Address Validation MethodabstractThe functional deficiency of the Internet architecture enables attackers the ability to easily to spoof IP source address. The traditional signature-and-verification based anti-spoofing methods are often limited by essential process based on an explicit analysis and process of the IP header and does not adapt to incremental deployment. This paper designs a multi-fence countermeasure based inter-domain source address validation method named VIP. By employing intelligent originating information label and extended MPLS based cloud and network, VIP enables lightweight-label-based packet forwarding and validation. And VIP offers gains in efficiency by reducing the load on both forwarding tables and validation processing without negative influences and complex operations on de facto networks. In addition to enhanced scalability, VIP may facilitate incremental deployment in the long run. Jun Bi, Wei Zhang 0040 |
NCA | 2 |
| 2012 | FaaS: filtering IP spoofing traffic as a serviceabstractNo abstract available. Bingyang Liu, Jun Bi, Xiaowei Yang 0001 |
SIGCOMM | 2 |
| 2012 | Catching popular prefixes at AS border routers with a prediction based method
Wei Zhang 0040, Jun Bi, Baobao Zhang |
Comput. Networks | 2 |
| 2011 | Caching Popular BGP Prefixes with Grey Modeling PredictionabstractInternet core routers are facing challenges brought by the ever-increasing transit bandwidth and routing scale. In order to meet the requirements of highly efficient packet forwarding, some solutions propose to load a small portion of the BGP RIB entries into the FIB. Therefore the most popular prefixes, which contribute major traffic loads, need to be cached in the FIB as long as possible. In this paper, we try to propose a prediction based method to cache those popular prefixes in the FIB. The cache strategy is guided by the traffic prediction of a grey model. We also apply FIB aggregation techniques to suppress the number of overlapped sub-prefixes of the popular prefixes on cache/route updates. We evaluate our method with real traffic traces and find that our prediction-based cache replacement strategy outperforms other cache strategies and matches Internet traffic dynamics very well. Wei Zhang 0040, Jun Bi, Baobao Zhang |
ICCCN | 2 |
| 2011 | OpenRouter: OpenFlow extension and implementation based on a commercial routerabstractBy analyzing challenges of current OpenFlow in production network, we propose three extensions of OpenFlow about FlowTable, control mode and OpenFlow protocol. Based on these extensions, a commercial OpenFlow-enabled router, named OpenRouter, is designed and implemented using only available and existing hardware in a commercial router. OpenRouter brings the abilities of control openness, integration of inside/outside protocols, and flexibility of OpenFlow message structure, low-cost implementation and deployment. We expect OpenRouter may accelerate the large-scale application and deployment of OpenFlow in production network. Jun Bi, Hongyu Hu |
ICNP | 2 |
| 2011 | IPv6 evolution, stability and deploymentabstractOur subject focuses on IPv6 network, which develops for more than 10 years. How IPv6 evolve in those years? Is IPv6 network mature enough to undertake the load produced by users? Can we find some principles to guide IPv6 deployment, which make the whole network more robust and efficiency? This paper tries to answer these questions with in-depth statistics. Good news is that network is growing at a speed of O(d2) (d is time) after 2006, moreover, network itself and its routing system become more and more stable. And we explore special properties of this preliminary network, We find that distribution of AS degree follows "Power-Law Distribution", but AS-level topology cannot be described as "Small-World Model" properly. We also propose a method to define the importance of AS and give a simple principle of IPv6 deployment. We even build "6Stats Project"[1] to provide data which help deploy IPv6. Xiaoke Jiang, Jun Bi, Yangyang Wang 0001, Zhijie He, Wei Zhang 0040, Hongcheng Tian |
ICNP | 2 |
| 2011 | A deployable approach for inter-AS anti-spoofingabstractFiltering IP packets with spoofed source addresses not only improves network security, but also helps with network diagnosis and management. Compared with filtering spoofing packets at the edge of network which involves high deployment and maintenance cost, filtering at autonomous system (AS) borders is more cost-effective. Inter-AS anti-spoofing, as its name suggests, is implemented on AS border routers to filter spoofing packets before their entering or leaving an AS. Existing inter-AS anti-spoofing approaches focus on filtering efficiency, but lacks of deployability. In this paper we first introduce three properties of a deployable inter-AS anti-spoofing approach, incremental deployability, high deployment incentives and low deployment cost. Then we propose DIA, the first inter-AS anti-spoofing approach meeting the three properties. We present the design of DIA and evaluate its deployability with real Internet data. The evaluation results show that DIA provides high deployment incentives for Internet Service Providers by significantly mitigating spoofing based denial of service attacks. Our implementation proves that DIA can be easily implemented in commodity routers and minimize the deployment cost. Bingyang Liu, Jun Bi |
ICNP | 2 |
| 2011 | EasyTrace: An easily-deployable light-weight IP traceback on an AS-level overlay networkabstractIP traceback can be used to find the origins and paths of attacking traffic. However, so far, no Internet-level IP traceback system has ever been deployed because of deployment difficulties. In this paper, we present an easily-deployable light-weight IP traceback based on flow (EasyTrace). In EasyTrace, it is not necessary to deploy any dedicated traceback software and hardware at routers, and an AS-level overlay network is built for incremental deployment. We theoretically analyze the quantitative relation among the probability that a flow is successfully traced back various AS-level hop number, independently sampling probability, and the number of packets that the flow comprises. Hongcheng Tian, Jun Bi, Wei Zhang 0040, Xiaoke Jiang |
ICNP | 2 |
| 2011 | AIDR: Aggregation of BGP routing table with AS path stretchabstractAs Internet growth, more and more prefix fragments are announced into the global routing system due to operational reasons of inconsecutive address allocation, multihoming, and traffic engineering. The BGP routing table size in Default Free Zone (DFZ) fast growth will consume more memory space and computational capacity. It has been known that Internet will face with routing scalability issue, especially in the large address space (e.g., IPv6) deployment. In this paper, we propose an innovation to BGP, named Aggregation-aware Inter-Domain Routing (AIDR). It will take the prefix aggregation into account to make tradeoff in the best route selection. We evaluate the effect of AIDR on global routing system using the BGP traces from RouteViews and RIPE. It shows that, averagely, AIDR-based aggregation can reduce to roughly 15%~35% of original routing table size under the 2.0 AS path stretch constraint, and to 25%~40% with no AS path stretch. Yangyang Wang 0001, Jun Bi |
ICNP | 2 |
| 2011 | Source address validation solution with OpenFlow/NOX architectureabstractCurrent Internet is lack of validation on source IP address, resulting in many security threats. The future Internet can face the similar routing locator spoofing problem without careful design. The current in-progress source address validation standard, i.e., SAVI, is not of enough protection due to the solution space constraint. In this article, a mechanism named VAVE is proposed to improve the SAVI solutions. VAVE employs OpenFlow protocol, which provides the de facto standard network innovation interface, to solve source address validation problem with a global view. Significant improvements can be found from our evaluation results. Guang Yao, Jun Bi, Peiyao Xiao |
ICNP | 2 |
| 2011 | A Framework to Quantify the Pitfalls of Using Traceroute in AS-Level Topology MeasurementabstractAlthough traceroute has the potential to discover AS links that are invisible to existing BGP monitors, it is well known that the common approach for mapping router IP addresses to AS numbers based on BGP routing tables is highly error-prone. We develop a systematic framework to quantify the potential errors of traceroute measurement in AS-level topology inference. In comparing traceroute-derived AS paths with BGP AS paths, we take a novel approach to identifying mismatched path segments and then inferring the causes of these mismatches through a set of tests. Our results show that about 60% of mismatches are due to routers using IP addresses belonging to peering neighbors. This result helps settle a debate in previous works regarding the major cause of errors in traceroute measurement. With the approximate ground truth of the ASes with BGP monitors inside, we identify the inaccuracy of publicly available traceroute-derived topology datasets and find that between 8% and 42% of AS adjacencies on the monitored ASes are false. With a new method to characterize AS links, we show that the derived (false) links between Tier-1/large ISPs and their customers' customers appear more frequently than real links do. Yu Zhang 0036, Ricardo V. Oliveira, Yangyang Wang 0001, Shen Su, Baobao Zhang, Jun Bi, Hongli Zhang 0001, Lixia Zhang 0001 |
IEEE J. Sel. Areas Commun. | 6 |
| 2010 | Empirical Analysis of Core-Edge Separation by Decomposing Internet Topology GraphabstractBorder Gateway Protocol (BGP) is the de facto standard protocol for the inter-domain routing. Due to multi-homing and traffic engineering, the BGP routing table size of default free zone (DFZ) is growing rapidly. Inter-domain routing is facing the scaling challenge. Many solutions have been proposed. Among them, the core-edge separation scheme gets more attentions than others due to its practical advantages. It separates specific prefixes of edge networks from entering into transit core, and reduces the DFZ BGP routing table size. However, there has less evaluation on how much scalability can be improved from core-edge separation. In this paper, we take the further step to quantifying the impact of the core-edge separation on Internet inter-domain routing. We find that separation at stub-transit can reduce 43% routing table size and prevent more than half of BGP updates. We decompose the topology graph by k-core and customer-provider based decomposition methods, and analyze the impact of deploying separation at different level of topological hierarchy. We believe that complicated separation deployment strategies (not the simple stub-transit split) are feasible to approaching an optimal effect. Yangyang Wang 0001, Jun Bi |
GLOBECOM | 2 |
| 2010 | A pull model IPv6 Duplicate Address DetectionabstractIn IPv6 network, before configuring any address, a node must perform Duplicate Address Detection (DAD) to ensure the address is unique on link. However, original DAD is unreliable and vulnerable. In this article, a pull model DAD is designed, which achieves improvements both in reliability and security through changing the solicitation model. Comparing with SEcure Neighbor Discovery (SEND), this proposal has advantage in lightweight overhead and flexibility of address generation. Through evaluation, it is found to be feasible and cost effective. Guang Yao, Jun Bi, Yueran Zhang |
LCN | 2 |
| 2010 | Passive IP traceback: capturing the origin of anonymous traffic through network telescopesabstractIP traceback can be used to find the origin of anonymous traffic; however, Internet-scale IP traceback systems have not been deployed due to a need for cooperation between Internet Service Providers (ISPs). This article presents an Internet-scale Passive IP Trackback (PIT) mechanism that does not require ISP deployment. PIT analyzes the ICMP messages that may scattered to a network telescope as spoofed packets travel from attacker to victim. An Internet route model is then used to help re-construct the attack path. Applying this mechanism to data collected by Cooperative Association for Internet Data Analysis (CAIDA), we found PIT can construct a trace tree from at least one intermediate router in 55.4% the fiercest packet spoofing attacks, and can construct a tree from at least 10 routers in 23.4% of attacks. This initial result shows PIT is a promising mechanism. Guang Yao, Jun Bi |
SIGCOMM | 2 |
| 2008 | A Trust and Reputation based Anti-SPIM MethodabstractInstant Messaging (IM) service is a killer application in the Internet. Due to the problem of IM spam (SPIM), building an effective anti-spim method is an important research topic. At present, most of anti-spim solutions are based on email-spam prevention techniques, which are not directly applicable to anti-spim. We present a new anti-spim method SpimRank, which integrates trust and reputation mechanisms with black-list technique. SpimRank also tracks user's historical action to deal with spim attacks in nearly real time, which is applicable to IM environment. Jun Bi, Wenmao Zhang |
INFOCOM | 1 |
| 2008 | A two-level source address spoofing prevention based on automatic signature and verification mechanismabstractIP source address spoofing is used by DDoS and DrDoS attacks in the Internet. This paper presents a signature-and-verification based IP spoofing prevention method, automatic peer-to-peer based anti-spoofing method (APPA). APPA has two levels: intra-AS (autonomous system) level and inter-AS level. In the intra-AS level, the end host tags a one-time key into each outgoing packet and the gateway at the AS border verifies the key. In inter-AS level, the gateway at the AS border tags a periodically changed key into the leaving packet and the gateway at border of the destination AS verifies and removes the key. The most prominent characteristic of APPA is the automatically synchronizing state-machine, which is used to update keys automatically and effectively. The benefits of APPA are: (1) preventing IP address spoofing strictly, end systems canpsilat even spoof addresses in the same AS or subnet, (2) providing very low running and management costs, (3) supporting anti-replay attacks and incremental deployment. Jun Bi |
ISCC | 2 |
| 2008 | A CGAbased IP source address authentication method in IPv6 access networkabstractIn this paper, we present a novel source address spoofing prevention method for IPv6 access network called CGA based source address authentication (CSAA). It makes use of CGA (cryptographically generated address) to generate an unspoofable identifier of host without PKI, and bind it to the authorized address of the host. Then all the packets sent out by the host can be validated in the first-hop router by a light-weight method. Guang Yao, Jun Bi |
LCN | 2 |
| 2008 | Shim6: Reference Implementation and Optimization
Jun Bi, Lizhong Xie |
Networking | 1 |
| 2007 | A Multihoming Based IPv4/IPv6 Transition Approach
Lizhong Xie, Jun Bi |
Networking | 2 |
| 2006 | Study on High Performance IPv4/IPv6 Transition and Access Service
Xiaoxiang Leng, Jun Bi |
ISPA | 2 |
| 2006 | Application Presence Fingerprinting for NAT-Aware Router
Jun Bi |
KES (2) | 1 |
| 1999 | A Formal Approach to Conformance Testing of Distributed Routing Protocols
Jun Bi |
FORTE | 1 |
| 1999 | An approach to concurrent TTCN test generation
Jun Bi |
J. Comput. Sci. Technol. | 1 |
| 1998 | A Concurrent TTCN based Approach to Conformance Testing of Distributed Routing Protocol OSPF v2abstractThis paper proposes an formal approach to conformance testing for OSPF v2, a widely used distributed routing protocol in the Internet. The routing function is performed in a distributed system, thus the testing is more complex than the traditional peer-to-peer protocol. The concurrent TTCN is a test notation that can handle concurrent test behavior and it is suitable for the routing function testing. We first discuss a concurrent TTCN based OSPF test architecture. Then we formally define and implement a concurrent TTCN based test system based on an extension of the LTS (labelled transition system). Finally, we present a specification model, the CEBE, to specify an OSPF entity and to generate (combine the data and control flow) test suite. Jun Bi |
ICCCN | 1 |