Eric Keller

dblp:87/2882 · DBLP profile ↗
← Back
56ranked-venue papers
9as first author
13since 2021 · last 2026
0000-0003-2556-9394ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 19 · 4 first-author · 5 since 2021Computer networks · 19 · 3 first-author · 6 since 2021Artificial intelligence and machine learning · 9 · 2 first-authorSecurity and privacy · 5 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 3Software engineering, systems software and programming languages · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Dynamic NUMA-Aware Data Structure Replication
Erika Hunhoff, Zack McKevitt, Ankit Bhardwaj 0002, Reto Achermann, Gerd Zellweger, Marcos K. Aguilera, Eric Keller
IPDPS7
2026 DeepSFU: Scalable Deepfake Detection for Video Conferencing
abstract
Deepfakes have emerged as a significant threat to online communications, enabling nearly indistinguishable impersonation of executives, public figures, and trusted contacts during video calls. While state-of-the-art deepfake detection models can achieve high accuracy offline, deploying them in real-time video conferencing systems remains challenging: the added computation quickly violates interactive latency budgets and greatly limits scalability. Our empirical analysis reveals that video decoding and frame movement dominate the detection pipeline, together accounting for approximately 86.6% of per-frame processing time.
Shirin Ebadi, S. M. H. Hosseini, Woongsub Shin, Evan Ram, Youngwook Son, Seyeon Kim 0001, Nam Bui, Kyunghan Lee, Eric Keller, Sangtae Ha
SIGCOMM10
2026 Di5Guise: 5G Privacy with vSIM
abstract
SIM cards have been the key building block of user authentication and security in cellular networks. While they are meant to serve as privacy protecting elements in cellular communications, they can be the root cause of privacy loss. Current eSIMs come with a fixed device profile—comprising a secret key, a certificate, and a unique eUICC identifier—that permanently binds every subscriber profile provisioned on the device to that device profile. This binding enables an attacker with the vantage point of a cellular operator to correlate subscriber identities back to a single device, piecing together a complete pattern of life—online activities, movement patterns, and real-world identity—even when users rotate subscriber identities or employ traffic obfuscation techniques. To mitigate this concern, we introduce Di5Guise, a privacy-enhancing architecture that breaks this correlation at its root by decoupling the device identity from the subscriber identity. Central to Di5Guise is vSIM, a virtualized SIM card that enables dynamic device profile provisioning, allowing each subscriber profile to be associated with a distinct, unlinkable device profile. Di5Guise establishes trust with the operator by ensuring that vSIM is running on secure hardware in a trustworthy state. We prototype Di5Guise on a Field Programmable Gate Array (FPGA) board and integrate it with srsRAN to demonstrate full compatibility with existing 5G infrastructure. Using a complex user correlation model, we show that Di5Guise reduces user re-identification accuracy from 93% to 49% when combined with obfuscation.
Shirin Ebadi, Zach Moolman, Tamara Silbergleit Lehman, Eric Keller
Proc. Priv. Enhancing Technol.4
2025 THORN-ML: Transparent Hardware Offloaded Resilient Networks for RDMA based Distributed ML Workloads
abstract
Distributed deep learning (DDL) requires a great investment in cloud infrastructure, including accelerated compute nodes and networking hardware capable of supporting high-performance networking, e.g., Remote Direct Memory Access (RDMA). When a host running a DDL application becomes unreachable, the cost can be high as application-level failure recovery is slow and disruptive. When the host is unreachable due to host failure, this is unavoidable; however, when the network components involved in attaching the host to the core data center network fail, we argue that this cost is avoidable. This paper introduces THORN-ML, a hardware-offloaded resilient network architecture that is completely transparent to DDL applications and works with commodity hardware. We evaluate THORN-ML on a cluster of 5 nodes with Nvidia A100 GPUs and Mellanox ConnectX-5 NICs, with several applications leveraging model parallelism and/or data parallelism, and find that THORN-ML reduces disruption from minutes (impacting the whole cluster) to milliseconds (impacting packets that can be re-transmitted).
Maziyar Nazari, Daniel Noland, Giulio Sidoretti, Erika Hunhoff, Tamara Silbergleit Lehman, Eric Keller
SoCC6
2025 Efficiency, Expressivity, and Extensibility in a Close-to-Metal NPU Programming Interface
abstract
Accelerators such as neural processing units (NPUs) deliver an enticing balance of performance and efficiency compared to general purpose compute architectures. However, effectively leveraging accelerator capabilities is not always simple: low-level programming toolkits may require substantial developer effort while high-level programming toolkits may abstract critical optimization features. This work aims to increase efficiency of designers using IRON, a toolkit for close-to-metal NPU performance engineers. We provide an updated programmer interface to IRON containing new and refined programming constructs. The new interface includes extensible features for placement and data transformation. These contributions are evaluated in terms of 1) efficiency, with analysis showing ~ 26% average reduction in lines of code and decreases in Halstead metrics for a variety of designs; 2) expressivity, demonstrating the new interface supports the wide range of features and patterns already supported by IRON; and 3) extensibility, illustrating the new tooling for placement and tiling can be extended to accommodate common use-cases.
Erika Hunhoff, Joseph Melber, Kristof Denolf, Andra Bisca, Samuel Bayliss, Stephen Neuendorffer, Jeff Fifield, Jack Lo, Pranathi Vasireddy, Phil James-Roxby, Eric Keller
FCCM11
2025 DND-Db: A Democratized Network Data Database for Tailored Routing and Security Campaigns
abstract
Despite the desire to fix BGP underlying security shortcomings, present solutions, such as RPKI, have struggled to achieve broad adoption. Focusing on providers' needs first can incentivize the adoption of platforms that better enable the integration of security mechanisms, thereby overcoming stagnation and deployment barriers. To demonstrate this concept, we propose a real-time global routing database of network data that providers could leverage to support the management, troubleshooting, and business needs of their own networks. We show how broadly sharing information about networks, such as link usage and cost, can be leveraged to obtain business optimal routing decisions that could reduce provider transit costs by an average of 10% over standard BGP route selection or to provide route selection based on customer-defined security requirements-incentives for a business to adopt. We then leverage the same database to show how security solutions, similar to RPKI and BGPsec, could easily be adopted to further enhance internet security outcomes, demonstrating an incentivized approach to security adoption.
Karl Olson, Bashayer Alharbi, Greg Cusack, Eric Keller
NOMS4
2024 LinuxFP: Transparently Accelerating Linux Networking
abstract
This paper introduces transparent acceleration into the Linux networking stack. To do so, we build on years of research in creating high-performance software-based packet processing systems. Rather than treating these technologies as alternative pipelines, we leverage the technology to create explicit fast paths in the Linux kernel. With this, Linux still serves as a complete implementation of all its supported protocols, but frequent operations on the critical path can be transparently han-dled by a fast path. We implement a controller that continuously introspects the Linux kernel to determine exactly what packet-processing functionality is currently configured. The controller then synthesizes and deploys a minimal fast past into the packet processing pipeline that only implements functionality that is currently needed. In this way, common command line tools, such as brctl, control plane software, such as FRRouting (FRR), and higher-level management frameworks such as Kubernetes and Ansible, work without modification and transparently benefit from a faster network data plane. Our system, LinuxFP, includes a controller that can implement IP forwarding, bridging, and IP filtering fast paths that are synthesized on-demand using their specific and current configuration in the kernel. We evaluate performance improvements using Linux management tools and a Kubernetes network plugin. We show performance improvements over Linux for packet forwarding of 77 % and 20 % for an unmodified Kubernetes network plugin.
Marcelo Abranches, Erika Hunhoff, Rohan Eswara, Oliver Michel, Eric Keller
ICDCS5
2023 Detecting Unseen Anomalies in Network Systems by Leveraging Neural Networks
abstract
Despite all the progress achieved in recent years in detecting anomalies in network systems, detecting unseen anomalies such as zero-day attacks still remained a challenging task. Traditional signature-based Network Intrusion Detection Systems (NIDS) cannot detect such anomalies as there exists no known signature for them. Moreover, Machine Learning-based (ML-based) NIDS trained with a vanilla supervised learning method cannot detect them as they come from a different distribution compared to what the model has been trained on. Domain adaptation techniques help transfer the knowledge gained from a labeled source domain to an unlabeled target domain. Such techniques have the potential to make a model trained on a dataset containing a few network attacks to detect new types of anomalies that might happen in the future. However, recent domain adaptation methods have been mostly designed for images and provide very limited benefits when applied to network traffic. In this paper, we introduce Proportional Progressive Pseudo-Labeling (PPPL), an effective approach for building a more general domain adaptation technique that can be leveraged to detect unseen anomalies in network systems. At the beginning of the training phase, PPPL progressively reduces target domain classification error, by training the model directly with pseudo-labeled target domain samples, while excluding samples with pseudo-labels that are more likely to be wrong from the training set and postponing training on such samples. Our evaluation conducted on the CICIDS2017 dataset shows that PPPL can significantly outperform other baselines in detecting unseen anomalies with up to 58% improvement based on the average F1 score.
Eric Keller, Saeid Tizpaz-Niari
IEEE Trans. Netw. Serv. Manag.2
2022 Getting back what was lost in the era of high-speed software packet processing
abstract
The need for high performance and custom software-based packet processing has resulted in decades of research. Most proposals bypass or replace the Linux networking stack with the unfortunate consequence of sacrificing the rich and robust functionality available within Linux and the ecosystem of management programs and control-plane software built on top of it. In this paper, we propose to rethink the design of the Linux network stack to address its shortcomings rather than creating alternative pipelines. This re-design involves (1) decomposing packet processing into a fast path and a slow path, and (2) transparently and dynamically creating a custom fast path that only implements the processing tasks currently configured. We leverage Linux's eXpress Data Path to load efficient and small fast-path modules, leaving the kernel stack to serve as the slow path. To materialize this vision, this paper introduces Transparent Network Acceleration (TNA), a prototype system that automatically generates a minimal data path based on introspection of the current networking configuration, avoiding many of the networking stack overheads in Linux while ensuring high performance and maintaining Linux's rich set of functionalities.
Marcelo Abranches, Oliver Michel, Eric Keller
HotNets3
2022 Escra: Event-driven, Sub-second Container Resource Allocation
abstract
This paper pushes the limits of automated resource allocation in container environments. Recent works set container CPU and memory limits by automatically scaling containers based on past resource usage. However, these systems are heavy- weight and run on coarse-grained time scales, resulting in poor performance when predictions are incorrect. We propose Escra, a container orchestrator that enables fine-grained, event- based resource allocation for a single container and distributed resource allocation to manage a collection of containers. Escra performs resource allocation on sub-second intervals within and across hosts, allowing operators to cost-effectively scale resources without performance penalty. We evaluate Escra on two types of containerized applications: microservices and serverless functions. In microservice environments, fine-grained and event- based resource allocation can reduce application latency by up to 96.9% and increase throughput by up to 3.2x when compared against the current state-of-the-art. Escra can increase performance while simultaneously reducing 50th and 99th%ile CPU waste by over 10x and 3.2x, respectively. In serverless environments, Escra can reduce CPU reservations by over 2.1x and memory reservations by more than 2x while maintaining similar end-to-end performance.
Greg Cusack, Maziyar Nazari, Sepideh Goodarzy, Erika Hunhoff, Prerit Oberai, Eric Keller, Eric Rozner, Richard Han 0001
ICDCS6
2021 Infinity: A Scalable Infrastructure for In-Network Applications
Marcelo Abranches, Karl Olson, Eric Keller
IM3
2021 StepNet: A Compositional Framework with Reduced Querying for Homing Complex Network Services
Azzam Alsudais, Shankaranarayanan Puzhavakath Narayanan, Bharath Balasubramanian, Zhe Huang 0001, Eric Keller
IM5
2021 Software Packet-Level Network Analytics at Cloud Scale
abstract
As networks grow in speed, scale, and complexity, operating them reliably requires continuous monitoring and increasingly sophisticated analytics. Because of these requirements, the platforms that support analytics in cloud-scale networks face demands for both higher throughput (to keep up with high packet rates) and increased generality and programmability (to cover a wider range of applications). Recent proposals have worked toward these goals by offloading analytics application logic to line-rate programmable data plane hardware, as scaling existing software analytics platforms is prohibitively expensive. The rigid design and constrained resources of data plane devices, however, fundamentally limit the types of analysis and the number of tasks that can run concurrently. In this article, we demonstrate that generality need not be sacrificed for high performance. Rather than offloading entire analytics applications to hardware, the core idea of our work is to offload only critical preprocessing tasks that are shared among applications (e.g., load balancing) to a line-rate hardware frontend while optimizing the core analytics software to exploit properties of network analytics workloads. Based on this design, we present Jetstream, a hybrid platform for network analytics that can run custom software-based analytics pipelines at throughputs of up to 250 million packets per second on a 16-core commodity server. Jetstream makes sophisticated, network-wide packet analytics feasible without compromising on generality or performance.
Oliver Michel, John Sonchack, Greg Cusack, Maziyar Nazari, Eric Keller, Jonathan M. Smith
IEEE Trans. Netw. Serv. Manag.5
2020 General Domain Adaptation Through Proportional Progressive Pseudo Labeling
abstract
Domain adaptation helps transfer the knowledge gained from a labeled source domain to an unlabeled target domain. During the past few years, different domain adaptation techniques have been published. One common flaw of these approaches is that while they might work well on one input type, such as images, their performance drops when applied to others, such as text or time-series. In this paper, we introduce Proportional Progressive Pseudo Labeling (PPPL), a simple, yet effective technique that can be implemented in a few lines of code to build a more general domain adaptation technique that can be applied on several different input types. At the beginning of the training phase, PPPL progressively reduces target domain classification error, by training the model directly with pseudo-labeled target domain samples, while excluding samples with more likely wrong pseudo-labels from the training set and also postponing training on such samples. Experiments on 6 different datasets that include tasks such as anomaly detection, text sentiment analysis and image classification demonstrate that PPPL can beat other baselines and generalize better.
Eric Keller
IEEE BigData2
2020 FluidMem: Full, Flexible, and Fast Memory Disaggregation for the Cloud
abstract
This paper presents a new approach to memory disaggregation called FluidMem that leverages the userfault mechanism in Linux to achieve full memory disaggregation in software. FluidMem enables dynamic and transparent resizing of an unmodified Virtual Machine’s (VM’s) memory footprint in the cloud. As a result, a VM’s memory footprint can seamlessly scale over multiple machines or even be downsized to a near-zero footprint on a given server. FluidMem’s architecture provides flexibility to cloud operators to manage remote memory without requiring guest intervention, while also supporting paging out the entirety of a VM’s pages within its address space. FluidMem integrates with a remote memory backend in a modular way, easily supporting systems such as RAMCloud to harness remote memory. We demonstrate FluidMem outperforms an existing memory disaggregation approach based on network swap. Microbenchmarks are evaluated to characterize the latency of different components of the FluidMem architecture, and two memory-intensive applications are demonstrated using FluidMem, the Graph500 benchmark, and MongoDB. Additionally, we show FluidMem can flexibly and efficiently grow and shrink the memory footprint of a VM as defined by a cloud provider.
Blake Caldwell, Sepideh Goodarzy, Sangtae Ha, Richard Han 0001, Eric Keller, Eric Rozner, Youngbin Im
ICDCS5
2020 Resource Management in Cloud Computing Using Machine Learning: A Survey
abstract
Efficient resource management in cloud computing research is a crucial problem because resource over-provisioning increases costs for cloud providers and cloud customers; resource under-provisioning increases the application latency, and it may violate service level agreements, which eventually makes cloud providers lose their customers and income. As a result, researchers have been striving to develop optimal resource management in cloud computing environments in different ways, such as container placement, job scheduling and multi-resource scheduling. Machine learning techniques are extensively used in this area. In this paper, we present a comprehensive survey on the projects that leveraged machine learning techniques for resource management solutions in the cloud computing environment. At the end, we provide a comparison between these projects. Furthermore, we propose some future directions that will guide researchers to advance this field.
Sepideh Goodarzy, Maziyar Nazari, Richard Han 0001, Eric Keller, Eric Rozner
ICMLA4
2019 Breaking the Trust Dependence on Third Party Processes for Reconfigurable Secure Hardware
abstract
Modern CPU designs are beginning to incorporate secure hardware features, but leave developers with little control over both the set of features and when and whether updates are available. Reconfigurable logic (e.g., FPGAs) has been proposed as an alternative as it is both hardware, so can have similar capabilities at a reasonable performance degradation, and programmable, allowing customization of the secure hardware. This programmability, however, opens new attack vectors that allow an adversary to re-program the FPGA. Past attempts to solve this rely on a party maintaining a shared key with the FPGA, but these business processes to keep that key secret have been shown to be quite vulnerable. In this paper, we propose a new mechanism which eliminates the trust dependence on third party processes. This new mechanism consists of a self-provisioning stage, where keys are generated internal to the FPGA and never exposed externally, coupled with a secure update mechanism which allows updates to be governed by a policy defined by the secure hardware application. To demonstrate, we fully implemented these mechanisms on a Xilinx Zynq UltraScale+ FPGA along with an example secure co-processor with remote attestation with a flexible root of trust (in contrast to Intel SGX which fixes the root of trust to be Intel). Our performance evaluation of two applications, a password manager and a contact matching application, illustrates using FPGAs is practical.
Aimee Coughlin, Greg Cusack, Jack Wampler, Eric Keller, Eric Wustrow
FPGA4
2019 FOCUS: Scalable Search Over Highly Dynamic Geo-distributed State
abstract
Finding nodes which match certain criteria, based on potentially highly dynamic information, is a critical need in many distributed systems, ranging from cloud management, to network service deployments, to emerging IoT applications. With the increasing scale, dynamicity, and richness of data, existing systems, which typically implement a custom solution based around message queues where nodes push status to a central database, are ill-suited for this purpose. In this paper, we present FOCUS, a general and scalable service which easily integrates into existing and emerging systems to provide this fundamental capability. FOCUS utilizes a gossip-based protocol for nodes to organize into groups based on attributes and current value. With this approach, nodes need not synchronize with a central database, and instead the FOCUS service only needs to query the sub-set of nodes which have the potential to positively match a given query. We show FOCUS's flexibility through an operational example of complex querying for Virtual Network Functions instantiation over cloud sites, and illustrate its ease of integration by replacing the push-based approach in OpenStack's placement service. Our evaluation demonstrates a 5-15× reduction in bandwidth consumption and an ability to scale much better than existing approaches.
Azzam Alsudais, Zhe Huang 0001, Bharath Balasubramanian, Shankaranarayanan Puzhavakath Narayanan, Eric Keller, Kaustubh R. Joshi
ICDCS6
2018 Making Serverless Computing More Serverless
abstract
In serverless computing, developers define a function to handle an event, and the serverless framework horizontally scales the application as needed. The downside of this function-based abstraction is it limits the type of application supported and places a bound on the function to be within the physical resource limitations of the server the function executes on. In this paper we propose a new abstraction for serverless computing: a developer supplies a process and the serverless framework seamlessly scales out the process's resource usage across the datacenter. This abstraction enables processing to not only be more general purpose, but also allows a process to break out of the limitations of a single server – making serverless computing more serverless. To realize this abstraction, we propose ServerlessOS, comprised of three key components: (i) a new disaggregation model, which leverages disaggregation for abstraction, but enables resources to move fluidly between servers for performance; (ii) a cloud orchestration layer which manages fine-grained resource allocation and placement throughout the application's lifetime via local and global decision making; and (iii) an isolation capability that enforces data and resource isolation across disaggregation, effectively extending Linux cgroup functionality to span servers.
Zaid Al-Ali, Sepideh Goodarzy, Ethan Hunter, Sangtae Ha, Richard Han 0001, Eric Keller, Eric Rozner
IEEE CLOUD6
2018 Turboflow: information rich flow record generation on commodity switches
abstract
Fine-grained traffic flow records enable many powerful applications, especially in combination with telemetry systems that supports high coverage, i.e., of every link and at all times. Current solutions, however, make undesirable trade-offs between infrastructure cost and information richness. Switches that generate flow records, e.g., NetFlow switches, are a low cost solution but current designs sacrifice information richness, e.g., by sampling. Information rich alternatives rely heavily on servers, which increases cost to the point that they are impractical for high coverage. In this paper, we present the design, implementation, and evaluation of TurboFlow, a flow record generator for programmable switches that does not compromise on either cost or information richness. TurboFlow produces fine- grained and unsampled flow records with custom features entirely at the switch without relying on any support from external servers. This is a challenge given high traffic rates and the limitations of switch hardware. To overcome, we decompose the flow record generation algorithm and optimize it for the heterogeneous processors in programmable switches. We show that with this design, TurboFlow can support multi-terabit workloads on readily available commodity switches to enable information rich monitoring with high coverage.
John Sonchack, Adam J. Aviv, Eric Keller, Jonathan M. Smith
EuroSys3
2018 Scaling Hardware Accelerated Network Monitoring to Concurrent and Dynamic Queries With *Flow
John Sonchack, Oliver Michel, Adam J. Aviv, Eric Keller, Jonathan M. Smith
USENIX ATC4
2018 A Practical Evaluation of Rate Adaptation Algorithms in HTTP-based Adaptive Streaming
Ibrahim Ayad, Youngbin Im, Eric Keller, Sangtae Ha
Comput. Networks3
2017 Augmenting cloud architectures to support decentralized applications
abstract
Despite the benefits of decentralized applications in terms of resilience and privacy, the overwhelming majority of applications with mainstream adoption are provided in a centralized manner. We argue that this is due to the direct benefits to the developer that centralization provides in terms of performance, monetization, and deployability. In this paper we introduce a new model, untrusted delegation, which joins the simplified deployment model of centralization with the benefits of decentralization. In this model, we decouple administrative ownership from administrative management, and leverage the existence of either a private cloud infrastructure, or a public cloud provider that acts as a neutral third party, that is augmented to support decentralization. Our initial prototype integrates with the Digital Ocean API and as a proof-of-concept, we can deploy Tor relay nodes with users only needing to sign up for a Digital Ocean account.
Michael Coughlin, Kelly Kaoudis, Eric Keller
IM3
2017 Stateless Network Functions: Breaking the Tight Coupling of State and Processing
Murad Kaplan, Azzam Alsudais, Eric Keller, Franck Le
NSDI3
2016 Timing-based reconnaissance and defense in software-defined networks
John Sonchack, Anurag Dubey, Adam J. Aviv, Jonathan M. Smith, Eric Keller
ACSAC5
2016 Enabling Practical Software-defined Networking Security Applications with OFX
John Sonchack, Jonathan M. Smith, Adam J. Aviv, Eric Keller
NDSS4
2016 Apps with Hardware: Enabling Run-time Architectural Customization in Smart Phones
Michael Coughlin, Ali Ismail, Eric Keller
USENIX ATC3
2015 POSTER: OFX: Enabling OpenFlow Extensions for Switch-Level Security Applications
abstract
Network Security applications that run on Software Defined Networks (SDNs) often need to analyze and process traffic in advanced ways. Existing approaches to adding such functionality to SDNs suffer from either poor performance, or poor deployability. In this paper, we propose and benchmark OFX: an OpenFlow extension framework that provides a better tradeoff between performance and deployability for SDN security applications by allowing them to dynamically install software modules onto network switches.
John Sonchack, Adam J. Aviv, Eric Keller, Jonathan M. Smith
CCS3
2014 WASP: a software-defined communication layer for hybrid wireless networks
abstract
In this paper we introduce WASP, a general communication layer for hybrid wireless networks where multiple networks are used to complement each other. In our system, we capitalize on an infrastructure with a ubiquitous,wide-area network to help enable the creation of a local mobile ad-hocnetwork in an efficient, scalable, evolvable, and manageable way. In particular, in an architecture inspired by software-defined networking,we decouple the control plane and data plane in the mobile devices and shift the control plane to a centralized controller. The controller, reachable via the wide-area network, manages a collection of mobile devices by informing each device how to handle traffic based on neighbor information provided by the mobile devices. With this, a mobile ad-hoc network can help reduce the data burden on the ubiquitous network, and the ubiquitous network can help reduce the burden on the mobile devices. WASP can be used in different networks with different applications such as cellular and military networks. In this paper, we based our implementation on Android and tested on a collection of Google Nexus-4 devices to measure metrics such as battery consumption. We evaluate on an extended ns-3 simulation platform which we added the ability to run unmodified Android applications on the nodes within ns-3. Our experiments show that WASP scales better than traditional ad-hoc networks with only a minimal trade off of energy. Additionally, we show that a content distribution scheme using WASP on smart phones with cellular data plans significantly offloads bandwidth from the cellular infrastructure, and in turn reduces expensive data usage and energy usage.
Murad Kaplan, Chenyu Zheng, Matthew Monaco, Eric Keller, Douglas C. Sicker
ANCS4
2014 Transparent, Live Migration of a Software-Defined Network
abstract
Increasingly, datacenters are virtualized and software-defined. Live virtual machine (VM) migration is becoming an indispensable management tool in such environments. However, VMs often have a tight coupling with the underlying network. Hence, cloud providers are beginning to offer tenants more control over their virtual networks. Seamless migration of all (or part) of a virtual network greatly simplifies management tasks like planned maintenance, optimizing resource usage, and cloud bursting. Our LIME architecture efficiently migrates an ensemble, a collection of virtual machines and virtual switches, for any arbitrary controller and end-host applications. To minimize performance disruptions, during the migration, LIME temporarily runs all or part of a virtual switch on multiple physical switches. Running a virtual switch on multiple physical switches must be done carefully to avoid compromising application correctness. To that end, LIME merges events, combines traffic statistics, and preserves consistency among multiple physical switches even across changes to the packet-handling rules. Using a formal model, we prove that migration under LIME is transparent to applications, i.e., any execution of the controller and end-host applications during migration is a completely valid execution that could have taken place in a migration-free setting. Experiments with our prototype, built on the Floodlight controller, show that ensemble migration can be an efficient tool for network management.
Soudeh Ghorbani, Cole Schlesinger, Matthew Monaco, Eric Keller, Matthew Caesar 0001, Jennifer Rexford, David Walker 0001
SoCC4
2014 Extending the software-defined network boundary
abstract
Given that Software-Defined Networking is highly successful in solving many of today's manageability, flexibility, and scalability issues in large-scale networks, in this paper we argue that the concept of SDN can be extended even further. Many applications (esp. stream processing and big-data applications) rely on graph-based inter-process communication patterns that are very similar to those in computer networks. To our mind, this network abstraction spanning over different types of entities is highly suitable for and would benefit from central (SDN-inspired) control for the same reasons classical networks do. In this work, we investigate the commonalities between such intra-host networks and classical computer networking. Based on this, we study the feasibility of a central network controller that manages both network traffic and intra-host communication over a custom bus system.
Oliver Michel, Michael Coughlin, Eric Keller
SIGCOMM3
2013 Active security
abstract
In this paper we introduce active security, a new methodology which introduces programmatic control within a novel feedback loop into the defense infrastructure. Active security implements a unified programming environment which provides interfaces to (i) protect the infrastructure under common attack scenarios (e.g., configure a firewall), (ii) sense the current state of the infrastructure through a wide variety of information, (iii) adjust the configuration of the infrastructure at run time based on sensed information, (iv) collect forensic evidence on-demand, at run-time for attribution, and (v) counter the attack through more advanced mechanisms such as migrating malicious code to a quarantined system. We built an initial prototype that extends the FloodLight software-defined networking controller to automatically interface with the Snort intrusion detection system to detect anomalies, the Linux Memory Extractor to collect forensic evidence at run-time, and the Volatility parsing tool to extract an executable from physical memory and analyze information about the malware (which can then be used by the active security system to better secure the infrastructure).
Ryan Hand, Michael Ton, Eric Keller
HotNets3
2013 Applying operating system principles to SDN controller design
abstract
Rather than creating yet another network controller which provides a framework in a specific (potentially new) programming language and runs as a monolithic application, in this paper we extend an existing operating system and leverage its software ecosystem in order to serve as a practical SDN controller. This paper introduces yanc, a controller platform for software-defined networks which exposes the network configuration and state as a file system, enabling user and system applications to interact through standard file I/O, and to easily take advantage of the tools available on the host operating system. In yanc, network applications are separate processes, are provided by multiple sources, and may be written in any language. Applications benefit from common and powerful technologies such as the virtual file system (VFS) layer, which we leverage to layer a distributed file system on top of, and Linux namespaces, which we use to isolate applications with different views (e.g., slices). In this paper we present the goals and design of yanc. Our initial prototype is built with the FUSE file system in user space on Linux and has been demonstrated with a simple static flow pusher application. Effectively, we are making Linux the network operating system.
Matthew Monaco, Oliver Michel, Eric Keller
HotNets3
2013 Towards Elastic Operating Systems
Ehab Ababneh, Richard Han 0001, Eric Keller
HotOS4
2012 Live migration of an entire network (and its hosts)
abstract
Live virtual machine (VM) migration can move applications from one location to another without a disruption in service. However, applications often consist of multiple VMs and rely on the state of the underlying network for basic reachability, access control, and QoS functionality. Rather than migrating an individual VM, we show how to migrate an ensemble---the VMs, the network, and the management system---to a different set of physical resources. Our LIME (LIve Migration of Ensembles) design leverages recent advances in Software Defined Networking (SDN) for a clear separation between the controller and the data-plane state in the switches. Transparent to the application running on the controller, LIME clones the data-plane state to a new set of switches, and then incrementally migrates the traffic sources (e.g., the VMs). During this transition, both networks deliver traffic and LIME maintains synchronized state. Experiments with our initial prototype, built on the Floodlight OpenFlow controller, suggest that network migration does not have to be a disruptive, middle-of-the-night maintenance event, but can become an integral network management mechanism completely transparent to applications.
Eric Keller, Soudeh Ghorbani, Matthew Caesar 0001, Jennifer Rexford
HotNets1
2011 Eliminating the hypervisor attack surface for a more secure cloud
abstract
Cloud computing is quickly becoming the platform of choice for many web services. Virtualization is the key underlying technology enabling cloud providers to host services for a large number of customers. Unfortunately, virtualization software is large, complex, and has a considerable attack surface. As such, it is prone to bugs and vulnerabilities that a malicious virtual machine (VM) can exploit to attack or obstruct other VMs -- a major concern for organizations wishing to move to the cloud. In contrast to previous work on hardening or minimizing the virtualization software, we eliminate the hypervisor attack surface by enabling the guest VMs to run natively on the underlying hardware while maintaining the ability to run multiple VMs concurrently. Our NoHype system embodies four key ideas: (i) pre-allocation of processor cores and memory resources, (ii) use of virtualized I/O devices, (iii) minor modifications to the guest OS to perform all system discovery during bootup, and (iv) avoiding indirection by bringing the guest virtual machine in more direct contact with the underlying hardware. Hence, no hypervisor is needed to allocate resources dynamically, emulate I/O devices, support system discovery after bootup, or map interrupts and other identifiers. NoHype capitalizes on the unique use model in cloud computing, where customers specify resource requirements ahead of time and providers offer a suite of guest OS kernels. Our system supports multiple tenants and capabilities commonly found in hosted cloud infrastructures. Our prototype utilizes Xen 4.0 to prepare the environment for guest VMs, and a slightly modified version of Linux 2.6 for the guest OS. Our evaluation with both SPEC and Apache benchmarks shows a roughly 1% performance gain when running applications on NoHype compared to running them on top of Xen 4.0. Our security analysis shows that, while there are some minor limitations with cur- rent commodity hardware, NoHype is a significant advance in the security of cloud computing.
Jakub Szefer, Eric Keller, Ruby B. Lee, Jennifer Rexford
CCS2
2011 Better by a HAIR: hardware-amenable Internet routing
Brent Mochizuki, Firat Kiyak, Eric Keller, Matthew Caesar 0001
Comput. Networks3
2010 NoHype: virtualized cloud infrastructure without the virtualization
abstract
Cloud computing is a disruptive trend that is changing the way we use computers. The key underlying technology in cloud infrastructures is virtualization -- so much so that many consider virtualization to be one of the key features rather than simply an implementation detail. Unfortunately, the use of virtualization is the source of a significant security concern. Because multiple virtual machines run on the same server and since the virtualization layer plays a considerable role in the operation of a virtual machine, a malicious party has the opportunity to attack the virtualization layer. A successful attack would give the malicious party control over the all-powerful virtualization layer, potentially compromising the confidentiality and integrity of the software and data of any virtual machine. In this paper we propose removing the virtualization layer, while retaining the key features enabled by virtualization. Our NoHype architecture, named to indicate the removal of the hypervisor, addresses each of the key roles of the virtualization layer: arbitrating access to CPU, memory, and I/O devices, acting as a network device (e.g., Ethernet switch), and managing the starting and stopping of guest virtual machines. Additionally, we show that our NoHype architecture may indeed be "no hype" since nearly all of the needed features to realize the NoHype architecture are currently available as hardware extensions to processors and I/O devices.
Eric Keller, Jakub Szefer, Jennifer Rexford, Ruby B. Lee
ISCA1
2010 Seamless BGP Migration with Router Grafting
Eric Keller, Jennifer Rexford, Jacobus E. van der Merwe
NSDI1
2009 Virtually eliminating router bugs
abstract
Software bugs in routers lead to network outages, security vulnerabilities, and other unexpected behavior. Rather than simply crashing the router, bugs can violate protocol semantics, rendering traditional failure detection and recovery techniques ineffective. Handling router bugs is an increasingly important problem as new applications demand higher availability, and networks become better at dealing with traditional failures. In this paper, we tailor software and data diversity (SDD) to the unique properties of routing protocols, so as to avoid buggy behavior at run time. Our bug-tolerant router executes multiple diverse instances of routing software, and uses voting to determine the output to publish to the forwarding table, or to advertise to neighbors. We design and implement a router hypervisor that makes this parallelism transparent to other routers, handles fault detection and booting of new router instances, and performs voting in the presence of routing-protocol dynamics, without needing to modify software of the diverse instances. Experiments with BGP message traces and open-source software running on our Linux-based router hypervisor demonstrate that our solution scales to large networks and efficiently masks buggy behavior.
Eric Keller, Minlan Yu, Matthew Caesar 0001, Jennifer Rexford
CoNEXT1
2009 Better by a HAIR: Hardware-Amenable Internet Routing
abstract
Routing protocols are implemented in the form of software running on a general-purpose microprocessor. However, conventional software-based router architectures face significant scaling challenges in the presence of ever-increasing routing table growth and churn. Recent advances in programmable hardware and high-level hardware description languages provide the opportunity to implement BGP directly at the hardware layer. Hardware-based implementation allows designs to take advantage of the parallelization and customizability of the underlying hardware to improve performance. As a first step in this direction, we design and implement a hardware-based BGP architecture. To understand the challenges in doing this, we propose an architecture and logical design for the core components of BGP running as a logical circuit in an FPGA. We then enumerate sources of complexity and performance bottlenecks, and derive modifications to BGP that reduce complexity of hardware offloading. Our results based on update traces from core Internet routers indicate an order of magnitude improvement in processing time and throughput.
Firat Kiyak, Brent Mochizuki, Eric Keller, Matthew Caesar 0001
ICNP3
2009 Data Driven Anomaly detection via Symbolic Identification of Complex Dynamical Systems
abstract
Some of the critical and practical issues regarding the problem of health monitoring of multi-component human-engineered systems have been discussed, and a syntactic method has been proposed. The method involves abstraction of a qualitative description from a general dynamical system structure, using state space embedding of the output data-stream and discretization of the resultant pseudo state and input spaces. The system identification is achieved through grammatical inference techniques, and the deviation of the plant output from the nominal estimated language gives a measure of anomaly in the system. The technique is validated on an experimental test-bed of a permanent magnet synchronous motor undergoing a gradual degradation of the encoder orientation feedback.
Subhadeep Chakraborty, Eric Keller, Asok Ray
SMC2
2008 Virtual routers on the move: live router migration as a network-management primitive
abstract
The complexity of network management is widely recognized as one of the biggest challenges facing the Internet today. Point solutions for individual problems further increase system complexity while not addressing the underlying causes. In this paper, we argue that many network-management problems stem from the same root cause---the need to maintain consistency between the physical and logical configuration of the routers. Hence, we propose VROOM (Virtual ROuters On the Move), a new network-management primitive that avoids unnecessary changes to the logical topology by allowing (virtual) routers to freely move from one physical node to another. In addition to simplifying existing network-management tasks like planned maintenance and service deployment, VROOM can also help tackle emerging challenges such as reducing energy consumption. We present the design, implementation, and evaluation of novel migration techniques for virtual routers with either hardware or software data planes. Our evaluation shows that VROOM is transparent to routing protocols and results in no performance impact on the data traffic when a hardware-based data plane is used.
Eric Keller, Brian Biskeborn, Jacobus E. van der Merwe, Jennifer Rexford
SIGCOMM2
2006 ECESS Inter-Module Interface Specification for Speech Synthesis
Javier Pérez, Antonio Bonafonte, Horst-Udo Hain, Eric Keller, Stefan Breuer, Jilei Tian
LREC4
2004 Hyper-Programmable Architectures for Adaptable Networked Systems
Gordon J. Brebner, Philip James-Roxby, Eric Keller, Chidamber Kulkarni
ASAP3
2004 Programming a hyper-programmable architecture for networked systems
abstract
Modern programmable logic devices have capabilities that are well suited for them to assume a central role in the holistic implementation of networked systems. We have devised a highly flexible soft platform architecture abstracted from such physical devices, which may be viewed as a particularly configurable and programmable type of network processor. In this paper, we discuss a programming model for the architecture, and present an XML-based description language for expressing the programming information. This intermediate language is designed both to be an attractive compilation target for domain-specific languages used for describing networking applications, and also to have efficient mappings to programmable logic devices, harnessing to the full their high degree of concurrency, interconnectivity and programmability. We present a detailed example, where a high-speed remote procedure call (RPC) protocol server for gigabit Ethernet was described directly in the XML-based language, and automatically compiled to a working implementation on a platform FPGA device. The exercise was carried out by a non-hardware expert in only two weeks, thus demonstrating the unlocking of access to programmable logic technology.
Eric Keller, Gordon J. Brebner
FPT1
2003 A Self-reconfiguring Platform
Brandon Blodget, Philip James-Roxby, Eric Keller, Scott McMillan, Prasanna Sundararajan
FPL3
2003 Software Decelerators
Eric Keller, Gordon J. Brebner, Philip James-Roxby
FPL1
2002 Gene Matching Using JBits
Steven A. Guccione, Eric Keller
FPL2
2001 Building Asynchronous Circuits with JBits
Eric Keller
FPL1
1999 From multilingual to polyglot speech synthesis
abstract
The paper addresses the problem of designing a language independent phonetic inventory for the speech recognisers with multilingual vocabulary. A new clustering algorithm for the definition of multilingual set of triphones is proposed. The clustering algorithm bases on a definition of a distance measure for triphones defined as a weighted sum of explicit estimates of the context similarity on a monophone level. The monophone similarity estimation method based on the algorithm of Houtgast. The clustering algorithm is integrated in a multilingual speech recognition system based on HTK V2.1.1. The ongoing experiments are based on the SpeechDat II databases. So far, experiments included the Slovenian, Spanish and German 1000 FDB SpeechDat (II) database. Current results are very promising. The use of clustering algorithm resulted in a significant reduction of the number of triphones at acceptable level of word and language identification accuracy degradation.
Christof Traber, Karl Huber, Karim Nedir, Beat Pfister, Eric Keller, Brigitte Zellner
EUROSPEECH5
1998 Neural network motivation for segmental distribution
Eric Keller
ICSLP1
1998 Evaluation of grapheme-to phoneme conversion for text-to-speech synthesis in French
Philippe Boula de Mareüil, François Yvon, Christophe d'Alessandro, V. Auberg, Michel Bagein, Gérard Bailly, Frédéric Béchet, S. Fonkia, Jean-Philippe Goldman, Eric Keller, Douglas D. O'Shaughnessy, Steve Pagel, F. Sannier, Jean Véronis, Brigitte Zellner Keller
LREC10
1998 The use of large text corpora for evaluating text-to-speech systems
Louis C. W. Pols, Jan P. H. van Santen, Masanobu Abe, Dan Kahn, Eric Keller
LREC5
1998 Objective evaluation of grapheme to phoneme conversion for text-to-speech synthesis in French
François Yvon, Philippe Boula de Mareüil, Christophe d'Alessandro, Véronique Aubergé, Michel Bagein, Gérard Bailly, Frédéric Béchet, S. Foukia, J.-F. Goldman, Eric Keller, Douglas D. O'Shaughnessy, Vincent Pagel, Fred Sannier, Jean Véronis, Brigitte Zellner
Comput. Speech Lang.10
1997 Simplification of TTS architecture vs. operational quality
Eric Keller
EUROSPEECH1