Vasileios Giotsas

dblp:87/7704 · also Vasilis Giotsas · DBLP profile ↗
← Back
38ranked-venue papers
14as first author
12since 2021 · last 2026
0000-0002-5277-6498ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 28 · 11 first-author · 10 since 2021Security and privacy · 4 · 3 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Systems, architecture and hardware · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A Global Inference and Assessment of Large Shared IP Addresses
abstract
The number of clients and users behind an IP address can differ by orders of magnitude, owing to large shared IPs such as VPNs, proxies, and Carrier-Grade NAT (CGN) gateways. However, limitations on visibility, the absence of Internet-wide data, and the dynamic nature of IP allocations make it difficult to disambiguate multi-user IPs (M-IPs) and their impact on service provision. In this paper we devise an inference technique to detect M-IPs. We train a classifier by annotating data from public sources with features extracted from a global CDN request log. To demonstrate reproducibility, we build a parallel model using public M-Lab data and achieve comparable accuracy with different features. An unanticipated result was the dominance of /24 feature importance over individual IPs. Using the CDN logs, we then evaluate implications of CGNs along multiple dimensions including user impact, relationship with IPv6 networks, and regional distributions. Our results reinforce various intuition, and potentially challenge some assumptions.
Vasileios Giotsas, Loqman Salamatian, Antoine Cordelle, Nick Wood, Marwan Fayed
SIGCOMM1
2024 What's in the Dataset? Unboxing the APNIC per AS User Population Dataset
abstract
The research measurement community needs methods and datasets to identify user concentrations and to accurately weight ASes against each other for analyzing measurements' coverage. However, academic researchers traditionally lack visibility into how many users are in each network or how much traffic flows to each network and so often fall back on treating all IP addresses or networks equally. As an alternative, some recent studies have used the APNIC per AS Population Estimates dataset, but it is unvalidated and its methodology is not fully public.
Loqman Salamatian, Calvin Ardi, Vasileios Giotsas, Matt Calder, Ethan Katz-Bassett, Todd Arnold
IMC3
2024 metAScritic: Reframing AS-Level Topology Discovery as a Recommendation System
abstract
Despite prior efforts, the vast majority of the AS-level topology of the Internet remains hidden from BGP and traceroute vantage points. In this work, we introduce metAScritic, a novel system inspired by recommender system literature, designed to infer interconnections within a given metro. metAScritic uses the intuition that the connectivity matrix at a given metro is a low-rank system, since ASes employ similar peering strategies according to their infrastructures, traffic profiles, and business models. This approach allows metAScritic to accurately reconstruct the complete peering connectivity by measuring a strategic subset of interconnections that capture ASes' underlying peering strategies. We evaluate metAScritic's performance across six large metropolitan areas, achieving an average F-score of 0.88 on various validation datasets, including ground truth. metAScritic measures more than 86K edges and infers more than 368K edges, compared to the 13K edges observed for this subset of ASes in public BGP feeds -- an increase of (24X) what is currently seen. We study the impact of our inferred links on Internet properties, illustrating the extent of the Internet's flattening and demonstrating our ability to better predict the impact of route leaks and prefix hijacks, compared to relying only on the existing public view.
Loqman Salamatian, Kevin Vermeulen, Ítalo S. Cunha, Vasileios Giotsas, Ethan Katz-Bassett
IMC4
2024 These are Not the PLCs You are Looking for: Obfuscating PLCs to Mimic Honeypots
abstract
Industry 4.0 and the trend of connecting legacy Industrial Control Systems (ICSs) to public networks have exposed these systems to various online threats. To combat these threats, honeypots have been widely used to provide proactive monitoring, detection and deception security capabilities. However, skilled attackers are now adept at fingerprinting and avoiding honeypots. Therefore, we take a fundamentally different approach in this paper. Instead of the honeypot representing a real system, we deploy it as a deterrent. Through obfuscation, the aim is to make an attacker believe the real system is a honeypot and collect threat intelligence data on the attacker. To achieve this, we introduce a new obfuscation technique that allows real ICSs to present themselves as honeypots. By taking advantage of honeypot fingerprinting techniques, we are able to deter attackers from interacting with the real Programmable Logic Controller (PLC) within the industrial network. The approach is implemented and evaluated using different penetration testing tools and an expert evaluation highlighting the benefits of obfuscation in that potential adversaries would be misled into assuming the PLC is a honeypot.
Sam Maesschalck, William Fantom, Vasileios Giotsas, Nicholas J. P. Race
IEEE Trans. Netw. Serv. Manag.3
2023 Into the Heat of the Debate: Simulating a Program Committee Within Computer Science Education
abstract
There are many teaching strategies in higher education; one of these is discussion-based teaching which aims to stimulate conversation and peer learning. Although this teaching strategy has many benefits for students, such as learning how to argue, it has not gained much traction in STEM subjects like Computer Science. However, soft skills have become increasingly important within these fields. A focus when recruiting for roles is not only on hard skills such as programming but also on the ability to communicate well with stakeholders. This paper explores and evaluates an approach to incorporate discussion-based teaching within computer science education, focusing on teaching hard and soft skills. To achieve this, we organised an emulated program committee type of activity for MSc students at our university. We evaluated the activity by asking the students to complete a survey and followed this up by interviewing several students to gather more in-depth reactions from the cohort. The results show that students feel they learnt about the topics tackled within the papers we have chosen, gained more confidence to tackle paper writing, understood the requirements of academic work, and improved their soft skills such as academic writing. The interviews show that students thoroughly enjoyed the activity and are keen to have more interactive discussion sessions like this.
Sam Maesschalck, Matthew Bradbury, Vasileios Giotsas
EDUCON3
2023 Replication: 20 Years of Inferring Interdomain Routing Policies
abstract
In 2003, Wang and Gao [67] presented an algorithm to infer and characterize routing policies as this knowledge could be valuable in predicting and debugging routing paths. They used their algorithm to measure the phenomenon of selectively announced prefixes, in which, ASes would announce their prefixes to specific providers to manipulate incoming traffic. Since 2003, the Internet has evolved from a hierarchical graph, to a flat and dense structure. Despite 20 years of extensive research since that seminal work, the impact of these topological changes on routing policies is still blurred.
Savvas Kastanakis, Vasileios Giotsas, Ioana Livadariu, Neeraj Suri
IMC2
2022 Understanding the confounding factors of inter-domain routing modeling
abstract
The Border Gateway Protocol (BGP) is a policy-based protocol, which enables Autonomous Systems (ASes) to independently define their routing policies with little or no global coordination. AS-level topology and AS-level paths inference have been long-standing problems for the past two decades, yet, an important question remains open: "which elements of Internet routing affect the AS-path inference accuracy and how much do they contribute to the error?". In this work, we: (1) identify the confounding factors behind Internet routing modeling, and (2) quantify their contribution on the inference error. Our results indicate that by solving the first-hop inference problem, we can increase the exact-path score from 33.6% to 84.1%, and, by taking geolocation into consideration, we can refine the accuracy up to 94.6%.
Savvas Kastanakis, Vasileios Giotsas, Neeraj Suri
IMC2
2022 Don't get stung, cover your ICS in honey: How do honeypots fit within industrial control system security
abstract
The advent of Industry 4.0 and smart manufacturing has led to an increased convergence of traditional manufacturing and production technologies with IP communications. Legacy Industrial Control System (ICS) devices, now interconnected via public networks, are exposed to a wide range of previously unconsidered threats, which must be considered to ensure the continued safe operation of industrial processes. This paper surveys the ICS honeypot deployments in the literature to date, provides an overview of ICS focused threat vectors, and studies how honeypots can be integrated within an organisations defensive strategy. We discuss relevant legislation, such as the UK Cyber Assessment Framework, the US NIST Framework for Improving Critical Infrastructure Cybersecurity, and associated industry-based standards and guidelines supporting operator compliance. This is used to frame a discussion on our survey of existing ICS honeypot implementations, and the role of honeypots in supporting regulatory objectives. We observe that many low-interaction honeypots are limited in their use. This is largely due to the increased knowledge attackers have on how real-world ICS devices are configured and operate vs the configurability of simulated honeypot systems. Furthermore, we find that environments with increased interaction provide more extensive capabilities and value, due to their inherent obfuscation delivered through the use of real-world systems. Based on these insights, we propose a novel framework towards the classification and implementation of ICS honeypots.
Sam Maesschalck, Vasileios Giotsas, Benjamin Green 0001, Nicholas J. P. Race
Comput. Secur.2
2022 BGP-Multipath Routing in the Internet
abstract
BGP-Multipath (BGP-M) is a multipath routing technique for load balancing. Distinct from other techniques deployed at a router inside an Autonomous System (AS), BGP-M is deployed at a border router that has installed multiple inter-domain border links to a neighbor AS. It uses the equal-cost multi-path (ECMP) function of a border router to share traffic to a destination prefix on different border links. Despite recent research interests in multipath routing, there is little study on BGP-M. Here we provide the first measurement and a comprehensive analysis of BGP-M routing in the Internet. We extracted information on BGP-M from query data collected from Looking Glass (LG) servers. We revealed that BGP-M has already been extensively deployed and used in the Internet. A particular example is Hurricane Electric (AS6939), a Tier-1 network operator, which has implemented >1,000 cases of BGP-M at 69 of its border routers to prefixes in 611 of its neighbor ASes, including many hyper-giant ASes and large content providers, on both IPv4 and IPv6 Internet. We examined the distribution and operation of BGP-M. We also ran traceroute using RIPE Atlas to infer the routing paths, the schemes of traffic allocation, and the delay on border links. This study provided the state-of-the-art knowledge on BGP-M with novel insights into the unique features and the distinct advantages of BGP-M as an effective and readily available technique for load balancing.
Jie Li 0117, Vasileios Giotsas, Yangyang Wang 0001, Shi Zhou
IEEE Trans. Netw. Serv. Manag.2
2021 Corrigendum: cloud provider connectivity in the flat internet
abstract
This corrigendum corrects and extends our results on the benefit of peer locking in mitigating the propagation of route leaks on the Internet, originally published in [2]. The updated results show even higher benefits of peer locking than originally reported, and an extended analysis covering additional peer locking deployment scenarios shows partial deployments also yield significant reduction in propagation of leaked routes.
Todd Arnold, Weifan Jiang, Matt Calder, Ítalo S. Cunha, Vasileios Giotsas, Ethan Katz-Bassett
Internet Measurement Conference6
2021 The ties that un-bind: decoupling IP from web services and sockets for robust addressing agility at CDN-scale
abstract
The couplings between IP addresses, names of content or services, and socket interfaces, are too tight. This impedes system manageability, growth, and overall provisioning. In turn, large-scale content providers are forced to use staggering numbers of addresses, ultimately leading to address exhaustion (IPv4) and inefficiency (IPv6).
Marwan Fayed, Lorenz Bauer, Vasileios Giotsas, Sami Kerola, Marek Majkowski, Pavel Odintsov, Jakub Sitnicki, Taejoong Chung, Dave Levin, Alan Mislove, Christopher A. Wood, Nick Sullivan
SIGCOMM3
2021 O Peer, Where Art Thou? Uncovering Remote Peering Interconnections at IXPs
abstract
Internet eXchange Points (IXPs) are Internet hubs that mainly provide the switching infrastructure to interconnect networks and exchange traffic. While the initial goal of IXPs was to bring together networks residing in the same city or country, and thus keep local traffic local, this model is gradually shifting. Many networks connect to IXPs without having physical presence at their switching infrastructure. This practice, called Remote Peering, is changing the Internet topology and economy, and has become the subject of a contentious debate within the network operators' community. However, despite the increasing attention it attracts, the understanding of the characteristics and impact of remote peering is limited. In this work, we introduce and validate a heuristic methodology for discovering remote peers at IXPs. We (i) identify critical remote peering inference challenges, (ii) infer remote peers with high accuracy (>97%) and coverage (94%) per IXP, and (iii) characterize different aspects of the remote peering ecosystem by applying our methodology to 30 large IXPs. We observe that remote peering is a significantly common practice in all the studied IXPs; for the largest IXPs, remote peers account for 40% of their member base. We also show that today, IXP growth is mainly driven by remote peering, which contributes two times more than local peering.
Vasileios Giotsas, George Nomikos, Vasileios Kotronis, Pavlos Sermpezis, Petros Gigis, Lefteris Manassakis, Christoph Dietzel, Stavros Konstantaras, Xenofontas A. Dimitropoulos
IEEE/ACM Trans. Netw.1
2020 Cloud Provider Connectivity in the Flat Internet
abstract
The Tier-1 ISPs have been considered the Internet's backbone since the dawn of the modern Internet 30 years ago, as they guarantee global reachability. However, their influence and importance are waning as Internet flattening decreases the demand for transit services and increases the importance of private interconnections. Conversely, major cloud providers -- Amazon, Google, IBM, and Microsoft-- are gaining in importance as more services are hosted on their infrastructures. They ardently support Internet flattening and are rapidly expanding their global footprints, which enables them to bypass the Tier-1 ISPs and other large transit providers to reach many destinations.
Todd Arnold, Weifan Jiang, Matt Calder, Ítalo S. Cunha, Vasileios Giotsas, Ethan Katz-Bassett
Internet Measurement Conference6
2020 Reduce, Reuse, Recycle: Repurposing Existing Measurements to Identify Stale Traceroutes
abstract
Many systems rely on traceroutes to monitor or characterize the Internet. The quality of the systems' inferences depends on the completeness and freshness of the traceroutes, but the refreshing of traceroutes is constrained by limited resources at vantage points. Previous approaches predict which traceroutes are likely out-of-date in order to allocate measurements, or monitor BGP feeds for changes that overlap traceroutes. Both approaches miss many path changes for reasons including the difficulty in predicting changes and the coarse granularity of BGP paths.
Vasileios Giotsas, Elverton C. Fazzion, Ítalo S. Cunha, Matt Calder, Harsha V. Madhyastha, Ethan Katz-Bassett
Internet Measurement Conference1
2020 (How Much) Does a Private WAN Improve Cloud Performance?
abstract
The construction of private WANs by cloud providers enables them to extend their networks to more locations and establish direct connectivity with end user ISPs. Tenants of the cloud providers benefit from this proximity to users, which is supposed to provide improved performance by bypassing the public Internet. However, the performance impact of cloud providers' private WANs is not widely understood.To isolate the impact of a private WAN, we measure from globally distributed vantage points to two large cloud providers, comparing performance when using their worldwide WAN and when instead using the public Internet. The benefits are not universal. While 48% of our vantage points saw improved performance when using the WAN, 43% had statistically indistinguishable median performance, and 9% had better performance over the public Internet. We find that the benefits of the private WAN tend to improve with client-to-server distance, but the benefits (or drawbacks) for a particular vantage point depend on specifics of its geographic and network connectivity.
Todd Arnold, Ege Gürmeriçliler, Georgia Essig, Arpit Gupta, Matt Calder, Vasileios Giotsas, Ethan Katz-Bassett
INFOCOM6
2020 λBGP: Rethinking BGP programmability
abstract
BGP has long been the de-facto control plane protocol for inter-network connectivity. Although initially designed to provide best-effort routing between ASes, the evolution of Internet services has created a demand for more complex control functionalities using the protocol. At the heart of this challenge lies the static nature of configuration mechanisms and the limited programmability of existing BGP speakers. Meanwhile, the SDN paradigm has demonstrated that open and generic network control APIs can greatly improve network functionality and seamlessly enable greater flexibility in network management. In this paper, we argue that BGP speaking systems can and should provide an open and rich control and configuration mechanism, in order to address modern era network control requirements. Towards this goal, we present λBGP, a modular and extensible BGP framework written in Haskell. The framework offers an extensible integration model for reactive BGP control that remains backward compatible with existing BGP standards and allows network managers to define route processing policies using a high-level language and to dynamically inject information sources into the path selection logic. Using a high-performance BGP traffic generator, we demonstrate that λBGP offers performance comparable to production BGP speakers, while dynamic AS route processing policies can be written in just a few lines of code.
Nicholas Hart, Charalampos Rotsos, Vasileios Giotsas, Nicholas J. P. Race, David Hutchison 0001
NOMS3
2020 A First Look at the Misuse and Abuse of the IPv4 Transfer Market
Vasileios Giotsas, Ioana Livadariu, Petros Gigis
PAM1
2020 Deep Video Precoding
abstract
Several groups worldwide are currently investigating how deep learning may advance the state-of-the-art in image and video coding. An open question is how to make deep neural networks work in conjunction with existing (and upcoming) video codecs, such as MPEG H.264/AVC, H.265/HEVC, VVC, Google VP9 and AOMedia AV1, AV2, as well as existing container and transport formats, without imposing any changes at the client side. Such compatibility is a crucial aspect when it comes to practical deployment, especially when considering the fact that the video content industry and hardware manufacturers are expected to remain committed to supporting these standards for the foreseeable future. We propose to use deep neural networks as precoders for current and future video codecs and adaptive video streaming systems. In our current design, the core precoding component comprises a cascaded structure of downscaling neural networks that operates during video encoding, prior to transmission. This is coupled with a precoding mode selection algorithm for each independently-decodable stream segment, which adjusts the downscaling factor according to scene characteristics, the utilized encoder, and the desired bitrate and encoding configuration. Our framework is compatible with all current and future codec and transport standards, as our deep precoding network structure is trained in conjunction with linear upscaling filters (e.g., the bilinear filter), which are supported by all web video players. Extensive evaluation on FHD (1080p) and UHD (2160p) content and with widely-used H.264/AVC, H.265/HEVC and VP9 encoders, as well as a preliminary evaluation with the current test model of VVC (v.6.2rc1), shows that coupling such standards with the proposed deep video precoding allows for 8% to 52% rate reduction under encoding configurations and bitrates suitable for video-on-demand adaptive streaming systems. The use of precoding can also lead to encoding complexity reduction, which is essential for cost-effective cloud deployment of complex encoders like H.265/HEVC, VP9 and VVC, especially when considering the prominence of high-resolution adaptive video streaming.
Eirina Bourtsoulatze, Aaron Chadha, Ilya Fadeev, Vasileios Giotsas, Yiannis Andreopoulos
IEEE Trans. Circuits Syst. Video Technol.4
2019 Profiling IoT-Based Botnet Traffic Using DNS
abstract
Internet-wide security and resilience have traditionally been subject to large-scale DDoS attacks initiated by various types of botnets. Since the Mirai outbreak in 2016 myriads of Mirai-alike IoT-based botnets have emerged. Such botnets rely on Mirai's base malware code and they infiltrate vulnerable IoT devices on an Internet-wide scale such as to instrument them to perform large-scale attacks such as DDoS. As recently shown, DDoS attacks triggered by Mirai-alike IoT-based botnets go far beyond traditional pre-2016 DDoS attacks since they have a much higher amplification and their propagation is far more aggressive. Thus, it is of crucial importance to tailor botnet detection schemes accordingly. This work provides a novel DNS-based profiling scheme over real datasets of Mirai-alike botnet activity captured on honeypots that are globally distributed. We firstly discuss features used in profiling botnets in the past and indicate how profiling IoT-based botnets in particular can be improved by leveraging DNS information out of a single DNS record. We further conduct an evaluation of our developed feature set over various Machine Learning (ML) classifiers and demonstrate the applicability of our scheme. Our resulted outputs indicate that the proposed feature set can significantly reduce botnet detection time whilst simultaneously maintaining high levels of accuracy of 99% on average under the random forest formulation.
Owen P. Dwyer, Angelos K. Marnerides, Vasileios Giotsas, Troy Mursch
GLOBECOM3
2019 Stable and Practical AS Relationship Inference with ProbLink
Colin Scott, Amogh Dhamdhere, Vasileios Giotsas, Arvind Krishnamurthy, Scott Shenker
NSDI4
2019 Dithen: A Computation-as-a-Service Cloud Platform for Large-Scale Multimedia Processing
abstract
We present Dithen, a novel computation-as-a-service (CaaS) cloud platform specifically tailored to the parallel execution of large-scale multimedia tasks. Dithen handles the upload/download of both multimedia data and executable items, the assignment of compute units to multimedia workloads, and the reactive control of the available compute units to minimize the cloud infrastructure cost under deadline-abiding execution. Dithen combines three key properties: (i) the reactive assignment of individual multimedia tasks to available computing units according to availability and predetermined time-to-completion constraints; (ii) optimal resource estimation based on Kalman-filter estimates; (iii) the use of additive increase multiplicative decrease (AIMD) algorithms (famous for being the resource management in the transport control protocol) for the control of the number of units servicing workloads. The deployment of Dithen over Amazon EC2 spot instances is shown to be capable of processing more than 80,000 video transcoding, face detection and image processing tasks (equivalent to the processing of more than 116 GB of compressed data) for less than $1 in billing cost from EC2. Moreover, the proposed AIMD-based control mechanism, in conjunction with the Kalman estimates, is shown to provide for more than 27 percent reduction in EC2 spot instance cost against methods based on reactive resource estimation. Finally, Dithen is shown to offer a 38 to 500 percent reduction of the billing cost against the current state-of-the-art in CaaS platforms on Amazon EC2 (Amazon Lambda and Amazon Autoscale). A baseline version of Dithen is currently available at dithen.com under the “AutoScale” option.
Joseph Doyle, Vasileios Giotsas, Mohammad Ashraful Anam, Yiannis Andreopoulos
IEEE Trans. Cloud Comput.2
2018 O Peer, Where Art Thou?: Uncovering Remote Peering Interconnections at IXPs
George Nomikos, Vasileios Kotronis, Pavlos Sermpezis, Petros Gigis, Lefteris Manassakis, Christoph Dietzel, Stavros Konstantaras, Xenofontas A. Dimitropoulos, Vasileios Giotsas
Internet Measurement Conference9
2017 Inferring BGP blackholing activity in the internet
abstract
The Border Gateway Protocol (BGP) has been used for decades as the de facto protocol to exchange reachability information among networks in the Internet. However, little is known about how this protocol is used to restrict reachability to selected destinations, e.g., that are under attack. While such a feature, BGP blackholing, has been available for some time, we lack a systematic study of its Internet-wide adoption, practices, and network efficacy, as well as the profile of blackholed destinations.
Vasileios Giotsas, Philipp Richter, Georgios Smaragdakis, Anja Feldmann, Christoph Dietzel, Arthur W. Berger
Internet Measurement Conference1
2017 Detecting Peering Infrastructure Outages in the Wild
abstract
Peering infrastructures, namely, colocation facilities and Internet exchange points, are located in every major city, have hundreds of network members, and support hundreds of thousands of interconnections around the globe. These infrastructures are well provisioned and managed, but outages have to be expected, e.g., due to power failures, human errors, attacks, and natural disasters. However, little is known about the frequency and impact of outages at these critical infrastructures with high peering concentration.
Vasileios Giotsas, Christoph Dietzel, Georgios Smaragdakis, Anja Feldmann, Arthur W. Berger, Emile Aben
SIGCOMM1
2016 Cloud Instance Management and Resource Prediction for Computation-as-a-Service Platforms
abstract
Computation-as-a-Service (CaaS) offerings have gained traction in the last few years due to their effectiveness in balancing between the scalability of Software-as-a-Service and the customisation possibilities of Infrastructure-as-a-Service platforms. To function effectively, a CaaS platform must have three key properties: (i) reactive assignment of individual processing tasks to available cloud instances (compute units) according to availability and predetermined time-to-completion (TTC) constraints, (ii) accurate resource prediction, (iii) efficient control of the number of cloud instances servicing workloads, in order to optimize between completing workloads in a timely fashion and reducing resource utilization costs. In this paper, we propose three approaches that satisfy these properties (respectively): (i) a service rate allocation mechanism based on proportional fairness and TTC constraints, (ii) Kalman-filter estimates for resource prediction, and (iii) the use of additive increase multiplicative decrease (AIMD) algorithms (famous for being the resource management in the transport control protocol) for the control of the number of compute units servicing workloads. The integration of our three proposals into a single CaaS platform is shown to provide for more than 27% reduction in Amazon EC2 spot instance cost against methods based on reactive resource prediction and 38% to 60% reduction of the billing cost against the current state-of-the-art in CaaS platforms (Amazon Lambda and Autoscale).
Joseph Doyle, Vasileios Giotsas, Mohammad Ashraful Anam, Yiannis Andreopoulos
IC2E2
2016 BGPStream: A Software Framework for Live and Historical BGP Data Analysis
Chiara Orsini 0001, Alistair King, Danilo Giordano, Vasileios Giotsas, Alberto Dainotti
Internet Measurement Conference4
2016 Sibyl: A Practical Internet Route Oracle
Ítalo S. Cunha, Pietro Marchetta, Matt Calder, Yi-Ching Chiu, Brandon Schlinker, Bruno V. A. Machado, Antonio Pescapè, Vasileios Giotsas, Harsha V. Madhyastha, Ethan Katz-Bassett
NSDI8
2016 Periscope: Unifying Looking Glass Querying
Vasileios Giotsas, Amogh Dhamdhere, K. C. Claffy
PAM1
2016 Media Query Processing for the Internet-of-Things: Coupling of Device Energy Consumption and Cloud Infrastructure Billing
abstract
Audio/visual recognition and retrieval applications have recently garnered significant attention within Internet-of-Things-oriented services, given that video cameras and audio processing chipsets are now ubiquitous even in low-end embedded systems. In the most typical scenario for such services, each device extracts audio/visual features and compacts them into feature descriptors, which comprise media queries. These queries are uploaded to a remote cloud computing service that performs content matching for classification or retrieval applications. Two of the most crucial aspects for such services are: (1) controlling the device energy consumption when using the service, and (2) reducing the billing cost incurred from the cloud infrastructure provider. In this paper, we derive analytic conditions for the optimal coupling between the device energy consumption and the incurred cloud infrastructure billing. Our framework encapsulates: the energy consumption to produce and transmit audio/visual queries, the billing rates of the cloud infrastructure, the number of devices concurrently connected to the same cloud server, the query volume constraint of each cluster of devices, and the statistics of the query data production volume per device. Our analytic results are validated via a deployment with: (1) the device side comprising compact image descriptors (queries) computed on Beaglebone Linux embedded platforms and transmitted to Amazon Web Services (AWS) Simple Storage Service, and (2) the cloud side carrying out image similarity detection via AWS Elastic Compute Cloud (EC2) instances, with the AWS Auto Scaling being used to control the number of instances according to the demand.
Francesco Renna, Joseph Doyle, Vasileios Giotsas, Yiannis Andreopoulos
IEEE Trans. Multim.3
2015 Mapping peering interconnections to a facility
abstract
Annotating Internet interconnections with robust physical coordinates at the level of a building facilitates network management including interdomain troubleshooting, but also has practical value for helping to locate points of attacks, congestion, or instability on the Internet. But, like most other aspects of Internet interconnection, its geophysical locus is generally not public; the facility used for a given link must be inferred to construct a macroscopic map of peering. We develop a methodology, called constrained facility search, to infer the physical interconnection facility where an interconnection occurs among all possible candidates. We rely on publicly available data about the presence of networks at different facilities, and execute traceroute measurements from more than 8,500 available measurement servers scattered around the world to identify the technical approach used to establish an interconnection. A key insight of our method is that inference of the technical approach for an interconnection sufficiently constrains the number of candidate facilities such that it is often possible to identify the specific facility where a given interconnection occurs. Validation via private communication with operators confirms the accuracy of our method, which outperforms heuristics based on naming schemes and IP geolocation. Our study also reveals the multiple roles that routers play at interconnection facilities; in many cases the same router implements both private interconnections and public peerings, in some cases via multiple Internet exchange points. Our study also sheds light on peering engineering strategies used by different types of networks around the globe.
Vasileios Giotsas, Georgios Smaragdakis, Bradley Huffaker, Matthew J. Luckie, K. C. Claffy
CoNEXT1
2015 IPv6 AS Relationships, Cliques, and Congruence
Vasileios Giotsas, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy
PAM1
2014 Inferring Complex AS Relationships
abstract
The traditional approach of modeling relationships between ASes abstracts relationship types into three broad categories: transit, peering, and sibling. More complicated configurations exist, and understanding them may advance our knowledge of Internet economics and improve models of routing. We use BGP, traceroute, and geolocation data to extend CAIDA's AS relationship inference algorithm to infer two types of complex relationships: hybrid relationships, where two ASes have different relationships at different interconnection points, and partial transit relationships, which restrict the scope of a customer relationship to the provider's peers and customers. Using this new algorithm, we find 4.5% of the 90,272 provider-customer relationships observed in March 2014 were complex, including 1,071 hybrid relationships and 2,955 partial-transit relationships. Because most peering relationships are invisible, we believe these numbers are lower bounds. We used feedback from operators, and relationships encoded in BGP communities and RPSL, to validate 20% and 6.9% of our partial transit and hybrid inferences, respectively, and found our inferences have 92.9% and 97.0% positive predictive values. Hybrid relationships are not only established betweenlarge transit providers; in 57% of the inferred hybrid transit/peering relationships the customer had a customer cone of fewer than 5 ASes.
Vasileios Giotsas, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy
Internet Measurement Conference1
2013 Inferring multilateral peering
abstract
The AS topology incompleteness problem is derived from difficulties in the discovery of p2p links, and is amplified by the increasing popularity of Internet eXchange Points (IXPs) to support peering interconnection. We describe, implement, and validate a method for discovering currently invisible IXP peering links by mining BGP communities used by IXP route servers to implement multilateral peering (MLP), including communities that signal the intent to restrict announcements to a subset of participants at a given IXP. Using route server data juxtaposed with a mapping of BGP community values, we can infer 206K p2p links from 13 large European IXPs, four times more p2p links than what is directly observable in public BGP data. The advantages of the proposed technique are threefold. First, it utilizes existing BGP data sources and does not require the deployment of additional vantage points nor the acquisition of private data. Second, it requires only a few active queries, facilitating repeatability of the measurements. Finally, it offers a new source of data regarding the dense establishment of MLP at IXPs.
Vasileios Giotsas, Shi Zhou, Matthew J. Luckie, K. C. Claffy
CoNEXT1
2013 AS relationships, customer cones, and validation
abstract
Business relationships between ASes in the Internet are typically confidential, yet knowledge of them is essential to understand many aspects of Internet structure, performance, dynamics, and evolution. We present a new algorithm to infer these relationships using BGP paths. Unlike previous approaches, our algorithm does not assume the presence (or seek to maximize the number) of valley-free paths, instead relying on three assumptions about the Internet's inter-domain structure: (1) an AS enters into a provider relationship to become globally reachable; and (2) there exists a peering clique of ASes at the top of the hierarchy, and (3) there is no cycle of p2c links. We assemble the largest source of validation data for AS-relationship inferences to date, validating 34.6% of our 126,082 c2p and p2p inferences to be 99.6% and 98.7% accurate, respectively. Using these inferred relationships, we evaluate three algorithms for inferring each AS's customer cone, defined as the set of ASes an AS can reach using customer links. We demonstrate the utility of our algorithms for studying the rise and fall of large transit providers over the last fifteen years, including recent claims about the flattening of the AS-level topology and the decreasing influence of tier-1 ASes on the global Internet.
Matthew J. Luckie, Bradley Huffaker, Amogh Dhamdhere, Vasileios Giotsas, K. C. Claffy
Internet Measurement Conference4
2013 Improving the discovery of IXP peering links through passive BGP measurements
abstract
The Internet Autonomous System (AS) topology has important implications on end-to-end routing, network economics and security. Despite the significance of the AS topology research, it has not been possible to collect a complete map of the AS interconnections due to the difficulties involved in discovering peering links. The problem of topology incompleteness is amplified by the increasing popularity of Internet eXchange Points (IXPs) and the “flattening” AS hierarchy. A recent study discovered that the number of missing peering links at a single IXP is larger than the total number of the observable peering links. As a result a large body of research focuses on measurement techniques that can alleviate the incompleteness problem. Most of these proposals require the deployment of additional BGP vantage points and traceroute monitors. In this paper we propose a new measurement methodology for improving the discovery of missing peering links through the publicly available BGP data. Our approach utilizes the traffic engineering BGP Communities used by IXPs' Route Servers to implement multi-lateral peering agreements. We are able to discover 36K additional p2p links from 11 large IXPs. The discovered links are not only invisible in previous BGP-based AS topology collections, but also 97% of those links are invisible to traceroute data from CAIDA's Ark and DIMES projects for June 2012. The advantages of the proposed technique are threefold. First, it provides a new source of previously invisible p2p links. Second, it does not require changes in the existing measurement infrastructure. Finally, it offers a new source of policy data regarding multilateral peering links at IXPs.
Vasileios Giotsas, Shi Zhou
INFOCOM1
2012 Valley-free violation in Internet routing - Analysis based on BGP Community data
abstract
The valley-free rule defines patterns of routing paths that allow the Internet Autonomous Systems (AS) to minimize their routing costs through selective announcement of BGP routes. The valley-free rule has been widely perceived as a universal property of the Internet BGP routing that is only violated due to transient configuration errors. Analysing the valley-free violations is important for a better understanding of BGP behaviour and inter-domain routing. This requires knowledge of the business relationships between ASes. The ground-truth data of AS relationships are not publicly available. Previous algorithms have inferred AS relationships based on the assumption that AS paths should be valley-free. Such inference results are biased and can not provide an objective assessment of the valley-free rule. Instead we extract the AS relationships directly from routing polices encoded in the BGP Community attribute. We are able to extract the business relationship of more than 30% of AS links based on BGP data collected from the RouteViews and RIPE RIS repositories in June 2011. We use our inferred AS relationships to analyse the valley-free violations in BGP routing. We reveal that the non valley-free paths are significantly more frequent than previously reported. As many as one fifth of AS paths in IPv6 BGP updates are valley paths. A substantial portion of these valley paths are persistent during the whole month of measurement. These observations strongly indicate that the valley paths are not merely a result of BGP misconfigurations. Instead they are the outcome of complex business relationships and deliberate policies by ASes using distinct unconventional models.
Vasileios Giotsas, Shi Zhou
ICC1
2011 Detecting and assessing the hybrid IPv4/IPv6 as relationships
abstract
The business relationships between the Autonomous Systems (ASes) play a central role in the BGP routing. The existing relationship inference algorithms are profoundly based on the valley-free rule and generalize their inference heuristics for both the IPv4 and IPv6 planes, introducing unavoidable inference artifacts. To discover and analyze the Type-of-Relationship (ToR) properties of the IPv6 topology we mine the BGP Communities attribute which provides an unexploited wealth of reliable relationship information. We obtain the actual relationships for 72% of the IPv6 AS links that are visible in the RouteViews and RIPE RIS repositories. Our results show that as many as 13% of AS links that serve both IPv4 and IPv6 traffic have different relationships depending on the IP version. Such relationships are characterized as hybrid. We observe that links with hybrid relationships are present in a large number of IPv6 AS paths. Furthermore, an unusually large portion of IPv6 AS paths violate the valley-free rule, indicating that the global reachability in the IPv6 Internet requires the relaxation of the valley-free rule. Our work highlights the importance of correctly inferring the AS relationships and the need to appreciate the distinct characteristics of IPv6 routing policies.
Vasileios Giotsas, Shi Zhou
SIGCOMM1
2009 A mobile healthcare system using IMS and the HL7 framework
abstract
The advent of Wireless Body-Area Sensor Networks (WBASNs) technologies enables the autonomic and remote collection of realtime physiological data related to the health status of patients with chronic diseases. At the same time the advances in wireless communication systems make possible the "anywhere, anytime" delivery of such data to medical staff and caregivers in order to allow them to easily monitor and quickly respond in emergencies. In this paper, we propose a system architecture that utilizes the IMS (IP Multimedia Subsystem) and the HL7 (Health Level Seven) technologies to implement a mobile and interoperable healthcare system to support WBASNs in a healthcare environment.
Stefanos A. Nikolidakis, Vasileios Giotsas, Dimitrios D. Vergados, Christos Douligeris
ANCS2