Levente Csikor

dblp:90/10890 · DBLP profile ↗
← Back
17ranked-venue papers
7as first author
6since 2021 · last 2024
0000-0002-1837-2158ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 4 first-author · 1 since 2021Software engineering, systems software and programming languages · 4 · 2 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 JUNCTION: A Scalable Multi-Access Solution Using Programmable Switches
abstract
Multi-access networks are increasingly important for reliable end-to-end connectivity and enhanced throughput performance. A scalable multi-access solution is required to roll out multi-access networks at scale. However, existing CPU-based solutions can no longer scale sustainably, as network traffic has outgrown the CPU performance growth. Consequently, hardware accelerators offer a compelling alternative. This paper introduces JUNCTION, a scalable multi-access solution designed using programmable switches. JUNCTION features a multipath protocol tailored to the hardware constraints and optimized for efficient memory utilization, enabling it to handle a large number of multipath sessions. We validate JUNCTION on a 5G-WiFi multi-access testbed. Our analysis demonstrates that it can scale an order of magnitude better than existing solutions.
Xin Zhe Khooi, Cha Hwan Song, Satis Kumar Permal, Nishant Budhdev, Levente Csikor, Raj Joshi, Mun Choon Chan
SECON5
2024 RollBack: A New Time-Agnostic Replay Attack Against the Automotive Remote Keyless Entry Systems
abstract
Automotive Keyless Entry (RKE) systems provide car owners with a degree of convenience, allowing them to lock and unlock their car without using a mechanical key. Today’s RKE systems implement disposable rolling codes, making every key fob button press unique, effectively preventing simple replay attacks. However, a prior attack called RollJam was proven to break all rolling code–based systems in general. By a careful sequence of signal jamming, capturing, and replaying, an attacker can become aware of the subsequent valid unlock signal that has not been used yet. RollJam, however, requires continuous deployment indefinitely until it is exploited. Otherwise, the captured signals become invalid if the key fob is used again without RollJam in place. We introduce RollBack, a new replay-and-resynchronize attack against most of today’s RKE systems. In particular, we show that even though the one-time code becomes invalid in rolling code systems, replaying a few previously captured signals consecutively can trigger a rollback-like mechanism in the RKE system. Put differently, the rolling codes become resynchronized back to a previous code used in the past from where all subsequent yet already used signals work again. Moreover, the victim can still use the key fob without noticing any difference before and after the attack. Unlike RollJam, RollBack does not necessitate jamming at all. In fact, it requires signal capturing only once and can be exploited at any time in the future as many times as desired. This time-agnostic property is particularly attractive to attackers, especially in car-sharing/renting scenarios in which accessing the key fob is straightforward. However, while RollJam defeats virtually any rolling code–based system, vehicles might have additional anti-theft measures against malfunctioning key fobs, hence against RollBack. Our ongoing analysis (with crowd-sourced data) against different vehicle makes and models has revealed that ∼ 50% of the examined vehicles in the Asian region are vulnerable to RollBack, whereas the impact tends to be smaller in other regions, such as Europe and North America.
Levente Csikor, Hoon Wei Lim, Jun Wen Wong, Soundarya Ramesh, Rohini Poolat Parameswarath, Mun Choon Chan
ACM Trans. Cyber Phys. Syst.1
2022 ZeroDNS: Towards Better Zero Trust Security using DNS
abstract
Due to the increasing adoption of public cloud services, virtualization, IoT, and emerging 5G technologies, enterprise network services and users, e.g., remote workforce, can be at any physical location. This results in that network perimeter cannot be defined precisely anymore, making adequate access control with traditional perimeter-based network security models (e.g., firewall, DMZ) challenging. The Zero Trust (ZT) network access framework breaks with this traditional approach by removing the implicit trust in the network. ZT demands strong authentication, authorization, and encryption techniques irrespective of the physical location of the devices. While several prominent companies have embraced ZT (e.g., Google, Microsoft, Cloudflare), its adoption has several obstacles.
Levente Csikor, Sriram Ramachandran, Anantharaman Lakshminarayanan
ACSAC1
2021 Privacy of DNS-over-HTTPS: Requiem for a Dream?
abstract
The recently proposed DNS-over-HTTPS (DoH) protocol is becoming increasingly popular in addressing the privacy concerns of exchanging plain-text DNS messages over potentially malicious transit networks (e.g., mass surveillance at ISPs). By employing HTTPS to encrypt DNS communications, DoH traffic inherently becomes indistinguishable from regular encrypted Web traffic, rendering active disruption (e.g., downgrading to the plain-text DNS) by transit networks extremely hard. In this work, we investigate whether DoH traffic is indeed indistinguishable from encrypted Web traffic. To this end, we collect several DoH traffic traces corresponding to 25 resolvers (including major ones, e.g., Google and Cloudftare) by visiting thousands of domains in Alexa's list of top-ranked websites at different geographical locations and environments. Based on the collected traffic, we train a machine learning model to classify HTTPS traffic as either Web or DoH. With our DoH identification model in place, we show that an authoritarian ISP can identify ∼97.4% (∼90%) of the DoH packets correctly in a closed-world (open-world) setting while only misclassifying 1 in 10,000 Web packets. To counter this DoH identification model, we propose an effective mitigation technique, making the identification model impractical for ISPs to filter and consequently downgrade DoH to plain-text DNS communications.
Levente Csikor, Min Suk Kang, Dinil Mon Divakaran
EuroS&P1
2021 In-Network Applications: Beyond Single Switch Pipelines
abstract
The emergence of commodity programmable switches have spawned a series of innovations in the network data plane. By making the traditionally stateless network architectures to be stateful, we can realize a diverse set of applications, e.g., networking monitoring, load-balancing, firewalls, entirely in the data plane. On the other hand, many existing in-network applications assume that the underlying switch is single-pipelined, however, in reality, commodity programmable switches are designed with multiple pipelines in mind. While this approach enables high scalability, it has introduced a serious disadvantage: maintaining states across the pipelines is non-trivial. For instance, without involving the control plane it is infeasible to keep track of a request and its response in different pipelines, thereby rendering many in-network proposals impractical.In this paper, we highlight this fundamental limitation that holds back the practical widespread adoption of stateful applications in today’s multi-pipeline switches. By scrutinizing recent in-network approaches, we identify that majority of them cannot operate as they are proposed on multi-pipeline switches. After raising awareness of this inevitable consequence, we discuss a set of possible workarounds for in-network applications to overcome this issue on multi-pipeline switches.
Xin Zhe Khooi, Levente Csikor, Jialin Li 0001, Dinil Mon Divakaran
NetSoft2
2021 Revisiting Heavy-Hitter Detection on Commodity Programmable Switches
abstract
Existing in-network heavy-hitter detection algorithms suffer from several shortcomings. On the one hand, most of the algorithms perform monitoring in intervals and reset the data structures in between; consequently, a notable amount of heavy hitters (HH) spanning across the intervals go undetected. On the other hand, the algorithms consume substantial hardware resources, potentially hindering other data plane functionalities to be integrated on the same device.In this work, we revisit the state-of-the-art in-network approaches in this regard and identify that they fall short in over-coming the aforementioned issues. In particular, we investigate whether it is possible to design a heavy-hitter detection algorithm that provides high accuracy without consuming substantial re-sources, thereby making it feasible to integrate with concurrent applications. To this end, we propose dSketch, a time-decaying algorithm for in-network heavy-hitter detection. Trace-driven simulations and evaluations on the Intel Tofino-based commodity switches show that dSketch significantly improves the detection rate of HHs by 5–10% while being resource- and operation-efficient in contrast to state-of-the-art approaches. Moreover, we show that dSketch can be integrated with standard switch functionalities such as switch. p4 with additional resources spared, offering itself as a compelling solution for switch data plane designers.
Xin Zhe Khooi, Levente Csikor, Jialin Li 0001, Min Suk Kang, Dinil Mon Divakaran
NetSoft2
2020 Towards Low Latency Industrial Robot Control in Programmable Data Planes
abstract
Due to the advanced control and machine learning techniques, today's industrial robots are faster and more accurate than human workers in well-structured repetitive tasks. However, in case of sudden changes in the operational area, such as unexpected obstacles or humans, robots have to be continuously monitored by powerful controllers for swift interventions (i.e., send emergency stop signals). As in the case of many verticals (e.g., transportation, shopping), the proliferation of Software-Defined Networking (SDN) and Network Function Virtualization (NFV) has started to captivate industry 4.0 as well in order to benefit from low infrastructure costs, and flexible management and resource provisioning. Besides all the advantages of the centralized approach, however, in critical situations (e.g., possible collisions, actuator damages or human injuries) the required ultra-low latency between the robots and the controller becomes an all-important factor, and one of the main concerns, at the same time, for industry leaders making the decision towards this paradigm shift. In this paper, we argue that by relying on recently emerged stateful and programmable data planes, it is possible to fill this gap by offloading latency-critical applications to the network, thereby bringing some intelligence much closer the robots. We present the first in-network robotic control application that is capable to intercept the communication between the robot and the controller and craft responses immediately if needed. In particular, we show that we can detect position threshold violations entirely in the data plane, close to the robot, and deliver emergency stop commands within no time with full compliance to the actual TCP session and application states.
Fabricio Rodriguez, Levente Csikor, Carlos Recalde, Christian Esteve Rothenberg, Gergely Pongrácz
NetSoft2
2020 DIDA: Distributed In-Network Defense Architecture Against Amplified Reflection DDoS Attacks
abstract
With each new DDoS attack potentially becoming a higher intensity attack than the previous ones, current ISP measures of over-provisioning or employing a scrubbing service are becoming ineffective and inefficient. We argue that we need an in-network solution (i.e., entirely in the data plane), to detect DDoS attacks, identify the corresponding traffic and mitigate promptly. In this paper, we propose the first distributed in-network defense architecture, DIDA, to cope with the sophisticated amplified reflection DDoS (AR-DDoS) attacks. We leverage programmable stateful data planes and efficient data structures and show that it is possible to keep track of per-user connections in an automated and distributed manner without overwhelming the network controller. Building on top of this data, DIDA can easily detect if unsolicited attack packets are sent towards a victim within an ISP network. Once an attack is detected, the routers at the network edge automatically block the malicious sources. We prototype DIDA in P4. Our preliminary experiments show that DIDA can detect and mitigate 99.8% of amplification attacks containing 7, 000 different sources while requiring less than 1% of the memory of current programmable switches.
Xin Zhe Khooi, Levente Csikor, Dinil Mon Divakaran, Min Suk Kang
NetSoft2
2020 Transition to SDN is HARMLESS: Hybrid Architecture for Migrating Legacy Ethernet Switches to SDN
abstract
Software-Defined Networking (SDN) offers a new way to operate, manage, and deploy communication networks and to overcome many long-standing problems of legacy networking. However, widespread SDN adoption has not occurred yet due to the lack of a viable incremental deployment path and the relatively immature present state of SDN-capable devices on the market. While continuously evolving software switches may alleviate the operational issues of commercial hardware-based SDN offerings, namely lagging standards-compliance, performance regressions, and poor scaling, they fail to match the cost-efficiency and port density. In this paper, we propose HARMLESS, a new SDN switch design that seamlessly adds SDN capability to legacy network gear, by emulating the OpenFlow switch OS in a separate software switch component. This way, HARMLESS enables a quick and easy leap into SDN, combining the rapid innovation and upgrade cycles of software switches with the port density and cost-efficiency of hardware-based appliances into a fully dataplane-transparent and vendor-neutral solution. HARMLESS incurs an order of magnitude smaller initial expenditure for an SDN deployment than existing turnkey vendor SDN solutions while, at the same time, yields matching, or even better, data plane performance for smaller enterprises.
Levente Csikor, Mark Szalay, Gábor Rétvári, Gergely Pongrácz, Dimitrios P. Pezaros, László Toka
IEEE/ACM Trans. Netw.1
2019 Tuple space explosion: a denial-of-service attack against a software packet classifier
abstract
Efficient and highly available packet classification is fundamental for various security primitives. In this paper, we evaluate whether the de facto Tuple Space Search (TSS) packet classification algorithm used in popular software networking stacks such as the Open vSwitch is robust against low-rate denial-of-service attacks. We present the Tuple Space Explosion (TSE) attack that exploits the fundamental space/time complexity of the TSS algorithm.
Levente Csikor, Dinil Mon Divakaran, Min Suk Kang, Attila Korösi, Balázs Sonkoly, Dávid Haja, Dimitrios P. Pezaros, Stefan Schmid 0001, Gábor Rétvári
CoNEXT1
2018 Toward a Sweet Spot of Data Plane Programmability, Portability, and Performance: On the Scalability of Multi-Architecture P4 Pipelines
abstract
Despite having received less attention compared to the control and application plane aspects of software-defined networking (SDN), the data plane is a critical piece of the puzzle. P4 takes SDN datapaths to the next level by unlocking deep programmability through a target-independent high-level programming language that can be compiled to run on a variety of targets (e.g., ASIC, FPGA, and GPU). This paper presents the design and evaluation of our sweet spot approach on SDN datapaths, offering three contending characteristics, namely, performance, portability, and scalability in multiple realistic scenarios. The focus is on our Multi-Architecture Compiler System for Abstract Data Planes proposal, which blends the high-level protocol-independent programmability of P4 with low-level but cross-platform (HW & SW) Application Programming Interfaces brought by OpenDataPlane, this way supporting many different vendors and architectures. Besides the performance evaluation for varying packet sizes and memory lookup tables, we investigate the impact of increasing pipeline complexity ranging from elemental L2 switching to more complex data center and border network gateways. We investigate the scalability for increasing the number of cores and evaluate a novel method for run-time core reallocation. Furthermore, we run experiments on different target platforms (e.g., ×86, ARM, 10G/100G), inducing different ways of packet mangling through specific drivers (e.g., DPDK and Netmap), and compare the results to state-of-the-art datapath alternatives.
P. Gyanesh Patra, Fabricio Rodriguez, Juan Sebastian Mejia, Daniel Lazkani Feferman, Levente Csikor, Christian Esteve Rothenberg, Gergely Pongrácz
IEEE J. Sel. Areas Commun.5
2017 End-Host Driven Troubleshooting Architecture for Software-Defined Networking
abstract
The high variability in traffic demands, the advanced networking services at various layers (e.g., load-balancers), and the steady penetration of SDN technology and virtualization make the crucial network troubleshooting tasks ever more challenging over multi-tenant environments. Service degradation is first realized by the users and, as being the only one having visibility to many relevant information (e.g., connection details) required for accurate and timely problem resolution, the infrastructure layer is often forced upon continuous monitoring resulting in wasteful resource management, not to mention the long time frames. In this paper, we propose an End-host-Driven Troubleshooting architecture (EDT), where users are able to share the application-specific connection details with the infrastructure to accelerate the identification of root causes of performance degradation, and to avoid the need for always-on, resource-intensive, and network-wide monitoring. Utilizing EDT, we provide some essential tools for real end-to-end trace routing (PTR), identifying packet losses, and carry out hop-by- hop latency measurements (HEL). In contrast to existing proposals, PTR traces the practical production traffic without the need of crafted probe packets by means of careful tagging mechanisms and additional ephemeral capturing flow rules. Besides involving negligible data plane deterioration, in certain cases PTR can drastically reduce the time needed to find a traversed path compared to existing solutions. Finally, by means of individual network functions, HEL measures the latency of each link along the found path without involving the controller into the calculation, hence resulting in significant reduction of control plane overhead.
Levente Csikor, Dimitrios P. Pezaros
GLOBECOM1
2016 Dataplane Specialization for High-performance OpenFlow Software Switching
abstract
OpenFlow is an amazingly expressive dataplane programming language, but this expressiveness comes at a severe performance price as switches must do excessive packet classification in the fast path. The prevalent OpenFlow software switch architecture is therefore built on flow caching, but this imposes intricate limitations on the workloads that can be supported efficiently and may even open the door to malicious cache overflow attacks. In this paper we argue that instead of enforcing the same universal flow cache semantics to all OpenFlow applications and optimize for the common case, a switch should rather automatically specialize its dataplane piecemeal with respect to the configured workload. We introduce ESwitch, a novel switch architecture that uses on-the-fly template-based code generation to compile any OpenFlow pipeline into efficient machine code, which can then be readily used as fast path. We present a proof-of-concept prototype and we demonstrate on illustrative use cases that ESwitch yields a simpler architecture, superior packet processing speed, improved latency and CPU scalability, and predictable performance. Our prototype can easily scale beyond 100 Gbps on a single Intel blade even with complex OpenFlow pipelines.
László Molnár, Gergely Pongrácz, Gábor Enyedi, Zoltán Lajos Kis, Levente Csikor, Ferenc Juhász, Attila Korösi, Gábor Rétvári
SIGCOMM5
2014 SDN based testbeds for evaluating and promoting multipath TCP
abstract
Multipath TCP is an experimental transport protocol with remarkable recent past and non-negligible future potential. It has been standardized recently, however the evaluation studies focus only on a limited set of isolated use-cases and a comprehensive analysis or a feasible path of Internet-wide adoption is still missing. This is mostly because in the current networking practice it is unusual to configure multiple paths between the endpoints of a connection. Therefore, conducting and precisely controlling multipath experiments over the real “internet” is a challenging task for some experimenters and impossible for others. In this paper, we invoke SDN technology to make this control possible and exploit large-scale internet testbeds to conduct end-to-end MPTCP experiments. More specifically, we establish a special purpose control and measurement framework on top of two distinct internet testbeds. First, using the OpenFlow support of GÉANT, we build a testbed enabling measurements with real traffic. Second, we design and establish a publicly available large-scale multipath capable measurement framework on top of PlanetLab Europe and show the challenges of such a system. Furthermore, we present measurements results with MPTCP in both testbeds to get insight into its behavior in such not well explored environment.
Balázs Sonkoly, Felician Németh, Levente Csikor, László Gulyás, András Gulyás
ICC3
2014 ESCAPE: extensible service chain prototyping environment using mininet, click, NETCONF and POX
abstract
Mininet is a great prototyping tool which combines existing SDN-related software components (e.g., Open vSwitch, OpenFlow controllers, network namespaces, cgroups) into a framework, which can automatically set up and configure customized OpenFlow testbeds scaling up to hundreds of nodes. Standing on the shoulders of Mininet, we implement a similar prototyping system called ESCAPE, which can be used to develop and test various components of the service chaining architecture. Our framework incorporates Click for implementing Virtual Network Functions (VNF), NETCONF for managing Click-based VNFs and POX for taking care of traffic steering. We also add our extensible Orchestrator module, which can accommodate mapping algorithms from abstract service descriptions to deployed and running service chains.
Attila Csoma, Balázs Sonkoly, Levente Csikor, Felician Németh, András Gulyás, Wouter Tavernier, Sahel Sahhaf
SIGCOMM3
2013 A large-scale multipath playground for experimenters and early adopters
abstract
Multipath TCP is an experimental transport protocol with remarkable recent past and non-negligible future potential. However the lack of available large-scale testbeds and publicly accessible multiple paths grossly prohibits the adoption of the technology. Here, we demonstrate a large-scale multipath playground deployed on PlanetLab Europe, which can be used either by experimenters and researchers to test and verify their multipath-related ideas (e.g. enhancing congestion control, fairness or even the arrangement of multiple paths) and also by early adopters to enhance their Internet connection even if single-homed.
Felician Németh, Balázs Sonkoly, Levente Csikor, András Gulyás
SIGCOMM3
2013 Optimizing IGP link costs for improving IP-level resilience with Loop-Free Alternates
Levente Csikor, János Tapolcai, Gábor Rétvári
Comput. Commun.1