VLDB 2026 Research / reviewers in the wild / expert
Raouf Boutaba
dblp:b/RaoufBoutaba
· DBLP profile ↗
366ranked-venue papers
18as first author
70since 2021 · last 2026
0000-0001-7936-6862ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 247 · 12 first-author · 37 since 2021Systems, architecture and hardware · 13 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 1 first-authorSoftware engineering, systems software and programming languages · 5Security and privacy · 4 · 2 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 1Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Over-Threshold Multiparty Private Set Intersection for Collaborative Network Intrusion Detection
Onur Eren Arpaci, Raouf Boutaba, Florian Kerschbaum |
NSDI | 2 |
| 2026 | Online Rounding and Pricing Schemes for k-Rental ProblemsabstractWe study two online resource allocation problems with reusability in an adversarial setting, namely \problemkRentalFD and \problemkRentalVD. In both problems, a decision-maker manages k identical reusable units and faces a sequence of rental requests over time. We develop theoretically grounded relax-and-round algorithms with provable competitive ratio guarantees for both settings. For \problemkRentalFD, we present an optimal randomized algorithm that achieves the best possible competitive ratio. The algorithm first computes an optimal fractional allocation using a price-based approach, and then applies a novel lossless online rounding scheme to obtain an integral solution. For \problemkRentalVD, we first establish the impossibility of achieving lossless online rounding. We then introduce a limited-correlation rounding technique that treats each unit independently while introducing controlled dependencies across allocation decisions involving the same unit. Combined with a carefully-crafted price-based method for computing the fractional allocation, this approach yields an order-optimal competitive ratio for the variable-duration setting. Hossein Nekouyan, Bo Sun 0004, Raouf Boutaba, Xiaoqi Tan |
WWW | 3 |
| 2026 | Leveraging LLM for Enhanced Incident Management in Wireless NetworksabstractIncident management in telecommunications networks generates large volumes of incident management tickets (IMTs), each containing heterogeneous and often unstructured text describing service outages, performance degradations, or security issues. Accurately categorizing these IMTs into multiple impact and cause labels is essential for rapid diagnosis and resolution. However, existing rule-based and standard language-model-based approaches struggle with noisy data, overlapping categories, and limited contextual understanding. To address these challenges, we propose two complementary solutions for automated multi-label classification of IMTs. To mitigate the effects of noisy data and overlapping categories, the first solution employs an encoder-based language model (i.e., Bidirectional Encoder Representations from Transformers (BERT)) with a relevance-guided feature selection strategy that focuses on semantically meaningful attributes. To improve contextual understanding and label consistency, the second solution leverages a decoder-based large language model (i.e., Phi-3.5) enhanced with retrieval-augmented generation (RAG) and a novel probabilistic re-ranking mechanism to refine label predictions. Experimental results show that our encoder-only model achieves an F1 score of 79.20%, while our RAG-enhanced decoder model achieves 94.98%, outperforming traditional machine learning models and BERT baselines by 23.59% and 29% on average, respectively. These findings demonstrate that combining fine-tuned language models with intelligent retrieval and re-ranking significantly improves classification accuracy in incident management systems. Md. Shamim Towhid, Nasik Sami Khan, Nashid Shahriar, Massimo Tornatore, Raouf Boutaba, Aladdin Saleh |
IEEE J. Sel. Areas Commun. | 5 |
| 2026 | 5Guard: Isolation-Aware End-to-End Slicing of 5G NetworksabstractNetwork slicing logically partitions the 5G infrastructure to cater to diverse verticals with varying requirements. However, resource sharing exposes the slices to threats and performance degradation, making slice isolation essential. Fully isolating slices is resource-prohibitive, prompting the need for isolation-aware network slicing, where each slice is assigned a tailored isolation level to balance security, usability, and overhead. This paper investigates end-to-end 5G network slicing with resource isolation from the perspective of the infrastructure provider, ensuring compliance with the customers' service-level agreements. We formulate the online 5G isolation-aware network slicing (5G-INS) as a mixed-integer programming problem, modeling realistic slice isolation levels and integrating slice prior itization. To solve 5G-INS, we propose 5Guard, a novel adaptive framework that leverages an ensemble of custom optimization algorithms to achieve the best solution within resource budget and time constraints. Our results show that 5Guard increases profit by up to 15.1% and admission by up to 33.5% in a real-world large-scale network compared to the best-performing individual. Furthermore, we analyze the trade-offs between isolation levels, their impact on resource utilization, and the effects of slice placement, demonstrating significant advantages over baseline approaches that enforce uniform isolation policies. Mehdi Bolourian, Noura Limam, Mohammad Ali Salahuddin 0001, Raouf Boutaba |
IEEE Trans. Mob. Comput. | 4 |
| 2026 | Active Learning for Transformer-Based Fault Diagnosis in 5G and Beyond Mobile NetworksabstractAs 5G and beyond mobile networks evolve, their increasing complexity necessitates advanced, automated, and datadriven fault diagnosis methods. While traditional data-driven methods falter with modern network complexities, Transformer models have proven highly effective for fault diagnosis through their efficient processing of sequential and time-series data. However, these Transformer-based methods demand substantial labeled data, which is costly to obtain. To address the lack of labeled data, we propose a novel active learning (AL) approach designed for Transformer-based fault diagnosis, tailored to the time-series nature of network data. AL reduces the need for extensive labeled datasets by iteratively selecting the most informative samples for labeling. Our AL method exploits the interpretability of Transformers, using their attention weights to create dependency graphs that represent processing patterns of data points. By formulating a one-class novelty detection problem on these graphs, we identify whether an unlabeled sample is processed differently from labeled ones in the previous training cycle and designate novel samples for expert annotation. Extensive experiments on real-world datasets show that our AL method achieves higher F1-scores than state-of-the-art AL algorithms with 50% fewer labeled samples and surpasses existing methods by up to 150% in identifying samples related to unseen fault types. Seyed Soheil Johari, Massimo Tornatore, Nashid Shahriar, Raouf Boutaba, Aladdin Saleh |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2026 | Cramér-Rao Bound Optimization for Multi-Functional Surface-Aided ISAC Systems
Runlong Ye 0001, Yuyang Peng, Ming Yue 0002, Fawaz AL-Hazemi, Juho Lee 0002, Raouf Boutaba |
IEEE Trans. Wirel. Commun. | 7 |
| 2025 | Resource Allocation for Satellite QKD Networks with Atmospheric ForecastabstractQuantum Key Distribution (QKD) is a foundational technology for future secure communications, and several QKD networks have been already deployed and tested around the world using optical fibers. However, these networks cannot scale in size due to the inefficiency of fiber QKD networks with increasing distances, making satellite networks a major candidate for long-distance QKD networks. In satellite QKD networks, satellites and ground stations can act as trusted relays, distributing keys between satellite-ground station pairs to serve requests among ground stations. Satellite QKD networks face fundamental challenges due the time-varying nature of the connection between ground stations and satellites, caused by both the satellite’s orbital movement and fluctuating atmospheric attenuation. Thus, it is necessary to design novel schemes to dynamically allocate resources for satellite QKD networks that adapt to evolving network conditions in different time intervals. In this work, we investigate the problem of resource allocation in satellite QKD networks taking into account the changing key generation rates, calculated according to evolving weather conditions and satellite visibility. We first model the achievable key rate of connections between satellite and ground stations under different weather conditions, which is used as an input for optimization. We formulate a Mixed-Integer Linear Programming (MILP) model to allocate resources in satellite QKD networks, which decides both link assignments (i.e., deciding which ground to connect to for satellites) and the appropriate routing path for the trusted relay. In addition, the MILP models multiple timeslots and considers keys stored in the quantum key pool (QKP), allowing keys generated during low-load periods to be used later during high-load periods. Moreover, we propose to decide the link configuration with heuristic algorithms and then utilize ILP to decide the appropriate routing path for the trusted relay, which significantly reduces the execution time. The numerical results show that incorporating link configuration within the ILP achieves up to 20% more total served keys compared to heuristicbased baseline approaches, but with an execution time up to 700x longer. Sun Gyu Park, Qiaolun Zhang, Raul C. Almeida, Mehdi Bolourian, Massimo Tornatore, Raouf Boutaba |
CNSM | 6 |
| 2025 | Routing and Wavelength Assignment with Minimal Attack Radius for QKD NetworksabstractQuantum Key Distribution (QKD) can distribute keys with guaranteed security but remains susceptible to key exchange interruption due to physical-layer threats, such as high-power jamming attacks. To address this challenge, we first introduce a novel metric, namely Maximum Number of Affected Requests (maxNAR), to quantify the worst-case impact of a single physical-layer attack, and then we investigate a new problem of Routing and Wavelength Assignment with Minimal Attack Radius (RWA-MAR). We formulate the problem using an Integer Linear Programming (ILP) model and propose a scalable heuristic to efficiently minimize maxNAR. Our approach incorporates key caching through Quantum Key Pools (QKPs) to enhance resilience and optimize resource utilization. Moreover, we model the impact of different QKD network architectures, employing Optical Bypass (OB) for optical switching of quantum channels and Trusted Relay (TR) for secure key forwarding. Moreover, a tunable parameter is designed in the heuristic to guide the preference for OB or TR, offering enhanced adaptability and dynamic control in diverse network scenarios. Simulation results show our method significantly outperforms the baseline in terms of security and scalability. Qiaolun Zhang, Zongshuai Yang, Stefano Bregni, Alberto Gatto 0001, Raouf Boutaba, Massimo Tornatore |
GLOBECOM | 6 |
| 2025 | Few-Shot Domain Adaptation for Effective Data Drift Mitigation in Network ManagementabstractMachine Learning (ML) models are increasingly employed for critical network management tasks such as traffic prediction, anomaly detection, root cause analysis, and resource allocation. A major issue in the reliability of these models is data drift, which refers to the discrepancy between training data (source domain) and test/operational data (target domain) caused by changes in network conditions and configurations. Domain adaptation, which aims to develop robust models that can generalize well across different but related domains, is a promising solution to the data drift issue. However, existing domain adaptation methods often fall short in few-shot scenarios, where target domain data is limited due to high data collection costs or restricted operational network access. Furthermore, the existing methods require the network management ML models to be frequently retrained or fine-tuned over time to adapt to the changes in data distributions, leading to high operational costs. To address these limitations, we propose a novel, model-agnostic domain adaptation approach specifically designed for few-shot scenarios and network data. In our approach, network management ML models are trained exclusively on source domain data with all the input features included, while a two-step method aligns test data samples from the target domain with the source domain during inference. The first step employs our proposed causal-inference-based feature separation (FS) method, which introduces a novel perspective by treating domain shift as soft interventions (interventions that adjust the probability distribution of features rather than making absolute changes) on a set of specific features. FS effectively separates domain-variant and domain-invariant features directly in the input space, even with limited target training data. In the second step of our approach, we propose a Generative Adversarial Network (GAN)-based reconstruction method, trained exclusively on source data, to reconstruct the domain-variant features given the domain-invariant features. During inference, the GAN model maps the domain-variant features of the target domain samples to the source domain distribution, allowing the use of domain-variant features without causing cross-domain performance degradation. Since our approach trains the network management ML models exclusively on source domain data, it eliminates the need for retraining or fine-tuning these models as network conditions or data distributions evolve over time, significantly reducing costs and operational overhead. Comprehensive evaluations on two public 5G network datasets demonstrate an average 52% improvement in mitigating data drift compared to state-of-the-art methods in terms of F1-score. Seyed Soheil Johari, Massimo Tornatore, Raouf Boutaba, Aladdin Saleh |
ICDCS | 3 |
| 2025 | Link Configuration for Fidelity-Constrained Entanglement Routing in Quantum Networks
Qiaolun Zhang, Nicola Di Cicco, Memedhe Ibrahimi, Raul C. Almeida, Alberto Gatto 0001, Raouf Boutaba, Massimo Tornatore |
INFOCOM | 6 |
| 2025 | Multi-Connectivity for Enhanced Throughput: a Critical StudyabstractMulti-connectivity is anticipated to provide more reliable, higher data rate connections for cellular network users by leveraging all available radio resources across base stations within one or multiple radio access technology(ies) (RAT). It aims to improve user mobility through multi-RAT connections or mitigate quality of service (QoS) degradation when users connect to congested cells through load-balancing traffic among base stations and distributing the user's flow across multiple links. Although many studies have investigated the benefits of multi-connectivity across various network deployments using analytical models or simulated environments, we critically assess these reported gains, particularly regarding system throughput. We argue that multi-connectivity's advantages are primarily restricted to scenarios with a low user-to-base station ratio and that dense networks are less likely to benefit. We formulate the user-to-base station association and resource allocation within a proportional fair (PF) setting across varying user densities to examine this. Our findings demonstrate that multi-connectivity offers no superiority over the PF single-connectivity baseline in dense networks. Furthermore, in sparse networks, we show that while multi-connectivity can potentially enhance system throughput, it does not significantly improve individual users' QoS, as the PF single-connectivity scheme can offer sufficient resources to every user. Amirmohammad Ghasemi, Noura Limam, Raouf Boutaba, Aladdin Saleh |
NOMS | 3 |
| 2025 | Blink: A P4-Based 5G Centralized UnitabstractThe stringent quality of service (QoS) requirements in 5G networks, particularly for ultra-reliable low-latency communication (urLLC) use cases, pose significant challenges for the centralized unit user plane (CU-UP) within the Radio Access Network (RAN). Current general-purpose processor (GPP)-based CU-UP deployments struggle to meet stringent QoS requirements, such as sub-millisecond latency and high reliability, especially under high traffic loads. We propose Blink, a P4-based system that offloads CU-UP functions to programmable switch ASICs, enabling high-speed packet processing and improved QoS. Blink employs a novel trigger-based offloading mechanism that can be dynamically adapted to network conditions, ensuring seamless transitions between GPP-based and P4-based processing. In our evaluations, Blink achieves a 1,941× lower median packet processing latency compared to GPP-based CU-UP deployments, while delivering 12% higher throughput and maintaining near-zero packet loss of 0.001%, crucial for urLLC applications. These improvements are sustained across multiple distributed units (DUs) and user equipment (UEs), making Blink a scalable and flexible solution for enhancing CU-UP performance in 5G networks. Mohamed Rouili, Raouf Boutaba |
NOMS | 2 |
| 2025 | vNetRunner: Per-VNF Slice Modeling for 5G and Beyond NetworksabstractThe adoption of virtualization in 5G and beyond networks enables the creation of network slices tailored to specific application requirements. While this flexibility is transformative, it introduces new challenges in slice management and orchestration (MANO). AI-based techniques are becoming essential for automated slice MANO. However, their effectiveness relies on the accuracy of network models that map VNF configurations and resource allocations to slice performance. Previous approaches, including simulations, control theory, and machine learning, face limitations such as high computational complexity, limited visibility, large data requirements, or specific use cases, e.g., in data center networks. In this work, we present vNetRunner, a framework for slice modeling using individually trained virtual network function models. We validate our framework using datasets from an open-source 5G testbed, focusing on traffic metrics such as mean delay and throughput. Our results demonstrate that vNetRunner estimates mean packet delay and throughput with Wasserstein distances of 6 ms and 0.554 Mbps, respectively, achieving execution times that are an order of magnitude faster than the state-of-the-art modeling approaches. Bo Sun 0004, Mohammad A. Salahuddin 0002, Raouf Boutaba, Aladdin Saleh |
NOMS | 4 |
| 2025 | RAID: Root Cause Anomaly Identification and Diagnosis
Joël Roman Ky, Bertrand Mathieu, Abdelkader Lahmadi, Minqi Wang, Nicolas Marrot, Raouf Boutaba |
ECML/PKDD (8) | 6 |
| 2025 | vChainnet: Accurate and Scalable End-to-End Slice Modeling for 5G and Beyond NetworksabstractThe need for accurate and scalable modeling of 5G and beyond networks has recently emerged, driven by the reliance on virtual network functions (VNFs) and network slicing. Unfortunately, traditional network modeling approaches fail to capture 5G network behavior since they disregard the domainspecific challenges of modeling 5G networks. We propose vChainNet, the first end-to-end network modeling framework that provides accurate, scalable, and generalizable per-VNF and slice-level modeling for 5G and beyond networks. vChainNet introduces a modular, sequence-to-sequence deep learning architecture that models each VNF independently and composes the per-VNF models for end-to-end slice delay prediction. Our system design overcomes key domain-specific challenges in modeling 5G networks, including the functional variability of VNFs, VNFs' stochastic behavior, and the scale introduced by network densification. To address these challenges, vChainNet tunes a lightweight model composed of over$\mathbf{9 5 \%}$fewer parameters than state-of-the-art models, fuses domain-specific manually-engineered features with automatic feature extraction, and optimizes a distribution-based loss function during model training. Our results show that vChainNet achieves an accuracy improvement up to 10.86 % compared to state-of-the-art traditional network models, while providing a speedup of up to 53.33 times over common packet-level simulators. Furthermore, vChainNet's reliance on tuning a lightweight model allows it to generalize to unseen VNF types without extra hyperparameter tuning efforts. These results demonstrate the accuracy, scalability, and generalization ability of vChainNet for modeling 5G and beyond networks. Hadj Ahmed Chikh Dahmane, Sherif Mostafa, Moustafa Youssef 0001, Raouf Boutaba |
WINCOM | 5 |
| 2025 | Posted Price Mechanisms for Online Allocation with Diseconomies of ScaleabstractThis paper addresses the online k-selection problem with diseconomies of scale (ØSDoS), where a seller seeks to maximize social welfare by optimally pricing items for sequentially arriving buyers, accounting for increasing marginal production costs. Previous studies have investigated deterministic dynamic pricing mechanisms for such settings. However, significant challenges remain, particularly in achieving optimality with small or finite inventories and developing effective randomized posted price mechanisms. To bridge this gap, we propose a novel randomized dynamic pricing mechanism for ØSDoS, providing a tighter lower bound on the competitive ratio compared to prior work. Our approach ensures optimal performance in small inventory settings (i.e., when k is small) and surpasses existing online mechanisms in large inventory settings (i.e., when k is large), leading to the best-known posted price mechanism for optimizing online selection and allocation with diseconomies of scale across varying inventory sizes. Hossein Nekouyan Jazi, Bo Sun 0004, Raouf Boutaba, Xiaoqi Tan |
WWW | 3 |
| 2025 | Toward a Privacy-Preserving and Secure Smart City: Recent Advances in User-Centric ApplicationsabstractThe ever-increasing global population has caused rapid urbanization in recent decades. Many cities around the world are trying to leverage information and communication technologies to resolve the resulting problems, such as traffic congestion and high energy consumption. This trend is part of the movement towards the development of the so-called smart cities that provide efficient, comfortable, and happy lives to their residents. In this respect, smart cities are indeed promising but have significant underlying complexity due to the number of variety of domains involved, including living, economy, mobility, governance, etc. However, in recent years, numerous cyber attacks and privacy leaks have been major obstacles to the widespread adoption and deployment of smart city applications. In general, smart city domains can be classified into user-centric applications and non-user-centric applications, such as critical infrastructures. This paper examines the key security and privacy challenges associated with recently trending user-centric smart city applications. First, we study the leading technologies along with superior security methods and privacy-enhancing technologies in smart cities. We also provide a critical survey of the security and privacy of novel user-centric smart city applications, namely smart parking, smart charging, and smart home. Our survey provides a detailed review of recent, relevant, and state-of-the-art research works to assist readers in gaining a comprehensive understanding of security and privacy challenges associated with smart cities. Finally, it outlines some research directions worth investigating in the future. The ultimate goal of this survey is to shed light on the pressing security and privacy challenges in smart cities and to provide insights for the development of secure and privacy-preserving smart cities. Mohammad Rasool Momeni, Abdollah Jabbari, Carol J. Fung, Raouf Boutaba |
IEEE Internet Things J. | 4 |
| 2025 | Anomaly Detection and Localization in NFV Systems by Utilizing Masked-Autoencoder and XAIabstractThe integration of Network Functions Virtualization (NFV) systems into mobile edge and core networks has heightened the need for effective anomaly detection and localization methods. The complexity of NFV demands robust mechanisms for network resilience, security, and performance. Machine Learning approaches have demonstrated promising solutions in crafting adaptive and efficient mechanisms for detecting and localizing potential anomalies within NFV systems. Particularly, Unsupervised Learning (UL) methods have garnered significant attention for their potential to detect anomalies without the need for labeled data. However, UL methods are susceptible to even minor levels of anomalous samples in the training data, termed contamination, which can severely compromise their performance. This paper proposes a novel approach using the Noisy-Student technique for anomaly detection. It addresses data contamination by combining a density-estimation teacher model for pseudo-labeling with a weakly-supervised student model based on a Masked Autoencoder trained on the pseudo-labeled data. For anomaly localization, we introduce a heuristic tailored for our anomaly detection model and two Explainable Artificial Intelligence (XAI)-based approaches applicable to any detection model. Extensive experiments on three NFV datasets demonstrate superior performance, with up to a 20% improvement in anomaly detection and up to a 22% improvement in localization, in terms of F1-score. Seyed Soheil Johari, Nashid Shahriar, Massimo Tornatore, Raouf Boutaba, Aladdin Saleh |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | A Two-Stage Reconfiguration in Network Function Virtualization: Toward Service Function Chain OptimizationabstractNetwork Function Virtualization (NFV), as a promising paradigm, speeds up the service deployment by separating network functions from proprietary devices and deploying them on common servers in the form of software. Any service in NFV-enabled networks is achieved as a Service Function Chain (SFC) which consists of a series of ordered Virtual Network Functions (VNFs). However, migration of VNFs for more flexible services within a dynamic NFV-enabled network is a key challenge to be addressed. Current VNF migration studies mainly focus on single VNF migration decisions without considering the sharing and concurrent migration of VNF instances. In this paper, we assume that each deployed VNF is used by multiple SFCs and deal with the optimal placement for the contemporaneous migration of VNFs based on the actual network situation. We formalize the VNF migration and SFC reconfiguration problem as a mathematical model, which aims to minimize the VNF migration between nodes or the total number of core changes per node. The approach is a two-stage MILP based on optimal order to solve the reconfiguration. Extensive evaluation shows that the proposed approach can reduce the change in terms of location or number of cores per node in a 6-node and 14-node networks while ensuring network latency compared with the model without reconfiguration. Karcius D. R. Assis, Raul C. Almeida, Hojjat Baghban, Alex Ferreira dos Santos, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | Monarch: Monitoring Architecture for 5G and Beyond Network SlicesabstractData-driven algorithms play a pivotal role in the automated orchestration and management of network slices in 5G and beyond networks, however, their efficacy hinges on the timely and accurate monitoring of the network and its components. To support 5G slicing, monitoring must be comprehensive and encompass network slices end-to-end (E2E). Yet, several challenges arise with E2E network slice monitoring. Firstly, existing solutions are piecemeal and cannot correlate network-wide data from multiple sources (e.g., different network segments). Secondly, different slices can have different requirements regarding Key Performance Indicators (KPIs) and monitoring granularity, which necessitates dynamic adjustments in both KPI monitoring and data collection rates in real-time to minimize network resource overhead. To address these challenges, in this paper, we present Monarch, a scalable monitoring architecture for 5G. Monarch is designed for cloud-native 5G deployments and focuses on network slice monitoring and per-slice KPI computation. We validate the proposed architecture by implementing Monarch on a 5G network slice testbed, with up to 50 network slices. We exemplify Monarch’s role in 5G network monitoring by showcasing two scenarios: monitoring KPIs at both slice and network function levels. Our evaluations demonstrate Monarch’s scalability, with the architecture adeptly handling varying numbers of slices while maintaining consistent ingestion times between 2.25 to 2.75 ms. Furthermore, we showcase the effectiveness of Monarch’s adaptive monitoring mechanism, exemplified by a simple heuristic, on a real-world 5G dataset. The adaptive monitoring mechanism significantly reduces the overhead of network slice monitoring by up to 76% while ensuring acceptable accuracy. Niloy Saha, Nashid Shahriar, Noura Limam, Raouf Boutaba, Aladdin Saleh |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | MicroOpt: Model-Driven Slice Resource Optimization in 5G and Beyond NetworksabstractA pivotal attribute of 5G networks is their capability to cater to diverse application requirements. This is achieved by creating logically isolated virtual networks, or slices, with distinct service level agreements (SLAs) tailored to specific use cases. However, efficiently allocating resources to maintain slice SLA is challenging due to varying traffic and quality-of-service (QoS) requirements. Traditional peak traffic-based resource allocation leads to over-provisioning, as actual traffic rarely peaks. Additionally, the complex relationship between resource allocation and QoS in end-to-end slices spanning different network segments makes conventional optimization techniques impractical. Existing approaches in this domain use mathematical network models (e.g., queueing models) or simulations, and various optimization methods but struggle with optimality, tractability, and generalizability across different slice types. In this paper, we propose MicroOpt, a novel framework that leverages a differentiable neural network-based slice model with gradient descent for resource optimization and Lagrangian decomposition for QoS constraint satisfaction. We evaluate MicroOpt against two state-of-the-art approaches using an open-source 5G testbed with real-world traffic traces. Our results demonstrate up to 21.9% improvement in resource allocation compared to these approaches across various scenarios, including different QoS thresholds and dynamic slice traffic. Mahdieh Ahmadi, Bo Sun 0004, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Aladdin Saleh |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2024 | CATS: Contrastive learning for Anomaly detection in Time SeriesabstractAnomaly detection (AD) plays a critical role in a wide variety of big data applications, including cybersecurity, monitoring, and network systems. It consists in finding patterns in time series data that indicate unexpected events such as faults or defects. Traditional AD approaches, predominantly based on reconstruction techniques, often yield suboptimal performance, particularly when anomalies are present in the training set. Conversely, contrastive learning (CL) has shown significant performance in image processing tasks and is increasingly applied in time series data classification and forecasting. However, traditional CL frameworks are not well-adapted for time series AD due to two key challenges. First, AD is typically performed only on normal instances, and thus CL does not benefit from knowledge about anomalous instances. Second, the temporal nature of time series data is often neglected when computing time series similarity, thereby hindering the effective learning of time series representation.To overcome these limitations, we propose CATS, a novel approach that leverages a temporal similarity measure to learn time series representations. Moreover, through negative data augmentation, CATS generates a more realistic distribution of anomalies, which enables anomaly-informed CL. Extensive experiments conducted on six real-world datasets demonstrate that CATS outperforms existing AD methods. Our results highlight the efficacy of CATS in enhancing time series AD performance in big data environment across various application domains. Joël Roman Ky, Bertrand Mathieu, Abdelkader Lahmadi, Raouf Boutaba |
IEEE Big Data | 4 |
| 2024 | 5GProvGen: 5G Provenance Dataset Generation FrameworkabstractThe softwarization and virtualization of the fifth-generation (5G) cellular networks bring about increased flexibility and faster deployment of new services. However, these advancements also introduce new vulnerabilities and unprecedented attack surfaces. The cloud-native nature of 5G networks mandates detecting and protecting against threats and intrusions in the cloud systems. Additionally, the evolving cyber-threat landscape and the growing reliance on cellular networks for mission-critical tasks reinforce the need for robust security systems, which should be capable of detecting stealthy and zero-day attacksRecent developments in Provenance-based Intrusion Detection Systems (PIDS) address these requirements. These host-based systems aim to analyze provenance graphs derived from system calls to uncover any deviation from the expected benign behaviour of the host. Provenance graphs are structured as holistic representations of the dependencies and causal relationships between digital objects, and hence they fit well in the Service-based Architecture (SBA) of 5G networks. However, deploying PIDS requires substantial datasets of provenance graphs collected from the relevant hosts. In this work, we propose a framework to generate provenance graphs datasets for a 5G core network. We provide an example dataset and evaluate the state-of-the-art PIDS in protecting a 5G network core from various threats. Amr Abouelkhair, Kiarash Majdi, Noura Limam, Mohammad A. Salahuddin 0002, Raouf Boutaba |
CNSM | 5 |
| 2024 | Signalling Load-aware Conditional Handover in 5G Non-Terrestrial NetworksabstractLow Earth orbit (LEO) satellites-based non-terrestrial networks (NTN) are envisioned to complement the fifth-generation (5G) terrestrial networks (TN), enabling global cellular services. However, the high mobility and large coverage of these satellites result in frequent and numerous inter-satellite handovers, leading to signalling storms that degrade the satellite gNodeB services. To address this, we mathematically formulate the handover problem and propose a novel signalling load-aware handover protocol based on conditional handover. We evaluate the effectiveness of the protocol using a customized discrete-event simulator and compare it against a set of baseline conditional handover schemes. Our findings show that the proposed protocol significantly reduces signalling peaks and balances the load more effectively, enhancing the robustness and efficiency of handover in 5G NTN. The simulator is made publicly available. Mohammad Ali Salahuddin 0001, Yunli Wang, Noura Limam, Bo Sun 0004, Diogo Barradas, Raouf Boutaba |
CNSM | 8 |
| 2024 | Secure and Efficient Group Handover Protocol in 5G Non-Terrestrial NetworksabstractThe growing low-Earth orbit (LEO) satellite con-stellations have become an essential part of the fifth-generation (5G) non-terrestrial network (NTN) market. These satellites can enable direct-to-cell connectivity for mobile devices and support various applications with ubiquitous coverage for 5G and beyond networks. However, satellite-based NTNs bring several challenges to the 5G handover protocol design. The high mobility of satellites can lead to signaling storms and security compromises during handovers. This paper addresses these challenges by proposing a secure and efficient group hand over protocol. The protocol's effectiveness is evaluated on a custom discrete-event simulator and compared against the baseline 5G hand over scheme. The simulator is made publicly available. A. Akbariazirani, Mohammad Ali Salahuddin 0001, Diogo Barradas, Noura Limam, Raouf Boutaba |
ICC | 7 |
| 2024 | Online Algorithms with Uncertainty-Quantified PredictionsabstractThe burgeoning field of algorithms with predictions studies the problem of using possibly imperfect machine learning predictions to improve online algorithm performance. While nearly all existing algorithms in this framework make no assumptions on prediction quality, a number of methods providing uncertainty quantification (UQ) on machine learning models have been developed in recent years, which could enable additional information about prediction quality at decision time. In this work, we investigate the problem of optimally utilizing uncertainty-quantified predictions in the design of online algorithms. In particular, we study two classic online problems, ski rental and online search, where the decision-maker is provided predictions augmented with UQ describing the likelihood of the ground truth falling within a particular range of values. We demonstrate that non-trivial modifications to algorithm design are needed to fully leverage the UQ predictions. Moreover, we consider how to utilize more general forms of UQ, proposing an online learning framework that learns to exploit UQ to make decisions in multi-instance settings. Bo Sun 0004, Jerry Huang, Nicolas Christianson, Mohammad Hajiesmaili, Adam Wierman, Raouf Boutaba |
ICML | 6 |
| 2024 | Evaluating Open-Source 5G SA Testbeds: Unveiling Performance Disparities in RAN ScenariosabstractFifth generation (5G) standalone (SA) mobile networks are rapidly gaining prominence worldwide, and becoming increasingly prevalent as the telecommunication industry standard. Most published work concerning 5G applications relies on open-source 5G radio access network (RAN) simulation and emulation tools to evaluate various concepts, algorithms, and use cases. However, these tools are not always accurate in conveying a realistic representation of real-world RAN performance and expected quality of service (QoS). This paper discusses the deployment of a 5G SA testbed supporting three different RAN scenarios of real and simulated deployments using open- source software, commercial-off-the-shelf (COTS) hardware, and software defined radios (SDRs). We experimentally evaluate the performance of these scenarios for the RAN and quantify their differences in terms of computational resource utilization, throughput, latency, coverage, and power consumption. Specifically, we explore the emulation and simulation tools’ ability to reflect realistic RAN performance and highlight the differences compared to the SDR-based deployment. Through this analysis, this paper provides insights into the performance of each approach and sheds light on the feasibility of using open- source software for 5G testing and experimentation. Mohamed Rouili, Niloy Saha, Morteza Golkarifard, Mohammad Zangooei, Raouf Boutaba, Ertan Onur, Aladdin Saleh |
NOMS | 5 |
| 2024 | Multi-objective optimization of asymmetric bit rate partitioning for multipath protection in elastic optical networks
Henrique A. Dinarte, Karcius D. R. Assis, Daniel A. R. Chaves, Raul C. Almeida, Raouf Boutaba |
Comput. Networks | 5 |
| 2024 | Flexible RAN Slicing in Open RAN With Constrained Multi-Agent Reinforcement LearningabstractNetwork slicing enables the provision of customized services in next-generation mobile networks. Accordingly, the network is divided into logically isolated networks that share underlying resources but are tailored to meet the distinct service requirements of their users. However, allocating the minimum necessary resources to satisfy slices’ requirements is challenging, particularly when the number of slices is variable or too large which is envisioned in Open RAN. State-of-the-art proposals leverage reinforcement learning (RL) algorithms; however, they suffer from over-provisioning and/or frequent violations of service-level agreement (SLA) due to the large and changing state and action spaces. This paper introduces a novel cooperative multi-agent RL algorithm for RAN slicing in Open RAN, designed to adapt to variable slice numbers and effectively scale as they grow. To train this model, we exploit a novel constrained RL algorithm that explicitly considers SLA constraints to maintain a decreasing SLA violation ratio during training. Our approach is compatible with the Open RAN architecture, allowing for feasible deployment in future mobile networks. CMARS surpasses RL methods in SLA satisfaction by 50% in large-scale slicing, using only 9% more resources. It has 8% fewer SLA violations and 19% lower resource consumption for a flexible number of slices. Mohammad Zangooei, Morteza Golkarifard, Mohamed Rouili, Niloy Saha, Raouf Boutaba |
IEEE J. Sel. Areas Commun. | 5 |
| 2024 | A Robust Cooperative Jamming Scheme for Secure UAV Communication via Intelligent Reflecting SurfaceabstractIn this paper, we propose a robust secure communication scheme for a two-Unmanned Aerial Vehicle (UAV) scenario with the assistance of Intelligent Reflecting Surface (IRS), in which one legitimate user and one eavesdropper are considered. In the proposed scheme, the information is transmitted from one UAV named information UAV to the user via the assistance of the IRS, while the jamming information is transmitted by the other UAV named jamming UAV equipped with multi-antenna to interfere with the eavesdropper and safeguard the communication between information UAV and legitimate receiver. For the considered communication system, we assume that the Channel State Information (CSI) of the eavesdropping channels are imperfect. In this imperfect CSI case, we formulate a robust non-convex optimization problem. By jointly optimizing UAV transmit power, trajectory, and IRS phase shifters, the suboptimal average secrecy rate of the proposed scheme can be obtained. Specifically, Lagrangian dual transform and quaduratic transform are introduced to convert the objective function into more tractable form; S-Procedure is used for handling CSI uncertainty; and a two-stage penalty function algorithm is applied to obtain rank-one phase shifters solution. Numerical simulation results validate some interesting insights: (1) The IRS can bring strong robustness to the two-UAV security communication system; (2) Deploying jamming UAV in the IRS-UAV security communication system can greatly improve security performance, especially employing more antennas at the jamming UAV. Runlong Ye 0001, Yuyang Peng, Fawaz AL-Hazemi, Raouf Boutaba |
IEEE Trans. Commun. | 4 |
| 2024 | Generalizable 5G RAN/MEC Slicing and Admission Control for Reliable Network OperationabstractThe virtualization and distribution of 5G Radio Access Network (RAN) functions across radio unit (RU), distributed unit (DU), and centralized unit (CU) in conjunction with multi-access edge computing (MEC) enable the creation of network slices tailored for various applications with distinct quality of service (QoS) demands. Nonetheless, given the dynamic nature of slice requests and limited network resources, optimizing long-term revenue for infrastructure providers (InPs) through real-time admission and embedding of slice requests poses a significant challenge. Prior works have employed Deep Reinforcement Learning (DRL) to address this issue, but these approaches require re-training with the slightest topology changes due to node/link failure or overlook the joint consideration of slice admission and embedding problems. This paper proposes a novel method, utilizing multi-agent DRL and Graph Attention Networks (GATs), to overcome these limitations. Specifically, we develop topology-independent admission and slicing agents that are scalable and generalizable across diverse metropolitan networks. Results demonstrate substantial revenue gains-up to 35.2% compared to heuristics and 19.5% when compared to other DRL-based methods. Moreover, our approach showcases robust performance in different network failure scenarios and substrate networks not seen during training without the need for re-training or re-tuning. Additionally, we bring interpretability by analyzing attention maps, which enables InPs to identify network bottlenecks, increase capacity at critical nodes, and gain a clear understanding of the model decision-making process. Mahdieh Ahmadi, Arash Moayyedi, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Aladdin Saleh |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2024 | AutoML4ETC: Automated Neural Architecture Search for Real-World Encrypted Traffic ClassificationabstractDeep learning (DL) has been successfully applied to encrypted network traffic classification in experimental settings. However, in production use, it has been shown that a DL classifier’s performance inevitably decays over time. Re-training the model on newer datasets has been shown to only partially improve its performance. Manually re-tuning the model architecture to meet the performance expectations on newer datasets is time-consuming and requires domain expertise. We propose AutoML4ETC, a novel tool to automatically design efficient and high-performing neural architectures for encrypted traffic classification. We define a novel, powerful search space tailored specifically for the early classification of encrypted traffic using packet header bytes. We show that with different search strategies over our search space, AutoML4ETC generates neural architectures that outperform the state-of-the-art encrypted traffic classifiers on several datasets, including public benchmark datasets and real-world TLS and QUIC traffic collected from the Orange mobile network. In addition to being more accurate, AutoML4ETC’s architectures are significantly more efficient and lighter in terms of the number of parameters. Finally, we make AutoML4ETC publicly available for future research. Navid Malekghaini, Elham Akbari, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba, Bertrand Mathieu, Stephanie Moteau, Stéphane Tuffin |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2023 | A Critical Study of Few-Shot Learning for Encrypted Traffic ClassificationabstractOver the past twenty years, a plethora of methods have been proposed for encrypted traffic classification (ETC), while the Server name indication (SNI) is deemed to solve the problem of classification for TLS traffic. However, SNI-based classification has its pitfalls and the SNI will likely be pushed into the encrypted tunnel in the future. In this work, we envision a futuristic scenario in which encrypted SNI is the norm and labeled traffic flows are scarce. In such settings, we tackle the problem of traffic classification at ISP level using few-shot learning. By means of six real-world ISP-level datasets collected between 2019 and 2021 and two publicly available client-side datasets, we study the performance of a few-shot learner on TLS data, including its cross-dataset generalizability. We further investigate the effect of the number of required labeled samples on the learner's performance. Our experiments show that the dataset-specificity of deep learners carries over to few-shot meta-learning, and calls for addressing the problem of generalizability for deep learning architectures. Elham Akbari, Sheikh A. Tahmid, Navid Malekghaini, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba, Bertrand Mathieu, Stephanie Moteau, Stéphane Tuffin |
CNSM | 6 |
| 2023 | Optimal Functional Splitting, Placement and Routing for Isolation-Aware Network Slicing in NG-RANabstractIn the rapidly evolving landscape of 5G and its successor technologies, the Next Generation Radio Access Network (NG-RAN) stands out as a transformative pillar. Functional splitting, a core concept in NG-RAN, splits the traditional base station into distinct functional entities, notably the Distributed Unit (DU), Centralized Unit (CU) and Radio Unit (RU). With flexible functional splitting, Infrastructure Providers (InPs) can dynamically allocate RAN resources to cater to each network slice's distinct throughput and latency demand. However, the problem of optimally selecting functional splits, placement of RAN functions in DU/CU with constrained computational capacities and determining routing paths present an NP-hard challenge. The coexistence of multiple slices on shared infrastructure may necessitate slice isolation for security, performance, and operational reasons, adding another layer of complexity. To address this multifaceted problem, we formulate an Integer Linear Programming (ILP) model that seeks to maximize the InP profit considering computation, virtual machine instantiation and routing costs. Using Gurobi optimizer, we show that optimal slice admission solutions directly impact InP profit and that enhanced computational capacities can increase the number of slices admitted. Maria Mushtaq, Morteza Golkarifard, Nashid Shahriar, Raouf Boutaba, Aladdin Saleh |
CNSM | 4 |
| 2023 | A Token-Prioritization Strategy for Handling Data Imbalance in Network-Change Ticket ClassificationabstractChanges are an integral part of the day-to-day operation of large telecommunications networks as they allow to keep pace with technological advancements, meet growing network demands, ensure scalability, enhance security, improve service quality, and meet customer expectations. Changing configurations, installing devices, and migrating traffic are some examples of these changes. These changes are documented by opening tickets through a ticket management system. Automation in the ticket management system is now becoming highly desirable to manage the large number of submitted tickets. An automated ticket management system supports the management of a ticket by automating several parts of a ticket's lifecycle. In this context, ticket classification problem consists in assigning an appropriate label to a ticket to be utilized in the later stages of the ticket management cycle. In this paper, we use a collection of network-change tickets from a real network operator to solve a ticket classification problem. We observe that the network-change ticket dataset is highly skewed in the number of tickets for different possible classes. We address this challenge of classification in a highly imbalanced dataset by proposing two token-prioritization strategies along with other components. We compare three variations of our proposed approach with three methods from the literature and show that the variations of the proposed approach outperform existing methods by up to 7% in terms of F1 score. Md. Shamim Towhid, Nasik Sami Khan, Nashid Shahriar, Massimo Tornatore, Raouf Boutaba, Aladdin Saleh |
CNSM | 5 |
| 2023 | Adaptive Entanglement Routing for Quantum Networks with CutoffabstractQuantum networks, with applications like Quantum Key Distribution (QKD), are gaining significant attention. However, their implementation faces challenges due to low entanglement generation success rates and quantum decoherence. Recent quantum technology advancements have extended entanglement memory lifetimes to one minute, termed cutoff, opening new opportunities for entanglement routing. We propose the Adaptive Entanglement Routing (AER) algorithm, which optimizes resource utilization to improve the success probability of serving entanglement and ultimately reduce the time needed for entanglement establishment. AER includes two phases: 1) determine redundant paths based on load and 2) utilize shared entanglements for entanglement swapping. Moreover, we design the highest-success-path (HSP) algorithm to maximize the success probability of entanglement routing with limited quantum memory. These innovative routing algorithms significantly reduce entanglement request failures, resulting in up to 70% reduction in average waiting times. Jiaheng Xiong, Qiaolun Zhang, Alberto Gatto 0001, Francesco Musumeci 0001, Raouf Boutaba, Massimo Tornatore |
CNSM | 5 |
| 2023 | Mitigating Signaling Storms in 5G with Blockchain-assisted 5GAKAabstractThis paper examines the registration signaling storm attack in 5G networks. This attack is initiated by massive registration requests and targets the 5G core network functions, leading to large-scale user service disruption. To mitigate this problem, we review the 5G Authentication and Key Agreement (5GAKA) protocol and highlight the impact of the exposure of the 5G core network (CN) to massive registration requests. We propose a blockchain-based authentication protocol to effectively block adversarial registration requests and secure the 5G network at a small cost. Our experiments reveal that our protocol is resistant to attacks and prove its superiority compared to a baseline mitigation approach. Paul Zeinaty, Noura Limam, Raouf Boutaba |
CNSM | 4 |
| 2023 | Soft Voting for Anomaly Detection in Internet of Medical ThingsabstractIn this paper, we propose an approach for anomaly detection in Internet of Medical Things based on the soft voting between the most accurate machine learning algorithms. We compare 12 machine learning and 5 deep learning algorithms for anomaly detection to identify the top 3. We apply these algorithms over public annotated dataset with network and physiological parameters. The soft voting predicts the anomaly based on the predicted probability by each individual model from the selected 3. We also compare the performance of the 17 algorithms before and after dimensionality reduction using two different techniques, and we found that soft voting using CatBoost, XGBoost and LightGBM outperforms hard voting and other algorithms, achieving a detection accuracy of 97.45 % and a false alarm rate of 2%. Osman Salem, Ahmed Mehaoua, Raouf Boutaba |
GLOBECOM | 3 |
| 2023 | The Sight for Hearing: An IoT-Based System to Assist Drivers with Hearing DisabilityabstractThe objective of this paper is to propose a new system to assist drivers with hearing disability, deaf or unfocused persons by recognizing and transforming audible signals, such as emergency vehicle sirens or honks into alerts displayed in the dashboard. Such conversion from audio to alert messages attracts the attention of unfocused drivers to hear the honking of other cars, and enhances the safety and the quality of life for deaf or hard-of-hearing drivers. We develop an IoT based system to identify, denoise and translate any significant voice signal around the driver's car into alert messages. The signal acquired by sensors is processed to identify the source and display the associated message through the use of several machine learning models with majority voting. Our experiments results show that the proposed solution is able to achieve a 95% accuracy when trained and validated against a real dataset of 600 files. Osman Salem, Ahmed Mehaoua, Raouf Boutaba |
ISCC | 3 |
| 2023 | Meta-ATMoS+: A Meta-Reinforcement Learning Framework for Threat Mitigation in Software-Defined NetworksabstractAs cyber threats become increasingly common, automated threat mitigation solutions are more necessary than ever. Conventional threat mitigation frameworks are difficult to tune for different network environments, but frameworks utilizing deep reinforcement learning (RL) have been proven to be an effective approach that can adapt to different networks automatically. Existing RL-based frameworks have shown to be generalizable to different network sizes and threats, and robust to false positives. However, training RL agents for these frameworks can be challenging in a production environment as the training process is time-consuming and disruptive to the production network. Hence, a staging environment is required to effectively train them. In this paper, we propose Meta-ATMoS+, a meta-RL framework for threat mitigation in software-defined networks. We leverage Model-Agnostic Meta-Learning (MAML) to find an initialization for the RL agent that generalizes to a variety of different network configurations. We show that the RL agent with MAML-learned initialization can accomplish few-shot learning on a target network with comparable performance to training on a staging environment. Few-shot learning not only allows the model to be trainable directly in the production environment but also enables human-in-the-loop RL for the mitigation of threats that do not have an easily-definable reward function. Hauton Tsang, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
LCN | 4 |
| 2023 | Generalizable GNN-based 5G RAN/MEC Slicing and Admission Control in Metropolitan NetworksabstractThe 5G RAN functions can be virtualized and distributed across the radio unit (RU), distributed unit (DU), and centralized unit (CU) to facilitate flexible resource management. Complemented by multi-access edge computing (MEC), these components create network slices tailored for applications with diverse quality of service (QoS) requirements. However, as the requests for various slices arrive dynamically over time and the network resources are limited, it is non-trivial for an infrastructure provider (InP) to optimize its long-term revenue from real-time admission and embedding of slice requests. Prior works have leveraged Deep Reinforcement Learning (DRL) to address this problem, however, these solutions either require re-training when facing topology changes or do not consider the slice admission and embedding problems jointly. In this paper, we use multi-agent DRL and Graph Attention Networks (GATs) to address these limitations. Specifically, we propose novel topology-independent admission and slicing agents that are scalable and generalizable to large and different metropolitan networks. Results show that the proposed approach converges faster and achieves up to 35.2% and 20% gain in revenue compared to heuristics and other DRL-based approaches, respectively. Additionally, we demonstrate that our approach is generalizable to scenarios and substrate networks previously unseen during training, as it maintains superior performance without re-training or re-tuning. Arash Moayyedi, Mahdieh Ahmadi, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Aladdin Saleh |
NOMS | 4 |
| 2023 | MonArch: Network Slice Monitoring Architecture for Cloud Native 5G DeploymentsabstractAutomated decision making algorithms are expected to play a key role in management and orchestration of network slices in 5G and beyond networks. State-of-the-art algorithms for automated orchestration and management tend to rely on data-driven methods which require a timely and accurate view of the network. Accurately monitoring an end-to-end (E2E) network slice requires a scalable monitoring architecture that facilitates collection and correlation of data from various network segments comprising the slice. The state-of-the-art on 5G monitoring mostly focuses on scalability, falling short in providing explicit support for network slicing and computing network slice key performance indicators (KPIs). To fill this gap, in this paper, we present MonArch, a scalable monitoring architecture for 5G, which focuses on network slice monitoring, slice KPI computation, and an application programming interface (API) for specifying slice monitoring requests. We validate the proposed architecture by implementing MonArch on a 5G testbed, and demonstrate its capability to compute a network slice KPI (e.g., slice throughput). Our evaluations show that MonArch does not significantly increase data ingestion time when scaling the number of slices and that a 5-second monitoring interval offers a good balance between monitoring overhead and accuracy. Niloy Saha, Nashid Shahriar, Raouf Boutaba, Aladdin Saleh |
NOMS | 3 |
| 2023 | Generalizable Resource Scaling of 5G Slices using Constrained Reinforcement LearningabstractNetwork slicing is a key enabler for 5G to support various applications. Slices requested by service providers (SPs) have heterogeneous quality of service (QoS) requirements, such as latency, throughput, and jitter. It is imperative that the 5G infrastructure provider (InP) allocates the right amount of resources depending on the slice’s traffic, such that the specified QoS levels are maintained during the slice’s lifetime while maximizing resource efficiency. However, there is a non-trivial relationship between the QoS and resource allocation. In this paper, this relationship is learned using a regression-based model. We also leverage a risk-constrained reinforcement learning agent that is trained offline using this model and domain randomization for dynamically scaling slice resources while maintaining the desired QoS level. Our novel approach reduces the effects of network modeling errors since it is model-free and does not require QoS metrics to be mathematically formulated in terms of traffic. In addition, it provides robustness against uncertain network conditions, generalizes to different real-world traffic patterns, and caters to various QoS metrics. The results show that the state-of-the-art approaches can lead to QoS degradation as high as 44.5% when tested on previously unseen traffic. On the other hand, our approach maintains the QoS degradation below a preset 10% threshold on such traffic, while minimizing the allocated resources. Additionally, we demonstrate that the proposed approach is robust against varying network conditions and inaccurate traffic predictions. Mahdieh Ahmadi, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Aladdin Saleh |
NOMS | 4 |
| 2023 | FogJam: A Fog Service for Detecting Traffic Congestion in a Continuous Data Stream VANET
Maycon Leone Maciel Peixoto, Edson Mota, Adriano H. O. Maia, Wellington Lobato, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Leandro A. Villas |
Ad Hoc Networks | 6 |
| 2023 | Deep learning for encrypted traffic classification in the face of data drift: An empirical study
Navid Malekghaini, Elham Akbari, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba, Bertrand Mathieu, Stephanie Moteau, Stéphane Tuffin |
Comput. Networks | 5 |
| 2023 | Spotting Anomalies at the Edge: Outlier Exposure-Based Cross-Silo Federated Learning for DDoS DetectionabstractDistributed Denial-of-Service (DDoS) attacks are expected to continue plaguing service availability in emerging networks which rely on distributed edge clouds to offer critical, latency-sensitive applications. However, edge servers increase the network attack surface, which is exacerbated with the massive number of connected Internet of Things (IoT) devices that can be weaponized to launch DDoS attacks. Therefore, it is crucial to detect DDoS attacks early, i.e., at the network edge. In this paper, we empower the network edge with intelligent DDoS detection by learning from similarities between different data and DDoS attacks available across the edge servers. To this end, we develop a novel Outlier Exposure (OE)-enabled cross-silo Federated Learning framework, namely FedOE. FedOE enables distributed training of OE-based ML models using a limited number of labeled outliers (i.e., attack flows) experienced at edge servers. We propose a novel OE-based Autoencoder (oAE) that can better discriminate anomalies in comparison to the widely adopted traditional Autoencoder, using a tailored, OE-based loss function. We evaluate oAE in FedOE and demonstrate its ability to generalize to zero-day attacks, with just 50 labeled attack flows per edge server. The results show that oAE achieves a high F1-score for most DDoS attacks, outclassing its non-OE counterpart. Vahid Pourahmadi, Hyame Assem Alameddine, Mohammad Ali Salahuddin 0001, Raouf Boutaba |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | DRL-Assisted Reoptimization of Network Slice Embedding on EON-Enabled Transport Networksabstract5G transport networks will support dynamic services with diverse requirements through network slicing. Elastic Optical Networks (EONs) facilitate transport network slicing by flexible spectrum allocation and tuning of transmission configurations. A major challenge in supporting dynamic services is the lack of priori knowledge of future slice requests. As a consequence, slice embedding can become sub-optimal over time, leading to spectrum fragmentation and skewed utilization. This in turn can block future slice requests, impacting operator revenue. To address this issue, operators can periodically re-optimize slice embedding for reducing fragmentation. In this paper, we address this problem of re-optimizing network slice embedding on EONs for minimizing fragmentation. The problem is solved in its splittable version, which significantly increases problem complexity, but also offers more opportunities for a larger set of re-configuration actions. We employ simulated annealing for systematically exploring the large solution space. We also propose a greedy algorithm to address the practical constraint of limiting the number of re-configuration steps. Moreover, we present a novel method based on Deep Reinforcement Learning (DRL) for determining when performing re-configuration is most effective. Our extensive simulations demonstrate that the greedy algorithm yields a solution very close to that obtained using simulated annealing while requiring orders of magnitude lesser re-configuration actions. Finally, we show that by applying the greedy algorithm periodically on the network according to the DRL-based time selection algorithm, a significant improvement in the total number of accepted slice requests can be achieved with only performing a limited number of re-configuration operations. Seyed Soheil Johari, Sepehr Taeb, Nashid Shahriar, Shihabur Rahman Chowdhury, Massimo Tornatore, Raouf Boutaba, Jeebak Mitra, Mahdi Hemmati |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2023 | ML Models for Detecting QoE Degradation in Low-Latency Applications: A Cloud-Gaming Case StudyabstractDetecting abnormal network events is an important activity of Internet Service Providers particularly when running critical applications (e.g., ultra low-latency applications in mobile wireless networks). Abnormal events can stress the infrastructure and lead to severe degradation of user experience. Machine Learning (ML) models have demonstrated their relevance in many tasks including Anomaly Detection (AD). While promising remarkable performance compared to manual or threshold-based detection, applying ML-based AD methods is challenging for operators due to the proliferation of ML models and the lack of well-established methodology and metrics to evaluate them and select the most appropriate one. This paper presents a comprehensive evaluation of eight unsupervised ML models selected from different classes of ML algorithms and applied to AD in the context of cloud gaming applications. We collect cloud gaming Key Performance Indicators (KPIs) time-series datasets in real-world network conditions, and we evaluate and compare the selected ML models using the same methodology, and assess their robustness to data contamination, their efficiency and computational complexity. In addition to the traditional F1-score performance metric used in anomaly detection, we use Matthews Coefficient Correlation (MCC) to better differentiate between models’ efficiencies. Our proposed methodology relies on window-based anomaly detection techniques as they are more useful for network operators compared to single point detection approaches. However, we found most existing window-based approaches to lack in accuracy and may under or over-estimate a model’s performance. Therefore, in this paper, we propose a novel Window Anomaly Decision (WAD) approach that overcomes these drawbacks. We leverage our experimental results to provide insights about the most relevant models for detecting QoE degradation and offer recommendations on their suitability for different application requirements. Joël Roman Ky, Bertrand Mathieu, Abdelkader Lahmadi, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | Coordinated Slicing and Admission Control Using Multi-Agent Deep Reinforcement Learningabstract5G Cloud Radio Access Networks (C-RANs) facilitate new forms of flexible resource management as dynamic RAN function splitting and placement. Virtualized RAN functions can be placed at different sites in the substrate network based on resource availability and slice constraints. Due to limited resources in the substrate network and variability in revenue of slices, the Infrastructure Provider (InP) must perform network slicing in a strategic manner, and accept or reject slice-requests to maximize long-term revenue. In this paper, we propose to use multi-agent Deep Reinforcement Learning (DRL) to jointly solve the problems of network slicing and slice Admission Control (AC). Multi-agent DRL along with reward shaping is a promising choice, which is well-suited to problems where multiple distinct tasks have to be performed optimally. The proposed DRL approach can learn the dynamics of slice-request traffic and effectively address these joint problems. We compare multi-agent DRL to approaches that use: (i) simple heuristics to address the problems, and (ii) DRL to address either slicing or AC. Our results show that the proposed approach achieves up to 30% and 5.18% gain in long-term InP revenue when compared to approaches (i) and (ii), respectively. Additionally, we show that multi-agent DRL is preferable to a single-agent DRL approach for the joint problems in terms of convergence time and InP revenue. Finally, we evaluate the robustness of the trained agents in scenarios that differ from training, such as different arrival rates and real dynamic traffic patterns. Arash Moayyedi, Mahdieh Ahmadi, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Aladdin Saleh |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2022 | Astrape: Anonymous Payment Channels with Boring Cryptography
Yuhao Dong, Ian Goldberg 0001, Sergey Gorbunov 0001, Raouf Boutaba |
ACNS | 4 |
| 2022 | Assessing Unsupervised Machine Learning solutions for Anomaly Detection in Cloud Gaming SessionsabstractCloud gaming applications have gained great adoption on the Internet particularly benefiting from the wide availability of broadband access networks. However, they still fail to meet users’ quality requirements when accessed using cellular networks due to common wireless channel degradations. Machine Learning (ML) techniques can be leveraged to detect such anomalies during users’ cloud gaming sessions. In this respect, unsupervised ML approaches are particularly interesting since they do not require labeled datasets. In this work, we investigate these approaches to understand their performance and their robustness. Our dataset consists of game sessions played on the public Google Stadia Cloud Gaming servers. The game sessions are played using a 4G network emulation replicating the capacity variations sampled on a commercial 4G network. We compare different models ranging from traditional approaches to deep learning and we evaluate their default performance while varying the level of contamination in their training datasets. Our experiments show that Auto-Encoders models achieve the best performance without contamination while the OC-SVM and the Isolation Forest are the most robust to data contamination. Joël Roman Ky, Bertrand Mathieu, Abdelkader Lahmadi, Raouf Boutaba |
CNSM | 4 |
| 2022 | Resource Management in Softwarized NetworksabstractCommunication networks are undergoing a major transformation through softwarization, which is changing the way networks are designed, operated, and managed. The enhanced programmability enabled by softwarization creates unique opportunities for adapting network function and resources in support of applications and users with diverse requirements. To effectively leverage the flexibility provided by network softwarization and realize its full potential, it is of paramount importance to devise proper mechanisms for allocating resources to different applications and users and for monitoring their usage over time. The overarching goal of this dissertation is to advance state-of-the-art in how resources are allocated and monitored and build the foundation for effective resource management in softwarized networks. Specifically, we address four resource management challenges in all three key enablers of network softwarization. First, we challenge the current practice of realizing network services with monolithic software network functions and propose a microservice-based disaggregated architecture enabling finer-grained resource allocation and scaling. Then, we devise optimal solutions and scalable heuristics for establishing virtual networks with guaranteed bandwidth and guaranteed survivability against failures in multi-layer IP-over-Optical and single-layer IP substrate networks, respectively. Finally, we propose adaptive sampling mechanisms for balancing the overhead of softwarized network monitoring and the accuracy of the network view constructed from monitoring data. Shihabur Rahman Chowdhury, Raouf Boutaba |
NOMS | 2 |
| 2022 | Anomaly Detection and Localization in NFV Systems: an Unsupervised Learning ApproachabstractDue to the scarcity of labeled faulty data, Unsupervised Learning (UL) methods have gained great traction for anomaly detection and localization in Network Functions Virtualization (NFV) systems. In a UL approach, training is performed on only normal data for learning normal data patterns, and deviation from the norm is considered as an anomaly. However, it has been shown that even small percentages of anomalous samples in the training data (referred to as contamination) can significantly degrade the performance of UL methods. To address this issue, we propose an anomaly-detection approach based on the Noisy-Student technique, which was originally introduced for leveraging unlabeled datasets in computer-vision classification problems. Our approach not only provides robustness against training-data contamination, but also can leverage this contamination to improve anomaly-detection accuracy. Moreover, after an anomaly is detected, localization of the anomalous virtualized network functions in an unsupervised manner is a challenging task in the absence of labeled data. For anomaly localization in NFV systems, we propose to exploit existing local AI-explainability methods to achieve a high localization performance and propose our own novel AI-explainability method, specifically designed for the anomaly-localization problem in NFV, to improve the performance further. We perform a comprehensive experimental analysis on two datasets collected on different NFV testbeds and show that our proposed solutions outperform the existing methods by up to 22% in anomaly detection and up to 19% in anomaly localization in terms of F1-score. Seyed Soheil Johari, Nashid Shahriar, Massimo Tornatore, Raouf Boutaba, Aladdin Saleh |
NOMS | 4 |
| 2022 | Detecting Multi-Step Attacks: A Modular Approach for Programmable Data PlaneabstractThe increasing sophistication of attacks over the last years such as the proliferation of complex multi-steps attacks, calls for new monitoring models and methods for diagnosing the attacks’ severity and mitigating them in a timely manner. In this paper, we propose an in-network monitoring approach capable of detecting a set of composed behaviors and consequently triggering different levels of alerts and reactions. Our approach is based on a Petri Net model capable of aggregating individual attacks into a multi-step composition. To this end, we propose a method for deriving a Match-Action Table (MAT) abstraction from a Petri net model. MATs can be then deployed on a P4 programmable data plane, enabling flexible re-composition of attack detection steps at runtime. We demonstrate the feasibility of our proposal by modeling the detection of a multi-step DNS cache poisoning attack and implementing the model on a P4 programmable data plane. Abir Laraba, Jérôme François, Isabelle Chrisment, Shihabur Rahman Chowdhury, Raouf Boutaba |
NOMS | 5 |
| 2022 | Demonstrating Network Slice KPI Monitoring in a 5G TestbedabstractNetwork slicing has been envisaged as a key enabler to satisfy diverse requirements of 5G networks, by creating multiple isolated end-to-end virtual networks dedicated to different services. An accurate view of these end-to-end 5G network slices is essential for both artificial intelligence (AI) driven slice orchestration, and data-driven automated service assurance. However, the existing open-source implementations of the 5G core do not natively support slice Key Performance Indicator (KPI) monitoring. In this demonstration, we show how to deploy a functional 5G testbed using a combination of open-source frameworks and tools, with a guide for configuring multiple network slices published on GitHub [1]. We also show the feasibility of monitoring and visualizing network slice KPIs using a representative cloud-gaming use-case. Niloy Saha, Alexander James, Nashid Shahriar, Raouf Boutaba, Aladdin Saleh |
NOMS | 4 |
| 2022 | Multi-Agent Deep Reinforcement Learning for Slicing and Admission Control in 5G C-RANabstract5G Cloud Radio Access Networks (C-RANs) facilitate new forms of flexible resource management as dynamic RAN function splitting and placement. Virtualized RAN functions can be placed at different sites in the substrate network according to resource availability and slice constraints. Due to limited resource availability in the substrate network, the Infrastructure Provider (InP) must perform network slicing in a strategic manner, and accept or reject slice-requests in order to maximize long-term revenue. In this paper, we propose to use multi-agent Deep Reinforcement Learning (DRL) to jointly solve the problems of network slicing and slice Admission Control (AC). Multi-agent DRL is a promising choice since it is well-suited to problems where multiple distinct tasks have to be performed optimally. The proposed DRL approach can learn the dynamics of slice-request traffic and effectively address these joint problems. We compare multi-agent DRL to approaches that use: (i) simple heuristics to address the problems, and (ii) DRL to address either slicing or AC. Our results show that the proposed approach achieves up to 18% and 3.8% gain in long-term InP revenue when compared to approaches (i) and (ii), respectively. Additionally, we show that multi-agent DRL is preferable to a single-agent DRL approach that addresses the problems jointly. Finally, we evaluate the robustness of the trained model in terms of its ability to generalize to scenarios that deviate from training. Arash Moayyedi, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Aladdin Saleh |
NOMS | 4 |
| 2022 | Dynamic clustering of software defined network switches and controller placement using deep reinforcement learning
EL Hocine Bouzidi, Abdelkader Outtagarts, Rami Langar, Raouf Boutaba |
Comput. Networks | 4 |
| 2022 | Non-Intrusive and Workflow-Aware Virtual Network Function Scheduling in User-SpaceabstractThe simple programming model and very low-overhead I/O capabilities of emerging packet processing techniques leveraging kernel-bypass I/O and poll-mode processing is gaining significant popularity for building high performance softwaremiddleboxes(akaVirtual Network Functions (VNFs)). However, existing OS schedulers fall short in rightsizing CPU allocation to poll-mode VNFs due to the schedulers’ shortcoming in capturing the actual processing cost of these VNFs. This issue is further exacerbated by their inability to consider VNF processing order when VNFs are chained to form Service Function Chains (SFCs). The state-of-the-art VNF schedulers proposed as an alternative to OS schedulers areintrusive, requiring the VNFs to be built with scheduler specific libraries or having carefully selected scheduling checkpoints. This highly restricts the VNFs that can properly work with these schedulers. In this article, we presentUNiS, aUser-spaceNon-intrusive work-flow aware VNFScheduler. Unlike existing approaches, UNiS is non-intrusive, i.e., does not require VNF modifications and treats poll-mode VNFs as black boxes. UNiS is also workflow-aware, i.e., takes SFC processing order into account while scheduling VNFs. Testbed experiments show thatUNiSis able to achieve a throughput within 90 and 98 percent of that achievable using an intrusive co-operative scheduler for synthetic and real data center traffic, respectively. Anthony, Shihabur Rahman Chowdhury, Tim Bai, Raouf Boutaba, Jérôme François |
IEEE Trans. Cloud Comput. | 4 |
| 2022 | Man-in-the-Middle Attack Mitigation in Internet of Medical ThingsabstractThe Internet of Medical Things are susceptible to Man-in-the-Middle (MitM) attack, which can identify healthcare emergency of monitored patients and replay normal physiological data to prevent the system from raising an alarm. In this article, we propose a framework to prevent a MitM from disrupting the operations and prohibiting the raise of alarms by the remote healthcare monitoring system. To reduce energy consumption for normal data transmission, and preserve the privacy of health data, our framework transmits a smaller size signature derived from acquired data with message authentication code, where the key is derived from received signal strength indication. Our experimental results for emergency detection show that our approach can achieve a high detection accuracy with a low false alarm rate of 3%. Osman Salem, Khalid Alsubhi, Aymen Shaafi, Mostafa Gheryani, Ahmed Mehaoua, Raouf Boutaba |
IEEE Trans. Ind. Informatics | 6 |
| 2022 | Latency and Mobility-Aware Service Function Chain Placement in 5G Networksabstract5G networks are expected to support numerous novel services and applications with versatile quality of service (QoS) requirements such as high data rates and low end-to-end (E2E) latency. It is widely agreed that E2E latency can be reduced by moving the computational capability closer to the network edge. The limited amount of computational resources of the edge nodes, however, poses the challenge of efficiently utilizing these resources while, at the same time, satisfying QoS requirements. In this work, we employ mixed-integer linear programming (MILP) techniques to formulate and solve a joint user association, service function chain (SFC) placement, where SFCs are composed of virtualized service functions (VSFs), and resource allocation problem in 5G networks composed of decentralized units (DUs), centralized units (CUs), and a core network (5GC). Specifically, we compare four approaches to solving the problem. The first two approaches minimize, respectively, the E2E latency experienced by users and the service provisioning cost. The other two instead aim at minimizing VSF migrations along with their impact on users’ quality of experience with the last one minimizing also the number of inter-CU handovers. We then propose a heuristic to address the scalability issue of the MILP-based solutions. Simulations results demonstrate the effectiveness of the proposed heuristic algorithm. Davit Harutyunyan, Nashid Shahriar, Raouf Boutaba, Roberto Riggio |
IEEE Trans. Mob. Comput. | 3 |
| 2022 | Chronos: DDoS Attack Detection Using Time-Based AutoencoderabstractCognitive network management is becoming quintessential to realize autonomic networking. However, the wide spread adoption of the Internet of Things (IoT) devices, increases the risk of cyber attacks. Adversaries can exploit vulnerabilities in IoT devices, which can be harnessed to launch massive Distributed Denial of Service (DDoS) attacks. Therefore, intelligent security mechanisms are needed to harden network security against these threats. In this paper, we propose Chronos, a novel time-based anomaly detection system. The anomaly detector, primarily an Autoencoder, leverages time-based features over multiple time windows to efficiently detect anomalous DDoS traffic. We develop a threshold selection heuristic that maximizes the F1-score across various DDoS attacks. Further, we compare the performance of Chronos against state-of-the-art approaches. We show that Chronos marginally outperforms another time-based system using a less complex anomaly detection pipeline, while out classing flow-based approaches with superior precision. In addition, we showcase the robustness of Chronos in the face of zero-day attacks, noise in training data, and a small number of training packets, asserting its suitability for online deployment. Mohammad Ali Salahuddin 0001, Vahid Pourahmadi, Hyame Assem Alameddine, Md. Faizul Bari, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2021 | Reoptimizing Network Slice Embedding on EON-enabled Transport Networksabstract5G transport networks will support dynamic services with diverse requirements through network slicing. Elastic Optical Networks (EONs) facilitate transport network slicing by flexible spectrum allocation and tuning of transmission configurations such as modulation format and forward error correction. A major challenge in supporting dynamic services is the lack of a priori knowledge of future slice requests. In consequence, slice embedding can become sub-optimal over time, leading to spectrum fragmentation and skewed utilization. This in turn can block future slice requests, impacting operator revenue. Therefore, operators need to periodically re-optimize slice embedding for reducing fragmentation. In this paper, we address this problem of re-optimizing network slice embedding on EONs for minimizing fragmentation. The problem is solved in its splittable version, which significantly increases problem complexity, but offers more opportunities for a larger set of re-configuration actions. We employ simulated annealing for systematically exploring the large solution space. We also propose a greedy algorithm to address the practical constraint to limit the number of re-configuration steps taken to reach a defragmentated state. Our extensive simulations demonstrate that the greedy algorithm yields a solution very close to that obtained using simulated annealing while requiring orders of magnitude lesser number of re-configuration actions. Sepehr Taeb, Nashid Shahriar, Shihabur Rahman Chowdhury, Massimo Tornatore, Raouf Boutaba, Jeebak Mitra, Mahdi Hemmati |
CNSM | 5 |
| 2021 | LINT: Accuracy-adaptive and Lightweight In-band Network Telemetry
Shihabur Rahman Chowdhury, Raouf Boutaba, Jérôme François |
IM | 2 |
| 2021 | Survivable Virtual Network Embedding
Nashid Shahriar, Raouf Boutaba |
IM | 2 |
| 2021 | RDP-based Lateral Movement detection using Machine Learning
Tim Bai, Haibo Bian, Mohammad Ali Salahuddin 0001, Abbas Abou Daya, Noura Limam, Raouf Boutaba |
Comput. Commun. | 6 |
| 2021 | Deep Q-Network and Traffic Prediction based Routing Optimization in Software Defined Networks
EL Hocine Bouzidi, Abdelkader Outtagarts, Rami Langar, Raouf Boutaba |
J. Netw. Comput. Appl. | 4 |
| 2021 | Markov Models for Anomaly Detection in Wireless Body Area Networks for Secure Health MonitoringabstractThe use of Wireless Body Area Networks (WBANs) in healthcare for pervasive monitoring enhances the lives of patients and allows them to fulfill their daily life activities while being monitored. Various non-invasive sensors are placed on the skin to monitor several physiological attributes, and the measured data are transmitted wirelessly to a centralized processing unit to detect changes in the health of the monitored patient. However, the transferred data are vulnerable to various sources of interference, sensor faults, measurement faults, injection and alteration by malicious attackers, etc. In this article, we propose a change point detection model based on a Markov chain for centralized anomaly detection in WBANs. The model is derived from the Root Mean Square Error (RMSE) between the forecasted and measured values for whole attributes. The RMSE transforms the monitored attributes into a univariate times series which is divided into overlapping sliding window. The joint probability of the sequence of RMSE values in each sliding window is calculated to decide whether a change has occurred or not. When an effective change is detected over k consecutive windows, the number of deviated attributes is used to distinguish faulty measurements from a health emergency. We apply our proposed approach on real physiological data from the Physionet database and compare it with existing approaches. Our experimental results prove the effectiveness of our proposed approach, as it achieves high detection accuracy with a low false alarm rate (5.2%). Osman Salem, Khalid Alsubhi, Ahmed Mehaoua, Raouf Boutaba |
IEEE J. Sel. Areas Commun. | 4 |
| 2021 | Disruption Minimized Bandwidth Scaling in EON-Enabled Transport Network SlicesabstractElastic Optical Networks (EONs) enable finer-grained resource allocation and tuning of transmission configurations for right-sized resource allocation. These features make EONs excellent choice for 5G transport networks supporting highly dynamic traffic with diverse Quality-of-Service (QoS) requirements. 5G network slices are expected to host applications with a dynamic nature (e.g., augmented/virtual reality broadcasting), which will result in slice resource requirement changing over time. The initial resource allocation to network slices has to be adapted to accommodate such changes without causing significant disruption to existing traffic and using minimal additional resources. In this paper, we address the problem of scaling bandwidth demand of network slices on an EON-enabled 5G transport network. In contrast to the state-of-the-art, we do not assume any specific technologies for minimizing disruption when accommodating the scaling request. Rather, we propose an Integer Linear Program (ILP) and a heuristic algorithm for accommodating scaling requests by choosing from a comprehensive set of reconfiguration actions. We carefully design a novel cost model for capturing traffic disruptions and additional resource usage by these different actions. Our extensive simulations using realistic network topologies shed light on the trade-off between additional resource usage and disruption while accommodating slice scaling requests by employing a comprehensive set of reconfiguration actions. Simulation results also show that our heuristic algorithm can find solutions that remain within 10% of ILP-based solutions, while executing several orders of magnitude faster than ILP. Nashid Shahriar, Mubeen Zulfiqar, Shihabur Rahman Chowdhury, Sepehr Taeb, Raouf Boutaba, Jeebak Mitra, Mahdi Hemmati |
IEEE J. Sel. Areas Commun. | 5 |
| 2021 | Uncovering Lateral Movement Using Authentication LogsabstractNetwork infiltrations due to advanced persistent threats (APTs) have significantly grown in recent years. Their primary objective is to gain unauthorized access to network assets, compromise system and data. APTs are stealthy and remain dormant for an extended period of time, which makes their detection challenging. In this article, we leverage machine learning (ML) to detect hosts in a network that are a target of an APT attack. We evaluate a number of ML classifiers to detect susceptible hosts in the Los Alamos National Lab dataset. We (i) scrutinize graph-based features extracted from host authentication logs, (ii) use feature engineering to reduce dimensionality, (iii) explore balancing the training dataset using over- and under-sampling techniques, (iv) evaluate numerous supervised ML techniques and their ensemble, (v) compare our classification model to the state-of-the-art approaches that leverage the same dataset, and show that our model outperforms them with respect to prediction performance and overhead, and (vi) perturb the attack patterns to study the influence of change in attack frequency and scale on classification performance, and propose a solution for such adversarial behavior. Haibo Bian, Tim Bai, Mohammad Ali Salahuddin 0001, Noura Limam, Abbas Abou Daya, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2021 | Mitigating TCP Protocol Misuse With Programmable Data PlanesabstractThis article proposes a new approach for detecting and mitigating the impact of misbehaving TCP end-hosts, specifically the Optimistic ACK attack, and Explicit Congestion Notification (ECN) abuse. In contrast to the state-of-the-art, we show that it is possible to mitigate such misbehavior leveraging emerging programmable data planes while not requiring any end-host or protocol modifications. A key challenge in doing so is to implement expressive, complex and stateful functions in the data plane within its restricted programming model. In this regard, we propose a security monitoring function that uses Extended Finite State Machine (EFSM) abstraction for monitoring stateful protocols in the data plane. We also design a mechanism for mapping a protocol's EFSM to programmable data plane primitives. Our evaluation results demonstrate that our approach can fully or partially restore the throughput loss caused by misbehaving end-hosts that manipulate TCP congestion control through misinformation. Abir Laraba, Jérôme François, Shihabur Rahman Chowdhury, Isabelle Chrisment, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2020 | Time-based Anomaly Detection using AutoencoderabstractDistributed Denial of Service (DDoS) attacks continue to draw significant attention, especially with the recent surge in cyber attacks that targeted the healthcare, education and financial sectors, during the COVID-19 pandemic. The expansion of virtualization and softwarization technologies, and the surge in Internet of Things (IoT) devices, increase the attack surface and the impact of attacks on networks. In this paper, we present a novel time-based anomaly detection system that leverages an Autoencoder. We explore the impact of different time-windows on detecting multiple DDoS attacks that are difficult to detect via the widely used flow-based features. We train and evaluate our Autoencoder on the recent CICDDoS2019 dataset, and show that our approach achieves an anomaly detection F1-score of over 99% for most attacks and greater than 95% for all attacks. Mohammad Ali Salahuddin 0001, Md. Faizul Bari, Hyame Assem Alameddine, Vahid Pourahmadi, Raouf Boutaba |
CNSM | 5 |
| 2020 | Online based learning for predictive end-to-end network slicing in 5G networksabstract5G networks are expected to provide a variety of services over the same physical infrastructure equipped with a combination of radio and wired transport networks and leveraging network virtualization and Software Defined Networking (SDN). In particular, network slicing is envisioned as a promising solution to enable optimal support for heterogeneous services sharing the same infrastructure. To this end, we design and implement, in this paper, an SDN based architecture for end-to-end network slicing which proactively and dynamically adapts radio slices to the transport network slices. The developed architecture enables the creation, modification and continuity of radio and transport network slices while considering their resource and Quality-of-Service (QoS) requirements. It leverages Machine Learning for predicting radio slices capacities, improving network resource utilization, and predicting congestion within each network slice. We also formulate this network slicing problem as a Linear Program (LP) aiming to minimize the total network delay. Finally, we propose an efficient heuristic algorithm with low time complexity and high estimation accuracy to solve large problem instances. Experimental results using the OpenAirInterface (OAI) platform, FlexRAN, ONOS SDN Controllers and OpenvSwitch demonstrate the efficiency of our approach in terms of guaranteeing low latency and high network throughput. EL Hocine Bouzidi, Abdelkader Outtagarts, Abdelkrim Hebbar, Rami Langar, Raouf Boutaba |
ICC | 5 |
| 2020 | Offloading Network Data Analytics Function to the Cloud with Minimum Cost and Maximum UtilizationabstractCloud computing is being embraced more and more by telecommunication operators for on-demand access to computing resources. Knowing that 5G Core reference architecture is envisioned to be cloud-native and service-oriented, we propose, in this paper, offloading to the cloud, some of 5G delay-tolerant Network Functions and in particular the Network Data Analytics Function (NWDAF). The dynamic selection of cloud resources to serve off-loaded 5G-NWDAF, while incurring minimum cost and maximizing utilization of served next generation Node-Bs (gNBs) requires agility and automation. This paper introduces a framework to automate the selection process that satisfies resource demands while meeting two objectives, namely, cost minimization and utilization maximization. We first formulate the mapping of gNBs to 5G-NWDAF problem as an Integer Linear Program (ILP). Then, we propose an algorithm to solve it based on branch-cut-and-price technique combining all of branch-and-price, branch-and-cut and branch-and-bound. Results using pricing data from a public cloud provider (Google Cloud Platform), show that our proposal achieves important savings in cloud computing costs and reduction in execution time compared to other state-of-the-art frameworks. Nazih Salhab, Rana Rahim, Rami Langar, Raouf Boutaba |
ICC | 4 |
| 2020 | Defeating Protocol Abuse with P4: Application to Explicit Congestion Notification
Abir Laraba, Jérôme François, Isabelle Chrisment, Shihabur Rahman Chowdhury, Raouf Boutaba |
Networking | 5 |
| 2020 | Deep Neural Networks approach for Power Head-Room Predictions in 5G Networks and Beyond
Nazih Salhab, Rana Rahim, Rami Langar, Raouf Boutaba |
Networking | 4 |
| 2020 | ATMoS: Autonomous Threat Mitigation in SDN using Reinforcement LearningabstractMachine Learning has revolutionized many fields of computer science. Reinforcement Learning (RL), in particular, stands out as a solution to sequential decision making problems. With the growing complexity of computer networks in the face of new emerging technologies, such as the Internet of Things and the growing complexity of threat vectors, there is a dire need for autonomous network systems. RL is a viable solution for achieving this autonomy. Software-defined Networking (SDN) provides a global network view and programmability of network behaviour, which can be employed for security management. Previous works in RL-based threat mitigation have mostly focused on very specific problems, mostly non-sequential, with ad-hoc solutions. In this paper, we propose ATMoS, a general framework designed to facilitate the rapid design of RL applications for network security management using SDN. We evaluate our framework for implementing RL applications for threat mitigation, by showcasing the use of ATMoS with a Neural Fitted Q-learning agent to mitigate an Advanced Persistent Threat. We present the RL model’s convergence results showing the feasibility of our solution for active threat mitigation. Iman Akbari, Ezzeldin Tahoun, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
NOMS | 5 |
| 2020 | Fault Tolerant Service Function ChainingabstractNetwork traffic typically traverses a sequence of middleboxes forming a service function chain, or simply a chain. Tolerating failures when they occur along chains is imperative to the availability and reliability of enterprise applications. Making a chain fault-tolerant is challenging since, in the event of failures, the state of faulty middleboxes must be correctly and quickly recovered while providing high throughput and low latency. Milad Ghaznavi, Elaheh Jalalpour, Bernard Wong 0001, Raouf Boutaba, Ali José Mashtizadeh |
SIGCOMM | 4 |
| 2020 | Latency and energy-aware provisioning of network slices in cloud networksabstractModern network services are constantly increasing their requirements in terms of bandwidth, latency and cost efficiency. To satisfy these requirements, the concept of network slicing has been introduced in the context of next-generation 5G networks. However, to successfully provision resources to slices, a complex optimization problem must be addressed to allocate resources over a cloud network, i.e., a distributed computing infrastructure interconnected through high-capacity network links. In this study, we propose two new latency and energy-aware optimization models for provisioning 5G slices in cloud networks comprising both distributed computing and network resources. The proposed approaches differ from other existing solutions since we conduct our studies with respect to the end-to-end latency. Relevant models of latency and energy consumption are proposed based on a comprehensive review of the state-of-the-art. To effectively solve those optimization problems, a configurable heuristic is also proposed and investigated over different network topologies. Performance of the proposed heuristic is compared against near-optimal solutions. Moreover, we assess the importance of matching between resource provisioning algorithms and architectural assumptions related to 5G network slices and a proper problem modeling. Piotr Borylo, Massimo Tornatore, Piotr Jaglarz, Nashid Shahriar, Piotr Cholda, Raouf Boutaba |
Comput. Commun. | 6 |
| 2020 | Joint Diversity and Redundancy for Resilient Service Chain ProvisioningabstractAchieving network resiliency in terms of availability, reliability and fault tolerance is a central concern for network designers and operators to achieve business continuity and increase productivity. It is particularly challenging in increasingly virtualized network environments where network services are exposed to both hardware (e.g., bare-metal servers, switches, links, etc.) and software (VNF instances) failures. This increased risk of failures can severely deteriorate the quality of the deployed services and even lead to complete service outages. In this context, deploying services in operational networks often exacerbates the availability problem and requires considering availability of hardware and software components both individually and collectively. A key challenge in this perspective is the additional resources needed to achieve partial or full recovery after failures. In this paper, we propose a joint selective diversity and tailored redundancy mechanism to provision resilient services in an NFV framework. Diversity splits a single VNF into a pool of “N” active instances called replicas while redundancy provides “P” standby ready-to-use instances called backups. Based on an enhanced N+P model, we propose a placement solution of Service Function Chains (SFC) modeled as a Mixed Integer Linear Program (MILP). The proposed solution is designed to meet a target SFC availability level and, at the same time, to reduce the inherent cost due to diversity (overhead) and redundancy (backup resources). We evaluate the efficiency of the proposed solution through numerically and experimentally. Results demonstrate that our solution, not only, improves service resiliency by avoiding complete service outages but can also overcome network resource fragmentation. Abdelhamid Alleg, Toufik Ahmed, Mohamed Mosbah 0001, Raouf Boutaba |
IEEE J. Sel. Areas Commun. | 4 |
| 2020 | A Disaggregated Packet Processing Architecture for Network Function VirtualizationabstractNetwork Function Virtualization (NFV) promises to reduce the capital and operational expenditure for network operators by moving packet processing from purpose-built hardware to software running on commodity servers. However, the state-of-the-art in NFV is merely replacing monolithic hardware with monolithic Virtual Network Functions (VNFs), i.e., software that realizes different network functions. This is a good first step towards transitioning to NFV, however, common functionality is repeatedly implemented in monolithic VNFs. Repeated execution of such redundant functionality is particularly common when VNFs are chained to realize Service Function Chains (SFCs) and results in wasted infrastructure resources. This stresses the need for re-architecting the NFV ecosystem, through modular VNF design and flexible service composition. From this perspective, we propose MicroNF (μNF in short), a disaggregated packet processing architecture facilitating the deployment of VNFs and SFCs using reusable, loosely-coupled, and independently deployable components. We have implemented the proposed system, including the different architecture components and optimizations for improving packet processing throughput and latency. Extensive experiments on a testbed demonstrate that: (i) compared to monolithic VNF based SFCs, those composed of μNFs achieve the same packet processing throughput while using less CPU cycles per packet on average; and (ii) μNF-based SFCs can sustain the same packet processing throughput as those based on state-of-the-art run-to-completion VNF architecture while using lesser number of CPU cores. Shihabur Rahman Chowdhury, Anthony, Haibo Bian, Tim Bai, Raouf Boutaba |
IEEE J. Sel. Areas Commun. | 5 |
| 2020 | Virtual Network Embedding With Guaranteed Connectivity Under Multiple Substrate Link FailuresabstractThis paper addresses Connectivity-aware Virtual Network Embedding (CoViNE) problem, which consists in embedding a virtual network (VN) on a substrate network while ensuring VN connectivity (without any bandwidth guarantee) against multiple substrate link failures. CoViNE provides a weaker form of survivability incurring less resource overhead than traditional VN survivability models. To optimally solve CoViNE, we present an Integer Linear Program (ILP), namely CoViNE-opt. CoViNE-opt enumerates an exponential number of edge-cuts in a VN severely limiting its scalability. Therefore, we decompose CoViNE into three sub-problems: i) augmenting a VN with virtual links to provide necessary connectivity, ii) identifying the virtual links that should be embedded disjointly, and iii) computing a VN embedding while satisfying the disjointness constraints. We introduce conflicting set abstraction that allows to address sub-problems (i) and (ii) without enumerating all the edge-cuts of a VN. We propose two novel solutions to CoViNE leveraging conflicting set, namely CoViNE-ILP and CoViNE-fast. CoViNE-ILP uses a heuristic algorithm to address sub-problems (i) and (ii), while an ILP is used for sub-problem (iii). In contrast, CoViNE-fast uses heuristics for solving all three sub-problems. Through simulation, we evaluate the optimality and scalability of our solutions and demonstrate a failure restoration use-case enabled by CoViNE. Nashid Shahriar, Reaz Ahmed, Shihabur Rahman Chowdhury, Md Mashrur Alam Khan, Raouf Boutaba, Jeebak Mitra |
IEEE Trans. Commun. | 5 |
| 2020 | BotChase: Graph-Based Bot Detection Using Machine LearningabstractBot detection using machine learning (ML), with network flow-level features, has been extensively studied in the literature. However, existing flow-based approaches typically incur a high computational overhead and do not completely capture the network communication patterns, which can expose additional aspects of malicious hosts. Recently, bot detection systems that leverage communication graph analysis using ML have gained attention to overcome these limitations. A graph-based approach is rather intuitive, as graphs are true representation of network communications. In this paper, we propose BotChase, a two-phased graph-based bot detection system that leverages both unsupervised and supervised ML. The first phase prunes presumable benign hosts, while the second phase achieves bot detection with high precision. Our prototype implementation of BotChase detects multiple types of bots and exhibits robustness to zero-day attacks. It also accommodates different network topologies and is suitable for large-scale data. Compared to the state-of-the-art, BotChase outperforms an end-to-end system that employs flow-based features and performs particularly well in an online setting. Abbas Abou Daya, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2020 | Reliable Slicing of 5G Transport Networks With Bandwidth Squeezing and Multi-Path Provisioningabstract5G network slicing allows partitioning of network resources to meet stringent end-to-end service requirements across multiple network segments, from access to transport. These requirements are shaping technical evolution in each of these segments. In particular, the transport segment is currently evolving in the direction of elastic optical networks (EONs), a new generation of optical networks supporting a flexible optical-spectrum grid and novel elastic transponder capabilities. In this paper, we focus on the reliability of 5G transport-network slices in EON. Specifically, we consider the problem of slicing 5G transport networks,i.e., establishing virtual networks on 5G transport, while providing dedicated protection. As dedicated protection requires a large amount of backup resources, our proposed solution incorporates two techniques to reduce backup resources: (i) bandwidth squeezing,i.e., providing a reduced protection bandwidth than the original request; and (ii) survivable multi-path provisioning. We leverage the capability of EONs to fine tune spectrum allocation and adapt modulation format and forward error correction for allocating spectrum resources. Our numerical evaluation over realistic network topologies quantifies the spectrum savings achieved by employing EON over traditional fixed-grid optical networks, and provides new insights on the impact of bandwidth squeezing and multi-path provisioning on spectrum utilization. One key takeaway from our evaluation is that multi-path provisioning can guarantee up to 40% of the bandwidth requested by a VN during failures by provisioning only 10% additional spectrum resources. This also caused VN blocking ratio for BSR up to 40% to remain very close to that of the no-backup case. Nashid Shahriar, Sepehr Taeb, Shihabur Rahman Chowdhury, Mubeen Zulfiqar, Massimo Tornatore, Raouf Boutaba, Jeebak Mitra, Mahdi Hemmati |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2019 | Host in Danger? Detecting Network Intrusions from Authentication LogsabstractRecently, network infiltrations due to advanced persistent threats (APTs) have grown significantly, resulting in considerable losses to businesses and organizations. APTs are stealthy attacks with the primary objective of gaining unauthorized access to network assets. They often remain dormant for an extended period of time, which makes their detection challenging. In this paper, we leverage machine learning (ML) to detect hosts in a network that are targeted by an APT attack. We evaluate a number of ML classifiers to detect susceptible hosts in the Los Alamos National Lab dataset. We explore (i) graph-based features extracted from multiple data sources i.e., network flows and host authentication logs, (ii) feature engineering to reduce dimensionality, and (iii) balancing the training dataset using numerous over- and under-sampling techniques. Finally, we compare our model to the state-of-the-art approaches that leverage the same dataset, and show that our model outperforms them with respect to prediction performance and overhead. Haibo Bian, Tim Bai, Mohammad Ali Salahuddin 0001, Noura Limam, Abbas Abou Daya, Raouf Boutaba |
CNSM | 6 |
| 2019 | Orchestrating End-to-end Slices in 5G Networksabstract5G networks are characterized by massive device connectivity, supporting a wide range of novel applications with their diverse Quality of Service (QoS) requirements. This poses a challenge since 5G as one-fits-all technology has to simultaneously address all these requirements. Network slicing has been proposed to cope with this challenge, calling for efficient slicing and slice placement strategies in order to ensure that the slice requirements (e.g., latency, data rate) are met, while the network resources are utilized in the most optimal manner. In this paper, we compare different end-to-end (E2E) slice placement strategies by formulating and solving a Mixed Integer Linear Programming (MILP) slice placement problem and study their trade-offs. E2E slice requests are modelled as Service Functions Chains (SFC), in which each core network and radio access network component is represented as a Virtual Network Function (VNF). Based on the analysis of the results, we then propose a slice placement heuristic algorithm whose objective is to minimize the number of VNF migrations in the network and their impact onto the slices while, at the same time, optimizing the network utilization and making sure that the QoS requirements of the considered slice requests are satisfied. The results of the simulations demonstrate the efficiency of the proposed algorithm. Davit Harutyunyan, Riccardo Fedrizzi, Nashid Shahriar, Raouf Boutaba, Roberto Riggio |
CNSM | 4 |
| 2019 | Reliable Slicing of 5G Transport Networks with Dedicated ProtectionabstractIn 5G networks, slicing allows partitioning of network resources to meet stringent end-to-end service requirements across multiple network segments, from access to transport. These requirements are shaping technical evolution in each of these segments. In particular, the transport segment is currently evolving in the direction of the so-called elastic optical networks (EONs), a new generation of optical networks supporting a flexible optical-spectrum grid and novel elastic transponder capabilities. In this paper, we focus on the reliability of 5G transport-network slices in EON. Specifically, we consider the problem of slicing 5G transport networks, i.e., establishing virtual networks on 5G transport, while providing dedicated protection. As dedicated protection requires a large amount of backup resources, our proposed solution incorporates two techniques to reduce backup resources: (i) bandwidth squeezing, i.e., providing a reduced protection bandwidth with respect to the original request; and (ii) survivable multi-path provisioning. We leverage the capability of EONs to fine tune spectrum allocation and adapt modulation format and Forward Error Correction (FEC) for allocating rightsize spectrum resources to network slices. Our numerical evaluation over realistic case-study network topologies quantifies the spectrum savings achieved by employing EON over traditional fixed-grid optical networks, and provides new insights on the impact of bandwidth squeezing and multi-path provisioning on spectrum utilization. Nashid Shahriar, Sepehr Taeb, Shihabur Rahman Chowdhury, Mubeen Zulfiqar, Massimo Tornatore, Raouf Boutaba, Jeebak Mitra, Mahdi Hemmati |
CNSM | 6 |
| 2019 | Machine Learning Based Resource Orchestration for 5G Network Slicesabstract5G will serve heterogeneous demands in terms of data-rate, reliability, latency, and efficiency. Mobile operators shall be able to serve all of these requirements using shared network infrastructure's resources. To this end, we propose in this paper a framework for resource orchestration for 5G network slices implementing four Quality of Service pillars. Starting from traffic classification, demands are marked so that they are best served by dedicated logical virtual networks called Network Slices (NSs). To optimally serve multiple NSs over the same physical network, we then implement a new dynamic slicing approach of network resources exploiting Machine Learning (ML). Indeed, as demands change dynamically, a mere recursive optimization leading to progressive convergence towards an optimum slice is not sufficient. Consequently, we need an initial well-informed slicing decision of physical resources from a total available resource pool. Moreover, we formalize both admission control and slice scheduler modules as Knapsack problems. Using our 5G experimental prototype based on OpenAirInterface (OAI), we generate a realistic dataset for evaluating ML based approaches as well as two baselines solutions (i.e. static slicing and uninformed random slicing-decisions). Simulation results show that using regression trees as an ML based approach for both classification and prediction, outperform other alternative solutions in terms of prediction accuracy and throughput. Nazih Salhab, Rana Rahim, Rami Langar, Raouf Boutaba |
GLOBECOM | 4 |
| 2019 | Virtual Network Embedding with Path-based Latency Guarantees in Elastic Optical NetworksabstractElastic Optical Network (EON) virtualization has recently emerged as an enabling technology for 5G network slicing. A fundamental problem in EON slicing (known as Virtual Network Embedding (VNE)) is how to efficiently map a virtual network (VN) on a substrate EON characterized by elastic transponders and flexible grid. Since a number of 5G services will have strict latency requirements, the VNE problem in EONs must be solved while guaranteeing latency targets. In existing literature, latency has always been modeled as a constraint applied on the virtual links of the VN. In contrast, we argue in favor of an alternate modeling that constrains the latency of virtual paths. Constraining latency over virtual paths (vs. over virtual links) poses additional modeling and algorithmic challenges to the VNE problem, but allows us to capture end-to-end service requirements. In this paper, we first model latency in an EON by identifying the different factors that contribute to it. We formulate the VNE problem with latency guarantees as an Integer Linear Program (ILP) and propose a heuristic solution that can scale to large problem instances. We evaluated our proposed solutions using real network topologies and realistic transmission configurations under different scenarios and observed that, for a given VN request, latency constraints can be guaranteed by accepting a modest increase in network resource utilization. Latency constraints instead showed a higher impact on VN blocking ratio in dynamic scenarios. Sepehr Taeb, Nashid Shahriar, Shihabur Rahman Chowdhury, Massimo Tornatore, Raouf Boutaba, Jeebak Mitra, Mahdi Hemmati |
ICNP | 5 |
| 2019 | A Graph-Based Machine Learning Approach for Bot Detection
Abbas Abou Daya, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
IM | 4 |
| 2019 | TMAS: A Traffic Monitoring Analytics System Leveraging Machine Learning
Elaheh Jalalpour, Milad Ghaznavi, Raouf Boutaba, Toufik Ahmed |
IM | 3 |
| 2019 | Achieving a Fully-Flexible Virtual Network Embedding in Elastic Optical NetworksabstractNetwork operators must continuously scale the capacity of their optical backbone networks to keep apace with the proliferation of bandwidth-intensive applications. Today’s optical networks are designed to carry large traffic aggregates with coarse-grained resource allocation, and are not adequate for maximizing utilization of the expensive optical substrate. Elastic Optical Network (EON) is an emerging technology that facilitates flexible allocation of fiber spectrum by leveraging finer-grained channel spacing, tunable modulation formats and Forward Error Correction (FEC) overheads, and baud-rate assignment, to right size spectrum allocation to customer needs. Virtual Network Embedding (VNE) over EON has been a recent topic of interest due to its importance for 5G network slicing. However, the problem has not yet been addressed while simultaneously considering the full flexibility offered by an EON. In this paper, we present an optimization model that solves the VNE problem over EON when lightpath configurations can be chosen among a large (and practical) set of combinations of paths, modulation formats, FEC overheads and baud rates. The VNE over EON problem is solved in its splittable version, which significantly increases problem complexity, but is much more likely to return a feasible solution. Given the intractability of the optimal solution, we propose a heuristic to solve larger problem instances. Key results from extensive simulations are: (i) a fully-flexible VNE can save up to 60% spectrum resources compared to that where no flexibility is exploited, and (ii) solutions of our heuristic fall in more than 90% of the cases, within 5% of the optimal solution, while executing several orders of magnitude faster. Nashid Shahriar, Sepehr Taeb, Shihabur Rahman Chowdhury, Massimo Tornatore, Raouf Boutaba, Jeebak Mitra, Mahdi Hemmati |
INFOCOM | 5 |
| 2019 | A Machine Learning Approach for RDP-based Lateral Movement DetectionabstractDetecting cyber threats has been an on-going research endeavor. In this era, advanced persistent threats (APTs) can incur significant cost for organizations and businesses. The ultimate goal of cyber security is to thwart attackers from achieving their malicious intent, whether it is credential stealing, infrastructure takeover, or program sabotage. Every cyber attack goes through several stages before its termination. Lateral movement (LM) is one of those stages which is of particular importance. Remote Desktop Protocol (RDP) is a method used in LM to successfully authenticate to an unauthorized host that leaves footprints on both host and network logs. In this paper, we propose to detect evidence of LM with an anomaly detection approach that leverages Windows RDP event logs. We evaluate various supervised machine learning (ML) techniques for classifying RDP sessions with high precision and recall. We also compare the performance of our proposed approach to a state-of-the-art approach and demonstrate that our ML model outperforms in classifying RDP sessions in Windows event logs. Tim Bai, Haibo Bian, Abbas Abou Daya, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
LCN | 6 |
| 2019 | SPONGE: Software-Defined Traffic Engineering to Absorb Influx of Network TrafficabstractExisting shortest path-based routing in wide area networks or equal cost multi-path routing in data center networks do not consider the load on the links while taking routing decisions. As a consequence, an influx of network traffic stemming from events such as distributed link flooding attacks and data shuffle during large scale analytics can congest network links despite the network having sufficient capacity on alternate paths to absorb the traffic. This can have several negative consequences such as service unavailability, delayed flow completion, packet losses, among others. In this regard, we propose SPONGE, a traffic engineering mechanism for handling sudden influx of network traffic. SPONGE models the network as a stochastic process, takes the switch queue occupancy and traffic rate as inputs, and leverages the multiple available paths in the network to route traffic in a way that minimizes the overall packet loss in the network. We demonstrate the practicality of SPONGE through an OpenFlow based implementation, where we periodically and pro-actively re-route network traffic to the routes computed by SPONGE. Mininet emulations using real network topologies show that SPONGE is capable of reducing packet drops by 20% on average even when the network is highly loaded because of an ongoing link flooding attack. Benoît Henry, Shihabur Rahman Chowdhury, Abdelkader Lahmadi, Romain Azaïs, Jérôme François, Raouf Boutaba |
LCN | 6 |
| 2019 | $\mu\mathrm{NF}$: A Disaggregated Packet Processing ArchitectureabstractNetwork Function Virtualization (NFV) promises to reduce the capital and operational expenditure for network operators by moving packet processing from purpose-built hardware to software running on commodity servers. However, the state-of-the-art in NFV is merely replacing monolithic hardware with monolithic Virtual Network Functions (VNFs), i.e., software that realizes different network functions. This is a good first step towards deploying NFV, however, common functionality is repeatedly implemented in monolithic VNFs. Repeated execution of such redundant functionality is particularly common when VNFs are chained to realize Service Function Chains (SFCs) and results in wasted infrastructure resources. This stresses the need for re-architecting the NFV ecosystem, through modular VNF design and flexible service composition. From this perspective, we propose MicroNF ( μNF in short), a disaggregated packet processing architecture facilitating the deployment of VNFs and SFCs using reusable and independently deployable components. Experimental results show that compared to monolithic VNF based SFCs, μNF-based ones achieve the same throughput by using less CPU cycles per packet on average. Shihabur Rahman Chowdhury, Anthony, Haibo Bian, Tim Bai, Raouf Boutaba |
NetSoft | 5 |
| 2019 | Latency-Aware Service Function Chain Placement in 5G Mobile NetworksabstractThe 5th generation mobile network (5G) is expected to support numerous services with versatile quality of service (QoS) requirements such as high data rates and low end-to-end (E2E) latency. It is widely agreed that E2E latency can be significantly reduced by moving content/computing capability closer to the network edge. However, since the edge nodes (i.e., base stations) have limited computing capacity, mobile network operators shall make a decision on how to provision the computing resources to the services in order to make sure that the E2E latency requirement of the services are satisfied while the network resources (e.g., computing, radio, and transport network resources) are used in an efficient manner. In this work, we employ integer linear programming (ILP) techniques to formulate and solve a joint user association, service function chain (SFC) placement, and resource allocation problem where SFCs, composed of virtualized service functions (VSFs), represent user requested services that have certain E2E latency and data rate requirements. Specifically, we compare three variants of an ILP-based algorithm that aim to minimize E2E latency of requested services, service provisioning cost, and VSF migration frequency, respectively. We then propose a heuristic in order to address the scalability issue of the ILP-based solutions. Simulations results demonstrate the effectiveness of the proposed heuristic algorithm. Davit Harutyunyan, Nashid Shahriar, Raouf Boutaba, Roberto Riggio |
NetSoft | 3 |
| 2019 | Collision Avoidance Energy Efficient Multi-Channel MAC Protocol for UnderWater Acoustic Sensor NetworksabstractCollisions in underwater acoustic networks can not be tolerated due to the fundamental differences between underwater acoustic propagation and terrestrial radio propagation. Thus, conceiving medium access protocols that avoid collision to the most possible extent is of paramount importance. In this paper, a multi-channel MAC protocol, MC-UWMAC, especially designed for underwater acoustic sensor networks, is proposed and evaluated. MC-UWMAC is an energy efficient MAC protocol that aims at achieving a collision free communication. MC-UWMAC operates on a single slotted control channel to avoid the missing receiver problem and multiple data channels to improve the network throughput. To guarantee to the most possible extent a collision free communication, MC-UWMAC uses two key newly designed procedures: i) a grid based slot assignment procedure on the common slotted control channel that approaches the 2-hop conflict free slot assignment and ii) a quorum based data channel allocation procedure. More precisely, according to MC-UWMAC, a sender uses its own dedicated slot on the common control channel for handshaking with an intended neighbor receiver. However, data transmission takes place in a unique data channel especially reserved for this pair of neighbor nodes. In fact, MC-UWMAC reserves for each pair of neighbor nodes a unique data channel that aims at being 2-hop conflict free. As such, the probability of collision is highly reduced and even completely mitigated in some scenarios. In addition, by using multiple channels, MC-UWMAC allows multiple data communications along with handshaking on the common control channel to take place at the same time and hence the network throughput as well as energy efficiency are improved. Simulation results show that MC-UWMAC can greatly improve the network performance especially in terms of energy consumption, throughput, and end-to-end delay. Fatma Bouabdallah, Chaima Zidi, Raouf Boutaba, Ahmed Mehaoua |
IEEE Trans. Mob. Comput. | 3 |
| 2019 | Nocturnal Epileptic Seizures Detection Using Inertial and Muscular SensorsabstractThis paper presents a lightweight approach for the early detection of nocturnal epileptic seizures through analysis of inertial data and muscle contractions. Our approach uses an overlapping sliding window to derive the variance of data acquired by the MPU 9,250 motion tracking device and single channel surface ElectroMyoGram (sEMG). The Exponentially Weighted Moving Average (EWMA) is used to forecast the current value of the data variance. When the Kullback-Leibler divergence between the forecasted and measured variances deviates from past values, a signal is transmitted to the base station to set the current counter in an alarm window. If the filling ratio of the alarm window is greater than a predefined threshold, an alarm is triggered by the base station. The proposed approach is intended to improve the performance of existing detection systems based on data analysis from Accelerometer. The MPU 9,250 is 9-axis motion tracking and used to detect motor seizures, and it contains a 3-axis Accelerometer, Gyroscope, and Magnetometer. The sEMG is used to detect silent seizures without jerky movements. Our experimental results on a real dataset from an epileptic patient show that our proposed approach is able to increase detection accuracy and reduce the low false alarm rate. Comparison with a Probability Density Function (PDF) further demonstrates the detection efficiency of our approach. Osman Salem, Khalid Alsubhi, Ahmed Mehaoua, Raouf Boutaba |
IEEE Trans. Mob. Comput. | 4 |
| 2019 | ESSO: An Energy Smart Service Function Chain OrchestratorabstractThe rapid development of technologies such as photo-intensive social networks, on-demand video streaming, online gaming, and the Internet of Things (IoT) is causing a tremendous growth of traffic volume. Such large-scale expansion is leading to higher energy consumption and carbon footprint for the telecommunication industry. Governments are trying to minimize the environmental impact by introducing regulations and taxes; driving companies to use renewable energy. However, renewable energy is still not as cost-effective compared to traditional sources of energy (i.e., brown energy), and their availability varies significantly across time and geographic locations. Therefore, it is a challenge for telecommunication companies to comply with regulations and minimize carbon footprint without significantly increasing their operational cost. In this context, we propose an Energy Smart Service Function Chain Orchestrator called ESSO. ESSO reduces the overall carbon footprint of a telecommunication network by opportunistically adapting Service Function Chain (SFC) locations to utilize more energy at locations with surplus renewable energy. ESSO minimizes brown energy consumption by migrating SFCs across different locations. In addition, ESSO provisions SFC components in a manner that allows switches, switch ports, and servers to be put into low-power consumption state. Our trace-driven simulations on real ISP topologies show that considering the availability of renewable energy sources during SFC embedding even for a small-scale network can result in 2-3× reduction in carbon footprint. Md. Faizul Bari, Shihabur Rahman Chowdhury, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2018 | UNiS: A User-space Non-intrusive Workflow-aware Virtual Network Function Scheduler
Anthony, Shihabur Rahman Chowdhury, Tim Bai, Raouf Boutaba, Jérôme François |
CNSM | 4 |
| 2018 | Bitforest: a Portable and Efficient Blockchain-Based Naming System
Yuhao Dong, Woojung Kim, Raouf Boutaba |
CNSM | 3 |
| 2018 | ENSC: Multi-Resource Hybrid Scaling for Elastic Network Service Chain in CloudsabstractSoftware-based network service chains in Network Function Virtualization (NFV) need to be dynamically allocated and scaled on hardware resources. This is because the resource demand of virtual network functions (VNFs) typically varies as a results of network flow volume. NFV elastic solutions by coarse-grained horizontal scaling or fine-grained vertical scaling have been investigated in recent years. However, none of the existing solutions can achieve both efficiency and scalability. To address this challenge, we propose elastic network service chain (ENSC), which utilizes a fine-grained hybrid scaling method to achieve both NFV efficiency and scalability. We systematically compare horizontal scaling with vertical scaling from six aspects and determine the priority within hybrid scaling. We formulate the resource allocation problem in the cloud datacenter as an integer linear programming (ILP) model and develop a heuristic algorithm called Rubik. Our evaluation results show that ENSC achieves higher acceptance ratios and resource utilization than horizontal scaling and vertical scaling methods. Hui Yu 0004, Jiahai Yang 0001, Carol J. Fung, Raouf Boutaba |
ICPADS | 4 |
| 2018 | sOFTDP: Secure and efficient OpenFlow topology discovery protocolabstractTopology discovery is one of the most critical tasks of Software-Defined Network (SDN) controllers. Current SDN controllers use the OpenFlow Discovery Protocol (OFDP) as the de-facto protocol for discovering the underlying network topology. In a previous work, we have shown the functional, performance and security limitations of OFDP. In this paper, we introduce and detail a novel protocol called secure and efficient OpenFlow Discovery Protocol sOTDP. sOFTDP requires minimal changes to OpenFlow switch design, eliminates major vulnerabilities in the topology discovery process and improves its performance. We have implemented sOFTDP as a topology discovery module in Floodlight for evaluation. The results show that our implementation is more secure than OFDP and previous security workarounds. Also, sOFTDP reduces the topology discovery time several orders of magnitude compared to the original OFDP and existing OFDP improvements. Abdelhadi Azzouni, Raouf Boutaba, Thi Mai Trang Nguyen, Guy Pujolle |
NOMS | 2 |
| 2018 | Dynamic allocation of power delivery paths in consolidated data centers based on adaptive UPS switching
Fawaz AL-Hazemi, Yuyang Peng, Chan-Hyun Youn, Josip Lorincz, Chao Li 0009, Song Guo 0001, Raouf Boutaba |
Comput. Networks | 7 |
| 2018 | Virtual Network Survivability Through Joint Spare Capacity Allocation and EmbeddingabstractA key challenge in network virtualization is to efficiently map a virtual network (VN) on a substrate network (SN), while accounting for possible substrate failures. This is known as the survivable VN embedding (SVNE) problem. The state-of-the-art literature has studied the SVNE problem from infrastructure providers' (InPs') perspective, i.e., provisioning backup resources in the SN. A rather unexplored solution spectrum is to augment the VN with sufficient spare backup capacity to survive substrate failures and embed the resulting VN accordingly. Such augmentation enables InPs to offload failure recovery decisions to the VN operator, thus providing more flexible VN management. In this paper, we study the problem of jointly optimizing spare capacity allocation in a VN and embedding the VN to guarantee full bandwidth in the presence of multiple substrate link failures. We formulate the optimal solution to this problem as a quadratic integer program that we transform into an integer linear program. We also propose a heuristic algorithm to solve larger instances of the problem. Based on analytical study and simulation, our key findings are: 1) provisioning shared backup resources in the VN can yield ~33% more resource efficient embedding compared to doing the same at the SN level and 2) our heuristic allocates ~21% extra resources compared to the optimal, while executing several orders of magnitude faster. Nashid Shahriar, Shihabur Rahman Chowdhury, Reaz Ahmed, Aimal Khan, Siavash Fathi, Raouf Boutaba, Jeebak Mitra |
IEEE J. Sel. Areas Commun. | 6 |
| 2018 | Multi-Layer Virtual Network EmbeddingabstractNetwork virtualization (NV), considered as a key enabler for overcoming the ossification of the Internet allows multiple heterogeneous virtual networks to co-exist over the same substrate network. Resource allocation problems in NV have been extensively studied for single layer substrates such as IP or Optical networks. However, little effort has been put to address the same problem for multi-layer IP-over-optical networks. The increasing popularity of multi-layer networks for deploying backbones combined with their unique characteristics ( e.g., topological flexibility of the IP layer) calls for the need to carefully investigate the resource provisioning problems arising from their virtualization. In this paper, we address the problem of multi-layer virtual network embedding (MULE; similar to multi-layer networks, this hybrid species brings the best of two species together.) on IP-over-optical networks. We propose two solutions to MULE: 1) an integer linear program formulation for the optimal solution (OPT-MULE) and 2) a heuristic to address the computational complexity of the optimal solution (FAST-MULE). We demonstrate through extensive simulations that on average our heuristic performs within $\boldsymbol \approx 1.47\boldsymbol \times $ of optimal solution while executing several orders of magnitude faster. Simulation results also show that FAST-MULE incurs ≈66% less cost on average than the state-of-the-art heuristic while accepting ≈60% more virtual network requests on average. Shihabur Rahman Chowdhury, Sara Ayoubi, Reaz Ahmed, Nashid Shahriar, Raouf Boutaba, Jeebak Mitra |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2018 | Guest Editors' Introduction: Special Section on Novel Techniques for Managing Softwarized NetworksabstractThe softwarization of networks is enabled by the SDN (Software-Defined Networking), NV (Network Virtualization), and NFV (Network Function Virtualization) paradigms, and offers many advantages for network operators, service providers and datacenter providers. Given the strong interest in both industry and academia in the softwarization of telecommunication networks and cloud computing infrastructures, a series of special section was established in IEEE Transactions on Network and Service Management, which aims at the timely publication of recent innovative research results on management of softwarized networks. Wolfgang Kellerer, Raouf Boutaba, Prosper Chemouil, Rafael Pasquini, Giovanni Schembra, Stefan Schmid 0001, Sandra Scott-Hayward, Kohei Shiomoto |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2018 | Event Detection in Wireless Body Area Networks Using Kalman Filter and Power DivergenceabstractThe collected data by biomedical sensors must be analyzed for automatic detection of physiological changes. The early identification of an event in collected data is required to trigger an alarm upon detection of patient health degradation. Such alarms inform healthcare professionals and allow them to quickly react by taking appropriate actions. However, events result from physiological change or faulty measurements, and lead to false alarms and unnecessary medical intervention. In this paper, we propose a framework for automatic detection of events from collected data by biomedical sensors. The proposed approach is based on the Kalman filter to forecast the current measurement and to derive the baseline of the time series. The power divergence is used to measure the distance between the forecasted and measured values. When a change occurs, this metric significantly deviates from past values. To distinguish emergency events from faulty measurements, we exploit the spatial correlation between the monitored attributes. We conduct experiments on real physiological data set and our results show that our proposed framework achieves a good detection accuracy with a low false alarm rate. Its simplicity and processing speed make our proposed framework efficient and effective for real-world deployment. Osman Salem, Ahmed Serhrouchni, Ahmed Mehaoua, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2017 | Delay-aware VNF placement and chaining based on a flexible resource allocation approachabstractNetwork Function Virtualization (NFV) is a promising technology that is receiving significant attention in both academia and the industry. NFV paradigm proposes to decouple Network Functions (NFs) from dedicated hardware equipment, offering a better sharing of physical resources and providing more flexibility to network operators. However, in such environment, efficient management mechanisms are crucial to address the problem of Placement and Chaining of Virtual Network Functions (PC-VNF). In this paper, we introduce a PC-VNF model based on a flexible resource allocation approach that takes into account service requirements in terms of latency, in addition to traditional connectivity and resource utilization. This is particularly important for emerging 5G services such as ultrareliable, low latency and massive machine type communications. The end-to-end performance needs to meet the user expectations as well as service requirements to provide the desired QoS/QoE. Our main goal is to determine the optimal VNF placement minimizing resource consumption while providing specific latency (i.e., end-to-end delay) and avoiding violation of Service Level Agreements (SLA) by constraining allocated resources to a given VNF to reach its required performance. Results show that our approach achieves the required latency with better resources utilization compared to the classical approaches, with a reduction of up to 40% of resource consumption and a higher rate of accepted requests by recovering 15 to 60 % of the rejected requests. Abdelhamid Alleg, Toufik Ahmed, Mohamed Mosbah 0001, Roberto Riggio, Raouf Boutaba |
CNSM | 5 |
| 2017 | NeuRoute: Predictive dynamic routing for software-defined networksabstractThis paper introduces NeuRoute, a dynamic routing framework for Software Defined Networks (SDN) entirely based on machine learning, specifically, Neural Networks. Current SDN/OpenFlow controllers use a default routing based on Dijkstra's algorithm for shortest paths, and provide APIs to develop custom routing applications. NeuRoute is a controller-agnostic dynamic routing framework that (i) predicts traffic matrix in real time, (ii) uses a neural network to learn traffic characteristics and (iii) generates forwarding rules accordingly to optimize the network throughput. NeuRoute achieves the same results as the most efficient dynamic routing heuristic but in much less execution time. Abdelhadi Azzouni, Raouf Boutaba, Guy Pujolle |
CNSM | 2 |
| 2017 | MULE: Multi-layer virtual network embeddingabstractNetwork Virtualization (NV), considered as a key enabler for overcoming the ossification of the Internet allows multiple heterogeneous virtual networks to co-exist over the same substrate network. Resource allocation problems in NV have been extensively studied for single layer substrates such as IP or Optical networks. However, little effort has been put to address the same problem for multi-layer IP-over-Optical networks. The increasing popularity of multi-layer networks for deploying backbones combined with their unique characteristics (e.g., topological flexibility of the IP layer) calls for the need to carefully investigate the resource provisioning problems arising from their virtualization. In this paper, we address the problem of MUlti-Layer virtual network Embedding (MULE) on IP-overOptical networks. We propose two solutions to MULE: an Integer Linear Program (ILP) formulation for the optimal solution and a heuristic to address the computational complexity of the optimal solution. We demonstrate through extensive simulations that on average our heuristic performs within ≈1.47 × of optimal solution and incurs ≈66% less cost than the state-of-the-art heuristic. Shihabur Rahman Chowdhury, Sara Ayoubi, Reaz Ahmed, Nashid Shahriar, Raouf Boutaba, Jeebak Mitra |
CNSM | 5 |
| 2017 | ReViNE: Reallocation of Virtual Network Embedding to eliminate substrate bottlenecksabstractPerceived as a key enabling technology for the future Internet, Network Virtualization (NV) allows an Infrastructure Provider (InP) to better utilize their Substrate Network (SN) by provisioning multiple Virtual Networks (VNs) from different Service Providers (SPs). A key challenge in NV is to efficiently map the VN requests from SPs on an SN, known as the Virtual Network Embedding (VNE) problem. VNE algorithms are typically online in nature. A VN embedding can become suboptimal over time due to the arrival and departure of other VNs as well as due to changes in SN such as failures. One way to mitigate the impact of such dynamism is to periodically reallocate resources for the existing VNs. VNE reallocation can increase an InP's revenue by decreasing bandwidth consumption and by increasing the possibility of accepting future VNs. In this paper, we study Reallocation of Virtual Network Embedding (ReViNE) problem to minimize the number of over utilized substrate links and total bandwidth cost on the SN. We propose an Integer Linear Programming formulation for the optimal solution (ReViNE-OPT) and a simulated annealing based heuristic (ReViNE-FAST) to solve larger problem instances. Simulation results show that on average our proposed heuristic performs within ∼19% of the optimal solution. Moreover, ReViNE-FAST generates more than 2.5× better solutions compared to the state-of-the-art simulated annealing based heuristic for VNE reallocation. Shihabur Rahman Chowdhury, Reaz Ahmed, Nashid Shahriar, Aimal Khan, Raouf Boutaba, Jeebak Mitra |
IM | 5 |
| 2017 | Toward avoiding energy holes in UnderWater Acoustic Sensor NetworksabstractUnderWater Acoustic Sensor Networks (UW-ASNs) require protocols that make judicious use of the limited energy budget of the underwater sensor nodes. In this paper, we tackle the problem of energy holes in UW-ASNs. We show that we can balance the energy consumption through the network provided that sensors can use multiple transmission ranges when they send or forward the periodically generated data. In particular, we suppose that sensors can adjust their communication ranges up to three possible levels and we determine the set of possible next hops with the associated load weights that lead to a fair energy consumption among all underwater sensors. Hence energy holes can be avoided and consequently the network lifetime is highly increased. Chaima Zidi, Fatma Bouabdallah, Raouf Boutaba, Ahmed Mehaoua |
IWCMC | 3 |
| 2017 | MC-UWMAC: A multi-channel MAC protocol for underwater sensor networksabstractFundamental differences between underwater acoustic propagation and terrestrial radio propagation impose the design of new networking protocols. In this paper, a multichannel MAC protocol, MC-UWMAC, especially designed for underwater acoustic sensor networks, is proposed and evaluated. MC-UWMAC is a low power MAC protocol operating on multichannel using a single slotted control channel and multiple data channels. To guarantee a collision free communication, MC-UWMAC uses a virtual grid based slot assignment linked with a quorum based data channel allocation. Specifically, control channel slots are dedicated for handshaking. Data transmission takes place in a unique data channel especially reserved for each communicating pair. Simulation results show that MC-UWMAC can greatly improve the network performance especially in terms of energy consumption, packet delivery ratio and end-to-end delay. Chaima Zidi, Fatma Bouabdallah, Raouf Boutaba, Ahmed Mehaoua |
WINCOM | 3 |
| 2017 | TCAM space-efficient routing in a software defined network
Sai Qian Zhang, Qi Zhang 0008, Ali Tizghadam, Byungchul Park, Hadi Bannazadeh, Raouf Boutaba, Alberto Leon-Garcia |
Comput. Networks | 6 |
| 2017 | An autonomous and efficient controller-based routing scheme for networking Named-Data mobility
Joao Vitor Torres, Igor D. Alvarenga, Raouf Boutaba, Otto Carlos M. B. Duarte |
Comput. Commun. | 3 |
| 2017 | Distributed Service Function ChainingabstractA service-function chain, or simply a chain, is an ordered sequence of service functions, e.g., firewalls and load balancers, composing a service. A chain deployment involvesselectingand instantiating a number of virtual network functions (VNFs), i.e., softwarized service functions,placingVNF instances, androutingtraffic through them. In the current optimization-models of a chain deployment, the instances of the same function are assumed to be identical, while typical service providers offer VNFs with heterogeneous throughput and resource configurations. The VNF instances of the same function are installed in a single physical machine, which limits a chain to the throughput of a few instances that can be installed in one physical machine. Furthermore, theselection,placement, androutingproblems are solved in isolation. We present distributed service function chaining that coordinates these operations, places VNF-instances of the same functiondistributedly, and selects appropriate instances from typical VNF offerings. Such a deployment uses network resources more efficiently and decouples a chain’s throughput from that of physical machines. We formulate this deployment as a mixed integer programming (MIP) model, prove its NP-Hardness, and develop a local search heuristic called Kariz. Extensive experiments demonstrate that Kariz achieves a competitive acceptance-ratio of 76%–100% with an extra cost of less than 24% compared with the MIP model. Milad Ghaznavi, Nashid Shahriar, Shahin Kamali, Reaz Ahmed, Raouf Boutaba |
IEEE J. Sel. Areas Commun. | 5 |
| 2017 | Joint Routing and Energy Management in UnderWater Acoustic Sensor NetworksabstractInterest in underwater acoustic sensor networks (UW-ASNs) has rapidly increased with the desire to control the large portion of the world covered by oceans. Fundamental differences between underwater acoustic propagation and terrestrial radio propagation may impose the design of new networking protocols and management schemes. In this paper, we focus on these fundamental differences in order to conceive a balanced routing strategy that overcomes the energy holes problem. Indeed, energy management is one of the major concerns in UW-ASNs due to the limited energy budget of the underwater sensor nodes. In this paper, we tackle the problem of energy holes in UW-ASNs while taking into consideration the unique characteristics of the underwater channel. The main contribution of this study is an in-depth analysis of the impact of these unique underwater characteristics on balancing the energy consumption among all underwater sensors. We prove that we can evenly distribute the transmission load among sensor nodes provided that sensors adjust their communication power when they send or forward the periodically generated data. In particular, we propose a balanced routing strategy along with the associated deployment pattern that meticulously determines the load weight for each possible next hop, that leads to fair energy consumption among all underwater sensors. Consequently, the energy holes problem is overcome and hence the network lifetime is improved. Fatma Bouabdallah, Chaima Zidi, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2017 | Topology-Aware Prediction of Virtual Network Function Resource RequirementsabstractNetwork functions virtualization (NFV) continues to gain attention as a paradigm shift in the way telecommunications services are deployed and managed. By separating network function from traditional middleboxes, NFV is expected to lead to reduced capital expenditure and operating expenditure, and to more agile services. However, one of the main challenges to achieving these objectives is how physical resources can be efficiently, autonomously, and dynamically allocated to virtualized network function (VNF) whose resource requirements ebb and flow. In this paper, we propose a graph neural network-based algorithm which exploits VNF forwarding graph topology information to predict future resource requirements for each VNF component (VNFC). The topology information of each VNFC is derived from combining its past resource utilization as well as the modeled effect on the same from VNFCs in its neighborhood. Our proposal has been evaluated using a deployment of a virtualized IP multimedia subsystem, and real VoIP traffic traces, with results showing an average prediction accuracy of 90%, compared to 85% obtained while using traditional feed-forward neural networks. Moreover, compared to a scenario where resources are allocated manually and/or statically, our technique reduces the average number of dropped calls by at least 27% and improves call setup latency by over 29%. Rashid Mijumbi, Sidhant Hasija, Steven Davy, Alan Davy, Brendan Jennings, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2017 | Analytical Model for Elastic Scaling of Cloud-Based FirewallsabstractThis paper shows how to properly achieve elasticity for network firewalls deployed in a cloud environment. Elasticity is the ability to adapt to workload changes by provisioning and de-provisioning resources in an autonomic manner, such that at each point in time the available resources match the current demand as closely as possible. Elasticity for cloud-based firewalls aims to satisfy an agreed-upon performance measure using only the minimal number of cloud firewall instances. Our contribution lies in determining the number of firewall instances that should be dynamically adjusted in accordance with the incoming traffic load and the targeted rules within the firewall rulebase. To do so, we develop an analytical model based on the principles of Markov chains and queueing theory. The model captures the behavior of a cloud-based firewall service comprising a load balancer and a variable number of virtual firewalls. From the analytical model, we then derive closed-form formulas to determine the minimal number of virtual firewalls required to meet the response time specified in the service level agreement. The model takes as input key system parameters including workload, processing capacity of load balancer and virtual machines, as well as the depth of the targeted firewall rules. We validate our model using discrete-event simulation, and real-world experiments conducted on Amazon Web Services cloud. We also provide numerical examples to show how our model can be used in practice by cloud performance/security engineers to achieve proper elasticity under fluctuating traffic load and variable depth of targeted firewall rules. Khaled Salah 0001, Prasad Calyam, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2017 | Generalized Recovery From Node Failure in Virtual Network EmbeddingabstractNetwork virtualization has evolved as a key enabling technology for offering the next generation network services. Recently, it is being rolled out in data center networks as a means to provide bandwidth guarantees to cloud applications. With increasing deployments of virtual networks (VNs) in commercial-grade networks with commodity hardware, VNs need to tackle failures in the underlying substrate network. In this paper, we study the problem of recovering a batch of VNs affected by a substrate node failure. The combinatorial possibilities of alternate embeddings of the failed virtual nodes and links of the VNs make the task of finding the most efficient recovery both non-trivial and intractable. Furthermore, any recovery approach ideally should not cause any service disruption for the unaffected parts of the VNs. We take into account these issues to design a generalized recovery approach that can achieve customized objectives such as fair treatment on the failed VNs, partial treatment based on priority, and so on. We provide integer linear programming (ILP) formulations for two variants of our recovery scheme, namely, fair recovery model and priority-based recovery model. We also propose a fast and scalable heuristic algorithm to tackle the computational complexity of the ILP solution. Evaluation results demonstrate that our heuristic performs close to the optimal solution and outperforms the state-of-the-art algorithm. Nashid Shahriar, Reaz Ahmed, Shihabur Rahman Chowdhury, Aimal Khan, Raouf Boutaba, Jeebak Mitra |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2017 | Guest Editors' Introduction: Special Issue on Advances in Management of Softwarized NetworksabstractSoftwarization of networks is an important trend, enabled by the NV (Network Virtualization), SDN (Software-Defined Networking), and NFV (Network Function Virtualization) paradigms and offers many advantages for network operators, service providers and datacenter providers. Given the strong interest in both industry and academia in the softwarization of telecommunication networks and cloud computing infrastructures, a series of special issues was established in IEEE Transactions on Network and Service Management, which aims at the timely publication of recent innovative research results on management of softwarized networks. Filip De Turck, Prosper Chemouil, Wolfgang Kellerer, Raouf Boutaba, Kohei Shiomoto, Roberto Riggio, Rafael Pasquini |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2016 | A connectionist approach to dynamic resource management for virtualised network functionsabstractNetwork Functions Virtualisation (NFV) continues to gain attention as a paradigm shift in the way telecommunications services are deployed and managed. By separating Network Functions (NFs) from traditional middleboxes, NFV is expected to lead to reduced CAPEX and OPEX, and to more agile services. However, one of the main challenges to achieving these objectives is on how physical resources can be efficiently, autonomously, and dynamically allocated to Virtualised Network Functions (VNFs) whose resource requirements ebb and flow. In this paper, we propose a Graph Neural Network (GNN)-based algorithm which exploits Virtual Network Function Forwarding Graph (VNF-FG) topology information to predict future resource requirements for each Virtual Network Function Component (VNFC). The topology information of each VNFC is derived from combining its past resource utilisation as well as the modelled effect on the same from VNFCs in its neighbourhood. Our proposal has been evaluated using a deployment of a virtualised IP Multimedia Subsystem (IMS), and real VoIP traffic traces, with results showing an average prediction accuracy of 90%. Moreover, compared to a scenario where resources are allocated manually and/or statically, our proposal reduces the average number of dropped calls by at least 27% and improves call setup latency by over 29%. Rashid Mijumbi, Sidhant Hasija, Steven Davy, Alan Davy, Brendan Jennings, Raouf Boutaba |
CNSM | 6 |
| 2016 | Emulating an infrastructure with EASEabstractIn the last decade we have observed a tremendous adoption of distributed applications and a trend to host services in private or public clouds. However, service providers still need to own an infrastructure to test their applications or services. A similar problem is faced by network operators when they want to introduce a new service in their production network. It is very difficult to determine the behavior of a new application or service without deploying it in the production environment. Bugs or misconfiguration can cause service outage and trigger customer churn along with loss of reputation. There are several publicly available testbeds such as Emulab, GENI or OFELIA that allow users to lease physical and virtual resources for emulation. However, these testbeds do not provide performance guarantee. Acquisition of physical instances provides performance guarantee and isolation, but compromises overall system utilization. On the other hand, acquisition of virtualized instances lack guarantee and isolation resulting in an unrealistic emulation outcome. To address these limitations, we propose EASE, a next generation multi-tenant infrastructure emulator with an aim to maximize hardware utilization while providing performance guarantee, isolation and full-fledged support for SDN and NFV. Arup Raton Roy, Shihabur Rahman Chowdhury, Md. Faizul Bari, Reaz Ahmed, Raouf Boutaba |
CNSM | 5 |
| 2016 | ReNoVatE: Recovery from node failure in virtual network embeddingabstractNetwork visualization (NV) has evolved as a key enabling technology for offering the next generation network services. Recently, it is being rolled out in data center networks as a means to provide bandwidth guarantees to cloud applications. With increasing deployments of virtual networks (VNs) in commercial-grade networks with commodity hardware, VNs need to tackle failures in the underlying substrate network. In this paper, we study the problem of recovering a batch of VNs affected by a substrate node failure. The combinatorial possibilities of alternate embeddings of the failed virtual nodes and links of the VNs makes the task of finding the most efficient recovery both non-trivial and intractable. Furthermore, any recovery approach ideally should not cause any service disruption for the unaffected parts of the VNs. We take into account these issues to design a recovery approach for maximizing recovery and minimizing the cost of recovery and network disruption. We provide an Integer Linear Programming (ILP) formulation of our recovery scheme. We also propose a fast and scalable heuristic algorithm to tackle the computational complexity of the ILP solution. Evaluation results demonstrate that our heuristic performs close to the optimal solution and outperforms the state-of-the-art algorithm. Nashid Shahriar, Reaz Ahmed, Aimal Khan, Shihabur Rahman Chowdhury, Raouf Boutaba, Jeebak Mitra |
CNSM | 5 |
| 2016 | Fingerprinting OpenFlow Controllers: The First Step to Attack an SDN Control PlaneabstractSoftware-Defined Networking (SDN) controllers are considered as Network Operating Systems (NOSs) and often viewed as a single point of failure. Detecting which SDN controller is managing a target network is a big step for an attacker to launch specific/effective attacks against it. In this paper, we demonstrate the feasibility of fingerpirinting SDN controllers. We propose techniques allowing an attacker placed in the data plane, which is supposed to be physically separate from the control plane, to detect which controller is managing the network. To the best of our knowledge, this is the first work on fingerprinting SDN controllers, with as primary goal to emphasize the necessity to highly secure the controller. We focus on OpenFlow-based SDN networks since OpenFlow is currently the most deployed SDN technology by hardware and software vendors. Abdelhadi Azzouni, Othmen Braham, Thi Mai Trang Nguyen, Guy Pujolle, Raouf Boutaba |
GLOBECOM | 5 |
| 2016 | Virtual network embedding in software-defined networksabstractResearch on network virtualization has been active for a number of years, during which a number of virtual network embedding (VNE) approaches have been proposed. These approaches, however, neglect important operational requirements imposed by the underlying virtualization platforms. In the case of SDN/OpenFlow-based virtualization, a crucial example of an operational requirement is the availability of enough memory space for storing flow rules in OpenFlow devices. In this paper, we advocate that VNE must be performed with some knowledge of the underlying physical networks, otherwise the deployment may suffer from unpredictable or even unsatisfactory performance. Considering SDN/OpenFlow-based physical networks as an important virtualization scenario, we propose an approach based on VNE and OpenFlow coordination for proper deployment of virtual networks (VNs). The proposed approach unfolds in the following main contributions: (i) a virtual infrastructure abstraction that allows a service provider to represent the details of his/her VN requirements in a comprehensive manner; (ii) a privacy-aware compiler that is able to preprocess this detailed VN request in order to obfuscate sensitive information and derive computable operational requirements; and (iii) a model for embedding requested VNs ensuring their feasibility at the physical level. The results obtained through our evaluation demonstrate that taking such operational requirements into account, as well as accurately assessing them, is of paramount importance to ensure the correct behavior of VNs hosted on top of the virtualization platform. Leonardo Richter Bays, Luciano Paschoal Gaspary, Reaz Ahmed, Raouf Boutaba |
NOMS | 4 |
| 2016 | Protecting virtual networks with DRONEabstractNetwork virtualization is enabling infrastructure providers (InPs) to offer new services to higher level service providers (SPs). InPs are usually bound by Service Level Agreements (SLAs) to ensure various levels of resource availability for different SPs' virtual networks (VNs). They provision redundant backup resources while embedding an SP's VN request to conform to the SLAs during physical failures in the infrastructure. An extreme of this backup resource provisioning is to reserve a dedicated backup of each element in an SP's VN request. Such dedicated protection scheme can enable an InP to ensure fast VN recovery, thus, providing high uptime guarantee to the SPs. In this paper, we study the 1 + 1-Protected Virtual Network Embedding (1 + 1-ProViNE) problem. We propose Dedicated Protection for Virtual Network Embedding (DRONE), a suite of solutions to the 1 + 1-ProViNE. DRONE includes an Integer Linear Programming (ILP) formulation for optimal solution (OPT-DRONE) and a heuristic (FAST-DRONE) to tackle the computational complexity in computing the optimal solution. Trace driven simulations show that FAST-DRONE allocates only 14.3% extra backup resources on average compared to the optimal solution, while executing 200-12000x faster. Shihabur Rahman Chowdhury, Reaz Ahmed, Md Mashrur Alam Khan, Nashid Shahriar, Raouf Boutaba, Jeebak Mitra |
NOMS | 5 |
| 2016 | Block Negative Acknowledgement protocol for reliable multicast in IEEE 802.11
Yousri Daldoul, Djamal-Eddine Meddour, Toufik Ahmed, Raouf Boutaba |
J. Netw. Comput. Appl. | 4 |
| 2016 | Dynamic Resource Allocation for MapReduce with Partitioning SkewabstractMapReduce has become a prevalent programming model for building data processing applications in the cloud. While being widely used, existing MapReduce schedulers still suffer from an issue known as partitioning skew, where the output of map tasks is unevenly distributed among reduce tasks. Existing solutions follow a similar principle that repartitions workload among reduce tasks. However, those approaches often incur high performance overhead due to the partition size prediction and repartitioning. In this paper, we present DREAMS, a framework that provides run-time partitioning skew mitigation. Instead of repartitioning workload among reduce tasks, we cope with the partitioning skew problem by controlling the amount of resources allocated to each reduce task. Our approach completely eliminates the repartitioning overhead, yet is simple to implement. Experiments using both real and synthetic workloads running on a 21-node Hadoop cluster demonstrate that DREAMS can effectively mitigate the negative impact of partitioning skew, thereby improving the job completion time by up to a factor of$2.29$over the native Hadoop YARN. Compared to the state-of-the-art solution, DREAMS can improve the job completion time by a factor of$1.65$. Qi Zhang 0008, Reaz Ahmed, Raouf Boutaba, Zhenghu Gong |
IEEE Trans. Computers | 4 |
| 2016 | Orchestrating Virtualized Network FunctionsabstractMiddleboxes or network appliances like firewalls, proxies, and WAN optimizers have become an integral part of today's ISP and enterprise networks. Middlebox functionalities are usually deployed on expensive and proprietary hardware that require trained personnel for deployment and maintenance. Middleboxes contribute significantly to a network's capital and operation costs. In addition, organizations often require their traffic to pass through a specific sequence of middleboxes for compliance with security and performance policies. This makes the middlebox deployment and maintenance tasks even more complicated. Network function virtualization (NFV) is an emerging and promising technology that is envisioned to overcome these challenges. It proposes to move packet processing from dedicated hardware middleboxes to software running on commodity servers. In NFV terminology, software middleboxes are referred to as virtualized network functions (VNFs). It is a challenging problem to determine the required number and placement of VNFs that optimizes network operational costs and utilization, without violating service level agreements. We call this the VNF orchestration problem (VNF-OP) and provide an integer linear programming formulation with implementation in CPLEX. We also provide a dynamic programming-based heuristic to solve larger instances of VNF-OP. Trace driven simulations on realworld network topologies demonstrate that the heuristic can provide solutions that are within 1.3 times of the optimal solution. Our experiments suggest that a VNF-based approach can provide more than 4× reduction in the operational cost of a network. Md. Faizul Bari, Shihabur Rahman Chowdhury, Reaz Ahmed, Raouf Boutaba, Otto Carlos M. B. Duarte |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2016 | Dedicated Protection for Survivable Virtual Network EmbeddingabstractNetwork virtualization is enabling infrastructure providers (InPs) to offer new services to service providers (SPs). InPs are usually bound by service level agreements to ensure various levels of resource availability for different SPs' virtual networks (VNs). They provision redundant backup resources while embedding an SP's VN request to conform to the SLAs during physical failures in the infrastructure. An extreme backup resource provisioning is to reserve a mutually exclusive backup of each element in an SP's VN request. Such dedicated protection scheme can enable an InP to ensure fast VN recovery, thus, providing high uptime guarantee to the SPs. In this paper, we study the 1 + 1-Protected Virtual Network Embedding (1 + 1-ProViNE) problem. We propose Dedicated Protection for Virtual Network Embedding (DRONE), a suite of solutions to the 1 + 1-ProViNE problem. DRONE includes an integer linear programming formulation for optimal solution (OPT-DRONE) and a heuristic (FAST-DRONE) to tackle the computational complexity of the optimal solution. Trace driven simulations show that FAST-DRONE allocates only 14.3% extra backup resources on average compared to the optimal solution, while executing 200-1200 times faster. Simulation results also show that FAST-DRONE can accept four times more VN requests on average compared to the state-of-the-art solution for providing dedicated protection to VNs. Shihabur Rahman Chowdhury, Reaz Ahmed, Md Mashrur Alam Khan, Nashid Shahriar, Raouf Boutaba, Jeebak Mitra |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2016 | Multi-Path Link Embedding for Survivability in Virtual NetworksabstractInternet applications are deployed on the same network infrastructure, yet they have diverse performance and functional requirements. The Internet was not originally designed to support the diversity of current applications. Network virtualization enables heterogeneous applications and network architectures to coexist without interference on the same infrastructure. Embedding a virtual network (VN) into a physical network is a fundamental problem in network virtualization. A VN embedding that aims to survive physical (e.g., link) failures is known as the survivable VN embedding (SVNE). A key challenge in the SVNE problem is to ensure VN survivability with minimal resource redundancy. To address this challenge, we propose survivability in multi-path link embedding (SiMPLE). By exploiting path diversity in the physical network, SiMPLE provides guaranteed VN survivability against single link failure while incurring minimal resource redundancy. In case of multiple arbitrary link failures, SiMPLE provides maximal survivability to the VNs. We formulate this problem as an integer linear program and implement it using GNU linear programming kit. We propose a greedy proactive approach to solve larger instances of the problem in case of single link failures. In presence of more than one link failures, we propose a greedy reactive algorithm as an extension to the previous one, which opportunistically recovers the lost bandwidth in the VNs. Simulation results show that SiMPLE outperforms full backup and shared backup schemes for SVNE, and produces near-optimal results. Md Mashrur Alam Khan, Nashid Shahriar, Reaz Ahmed, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2016 | Guest Editors' Introduction: Special Issue on Management of Softwarized NetworksabstractThere is currently a strong interest in both industry and academia in the softwarization of telecommunication networks and cloud computing infrastructures. This evolution is enabled by three paradigms. First, Software-Defined Networking (SDN) allows network control to be separated from the forwarding plane and allows for a flexible management of the network resources. Second, Network Virtualization (NV) brings virtualization concepts to the network, similar to cloud computing, which was enabled by virtualization of servers. Third, Network Function Virtualization (NFV) focuses on virtualization of software-based network functions. Instead of installing and managing dedicated hardware devices for these functions, they are implemented as software components and deployed on commodity hardware infrastructures, in most cases operated by a network operator or cloud infrastructure provider. Service Function Chaining (SFC) consists of building services using virtual network functions (VNFs). These three paradigms are synergetic and reinforce each other when used together. Several initial SDN, NV and NFV deployments are already operational in providers’ networks. Filip De Turck, Prosper Chemouil, Raouf Boutaba, Minlan Yu, Christian Esteve Rothenberg, Kohei Shiomoto |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2016 | αRoute: Routing on NamesabstractOne of the crucial building blocks for Information Centric Networking ICN is a name based routing scheme that can route directly on content names instead of IP addresses. However, moving the address space from IP addresses to content names brings the scalability issues to a whole new level, due to two reasons. First, name aggregation is not as trivial a task as the IP address aggregation in BGP routing. Second, the number of addressable contents in the Internet is several orders of magnitude higher than the number of IP addresses. With the current size of the Internet, name based, anycast routing is very challenging specially when routing efficiency is of prime importance. We propose a name-based routing scheme αRoute for ICN that offers efficient bandwidth usage, guaranteed content lookup and scalable routing table size. αRoute consists of two components: an alphanumeric Distributed Hash Table DHT and an overlay to underlay Internet topology mapping algorithm. Simulation results show that αRoute performs significantly better than Content Centric Network CCN in terms of network bandwidth usage, lookup latency and load balancing. Reaz Ahmed, Md. Faizul Bari, Shihabur Rahman Chowdhury, Md. Golam Rabbani, Raouf Boutaba, Bertrand Mathieu |
IEEE/ACM Trans. Netw. | 5 |
| 2016 | Performance and scalability evaluation of IEEE 802.11v/aa multicast transportabstractAbstract IEEE 802.11v and 802.11aa are two recent amendments that define new functionalities in order to support a reliable multicast transport over wireless networks. The first amendment introduces directed multicast service (DMS). On the other hand, 802.11aa defines the groupcast with retries (GCR) service, which proposes two retransmission policies: block acknowledgement (GCR‐BACK) and unsolicited retry (GCR‐UR). In this paper, we evaluate the throughput and the scalability of these new proposals using both analytical and simulation approaches. We show that DMS has the lowest scalability, while GCR‐BACK is not appropriate for groups with a large number of receivers. We conclude that GCR‐UR is the most appropriate for large groups. However, increasing the number of transmission retries reduces significantly the achieved throughput of the unsolicited retry policy. Copyright © 2016 John Wiley & Sons, Ltd. Yousri Daldoul, Djamal-Eddine Meddour, Toufik Ahmed, Raouf Boutaba |
Wirel. Commun. Mob. Comput. | 4 |
| 2016 | Routing design avoiding energy holes in underwater acoustic sensor networksabstractAbstract Interest in underwater acoustic sensor networks (UW‐ASNs) has rapidly increased with the desire to control the large portion of the world covered by oceans. Energy efficiency is one of the major concerns in UW‐ASNs due to the limited energy budget of the underwater sensor nodes. In this paper, we tackle the problem of energy holes in UW‐ASNs while taking into consideration the unique characteristics of the underwater channel. We prove that we can evenly distribute the transmission load among sensor nodes provided that sensors adjust their communication range when they send or forward the periodically generated data. In particular, we propose a balanced routing strategy along with the associated deployment pattern that meticulously determines the load weight for each possible next hop that leads to fair energy consumption among all underwater sensors. Consequently, the energy holes problem is overcome, and hence, the network lifetime is improved. To the best of our knowledge, this is the first work that addresses the energy hole problem in UW‐ASNs. Copyright © 2016 John Wiley & Sons, Ltd. Chaima Zidi, Fatma Bouabdallah, Raouf Boutaba |
Wirel. Commun. Mob. Comput. | 3 |
| 2015 | On orchestrating virtual network functionsabstractMiddleboxes or network appliances like firewalls, proxies, and WAN optimizers have become an integral part of today's ISP and enterprise networks. Middlebox functionalities are usually deployed on expensive and proprietary hardware that require trained personnel for deployment and maintenance. Middleboxes contribute significantly to a network's capital and operational costs. In addition, organizations often require their traffic to pass through a specific sequence of middleboxes for compliance with security and performance policies. This makes the middlebox deployment and maintenance tasks even more complicated. Network Function Virtualization (NFV) is an emerging and promising technology that is envisioned to overcome these challenges. It proposes to move packet processing from dedicated hardware middleboxes to software running on commodity servers. In NFV terminology, software middleboxes are referred to as Virtual Network Functions (VNFs). It is a challenging problem to determine the required number and placement of VNFs that optimize network operational costs and utilization, without violating service level agreements. We call this the VNF Orchestration Problem (VNF-OP) and provide an Integer Linear Programming (ILP) formulation with implementation in CPLEX. We also provide a dynamic programming based heuristic to solve larger instances of VNF-OP. Trace driven simulations on real-world network topologies demonstrate that the heuristic can provide solutions that are within 1.3 times of the optimal solution. Our experiments suggest that a VNF based approach can provide more than 4 χ reduction in the operational cost of a network. Md. Faizul Bari, Shihabur Rahman Chowdhury, Reaz Ahmed, Raouf Boutaba |
CNSM | 4 |
| 2015 | SiMPLE: Survivability in multi-path link embeddingabstractInternet applications are deployed on the same network infrastructure, yet they have diverse performance and functional requirements. The Internet was not originally designed to support the diversity of current applications. Network Virtualization can enable heterogeneous applications and network architectures to coexist without interference on the same infrastructure. Embedding a Virtual Network (VN) into a physical network is a fundamental problem in Network Virtualization. A VN Embedding that aims to survive physical (e.g., link) failures is known as the Survivable Virtual Network Embedding (SVNE). A key challenge in the SVNE problem is to ensure VN survivability with minimal resource redundancy. To address this challenge, we propose SiMPLE. By exploiting path diversity in the physical network, SiMPLE provides guaranteed VN survivability against single link failure. In addition, SiMPLE produces highly surviv-able VN embeddings in presence of multiple link failures while incurring very low resource redundancy. We provide an ILP formulation for this problem and implement it using GLPK. We also propose a greedy algorithm to solve larger instances of the problem. Simulation results show that our solution outperforms full backup and shared backup schemes for SVNE, and produces near-optimal results. Md Mashrur Alam Khan, Nashid Shahriar, Reaz Ahmed, Raouf Boutaba |
CNSM | 4 |
| 2015 | IoNCloud: Exploring application affinity to improve utilization and predictability in datacentersabstractThe intra-cloud network is typically shared in a best-effort manner, which causes tenant applications to have no actual bandwidth guarantees. Recent proposals address this issue either by statically reserving a slice of the physical infrastructure for each application or by providing proportional sharing among flows. The former approach results in overprovisioned network resources, while the latter requires substantial management overhead. In this paper, we introduce a resource allocation strategy that aims at providing an efficient way to predictably share bandwidth among applications and at minimizing resource underutilization while maintaining low management overhead. To demonstrate the benefits of the strategy, we develop IoNCloud, a system that implements the proposed allocation scheme. IoNCloud employs the abstraction of attraction/repulsion among applications according to their temporal bandwidth demands in order to group them in virtual networks. In doing so, we explore the trade-off between high resource utilization (which is desired by providers to achieve economies of scale) and strict network guarantees (necessary for tenants to run jobs predictably). Evaluation results show that IoNCloud can (a) provide predictable network sharing; and (b) reduce allocated bandwidth, resource underutilization and management overhead when compared against state-of-the-art proposals. Daniel S. Marcon, Miguel C. Neves, Rodrigo Ruas Oliveira, Leonardo Richter Bays, Raouf Boutaba, Luciano Paschoal Gaspary, Marinho P. Barcellos |
ICC | 5 |
| 2015 | Aurora: Adaptive Block Replication in Distributed File SystemsabstractDistributed file systems such as Google File System and Hadoop Distributed File System have been used to store large volumes of data in Cloud data centers. These systems divide data sets in blocks of fixed size and replicate them over multiple machines to achieve both reliability and efficiency. Recent studies have shown that data blocks tend to have a wide disparity in data popularity. In this context, the naive block replication schemes used by these systems often cause an uneven load distribution across machines, which reduces the overall I/O throughput of the system. While many replication algorithms have been proposed, existing solutions have not carefully studied the placement of data blocks that balances the load across machines, while ensuring node and rack-level reliability requirements are satisfied. In this paper, we study the dynamic data replication problem with the goal of balancing machine load while ensuring machine and rack-level reliability requirements are met. We propose several local search algorithms that provide constant approximation guarantees, yet simple and practical for implementation. We further present Aurora, a dynamic block placement mechanism that implements these algorithms in the Hadoop Distributed File System with minimal overhead. Through experiments using workload traces from Yahoo! and Facebook, we show Aurora reduces machine load imbalance by up to 26.9% compared to existing solutions, while satisfying node and rack-level reliability requirements. Qi Zhang 0008, Sai Qian Zhang, Alberto Leon-Garcia, Raouf Boutaba |
ICDCS | 4 |
| 2015 | FSM-based Wi-Fi power estimation method for smart devicesabstractWith the increased popularity of mobile data applications, Wi-Fi power consumption on smartphones is now a significant portion of mobile energy expenditure. In their efforts to develop more energy efficient applications, the applications developers use energy estimation tools as a benchmark. Although hardware based power meter has high estimation accuracy, it is cumbersome to operate as it relies on physically attaching wires to the battery, and moreover the price of hardware based power meter is expensive. Therefore software based power estimation tools such as PowerTutor are popular. In our prior research using PowerTutor as power meter, we discovered that PowerTutor has large Wi-Fi power estimation error (over 1000%) on post 2012 phones. In this work, we propose a new FSM-based Wi-Fi power model based on IEEE 802.11 communication patterns and Wi-Fi hardware configuration with significantly increased power estimation accuracy. We designed and implemented our power model as an estimation tool called PowerGuide. Our experiments with PowerGuide in field operations showed that PowerGuide can achieve an average estimation accuracy of 86% compared to hardware power meters even with moderate polling period. Jian Li 0024, Jin Xiao 0005, James Won-Ki Hong, Raouf Boutaba |
IM | 4 |
| 2015 | DREAMS: Dynamic resource allocation for MapReduce with data skewabstractMapReduce has become a popular model for large-scale data processing in recent years. However, existing MapRe-duce schedulers still suffer from an issue known as partitioning skew, where the output of map tasks is unevenly distributed among reduce tasks. In this paper, we present DREAMS, a framework that provides run-time partitioning skew mitigation. Unlike previous approaches that try to balance the workload of reducers by repartitioning the intermediate data assigned to each reduce task, in DREAMS we cope with partitioning skew by adjusting task run-time resource allocation. We show that our approach allows DREAMS to eliminate the overhead of data repartitioning. Through experiments using both real and synthetic workloads running on a 11-node virtual virtualised Hadoop cluster, we show that DREAMS can effectively mitigate negative impact of partitioning skew, thereby improving job performance by up to 20.3%. Qi Zhang 0008, Mohamed Faten Zhani, Raouf Boutaba, Zhenghu Gong |
IM | 4 |
| 2015 | URL forwarding for NAT traversalabstractRapid technological advancement has induced widespread adoption of smart, powerful and multi-purpose enduser devices (e.g., phones, tablets, set-top boxes, gaming console etc.) in our daily life. Unfortunately, the available mechanisms for accessing, configuring and controlling these devices are still primitive, and require physical access to the devices. Enabling remote access to these devices through a widely used protocol, such as HTTP, can significantly improve their usability and can foster innovative applications. However, the end-devices are often NATed by home gateways, which is not suitable for HTTP access over the Internet. In this work, we present a mechanism for seamless traversal of HTTP traffic through home gateways. Our approach builds upon the existing Web-technology. It allows remote access using global DNS names, despite the end-devices having local IPs. As a proof of concept, we realize the proposed architecture on the well-accepted OpenWRT platform, and report experimental results on device access performance. Md. Ahsan Raza, Reaz Ahmed, Raouf Boutaba |
IM | 3 |
| 2015 | NetSoft 2015 - ForewordabstractOn behalf of the Organizing and Technical Program Committees, we are pleased to welcome you to the inaugural conference on IEEE Network Softwarization (NetSoft 2015), in London, UK, April 13–17, 2015. Prosper Chemouil, George Pavlou, Raouf Boutaba, Alex Galis |
NetSoft | 3 |
| 2015 | nf.io: A File System Abstraction for NFV OrchestrationabstractNo abstract available. Md. Faizul Bari, Shihabur Rahman Chowdhury, Reaz Ahmed, Raouf Boutaba |
SIGCOMM | 4 |
| 2015 | Cloud networking and communications IIabstractMade available in DSpace on 2016-06-07T13:36:10Z (GMT). No. of bitstreams: 1 wos_000367123300001.pdf: 410004 bytes, checksum: 6de6b0e120e3cfc1bb14dcf5e725aa36 (MD5) Previous issue date: 2015 Raouf Boutaba, Nelson L. S. da Fonseca, Dzmitry Kliazovich, Noura Limam |
Comput. Networks | 1 |
| 2015 | Impact of device unavailability on the reliability of multicast transport in IEEE 802.11 networks
Yousri Daldoul, Djamal-Eddine Meddour, Toufik Ahmed, Raouf Boutaba |
Comput. Networks | 4 |
| 2015 | Special Issue: Interactive Multimedia Convergence
Jong-Hun Kim, Raouf Boutaba, Junseok Yoo |
Multim. Tools Appl. | 2 |
| 2015 | PRISM: Fine-Grained Resource-Aware Scheduling for MapReduceabstractMapReduce has become a popular model for data-intensive computation in recent years. By breaking down each job into small map and reduce tasks and executing them in parallel across a large number of machines, MapReduce can significantly reduce the running time of data-intensive jobs. However, despite recent efforts toward designing resource-efficient MapReduce schedulers, existing solutions that focus on scheduling at the task-level still offer sub-optimal job performance. This is because tasks can have highly varying resource requirements during their lifetime, which makes it difficult for task-level schedulers to effectively utilize available resources to reduce job execution time. To address this limitation, we introduce PRISM, a fine-grained resource-aware MapReduce scheduler that divides tasks into phases, where each phase has a constant resource usage profile, and performs scheduling at the phase level. We first demonstrate the importance of phase-level scheduling by showing the resource usage variability within the lifetime of a task using a wide-range of MapReduce jobs. We then present a phase-level scheduling algorithm that improves execution parallelism and resource utilization without introducing stragglers. In a 10-node Hadoop cluster running standard benchmarks, PRISM offers high resource utilization and provides 1.3× improvement in job running time compared to the current Hadoop schedulers. Qi Zhang 0008, Mohamed Faten Zhani, Yuke Yang, Raouf Boutaba, Bernard Wong 0001 |
IEEE Trans. Cloud Comput. | 4 |
| 2015 | An Operations Research Game Approach for Resource and Power Allocation in Cooperative Femtocell NetworksabstractFemtocells are emerging as a key technology to improve coverage and network capacity in indoor environments. When femtocells use different frequency bands than macrocells (i.e., split-spectrum approach), femto-to-femto interference remains the major issue. In particular, congestion cases in which femtocell demands exceed the available resources raise several challenging questions: how much a femtocell can demand? how much it can obtain? and how this shall depends on the interference with its neighbors? Strategic interference management between femtocells via power control and resource allocation mechanisms is needed to avoid performance degradation during congestion cases. In this paper, we model the resource and power allocation problem as an operations research game, where imputations are deduced from cooperative game theory, namely the Shapley value and the Nucleolus, using utility components results of partial optimizations. Based on these evaluations, users' demands are first rescaled to strategically justified values. Then, a power-level and throughput optimization using the rescaled demands is conducted. The performance of the developed solutions is analyzed and extensive simulation results are presented to illustrate their potential advantages. In particular, we show that the Shapley value solution with power control offers the overall best performance in terms of throughput, fairness, spectrum spatial reuse, and transmit power, with a slightly higher time complexity compared to alternative solutions. Rami Langar, Stefano Secci, Raouf Boutaba, Guy Pujolle |
IEEE Trans. Mob. Comput. | 3 |
| 2015 | Flow-Based Management For Energy Efficient Campus NetworksabstractRecent studies have shown that the energy consumption of wireless access networks is a threat to the sustainability of mobile cloud services. Consequently, energy efficient solutions are becoming crucial for both local and wireless access networks. In this paper, we propose a flow-based management framework to achieve energy efficiency in campus networks. We address the problem from the dynamic perspective, where users come and leave the system in an unpredictable way. Specifically, we propose an online flow-based routing approach that allows dynamic reconfiguration of existing flows as well as dynamic link rate adaptation, while taking into account users' demands and mobility. Our approach is compliant with the emerging software defined networking (SDN) paradigm since it can be integrated as an application on top of an SDN controller. To achieve this, we first formulate the flow-based routing problem as an integer linear program (ILP). As this problem is known to be NP-hard, we then propose a simple yet efficient ant colony-based approach to solve the formulated ILP. Through extensive simulations, we show that our proposed approach is able to achieve significant gains in terms of energy consumption, compared to heuristic solutions and conventional routing solutions such as the shortest path (SP) routing, the minimum link residual capacity routing metric (MRC), and the load balancing (LB) scheme. In particular, we show that the energy consumption can be reduced by up to 7%, 35%, 44%, and 49% compared to Greedy-OFER, MRC, SP, and LB, respectively, while ensuring the required quality of service (QoS). Ahmed Amokrane, Rami Langar, Raouf Boutaba, Guy Pujolle |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2015 | Greenslater: On Satisfying Green SLAs in Distributed CloudsabstractWith the massive adoption of cloud-based services, high energy consumption and carbon footprint of cloud infrastructures have become a major concern in the IT industry. Consequently, many governments and IT advisory organizations have urged IT stakeholders (i.e., cloud provider and cloud customers) to embrace green IT and regularly monitor and report their carbon emissions and put in place efficient strategies and techniques to control the environmental impact of their infrastructures and/or applications. Motivated by this growing trend, we investigate, in this paper, how cloud providers can meet Service Level Agreements (SLAs) with green requirements. In such SLAs, a cloud customer requires from cloud providers that carbon emissions generated by the leased resources should not exceed a fixed bound. We hence propose a resource management framework allowing cloud providers to provision resources in the form of Virtual Data Centers (VDCs) (i.e., a set of virtual machines and virtual links with guaranteed bandwidth) across a geo-distributed infrastructure with the aim of reducing operational costs and green SLA violation penalties. Extensive simulations show that the proposed solution maximizes the cloud provider's profit and minimizes the violation of green SLAs. Ahmed Amokrane, Rami Langar, Mohamed Faten Zhani, Raouf Boutaba, Guy Pujolle |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2015 | A Path Generation Approach to Embedding of Virtual NetworksabstractAs the virtualization of networks continues to attract attention from both industry and academia, the virtual network embedding (VNE) problem remains a focus of researchers. This paper proposes a one-shot, unsplittable flow VNE solution based on column generation. We start by formulating the problem as a path-based mathematical program called the primal, for which we derive the corresponding dual problem. We then propose an initial solution which is used, first, by the dual problem and then by the primal problem to obtain a final solution. Unlike most approaches, our focus is not only on embedding accuracy but also on the scalability of the solution. In particular, the one-shot nature of our formulation ensures embedding accuracy, while the use of column generation is aimed at enhancing the computation time to make the approach more scalable. In order to assess the performance of the proposed solution, we compare it against four state of the art approaches as well as the optimal link-based formulation of the one-shot embedding problem. Experiments on a large mix of virtual network (VN) requests show that our solution is near optimal (achieving about 95% of the acceptance ratio of the optimal solution), with a clear improvement over existing approaches in terms of VN acceptance ratio and average substrate network (SN) resource utilization, and a considerable improvement (92% for a SN of 50 nodes) in time complexity compared to the optimal solution. Rashid Mijumbi, Joan Serrat 0001, Juan-Luis Gorricho, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2015 | Guest Editors' Introduction: Special Issue on Efficient Management of SDN/NFV-Based Systems - Part IabstractThe articles in this special section focus on the evolution of software defined networking; network virtualization; and network function virtualization. Filip De Turck, Raouf Boutaba, Prosper Chemouil, Jun Bi, Cédric Westphal |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2015 | Guest Editors' Introduction: Special issue on efficient management of SDN/NFV-based systems - Part IIabstractIn Part I of the special issue, the main reported research contributions were: efficient resource allocation and management of softwarized network functions, design of highperformance platforms to allow network function virtualization on commodity machines, and enabling efficient collaboration between providers in softwarized networks. From the twenty six submitted papers, four papers had been selected for Part I of the special issue. An additional set of four more papers have been accepted for this Part II, after a thorough revision by the authors to take into account the detailed comments from the reviewers. The four selected papers in Part II of the special address three very important topics for the efficient management of Software-Defined Networking/Virtualized Network Functions-based (SDN/NFV-based) telecommunication systems: (i) optimizations to flow-based software-defined networks to address the scalability and energy consolidation requirements, (ii) programming abstractions in wireless software-defined networks, and (iii) improved network virtualization to more efficiently support latency sensitive applications. Filip De Turck, Raouf Boutaba, Prosper Chemouil, Jun Bi, Cédric Westphal |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2015 | Joint Optimization for the Delivery of Multiple Video Channels in Telco-CDNsabstractThe delivery of live video channels for services such as twitch.tv leverages the so-called Telco-CDN-Content Delivery Network (CDN) deployed within the Internet Service Provider (ISP) domain. A Telco-CDN can be regarded as an intra-domain overlay network with tight resources and critical deployment constraints. This paper addresses two problems in this context: (1) the construction of the overlays used to deliver the video channels from the entrypoints of the Telco-CDN to the appropriate edge servers; and (2) the allocation of the required resources to these overlays. Since bandwidth is critical for entrypoints and edge servers, our ultimate goal is to deliver as many video channels as possible while minimizing the total bandwidth consumption. To achieve this goal, we propose two approaches: a two-step optimization where the optimal overlays are firstly computed, then an optimal resource allocation based on these pre-computed overlays is performed; and a joint optimization where both optimization problems are simultaneously solved. We also devise fast heuristic algorithms for each of these approaches. The conducted evaluations of these two approaches and algorithms provide useful insights into the management of critical Telco-CDN infrastructures. Fen Zhou 0001, Jiayi Liu 0001, Gwendal Simon, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2014 | PowerGuide: Accurate Wi-Fi power estimator for smartphonesabstractWi-Fi is a popular wireless communication technology for smart devices such as smartphones, however, Wi-Fi related energy consumption in smartphones contributes to a significant portion of its energy expenditure. Hence it is important to carefully analyze and profile Wi-Fi energy expenditure in order to improve mobile applications' energy efficiency. Although hardware based power meters provide very accurate power measurement result, it is infeasible to expect mobile application developers to rely on power meters. As alternative solutions, software based power estimation tools are popular. Most of the existing power estimation solutions to date do not provide accurate estimation result, as we disclose in this paper by analyzing the popular PowerTutor. Therefore, we propose a new Wi-Fi power model by taking into account important IEEE 802.11 communication patterns as well as Wi-Fi hardware settings in a way that increases the accuracy of power estimation. We design and implement the proposed power model as a smartphone application and deploy it into a real device for validation. The evaluation results show that our solution can achieve an estimation accuracy up to 86% compared to hardware power meters, and is much more accurate than PowerTutor. Jian Li 0024, Jin Xiao 0005, Heni Azzouz, James Won-Ki Hong, Raouf Boutaba |
APNOMS | 5 |
| 2014 | Venice: Reliable virtual data center embedding in cloudsabstractCloud computing has become a cost-effective model for deploying online services in recent years. To improve the Quality-of-Service (QoS) of the provisioned services, recently a number of proposals have advocated to provision both guaranteed server and network resources in the form of Virtual Data Centers (VDCs). However, existing VDC scheduling algorithms have not fully considered the reliability aspect of the allocations in terms of (1) hardware failure characteristics on which the service is hosted, and (2) the impact of individual failures on service availability, given the dependencies among the virtual components. To address this limitation, in this paper we present a technique for computing VDC availability that considers heterogeneous hardware failure rates and dependencies among virtual components. We then propose Venice, an availability-aware VDC embedding framework for achieving high VDC availability and low operational costs. Experiments show Venice can significantly improve VDC availability while achieving higher income compared to availability-oblivious solutions. Qi Zhang 0008, Mohamed Faten Zhani, Maissa Jabri, Raouf Boutaba |
INFOCOM | 4 |
| 2014 | pWeb: A personal interface to the world wide webabstractCentralized social networking and media sharing portals provide inadequate support for preserving user privacy, content ownership and control. These problems can be mitigated through distributed Web services as demonstrated by a number of academic projects and industrial deployments. In general, these distributed services do not assign globally recognized, persistent names to the user devices. As a result, these solutions work in isolation and also cannot inter-operate with traditional Web technology. In this work, we present a decentralized and scalable platform, named pWeb, for distributing web services, like online social networks and media streaming, across end-user devices. pWeb assigns Internet compatible names to end-user devices, and provides name resolution and directory services. A user can retain ownership, and make the services and contents in his devices searchable and accessible at different privacy levels, e.g., friends, family and public. New services can be easily developed and deployed over the pWeb platform. We have developed a working prototype of the platform, and to demonstrate its effectiveness we have implemented a video streaming application for Android and Windows platforms. We also present performance results from our prototype implementation. Reaz Ahmed, Shihabur Rahman Chowdhury, Alexander Pokluda, Md. Faizul Bari, Raouf Boutaba, Bertrand Mathieu |
Networking | 5 |
| 2014 | CQNCR: Optimal VM migration planning in cloud data centersabstractWith the proliferation of cloud computing, virtu-alization has become the cornerstone of modern data centers and an effective solution to reduce operational costs, maximize utilization and improve performance and reliability. One of the powerful features provided by virtualization is Virtual Machine (VM) migration, which facilitates moving workloads within the infrastructure to reach various performance objectives. As recent virtual resource management schemes are more reliant on this feature, a large number of VM migrations may be triggered simultaneously to optimize resource allocations. In this context, a challenging problem is to find an efficient migration plan, i.e., an optimal sequence in which migrations should be triggered in order to minimize the total migration time and impact on services. In this paper, we propose CQNCR (read as sequencer), an effective technique for determining the execution order of massive VM migrations within data centers. Specifically, given an initial and a target resource configuration, CQNCR sequences VM migrations so as to efficiently reach the final configuration with minimal time and impact on performance. Experiments show that CQNCR can significantly reduce total migration time by up to 35% and service downtime by up to 60%. Md. Faizul Bari, Mohamed Faten Zhani, Qi Zhang 0008, Reaz Ahmed, Raouf Boutaba |
Networking | 5 |
| 2014 | Managing the file system from the kernelabstractIn this paper, we investigate the benefits of adding autonomic capabilities inside the operating system. We have developed and implemented a solution that focuses on three use cases (continuous file permission compliance, dynamic disk cleanup, and accidental removal protection) for the file system, and encapsulates all the respective file system monitoring, troubleshooting and error remedial operations in a Linux kernel module. The main benefits of this approach are the capability to detect issues instantly when they occur, and fix these issues transparently, with the invoking applications being unaware of their occurrence. These capabilities are not present in external agent architectures, including contemporary configuration management systems, like Puppet, Chef, or CFEngine. We have built a prototype and evaluated the performance of the most resource intensive use case, dynamic disk cleanup, using the FileBench file system benchmarking tool. Shihabur Rahman Chowdhury, Constantin Adam, Frederick Wu, John J. Rofrano, Raouf Boutaba |
NOMS | 5 |
| 2014 | PayLess: A low cost network monitoring framework for Software Defined NetworksabstractSoftware Defined Networking promises to simplify network management tasks by separating the control plane (a central controller) from the data plane (switches). OpenFlow has emerged as the de facto standard for communication between the controller and switches. Apart from providing flow control and communication interfaces, OpenFlow provides a flow level statistics collection mechanism from the data plane. It exposes a high level interface for per flow and aggregate statistics collection. Network applications can use this high level interface to monitor network status without being concerned about the low level details. In order to keep the switch design simple, this statistics collection mechanism is implemented as a pull-based service, i.e. network applications and in turn the controller has to periodically query the switches about flow statistics. The frequency of polling the switches determines monitoring accuracy and network overhead. In this paper, we focus on this trade-off between monitoring accuracy, timeliness and network overhead. We propose PayLess - a monitoring framework for SDN. PayLess provides a flexible RESTful API for flow statistics collection at different aggregation levels. It uses an adaptive statistics collection algorithm that delivers highly accurate information in real-time without incurring significant network overhead. We utilize the Floodlight controller's API to implement the proposed monitoring framework. The effectiveness of our solution is demonstrated through emulations in Mininet. Shihabur Rahman Chowdhury, Md. Faizul Bari, Reaz Ahmed, Raouf Boutaba |
NOMS | 4 |
| 2014 | Evaluating allocation paradigms for multi-objective adaptive provisioning in virtualized networksabstractRecent advances in virtualization technology have made it possible to partition a network into multiple virtual networks managed by different users. Although virtual networks share the same physical infrastructure, they host diverse applications with different goals. Unfortunately, current virtual network provisioning solutions have only focused on achieving a single objective that may not be suited for all the applications deployed across the network. In this paper, we propose an adaptive provisioning framework for virtualized networks that takes into consideration the characteristics of multiple applications and their distinct performance objectives. The proposed framework is based on the concept of allocation paradigm, which is defined as a set of application-driven provisioning policies that guide the resource allocation process. To determine the efficiency of a particular paradigm, we propose a virtual network performance computation model based on data measured from existing benchmarks. Simulation results show that our model helps network providers to select the best allocation paradigms in terms of provisioning quality. Rafael Pereira Esteves, Lisandro Z. Granville, Mohamed Faten Zhani, Raouf Boutaba |
NOMS | 4 |
| 2014 | RevMatch: An efficient and robust decision model for collaborative malware detectionabstractThis work falls in the area of collaborative malware detection systems which rely on expertise and knowledge from multiple different antivirus software for malware detection. A critical component of such systems is the collaborative malware detection decision process. In this paper, we propose a novel decision model, RevMatch, where collaborative malware decisions are made based on labeled malware detection history from participating antiviruses. We evaluate our proposal using real-world malware data sets and demonstrate that collaborative malware detection techniques can improve the malware detection accuracy compared to using a single albeit the best antivirus. Moreover, we demonstrate how RevMatch outperforms all other existing collaborative decision models in terms of detection accuracy while being computationally efficient and robust against various malicious insider attacks. Carol J. Fung, Disney Yan Lam, Raouf Boutaba |
NOMS | 3 |
| 2014 | Energy efficient Wi-Fi management for smart devicesabstractData communication is a significant component of smart device energy consumption today, and is likely to increase with the rising connectivity demands of today's mobile applications. Wi-Fi is a major supporting technology and as such, efficient energy management solutions are much needed. In this paper, we detail the Wi-Fi energy consumption characteristics and propose two energy saving schemes: packing and alignment, implementable at the application layer. Our investigations also reveal that these schemes are highly reliant on the network metric - available bandwidth, which is not readily obtainable on smartphones and existing wired solutions are ill-suited due to the dynamics of the wireless environment, as well as the energy constraint of mobile devices. Therefore, we propose a new energy efficient bandwidth measurement tool called BreezChirp. As validation, we implemented both BreezChirp and the Wi-Fi management schemes on modern Andriod smartphones and evaluated their performance through field experiments. Jian Li 0024, Jin Xiao 0005, Huu Nhat Minh Nguyen, James Won-Ki Hong, Raouf Boutaba |
NOMS | 5 |
| 2014 | Design and management of DOT: A Distributed OpenFlow TestbedabstractWith the growing adoption of Software Defined Networking (SDN), there is a compelling need for SDN emulators that facilitate experimenting with new SDN-based technologies. Unfortunately, Mininet [1], the de facto standard emulator for software defined networks, fails to scale with network size and traffic volume. The aim of this paper is to fill the void in this space by presenting a low cost and scalable network emulator called Distributed OpenFlow Testbed (DOT). It can emulate large SDN deployments by distributing the workload over a cluster of compute nodes. Through extensive experiments, we show that DOT can overcome the limitations of Mininet and emulate larger networks. We also demonstrate the effectiveness of DOT on four Rocketfuel topologies. DOT is available for public use and community-driven development at dothub.org. Arup Raton Roy, Md. Faizul Bari, Mohamed Faten Zhani, Reaz Ahmed, Raouf Boutaba |
NOMS | 5 |
| 2014 | Dynamic workload management in heterogeneous Cloud computing environmentsabstractCloud computing is a paradigm that harnesses massive resource capacity of data centers to support applications in a scalable, flexible, reliable and cost-effective manner. Despite its recent success and rapid adoption in the IT industry, recent literature has shown that effective workload management in cloud computing environments remains to be a difficult challenge. A key reason behind this difficulty is that resources and workloads in production environments are both heterogeneous and dynamic. In particular, large cloud data centers often consist of machines with heterogeneous capacities and performance characteristics. At the same time, cloud workloads often show significant diversity in terms of priority, resource requirements, arrival rate and performance objectives. Consequently, it is difficult to devise heterogeneity and dynamicity-aware management scheme that satisfy diverse application performance objectives, while reducing operational expenses such as energy consumption. This work addresses several key challenges pertaining to dynamic workload management in heterogenous Cloud environments. Specifically, we first present a scheme that place service application across geographically distributed data centers to meet service demand while minimizing total resource usage cost. Then, we design a heterogeneity-aware dynamic application provisioning technique to minimize energy consumption while satisfying performance objectives. Finally, we study the problem of MapReduce scheduling and present a novel scheme that leverages heterogenous run-time task usage characteristics. Through experiments and simulations, we show our proposed solutions can significantly reduce data center energy consumption, while achieving better application performance in terms of service response time and job completion time. Qi Zhang 0008, Raouf Boutaba |
NOMS | 2 |
| 2014 | DOT: distributed OpenFlow testbedabstractWith the growing adoption of Software Defined Networking (SDN) technology, there is a compelling need for an SDN emulator that can facilitate experimenting with new SDN solutions. Unfortunately, Mininet, the de facto standard emulator for software defined networks, fails to scale with network size and traffic volume. To address these limitations, we developed Distributed OpenFlow Testbed (DOT), a highly scalable emulator for SDN. It can emulate large SDN deployments by distributing the workload over a cluster of compute nodes. Moreover, DOT can emulate a wider range of network services compared to other publicly available SDN emulators and simulators. Our demonstration will illustrate several features of DOT including: (i) how easy it is to setup the emulator, (ii) how to deploy a topology using a single configuration file, (iii) how to run a connectivity test to ensure that the emulated network is properly deployed, and (iv) how to control and monitor the emulated components from a centralized location. We will also showcase DOT by emulating two applications: (i) policy based traffic steering through middleboxes and (ii) traffic monitoring. Arup Raton Roy, Md. Faizul Bari, Mohamed Faten Zhani, Reaz Ahmed, Raouf Boutaba |
SIGCOMM | 5 |
| 2014 | Energy efficient management framework for multihop TDMA-based wireless networks
Ahmed Amokrane, Rami Langar, Raouf Boutaba, Guy Pujolle |
Comput. Networks | 3 |
| 2014 | Cloud networking and communications
Raouf Boutaba, Noura Limam, Stefano Secci, Tarik Taleb |
Comput. Networks | 1 |
| 2014 | Efficient content delivery scheme for layered video streaming in large-scale networks
Abbas Bradai, Toufik Ahmed, Raouf Boutaba, Reaz Ahmed |
J. Netw. Comput. Appl. | 3 |
| 2014 | Avoiding Quality Bottlenecks in P2P Adaptive StreamingabstractThis paper addresses the problem of quality bottleneck in adaptive SVC streaming. Quality bottleneck occurs in adaptive streaming systems when the desired video quality cannot be obtained even if the network capabilities are sufficient. In the context of SVC layered video streaming, we have observed that enhancement layers remain around the video source and fail to reach all the participating peers. To overcome this problem, we propose an adaptive SVC streaming solution that cooperatively integrates strategies of overlay formation, data scheduling and content adaptation. Performance evaluation using simulations shows that the proposed streaming solution reduces the quality bottleneck, increases churn-tolerance and optimizes bandwidth utilization. Samir Medjiah, Toufik Ahmed, Raouf Boutaba |
IEEE J. Sel. Areas Commun. | 3 |
| 2014 | Dynamic Heterogeneity-Aware Resource Provisioning in the CloudabstractData centers consume tremendous amounts of energy in terms of power distribution and cooling. Dynamic capacity provisioning is a promising approach for reducing energy consumption by dynamically adjusting the number of active machines to match resource demands. However, despite extensive studies of the problem, existing solutions have not fully considered the heterogeneity of both workload and machine hardware found in production environments. In particular, production data centers often comprise heterogeneous machines with different capacities and energy consumption characteristics. Meanwhile, the production cloud workloads typically consist of diverse applications with different priorities, performance and resource requirements. Failure to consider the heterogeneity of both machines and workloads will lead to both sub-optimal energy-savings and long scheduling delays, due to incompatibility between workload requirements and the resources offered by the provisioned machines. To address this limitation, we present Harmony, a Heterogeneity-Aware dynamic capacity provisioning scheme for cloud data centers. Specifically, we first use the K-means clustering algorithm to divide workload into distinct task classes with similar characteristics in terms of resource and performance requirements. Then we present a technique that dynamically adjusting the number of machines to minimize total energy consumption and scheduling delay. Simulations using traces from a Google's compute cluster demonstrate Harmony can reduce energy by 28 percent compared to heterogeneity-oblivious solutions. Qi Zhang 0008, Mohamed Faten Zhani, Raouf Boutaba, Joseph L. Hellerstein |
IEEE Trans. Cloud Comput. | 3 |
| 2014 | Online Anomaly Detection in Wireless Body Area Networks for Reliable Healthcare MonitoringabstractIn this paper, we propose a lightweight approach for online detection of faulty measurements by analyzing the data collected from medical wireless body area networks. The proposed framework performs sequential data analysis using a smart phone as a base station, and takes into account the constrained resources of the smart phone, such as processing power and storage capacity. The main objective is to raise alarms only when patients enter in an emergency situation, and to discard false alarms triggered by faulty measurements or ill-behaved sensors. The proposed approach is based on the Haar wavelet decomposition, nonseasonal Holt-Winters forecasting, and the Hampel filter for spatial analysis, and on for temporal analysis. Our objective is to reduce false alarms resulting from unreliable measurements and to reduce unnecessary healthcare intervention. We apply our proposed approach on real physiological dataset. Our experimental results prove the effectiveness of our approach in achieving good detection accuracy with a low false alarm rate. The simplicity and the processing speed of our proposed framework make it useful and efficient for real time diagnosis. Osman Salem, Yaning Liu, Ahmed Mehaoua, Raouf Boutaba |
IEEE J. Biomed. Health Informatics | 4 |
| 2014 | Reconciling the Overlay and Underlay TussleabstractIn the presence of multiple overlays and underlays, the emerging global network behavior is the result of interactions of self-serving overlay routing decisions and independent underlay management actions. It is crucial for network operators, service, and content providers to have a good grasp of the underlying principles in order to better design and manage current and future networks and services. In this paper, we describe special game scenarios wherein the interaction of noncooperative overlays and underlays in multidomain networks can result in an operable global configuration in linear time and the overall convergence is polynomial in the unweighed case. For weighted games, we find that weighted Shapley potential can achieve linear time convergence to an operable state. Furthermore, we analyze the interaction of overlays and underlays as a two-stage congestion game and recommend simple operational guidelines to ensure global stability. We further explore the use of Shapley value as an enabler of mutual cooperation in an otherwise competitive environment. Our simulation results confirm our findings and demonstrate its effectiveness in general networks. Jin Xiao 0005, Raouf Boutaba |
IEEE/ACM Trans. Netw. | 2 |
| 2013 | Dynamic Controller Provisioning in Software Defined NetworksabstractSoftware Defined Networking (SDN) has emerged as a new paradigm that offers the programmability required to dynamically configure and control a network. A traditional SDN implementation relies on a logically centralized controller that runs the control plane. However, in a large-scale WAN deployment, this rudimentary centralized approach has several limitations related to performance and scalability. To address these issues, recent proposals have advocated deploying multiple controllers that work cooperatively to control a network. Nonetheless, this approach drags in an interesting problem, which we call the Dynamic Controller Provisioning Problem (DCPP). DCPP dynamically adapts the number of controllers and their locations with changing network conditions, in order to minimize flow setup time and communication overhead. In this paper, we propose a framework for deploying multiple controllers within an WAN. Our framework dynamically adjusts the number of active controllers and delegates each controller with a subset of Openflow switches according to network dynamics while ensuring minimal flow setup time and communication overhead. To this end, we formulate the optimal controller provisioning problem as an Integer Linear Program (ILP) and propose two heuristics to solve it. Simulation results show that our solution minimizes flow setup time while incurring very low communication overhead. Md. Faizul Bari, Arup Raton Roy, Shihabur Rahman Chowdhury, Qi Zhang 0008, Mohamed Faten Zhani, Reaz Ahmed, Raouf Boutaba |
CNSM | 7 |
| 2013 | Joint optimization for the delivery of multiple video channels in Telco-CDNabstractA Telco-CDN can be regarded as an intra-domain overlay network with tight resources and critical deployment constraints. This paper addresses two problems in this context: (1) the construction of the overlays used to deliver the video channels from the entrypoints of the Telco-CDN to the appropriate edge servers; and (2) the allocation of the required resources to these overlays. Our ultimate goal is to maximize the number of delivered channels while preserving network resources. Two classes of heuristic algorithms, namely two-step optimization and joint-optimization, are proposed to solve these problems. The conducted evaluations confirm the efficiency of the joint-optimization approach. Fen Zhou 0001, Jiayi Liu 0001, Gwendal Simon, Raouf Boutaba |
CNSM | 4 |
| 2013 | Online flow-based energy efficient management in Wireless Mesh NetworksabstractThe last few years have witnessed an increase in energy consumption in Information and Communication Technology (ICT). Naturally, energy efficient solutions are becoming crucial for both local and wireless access networks. In this paper, we propose a new framework to support energy efficient management in Wireless Mesh Networks (WMNs). A key distinguishing feature of our solution is its online flow-based routing approach since existing flows are dynamically consolidated or even re-routed at fixed intervals according to live arrival and departure of mesh clients. The proposed solution is compliant with emerging Software Defined Networking (SDN) paradigm since it relies on a central controller to monitor and manage the network. To achieve this, we first formulate the problem as an integer linear program (ILP). As this problem is known to be NP-hard, we then propose a simple yet efficient Ant Colony-based approach to solve the formulated ILP problem. Through extensive simulations, we show that our proposed approach is able to achieve significant gains in terms of energy consumption, compared to conventional routing solutions such as the Shortest Path (SP) routing, the Minimum link Residual Capacity routing metric (MRC) and the load balancing (LB) scheme. Specifically, we show that our approach reduces the energy consumption by up to 13%, 20%, and 52%, compared to MRC, SP and LB, respectively, while achieving the required QoS. Ahmed Amokrane, Rami Langar, Raouf Boutaba, Guy Pujolle |
GLOBECOM | 3 |
| 2013 | Demands rescaling for resource and power allocation in cooperative femtocell networksabstractFemtocell provisioning is emerging as a key technology to improve coverage and network capacity in indoor environments. When femtocells use different frequency bands than macrocells (i.e., split-spectrum approach), femto-to-femto interference remains the major issue. In particular, congestion cases in which femtocell demands exceed the available resources pose an important challenge. In this paper, we propose a joint resource and power allocation strategy for the management of interference in cooperative femtocell networks. We model the resource and power allocation problem as an operations research game, where imputations are deduced from cooperative game theory, namely the Shapley value and the Nucleolus, using utility components results of partial optimizations. The performance of the developed solutions is analyzed and extensive simulation results are presented to illustrate their potential advantages. In particular, we show that the Shapley value solution with power control offers the overall best performance in terms of throughput, fairness, and transmit power, compared to alternative solutions. Mouna Hkimi, Rami Langar, Stefano Secci, Raouf Boutaba, Guy Pujolle |
ICC | 4 |
| 2013 | Harmony: Dynamic Heterogeneity-Aware Resource Provisioning in the CloudabstractData centers today consume tremendous amount of energy in terms of power distribution and cooling. Dynamic capacity provisioning is a promising approach for reducing energy consumption by dynamically adjusting the number of active machines to match resource demands. However, despite extensive studies of the problem, existing solutions for dynamic capacity provisioning have not fully considered the heterogeneity of both workload and machine hardware found in production environments. In particular, production data centers often comprise several generations of machines with different capacities, capabilities and energy consumption characteristics. Meanwhile, the workloads running in these data centers typically consist of a wide variety of applications with different priorities, performance objectives and resource requirements. Failure to consider heterogenous characteristics will lead to both sub-optimal energy-savings and long scheduling delays, due to incompatibility between workload requirements and the resources offered by the provisioned machines. To address this limitation, in this paper we present HARMONY, a Heterogeneity-Aware Resource Management System for dynamic capacity provisioning in cloud computing environments. Specifically, we first use the K-means clustering algorithm to divide the workload into distinct task classes with similar characteristics in terms of resource and performance requirements. Then we present a novel technique for dynamically adjusting the number of machines of each type to minimize total energy consumption and performance penalty in terms of scheduling delay. Through simulations using real traces from Google's compute clusters, we found that our approach can improve data center energy efficiency by up to 28% compared to heterogeneity-oblivious solutions. Qi Zhang 0008, Mohamed Faten Zhani, Raouf Boutaba, Joseph L. Hellerstein |
ICDCS | 3 |
| 2013 | Paradigm-based adaptive provisioning in virtualized data centers
Rafael Pereira Esteves, Lisandro Z. Granville, Hadi Bannazadeh, Raouf Boutaba |
IM | 4 |
| 2013 | Design and management of collaborative intrusion detection networks
Carol J. Fung, Raouf Boutaba |
IM | 2 |
| 2013 | On tackling virtual data center embedding problem
Md. Golam Rabbani, Rafael Pereira Esteves, Maxim Podlesny, Gwendal Simon, Lisandro Z. Granville, Raouf Boutaba |
IM | 6 |
| 2013 | VDC Planner: Dynamic migration-aware Virtual Data Center embedding for clouds
Mohamed Faten Zhani, Qi Zhang 0008, Gwendal Simon, Raouf Boutaba |
IM | 4 |
| 2013 | αRoute: A name based routing scheme for Information Centric NetworksabstractOne of the crucial building blocks for Information Centric Networking (ICN) is a name based routing scheme that can route directly on content names instead of IP addresses. However, moving the address space from IP addresses to content names brings scalability issues to a whole new level, due to two reasons. First, name aggregation is not as trivial a task as the IP address aggregation in BGP routing. Second, the number of addressable contents in the Internet is several orders of magnitude higher than the number of IP addresses. With the current size of the Internet, name based, anycast routing is very challenging specially when routing efficiency is of prime importance. We propose a novel name-based routing scheme (αRoute) for ICN that offers efficient bandwidth usage, guaranteed content lookup and scalable routing table size. Reaz Ahmed, Md. Faizul Bari, Shihabur Rahman Chowdhury, Md. Golam Rabbani, Raouf Boutaba, Bertrand Mathieu |
INFOCOM | 5 |
| 2013 | Reliable and energy efficient cooperative detection in wireless sensor networks
Fatma Bouabdallah, Nizar Bouabdallah, Raouf Boutaba |
Comput. Commun. | 3 |
| 2013 | A Naming Scheme for P2P Web HostingabstractThe peer—to—peer paradigm has great potential of providing the next generation Web hosting infrastructure. Profound advancements in P2P technology in the last decade have proven its capability to provide functionality similar to traditional client—server systems at a much larger scale with relatively lower cost. Existing centralized website hosting technology has a number of inherent deficiencies including scalability, single point of failure, administration overhead, hosting expenses, etc. P2P Web hosting can effectively address these problems and hence open a new era for next generation Web hosting. However peer availability and content location are highly dynamic in a P2P network. This dynamism raises a number of research challenges related to naming, addressing, indexing, and searching in a P2P environment. In this paper we identify the practical requirements for devising a secure, persistent, and human—friendly naming scheme for P2P Web hosting and propose a novel naming scheme that satisfies all these requirements. We also present extensive simulation results validating the accuracy, scalability and fault-resilience of the proposed naming scheme. Md. Faizul Bari, Md. Rakibul Haque, Reaz Ahmed, Raouf Boutaba, Bertrand Mathieu |
IEEE J. Sel. Areas Commun. | 4 |
| 2013 | Dynamic Service Placement in Geographically Distributed CloudsabstractLarge-scale online service providers have been increasingly relying on geographically distributed cloud infrastructures for service hosting and delivery. In this context, a key challenge faced by service providers is to determine the locations where service applications should be placed such that the hosting cost is minimized while key performance requirements (e.g., response time) are ensured. Furthermore, the dynamic nature of both demand pattern and infrastructure cost favors a dynamic solution to this problem. Currently most of the existing solutions for service placement have either ignored dynamics, or provided solutions inadequate to achieve this objective. In this paper, we present a framework for dynamic service placement problems based on control- and game-theoretic models. In particular, we present a solution that optimizes the hosting cost dynamically over time according to both demand and resource price fluctuations. We further consider the case where multiple service providers compete for resources in a dynamic manner. This paper extends our previous work [1] by analyzing the outcome of the competition in terms of both price of stability and price of anarchy. Our analysis suggests that in an uncoordinated scenario where service providers behave in a selfish manner, the resulting Nash equilibrium can be arbitrarily worse than the optimal centralized solution in terms of social welfare. Based on this observation, we present a coordination mechanism that can be employed by the infrastructure provider to maximize the social welfare of the system. Finally, we demonstrate the effectiveness of our solutions using realistic simulations. Qi Zhang 0008, Quanyan Zhu, Mohamed Faten Zhani, Raouf Boutaba, Joseph L. Hellerstein |
IEEE J. Sel. Areas Commun. | 4 |
| 2013 | Greenhead: Virtual Data Center Embedding across Distributed InfrastructuresabstractCloud computing promises to provide on-demand computing, storage, and networking resources. However, most cloud providers simply offer virtual machines (VMs) without bandwidth and delay guarantees, which may hurt the performance of the deployed services. Recently, some proposals suggested remediating such limitation by offering virtual data centers (VDCs) instead of VMs only. However, they have only considered the case where VDCs are embedded within a single data center. In practice, infrastructure providers should have the ability to provision requested VDCs across their distributed infrastructure to achieve multiple goals including revenue maximization, operational costs reduction, energy efficiency, and green IT, or to simply satisfy geographic location constraints of the VDCs. In this paper, we propose Greenhead, a holistic resource management framework for embedding VDCs across geographically distributed data centers connected through a backbone network. The goal of Greenhead is to maximize the cloud provider's revenue while ensuring that the infrastructure is as environment-friendly as possible. To evaluate the effectiveness of our proposal, we conducted extensive simulations of four data centers connected through the NSFNet topology. Results show that Greenhead improves requests' acceptance ratio and revenue by up to 40 percent while ensuring high usage of renewable energy and minimal carbon footprint. Ahmed Amokrane, Mohamed Faten Zhani, Rami Langar, Raouf Boutaba, Guy Pujolle |
IEEE Trans. Cloud Comput. | 4 |
| 2013 | SVNE: Survivable Virtual Network Embedding Algorithms for Network VirtualizationabstractNetwork virtualization can offer more flexibility and better manageability for the future Internet by allowing multiple heterogeneous virtual networks (VN) to coexist on a shared infrastructure provider (InP) network. A major challenge in this respect is the VN embedding problem that deals with the efficient mapping of virtual resources on InP network resources. Previous research focused on heuristic algorithms for the VN embedding problem assuming that the InP network remains operational at all times. In this paper, we remove this assumption by formulating the survivable virtual network embedding (SVNE) problem. We then develop a pro-active, and a hybrid policy heuristic to solve it, and a baseline policy heuristic to compare to. The hybrid policy is based on a fast re-routing strategy and utilizes a pre-reserved quota for backup on each physical link. Our evaluation results show that our proposed heuristics for SVNE outperform the baseline heuristic in terms of long term business profit for the InP, acceptance ratio, bandwidth efficiency, and response time. Muntasir Raihan Rahman, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2013 | Efficient reporting node selection-based MAC protocol for wireless sensor networks
Fatma Bouabdallah, Nizar Bouabdallah, Raouf Boutaba |
Wirel. Networks | 3 |
| 2012 | Event-based estimation of user experience for network video streamingabstractIn managing multimedia services, it is important to understand how network performance affects user experience. The model presented in this paper aims to estimate user perception of video quality based on defect events, which are automatically classified by machine learning techniques. The underlying principle of our model is that human experience is event-based and there is a strong correlation between defective events and user MOS. Through experiments, we show that our model can detect different types of defect events with good accuracy even under small data set, and we find that indeed different defect event types affect user experience with different sensitivity. Jin Xiao 0005, James Won-Ki Hong, Ahmed Mehaoua, Raouf Boutaba |
APNOMS | 5 |
| 2012 | Application-centric Wi-Fi energy management on smart phoneabstractVast majority of the services running on the smart phone today are networked in that significant amount of communication is required. Smart phone energy expenditure due to Wi-Fi communications constitutes significant portion of the battery discharge. In this paper, we first investigate the key factors influencing Wi-Fi energy consumption, and propose three energy management schemes: 1) Dynamic control of Wi-Fi on/off interface; 2) improve communication efficiency via application packing; and 3) elongation of Wi-Fi Power Save Mode (PSM) via application alignment under mixed application workload. We also design and test our solution as a device-side application utilizing general system process scheduling and network firewall techniques. As the result, our solution is easy to deploy, applicable to most mobile devices, and we explicitly tackle the challenging case of download management. Through extensive experimentation and solution prototyping, we show the effectiveness of device side Wi-Fi energy management and the importance of considering application characteristics. Jian Li 0024, Jin Xiao 0005, James Won-Ki Hong, Raouf Boutaba |
APNOMS | 4 |
| 2012 | Diurnal availability for peer-to-peer systemsabstractEnsuring content availability in a persistent manner is essential for providing any consistent service over peer-to-peer (P2P) systems. This paper introduces an efficient protocol, called DATA, to design highly available P2P systems irrespective of peer uptime and churn. Our approach utilizes the diurnal pattern of globally dispersed peers to develop a grouping strategy where each group aims to ensure 24 × 7 data availability within the group. Simulation results reveal that our protocol converges fast and ensures high availability for each group with minimal overhead. Nashid Shahriar, Mahfuza Sharmin, Reaz Ahmed, Raouf Boutaba, Bertrand Mathieu |
CCNC | 5 |
| 2012 | A green framework for energy efficient management in TDMA-based Wireless Mesh Networks
Ahmed Amokrane, Rami Langar, Raouf Boutaba, Guy Pujolle |
CNSM | 3 |
| 2012 | Comfort-aware home energy management under market-based Demand-Response
Jin Xiao 0005, Jian Li 0024, Raouf Boutaba, James Won-Ki Hong |
CNSM | 3 |
| 2012 | Embedded Markov process based model for performance analysis of Intrusion Detection and Prevention SystemsabstractIntrusion Detection and/or Prevention Systems (IDPSs) are now a crucial defensive measure to defend against attacks intended to breach the security and operation of enterprise information systems. The IDPS configuration can, however, have a negative impact on network performance in terms of end-to-end delay and packet loss. This paper proposes an analytical queuing model based on the embedded Markov chain which analyzes the performance of the IDPS and evaluates its impact on performance. Through extensive simulations, we validate the proposed model and the numerical equations that estimate various performance metrics. Our results show that this model can be leveraged to assess and set up an effective configuration for the IDPS, achieving simultaneously the trade-off between security enforcement levels on one side and network Quality of Service (QoS) requirements on the other. Khalid Alsubhi, Mohamed Faten Zhani, Raouf Boutaba |
GLOBECOM | 3 |
| 2012 | QoS-based power control and resource allocation in OFDMA femtocell networksabstractThis paper proposes a new joint power control and resource allocation algorithm in OFDMA femtocell networks. We consider both QoS constrained high-priority (HP) and best-effort (BE) users having different types of application and bandwidth requirements. Our objective is to minimize the transmit power of each femtocell, while satisfying a maximum number of HP users and serving BE users as well as possible. This optimization problem is multi-objective NP-hard. Hence, we propose a new scheme based on clustering and taking into account QoS requirements of users. We show by extensive network simulation results that our proposal outperforms three state of the art schemes (Centralized-Dynamic Frequency Planning, C-DFP, Distributed Random Access, DRA and Distributed Resource Allocation with Power Minimization, DRAPM as well as our previous proposal, FCRA, in both low and high density networks. The results concern the rate of rejected users, the throughput satisfaction rate, the spectrum spatial reuse, fairness, as well as computation time. Abbas Antoun Hatoum, Rami Langar, Nadjib Aitsaadi, Raouf Boutaba, Guy Pujolle |
GLOBECOM | 4 |
| 2012 | A bankruptcy game approach for resource allocation in cooperative femtocell networksabstractFemtocells have recently appeared as a viable solution to enable broadband connectivity in mobile cellular networks. Instead of redimensioning macrocells at the base station level, the modular installation of short-range access points can grant multiple benefits, provided that interference is efficiently managed. In the case where femtocells use different frequency bands than macrocells (i.e., split-spectrum approach), interference between femtocells is the major issue. In particular, congestion cases in which femtocell demands exceed the available bandwidth pose an important challenge. If, as expected, the femtocell service is going to be separately billed by legacy wire-line Internet Service Providers, strategic interference management and resource allocation mechanisms are needed to avoid performance degradation during congestion cases. In this paper, we model the resource allocation in cooperative femtocell networks as a bankruptcy game. We identify possible solutions from cooperative game theory, namely the Shapley value and the Nucleolus, and show through extensive simulations of realistic scenarios that they outperform two state-of-the-art schemes, namely Centralized-Dynamic Frequency Planning, C-DFP, and Frequency-ALOHA, F-ALOHA. In particular, the Nucleolus solution offers best performance overall in terms of throughput and fairness, at a lower time complexity. Sahar Hoteit, Stefano Secci, Rami Langar, Guy Pujolle, Raouf Boutaba |
GLOBECOM | 5 |
| 2012 | Dynamic Service Placement in Geographically Distributed CloudsabstractLarge-scale online service providers have been increasingly relying on geographically distributed cloud infrastructures for service hosting and delivery. In this context, a key challenge faced by service providers is to determine the locations where service applications should be placed such that the hosting cost is minimized while key performance requirements (e.g. response time) are assured. Furthermore, the dynamic nature of both demand pattern and infrastructure cost favors a dynamic solution to this problem. Currently most of the existing solutions for service placement have either ignored dynamics, or provided inadequate solutions that achieve both objectives at the same time. In this paper, we present a framework for dynamic service placement problems based on control- and game-theoretic models. In particular, we present a solution that optimizes the desired objective dynamically over time according to both demand and resource price fluctuations. We further consider the case where multiple service providers compete for resource in a dynamic manner, and show that there is a Nash equilibrium solution which is socially optimal. Using simulations based on realistic topologies, demand and resource prices, we demonstrate the effectiveness of our solution in realistic settings. Qi Zhang 0008, Quanyan Zhu, Mohamed Faten Zhani, Raouf Boutaba |
ICDCS | 4 |
| 2012 | On the complexity of routing in wireless multihop networkabstractWireless backbone networks represent an attractive alternative to wired networks in situations where cost, speed of deployment, and flexibility in network design are important. In typical configurations, users connect to wireless routers of the backbone network, which then redirect the traffic to one of the existing network gateways. To improve the network performance, wireless backbone routers redirect their traffic to the network gateways so as to maximize amount of traffic that can be supported by the network. In this paper, we prove that this problem is NP-hard as a result of the wireless interference that is created between geographically close transmission links. We consequently design and investigate the performance of interference-aware algorithms suitable for multi-channel environments against more traditional routing approaches. We evaluate their performance in simulated environments based on data taken from existing networks, and show that interference-based heuristics exhibit advantageous performance in non-uniform deployment. Sonia Waharte, Alexander Golynski, Raouf Boutaba |
IWCMC | 3 |
| 2012 | The impact of network performance on perceived video quality in H.264/AVCabstractMultimedia services have become a dominant part of the network and content provider's service portfolio. A formal modeling methodology for video quality assessment not only affords the providers a clear cause-effect management view of their services, but also helps to guide management and planning operations. We examine the relation between network performance and perceived video quality through VIDAR, a comprehensive VIDeo quality Analyzer in Real-time. VIDAR links network performance to objective frame quality (eSSIM), and modify eSSIM values by subjective filters. Through experiments, we show that VIDAR helps providers to better understand and assess the impact of the network performance on perceived video quality. Arum Kwon, Jin Xiao 0005, Sin-Seok Seo, James Won-Ki Hong, Raouf Boutaba |
NOMS | 5 |
| 2012 | An evasive attack on SNORT flowbitsabstractThe support of stateful signatures is an important feature of signature-based Network Intrusion Detection Systems (NIDSs) which permits the detection of multi-stage attacks. However, due to the difficulty to completely simulate every application protocol, several NIDS evasion techniques exploit this Achilles' heel, making the NIDS and its protected system see and explain a packet sequence differently. In this paper, we propose an evasion technique to the Snort NIDS which exploits its flowbits feature. We specify the flowbit evasion attack and provide practical algorithms to solve it with controllable false positives and formally prove their correctness and completeness. We implemented a tool called SFET which can automatically parse a Snort rule set, generate all possible sequences that can evade it, as well as produce a patch to guard the rule set against those evasions. Although Snort was used for illustration, both the evasion attack and the solution to it are applicable to any stateful signature-based NIDS. Tung Tran 0002, Issam Aib, Ehab Al-Shaer, Raouf Boutaba |
NOMS | 4 |
| 2012 | A cross layer architecture for multicast and unicast video transmission in mobile broadband networks
Djamal-Eddine Meddour, Alaeddine Abdallah Djamal, Toufik Ahmed, Raouf Boutaba |
J. Netw. Comput. Appl. | 4 |
| 2012 | GUIDEX: A Game-Theoretic Incentive-Based Mechanism for Intrusion Detection NetworksabstractTraditional intrusion detection systems (IDSs) work in isolation and can be easily compromised by unknown threats. An intrusion detection network (IDN) is a collaborative IDS network intended to overcome this weakness by allowing IDS peers to share detection knowledge and experience, and hence improve the overall accuracy of intrusion assessment. In this work, we design an IDN system, called GUIDEX, using game-theoretic modeling and trust management for peers to collaborate truthfully and actively. We first describe the system architecture and its individual components, and then establish a game-theoretic framework for the resource management component of GUIDEX. We establish the existence and uniqueness of a Nash equilibrium under which peers can communicate in a reciprocal incentive compatible manner. Based on the duality of the problem, we develop an iterative algorithm that converges geometrically to the equilibrium. Our numerical experiments and discrete event simulation demonstrate the convergence to the Nash equilibrium and the security features of GUIDEX against free riders, dishonest insiders and DoS attacks. Quanyan Zhu, Carol J. Fung, Raouf Boutaba, Tamer Basar |
IEEE J. Sel. Areas Commun. | 3 |
| 2012 | An analysis of peer similarity for recommendations in P2P systems
Loubna Mekouar, Youssef Iraqi, Raouf Boutaba |
Multim. Tools Appl. | 3 |
| 2012 | Effective Acquaintance Management based on Bayesian Learning for Distributed Intrusion Detection NetworksabstractAn effective Collaborative Intrusion Detection Network (CIDN) allows distributed Intrusion Detection Systems (IDSes) to collaborate and share their knowledge and opinions about intrusions, to enhance the overall accuracy of intrusion assessment as well as the ability of detecting new classes of intrusions. Toward this goal, we propose a distributed Host-based IDS (HIDS) collaboration system, particularly focusing on acquaintance management where each HIDS selects and maintains a list of collaborators from which they can consult about intrusions. Specifically, each HIDS evaluates both the false positive (FP) rate and false negative (FN) rate of its neighboring HIDSes' opinions about intrusions using Bayesian learning, and aggregates these opinions using a Bayesian decision model. Our dynamic acquaintance management algorithm allows each HIDS to effectively select a set of collaborators. We evaluate our system based on a simulated collaborative HIDS network. The experimental results demonstrate the convergence, stability, robustness, and incentive-compatibility of our system. Carol J. Fung, Jie Zhang 0002, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2012 | Performance Modeling and Analysis of Network FirewallsabstractNetwork firewalls act as the first line of defense against unwanted and malicious traffic targeting Internet servers. Predicting the overall firewall performance is crucial to network security engineers and designers in assessing the effectiveness and resiliency of network firewalls against DDoS (Distributed Denial of Service) attacks as those commonly launched by today's Botnets. In this paper, we present an analytical queueing model based on the embedded Markov chain to study and analyze the performance of rule-based firewalls when subjected to normal traffic flows as well as DoS attack flows targeting different rule positions. We derive equations for key features and performance measures of engineering and design significance. These features and measures include throughput, packet loss, packet delay, and firewall's CPU utilization. In addition, we verify and validate our analytical model using simulation and real experimental measurements. Khaled Salah 0001, Khalid Elbadawi, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2012 | ViNEYard: Virtual Network Embedding Algorithms With Coordinated Node and Link MappingabstractNetwork virtualization allows multiple heterogeneous virtual networks (VNs) to coexist on a shared infrastructure. Efficient mapping of virtual nodes and virtual links of a VN request onto substrate network resources, also known as the VN embedding problem, is the first step toward enabling such multiplicity. Since this problem is known to beNP-hard, previous research focused on designing heuristic-based algorithms that had clear separation between the node mapping and the link mapping phases. In this paper, we present ViNEYard-a collection of VN embedding algorithms that leverage better coordination between the two phases. We formulate the VN embedding problem as a mixed integer program through substrate network augmentation. We then relax the integer constraints to obtain a linear program and devise two online VN embedding algorithms D-ViNE and R-ViNE using deterministic and randomized rounding techniques, respectively. We also present a generalized window-based VN embedding algorithm (WiNE) to evaluate the effect of lookahead on VN embedding. Our simulation experiments on a large mix of VN requests show that the proposed algorithms increase the acceptance ratio and the revenue while decreasing the cost incurred by the substrate network in the long run. Mosharaf Chowdhury, Muntasir Raihan Rahman, Raouf Boutaba |
IEEE/ACM Trans. Netw. | 3 |
| 2012 | FireCol: a collaborative protection network for the detection of flooding DDoS attacksabstractDistributed denial-of-service (DDoS) attacks remain a major security problem, the mitigation of which is very hard especially when it comes to highly distributed botnet-based attacks. The early discovery of these attacks, although challenging, is necessary to protect end-users as well as the expensive network infrastructure resources. In this paper, we address the problem of DDoS attacks and present the theoretical foundation, architecture, and algorithms of FireCol. The core of FireCol is composed of intrusion prevention systems (IPSs) located at the Internet service providers (ISPs) level. The IPSs form virtual protection rings around the hosts to defend and collaborate by exchanging selected traffic information. The evaluation of FireCol using extensive simulations and a real dataset is presented, showing FireCol effectiveness and low overhead, as well as its support for incremental deployment in real networks. Jérôme François, Issam Aib, Raouf Boutaba |
IEEE/ACM Trans. Netw. | 3 |
| 2011 | Poster: SMURFEN: a rule sharing collaborative intrusion detection network
Carol J. Fung, Quanyan Zhu, Raouf Boutaba, Tamer Basar |
CCS | 3 |
| 2011 | Mitigating the negative impact of preemption on heterogeneous MapReduce workloads
Lu Cheng 0002, Qi Zhang 0008, Raouf Boutaba |
CNSM | 3 |
| 2011 | SMURFEN: A system framework for rule sharing collaborative intrusion detection
Carol J. Fung, Quanyan Zhu, Raouf Boutaba, Tamer Basar |
CNSM | 3 |
| 2011 | Rule Mode Selection in Intrusion Detection and Prevention SystemsabstractProtection and performance are the major requirements for any Intrusion Detection and/or Prevention System (IDPS). Existing IDPSs do not seem to provide a satisfactory method of achieving these two conflicting goals. Intrusion Detection Systems (IDSs) fulfill the network performance requirement but exhibit poor protection under successive attacks. On the other hand, Intrusion Prevention Systems (IPSs) can protect the network by dropping the malicious packets that match any attacking pattern; however, this can have a negative impact on network performance in terms of delay as the attacking patterns increase. This results in a tradeoff between security enforcement levels on one hand and the performance and usability of an enterprise information system on the other. This paper aims to study the impact of security enforcement levels on the performance and usability of an enterprise information system. We propose a rule mode selection optimization technique that aims to determine an appropriate IDPS configuration set in order to maximize the security enforcement levels while avoiding any unnecessary network performance degradation. Simulation was conducted to validate our proposed technique. The results demonstrate that it is desirable to strike a balance between system security and network performance. Khalid Alsubhi, Yassir Alhazmi, Nizar Bouabdallah, Raouf Boutaba |
GLOBECOM | 4 |
| 2011 | Performance Modeling of Routing Dependability in Home NetworksabstractIn this paper, we propose a new routing protocol for home networks, called dependable routing protocol (DRP) that adapts to the changes in local topology within home networks environments. DRP is based on an effective selection of paths through which a packet must pass to reach the home unit. The selection, in such dynamic home networks, is made using dependable routing, i.e, in a way that maximizes the routes quality between the network nodes and the home unit while minimizing the Failure of Service (FoS). To minimize FoS, DRP maintains requirements on both the tolerable end-to-end delay (for time-sensitive routing) and the bit error rate (for reliable routing) within the network. To achieve this, we formulate the routing dependability problem mathematically as a constrained optimization problem. Specifically, analytical expressions for the route quality as well as the delay and bit error rate of a route in a home network scenario are derived. Numerical and simulation results show that the proposed approach gives optimal or near-optimal solutions and improves significantly the home network performance when compared to one prominent routing protocol: the Minimum Total Transmission Power Routing scheme, MTPR. Hanan Saleet, Sagar Naik, Rami Langar, Raouf Boutaba, Amiya Nayak, Vineet Srivastava 0002 |
GLOBECOM | 4 |
| 2011 | A Distributed OFDMA Medium Access Control for Underwater Acoustic Sensors NetworksabstractIn this paper, we propose UW-OFDMAC, a distributed Medium Access Control (MAC) protocol tuned for Under-Water Acoustic Sensor Networks (UW-ASNs). It is a transmitter based Orthogonal Frequency Division Multiple Access (OFDMA)scheme that integrates an original power and OFDMA parameters self-assignment algorithm to set the optimal transmit power, subcarrier spacing and guard interval duration. UW-OFDMAC aims at achieving two objectives, namely, guarantee high bandwidth efficiency and low energy consumption. Simulation results show that UW-OFDMAC outperforms the basic OFDMA protocol tuned for the underwater environment. Fatma Bouabdallah, Raouf Boutaba |
ICC | 2 |
| 2011 | FCRA: Femtocell Cluster-Based Resource Allocation Scheme for OFDMA NetworksabstractRecently, operators have resorted to femtocell networks in order to enhance indoor coverage and quality of service since macro-antennas fail to reach these objectives. Nevertheless, they are confronted to many challenges to make a success of femtocells deployment. In this paper, we address the issue of resources allocation in femtocell networks using OFDMA technology (e.g., WiMAX, LTE). Specifically, we propose a hybrid centralized/distributed resource allocation strategy namely Femtocell Cluster-based Resource Allocation (FCRA). Firstly, FCRA builds disjoint femtocell clusters. Then, within a cluster the optimal resource allocation for each femtocell is performed by its cluster-head. Finally, the contingent collisions among different clusters are fixed. To achieve this, we formulate the problem mathematically as Min-Max optimization problem. Performance analysis shows that FCRA converges to the optimal solution in small-sized networks and outperforms two prominent related schemes (C-DFP and DRA) in large-sized ones. The results concern the throughput satisfaction rate, the spectrum spatial reuse, and the convergence time metrics. Abbas Antoun Hatoum, Nadjib Aitsaadi, Rami Langar, Raouf Boutaba, Guy Pujolle |
ICC | 4 |
| 2011 | Performance analysis in Intrusion Detection and Prevention SystemsabstractIntrusion Detection and/or Prevention Systems (IDPS) represent an important line of defense against a variety of attacks that can compromise the security and proper functioning of an enterprise information system. Although many IDPS systems have been proposed, their appropriate configuration and control for effective attacks detection/prevention and efficient resources consumption has always been challenging. The evaluation of the IDPS performance for any given security configuration is a crucial step for improving real-time capability. This paper aims to analyze the impact of security enforcement levels on the performance and usability of an enterprise information system. We develop a new analytical model to investigate the relationship between the IDPS performance and the rules mode selection. In particular, we analyze the IDPS rule-checking process along with its consequent action (i.e., alert or drop) on the resulting security of the network, and on the average service time per event. Simulation was conducted to validate our performance analysis study. Our results show that applying different sets of rules categories and configuration parameters impacts average service time and affects system security. The results demonstrate that it is desirable to strike a balance between system security and network performance. Khalid Alsubhi, Nizar Bouabdallah, Raouf Boutaba |
Integrated Network Management | 3 |
| 2011 | Message from the IWCMC 2011 chairsabstractOn behalf of the Technical Program Committee, we welcome all of you to the IEEE International Wireless Communications and Mobile Computing Conference (IEEE IWCMC 2011) in the beautiful campus of Bahcesehir University, Istanbul, Turkey! We are indeed delighted that this year's IEEE IWCMC accomplishes its goal under the conference theme “Making Wireless Communities,” and continues its tradition of providing the premier forum for presentation of research results and experience reporting on the cutting edge research in the general areas of wireless communications and mobile computing. This year, we received more than 1000 submissions from 51 countries worldwide. Each paper received at least three peer technical reviews, comprised of 49 Symposia Chairs/Co-Chairs and a total of more than 450 TPC members from academia, government laboratories, and industries. After carefully examining all the received review reports, the IEEE IWCMC 2011 TPC finally selected about 35% high-quality papers for presentation at the conference and publication in the IEEE IWCMC 2011 proceedings. The conference program starts on Monday July 4thwith a full day Tutorials that is free of charge to all our attendees. Then, each day starts with a keynote speaker chosen from renowned world-class leaders in the area-Dr. Rick Stevens, Dr. Mario Gerla, and Dr. Sajal Das, highlighting the latest research trends in the wireless communications, mobile computing, and networks. This year, the technical sessions reflect the continued and growing interests in a wide range of spectrum, including wireless communications and networks, cross-layer design and optimization, mobile computing, wireless sensor networks, network security, and use of wireless technologies in social emergency applications. We also added a special Workshop this year to address practical aspects of Wireless Communications and Mobile Computing, such as Multihop Wireless Network Testbeds and Experiments, Network and Communications for Advanced Society, and Federated Wireless Sensor Systems (FedSenS). There are five special sessions composed of invited papers from renowned experts from around the world. Outstanding papers will be selected for four Special Issues in well known international journals. Our objective in the future is to reduce the acceptance rate further to reach 30% and less. In addition, we would like to reduce the number of Symposia and Workshops as well to meet the conference theme. Khaled Ben Letaief, Mario Gerla, Ahmed Helmy, Sajal K. Das 0001, Raouf Boutaba, Mohsen Guizani |
IWCMC | 5 |
| 2011 | Persistent naming for P2P Web hostingabstractThe peer-to-peer paradigm has great potential of contributing to the next generation web-hosting infrastructure. Profound advancements in P2P technologies in the last decade have proven their capability to provide the same functionality as traditional client-server systems at a much larger scale and much lower cost. Existing centralized website hosting technology has a number of inherent deficiencies, including: scalability issues; single point of failure; administrative overhead; and hosting expenses. P2P Web hosting can effectively address these problems and open a new era for the next generation web technology. Unlike the current web however, peer availability and content placement are highly dynamic in P2P networks. This dynamism raises a number of research challenges related to naming, indexing, searching and hosting in P2P environments. In this paper we identify the practical requirements for devising a persistent naming scheme for P2P web-hosting on top of highly dynamic non-persistent P2P networks and present a novel naming architecture for satisfying these requirements. Md. Faizul Bari, Md. Rakibul Haque, Reaz Ahmed, Raouf Boutaba, Bertrand Mathieu |
Peer-to-Peer Computing | 4 |
| 2011 | QoS capacity of virtual wireless networks
Brent Ishibashi, Nizar Bouabdallah, Raouf Boutaba |
Comput. Networks | 3 |
| 2011 | Recent Advances in Network Convergence
Peter Rost, Raouf Boutaba, Klaus Doppler, Ashwin Gumaste |
Comput. Networks | 2 |
| 2011 | Performance of Cognitive Radio-Based Wireless Mesh NetworksabstractCognitive radio presents a new approach to wireless spectrum utilization and management. In this work, the potential performance improvement gained by applying cognitive radio to wireless mesh networks is investigated. Specifically, the potential benefits in terms of QoS provided to users and the efficiency of resource utilization are quantified in a system consisting of a collection of one or more service provider wireless networks. To achieve this, we formulate the problem mathematically using integer linear programming. It is shown that the cognitive radio abilities provide an advantage over the classical network, either by improving QoS through increasing the probability of accepting connection requests, or by reducing the resources needed to fulfill the QoS requirements of users. This advantage is gained without impacting the service of primary clients. More importantly, we show that virtual wireless networks can be created, utilizing only the residual wasted bandwidth of the primary service providers. These virtual networks are able to support large volumes of users, while still ensuring that QoS reliability requirements, such as acceptance probability guarantees, are achieved. Nizar Bouabdallah, Brent Ishibashi, Raouf Boutaba |
IEEE Trans. Mob. Comput. | 3 |
| 2011 | Dirichlet-Based Trust Management for Effective Collaborative Intrusion Detection NetworksabstractThe accuracy of detecting intrusions within a Collaborative Intrusion Detection Network (CIDN) depends on the efficiency of collaboration between peer Intrusion Detection Systems (IDSes) as well as the security itself of the CIDN. In this paper, we propose Dirichlet-based trust management to measure the level of trust among IDSes according to their mutual experience. An acquaintance management algorithm is also proposed to allow each IDS to manage its acquaintances according to their trustworthiness. Our approach achieves strong scalability properties and is robust against common insider threats, resulting in an effective CIDN. We evaluate our approach based on a simulated CIDN, demonstrating its improved robustness, efficiency and scalability for collaborative intrusion detection in comparison with other existing models. Carol J. Fung, Jie Zhang 0002, Issam Aib, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2010 | Effective acquaintance management for Collaborative Intrusion Detection NetworksabstractAn effective Collaborative Intrusion Detection Network (CIDN) allows distributed Intrusion Detection Systems (IDSes) to collaborate and share their knowledge and opinions about intrusions, to enhance the overall accuracy of intrusion assessment as well as the ability of detecting new classes of intrusions. Towards this goal, we propose a distributed Host-based IDS (HIDS) collaboration system, particularly focusing on acquaintance management where each HIDS selects and maintains a list of collaborators from which they can consult about intrusions. More specifically, each HIDS evaluates both the false positive (FP) rate and false negative (FN) rate of its neighboring HIDSes' opinions about intrusions using Bayesian learning, and aggregates their opinions about intrusions using a Bayesian decision model. Our dynamic acquaintance management algorithm allows each HIDS to effectively select a set of collaborators. We evaluate our system based on a simulated collaborative HIDS network. The experimental results demonstrate the convergence, stability and incentive of our system. Carol J. Fung, Jie Zhang 0002, Raouf Boutaba |
CNSM | 3 |
| 2010 | Near optimal demand-side energy management under real-time demand-response pricingabstractIn this paper, we present demand-side energy management under real-time demand-response pricing as a task scheduling problem which is NP-hard. Using minmax as the objective, we show that the schedule produced by our minMax scheduling algorithm has a number of salient advantages: significant peak-shaving, cost reduction, and risk-aversion for the consumers. We prove that our algorithm finds near-optimal solutions and our simulation study show that the actual performance is better than the worst-case bound. The algorithm is simple to implement and efficient at the scale of large enterprises. Jin Xiao 0005, Jae Yoon Chung, Jian Li 0024, Raouf Boutaba, James Won-Ki Hong |
CNSM | 4 |
| 2010 | Towards Efficient Use of Radio Resources in Single Channel Wireless Mesh NetworksabstractIn this paper, we address the radio resource utilization efficiency in single channel wireless mesh networks (WMNs) while considering the mobility of users and when multiple simultaneous connections on the same channel exist in the network. To achieve this, we use clustering. We first identify through analytical models and simulations the cases where clustering is helpful. Building on these results, we propose two clustering schemes that take into consideration the mobility properties of users in order to improve the WMN performance. We prove that both schemes can achieve significant gains in terms of radio resource utilization, especially when the number of simultaneous connections in the network increases. Specifically, we show that the first scheme fits better low-connected wireless mesh networks, whereas the second scheme is more suitable for highly-connected networks. Rami Langar, Salsabil Njima, Nizar Bouabdallah, Raouf Boutaba, Guy Pujolle |
GLOBECOM | 4 |
| 2010 | QoS Support in Delay Tolerant Vehicular Ad Hoc NetworksabstractIn this paper, we propose a new intersection-based geographical routing protocol, called delay tolerant routing protocol (DTRP) that adapts to the changes in the local topology within city environments. DTRP is based on an effective selection of road intersections through which a packet must pass to reach the gateway to the Internet. The selection, in such delay tolerant VANETs, is made in a way that maximizes the connectivity probability of the route between mobile nodes and the gateway while maintaining a threshold for the end-to-end delay and the hop count within the network. To achieve this, we formulate the QoS routing problem mathematically as a constrained optimization problem. Specifically, analytical expressions for the connectivity probability as well as the delay and hop count of a route in a two-way road scenario are derived. Then, we propose a genetic algorithm to solve the optimization problem. Numerical and simulation results show that the proposed approach gives optimal or near-optimal solutions and improves significantly the VANETs performance when compared with several prominent routing protocols, such as GPSR, GPCR and OLSR. Hanan Saleet, Rami Langar, Sagar Naik, Raouf Boutaba, Amiya Nayak, Nishith Goel |
GLOBECOM | 4 |
| 2010 | Interferer Link-Aware Routing in Wireless Mesh NetworksabstractThis paper presents a new metric for routing in wireless mesh networks (WMNs). The proposed metric does not only consider the quality of wireless links to choose a high throughput path between a pair of nodes, but it also includes the resulting interference introduced by using such links. The philosophy behind this metric is to choose a good path for an arriving connection, not necessarily the best in terms of throughput, but that alleviates the resulting interference in order to preserve good paths for the subsequent arriving connections. In doing so, we find that our metric significantly outperforms previously proposed routing metrics when multiple concurrent flows are considered in the network. The total network throughput is indeed increased. Rami Langar, Nizar Bouabdallah, Raouf Boutaba, Guy Pujolle |
ICC | 3 |
| 2010 | Mesh-Based Broadband Home Network Solution: Setup and ExperimentsabstractIn this paper, we investigate architectural and practical issues related to the setup of a broadband home network solution. Our experience led us to the consideration of a hybrid, wireless and wired, Mesh-Network to enable high data rate service delivery everywhere in the home. We demonstrate the effectiveness of our proposal using a real experimental testbed. This latter consists of a multi-hop mesh network composed of a home gateway and "extenders" supporting several types of physical connectivity including PLC, WiFi, and Ethernet. The solution also includes a layer 2 implementation of the OLSR protocol for path selection. We developed an extension of this protocol for QoS assurance and to enable the proper execution of existing services. We have also implemented a fast WiFi handover algorithm to ensure service continuity in case of user mobility among the extenders inside the home. Djamal-Eddine Meddour, Abdesselem Kortebi, Raouf Boutaba |
ICC | 3 |
| 2010 | A Distributed Sequential Algorithm for Collaborative Intrusion Detection NetworksabstractCollaborative intrusion detection networks are often used to gain better detection accuracy and cost efficiency as compared to a single host-based intrusion detection system (IDS). Through cooperation, it is possible for a local IDS to detect new attacks that may be known to other experienced acquaintances. In this paper, we present a sequential hypothesis testing method for feedback aggregation for each individual IDS in the network. Our simulation results corroborate our theoretical results and demonstrate the properties of cost efficiency and accuracy compared to other heuristic methods. The analytical result on the lower-bound of the average number of acquaintances for consultation is essential for the design and configuration of IDSs in a collaborative environment. Quanyan Zhu, Carol J. Fung, Raouf Boutaba, Tamer Basar |
ICC | 3 |
| 2010 | Efficient Active Probing for Fault Diagnosis in Large Scale and Noisy NetworksabstractActive probing is an effective tool for monitoring networks. By measuring probing responses, we can perform fault diagnosis actively and efficiently without instrumentation on managed entities. In order to reduce the traffic generated by probing messages and the measurement infrastructure costs, an optimal set of probes is desirable. However, the computational complexity for obtaining such an optimal set is very high. Existing works assume single-fault scenarios, apply only to small size networks, or use simplistic methods that are vulnerable to noises. In this paper, by exploiting the conditionally independent property in Bayesian networks, we prove a theorem on the information provided by a set of probes. Based on this theorem and structure property of Bayesian networks, we propose two approaches which can effectively reduce the computation time. A highly efficient adaptive probing algorithm is then presented. Compared with previous techniques, experiments have shown that our approach is more efficient in selecting an optimal set of probes without degrading diagnosis quality in large scale and noisy networks. Lu Cheng 0002, Xuesong Qiu 0001, Luoming Meng, Raouf Boutaba |
INFOCOM | 5 |
| 2010 | Cross layer optimization architecture for video streaming in WIMAX networksabstractIn this paper, we propose a cross layer optimizer named XLO between scalable video streaming application and IEEE 802.16 MAC layer. The main objective is to allow video streaming application to adapt its parameters according to 802.16 MAC layer conditions and resource availability. XLO uses the existing service flow management messages exchanged between base station (BS) and subscriber station (SS) and makes them available to the video streaming application via a specific XLO interface. We implemented the XLO in the QualNet simulator and performed extensive simulations using a personalized scalable video traffic generator, capable of streaming video with different data rates. We also introduce an enhanced admission control function at the BS that takes into account video adaptability property. The simulation results show the effectiveness of our XLO mechanism for delivering better quality of service. Alaeddine Abdallah Djamal, Djamal-Eddine Meddour, Toufik Ahmed, Raouf Boutaba |
ISCC | 4 |
| 2010 | Topology-Awareness and Reoptimization Mechanism for Virtual Network Embedding
Nabeel Farooq Butt, Mosharaf Chowdhury, Raouf Boutaba |
Networking | 3 |
| 2010 | Survivable Virtual Network Embedding
Muntasir Raihan Rahman, Issam Aib, Raouf Boutaba |
Networking | 3 |
| 2010 | Dynamic Service Placement in Shared Service Hosting Infrastructures
Qi Zhang 0008, Jin Xiao 0005, Eren Gürses, Martin Karsten, Raouf Boutaba |
Networking | 5 |
| 2010 | Bayesian decision aggregation in collaborative intrusion detection networksabstractCooperation between intrusion detection systems (IDSs) allow collective information and experience from a network of IDSs to be shared for improving the accuracy of detection. A critical component of a collaborative network is the mechanism of feedback aggregation in which each IDS makes an overall security evaluation based on peer opinions and assessments. In this paper, we propose a collaboration framework for intrusion detection networks (CIDNs) and use a Bayesian approach for feedback aggregation by minimizing the combined costs of missed detection and false alarm. The proposed model is highly scalable, robust, and cost effective. Experimental results demonstrate an improvement in the true positive detection rate and a reduction in the average cost of our mechanism compared to existing models. Carol J. Fung, Quanyan Zhu, Raouf Boutaba, Tamer Basar |
NOMS | 3 |
| 2010 | Business-driven management of differentiated servicesabstractSeveral intra- and inter-domain quality of service (QoS) provisioning mechanisms for IP networks have been researched and developed using Differentiated Services (DiffServ) technology. However, the incremental efforts needed to manage DiffServ networks from a business-oriented viewpoint have received relatively little attention. This paper addresses this gap and presents a framework for achieving business-driven QoS provisioning in DiffServ over MPLS networks. We provide a rich model of SLA and business indicators as well as reasonable mapping functions that define, with key degrees of importance, the impact of business indicators over service management policies. Business and service indicators are used to control static and dynamic admission of services. The paper advances the state of the art by considering the influence of business-level objectives on the policy refinement process. We evaluate and discuss the effectiveness of our approach through a simulation environment that we developed over OPNET. Javier Rubio-Loyola, Marinos Charalambides, Issam Aib, Joan Serrat 0001, George Pavlou, Raouf Boutaba |
NOMS | 6 |
| 2010 | Multi-provider service negotiation and contracting in network virtualizationabstractNetwork virtualization environment (VNE) affords great business flexibility to the customers and the providers as multiple providers can jointly support a customer's virtual network. Under the current network model, a group of Infrastructure Providers (InPs) peer with each other to provide a packaged deal. Such a business arrangement is not customer-driven, does not promote fair market competition and does not ensure cost minimization. Furthermore, the on-demand nature of virtual networks requires efficient and automated service negotiation and contracting. In this paper, we present V-Mart. To the InPs, V-Mart offers an environment to participate in a faithful and fair competition over the VN resources; and to the SPs, it offers a customer-driven virtual resource partitioning and contracting engine. V-Mart uses a two-stage Vickrey auction model that is strategy-proof, flexible to diverse InP pricing models, and functions over heterogenous multi-commodity market that characterizes the NVE. Through analysis and simulation we show the flexibility and effectiveness of V-Mart. Fida-E. Zaheer, Jin Xiao 0005, Raouf Boutaba |
NOMS | 3 |
| 2010 | Special issue on "Wireless Multi-Hop Networking for Infrastructure Access"
Raouf Boutaba, Seán Murphy, Albert Banchs |
Comput. Networks | 1 |
| 2010 | A survey of network virtualization
Mosharaf Chowdhury, Raouf Boutaba |
Comput. Networks | 2 |
| 2010 | Recent advances in autonomic communications [Guest Editorial]abstractThe nine papers in this special issue focus on recent advances in autonomic communications. This issue addresses four areas in which autonomics play a central role: network architectures, traffic management, monitoring, and resource management. Raouf Boutaba, Jean-Philippe Martin-Flatin, Joseph L. Hellerstein, Randy H. Katz, George Pavlou, Chin-Tau A. Lea |
IEEE J. Sel. Areas Commun. | 1 |
| 2010 | Farewell MessageabstractThis is my Farewell Message as Editor-in-Chief of the IEEE Transactions on Network and Service Management (TNSM). I have been involved with TNSM since its inception as the founding Editor-in-Chief and would like to use this editorial to provide a brief history of the journal, summarize what has been achieved in the past seven years, pass the baton to the next Editor-in-Chief, and finally acknowledge those who helped in bringing the journal to where it is today. Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2010 | Design and Analysis of Mobility-Aware Clustering Algorithms for Wireless Mesh NetworksabstractOne of the major concerns in wireless mesh networks (WMNs) is the radio resource utilization efficiency, which can be enhanced by efficiently managing the mobility of users. To achieve this, we propose in this paper the use of mobility-aware clustering. The main idea behind WMN clustering is to restrict a major part of the exchanged signaling messages due to the mobility of users to a local area (i.e., inside a cluster). As such, less wireless links are used by the signaling messages, which reduces the resources occupied by a mobile user during its service and thus improves the total network capacity. Through analytical models and simulations, this work first identifies the cases where clustering is helpful. Building on these results, we propose two clustering schemes that take into consideration the mobility properties of the users in order to improve the WMN performance. We prove that both schemes can achieve significant gains in terms of radio resource utilization. Specifically, we show that the first scheme fits better both large and low-connected wireless mesh networks, whereas the second scheme is more suitable for both small to moderate and highly connected networks. Nizar Bouabdallah, Rami Langar, Raouf Boutaba |
IEEE/ACM Trans. Netw. | 3 |
| 2010 | Assessing Software Service Quality and Trustworthiness at Selection TimeabstractThe integration of external software in project development is challenging and risky, notably because the execution quality of the software and the trustworthiness of the software provider may be unknown at integration time. This is a timely problem and of increasing importance with the advent of the SaaS model of service delivery. Therefore, in choosing the SaaS service to utilize, project managers must identify and evaluate the level of risk associated with each candidate. Trust is commonly assessed through reputation systems; however, existing systems rely on ratings provided by consumers. This raises numerous issues involving the subjectivity and unfairness of the service ratings. This paper describes a framework for reputation-aware software service selection and rating. A selection algorithm is devised for service recommendation, providing SaaS consumers with the best possible choices based on quality, cost, and trust. An automated rating model, based on the expectancy-disconfirmation theory from market science, is also defined to overcome feedback subjectivity issues. The proposed rating and selection models are validated through simulations, demonstrating that the system can effectively capture service behavior and recommend the best possible choices. Noura Limam, Raouf Boutaba |
IEEE Trans. Software Eng. | 2 |
| 2009 | Capacity of Wireless Multi-hop Networks Using Physical Carrier Sense and Transmit Power ControlabstractIn this paper, we investigate the capacity of CSMA (carrier sense multiple access) based wireless multi-hop networks with random topologies described by the hop length distribution. First we develop an analytical model for the effective link capacity as a function of transmit power adaptation policy, physical carrier sense threshold, hop length distribution and medium access probability of p-persistent CSMA. Secondly, we devise an optimal transmit power control scheme that maximizes the network capacity by adjusting the transmit power and the corresponding physical carrier sense threshold. Thereafter, it is extended for the joint optimization of these parameters with the medium access probability of CSMA. Finally we compare the optimal power control scheme with the minimum transmit power policy in. Results show that the proposed power control scheme optimally trades off the spatial reuse (number of interfering links) to the link SIR (signal-to-interference ratio) and achieves an amount of ~%15 increase in network capacity when both schemes employ joint optimization. Eren Gürses, Raouf Boutaba |
GLOBECOM | 2 |
| 2009 | Adaptive Message Routing with QoS Support in Vehicular Ad Hoc NetworksabstractAs progress in VANETs research continues, there is a persuasive need to support Quality of Service (QoS) routing in such networks. While greedy forwarding is used in many MANETs applications, it is found that it is not convenient for VANETs applications. In this paper, we investigate the important and difficult challenge of QoS routing in VANETs. First, we present an adaptive message routing protocol that uses up to date information about the local topology in order to find the route with minimum end-to-end delay while maintaining a threshold for the connectivity probability and hop count. Then, we propose a genetic algorithm to solve this. To do so, we formulate the QoS routing as a constrained optimization problem. We also derive analytical expressions for the delay as well as the connectivity probability of a route in a two-way street scenario. Numerical and simulation results show that our algorithm gives an optimal or near optimal solutions, which provides an interactive and effective design environment and enriches our protocol performance compared to GPCR. Hanan Saleet, Rami Langar, Otman A. Basir, Raouf Boutaba |
GLOBECOM | 4 |
| 2009 | Policy-Based Security Configuration Management, Application to Intrusion Detection and PreventionabstractIntrusion detection and/or prevention systems (IDPS) represent an important line of defense against the variety of attacks that can compromise the security and well functioning of an enterprise information system. IDPSes can be network or host-based and can collaborate in order to provide better detections of malicious traffic. Although several IDPS systems have been proposed, their appropriate configuration and control for effective detection and prevention of attacks has always been far from trivial. Another concern is related to the slowing down of system performance when maximum security is applied, hence the need to trade off between security enforcement levels and the performance and usability of an enterprise information system. In this paper we motivate the need for and present a policy-based framework for the configuration and control of the security enforcement mechanisms of an enterprise information system. The approach is based on dynamic adaptation of security measures based on the assessment of system vulnerability and threat prediction and provides several levels of attack containment. As an application, we have implemented a dynamic policy-based adaptation mechanism between the Snort signature-based IDPS and the light weight anomaly-based FireCollaborator IDS. Experiments conducted over the DARPA 2000 and 1999 intrusion detection evaluation datasets show the viability of our framework. Khalid Alsubhi, Issam Aib, Jérôme François, Raouf Boutaba |
ICC | 4 |
| 2009 | Cross-Layer Design for Energy Conservation in Wireless Sensor NetworksabstractWireless sensor networks (WSNs) require energy- efficient protocols to improve the network lifetime. In this work, we adopt a cross-layer strategy that considers routing and MAC layers jointly. At the routing layer, we propose balancing the traffic through the WSN. We show that sending the traffic generated by each sensor node through multiple paths instead of using a single path allows significant energy conservation. On the other hand, at the MAC layer, we propose to control the retry limit of retransmissions over each wireless link. We show that by efficiently adjusting the retry limit for each link, further energy conservation can be achieved, improving thus the network lifetime. A new analytical model for the joint optimization system is complemented by simulations in order to quantitatively evaluate the benefits of our proposal. Fatma Bouabdallah, Nizar Bouabdallah, Raouf Boutaba |
ICC | 3 |
| 2009 | Distributed Quality-Lifetime Maximization in Wireless Video Sensor NetworksabstractOwing to the availability of low-cost and low-power CMOS cameras, wireless video sensor networks (WVSN) has recently become a reality. However video encoding is still a costly process for energy and capacity constrained sensor nodes and its optimal joint control with the communication protocols has a direct impact on the network lifetime. In this paper we propose a distributed quality-lifetime control algorithm where quality is simply measured by the visual signal quality. In order to formulate the quality-lifetime problem, we consider the power-rate-distortion (P-R-D) model of the video encoder together with the rate control, medium access and routing functions of the underlying communication protocol and formulate the problem as a generalized network utility maximization (GNUM) problem. Then we construct a distributed solution based on duality and proximal point methods with necessary convergence analysis. Simulation results support that optimal quality-lifetime control is possible through the proposed distributed algorithm, where the desired point of operation is simply adjusted by the sink via a configuration parameter. Eren Gürses, Raouf Boutaba |
ICC | 3 |
| 2009 | Service Engineering for Inter-Domain Overlay NetworksabstractIn recent years application-level networking (e.g. overlay networks, P2P networks) has become key enabling architecture for supporting distributed services on the Internet. We consider overlays to have delay and cost requirements and thus there exists an optimal distribution of the overlay traffic (the service engineering problem) across multi-domain underlay networks such that these requirements can be satisfied while achieving fairness among the overlays. To this end, we formulate the problem as a convex optimization problem and propose a distributed solution. We show the efficiency and effectiveness of our approach through simulation studies. Eren Gürses, Jin Xiao 0005, Raouf Boutaba |
ICC | 3 |
| 2009 | A Distributed Approach for Location Lookup in Vehicular Ad Hoc NetworksabstractEfficient location management is one of the major challenges in vehicular ad hoc networks (VANETs). Due to the high mobility of vehicles and the increase in their number, the location information updating and querying messages will consume the limited bandwidth of VANETs. This involves the development of a scalable and locality-aware location service management protocol. In this paper, we propose a promising solution called the modified region-based location service management protocol (MRLSMP), which utilizes the existing infrastructure on the road as a location management service entity. To evaluate the efficiency of our proposal, we compare our scheme with existing solutions using both analytical and simulation approaches. Specifically, we develop analytical models to evaluate the total control overhead. Numerical and simulation results show that our protocol scales better than existing schemes, when increasing the size of VANETs which enhances the feasibility of such large scale ad hoc networks. Hanan Saleet, Rami Langar, Otman A. Basir, Raouf Boutaba |
ICC | 4 |
| 2009 | Impact of Gateways Placement on Clustering Algorithms in Wireless Mesh NetworksabstractAbstract—In wireless mesh networks, designing algorithms that efficiently balance the traffic loads among a given set of network gateways is a challenging problem. Links interfere, transfer capacity is limited, and traffic demands vary overtime. The position of the gateways also affects the overall network performance as a result of its direct impact on the way routers are associated to gateways. In this paper, we investigate the performance of several routers-to-gateways association heuristics in relation with different gateway placement algorithms.We show that if bounds on the number of hops between routers and gateways exist, load-based heuristics perform the best. In general cases however, interference-based approaches provide better load balancing. Sonia Waharte, Raouf Boutaba, Pascal Anelli |
ICC | 2 |
| 2009 | Characterization and Solution to a Stateful IDS EvasionabstractWe identify a new type of stateful IDS evasion, named signature evasion. We formalize the signature evasion on those Stateful IDSs whose state can be modeled using Deterministic Finite State Automata (DFAs). We develop an efficient algorithm which operates on rule set DFAs and derives a minimal rectification of evasive paths. Finally, we evaluate our solution on Snort signatures, identify and rectify existing vulnerable flowbit rule sets. Issam Aib, Tung Tran 0002, Raouf Boutaba |
ICDCS | 3 |
| 2009 | iMark: An identity management framework for network virtualization environmentabstractNetwork virtualization has been propounded as an open and flexible future internetworking paradigm that allows multiple virtual networks (VNs) to co-exist on a shared physical substrate. Each VN in a network virtualization environment (NVE) is free to implement its own naming, addressing, routing, and transport mechanisms. While such flexibility allows fast and easy deployment of diversified applications and services, ensuring end-to-end communication and universal connectivity poses a daunting challenge. This paper advocates that effective and efficient management of heterogeneous identifier spaces is the key to solving the problem of end-to-end connectivity in an NVE. We propose iMark, an identity management framework based on a global identity space, which enables end hosts to communicate with each other within and outside of their own networks through a set of controllers, adapters, and well-placed mappings without sacrificing the autonomy of the concerned VNs. We describe the procedures that manipulate these mappings between different identifier spaces and provide performance evaluation of the proposed framework. Mosharaf Chowdhury, Fida-E. Zaheer, Raouf Boutaba |
Integrated Network Management | 3 |
| 2009 | Robust and scalable trust management for collaborative intrusion detectionabstractThe accuracy of detecting intrusions within an intrusion detection network (IDN) depends on the efficiency of collaboration between the peer intrusion detection systems (IDSes) as well as the security itself of the IDN against insider threats. In this paper, we study host-based IDNs and introduce a Dirichlet-based model to measure the level of trustworthiness among peer IDSes according to their mutual experience. The model has strong scalability properties and is robust against common insider threats, such as a compromised or malfunctioning peer. We evaluate our system based on a simulated collaborative host-based IDS network. The experimental results demonstrate the improved robustness, efficiency, and scalability of our system in detecting intrusions in comparison with existing models. Carol J. Fung, Jie Zhang 0002, Issam Aib, Raouf Boutaba |
Integrated Network Management | 4 |
| 2009 | Virtual Network Embedding with Coordinated Node and Link MappingabstractRecently network virtualization has been proposed as a promising way to overcome the current ossification of the Internet by allowing multiple heterogeneous virtual networks (VNs) to coexist on a shared infrastructure. A major challenge in this respect is the VN embedding problem that deals with efficient mapping of virtual nodes and virtual links onto the substrate network resources. Since this problem is known to be NP-hard, previous research focused on designing heuristic-based algorithms which had clear separation between the node mapping and the link mapping phases. This paper proposes VN embedding algorithms with better coordination between the two phases. We formulate the VN embedding problem as a mixed integer program through substrate network augmentation. We then relax the integer constraints to obtain a linear program, and devise two VN embedding algorithms D-ViNE and R-ViNE using deterministic and randomized rounding techniques, respectively. Simulation experiments show that the proposed algorithms increase the acceptance ratio and the revenue while decreasing the cost incurred by the substrate network in the long run. Mosharaf Chowdhury, Muntasir Raihan Rahman, Raouf Boutaba |
INFOCOM | 3 |
| 2009 | Adaptive Early Packet Filtering for Defending Firewalls Against DoS AttacksabstractA major threat to data networks is based on the fact that some traffic can be expensive to classify and filter as it will undergo a longer than average list of filtering rules before being rejected by the default deny rule. An attacker with some information about the access-control list (ACL) deployed at a firewall or an intrusion detection and prevention system (IDS/IPS) can craft packets that will have maximum cost. In this paper, we present a technique that is light weight, traffic-adaptive and can be deployed on top of any filtering mechanism to pre-filter unwanted expensive traffic. The technique utilizes Internet traffic characteristics coupled with a special carefully tuned representation of the policy to generate early defense policies. We use Boolean expressions built as binary decision diagrams (BDD) to represent relaxed versions of the policy that are faster to evaluate. Moreover, it is guaranteed that the technique will not add an overhead that will not be compensated by the gain in filtering time in the underlying filtering method. Evaluation has shown considerable savings to the overall filtering process, thus saving the firewall processing power and increasing overall throughput. Also, the overhead changes according to the traffic behavior, and can be tuned to guarantee its worst case time cost. Adel El-Atawy, Ehab Al-Shaer, Tung Tran 0002, Raouf Boutaba |
INFOCOM | 4 |
| 2009 | QPM: Phonetic Aware P2P SearchingabstractEfficient discovery of information based on partially specified and misspelled query keywords is a challenging problem in large scale peer-to-peer (P2P) networks. This paper presents QPM, a P2P search mechanism for efficient information retrieval with misspelled and partial keywords. QPM uses the double metaphone algorithm to phonetically match misspelled query keywords with advertised keywords. For achieving bandwidth efficiency and similarity matching, QPM incorporates second order Reed-Muller code within the Plexus protocol having a logarithmic routing efficiency on overlay network size. QPM supports large scale networks and achieves better resilience to peer failure by maintaining redundant routing paths and by systematically placing index replicas. The concept presented in this paper is supported by necessary experimental evaluation. Md. Rakibul Haque, Reaz Ahmed, Raouf Boutaba |
Peer-to-Peer Computing | 3 |
| 2009 | A Heuristic for Fair Correlation-Aware Resource Placement
Raouf Boutaba, Martin Karsten, Maxwell Young |
SEA | 1 |
| 2009 | Mobility-aware clustering algorithms with interference constraints in wireless mesh networks
Rami Langar, Nizar Bouabdallah, Raouf Boutaba |
Comput. Networks | 3 |
| 2009 | Design and Performance Evaluation of IAR: Interference-Aware Routing Metric for Wireless Mesh Networks
Sonia Waharte, Brent Ishibashi, Raouf Boutaba, Djamal-Eddine Meddour |
Mob. Networks Appl. | 3 |
| 2009 | A contribution-based service differentiation scheme for peer-to-peer systems
Loubna Mekouar, Youssef Iraqi, Raouf Boutaba |
Peer-to-Peer Netw. Appl. | 3 |
| 2009 | Plexus: a scalable peer-to-peer protocol enabling efficient subset search
Reaz Ahmed, Raouf Boutaba |
IEEE/ACM Trans. Netw. | 2 |
| 2009 | Proposal and analysis of adaptive mobility management in ip-based mobile networksabstractEfficient mobility management is one of the major challenges for next-generation mobile systems. Indeed, a mobile node (MN) within an access network may cause excessive signaling traffic and service disruption due to frequent handoffs. The two latter effects need to be minimized to support quality of service (QoS) requirements of emerging multimedia applications. In this paper, we propose a new adaptive micromobility management scheme designed to track efficiently the mobility of nodes so as to minimize both handoff latency and total signaling cost while ensuring the MN's QoS requirements. We introduce the concept of residing area. Accordingly, the micromobility domain is divided into virtual residing areas where the MN limits its signaling exchanges within this local region instead of communicating with the relatively far away root of the domain at each handoff occurrence. A key distinguishing feature of our solution is its adaptive nature since the virtual residing areas are constructed according to the current network state and the QoS constraints. To evaluate the efficiency of our proposal, we compare our scheme with existing solutions using both analytical and simulation approaches for the 2-D random walk model as well as real mobility patterns. Numerical and simulation results show that our proposed scheme can significantly reduce registration updates and link usage costs and provide low handoff latency and packet loss rate under various scenarios. Rami Langar, Nizar Bouabdallah, Raouf Boutaba, Bruno Sericola |
IEEE Trans. Wirel. Commun. | 3 |
| 2008 | Analysis of the latency-lifetime tradeoff in wireless sensor networksabstractEnergy conservation is a primary concern in wireless sensor networks due to the limited capacity of the sensor nodes' batteries. In this paper, we study the relationship between sensor networks performance, particularly its lifetime, and the number of reporting nodes N by using both analytical and simulation approaches. We first show that decreasing N increases considerably the network lifetime. Moreover, we demonstrate that the average time required to report an event is a convex function of N. Based on these results, and as a main contribution, we prove that the optimal number of reporting nodes enabling the shortest latency to report reliably an event does not really lead to the most efficient way of energy consumption. In this paper, we analyze the tradeoff between these two requirements. We provide a simple methodology to achieve this tradeoff which is specific to each sensor application, depending on its particular needs. Fatma Bouabdallah, Nizar Bouabdallah, Raouf Boutaba |
AICCSA | 3 |
| 2008 | Performance study of wireless mesh networks routing metricsabstractMultihop wireless mesh networks are an attractive solution for providing last-mile connectivity. However, the shared nature of the transmission medium makes it challenging to fully exploit these networks. In an attempt to improve the radio resource utilization, several muting metrics have been specifically designed for wireless mesh networks. However, although some evaluations have been conducted to assess the performance of these metrics in some contrived scenarios, no overall comparison has been performed. We therefore studied the performance of the most popular routing metrics currently used in wireless mesh networks; Hop Count, Blocking Metric, Expected Tran- mission Count (ETX), Expected Transmission Tune (ETT), Modified ETX (mETX), Network Allocation Vector Count (NAVC) and Metric of Inteiference and Channel-Switching (MIC). We showed under various simulation scenarios that although all the metrics except NAVC offer the same end- to-end delay and packet loss ratio, differences can he distinguished in terms of traffic load repartition. In particular, the congestion-avoidance strategies of ETX, mETX, and MIC prevent the starvation of flows following longer paths and consequently provide a more uniform traffic repartition. Sonia Waharte, Brent Ishibashi, Raouf Boutaba, Djamal-Eddine Meddour |
AICCSA | 3 |
| 2008 | Load-Balanced Routing Scheme for Energy-Efficient Wireless Sensor NetworksabstractWireless sensor networks (WSNs) require appropriate protocols that make judicious use of the finite energy resources of the sensor nodes. In this paper, we investigate the potential energy conservation achieved by balancing the traffic throughout the WSN. We show that distributing the traffic generated by each sensor node through multiple paths instead of using a single path allows significant energy savings. In order to quantitatively evaluate the benefits of the proposed load balancing technique, a new analytical model for load-balanced systems is elaborated and approved by simulations. Fatma Bouabdallah, Nizar Bouabdallah, Raouf Boutaba |
GLOBECOM | 3 |
| 2008 | Proposal and Analysis of Region-Based Location Service Management Protocol for VANETsabstractOne of the major challenges for vehicular ad hoc networks (VANETs) is related to efficient location management issue. In this paper, we propose a new region-based location service management protocol (RLSMP) that uses mobility patterns as means to synthesize vehicle movement and thus can be used in VANETs applications. One of the key distinguishing features of our solution from existing literature is its scalability since it uses message aggregation in both updating and querying, and promises locality awareness as well as minimum signaling overhead. To evaluate the efficiency of our proposal, we compare our scheme with existing solutions using both analytical and simulation approaches. To achieve this, we develop analytical models to evaluate the location updates cost. Numerical and simulation results show that our protocol scales better than existing schemes, when increasing the size of VANET which enhances the feasibility of such large scale ad hoc networks. Hanan Saleet, Rami Langar, Otman A. Basir, Raouf Boutaba |
GLOBECOM | 4 |
| 2008 | Nonlinear Quadratic Pricing for Concavifiable Utilities in Network Rate ControlabstractThis paper deals with a category of concavifiable functions that can be used to model inelastic traffic in the network. Such class of functions can be concavified within an interval of interest using a quadratic pricing term so that we obtain as a result a concave objective function. We use a game- theoretical framework as well as a centralized optimization approach to discuss the heterogeneous network with nonlinear quadratic pricing. We point out the equivalence between these two frameworks and use a Stackelberg player as an extra degree of freedom to design pricing policy for the network. In the end, we propose an auction-like iterative algorithm and illustrate it with a numerical example. Quanyan Zhu, Raouf Boutaba |
GLOBECOM | 2 |
| 2008 | Energy Conservation in Reliable Wireless Sensor NetworksabstractEnergy-efficiency is one of the major concerns in wireless sensor networks since it impacts the network lifetime. In this paper, we investigate the relationship between sensor network performance, particularly its lifetime, and the number of active reporting nodes N by using both analytical and simulation approaches. We first demonstrate that decreasing the number of reporting nodes increases the number of reports that need to be sent to the sink, in order to achieve the desired information reliability regarding the detected event. On the other hand, we show that reducing the number of reporting nodes alleviates the energy wastage due to collisions. Based on this tradeoff, and as a main contribution, we derive the optimal number of reporting nodes Nopt.energythat minimizes the energy consumed to report reliably the occurrence of an event. In other words, we prove that limiting the reporting tasks of a detected event to a small subset of sensor nodes (i.e., Nopt.energy), instead of using all the sensor nodes in the event area, enables significant energy conservation. Fatma Bouabdallah, Nizar Bouabdallah, Raouf Boutaba |
ICC | 3 |
| 2008 | Interference-Aware Routing Metric for Improved Load Balancing in Wireless Mesh NetworksabstractMultihop wireless mesh networks are an attractive solution for providing last-mile connectivity. However, the shared nature of the transmission medium makes it challenging to fully exploit these networks. Nodes interfere with each other, resulting in packet loss and degraded network performance. In this paper, a routing metric specifically designed for WMNs is proposed. The Interference-Aware Routing metric (IAR) uses MAC-level information to measure the share of the channel that each link is able to utilize effectively. As a result, paths are selected that exhibit the least interference. Simulations show that utilizing this metric provides significant performance improvements in terms of end-to-end delay compared to several existing metrics. Sonia Waharte, Brent Ishibashi, Raouf Boutaba, Djamal-Eddine Meddour |
ICC | 3 |
| 2008 | QoS Performance Analysis of Cognitive Radio-Based Virtual Wireless NetworksabstractCognitive radio presents a new approach to wireless spectrum utilization and management. In this work, the potential performance improvement gained by applying cognitive radio to multiple-provider wireless systems is investigated. It is shown that virtual wireless networks can be created, utilizing only the residual wasted bandwidth of the primary service providers. These virtual networks are able to support large volumes of users, while still ensuring that QoS reliability requirements, such as blocking and dropping guarantees, are achieved. A Markov chain-based analysis of classic and cognitive systems is complemented by simulations in order to present a quantified perspective of the potential benefits of cognitive radio techniques. Brent Ishibashi, Nizar Bouabdallah, Raouf Boutaba |
INFOCOM | 3 |
| 2008 | Distributed pattern matching: Concept and applications in internet-scale networks
Raouf Boutaba |
ISCC | 1 |
| 2008 | Distributed search revisited: Resolving the conflict of flexibility and efficiencyabstractPeer-to-peer technology has impacted a wide range of distributed systems beyond simple file-sharing. Distributed XML databases, distributed computing, server-less Web publishing and networked resource/service sharing are only a few to name. Despite the diversity in applications, these systems share a common problem regarding searching and discovery of information. This commonality stems from transitory peer population and volatile peer content. As an effect users do not have the exact information about what they are looking for. Rather queries are based on partial information, which requires the search mechanism to be flexible. On the other hand to scale with network size the search mechanism is also required to be bandwidth efficient. This talk introduces a generic framework called distributed pattern matching to address the search problem in distributed environments while achieving both search flexibility and efficiency. Raouf Boutaba |
LCN | 1 |
| 2008 | On the Probability of Finding Non-interfering Paths in Wireless Multihop Networks
Sonia Waharte, Raouf Boutaba |
Networking | 2 |
| 2008 | Alert prioritization in Intrusion Detection SystemsabstractIntrusion Detection Systems (IDSs) are designed to monitor user and/or network activity and generate alerts whenever abnormal activities are detected. The number of these alerts can be very large; making the task of security analysts difficult to manage. Furthermore, IDS alert management techniques, such as clustering and correlation, suffer from involving unrelated alerts in their processes and consequently provide imprecise results. In this paper, we propose a fuzzy-logic based technique for scoring and prioritizing alerts generated by an IDS(1). In addition, we present an alert rescoring technique that leads to a further reduction of the number of alerts. The approach is validated using the 2000 DARPA intrusion detection scenario specific datasets and comparative results between the Snort IDS alert scoring and our scoring and prioritization scheme are presented. Khalid Alsubhi, Ehab Al-Shaer, Raouf Boutaba |
NOMS | 3 |
| 2008 | Peer-to-Peer networking: State of the art and research challenges
Raouf Boutaba |
NOMS | 1 |
| 2008 | CyberPlanner: A comprehensive toolkit for network service providersabstractWith the increased network size and diversity, and the proliferation in applications and services, the network service providers are faced with a flood of information from many levels of their network and service operations, often in uncorrelated forms. At the same time, the focus of network services is shifting from managing networks to managing services and customers. CyberPlanner is a comprehensive toolkit for the collection, correlation and filtering of metrics at all levels of a network service providerpsilas business. In this paper, we present its concept, modeling methodologies and implementation. Experience gained from CyberPlanner testing and operations in both academic and industrial settings demonstrates its effectiveness and potential in assisting many key provider operations such as customer-oriented trouble diagnostics, network dimensioning and upgrading, service planning and business revenue forecasting. Raouf Boutaba, Jin Xiao 0005, Issam Aib |
NOMS | 1 |
| 2008 | QoS and reputation-aware service selectionabstractThe advent of service-oriented architectures has created a unique opportunity for business providers and consumers to establish more versatile and flexible interactions across the Internet by means of a new generation of services that are discoverable, composable, configurable, and reusable. In order to support such services all along their life cycle, underlying service-oriented infrastructures have to provide various functionalities, including service discovery. In large scale environments, like the Internet, a discovery process may result in a very large number of matching services. Service quality, cost and reputation are substantial aspects for differentiating between similar services. In order to help users select the most appropriate service, an automated service selection algorithm is proposed. The devised algorithm helps to accurately predict service suitability to quality requirements while taking into account the reputation parameter. Noura Limam, Raouf Boutaba |
NOMS | 2 |
| 2008 | Correlation-based load balancing for network intrusion detection and prevention systemsabstractIn large-scale enterprise networks, multiple network intrusion detection and prevention systems are used to provide high quality protections. In this context, keeping load evenly distributed among the systems is crucial. This is because even load distributions provide protection to the networks and improve the networks' quality of service.A challenging problem, however, is to maintain the load balancing of the systems while minimizing the loss of correlation information due to distributing traffic. Since anomaly- based detection and prevention of some intrusions, such as distributed denial of service (DDoS) attacks and port scans, require a single system to analyze correlated flows of the attacks, this loss of correlation information might severely affect the accuracy of the detections and preventions.In this paper, we address this challenging problem by first formalizing the load balancing problem as an optimization problem, considering both the systems' load variance and the correlation information loss. We then present our Benefit-based Load Balancing (BLB) algorithm as a solution to the optimization problem.We have implemented a prototype load-balancer which uses the BLB algorithm. We evaluated the load-balancer against various port scans and DDoS attacks. The evaluation results show that our load-balancer significantly improves the detection accuracy of these attacks while keeping the systems' load close within a desired bound. Raouf Boutaba, Ehab Al-Shaer |
SecureComm | 2 |
| 2008 | The Relationship between Sensor Networks Performance and the Number of Reporting NodesabstractEnergy conservation is a primary concern in wireless sensor networks due to the limited capacity of the sensor nodes' batteries. In this paper, we study the relationship between sensor networks performance, particularly its lifetime, and the number of reporting nodes N by using both analytical and simulation approaches. We first show that decreasing N increases considerably the network lifetime. Moreover, we demonstrate that the average time required to report an event is a convex function of N. Based on these results, and as a main contribution, we prove that the optimal number of reporting nodes enabling the shortest latency to report reliably an event does not really lead to the most efficient way of energy consumption. In this paper, we analyze the tradeoff between these two requirements. We provide a simple methodology to achieve this tradeoff which is specific to each sensor application, depending on its particular needs. Fatma Bouabdallah, Nizar Bouabdallah, Raouf Boutaba |
WCNC | 3 |
| 2008 | Toward Reliable and Efficient Reporting in Wireless Sensor NetworksabstractEnergy-efficiency is one of the major concerns in wireless sensor networks since it impacts the network lifetime. In this paper, we investigate the relationship between sensor network performance, particularly its lifetime, and the number of active reporting nodes N by using both analytical and simulation approaches. We first demonstrate that decreasing the number of reporting nodes increases the number of reports that need to be sent to the sink in order to achieve the desired information reliability regarding a detected event. On an other side, we show that reducing the number of reporting nodes reduces the probability of collision occurrence. Based on these results, and as a first main contribution, we derive the optimal number of reporting nodes Nopt_energy that minimizes the energy consumed to report reliably the occurrence of an event. In other words, we prove that limiting the reporting tasks of a detected event to a small subset of sensor nodes (i.e., Nopt_energy), instead of using all the sensor nodes in the event area, enables significant energy conservation. Fatma Bouabdallah, Nizar Bouabdallah, Raouf Boutaba |
IEEE Trans. Mob. Comput. | 3 |
| 2008 | Meet In the Middle Cross-Layer Adaptation for Audiovisual Content DeliveryabstractThis paper describes a new architecture and implementation of an adaptive streaming system (e.g., television over IP, video on demand) based on cross-layer interactions. At the center of the proposed architecture is the meet in the middle concept involving both bottom-up and top-down cross layer interactions. Each streaming session is entirely controlled at the RTP layer where we maintain a rich context that centralizes the collection of (i) instantaneous network conditions measured at the underlying layers (i.e.: link, network, and transport layers) and (ii) user- and terminal-triggered events that impose new real-time QoS adaptation strategies. Thus, each active multimedia session is tied to a broad range of parameters, which enable it to coordinate the QoS adaptation throughout the protocol layers and thus eliminating the overhead and preventing counter-productiveness among separate mechanisms implemented at different layers. The MPEG-21 framework is used to provide a common support for implementing and managing the end-to-end QoS of audio/video streams. Performance evaluations using peak signal to noise ratio (PSNR) and structural similarity index (SSIM) objective video quality metrics show the benefits of using the proposed Meet In the Middle cross-layer design compared to traditional media delivery approaches. Ismail Djama, Toufik Ahmed, Abdelhamid Nafaa, Raouf Boutaba |
IEEE Trans. Multim. | 4 |
| 2008 | Efficient fault diagnosis using incremental alarm correlation and active investigation for internet and overlay networksabstractFault localization is the core element in fault management. Symptom-fault map is commonly used to describe the symptom-fault causality in fault reasoning. For Internet service networks, a well-designed monitoring system can effectively correlate the observable symptoms (i.e., alarms) with the critical network faults (e.g., link failure). However, the lost and spurious symptoms can significantly degrade the performance and accuracy of a passive fault localization system. For overlay networks, due to limited underlying network accessibility, as well as the overlay scalability and dynamics, it is impractical to build a static overlay symptom-fault map. In this paper, we firstly propose a novel active integrated fault reasoning (AIR) framework to incrementally incorporate active investigation actions into the passive fault reasoning process based on an extended symptom-fault-action (SFA) model. Secondly, we propose an overlay network profile (ONP) to facilitate the dynamic creation of an overlay symptom-fault-action (called O-SFA) model, such that the AIR framework can be applied seamlessly to overlay networks (called O-AIR). As a result, the corresponding fault reasoning and action selection algorithms are elaborated. Extensive simulations and Internet experiments show that AIR and O-AIR can significantly improve both accuracy and performance in the fault reasoning for Internet and overlay service networks, especially when the ratio of the lost and spurious symptoms is high. Yongning Tang, Ehab Al-Shaer, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2008 | A comprehensive analysis of mobility management in MPLS-based wireless access networks
Rami Langar, Nizar Bouabdallah, Raouf Boutaba |
IEEE/ACM Trans. Netw. | 3 |
| 2007 | Analysis of the Impact of the Number of Reporting Nodes on Sensor Networks LifetimeabstractEnergy-efficiency is one of the major concerns in wireless sensor networks since it impacts the network lifetime. In this paper, we investigate the relationship between sensor networks performance, particularly its lifetime, and the number of reporting nodes N by using both analytical and simulation approaches. We first show that the network lifetime and the number of correctly received reports increase when N decreases. Moreover, we demonstrate that the average time required to report an event is a convex function of N. Based on these results, and as the main contribution, we prove that the optimal number of reporting nodes minimizing the energy consumption in the network does not correspond to the optimal number of reporting nodes allowing the fastest way to report an event. The tradeoff between these two requirements is therefore specific to each sensor application, depending on its particular needs. In this paper, we provide a simple methodology to achieve this tradeoff. Fatma Bouabdallah, Nizar Bouabdallah, Raouf Boutaba |
GLOBECOM | 3 |
| 2007 | Adaptive Mobility Management for IP/MPLS-Based Wireless Networks: A Proposal and AnalysisabstractIn this paper, we propose a new adaptive MPLS-enabled micro-mobility management scheme designed to track efficiently the mobility of nodes so as to minimize both handoff latency and total signaling cost while ensuring the mobile node's QoS requirements. To achieve this, we introduce a new concept called residing area. Accordingly, the micro-mobility domain is divided into virtual residing areas where the MN limits its signaling exchanges within this local region instead of communicating with the relatively far away root of the domain at each handoff occurrence. One of the key distinguishing features of our solution from existing literature is its adaptive nature since the virtual residing areas are constructed according to the current network state and the QoS constraints. To evaluate the efficiency of our proposal, we compare our scheme with existing solutions using both analytical and simulation approaches. Numerical and simulation results show that our proposed scheme can significantly reduce registration updates and link usage costs and provide low handoff latency under various scenarios. Rami Langar, Nizar Bouabdallah, Raouf Boutaba |
GLOBECOM | 3 |
| 2007 | Min-Max Congestion in Interference-Prone Wireless Mesh NetworksabstractUsers' demand of seamless connectivity has pushed for the development of alternatives to traditional infrastructure networks. Potential solutions should be low-cost, easily deployable and adaptive to the environment. One approach that has gained tremendous attention over the past few years consists in deploying a backbone of access points wirelessly interconnected, offering users access to the wired infrastructure via multi-hop communication. However, the limited transfer capacities and the interference resulting from a shared transmission medium can prevent further deployment if the network performance does not meet users' expectations. In this work, we explore different ways to improve the nominal network capacity while accounting for the phenomena of intra-interference (interference on a single path) and inter-interference (interference among flows on different paths). In particular, under the assumptions of splitable traffic flows, we present an interference-aware linear- programming formulation of the min-max congestion problem with and without constraints on the path length. Finally, we evaluate via simulations the potential bandwidth capacity gain resulting from the implementation of these different approaches. Sonia Waharte, Arash Farzan, Raouf Boutaba |
ICC | 3 |
| 2007 | Business-Driven Optimization of Policy-Based Management solutionsabstractWe consider whether the off-line compilation of a set of Service Level Agreements (SLAs) into low-level management policies can lead to the runtime maximization of the overall business profit for a service provider. Using a simple Web application hosting SLA template for a utility service provider, we derive low-level QoS management policies and validate their consistency. We show how the default first come first served (FCFS) mechanism for the runtime scheduling of triggered policies fails to deliver an all times maximum business profit for the service provider. To achieve a better business profit, first a penalty/reward model that is derived from the SLA Service Level Objectives (SLOs) is used to assign runtime utility tags to triggered policies. Then three policy scheduling algorithms, which are based on the prediction of the future state of the running SLAs, are used to drive the runtime actions of the Policy Decision Point (PDP). The prediction function per see involved the unsolved problem of predicting in realtime the evolution of the transient state of a variant of an M/M/Ct/Ct queue. A simple approximative solution to the latter problem is provided. Finally, using the VS policy simulator tool, comparative simulation results for the business profit generated by each of the proposed policy scheduling algorithms are presented. VS is a novel tool which we have developed to respond to the increasing need of benchmarking SLA and policy-based management solutions. Issam Aib, Raouf Boutaba |
Integrated Network Management | 2 |
| 2007 | PolicyVis: Firewall Security Policy Visualization and Inspection
Tung Tran 0002, Ehab Al-Shaer, Raouf Boutaba |
LISA | 3 |
| 2007 | Joint call and packet QoS in cellular packet networks
Majid Ghaderi, Raouf Boutaba, Gary W. Kenward |
Comput. Networks | 2 |
| 2007 | OSDA: Open service discovery architecture for efficient cross-domain service provisioning
Noura Limam, Joanna Ziembicki, Reaz Ahmed, Youssef Iraqi, Tianshu Li, Raouf Boutaba, Fernando Cuervo |
Comput. Commun. | 6 |
| 2007 | Distributed pattern matching: a key to flexible and efficient P2P searchabstractFlexibility and efficiency are the prime requirements for any P2P search mechanism. Existing P2P systems do not provide satisfactory solution for achieving these two conflicting goals. Unstructured search protocols (as adopted in Gnutella and FastTrack) provide search flexibility but exhibit poor performance characteristics. Structured search techniques (mostly Distributed Hash Table (DHT)-based), on the other hand, can efficiently route queries but support exact-match semantic only. In this paper we have defined Distributed Pattern Matching (DPM) problem and have presented a novel P2P architecture, named Distributed Pattern Matching System (DPMS), as a solution. Possible application areas of DPM include P2P search, service discovery and P2P databases. In DPMS, advertised patterns are replicated and aggregated by the peers, organized in a lattice-like hierarchy. Replication Improves availability and resilience to peer failure, and aggregation reduces storage overhead. An advertised pattern can be discovered using any subset of its 1-bits. Search complexity in DPMS is logarithmic to the total number of peers in the system. Advertisement overhead and guarantee on search completeness is comparable to that of DHT-based systems. We have presented mathematical analysis and simulation results to demonstrate the effectiveness of DPMS. Reaz Ahmed, Raouf Boutaba |
IEEE J. Sel. Areas Commun. | 2 |
| 2007 | Admission control in data transfers over lightpathsabstractThe availability of optical network infrastructure and appropriate user control software has recently made it possible for scientists to establish end-to-end circuits across multiple management domains in support of large data transfers. These high-performance data paths are typically provisioned over 10 Gigabit optical links, and accessed using ethernet encapsulation at Gigabit and 10 Gigabit rates. The resulting mixture of circuit sizes gives rise to resource conflicts whereby requests to allocate bandwidth partitions are blocked despite vast underutilization of the optical link. In an attempt to remedy this problem, we investigate intelligent admission control policies that consider the long-term effects of admission decisions. Using analytic techniques we show that the greedy policy, which accepts requests to allocate bandwidth partitions whenever sufficient bandwidth exists, is suboptimal in a pertinent scenario. We then consider dynamic online computation of the optimal admission control policy and show that the acceptance ratio of requests to establish end-to-end circuits can be improved by up to 19% on a fifteen-node network where the behaviour of each link is governed by a local optimization effort. Wojciech M. Golab, Raouf Boutaba |
IEEE J. Sel. Areas Commun. | 2 |
| 2007 | On Leveraging Policy-Based Management for Maximizing Business ProfitabstractThis paper presents a systematic approach to business and policy driven refinement. It also discusses an implementation of an application-hosting service level agreement (SLA) use case. We make use of a simple application hosting SLA template, for which we derive a low-level policy-based service level specification (SLS). The SLS policy set is then analyzed for static consistency and runtime efficiency. The Static Analysis phase involves several consistency tests introduced to detect and correct errors in the original SLS. The Dynamic analysis phase considers the runtime dynamics of policy execution as part of the policy refinement process. This latter phase aims at optimizing the business profit of the service provider. Through mathematical approximation, we derive three policy scheduling algorithms. The algorithms are then implemented and compared against random and first come first served (FCFS) scheduling. This paper shows, in addition to the systematic refinement process, the importance of analyzing the dynamics of a policy management solution before it is actually implemented. The simulations have been performed using the VS Policy Simulator tool. Issam Aib, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2007 | Assessing network service profitability: modeling from market science perspective
Jin Xiao 0005, Raouf Boutaba |
IEEE/ACM Trans. Netw. | 2 |
| 2006 | Mobility Modeling and Handoff Analysis for IP/MPLS-Based Cellular NetworksabstractOne of the major challenges for the wireless networks is related to efficient mobility management issue. In this paper, we propose a new micro-mobility management scheme, called Micro Mobile MPLS, that supports both mobility and quality-of-service (QoS) management in cellular networks. Our proposal includes two protocol variants. In the first variant, called FC-Micro Mobile MPLS, the forwarding chain (FC) concept is provided to track efficiently the host mobility within a domain. This concept fits mobile nodes (MNs) with high mobility rate. The second protocol variant, called Master Forwarding Chain (MFC)-Micro Mobile MPLS, aims to reduce the total signaling cost by controlling the number of registration updates with the root of the domain. In order to assess the efficiency of our proposals, the aforesaid protocols are compared with respect to the existing solutions. To achieve this, we develop analytical models to evaluate both registration updates and link usage costs. Numerical and simulation results show that the proposed mechanisms can significantly reduce the registration updates cost and provide low handoff latency and packet loss rate under various scenarios. Rami Langar, Nizar Bouabdallah, Samir Tohmé, Raouf Boutaba |
GLOBECOM | 4 |
| 2006 | Totally Disjoint Multipath Routing in Multihop Wireless NetworksabstractSpreading traffic over multiple paths has been shown to enhance network performance compared to single path routing. However, the route coupling effect specific to wireless environments (consequent to the shared transmission medium) can significantly reduce the benefits of such an approach. In this paper, we focus on the 2-path routing problem in a non-mobile and non energy-constrained network. We evaluate the network performance and the effect of interference in a single source-destination pair scenario and for multiple source-destinations pairs. In the former case, we provide an analytical evaluation of the throughput and propose a position-based algorithm to iteratively find a path between a source and a destination. In the latter case, we demonstrate how interference can significantly degrade the nominal network capacity and void the benefits of multipath routing. Sonia Waharte, Raouf Boutaba |
ICC | 2 |
| 2006 | Max-Min Fair Capacity of Wireless Mesh NetworksabstractThe use of WMNs as backbone for large wireless access networks imposes strict bandwidth requirements. It is therefore necessary to study and quantify the capacity of such systems. In this paper, we argue that the capacity of WMNs should be addressed in the context of fairness to ensure proper operation of WMNs. Among the fairness schemes, max-min fairness allows fair and efficient use of network resources. We therefore propose an algorithm for max-min capacity calculation, formulated in term of collision domains. In addition, we show how to calculate the effective load of collision domains, assuming IEEE 802.11 as the MAC protocol. We illustrate our proposed algorithm and validate our results over baseline and general topologies Bassam Aoun, Raouf Boutaba |
MASS | 2 |
| 2006 | Distributed Pattern Matching for P2P SystemsabstractFlexibility and efficiency are the prime requirements for any P2P search mechanism. Existing P2P systems do not seem to provide satisfactory solution for achieving these two conflicting goals. Unstructured search protocols (as adopted in Gnutella and FastTrack), provide search flexibility but exhibit poor performance characteristics. Structured search techniques (mostly distributed hash table (DHT)-based), on the other hand, can efficiently route queries to target peers but support exact-match queries only. In this paper we present a novel P2P system, called distributed pattern matching system (DPMS), for enabling flexible and efficient search. Distributed pattern matching can be used to solve problems like wildcard searching (for file-sharing P2P systems), partial service description matching (for service discovery systems) etc. DPMS uses a hierarchy of indexing peers for disseminating advertised patterns. Patterns are aggregated and replicated at each level along the hierarchy. Replication improves availability and resilience to peer failure, and aggregation reduces storage overhead. An advertised pattern can be discovered using any subset of its 1-bits; this allows inexact matching and queries in conjunctive normal form. Search complexity (i.e., the number of peers to be probed) in DPMS is O (log N + zetalog N/log N), where N is the total number of peers and zeta is proportional to the number of matches, required in a search result. The impact of churn problem is less severe in DPMS than DHT-based systems. Moreover, DPMS provides guarantee on search completeness for moderately stable networks. We demonstrate the effectiveness of DPMS using mathematical analysis and simulation results Reaz Ahmed, Raouf Boutaba |
NOMS | 2 |
| 2006 | Analysis of Capacity Improvements in Multi-Radio Wireless Mesh NetworksabstractIn this paper, we argue that additional radios should be placed according to the distribution of traffic load in WMN. We show that the capacity of a WMN is constrained by the bottleneck collision domain; hence, placing an equal number of radios at all nodes is not necessary. Only collision domains that need to support higher traffic load should be given more bandwidth by setting up additional radios, so that interfering wireless links would operate on different channels, avoiding interference and enabling multiple parallel transmissions. Furthermore, we determine the upper bound on capacity improvements, and show that much less radios are required compared to conventional k-NIC architectures Bassam Aoun, Raouf Boutaba, Gary W. Kenward |
VTC Spring | 2 |
| 2006 | Management in peer-to-peer systems: Trust, reputation and security
Raouf Boutaba, Alan Marshall 0001 |
Comput. Networks | 1 |
| 2006 | Group shared protection for spare capacity reconfiguration in optical networks
Anwar Haque, Pin-Han Ho, Raouf Boutaba |
Comput. Networks | 3 |
| 2006 | Peer-to-peer's most wanted: Malicious peers
Loubna Mekouar, Youssef Iraqi, Raouf Boutaba |
Comput. Networks | 3 |
| 2006 | Special issue: monitoring and measurements of IP networks
Raouf Boutaba, Ehab Al-Shaer, Kevin C. Almeroth |
Comput. Commun. | 1 |
| 2006 | pMeasure: A peer-to-peer measurement infrastructure for the internet
Raouf Boutaba |
Comput. Commun. | 2 |
| 2006 | Economical protection in MPLS networks
Ajay Pal Singh Virk, Raouf Boutaba |
Comput. Commun. | 2 |
| 2006 | Dynamic cell-based MAC protocol for target detection applications in energy-constrained wireless networks
Sonia Waharte, Raouf Boutaba |
Comput. Commun. | 2 |
| 2006 | Gateway Placement Optimization in Wireless Mesh Networks With QoS ConstraintsabstractIn a wireless mesh network (WMN), the traffic is aggregated and forwarded towards the gateways. Strategically placing and connecting the gateways to the wired backbone is critical to the management and efficient operation of a WMN. In this paper, we address the problem of gateways placement, consisting in placing a minimum number of gateways such that quality-of-service (QoS) requirements are satisfied. We propose a polynomial time near-optimal algorithm which recursively computes minimum weighted Dominating Sets (DS), while consistently preserving QoS requirements across iterations. We evaluate the performance of our algorithm using both analysis and simulation, and show that it outperforms other alternative schemes by comparing the number of gateways placed in different scenarios Bassam Aoun, Raouf Boutaba, Youssef Iraqi, Gary W. Kenward |
IEEE J. Sel. Areas Commun. | 2 |
| 2006 | Routing protocols in wireless mesh networks: challenges and design considerations
Sonia Waharte, Raouf Boutaba, Youssef Iraqi, Brent Ishibashi |
Multim. Tools Appl. | 2 |
| 2006 | Call Admission Control for Voice/Data Integration in Broadband Wireless NetworksabstractThis paper addresses bandwidth allocation for an integrated voice/data broadband mobile wireless network. Specifically, we propose a new admission control scheme called EFGC, which is an extension of the well-known fractional guard channel scheme proposed for cellular networks supporting voice traffic. The main idea is to use two acceptance ratios, one for voice calls and the other for data calls in order to maintain the proportional service quality for voice and data traffic while guaranteeing a target handoff failure probability for voice calls. We describe two variations of the proposed scheme: EFGC-REST, a conservative approach which aims at preserving the proportional service quality by sacrificing the bandwidth utilization, and EFGC-UTIL, a greedy approach which achieves higher bandwidth utilization at the expense of increasing the handoff failure probability for voice calls. Extensive simulation results show that our schemes satisfy the hard constraints on handoff failure probability and service differentiation while maintaining a high bandwidth utilization. Majid Ghaderi, Raouf Boutaba |
IEEE Trans. Mob. Comput. | 2 |
| 2006 | Call admission control in mobile cellular networks: a comprehensive surveyabstractAbstract Call admission control (CAC) is a key element in the provision of guaranteed quality of service (QoS) in wireless networks. The design of CAC algorithms for mobile cellular networks is especially challenging given the limited and highly variable resources, and the mobility of users encountered in such networks. This article provides a survey of admission control schemes for cellular networks and the research in this area. Our goal is to provide a broad classification and thorough discussion of existing CAC schemes. We classify these schemes based on factors such as deterministic/stochastic guarantees, distributed/local control and adaptivity to traffic conditions. In addition to this, we present some modeling and analysis basics to help in better understanding the performance and efficiency of admission control schemes in cellular networks. We describe several admission control schemes and compare them in terms of performance and complexity. Handoff prioritization is the common characteristic of these schemes. We survey different approaches proposed for achieving handoff prioritization with a focus on reservation schemes. Moreover, optimal and near‐optimal reservation schemes are presented and discussed. Also, we overview other important schemes such as those designed for multi‐service networks and hierarchical systems as well as complete knowledge schemes and those using pricing for CAC. Finally, the paper concludes on the state of current research and points out some of the key issues that need to be addressed in the context of CAC for future cellular networks. Copyright © 2005 John Wiley & Sons, Ltd. Majid Ghaderi, Raouf Boutaba |
Wirel. Commun. Mob. Comput. | 2 |
| 2006 | Forward focus: using routing information to improve medium access control in ad hoc networksabstractAbstract Multihop packet forwarding is a vital process in an ad hoc network. All ad hoc networking protocols, but particularly routing and medium access control protocols, must work together in order for the network to be successful. However, current MAC protocols such as IEEE 802.11 do not consider this multihop nature at all. This work develops a modification to 802.11 that focuses on forwarding packets. Routing information is utilized to streamline the sharing of the medium, by allowing forwarding nodes to reuse an already‐acquired channel. Using forward focus (FF), nodes are encouraged to participate in the forwarding process and are rewarded for doing so. Simulation‐generated performance evaluations reveal that the result is a MAC protocol with improved efficiency and effectiveness. Copyright © 2006 John Wiley & Sons, Ltd. Brent Ishibashi, Raouf Boutaba |
Wirel. Commun. Mob. Comput. | 2 |
| 2005 | Detecting malicious peers in a reputation-based peer-to-peer systemabstractIn this paper we propose a reputation management scheme for partially decentralized peer-to-peer systems. The reputation scheme helps building trust between peers based on their past experiences and feedbacks from other peers. Our system is novel in that it is able to detect not only malicious peers sending inauthentic files but also malicious peers that are lying in their feedbacks. To detect those peers, we introduce the new concept of suspicious transactions. The simulation results show that the proposed scheme is able to effectively detect malicious peers and isolate them from the system, hence reducing the amount of inauthentic uploads and increasing peers' satisfaction. Loubna Mekouar, Youssef Iraqi, Raouf Boutaba |
CCNC | 3 |
| 2005 | Free riders under control through service differentiation in peer-to-peer systemsabstractTrust is required in a file sharing peer-to-peer system to achieve better cooperation among peers. In reputation-based peer-to-peer systems, reputation is used to build trust among peers. In these systems, highly reputable peers will usually be selected to upload requested files, decreasing significantly malicious uploads in the system. However, these peers need to be motivated to upload files by increasing the benefits that they receive from the system. In addition, it is necessary to motivate free riders to contribute to the system by sharing files. Malicious peers must be forced to contribute positively by uploading authentic files instead of malicious ones. In this paper, the contribution behavior of the peer is used as a guideline for service differentiation. The new concept of availability is introduced for partially-decentralized peer-to-peer systems. Both availability and involvement of the peer are used to assess its contribution behavior. Simulation results confirm the ability of the proposed scheme to effectively identify both free riders and malicious peers and reduce the level of service provided to them. Simulation results also confirm that based on rational behavior, peers are motivated to increase their contribution to receive services. Moreover, using our scheme, peers must continuously participate, reducing significantly the so-called milking phenomenon Loubna Mekouar, Youssef Iraqi, Raouf Boutaba |
CollaborateCom | 3 |
| 2005 | Peer-to-peer networking and management
Raouf Boutaba |
Integrated Network Management | 1 |
| 2005 | Zero-budget network dimensioningabstractTraffic engineering has been widely used to improve network performance while keeping the resource utilization balanced. The existing traffic engineering approaches, however, lead to network upgrades from time to time. While these upgrades might be successfully financed during economic prosperities, it poses a problem when the economic situation deteriorates. We propose in this paper a novel approach that is able to reveal whether a traffic re-engineering is necessary. In case budget is not available for upgrades, this approach can optimally decide which demand to satisfy so as to maximize network operators' revenue. We demonstrate the usefulness and the effectiveness of the approach by conducting traffic engineering on an example network and by describing some of its added values as well. Youssef Iraqi, Raouf Boutaba |
Integrated Network Management | 3 |
| 2005 | Active integrated fault localization in communication networksabstractFault localization is a core element in fault management. Many fault reasoning techniques use deterministic or probabilistic symptom-fault causality model for fault diagnoses and localization. Symptom-fault map is commonly used to describe symptom-fault causality in fault reasoning. However, due to lost and spurious symptoms in fault reasoning systems that passively collect symptoms, the performance and accuracy of the fault localization can be significantly degraded. In this paper, we propose an extended symptom-fault-action model to incorporate actions into fault reasoning process to tackle the above problem. This technique is called active integrated fault reasoning (AIR), which contains three modules: fault reasoning, fidelity evaluation and action selection. Corresponding fault reasoning and action selection algorithms are elaborated. Simulation study shows both performance and accuracy of fault reasoning can be greatly improved by taking actions, especially when the rate of spurious and lost symptoms is high. Yongning Tang, Ehab Al-Shaer, Raouf Boutaba |
Integrated Network Management | 3 |
| 2005 | QoS-aware service composition in large scale multi-domain networksabstractNext generation networks are envisioned to support dynamic and customizable service compositions at Internet scale. To facilitate the communication between distributed software components, on-demand and QoS-aware network service composition across large scale networks emerges as a key research challenge. This paper presents a fast QoS-aware service composition algorithm for selecting a set of interconnected domains with specific service classes. We further show how such algorithm can be used to support network adaptation and service mobility. In simulation studies performed on large scale networks, the algorithm exhibits very high probability of finding the optimal solution within short execution time. In addition, we present a distributed service composition framework utilizing this algorithm. Jin Xiao 0005, Raouf Boutaba |
Integrated Network Management | 2 |
| 2005 | Stochastic Admission Control for Quality of Service in Wireless Packet Networks
Majid Ghaderi, Raouf Boutaba, Gary W. Kenward |
NETWORKING | 2 |
| 2005 | A mobility management tool-the realistic mobility modelabstractThis paper introduces a new mobility model which takes into account user motivation for mobility as well as geographic constraints on mobility. Joe Capka, Raouf Boutaba |
WiMob (2) | 2 |
| 2005 | Topology and mobility considerations in mobile ad hoc networks
Brent Ishibashi, Raouf Boutaba |
Ad Hoc Networks | 2 |
| 2005 | A measurement-based approach for dynamic QoS adaptation in DiffServ networks
Toufik Ahmed, Raouf Boutaba, Ahmed Mehaoua |
Comput. Commun. | 2 |
| 2005 | Weight allocation in distributed admission control for wireless networks
Youssef Iraqi, Raouf Boutaba |
Comput. Commun. | 2 |
| 2005 | Adaptive packet video streaming over IP networks: a cross-layer approachabstractThere is an increasing demand for supporting real-time audiovisual services over next-generation wired and wireless networks. Various link/network characteristics make the deployment of such demanding services more challenging than traditional data applications like e-mail and the Web. These audiovisual applications are bandwidth adaptive but have stringent delay, jitter, and packet loss requirements. Consequently, one of the major requirements for the successful and wide deployment of such services is the efficient transmission of sensitive content (audio, video, image) over a broad range of bandwidth-constrained access networks. These media will be typically compressed according to the emerging ISO/IEC MPEG-4 standard to achieve high bandwidth efficiency and content-based interactivity. MPEG-4 provides an integrated object-oriented representation and coding of natural and synthetic audiovisual content for its manipulation and transport over a broad range of communication infrastructures. In This work, we leverage the characteristics of MPEG-4 and Internet protocol (IP) differentiated service frameworks, to propose an innovative cross-layer content delivery architecture that is capable of receiving information from the network and adaptively tune transport parameters, bit rates, and QoS mechanisms according to the underlying network conditions. This service-aware IP transport architecture is composed of: 1) an automatic content-level audiovisual object classification model; 2) a reliable application level framing protocol with fine-grained TCP-Friendly rate control and adaptive unequal error protection; and 3) a service-level QoS matching/packet tagging algorithm for seamless IP differentiated service delivery. The obtained results demonstrate, that breaking the OSI protocol layer isolation paradigm and injecting content-level semantic and service-level requirements within the transport and traffic control protocols, lead to intelligent and efficient support of multimedia services over complex network architectures. Toufik Ahmed, Ahmed Mehaoua, Raouf Boutaba, Youssef Iraqi |
IEEE J. Sel. Areas Commun. | 3 |
| 2005 | Conflict classification and analysis of distributed firewall policiesabstractFirewalls are core elements in network security. However, managing firewall rules, particularly, in multifirewall enterprise networks, has become a complex and error-prone task. Firewall filtering rules have to be written, ordered, and distributed carefully in order to avoid firewall policy anomalies that might cause network vulnerability. Therefore, inserting or modifying filtering rules in any firewall requires thorough intrafirewall and interfirewall analysis to determine the proper rule placement and ordering in the firewalls. In this paper, we identify all anomalies that could exist in a single- or multifirewall environment. We also present a set of techniques and algorithms to automatically discover policy anomalies in centralized and distributed firewalls. These techniques are implemented in a software tool called the "Firewall Policy Advisor" that simplifies the management of filtering rules and maintains the security of next-generation firewalls. Ehab Al-Shaer, Hazem H. Hamed, Raouf Boutaba, Masum Hasan |
IEEE J. Sel. Areas Commun. | 3 |
| 2005 | QoS-aware service composition and adaptation in autonomic communicationabstractAdvents in network technology and distributed system design have propelled network communication service beyond best effort data delivery. With the rising complexity of network infrastructures and the need for on-demand provisioning operations, a high degree of self-sufficiency and automation is required in the network service infrastructure. Guided by the autonomic communication principle, this paper first presents an autonomic service provisioning framework for establishing quality-of-service (QoS)-assured end-to-end communication paths across administratively independent domains. Through graph abstraction, we show that the domain composition and adaptation problem could be reduced to the classic k-multiconstrained optimal path (MCOP) problem. In analyzing existing k-MCOP solutions, we show their inefficiencies when applied to the service provisioning context and establish a number of new domain composition and adaptation algorithms. These new algorithms are designed for the self-configuration, self-optimization, and self-adaptation of end-to-end network communications and can provide hard QoS guarantees over domains with relative QoS differentiations. Through in-depth experimentations, we compare the performance of our algorithms with classic k-MCOP solutions and demonstrate the effectiveness of our approach. Jin Xiao 0005, Raouf Boutaba |
IEEE J. Sel. Areas Commun. | 2 |
| 2004 | Group shared protection (GSP): a scalable solution for spare capacity reconfiguration in mesh WDM networksabstractThis paper proposes a novel framework of shared protection, namely group shared protection (GSP), in mesh wavelength division multiplexing (WDM) networks with dynamically arriving connection requests. Based on the (M:N)/sup n/ control architecture, GSP has n mutually independent protection groups, each of which contains N SRLG-disjoint working paths protected by M protection paths. Due to the SRLG-disjointedness of the working paths in each protection group, GSP not only allows the spare capacity to be totally sharable among the corresponding working paths, but also reduces the number of working paths affected due to a single link failure. Based on the framework, an integer linear program (ILP) formulation that can optimally reconfigure the spare capacity for a specific protection group whenever a working-protection path-pair joins is proposed. Two heuristics namely link-shared protection (LSP) and ring-shared protection (RSP) are introduced for further compromising the performance and the computational complexity. The proposed schemes are compared with a reported one, namely successive survivable routing (SSR). The experimental results show that LSP, RSP and SSR yield similar performance in terms of resource sharing, whereas ILP outperforms all of them by (6-16%). Due to the limited number of working paths in each protection group, ILP can handle a dynamically arriving connection request in a reasonable amount of time. Also, we find that the number of affected working paths in GSP is about half of that in SSR. We conclude that GSP provides a scalable and efficient solution for dynamic spare capacity reconfiguration following the (M:N)/sup n/ control architecture. Anwar Haque, Pin-Han Ho, Raouf Boutaba, James Ho |
GLOBECOM | 3 |
| 2004 | Call Admission Control for Voice/Data Integration in Broadband Wireless Networks
Majid Ghaderi, Raouf Boutaba |
NETWORKING | 2 |
| 2004 | Customer-centric network upgrade strategy: maximizing investment benefits for enhanced service qualityabstractWith the ever increasing demand for network resources, network operators and Internet service providers are under constant pressure to accommodate more network bandwidth and offer better service quality via periodic network upgrades, Given a budget constraint, a sound network upgrade decision should maximize investment benefit which is contingent on the degree of customer satisfaction. This paper presents a customer-centric approach in making network upgrade decisions, where customer satisfaction is the key evaluation criterion. Network performance is related to customer's perceived service quality and component upgrades are assessed based on their profitability. As demonstrated using a case scenario, our approach results in effective upgrade decisions that enhance service quality, improve customer satisfaction, and maximize revenue. Jin Xiao 0005, Raouf Boutaba |
NOMS (1) | 2 |
| 2004 | Data service performance analysis in GPRS systemsabstractWe describe an analytical approach for deriving the packet delay distribution in a cell of a wireless network operating on the general packet radio service (GPRS) standard. Based on that, the average packet delay and packet loss probability are also computed. Our approach is based on a decomposition of system behavior into short-term and long-term behaviors to simplify the analytical modeling. In addition to the effect of voice call handoffs, the impact of packet forwarding and dedicated data channels on data service performance is also taken into consideration. The performance estimates produced by the analytical approach are compared with those generated by simulation experiments. The comparison results confirm the relative accuracy of the analytical approach. Majid Ghaderi, Raouf Boutaba |
PIMRC | 2 |
| 2004 | Enabling real-time All-IP wireless networksabstractWe propose an all-IP wireless network architecture that does not require any change inside the network and can interwork with the existing wired network. This architecture is based on the operation of intserv over diffserv network. The standard KSVP protocol is used for signaling and reservation. The approach is based on probabilistic behavior of mobile users and does not require precise knowledge of user mobility specification. The architecture allows mobile users to specify both packet-level and connection-level quality of service (QoS) parameters. Simulation results show that the proposed architecture allows flexible network resource management while achieving high resource utilization. Youssef Iraqi, Majid Ghaderi, Raouf Boutaba |
WCNC | 3 |
| 2004 | Pricing and admission control for QoS-enabled Internet
Tianshu Li, Youssef Iraqi, Raouf Boutaba |
Comput. Networks | 3 |
| 2004 | Web services architecture for user control and management of optical Internet networksabstractOne of the primary goals of the CA*net 4 network is to provide end users with the ability, on a peer-to-peer basis, to provision, manage, and control the routing of their own lightpaths across the network without the need to signal or request services from any central network management authority or server. A novel approach to such end-user management and control of lightpaths is described, which uses Web services architecture and grid technology. Bill St. Arnaud, Andrew K. Bjerring, Omar Cherkaoui, Raouf Boutaba, Martin Pott, Wade Hong |
Proc. IEEE | 4 |
| 2003 | A multi-commodity flow based approach to virtual network resource allocationabstractThe virtual network (VN) concept has been studied as a useful mean in supporting rapid service creation and deployment. This paper proposes a scheme for allocating resources to VNs with the objective of maximizing the number of VNs that can be accommodated into a network. In our scheme, resources are pre-allocated for each pair of edge nodes, using the solution to the multi-commodity flow problem. A VN creation request consists of a set of edge node pairs and the bandwidth requirements between each pair. A request is satisfied or accepted by utilizing the pre-allocated resource and possibly the residual resource pool after pre-allocation. Extensive simulation studies show that the proposed scheme accepts more VN requests and yields better network resource utilization over traditional approaches. Service providers may potentially boost revenue by a simple switch to a more intelligent resource allocation scheme. Wayne Szeto, Youssef Iraqi, Raouf Boutaba |
GLOBECOM | 3 |
| 2003 | Tariff-Based Pricing and Admission Control for DiffServ Networks
Tianshu Li, Youssef Iraqi, Raouf Boutaba |
Integrated Network Management | 3 |
| 2003 | The Degree of Participation Concept in Ad Hoc NetworksabstractThe paper introduces the novel concept of degree-of-participation (DP) in mobile ad hoc networks. The degree-of-participation concept allows nodes in the ad hoc network to express the level of involvement they are willing to give to the forwarding process. The paper also introduces a DP-based routing scheme for mobile ad hoc networks. Performance evaluations show that the degree-of-participation allows a more resource-aware forwarding process. Youssef Iraqi, Raouf Boutaba |
ISCC | 2 |
| 2003 | Grid-Controlled Lightpaths for High Performance Grid Applications
Raouf Boutaba, Wojciech M. Golab, Youssef Iraqi, Tianshu Li, Bill St. Arnaud |
J. Grid Comput. | 1 |
| 2002 | Interworking between SIP and MPEG-4 DMIF for heterogeneous IP video conferencingabstractThis article discusses technical issues related to delivery and control of IP multimedia services, such as videoconferencing, involving heterogeneous end terminals. In particular, it describes the design and implementation of an experimental system for interworking between IETF SIP (session initiation protocol) and ISO MPEG-4 DMIF (delivery multimedia integration framework) session and call control signaling protocols. This IP videoconferencing interworking system is composed of two core units for supporting delivery of audio-video streams from a DMIF domain to a SIP domain (i.e. DMIF2SIP unit) and from a SIP domain to a DMIF domain (i.e. SIP2DMIF unit). These units perform various translation functions for transparent establishment and control of multimedia sessions across an IP networking environment, including, session protocol conversion, service gateway conversion and address translation. Toufik Ahmed, Ahmed Mehaoua, Raouf Boutaba |
ICC | 3 |
| 2002 | Dynamic Online Routing Algorithm for MPLS Traffic Engineering
Wayne Szeto, Raouf Boutaba, Youssef Iraqi |
NETWORKING | 2 |
| 2002 | Programmable accounting management for virtual private networksabstractUntil now, proposals for IP accounting management have not exploited the power of programmable networks. Thus, real-time charging and pricing schemes are still regarded as impractical, because the accounting management tasks are executed only at the edges. We introduce the notion of programmable accounting management which is more flexible, efficient and scalable. Specifically, we propose real-time charging and pricing mechanisms using programmable networks. Moreover, we propose a novel programmable accounting architecture for QoS-enabled virtual private networks (VPNs). This architecture gives the flexibility to the providers to employ real-time accounting, and offers an open accounting interface inside the network nodes. This entails that also the VPN subscribers can execute accounting tasks inside the network nodes. For example, they can keep their providers under surveillance, or they can apply their own accounting policies for their users. Anna Evlogimenou, Raouf Boutaba |
NOMS | 2 |
| 2002 | Distributed Video Production: Tasks, Architecture and QoS Provisioning
Raouf Boutaba, Ned Ning Ren, Yasser Rasheed, Alberto Leon-Garcia |
Multim. Tools Appl. | 1 |
| 2001 | A cooperative QoS control framework for streaming video applicationsabstractThis article describes a cooperative framework for the transport and the QoS control of delay-tolerant video streaming applications using MPEG-2 encoding and broadband ATM networks. The proposed framework integrates three components: (1) a dynamic video frame-level priority assignment mechanism based on MPEG data structure and feedback from the network (DexPAS); (2) an audio-visual AAL-5 SSCS with forward error correction capabilities (AV-SSCS); and (3) an intelligent packet video discard mechanism called FEC-PSD, that adaptively and selectively adjusts cell drop levels to switch buffer occupancy, video cell payload type and forward error correction capability of the destination. The proposed QoS control and video delivery framework is evaluated using simulation. Ahmed Mehaoua, Raouf Boutaba |
GLOBECOM | 2 |
| 2001 | When is it worth involving several cells in the call admission control process for multimedia cellular networks?abstractIn this paper, we enhance our distributed call admission control scheme developed for cellular mobile networks. The new scheme can dynamically adapt to changes in the network load to maintain a target call dropping probability. We investigate the impact of the number of neighboring cells involved in a call admission decision in addition to the cell where the call originated. The neighboring cells provide significant information about their ability to support the new mobile user in the future. This distributed process allows the original cell to make a more clear-sighted admission decision for the new user. Simulations are presented with a detailed analysis of a comparison between two schemes involving different number of cells. Youssef Iraqi, Raouf Boutaba |
ICC | 2 |
| 2001 | A Java API for Advanced Faults ManagementabstractThe paper proposes an alternative for modeling managed resources using Java and telecommunication network management standards. It emphasizes functions related to fault management, namely: diagnostic testing and performance monitoring. Based on Java management extension (JMX/sup TM/), specific extensions are proposed to facilitate diagnostic testing and performance measurements implementation. The new API also called Java fault management extension (JFMX) consists of managed objects that model real resources being tested or monitored and support objects defined for the need of diagnostic testing and performance measurements. The paper discusses four Java implementations of a 3-tier client/server scenario focusing on the "SystemUnderTest" package of the new API to instrument a minimalist managed system scenario. These implementations are respectively built on top of the following Java based communication infrastructures: JMX/JFMX, RMI, CORBA/Java, and Voyager/sup TM/. The paper extends the Voyager implementation with JMX/JFMX and uses their dynamic and advanced features to provide a highly efficient solution. The later implementation also uses the mobile agent paradigm to overcome well-known limitations of the RPC based implementations. Mahamat Guiagoussou, Raouf Boutaba, Michel Kadoch |
Integrated Network Management | 2 |
| 2001 | Performance Evaluation of a Distributed Call Admission Control for QoS-Sensitive Wireless Mobile NetworksabstractThis paper presents a performance evaluation of a distributed call admission control framework developed for cellular mobile networks. The call admission control algorithm involves not only the original cell (handling the new admission request) but also a cluster of neighboring cells. The neighboring cells provide significant information about their ability to support the new mobile user in the future. This distributed process allows the original cell to make a more clear-sighted admission decision for the new user. Simulations are provided to show the improvements obtained using our framework. Youssef Iraqi, Raouf Boutaba |
ISCC | 2 |
| 2001 | Supporting MPEG video VBR traffic in wireless networks
Youssef Iraqi, Raouf Boutaba |
Comput. Commun. | 2 |
| 2000 | Network security management with intelligent agentsabstractMulti-agent systems technology can be useful for efficiently designing and maintaining secure networks. Indeed, networks evolve at a rapid pace in terms of the number and type of components and user access queries as well as intrusion possibilities. Features such as autonomy, adaptability and flexibility of the "intelligent" agent paradigm allow the managing of network evolution in a controlled way. The focus of our work concerns one critical security management issue, that is, intrusion detection. We propose a novel approach called IA-NSM (intelligent agents for network security management) for intrusion detection using intelligent agent technology. IA-NSM provides a flexible integration of a multi-agent system in a classical networked environment to enhance its protection level against inherent attacks. Karima Boudaoud, Houda Labiod, Raouf Boutaba, Zahia Guessoum |
NOMS | 3 |
| 2000 | An adaptive distributed call admission control for QoS-sensitive wireless mobile networksabstractThis paper introduces an adaptive distributed call admission control framework developed for cellular mobile networks. The main feature of the proposed framework is a more efficient support for mobile multimedia users having dynamic bandwidth requirements. This is achieved by imposing an upper bound on the experienced call dropping probability, regardless of network load changes, while maintaining a high network resource utilization. The call admission control algorithm presented in this paper involves not only the original cell (handling the new admission request) but also a cluster of neighboring cells. The neighboring cells provide significant information about their ability to support the new mobile user in the future. This distributed process allows the original cell to make a more clear-sighted admission decision for the new user. The cell changes the acceptance threshold dynamically to maintain a target call dropping probability. Simulations are provided to show the improvements obtained using our framework. Youssef Iraqi, Raouf Boutaba |
WCNC | 2 |
| 2000 | QoS control in wireless ATM
Youssef Iraqi, Raouf Boutaba, Alberto Leon-Garcia |
Mob. Networks Appl. | 2 |
| 1999 | The impacts of errors and delays on the performance of MPEG2 video communicationsabstractTransmission of MPEG2-encoded video is one of the most demanding applications in terms of network resources and QoS requirement. It needs high bandwidth with stringent transmission delays. It can not tolerate large variations on delays and it requires low error and loss data rates. Therefore, in order to design efficient integrated video communication systems over ATM networks, we propose in this paper to analyze the effects of errors and delays on both video signal and network performance. Ahmed Mehaoua, Raouf Boutaba |
ICASSP | 2 |
| 1999 | Towards an efficient ATM best effort video delivery serviceabstractThis paper addresses the transport of real-time multimedia traffic generated by MPEG-2 applications over ATM networks using an enhanced UBR best effort service (UBR+). Based on the factors affecting the picture quality during transmission, we propose an efficient and cost-effective ATM best effort delivery service. The proposed service integrates three components: a dynamic frame level priority assignation mechanism based on the MPEG data structure and feedback from the network (DexPAS), a novel audiovisual AAL5 SSCS with FEC, and an intelligent packet video discard scheme named SA-PSD, which adaptively and selectively adjusts the cell drop level to switch buffer occupancy, video cell payload type and forward error correction ability of the destination. The overall best effort video delivery framework is evaluated using ATM network simulation and MPEG-2 video traces. The ultimate aim of this framework is twofold. First, minimizing loss for critical video data with bounded end-to-end delay for arriving cells. Second, reducing the bad throughput crossing the network during congestion. Compared to previous approaches, performance evaluation shows a good protection of predictive coded and bidirectional predictive coded frames at the video slice layer. Ahmed Mehaoua, Raouf Boutaba, Song Pu, Yasser Rasheed, Alberto Leon-Garcia |
ICC | 2 |
| 1999 | MIBlets: A Practical Approach to Virtual Network ManagementabstractThis paper introduces the MIBlet concept as a means for effectively designing and managing virtual networks (VN). MIBlets are logical structures providing abstract and selective views of the physical network resources allocated to VN customers. They result from the partitioning of the network resources (their MIB representations) and restrict customers' access only to those resources allocated to them. Different partitioning schemes are supported to provide virtual network services with different quality of service requirements. Customer control/management functions are implemented through MIBlet controllers located at every network node involved in the customer network. MIBlet controllers enforce customers' access control and resource usage policing strategies and are invoked to set up, monitor and control the customer connections. In this paper the partitioning of network resources into MIBlets is mainly addressed within the scope of the ATM testbed as a part of the network resources management (NRM) project of the Network Architecture Laboratory at the University of Toronto. Walfrey Ng, Andrew Do-Sung Jun, HungKei Keith Chow, Raouf Boutaba, Alberto Leon-Garcia |
Integrated Network Management | 4 |
| 1999 | Policies in SNMPv3-based ManagementabstractTwo important achievements in the network management area motivated the work presented in this paper. The first one is the wide acceptance of the policy concept and its introduction as a means for driving management procedures. The second concerns the capabilities brought by the version 3 of the SNMP protocol for configurable and secure network management. The deployment of SNMPv3 at equipment level allows henceforth concretizing the policy-driven management, refining enterprise policies and enforcing them down the managed network resources. This paper aims at integrating the policy concept into the SNMPv3 framework. It proposes a set of rules to map authorization policies to the VACM (view based access control model) standardized as part of the SNMPv3 management framework. Policy attributes are maintained in a configuration database local to the SNMPv3 entity and a new application is incorporated into the SNMPv3 entity to perform the mapping. This will ultimately allow manager and management applications to enforce enterprise authorization policies independently of the security model(s) implemented by SNMPv3 entities. Salima Omari, Raouf Boutaba, Omar Cherkaoui |
Integrated Network Management | 2 |
| 1999 | Proposal of An AudioVisual SSCS with Forward Error CorrectionabstractThis paper addresses the transport of real-time multimedia traffic generated by MPEG-2 applications over ATM best effort services (ABR, UBR+). To cope with network congestion and the unreliability of the ATM adaptation layer type 5 (AAL5), we propose a new service-specific convergence sublayer for audiovisual applications. The proposed AV-SSCS includes adaptive forward data error correction (FEC) based on Reed-Solomon and parity codes. With respect to network load and video packet loss ratio measured at the destination, the source can dynamically increase or reduce the FEC efficiency (i.e., the amount of data redundancy) to provide a higher protection to the video packet or a better use of the shared bandwidth respectively. Ahmed Mehaoua, Raouf Boutaba, Jean-Pierre Claudé, Guy Pujolle |
ISCC | 2 |
| 1999 | Statistical properties of MPEG video traffic and their impact on bandwidth allocation in wireless ATM networksabstractIn this paper, we analyse the statistical data sets of several MPEG encoded videos and propose a model of the elements of a scene. The proposed model permits the characterisation of the elements of the stream scenes. The model can be used to allocate bandwidth dynamically on a scene basis and will result in a high capacity gain while guaranteeing the same and even better QoS. This model is particularly suited for MPEG encoded VBR traffic in wireless ATM networks. Youssef Iraqi, Raouf Boutaba, Rachida Dssouli |
WCNC | 2 |
| 1999 | A generic platform for scalable access to multimedia-on-demand systemsabstractAccess to multimedia servers is commonly done according to a client/server model where the end user at the client host retrieves multimedia objects from a multimedia server. In a distributed environment, a number of end users may need to access a number of multimedia servers through one or several communication networks. Such a scenario reveals the requirement for a distributed access platform. In addition, the demand for multimedia information is increasing beyond the capabilities of high performance storage devices. Therefore, load distribution and scalability issues must be addressed while designing and implementing the distributed access platform. This paper introduces a scalable access platform (SAP) for managing user access to multimedia-on-demand systems while optimizing resource utilization. The platform is generic and capable of integrating heterogeneous multimedia servers. SAP operation combines static replication and dynamic load distribution policies. It provides run time redirecting of client requests to multimedia servers according to the workload information dynamically collected in the system. To support multimedia-on-demand systems with differing quality-of-service (QoS) requirements, the platform also takes into account, as part of the access process, user QoS requirements and cost constraints. This paper also presents an application of the generic platform implementing a scalable movie-on-demand system, called SMoD. Performance evaluation based on simulation shows that in many cases SMoD can reduce the blocking probability of user requests, and thus can support more users than classical video-on-demand (VoD) systems. It also shows that the load is better distributed across the video servers of the system. Raouf Boutaba, Abdelhakim Hafid |
IEEE J. Sel. Areas Commun. | 1 |
| 1999 | Editorial - Resource Management in Mobile Wireless Communication Networks
Raouf Boutaba, Joakim Kalvenes, Guy Pujolle |
Mob. Networks Appl. | 1 |
| 1998 | Performance analysis of cell discarding techniques for best effort video communications over ATM networks
Ahmed Mehaoua, Raouf Boutaba |
Comput. Networks ISDN Syst. | 2 |
| 1997 | Deriving Variabel Polling Frequency Policies for Pro-activce Management in Networks and Distributed Systems
Petre Dini, Raouf Boutaba |
Integrated Network Management | 2 |
| 1997 | A TMN framework for faults diagnostic in wireless telecommunication networksabstractThe occurrence of a fault in a critical component of large telecommunication system may cause multiple abnormal situations leading to large number of different alarms at different locations. Appropriate management tools are required to automatically filter and correlate these alarms in order to localize faulty components. Such tools must be based not only on the description, state and behavior of the managed components, but also on explicit description of the dynamic state and behavior of the relationships between these components. The paper explores the usage of relations between wireless network managed components within a TMN based framework. The proposed framework is used in the design of a TMN based fault management system including alarms correlation and fault diagnostic for wireless networks. Mahamat Guiagoussou, Raouf Boutaba |
ISCC | 2 |
| 1997 | An extended priority data partition scheme for MPEG video connections over ATMabstractTransmission of compressed video over ATM networks requires efficient data priority partition techniques. In association with intelligent cell discard schemes, these techniques aim to minimize the loss probability of critical information in the situation of congestion. We propose a new video-oriented priority data partition mechanism named the extended priority assignation scheme (ExPAS). This mechanism better uses the cell header and allows the definition of up to three service classes per connection. To evaluate its performance, we have also designed an adaptive cell dropping scheme which takes benefits of the new features. In comparison with previous priority partition techniques based on the cell loss probability (CLP) mechanism, ExPAS with the adaptive selective cell discard (A-SDC) scheme shows better results in minimizing cell losses of intra-coded frames. Ahmed Mehaoua, Raouf Boutaba, Guy Pujolle |
ISCC | 2 |
| 1997 | An adaptive and selective cell drop policy with dynamic data partitioning for best effort video over ATMabstractWe propose and evaluate a new MPEG based video delivery framework for use with ATM best effort services (e.g. available bit rate and unspecified bit rate). The presented framework relies on three components: a video oriented cell discarding scheme, which adaptively and selectively adjusts drop level to switch buffer occupancy and video cell payload types; a dynamic frame level priority data partition mechanism based on MPEG data structure and feedback from the network; and an enhanced ATM Adaptation Layer type 5 associated with a new slice based MPEG2 encapsulation strategy. This best effort video delivery framework is evaluated using simulation and real MPEG video data. Ahmed Mehaoua, Raouf Boutaba, Guy Pujolle |
LCN | 2 |
| 1996 | The Two Real-Time Solitudes: computerized control and telecommunicationsabstractWhile the two solitudes of our title, computerized control and telecommunications, are both concerned with computerized solutions to real world problems, we suggest that they are really addressing different needs and are therefore naturally preoccupied by slightly different concerns. We present a taxonomy of key elements intended to make such differences explicit in order to promote more mutual understanding and more collaborative work where concerns are shared. In particular, we suggest that one key difference lies in the nature of the timing requirements associated with reactivity, and whether they are considered as extensions to logical correctness or performance. Paul Freedman, Daniel Gaudreau, Raouf Boutaba, Ahmed Mehaoua |
ICECCS | 3 |
| 1994 | Towards Integrated Network Management : A Domain/policy Approach And Its Application To A High Speed Multi-networkabstractIn this paper we introduce a methodology for structuring the management of networked systems. Domains are used as a means for grouping resources according to different criteria. Moreover, we present a management model and the respective activity flows including interactions between managing components. As an example, we apply our concepts to structure the management of a high speed multi-network (ATM, DQDB, FDDI). Emphasis lies on Quality of Service management in the FDDI management domain. Raouf Boutaba, Simon Znaty |
NOMS | 1 |