VLDB 2026 Research / reviewers in the wild / expert
Yennun Huang
dblp:84/3147
· DBLP profile ↗
70ranked-venue papers
7as first author
14since 2021 · last 2026
0000-0001-9312-0113ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 26 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 23 · 1 first-author · 4 since 2021Systems, architecture and hardware · 20 · 2 first-author · 4 since 2021Computer networks · 9 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Theory of computation · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An optimization-based resource orchestration algorithm for enhanced admission control and QoS assurance in network slicing of software-defined networksabstract• Proposed an optimization-driven resource orchestration algorithm that enhances admission control and ensures Quality of Service (QoS) in SDN-based network slicing. • Introduced a Partial Admission Control (PAC) strategy, dynamically allocating network resources based on priority and real-time availability, addressing the limitations of rigid binary admission models. Efficient resource orchestration is essential for ensuring high Quality of Service (QoS) and reliability in Software-defined Networks (SDNs). This paper introduces an optimization-based algorithm that integrates Lagrangian Relaxation (LR) and Queueing Theory to enhance admission control and priority scheduling in SDNs. The proposed approach overcomes the limitations of traditional binary admission control methods by enabling Partial Admission Control (PAC), which allows more flexible resource allocation. The system’s performance is significantly improved through the use of non-preemptive and preemptive priority scheduling, while LR techniques effectively manage complex network conditions. Specifically, the proposed Bisection-Search (B-S) heuristic leverages the Lagrangian multipliers generated during the optimization process to intelligently guide resource allocation, consistently producing high-quality feasible solutions ( Z primal ). These solutions are validated against the theoretical bound ( Z LR ) provided by the LR method, demonstrating a provably small duality gap. The proposed algorithm is evaluated through extensive simulations across diverse network scales, traffic loads, and delay constraints, demonstrating substantial improvements in network performance and service differentiation. These results provide a comprehensive analysis of the performance envelope of the proposed framework, highlighting the trade-offs between solution quality, computational complexity, and network scale. The study offers an adaptive and mathematically grounded solution, demonstrating its effectiveness in complex, high-contention networking environments. Yu-Fang Chen 0001, Frank Yeong-Sung Lin, Wei-Cheng Shih, Tzu-Lung Sun, Ming-Chi Tsai, Yennun Huang, Chiu-Han Hsiao |
Comput. Networks | 6 |
| 2025 | IPMES+: Enhancing Incremental TTP Detection with Frequency and Flow SemanticsabstractAdvanced Persistent Threat (APT) cyberattacks are a major concern for both businesses and governments, making APT detection a crucial area in cybersecurity research. Detecting short-duration attack steps, also known as Tactics, Techniques, and Procedures (TTPs), has proven effective in assisting APT detection. However, existing incremental matching tools lack support for high-level pattern semantics, such as frequency and flow, causing potential inefficiency and evasion by slightly changing attack operations. To address this, we propose a feasible solution called IPMES+1, which incorporates intricate designs and optimizations. IPMES+ is the first TTP detection tool to provide incremental time-constrained graph-based pattern matching with frequency and flow semantics. Evaluations on synthetic and real-world datasets demonstrate that IPMES+ is not only necessary and feasible for enhancing practical TTP detection but also superior to existing tools that lack these advanced capabilities. Ping-Ting Liu, Bo-Wei Lin, Yennun Huang |
DSN | 4 |
| 2025 | Adaptive Traffic Control: OpenFlow-Based Prioritization Strategies for Achieving High Quality of Service in Software-Defined NetworkingabstractThis paper tackles key challenges in Software-Defined Networking (SDN) by proposing a novel approach for optimizing resource allocation and dynamic priority assignment using OpenFlow’s priority field. The proposed Lagrangian relaxation (LR)-based algorithms significantly reduces network delay, achieving performance management with dynamic priority levels while demonstrating adaptability and efficiency in a sliced network. The algorithms’ effectiveness were validated through computational experiments, highlighting the strong potential for QoS management across diverse industries. Compared to the Same Priority baseline, the proposed methods: RPA, AP–1, and AP–2, exhibited notable performance improvements, particularly under strict delay constraints. For future applications, the study recommends expanding the algorithm to handle larger networks, integrating it with artificial intelligence technologies for proactive resource optimization. Additionally, the proposed methods lay a solid foundation for addressing the unique demands of 6G networks, particularly in areas such as base station mobility (Low-Earth Orbit, LEO), ultra-low latency, and multi-path transmission strategies. Yu-Fang Chen 0001, Frank Yeong-Sung Lin, Sheng-Yung Hsu, Tzu-Lung Sun, Yennun Huang, Chiu-Han Hsiao |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2024 | IPMES: A Tool for Incremental TTP Detection Over the System Audit Event StreamabstractAdvanced persistent threat (APT) cyberattacks are serious threats to corporations and governments. The prolong dwell time associated with APTs significantly increase the difficulty on detecting them in provenance graphs. To reduce the detection complexity, some works have demonstrated the effectiveness of employing pattern matching on provenance graphs in conjunction with APT lifecycle models to pinpoint short-duration attack steps, also known as “tactics, techniques, and procedures” (TTPs). However, when dealing with more complex TTPs, particularly those involving graph-based and partial ordering, few tools can incrementally and efficiently handle them. In this paper, we present IPMES11https://github.com/littleponywork/IPMES, a tool that has been publicly released to address this gap. By leveraging specific optimizations, it provides efficient incremental matching for those TTPs, and can handle practical system audit event streams. Experiments conducted on synthetic and real-world data demonstrated the practical feasibility of IPMES in TTP detection. Ping-Ting Liu, Bo-Wei Lin, Yi-Chun Liao 0001, Yennun Huang |
DSN | 5 |
| 2024 | Enhancement on Target-Gripper Alignment: A Tomato Harvesting Robot with Dual-Camera Image-Based Visual ServoingabstractAutomation application in crop harvesting has increased in the past decades. Various types of harvesting robots are emerging in both commercial and research areas. One of the main challenges is the precision alignment of the gripper and the target crop. An undesired dislocation can harm both the gripper and the crop, which is mainly caused by uncertainties from the sensors and the manipulator. To solve the problem, the dual-camera setup is designed and implemented on a self-built robot. The perception of the tomato is done by a fixed depth camera and a camera without depth on the gripper. The proposed dual-camera image-based visual servoing (IBVS) controller is designed to deal with the image feedback from both cameras and the proof of asymptotically convergence is provided. Furthermore, the cumulative error compensation reduces the time for the harvesting process. The experiments were conducted in the greenhouse and tested under various conditions. The time cost is formulated as a function and the success picking rate of tomatoes is 68.4%. Lu-Ching Wang, Yen-Cheng Chu, Yennun Huang, Feng-Li Lian |
ICRA | 3 |
| 2024 | Precision and Robust Models on Healthcare Institution Federated Learning for Predicting HCC on Portal Venous CT ImagesabstractHepatocellular carcinoma (HCC), the most common type of liver cancer, poses significant challenges in detection and diagnosis. Medical imaging, especially computed tomography (CT), is pivotal in non-invasively identifying this disease, requiring substantial expertise for interpretation. This research introduces an innovative strategy that integrates two-dimensional (2D) and three-dimensional (3D) deep learning models within a federated learning (FL) framework for precise segmentation of liver and tumor regions in medical images. The study utilized 131 CT scans from the Liver Tumor Segmentation (LiTS) challenge and demonstrated the superior efficiency and accuracy of the proposed Hybrid-ResUNet model with a Dice score of 0.9433 and an AUC of 0.9965 compared to ResNet and EfficientNet models. This FL approach is beneficial for conducting large-scale clinical trials while safeguarding patient privacy across healthcare settings. It facilitates active engagement in problem-solving, data collection, model development, and refinement. The study also addresses data imbalances in the FL context, showing resilience and highlighting local models' robust performance. Future research will concentrate on refining federated learning algorithms and their incorporation into the continuous implementation and deployment (CI/CD) processes in AI system operations, emphasizing the dynamic involvement of clients. We recommend a collaborative human-AI endeavor to enhance feature extraction and knowledge transfer. These improvements are intended to boost equitable and efficient data collaboration across various sectors in practical scenarios, offering a crucial guide for forthcoming research in medical AI. Chiu-Han Hsiao, Frank Yeong-Sung Lin, Tzu-Lung Sun, Yen-Yen Liao, Chih-Horng Wu, Yu-Chun Lai, Hung-Pei Wu, Pin-Ruei Liu, Bo-Ren Xiao, Yennun Huang |
IEEE J. Biomed. Health Informatics | 11 |
| 2023 | User-Driven Synthetic Dataset Generation With Quantifiable Differential PrivacyabstractRecently, releasing data to a third party for secondary analysis has become a trend of service computing. However, data owners are concerned that such a move may expose individuals’ records, which is in violation of regulations such as the European Union's General Data Protection Regulation. Differential privacy has been proposed as a possible solution to the aforementioned problem. The privacy budget$\varepsilon$in differential privacy is for theoretical interpretation, but in practice, its application in measuring the risk of data disclosure has not been well studied, especially with sampling-based synthetic datasets. Moreover, datasets released by data owners with quantifiable privacy levels and the explicit utility for these datasets have yet to be well developed. In this paper, we present an intuitive approach for defining the privacy level (i.e., data hit rate and$k$-level) and utility level (i.e., basic statistics and a series of data mining models), and the privacy budget$\varepsilon$is quantified for evaluating the risk and utility of private data. In addition, we propose two user-driven synthetic dataset hunting methods to generate a synthetic dataset with the specified privacy objective, enabling the data owner (e.g., the government and financial companies) to understand the possible privacy risk and thereby release datasets with confirmed privacy level. To the best of our knowledge, this is the first method that allows data providers to automatically generate synthetic datasets with a quantifiable privacy level for the service of open data. Bo-Chen Tai, Yao-Tung Tsou, Szu-Chuang Li, Yennun Huang, Pei-Yuan Tsai, Yu-Cheng Tsai |
IEEE Trans. Serv. Comput. | 4 |
| 2022 | A Federated Learning-Based Precision Prediction Model for External Elastic Membrane and Lumen Boundary Segmentation in Intravascular Ultrasound Images
Chiu-Han Hsiao, Tsung-Yu Peng, Wei-Chieh Huang, Hsin-I Teng, Tse-Min Lu, Frank Yeong-Sung Lin, Yennun Huang |
AINA (1) | 7 |
| 2022 | A Machine Learning-Based Model for Predicting the Risk of Cardiovascular Disease
Chiu-Han Hsiao, Po-Chun Yu, Chia-Ying Hsieh, Bing-Zi Zhong, Yu-Ling Tsai, Hao-Min Cheng, Wei-Lun Chang, Frank Yeong-Sung Lin, Yennun Huang |
AINA (1) | 9 |
| 2022 | Examining the Utility of Differentially Private Synthetic Data Generated using Variational Autoencoder with TensorFlow PrivacyabstractWith the emergence of AI(artificial intelligence), it is becoming more and more critical for organizations to utilize it to their advantage. However, organizations that possess a decent amount of data might not have the technical competence to perform machine learning, and vice versa. Hence, it is reasonable for the two kinds of organizations to work together to realize the value of the data. With the increasing concern over data privacy, regulations such as GDPR(General Data Protection Regulation) prevent an organization from sharing data with another unless the data is processed to the point that the individuals in the data are not identifiable. Various ways of data anonymization have been proposed and developed, including the ones that utilize neural networks to achieve the goal, like AE, VAE, and GAN. With the addition of a differential privacy framework like TensorFlow Privacy, privacy can be guaranteed, but data still needs to be usable after privacy protection measures are deployed. The present study aims to integrate TensorFlow Privacy into the synthetic data generation process and evaluate its usefulness for daily use in the industries. Since TensorFlow Privacy brings a provable privacy guarantee to synthetic data, the present study focuses on the evaluation of data utility. TensorFlow is widely used for machine learning in the industry and academically. TensorFlow Privacy, which is also developed by Google, can prove to be a valuable addition to the synthetic data generation pipeline. The result shows that VAE with TensorFlow Privacy 1) generates synthetic data with good data utility in most cases in terms of descriptive statistics and machine learning classification tasks, and 2) The customizable TensorFlow Privacy parameters work as intended in terms of privacy-utility trade-off. Bo-Chen Tai, Szu-Chuang Li, Yennun Huang, Pang-Chieh Wang |
PRDC | 3 |
| 2021 | Automatic Kidney Volume Estimation System Using Transfer Learning Techniques
Chiu-Han Hsiao, Ming-Chi Tsai, Frank Yeong-Sung Lin, Ping-Cherng Lin, Feng-Jung Yang, Shaoyu Yang 0003, Sung-Yi Wang, Pin-Ruei Liu, Yennun Huang |
AINA (2) | 9 |
| 2021 | Smart Machine Box with Early Failure Detection for Automatic Tool Changer Subsystem of CNC Machine Tool in the Production LineabstractThis research aims to propose an innovative smart system we developed for early failure detection of Automatic Tool Change (ATC) systems. Input data is the system's tool magazine door open/close signals. Then, 41 indicators from 26 machines are obtained from statistics-based feature extraction methods. Under the guidance of predefined risk levels, nine high-ranking top level indicators are selected using correlation and regression analysis. In addition, some lightweight supervised learning algorithms are used to build and train the model to solve the classification problem of the system states, such as Normal, Caution, and Danger. The experimental results confirm that the high-ranking indicators can achieve the most prominent and stable performance under a series of tests. Under 10-fold cross-validation, the average accuracy is 89.43 %, which is 19~38 % higher than those of other feature groups. Among them, the Naive Bayes algorithm obtains the best accuracy of 94.2 %. This proves that the proposed smart system can effectively grasp the health status of the ATC systems. Shang-Chih Lin, Shun-Feng Su, Yennun Huang |
IECON | 3 |
| 2021 | A VAE Conversion Method for Private Data LinkageabstractData linkage plays a crucial role in realizing big data's value but is often regarded as a threat to personal privacy. Regulations like GDPR requires users' consent on each specific use of data, which is not practical for data analyzers. In this study, we propose a way to address the problem by having a trustworthy third party collect data from two or more parties, then use the data to train one or more variational autoencoder (VAE) models to remove privacy and send them to the data providers. Using this model, the users express their consent to share data with a trustworthy party. The third party links data from various datasets together to build a variational autoencoder model that allows all parties to generate datasets with full attributes without revealing sensitive personal data. System architectures and machine learning accuracy of generated data sets are measured in this study. Bo-Chen Tai, Szu-Chuang Li, Yennun Huang |
PRDC | 3 |
| 2021 | (k, ε , δ)-Anonymization: privacy-preserving data release based on k-anonymity and differential privacy
Yao-Tung Tsou, Mansour Naser Alraja, Li-Sheng Chen, Yu-Hsiang Chang, Yung-Li Hu, Yennun Huang, Chia-Mu Yu, Pei-Yuan Tsai |
Serv. Oriented Comput. Appl. | 6 |
| 2019 | Evaluating Variational Autoencoder as a Private Data Release Mechanism for Tabular DataabstractMulti-market businesses can collect data from different business entities and aggregate data from various sources to create value. However, due to the restriction of privacy regulation, it could be illegal to exchange data between business entities of the same parent company, unless the users have opted-in to allow it. Regulations such as the EU's GDPR allows data exchange if data is anonymized appropriately. In this study, we use variational autoencoder as a mechanism to generate synthetic data. The privacy and utility of the generated data sets are measured. And its performance is compared with the performance of the plain autoencoder. The primary findings of this study are 1) variational autoencoder can be an option for data exchange with good accuracy even when the number of latent dimensions is low 2) plain autoencoder still provides better accuracy when the number of hidden nodes is high 3) variational autoencoder, as a generative model, can be given to a data user to generate his version of data that closely mimic the original data set. Szu-Chuang Li, Bo-Chen Tai, Yennun Huang |
PRDC | 3 |
| 2019 | Data Prefetching and Eviction Mechanisms of In-Memory Storage Systems Based on Scheduling for Big Data ProcessingabstractIn-memory techniques keep data into faster and more expensive storage media for improving performance of big data processing. However, existing mechanisms do not consider how to expedite the data processing applications that access the input datasets only once. Another problem is how to reclaim memory without affecting other running applications. In this paper, we provide scheduling-aware data prefetching and eviction mechanisms based on Spark, Alluxio, and Hadoop. The mechanisms prefetch data and release memory resources based on the scheduling information. A mathematical method is proposed for maximizing the reduction of data access time. To make the mechanisms applicable in large-scale environments, we propose a heuristic algorithm to reduce the computational time. Furthermore, an enhanced version of the heuristic algorithm is also proposed to increase the amount of prefetched data. Finally, we perform real-testbed and simulation experiments to show the effectiveness of the proposed mechanisms. Ting-Yuan Hsia, Yennun Huang, Sy-Yen Kuo |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2018 | Exploring the Relationship Between Dimensionality Reduction and Private Data ReleaseabstractIt is important to facilitate data sharing between data owners and data analysts as data owners do not always have the ability to process and analyze data. For example, governments around the world are starting to release collected data to the public to leverage data analysis competence of the crowd. However, some privacy leakage incidents have made the public to rediscover the importance of privacy protection, leading to new privacy regulations. In existing researches dimensionality reduction has played an important role in private data release mechanisms to improve utility but its influence on privacy protection has never been examined. In this study, we perform a series of experiments and found that dimensionality reduction could provide similar privacy protection effects as K-anonymity mechanisms, and it could work as a preprocessor of K-anonymity process to it to reduce the generalization and suppression needed. Bo-Chen Tai, Szu-Chuang Li, Yennun Huang, Neeraj Suri, Pang-Chieh Wang |
PRDC | 3 |
| 2018 | InfoLeak: Scheduling-Based Information LeakageabstractCovert-and side-channel attacks, typically enabled by the usage of shared resources, pose a serious threat to complex systems such as the Cloud. While their exploitation in the real world depends on properties of the execution environment (e.g., scheduling), the explicit consideration of these factors is often neglected. This paper introduces InfoLeak, an information leakage model that establishes the crucial role of the scheduler for exploiting core-private caches as covert channels. We show, formally and empirically, how the availability of these channels and the corresponding attack feasibility are affected by scheduling. Moreover, our model allows security experts to assess the related threat, posed by core-private cache covert channels for a particular system by considering solely the scheduling information. To validate the utility of InfoLeak, we deploy a covert-channel attack and correlate its success ratio to the scheduling of the attacker processes in the target system. We demonstrate the applicability of the InfoLeak model for analyzing the scheduling information for possible information leakage and also provide an example on its usage. Tsvetoslava Vateva-Gurova, Salman Manzoor, Yennun Huang, Neeraj Suri |
PRDC | 3 |
| 2018 | PPDCA: Privacy-preserving crowdsensing data collection and analysis with randomized responseabstractRandomized response mechanisms for guaranteeing crowdsensing data privacy have attracted scholarly attention; aggregators can ensure privacy by collecting only randomized data and individuals have plausible deniability regarding their responses. The analysts employed by organizations can still make predictions and conduct analyses using the randomized data. Existing randomized response-based data collection solutions have severely restricted functionality and usability, resulting in impractical and inefficient systems. Hence, we propose a randomized response-based privacy-preserving crowdsensing data collection and analysis (PPDCA) method, in which a complementary randomized response (C-RR) approach is designed to guarantee data privacy and to preserve features for data analysis. Moreover, we transform encoded data into binary vectors and generate a learning network using a deep learning framework. Through C-RR and our learning model, PPDCA can perform exceptionally in terms of high-utility analysis for the collected client-side strings, compared with state-of-the-art methods. Bo-Cheng Lin, Shang-Hong Wu, Yao-Tung Tsou, Yennun Huang |
WCNC | 4 |
| 2017 | Scheduling-Aware Data Prefetching for Data Processing Services in CloudabstractCloud computing services provide flexible computing and storage resources to process large amount of datasets. In-memory techniques keep the frequently used data into faster and more expensive storage media for improving performance of data processing services. Data prefetching aims to move data to low-latency storage media to meet requirements of performance. However, existing mechanisms do not consider how to benefit the data processing applications which do not frequently access the same datasets. Another problem is how to reclaim memory resources without affecting other running applications. In this paper, we provide a Scheduling-Aware Data Prefetching (SADP) mechanism for data processing services in a cloud data center. The SADP includes data prefetching and data eviction mechanisms. It firstly evicts the data from memory to release resources for hosting other data blocks, and then it caches the data that will be used in near future. Finally, real-testbed experiments are performed to show the effectiveness of the proposed SADP. Ting-Yuan Hsia, Yennun Huang, Sy-Yen Kuo |
AINA | 3 |
| 2017 | Data-Driven Approach for Evaluating Risk of Disclosure and Utility in Differentially Private Data ReleaseabstractDifferential privacy (DP) is a popular technique for protecting individual privacy and at the same for releasing data for public use. However, very few research efforts are devoted to the balance between the corresponding risk of data disclosure (RoD) and data utility. In this paper, we propose data-driven approaches for differentially private data release to evaluate RoD, and offer algorithms to evaluate whether the differentially private synthetic dataset has sufficient privacy. In addition to the privacy, the utility of the synthetic dataset is an important metric for differentially private data release. Thus, we also propose the data-driven algorithm via curve fitting to measure and predict the error of the statistical result incurred by random noise added to the original dataset. Finally, we present an algorithm for choosing appropriate privacy budget ∈ with the balance between the privacy and utility. Kang-Cheng Chen, Chia-Mu Yu, Bo-Chen Tai, Szu-Chuang Li, Yao-Tung Tsou, Yennun Huang, Chia-Ming Lin |
AINA | 6 |
| 2017 | K-Aggregation: Improving Accuracy for Differential Privacy Synthetic Dataset by Utilizing K-Anonymity AlgorithmabstractEnterprises and governments around the world have been attempting to leverage intelligence from the community by making formally in-house database available to the public for analyzing. The released data was often “anonymized”: sensitive attributes were removed from the dataset for privacy protection. However it is proved that masking sensitive attributes alone is not adequate for data protection. Differential privacy can be used to generate “synthetic dataset” that retain statistical properties of the original dataset and limit data-leaking risk at the same time, but there's always a trade-off between data privacy and utility. In this study we aggregate data counts across value with little counts to ease the problem of excessive error at the data value with small data count. Experiments show that K-aggregation has the potential to reduce error of count queries on value with smaller counts. Limitations of this approach are also discussed. Bo-Chen Tai, Szu-Chuang Li, Yennun Huang |
AINA | 3 |
| 2017 | Evaluating the Risk of Data Disclosure Using Noise Estimation for Differential PrivacyabstractDifferential privacy is a recent notion of data privacy protection, which does not matter even when an attacker has arbitrary background knowledge in advance. Consequently, it is viewed as a reliable protection mechanism for sensitive information. Differential privacy introduces Laplace noise to hide the true value in a dataset while preserving statistic properties. However, the large amount of Laplace noise added into a dataset is typically defined by the discursive scale parameter of the Laplace distribution. The privacy parameter ε in differential privacy is with theoretical interpretation, but the implication on the risk of data disclosure (called RoD for short) in practice has not yet been studied. Moreover, choosing appropriate value for ε is not an easy task since it impacts the level of privacy in a dataset significantly. In this paper, we define and evaluate the RoD in a dataset with either numerical or binary attributes for numerical or counting queries with multiple attributes based on the noise estimation. Through confidence probability of noise estimation, we give a simple way to choose the privacy parameter ε. Finally, we show the relation of the RoD and privacy parameter ε in experimental results. To the best of our knowledge, this is the first research work in using noise estimation to practically evaluate the RoD for multiple attributes (both numerical and binary data). Hung-Li Chen, Jia-Yang Chen, Yao-Tung Tsou, Chia-Mu Yu, Bo-Chen Tai, Szu-Chuang Li, Yennun Huang, Chia-Ming Lin |
PRDC | 7 |
| 2017 | Application Execution Time Prediction for Effective CPU Provisioning in Virtualization EnvironmentabstractProvisioning of hardware resources through virtual machines (VMs) has been widely used for supporting server consolidation and infrastructure-as-a-cloud computing. We propose NICBLE to support accurate CPU resource provisioning for application workload running on VMs. While CPU is essential for any application workload, not every workload requires the same level of CPU resource. The VM tenants may also have different expectations of application performance and preferences. NICBLE models the execution of an application workload and employs a simulation-based algorithm to predict the impact on application execution time for a hypothetical VM configuration change on the number of CPUs. One may use NICBLE to reason about whether changing the number of CPUs will significantly affect the application performance. We built the NICBLE prototype on top of the Xen hypervisor [1]. NICBLE does not require modification to the guest systems. The performance overhead on the guest system is negligible. Our evaluation indicates that NICBLE is able to provide accurate prediction with an average error rate of less than 15 percent for non-adaptive application workload. Yu-Sung Wu, Yi-Yung Chen, Chieh-Min Wang, Yennun Huang |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2015 | A Programming Framework for Implementing Fault-Tolerant Mechanism in IoT Applications
Yung-Li Hu, Yuo-Yu Cho, Wei-Bing Su, David S. L. Wei, Yennun Huang, Jiann-Liang Chen, Ing-Yi Chen, Sy-Yen Kuo |
ICA3PP (3) | 5 |
| 2015 | Network-traffic anomaly detection with incremental majority learningabstractDetecting anomaly behavior in large network traffic data has presented a great challenge in designing effective intrusion detection systems. We propose an adaptive model to learn majority patterns under a dynamic changing environment. We first propose unsupervised learning on data abstraction to extract essential features of samples. We then adopt incremental majority learning with iterative evolutions on fitting envelopes to characterize the majority of samples within moving windows. A network traffic sample is considered an anomaly if its abstract feature falls on the outside of the fitting envelope. We justify the effectiveness of the presented approach against 150000+ traffic samples from the NSL-KDD dataset in training and testing, demonstrating positive promise in detecting network attacks by identifying samples that have abnormal features. Shin-Ying Huang, Fang Yu 0001, Rua-Huan Tsaih, Yennun Huang |
IJCNN | 4 |
| 2014 | Resistant learning on the envelope bulk for identifying anomalous patternsabstractAnomalous patterns are observations that lie far away from the fitting function deduced from the bulk of the given observations. This work addresses the research issue to effectively identify anomalous patterns in both contexts of resistant learning, where there is no assumption about the fitting function form, and of changing environments. The resistant learning means that the learning procedure is not impacted significantly by the outlying observations. In literature, there is the resistant learning with searching a near-perfect fitting function for identifying the bulk of the majority of observations. However, the learning algorithm with searching a near-perfect fitting function suffers from time inefficiency. To effectively identify anomalous patterns in both contexts of resistant learning and changing environments, this study proposes a new resistant learning algorithm with envelope module that learns to evolve a nonlinear fitting function wrapped with a constant-width envelope for containing the majority of observations and thus identifying anomalous patterns. An illustrative experiment is set up to justify the effectiveness of the envelope module and the experimental result shows the positive promise. Shin-Ying Huang, Fang Yu 0001, Rua-Huan Tsaih, Yennun Huang |
IJCNN | 4 |
| 2014 | PCTopk: Privacy-and Correctness-Preserving Functional Top-k Query on Un-trusted Data Storage in Two-Tiered Sensor NetworksabstractThis paper proposes an efficient mechanism, called PCTopk, for functional top-k query with a combination of multiple conditions/dimensions in two-tiered sensor networks to simultaneously preserve data privacy and correctness (i.e., authenticity and integrity). PCTopk constructs a layered authentication tree, cooperated with an order-preserving symmetric encryption technique, for only permitting storage nodes to systematically process inquired data over encryption domain and enabling querists to efficiently verify the authentic and complete query results. To the best of our knowledge, this is the first research work on the issue of secure functional top-k query with a combination of multiple conditions in two-tiered sensor networks. The performance evaluation results show that PCTopk takes significantly less energy consumption and storage space than prior arts while preserving data privacy and correctness. Yao-Tung Tsou, Yung-Li Hu, Yennun Huang, Sy-Yen Kuo |
SRDS | 3 |
| 2013 | Design of event-based Intrusion Detection System on OpenFlow NetworkabstractOpenFlow (OF) Network is a novel network architecture many famous cloud service providers have applied it to build their data center network. The difference between OF Network and traditional network architecture is the decoupling of controller planes and data planes for network management. Intrusion detection is very important in cloud computing to improve system security. Because OF network can improve the response time of an alert by efficiently configuring network flows, we design an event-based Intrusion Detection System (IDS) architecture on OF network. Yung-Li Hu, Wei-Bing Su, Li-ying Wu, Yennun Huang, Sy-Yen Kuo |
DSN | 4 |
| 2013 | Network traffic anomaly detection based on growing hierarchical SOMabstractNetwork anomaly detection aims to detect patterns in a given network traffic data that do not conform to an established normal behavior. Distinguishing different anomaly patterns from large amount of data can be a challenge, let alone visualizing them in a comparative perspective. Recently, the unsupervised learning method such as the K-means [3], self-organizing map (SOM) [2], and growing hierarchical self-organizing map (GHSOM) [1] have been shown to be able to facilitate network anomaly detection [4][5]. However, there is no study addressing both mining and detecting task. This study leverages the advantage of GHSOM to analyze the network traffic data and visualize the distribution of attack patterns with hierarchical relationship. In the mining stage, the geometric distances between each pattern and its descriptive information are revealed in the topological space. The density and the sample size of each node can help to detect anomalous network traffic. In the detecting stage, this study extends the traditional GHSOM and uses the support vector machine (SVM) [6] to classify network traffic data into the predefined categories. The proposed approach achieves (1) help understand the behaviors of anomalous network traffic data (2) provide effective classification rule to facilitate network anomaly detection and (3) accumulate network anomaly detection knowledge for both mining and detecting purpose. The public dataset and the private dataset are used to evaluate the proposed approach. The expected result is to confirm that the proposed approach can help understand network traffic data, and the detecting mechanism is effective for identifying anomalous behavior. Shin-Ying Huang, Yennun Huang |
DSN | 2 |
| 2013 | Mining Large Network Reconnaissance DataabstractThis paper examines techniques for a large network infrastructure reconnaissance and dives into a real-world case study of a nation-wide passive network vulnerability assessment. The main goal of this study is to understand methods of a large network risk evaluation and conduct practical experiments using a national network. The main contribution of this paper is a non-intrusive method of a large network infrastructure reconnaissance and an application of acquired data to measure network vulnerability exposures within the analysed network. In this study our assumption is based on an estimation that actual threats come from the actively exploited vulnerabilities. Information on exploit-targeted platforms and vulnerabilities could be easily collected from a large set of malicious websites and automatically turned into signatures. We propose an automated method of building such signatures and use those to analyse the reconnaissance data set to identify ranges of vulnerable systems. Fedor V. Yarochkin, Yennun Huang, Yung-Li Hu, Sy-Yen Kuo |
PRDC | 2 |
| 2012 | Holography: a behavior-based profiler for malware analysisabstractSUMMARY Behavior‐based detection and signature‐based detection are two popular approaches to malware (malicious software) analysis. The security industry, such as the sector selling antivirus tools, has been using signature and heuristic‐based technologies for years. However, this approach has been proven to be inefficient in identifying unknown malware strains. On the other hand, the behavior‐based malware detection approach has a greater potential in identifying previously unknown instances of malicious software. The accuracy of this approach relies on techniques to profile and recognize accurate behavior models. Unfortunately, with the increasing complexity of malicious software and limitations of existing automatic tools, the current behavior‐based approach cannot discover many newer forms of malware either. In this paper, we implement ‘holography platform’, a behavior‐based profiler on top of a virtual machine emulator that intercepts the system processes and analyzes the CPU instructions, CPU registers, and memory. The captured information is stored in a relational database, and data mining techniques are used to extract information. We demonstrate the breadth of the ‘holography platform’ by conducting two experiments: a packed binary behavior analysis and a malvertising (malicious advertising) incident tracing. Both tasks are known to be very difficult to do efficiently using existing methods and tools. We demonstrate how the precise behavior information can be easily obtained using the ‘holography platform’ tool. With these two experiments, we show that the ‘holography platform’ can provide security researchers and automatic malware detection systems with an efficient malicious software behavior analysis solution. Copyright © 2011 John Wiley & Sons, Ltd. Shih-Yao Dai, Fedor V. Yarochkin, Yennun Huang, Sy-Yen Kuo |
Softw. Pract. Exp. | 4 |
| 2011 | Malware Profiler Based on Innovative Behavior-Awareness TechniqueabstractIn order to steal valuable data, hackers are uninterrupted research and development new techniques to intrude computer systems. Opposite to hackers, security researchers are uninterrupted analysis and tracking new malicious techniques for protecting sensitive data . There are a lot of existing analyzers can be used to help security researchers to analyze and track new malicious techniques. However, these existing analyzers cannot provide sufficient information to security researchers to perform precise assessment and deep analysis. In this paper, we introduce a behavior-based malicious software profiler, named Holography platform, to assist security researchers to obtain sufficient information. Holography platform analyzes virtualization hardware data, including CPU instructions, CPU registers, memory data and disk data, to obtain high level behavior semantic of all running processes. High level behavior semantic can provide sufficient information to security researchers to perform precise assessment and deep analysis new malicious techniques, such as malicious advertisement attack(malvertising attack). Shih-Yao Dai, Fedor V. Yarochkin, Sy-Yen Kuo, Yennun Huang |
PRDC | 5 |
| 2009 | Xprobe2++: Low volume remote network information gathering toolabstractActive operating system fingerprinting is the process of actively determining a target network system's underlying operating system type and characteristics by probing the target system network stack with specifically crafted packets and analyzing received response. Identifying the underlying operating system of a network host is an important characteristic that can be used to complement network inventory processes, intrusion detection system discovery mechanisms, security network scanners, vulnerability analysis systems and other security tools that need to evaluate vulnerabilities on remote network systems. Fedor V. Yarochkin, Ofir Arkin, Meder Kydyraliev, Shih-Yao Dai, Yennun Huang, Sy-Yen Kuo |
DSN | 5 |
| 2009 | Holography: A Hardware Virtualization Tool for Malware AnalysisabstractBehavior-based detection methods have the ability to detect unknown malicious software (malware). The success of behavior-based detection methods must depend on sufficient number of abnormal behavior models. Insufficient number of abnormal behavior models can lead to high false positive and/or false negative rates. The majority of abnormal behavior models can only be derived by observing application behavior at lower level. However the traditional approaches are not very efficient in this type of analysis. In this paper, we present Holography,a virtual hardware-level tool to capture actions of malware programs. Holography does not rely on any driver that is installed on an operating system to log the execution profile of malware programs. Instead, Holography relies on only hardware level information to capture actions of malware programs. As a result, Holography is invisible to malware programs and therefore cannot be disabled or bypassed by malware programs. Shih-Yao Dai, Fedor V. Yarochkin, Jain-Shing Wu, Chih-Hung Lin, Yennun Huang, Sy-Yen Kuo |
PRDC | 5 |
| 2009 | Towards capacity and profit optimization of video-on-demand services in a peer-assisted IPTV platform
Yih-Farn Robin Chen, Yennun Huang, Rittwik Jana, Hongbo Jiang 0001, Michael Rabinovich, Jeremy Rahe, Bin Wei 0003 |
Multim. Syst. | 2 |
| 2008 | Towards Adaptive Covert Communication SystemabstractCovert channels are secret communication paths, which existance is not expected in the original system design. Covert channels can be used as legimate tools of censorship resistance, anonimity and privacy preservation to address issues with "national" firewalls, citizen profiling and other "unethical" uses of information technology. Current steganographic methods that implement covert channels within network traffic, are highly dependent on particular media data or network protocol to hide data. In this paper we investigate the methods and an algorithm for implementing adaptive covert communication system that works on real-world Internet, capable of using multiple application-level protocols as its communication media and can be implemented as network application, therefore requires no system modifications of communicating nodes. The key difference from previous solutions is the use of adaptive redundant mechanism, which allows real-time underlying protocol switching and adaptation to the dynamic network configuration changes. Fedor V. Yarochkin, Shih-Yao Dai, Chih-Hung Lin, Yennun Huang, Sy-Yen Kuo |
PRDC | 4 |
| 2007 | Clicker - An IPTV Remote Control in Your Cell PhoneabstractThis paper investigates a novel concept of providing seamless control and portability of an IPTV viewing session. A solution employing a middleware system, a secure hardware token and a cell phone are used to demonstrate how an IPTV session can be securely controlled remotely and moved between multiple viewing stations. We have built a prototype of the system and demonstrated its flexible features. Depending on the user's protocol of choice, most remote control operations from a mobile device took less than 5 seconds to execute. An interesting capability of previewing content of other channels via the user's device while still continuing to watch the program on the viewing station differentiates it from today's IPTV offers. Finally for mobile content delivery, we address the problem of dynamic device profile selection and content adaptation using a classification algorithm to match the best content alternative destined for a mobile. Rittwik Jana, Yih-Farn Robin Chen, David C. Gibbon, Yennun Huang, Serban Jora, Bin Wei 0003 |
ICME | 4 |
| 2007 | Capacity analysis of MediaGrid: a P2P IPTV platform for fiber to the node (FTTN) networksabstractThis paper studies the conditions under which P2P sharing can increase the capacity of IPTV services over FTTN networks. For a typical FTTN network, our study shows a) P2P sharing is not beneficial when the total traffic in a local video office is low; b) P2P sharing increases the load on FTTN switches and routers in local video offices; c) P2P sharing is the most beneficial when the network bottleneck is experienced in the southbound segment of a local video office (equivalently a northbound segment of an FTTN switch); and d) sharing among all FTTN serving communities is not needed when network congestion problems are solved by using some other technologies such as program pre-caching or replication. Based on the analytical results, design for IPTV services which monitors FTTN network conditions and decides when and how to share videos among peers to maximize the service capacity. Simulations and bounds both validate the potential benefits of the MediaGrid IPTV service platform. Yennun Huang, Yih-Farn Robin Chen, Rittwik Jana, Hongbo Jiang 0001, Michael Rabinovich, Amy R. Reibman, Bin Wei 0003 |
IEEE J. Sel. Areas Commun. | 1 |
| 2007 | Self-Healing Spyware: Detection, and RemediationabstractSpyware has become a significant threat to most Internet users as it introduces serious privacy disclosure, and potential security breach to the systems. It has not only utilized critical areas of the computer system to survive reboots, but also grown resilient against current anti-spyware tools; they are capable of self-healing themselves against deletion. Because existing anti-spyware tools are stateless in the sense that they do not remember or monitor the spyware programs that were deleted, they fail to remove self-healing spyware from the system completely. This paper proposes a stateful approach that is based on characterizing spyware invasion as a trust information flow problem, and implements STARS (stateful threat-aware removal system), which is a tool that at run time monitors critical system behaviors, and ensures that removed spyware programs do not reinstall themselves, to enforce information flow policy in the system. If a reinstallation (self-healing) is detected, STARS infers the source of such activities, and discovers additional ldquosuspiciousrdquo programs. Experimental results show that STARS is effective in removing self-healing spyware programs that resist removal by existing anti-spyware tools. Yi-Min Wang, Sy-Yen Kuo, Yennun Huang |
IEEE Trans. Reliab. | 4 |
| 2006 | A Stateful Approach to Spyware Detection and RemovalabstractSpyware, a type of potentially unwanted programs (PUPs), has become a significant threat to most Internet users as it introduces serious privacy disclosure and potential security breach to the systems. Current anti-spyware tools use signatures to detect spyware programs. Over time, spyware programs have grown more resilient to this technique; they utilize critical areas of the system to survive reboots and set up mini-installers that re-install a spyware program after it's been detected and removed. Since existing anti-spyware tools are stateless in the sense that they do not remember and monitor the spyware programs that were removed, they fail to permanently remove these self-healing spyware programs. This paper proposes STARS (stateful threat-aware removal system): a tool that at run time intercepts critical system accesses and assures removed spyware does not re-install itself after a successful removal of spyware program in the system. If a re-installation (self-healing) is detected, STARS infers the source of such activities and discovers additional "suspicious" programs. Experimental results show that STARS is effective in removing self-healing spyware programs that existing anti-spyware tools fail to do Yennun Huang, Yi-Min Wang, Sy-Yen Kuo |
PRDC | 2 |
| 2006 | A Scalable Port Forwarding for P2P-Based Wi-Fi Applications
Yennun Huang, Ing-Yi Chen, Shyue-Kung Lu, Sy-Yen Kuo |
WASA | 2 |
| 2005 | An Evaluation of the Virtual Router Redundancy Protocol Extension with Load BalancingabstractVirtual router redundancy protocol (VRRP) is designed to eliminate the single point of failure in the static default routing environment in LAN. The original VRRP protocol does not support load balancing for both incoming and outgoing traffic. This paper describes EVRRP, i.e. enhanced VRRP. EVRRP supports an efficient multiple-node cluster and symmetric load balancing among routers. Each router periodically exchanges information to determine the status of the master and backups. The master router distributes and redirects the traffic to one of the backup routers by ICMP redirect message. Backup routers accept the traffic from the master and one of the backup routers takes over the master traffic using a gratuitous ARP message when the master fails. The improved election protocol speeds up the original VRRP election protocol and shortens the failover time by adding a new state in the previous VRRP state diagram and a new protocol type. An extensive evaluation of the EVRRP protocol is described in the paper. Jen-Hao Kuo, Siong-Ui Te, Pang-Ting Liao, Chun-Ying Huang, Pan-Lung Tsai, Chin-Laung Lei, Sy-Yen Kuo, Yennun Huang, Zsehong Tsai |
PRDC | 8 |
| 2005 | A Multi-Faceted Approach towards Spam-Resistible MailabstractAs checking spam became part of our daily life, unsolicited bulk e-mails (UBE) have become unmanageable and intolerable. Bulk volume of spam e-mails delivering to mail transfer agents (MTAs) is similar to the effect of denial of services (DDoS) attacks as it dramatically reduces the dependability and efficiency of networking systems and e-mail servers. Spam mails may also be used to carry viruses and worms which could significantly affect the availability of computer systems and networks. There have been many solutions proposed to filter spam in the past. Unfortunately there is no silver bullet to deter spammers and eliminate spam mails. That is, in isolation, each of existing spam protection mechanisms has its own advantages and disadvantages. In this paper, we analyze the shortcomings of existing anti-spam solutions and propose a multi-faceted approach using the spam-resistible mail agent (SRMA), which provides the most advantages and the least disadvantages of existing anti-spam solutions. Our experiments show that the proposed SRMA is immune to existing spambots and the prototype proves to be effective, feasible and deployable. Yennun Huang, Shyue-Kung Lu, Ing-Yi Chen, Sy-Yen Kuo |
PRDC | 2 |
| 2004 | Gatekeeper: Monitoring Auto-Start Extensibility Points (ASEPs) for Spyware Management
Yi-Min Wang, Roussi Roussev, Chad Verbowski, Aaron Johnson 0001, Yennun Huang, Sy-Yen Kuo |
LISA | 6 |
| 2004 | NT-SwiFT: software implemented fault tolerance on Windows NT
Deron Liang, Pi-Yu Chung, Yennun Huang, Chandra M. R. Kintala, Adam Woei-Jyh Lee, Timothy K. Tsai, Chung-Yih Wang |
J. Syst. Softw. | 3 |
| 2001 | A Checkpointing Tool for Palm Operating SystemabstractIt is foreseeable that handheld devices will be involved in the arena of distributed computing in the near future. To provide a dependable computing environment, check-pointing and rollback recovery is a useful and important technique for fault-tolerant distributed computing systems. For the most popular platform among handhelds, Palm OS, its built-in HotSync tool can take a partial snapshot of a system state, but it synchronizes only the static data in the handheld with a PC. All dynamic data of applications are lost if a failure occurs and the Palm OS is reset. In order to accommodate mobile computing devices with checkpointing and rollback recovery capability, dynamic data such as global variables should be checkpointed to tolerate system reset/crash failure. Therefore, we developed a checkpointing tool, which provides a set of APIs to checkpoint Palm applications. Using the checkpointing tool, dynamic data in a Palm device can be saved and recovered from a system reset. We describe the tool and demonstrate its usefulness in four popular Palm applications. Chi-Yi Lin, Sy-Yen Kuo, Yennun Huang |
DSN | 3 |
| 2001 | Robustness Testing and Hardening of CORBA ORB ImplementationsabstractBefore using CORBA (Common Object Request Broker Architecture) applications in mission-critical scenarios, it is important to understand the robustness of the Object Request Broker (ORB) being used, which forms the platform for CORBA applications. We have extended the Ballista software testing technique to test the exception-handling robustness of C++ ORB client-side application interfaces, and have tested two major versions of three ORB implementations on two operating systems, yielding robustness failure rates ranging from 26% to 42%. To improve ORB robustness, we also propose a probing method to harden object and pseudo-object related data types against exceptional inputs. Using these probes on omniORB 2.8 has proven to be effective in eliminating some cases of robustness failures found during testing. These results suggest that CORBA implementations currently have significant robustness vulnerabilities, but that some important classes of problems can be overcome with better exception-handling approaches. Jiantao Pan, Philip Koopman, Daniel P. Siewiorek, Yennun Huang, Robert Gruber, Mimi Ling Jiang |
DSN | 4 |
| 1999 | An Accelerative Pre-Allocation Protocol for Wavelength Division Multiplexing Star-Coupled NetworksabstractFor the wavelength division multi-access system (WDMA), the reservation approach and the pre-allocation approach are two major media access protocols to support the packet-switched traffic. In this paper, a new media access control (MAC) protocol, the AP-WDMA (accelerative pre-allocation), is proposed for the WDMA. Although implemented on a simple basic architecture, it does provide a better media access protocol which can be easily extended to all the WDMA. Through evaluations, the AP-WDMA is shown to be able to overcome the wavelength limitation through a channel sharing mechanism and enable efficient transmission with the accelerative mechanism. The AP-WDMA relieves these technology constraints restricting the tunability to only one end and the table size to only n+2 memory spaces, where n is the number of stations. Chuan-Ching Sue, Wen-Yu Tseng, Sy-Yen Kuo, Yennun Huang |
ISCC | 4 |
| 1999 | A Simple and Efficient Deadlock Recovery Scheme for Wormhole Routed 2-Dimensional MeshesabstractIn order to avoid deadlocks, prevention-based routing algorithms impose certain routing restrictions which lead to high hardware complexity or low adaptability. If deadlock occurrences are extremely rare, recovery-based routing algorithms become more attractive with respect to hardware complexity and routing adaptability. A simple architecture where each router is provided with an additional special flit buffer was developed to achieving deadlock recovery. Disha-SEQ and Disha-CON are two deadlock recovery schemes based on such an architecture to accomplish sequential recovery and concurrent recovery, respectively. In this paper, we propose a simple recovery scheme for a 2D mesh with the same router architecture, and reduce drawbacks in Disha-SEQ or Disha-CON, such as hardwired tokens, finding the Hamiltonian cycle, Hamiltonian path labeling for each node, and non-minimal path routing. Moreover, the simulation results show that the proposed scheme has a similar performance to Disha-CON and is better than Disha-SEQ. Shih-Chang Wang, Hung-Yau Lin, Sy-Yen Kuo, Yennun Huang |
PRDC | 4 |
| 1999 | Issues in the Design of a Reflective Library for Checkpointing C++ ObjectsabstractObject Persistence is an important feature of Object-oriented languages. The C++ language specification does not include or discuss any method of providing persistence for C++ objects. Several schemes have been developed for adding persistence to C++. Some of them require persistent objects to be allocated and treated differently than non-persistent objects, while some others require the programmer to provide vital parts of the persistence mechanism. It is desirable to make the persistence feature transparent, but the nature of C++ makes it difficult. This paper discusses in detail the various interesting language issues to be considered for adding persistence to C++ and how they lead to the design of the reflective object-checkpointing library, MemberAnalyzer. Mangesh Kasbekar, Chita R. Das, Shalini Yajnik, Reinhard Klemm, Yennun Huang |
SRDS | 5 |
| 1998 | Checkpoints-on-Demand with Active ReplicationabstractCheckpointing and roll-back recovery is a well known technique for recovering from software process failures. Analytical models have been developed for computing the completion time of processes that use various checkpointing strategies such as periodic checkpointing, random checkpointing etc. In this paper, we show that with active replication of processes, a strategy that uses a mechanism we call checkpoints-on-demand will result in an expected completion time smaller than that can be achieved with traditional schemes that use periodic checkpoints. With checkpoints-on-demand, when a process fails, it is recovered from an induced checkpoint taken of a replica of the process. Recovery of persistent server processes through state-transfer from a replica has been proposed in the context of group communication systems and in the process cloning approach of the Delta-4 architecture. But it has not been previously proposed and analyzed as a mechanism for reducing the expected completion time of a long running process. Sampath Rangarajan, Sachin Garg, Yennun Huang |
SRDS | 3 |
| 1997 | Xept: a software instrumentation method for exception handlingabstractModern software systems are often built from existing library components. A common problem is how to fix bugs when source code is not available. Xept is an instrumentation language and tool that can be used to add to object code the ability to detect, mask, recover and propagate exceptions from library functions. This helps to alleviate or avoid a large class of errors resulting from function misuses. Examples are given to show applications of Xept in actual software systems. Kiem-Phong Vo, Yi-Min Wang, Pi-Yu Chung, Yennun Huang |
ISSRE | 4 |
| 1997 | STL: a tool for on-line software update and rejuvenation (Abstract)abstractSummary form only given, as follows. A large number of tools and techniques have been developed in the past to achieve a 24/spl times/7 system availability (24 hours a day and 7 days a week) by reducing unscheduled system downtime due to failures. However, a highly available or fault-tolerant system may still have to be taken off-line for software and hardware updates, maintenance and rejuvenation. Therefore, the scheduled downtime for maintenance could become the major source of system unavailability. One big challenge in a highly available system is to keep the system running while it is undergoing software updates or bug fixes. In this paper, we describe a tool that can be used to perform an online update of software in a cluster environment. The tool consists of a protocol compiler (stgen) and a library (libst) for marshaling and unmarshaling data during a software update. The tool has the ability to transfer complex data structures between two processes even if the data definitions in the two processes are different. The data transfer format is machine-independent. Hence, the tool can transfer data across processes running on different machine types. The paper describes some real-life applications of the tool and presents performance measurements of the tool for these applications. Shalini Yajnik, Yennun Huang |
ISSRE | 2 |
| 1997 | On the Scalability and Mean-Time to Failure of k Resilient Protocols
Sampath Rangarajan, Yennun Huang, Satish K. Tripathi |
Acta Informatica | 2 |
| 1997 | ONE-IP: Techniques for Hosting a Service on a Cluster of Machines
Om P. Damani, Pi-Yu Chung, Yennun Huang, Chandra M. R. Kintala, Yi-Min Wang |
Comput. Networks | 3 |
| 1997 | Progressive Retry for Software Failure Recovery in Message-Passing ApplicationsabstractA method of execution retry for bypassing software faults in message-passing applications is described in this paper. Based on the techniques of checkpointing and message logging, we demonstrate the use of message replaying and message reordering as two mechanisms for achieving localized and fast recovery. The approach gradually increases the rollback distance and the number of affected processes when a previous retry fails, and is therefore named progressive retry. Examples from telecommunications software systems and performance measurements from an application-level implementation are described to illustrate the benefits of the scheme. Yi-Min Wang, Yennun Huang, W. Kent Fuchs, Chandra M. R. Kintala, Gaurav Suri |
IEEE Trans. Computers | 2 |
| 1996 | Minimizing Completion Time of a Program by Checkpointing and RejuvenationabstractCheckpointing with rollback-recovery is a well known technique to reduce the completion time of a program in the presence of failures. While checkpointing is corrective in nature, rejuvenation refers to preventive maintenance of software aimed to reduce unexpected failures mostly resulting from the "aging" phenomenon. In this paper, we show how both these techniques may be used together to further reduce the expected completion time of a program. The idea of using checkpoints to reduce the amount of rollback upon a failure is taken a step further by combining it with rejuvenation. We derive the equations for expected completion time of a program with finite failure free running time for the following three cases when; (a) neither checkpointing nor rejuvenation is employed, (b) only checkpointing is employed, and finally (c) both checkpointing and rejuvenation are employed.We also present numerical results for Weibull failure time distribution for the above three cases and discuss optimal checkpointing and rejuvenation that minimizes the expected completion time. Using the numerical results, some interesting conclusions are drawn about benefits of these techniques in relation to the nature of failure distribution. Sachin Garg, Yennun Huang, Chandra M. R. Kintala, Kishor S. Trivedi |
SIGMETRICS | 2 |
| 1996 | Developing reliable applications on cluster systemsabstractA cluster is a group of computers which are loosely connected together to provide fast and reliable services. There have been many applications built on cluster systems such as distributed/parallel database applications, telecommunication systems and, recently, internet/intranet servers. Cluster systems can deliver similar or better performance and reliability than traditional mainframes, supercomputers and fault-tolerant systems with a much lower hardware cost. Yennun Huang |
SRDS | 1 |
| 1995 | Computing Reliability Intervals for k-Resilient Protocolsabstractk-resilient protocols are used in some parallel and distributed system applications for increased availability of resources. A protocol running on an n site system is k resilient if it could tolerate up to k failures and operate correctly. The reliability of such a protocol is defined as the probability that no more than k sites have failed. Such a k-resilient protocol is beneficial only when its reliability is greater than the reliability of a protocol running on a system with a single site. We consider k-resilient protocols and develop a general technique for approximately computing the time until which these protocols have higher reliability than protocols running on single site systems. We call this time the reliability interval. Our general techniques for computing the reliability interval can be used irrespective of the type of failure distribution (with respect to time) of the sites of the system. We use experimental results to validate our technique.> Sampath Rangarajan, Yennun Huang, Satish K. Tripathi |
IEEE Trans. Computers | 2 |
| 1995 | Parallel architectures for processing high speed network signaling protocolsabstractWe study the effectiveness of different parallel architectures for achieving the high throughputs and low latencies needed in processing signaling protocols for high speed networks. A key performance issue is the trade off between the load balancing gains and the call record management overhead. Arranging processors in large groups potentially yields higher load balancing gains but also incurs higher overhead in maintaining consistency among the replicated copies of the call records. We study this tradeoff and its impact on the design of protocol processing systems for two generic classes of parallel architectures, namely, shared memory and distributed memory architectures. In shared memory architectures, maintaining a common message queue in the shared memory can provide the maximal load balancing gains. We show, however, in order to optimize performance it is necessary to organize the processors in small groups since large groups result in higher call record management overhead. In distributed memory architectures with each processor maintaining its own message queue there is no inherent provision for load balancing. Based on a detailed simulation analysis we show that organizing the processors into small groups and using a simple distributed load balancing scheme yields modest performance gains even after call record management overheads are taken into account. We find that the common message queue architecture outperforms the distributed architecture in terms of lower response time due to its improved load balancing capability. Finally, we do a fault-tolerance analysis with respect to the call-record data structure. Using a simple failure recovery model of the processors and the local memory, we show that in the case of shared memory architecture, the availability is also optimized when processors are organized in small groups. This is because when comparing architectures the higher call record management overhead incurred for larger group sizes must be accounted for as system unavailability. Dipak Ghosal, T. V. Lakshman, Yennun Huang |
IEEE/ACM Trans. Netw. | 3 |
| 1994 | High-Speed Protocol Processing Using Parallel ArchitecturesabstractThe authors study the effectiveness of different parallel architectures for achieving high throughputs necessary for processing signaling traffic in high speed networks. They consider shared memory and distributed memory parallel architectures for processing signaling messages. A key performance issue is the trade-off between load balancing gains and call record management overhead; arranging processors in large groups potentially yields higher load balancing gains but also incurs higher overhead in maintaining consistency amongst the replicated copies of the call records. They study this tradeoff and its impact on the choice of optimal parallel architectures for protocol processing. The results show that for shared memory architectures, which provide the maximal load balancing gains, organizing the processors in small groups optimizes the performance for a wide range of traffic loads. For distributed memory architectures, which do not inherently provide any load balancing, organizing the processors into small groups and using a simple distributed load balancing scheme yields modest performance gains even after call record management overheads are taken into account. A good architecture is a hybrid one using a distributed architecture in which each node is a small processing group with shared memory.> Dipak Ghosal, T. V. Lakshman, Yennun Huang |
INFOCOM | 3 |
| 1993 | Resource Allocation for Primary-Site Fault-Tolerant SystemsabstractResource allocation for a distributed system employing the primary site approach for fault tolerance is discussed. Two kinds of systems are considered. The first consists of fault-tolerant nodes where each node has many duplicated servers. One server is the primary, which serves user requests, and the rest are backup. The second does not have fault-tolerant nodes. To tolerate node failures, each node uses other nodes as backups. When a node fails, all requests initially allocated to the node are served by one of its backups. To study the resource allocation for such systems, an approximate model for each system is developed. Using these models, efficient allocation algorithms that take into account the failure/repair rates of the system and the fault-tolerant overheads are presented. Using experimental results, it is shown that the algorithms give the optimal or suboptimal allocations. The algorithms, which incur little overhead, can improve the system performance significantly over an intuitive allocation algorithm.> Yennun Huang, Satish K. Tripathi |
IEEE Trans. Software Eng. | 1 |
| 1992 | On the Availability of Parallel Protocol-Processing Systems
Yennun Huang, T. V. Lakshman, Dipak Ghosal |
ICPP (3) | 1 |
| 1992 | Computing Threshold Times for k-Resilient Protocols
Sampath Rangarajan, Yennun Huang, Satish K. Tripathi |
ICPP (2) | 2 |
| 1992 | Effect of Fault Tolerance on Response Time-Analysis of the Primary Site ApproachabstractThe effect of the primary site approach for fault tolerance on the response time is studied. In the primary site approach, the service to be made fault tolerant is replicated at many nodes, one of which is designated as primary and the others as backups. All the requests for operations on the data object are sent to the primary site. The primary fails, one of the backups takes over as primary. The primary site periodically checkpoints its state on the backups. An analytical model for studying the average response time of the primary site system and analyzing the effects of the checkpointing frequency and the degree of replication on the response time is presented. This model is used to compare the response time of the system to that of a system without any fault tolerance.> Yennun Huang, Pankaj Jalote |
IEEE Trans. Computers | 1 |
| 1991 | Effective Load and Resource Sharing in Parallel Protocol-Processing Systems
T. V. Lakshman, Dipak Ghosal, Yennun Huang, Satish K. Tripathi |
ICPP (1) | 3 |
| 1989 | Availability Analysis of the Primary Site Approach for Fault ToleranceabstractThe primary site approach is often used to support fault tolerance against node failures. The authors present an analytic model to evaluate the availability of a system using the primary site approach. The effect of the number of replicas and the checkpoint interval were studied using the model. The authors found that the optimal checkpoint interval is proportional to the square root of the checkpoint overhead and inversely proportional to the request arrival rate. For the degree of replication, the results depend on what kind of checkpointing scheme is used. In systems using the broadcasting scheme, it was found that there is no optimal degree of replication: increasing the degree of replication increases the availability. However, in systems using the point-to-point checkpointing scheme, an optimal degree of replication exists: increasing the degree of replication beyond this optimum decreases the availability. Although the authors only consider a single repair server in the system, the model can easily be extended to allow multiple repair servers.> Yennun Huang, Pankaj Jalote |
SRDS | 1 |
| 1989 | Analytic Models for the Primary Site Approach to Fault-Tolerance
Yennun Huang, Pankaj Jalote |
Acta Informatica | 1 |
| 1987 | Local Area Networks: Software and Related IssuesabstractIn this paper, we present a review of the issues that affect the software requirements for a local area network. We introduce protocols for the local area networks and characterize their software needs. Two approaches to operating systems are outlined and examples of each approach are presented. Various applications which use local area networks and performance issues are also discussed. Satish K. Tripathi, Yennun Huang, Sushil Jajodia |
IEEE Trans. Software Eng. | 2 |