David Kotz

dblp:k/DavidKotz · also David F. Kotz · DBLP profile ↗
← Back
98ranked-venue papers
17as first author
12since 2021 · last 2026
0000-0001-7411-2783ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 40 · 5 first-author · 1 since 2021Systems, architecture and hardware · 16 · 7 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 15 · 1 first-author · 2 since 2021Security and privacy · 12 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 4 · 2 first-authorDatabases, data management, data science and information retrieval · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021
YearPublicationVenuePosition
2026 CAEC: Confidential, Attestable, and Efficient Inter-CVM Communication with Arm CCA
abstract
Confidential Virtual Machines (CVMs) are increasingly adopted to protect sensitive workloads from privileged adversaries such as the hypervisor. While they provide strong isolation guarantees, existing CVM architectures lack first-class mechanisms for inter-CVM data sharing due to their disjoint memory model, making inter-CVM data exchange a performance bottleneck in compartmentalized or collaborative multi-CVM systems. Under this model, a CVM's accessible memory is either shared with the hypervisor or protected from both the hypervisor and all other CVMs. This design simplifies reasoning about memory ownership; however, it fundamentally precludes plaintext data sharing between CVMs because all inter-CVM communication must pass through hypervisor-accessible memory, requiring costly encryption and decryption to preserve confidentiality and integrity. In this paper, we introduce CAEC, a system that enables protected memory sharing between CVMs. CAEC builds on Arm Confidential Compute Architecture (CCA) and extends its firmware to support Confidential Shared Memory (CSM), a memory region securely shared between multiple CVMs while remaining inaccessible to the hypervisor and all non-participating CVMs. CAEC's design is fully compatible with CCA hardware and introduces only a modest increase (6%) in CCA firmware code size. CAEC delivers substantial performance benefits across a range of workloads. For instance, inter-CVM communication over CAEC achieves up to 209x reduction in CPU cycles compared to encryption-based mechanisms over hypervisor-accessible shared memory. By combining high performance, strong isolation guarantees, and attestable sharing semantics, CAEC provides a practical and scalable foundation for the next generation of trusted multi-CVM services across both edge and cloud environments.
Sina Abdollahi, Amir Al Sadi, David Kotz, Marios Kogias, Hamed Haddadi 0001
EuroS&P3
2025 Comparing Smart-Home Devices that Use the Matter Protocol
abstract
This paper analyzes Google Home, Apple HomeKit, Samsung SmartThings, and Amazon Alexa platforms, focusing on their integration with the Matter protocol. Matter is a connectivity standard developed by the Connectivity Standards Alliance (CSA) for the smart-home industry. By examining key features and qualitative metrics, this study aims to provide valuable insights for consumers and industry professionals in making informed decisions about smart-home devices. We conducted (from May to August 2024) a comparative analysis to explore how Google Home Nest, Apple HomePod Mini, Samsung SmartThings station, and Amazon Echo Dot platforms leverage the power of Matter to provide seamless and integrated smart-home experiences.
Wondimu Zegeye, Ravindra Mangar, Jingyu Qian, Vinton Morris, Mounib Khanafer, Kevin T. Kornegay, Timothy J. Pierson, David Kotz
CCNC8
2024 Smart Use of Smart Devices in Your Home: A Smart Home Security and Privacy Workshop for the General Public
abstract
With 'smart' technology becoming more prevalent in homes, computing is increasingly embedded into everyday life. The benefits are well-advertised, but the risks associated with these technologies are not as clearly articulated. We aim to address this gap by educating community members on some of these risks, and providing actionable advice to mitigate risks. To this end, we describe our efforts to design and implement a hands-on workshop for the public on smart-home security and privacy.
Tushar M. Jois, Tina Pavlovich, Brigid M. McCarron, David Kotz, Timothy J. Pierson
SIGCSE (1)4
2024 Detecting Battery Cells with Harmonic Radar
abstract
Harmonic radar systems have been shown to be an effective method for detecting the presence of electronic devices, even if the devices are powered off. Prior work has focused on detecting specific non-linear electrical components (such as transistors and diodes) that are present in any electronic device. In this paper we show that harmonic radar is also capable of detecting the presence of batteries. We tested a proof-of-concept system on Alkaline, NiMH, Li-ion, and Li-metal batteries. With the exception of Li-metal coin cells, the prototype harmonic radar detected the presence of batteries in our experiments with 100% accuracy.
Cesar Arguello, Beatrice Perez, Timothy J. Pierson, David Kotz
WISEC4
2024 Contextualizing Interpersonal Data Sharing in Smart Homes
abstract
A key feature of smart home devices is monitoring the environment and recording data. These devices provide security via motion-detection video alerts, cost-savings via thermostat usage history, and peace of mind via functions like auto-locking doors or water leak detectors. At the same time, the sharing of this information in interpersonal relationships---though necessary---is currently accomplished on an all-or-nothing basis. This can easily lead to oversharing in a multi-user environment. Although prior work has studied people's perceptions of information sharing with vendors or ISPs, the sharing of household data among users who interact personally is less well understood. Interpersonal situations make data sharing much more context-based and, thus, more complicated. In this paper, we use themes from the theory of contextual integrity in an online survey (n=1,992) to study how people perceive data sharing with others in smart homes and inform future designs and research. Our results show that data recipients in a smart home can be reduced to three major groups, and data types matter more than device types. We also found that the types of access control desired by users can vary from scenario to scenario. Depending on whom they are sharing data with and about what data, participants expressed varying levels of comfort when presented with different types of access control (e.g., explicit approval versus time-limited access). Taken together, this provides strong evidence that a more dynamic access control system is needed, and we can design it in a more usable way.
Weijia He, Nathan Reitinger, Atheer Almogbil, Yi-Shyuan Chiang, Timothy J. Pierson, David Kotz
Proc. Priv. Enhancing Technol.6
2024 Interpretable Feature Learning in Multivariate Big Data Analysis for Network Monitoring
abstract
There is an increasing interest in the development of new data-driven models useful to assess the performance of communication networks. For many applications, like network monitoring and troubleshooting, a data model is of little use if it cannot be interpreted by a human operator. In this paper, we present an extension of the Multivariate Big Data Analysis (MBDA) methodology, a recently proposed interpretable data analysis tool. In this extension, we propose a solution to the automatic derivation of features, a cornerstone step for the application of MBDA when the amount of data is massive. The resulting network monitoring approach allows us to detect and diagnose disparate network anomalies, with a data-analysis workflow that combines the advantages of interpretable and interactive models with the power of parallel processing. We apply the extended MBDA to two case studies: UGR’16, a benchmark flow-based real-traffic dataset for anomaly detection, and Dartmouth’18, the longest and largest Wi-Fi trace known to date.
José Camacho 0001, Katarzyna Wasielewska, Rasmus Bro, David Kotz
IEEE Trans. Netw. Serv. Manag.4
2022 Amanuensis: provenance, privacy, and permission in TEE-enabled blockchain data systems
abstract
Blockchain technology is heralded for its ability to provide transparent and immutable audit trails for data shared among semi-trusted parties. With the addition of smart contracts, blockchains can track and verify arbitrary computations – which enables blockchain users to verify the provenance of information derived from data through the blockchain. This provenance comes at the cost of data confidentiality and user privacy, however, which is unacceptable for many sensitive applications. The need for verifiable yet confidential data sharing and computation has led some to add trusted execution environment (TEE) hardware to blockchain platforms. By moving sensitive operations (e.g., data decryption and analysis) off of the blockchain and into a TEE, they get both the confidentiality of TEEs and the transparency of blockchains without the need to completely trust any one party in the data-sharing ecosystem.In this paper, we build on our TEE-enabled blockchain data-sharing system, Amanuensis, to ensure the freshness of access-control lists shared between the blockchain and TEE, and to improve the privacy of users interacting within the system. We also detail how TEE-based remote attestation help us to achieve information provenance – specifically, how to achieve information provenance in the context of the Intel SGX trusted execution environment. Finally, we present an evaluation of our system, in which we test several real-world machine-learning applications (logistic regression, kNN, SVM) to determine the run-time overhead of information confidentiality and provenance. Each machine-learning program exhibited a slowdown between 1.1 and 2.8x when run inside of our confidential environment, and took an average of 59 milliseconds to verify the provenance of an input data set.
Taylor Hardin, David Kotz
ICDCS2
2022 Evaluating voice-assistant commands for dementia detection
Xiaohui Liang 0002, John A. Batsis, Youxiang Zhu, Tiffany M. Driesse, Robert M. Roth, David Kotz, Brian MacWhinney
Comput. Speech Lang.6
2021 Recurring verification of interaction authenticity within bluetooth networks
abstract
Although user authentication has been well explored, device-to-device authentication - specifically in Bluetooth networks - has not seen the same attention. We propose Verification of Interaction Authenticity (VIA) - a recurring authentication scheme based on evaluating characteristics of the communications (interactions) between devices. We adapt techniques from wireless traffic analysis and intrusion-detection systems to develop behavioral models that capture typical, authentic device interactions (behavior); these models enable recurring verification of device behavior. To evaluate our approach we produced a new dataset consisting of more than 300 Bluetooth network traces collected from 20 Bluetooth-enabled smart-health and smart-home devices. In our evaluation, we found that devices can be correctly verified at a variety of granularities, achieving an F1-score of 0.86 or better in most cases.
Travis Peters, Timothy J. Pierson, Sougata Sen, José Camacho 0001, David Kotz
WISEC5
2021 Introduction to the Special Issue on the Wearable Technologies for Smart Health, Part 2
abstract
No abstract available.
David Kotz, Guoliang Xing
ACM Trans. Comput. Heal.1
2021 Amanuensis: Information provenance for health-data systems
Taylor Hardin, David Kotz
Inf. Process. Manag.2
2021 VibeRing: Using vibrations from a smart ring as an out-of-band channel for sharing secret keys
Sougata Sen, David Kotz
Pervasive Mob. Comput.2
2020 Longitudinal analysis of a campus Wi-Fi network
José Camacho 0001, Chris McDonald, Ron Peterson, David Kotz
Comput. Networks5
2020 Introduction to the Special Issue on the Wearable Technologies for Smart Health
abstract
No abstract available.
David Kotz, Guoliang Xing
ACM Trans. Comput. Heal.1
2020 Continuous Detection of Physiological Stress with Commodity Hardware
abstract
Timely detection of an individual’s stress level has the potential to improve stress management, thereby reducing the risk of adverse health consequences that may arise due to mismanagement of stress. Recent advances in wearable sensing have resulted in multiple approaches to detect and monitor stress with varying levels of accuracy. The most accurate methods, however, rely on clinical-grade sensors to measure physiological signals; they are often bulky, custom made, and expensive, hence limiting their adoption by researchers and the general public. In this article, we explore the viability of commercially available off-the-shelf sensors for stress monitoring. The idea is to be able to use cheap, nonclinical sensors to capture physiological signals and make inferences about the wearer’s stress level based on that data. We describe a system involving a popular off-the-shelf heart rate monitor, the Polar H7; we evaluated our system with 26 participants in both a controlled lab setting with three well-validated stress-inducing stimuli and in free-living field conditions. Our analysis shows that using the off-the-shelf sensor alone, we were able to detect stressful events with an F 1-score of up to 0.87 in the lab and 0.66 in the field, on par with clinical-grade sensors.
Varun Mishra 0001, Gunnar Pope, Sarah E. Lord, Stephanie Lewia, Byron Lowens, Kelly Caine, Sougata Sen, Ryan J. Halter, David Kotz
ACM Trans. Comput. Heal.9
2020 Securely Connecting Wearables to Ambient Displays with User Intent
abstract
Wearables are often small and have limited user interfaces, hence they often wirelessly interface with a personal smartphone or a personal computer to relay information from the wearable for display. In this paper, we envision a new method LightTouch by which a wearable can establish a secure connection to an ambient display, such as a television or computer monitor, based on the user's intention to connect to the display. Such connections must be secure to prevent impersonation attacks, must work with unmodified display hardware, and must be easy to establish. LightTouch uses standard RF methods for communicating the data to display, securely bootstrapped with a key shared via a brightness channel between the low cost, low power, ambient light sensor of a wearable and the screen of the display. A screen touch gesture is adopted by users to ensure the modulation of screen brightness can be accurately and securely captured by the ambient light sensor. We further propose novel on-screen localization and correlation algorithms to improve security and reliability. Through experiments we demonstrate that LightTouch is compatible with current display and wearable designs, easy-to-use (5-6 seconds), reliable for connecting displays (98 percent success connection ratio), and secure against impersonation attacks.
Xiaohui Liang 0002, Ronald A. Peterson, David Kotz
IEEE Trans. Dependable Secur. Comput.3
2019 Experience: Design, Development and Evaluation of a Wearable Device for mHealth Applications
abstract
Wrist-worn devices hold great potential as a platform for mobile health (mHealth) applications because they comprise a familiar, convenient form factor and can embed sensors in proximity to the human body. Despite this potential, however, they are severely limited in battery life, storage, bandwidth, computing power, and screen size. In this paper, we describe the experience of the research and development team designing, implementing and evaluating Amulet? an open-hardware, open-software wrist-worn computing device? and its experience using Amulet to deploy mHealth apps in the field. In the past five years the team conducted 11 studies in the lab and in the field, involving 204 participants and collecting over 77,780 hours of sensor data. We describe the technical issues the team encountered and the lessons they learned, and conclude with a set of recommendations. We anticipate the experience described herein will be useful for the development of other research-oriented computing platforms. It should also be useful for researchers interested in developing and deploying mHealth applications, whether with the Amulet system or with other wearable platforms.
George Boateng, Vivian Motti 0001, Varun Mishra 0001, John A. Batsis, Josiah D. Hester, David Kotz
MobiCom6
2019 Proximity Detection with Single-Antenna IoT Devices
abstract
Providing secure communications between wireless devices that encounter each other on an ad-hoc basis is a challenge that has not yet been fully addressed. In these cases, close physical proximity among devices that have never shared a secret key is sometimes used as a basis of trust; devices in close proximity are deemed trustworthy while more distant devices are viewed as potential adversaries. Because radio waves are invisible, however, a user may believe a wireless device is communicating with a nearby device when in fact the user's device is communicating with a distant adversary. Researchers have previously proposed methods for multi-antenna devices to ascertain physical proximity with other devices, but devices with a single antenna, such as those commonly used in the Internet of Things, cannot take advantage of these techniques.
Timothy J. Pierson, Travis Peters, Ronald A. Peterson, David Kotz
MobiCom4
2019 CloseTalker: Secure, Short-Range Ad Hoc Wireless Communication
abstract
Secure communication is difficult to arrange between devices that have not previously shared a secret. Previous solutions to the problem are susceptible to man-in-the-middle attacks, require additional hardware for out-of-band communication, or require an extensive public-key infrastructure. Furthermore, as the number of wireless devices explodes with the advent of the Internet of Things, it will be impractical to manually configure each device to communicate with its neighbors. Our system, CloseTalker, allows simple, secure, ad hoc communication between devices in close physical proximity, while jamming the signal so it is unintelligible to any receivers more than a few centimeters away. CloseTalker does not require any specialized hardware or sensors in the devices, does not require complex algorithms or cryptography libraries, occurs only when intended by the user, and can transmit a short burst of data or an address and key that can be used to establish long-term or long-range communications at full bandwidth. In this paper we present a theoretical and practical evaluation of CloseTalker, which exploits Wi-Fi MIMO antennas and the fundamental physics of radio to establish secure communication between devices that have never previously met. We demonstrate that CloseTalker is able to facilitate secure in-band communication between devices in close physical proximity (about 5~cm), even though they have never met nor shared a key.
Timothy J. Pierson, Travis Peters, Ronald A. Peterson, David Kotz
MobiSys4
2018 GeriActive: Wearable app for monitoring and encouraging physical activity among older adults
abstract
The ability to monitor a person's level of daily activity can inform self-management of physical activity and assist in augmenting behavioral interventions. For older adults, the importance of regular physical activity is critical to reduce the risk of long-term disability. In this work, we present GeriActive, an application on the Amulet wrist-worn device that monitors in real time older adults' daily activity levels (low, moderate and vigorous), which we categorized using metabolic equivalents (METs). The app implements an activity-level detection model we developed using a linear Support Vector Machine (SVM). We trained our model using data from volunteer subjects (n=29) who performed common physical activities (sit, stand, lay down, walk and run) and obtained an accuracy of 94.3% with leave-one-subject-out (LOSO) cross-validation. We ran a week-long field study to evaluate the usability and battery life of the GeriActive system where 5 older adults wore the Amulet as it monitored their activity level. Their feedback showed that our system has the potential to be usable and useful. Our evaluation further revealed a battery life of at least 1 week. The results are promising, indicating that the app may be used for activity-level monitoring by individuals or researchers for health delivery interventions that could improve the health of older adults.
George Boateng, John A. Batsis, Patrick Proctor, Ryan J. Halter, David Kotz
BSN5
2018 An ultra-low resource wearable EDA sensor using wavelet compression
abstract
This study presents an ultra-low resource platform for physiological sensing that uses on-chip wavelet compression to enable long-term recording of electrodermal activity (EDA) within a 64kB microcontroller. The design is implemented on a wearable platform and provides improvements in size and power compared to existing wearable technologies and was used in a lab setting to monitor EDA of 27 participants throughout a stress induction protocol. We demonstrate the device's sensitivity to stress induction by providing descriptive statistics of 8 common EDA signal features for each stressor of the experiment. To the best of our knowledge, this is the first time a generic, 16-bit microcontroller (MCU) has been used to record real-time physiological signals on a wearable platform without the use of external memory chips or wireless transmission for extended periods of time. The compression techniques described can lead to reductions in size, power, and cost of wearable biosensors with little or no modifications to existing sensor hardware and could be valuable for applications interested in monitoring long-term physiological trends at lower data rates and memory requirements.
Gunnar Pope, Varun Mishra 0001, Stephanie Lewia, Byron Lowens, David Kotz, Sarah E. Lord, Ryan J. Halter
BSN5
2018 Poster: Proximity Detection with Single-Antenna IoT Devices
abstract
Close physical proximity among wireless devices that have never shared a secret key is sometimes used as a basis of trust. In these cases, devices in close proximity are deemed trustworthy while more distant devices are viewed as potential adversaries. Because radio waves are invisible, however, a user may believe a wireless device is communicating with a nearby device when in fact the user's device is communicating with a distant adversary. Researchers have previously proposed methods for multi-antenna devices to ascertain physical proximity with other devices, but devices with a single antenna, such as those commonly used in the Internet of Things, cannot take advantage of these techniques. We investigate a method for a single-antenna Wi-Fi device to quickly determine proximity with another Wi-Fi device. Our approach leverages the repeating nature Wi-Fi's preamble and the characteristics of a transmitting antenna's near field to detect proximity with high probability. Our method never falsely declares proximity at ranges longer than 14 cm.
Timothy J. Pierson, Travis Peters, Ronald A. Peterson, David Kotz
MobiCom4
2018 Application Memory Isolation on Ultra-Low-Power MCUs
Taylor Hardin, Ryan Scott, Patrick Proctor, Josiah D. Hester, Jacob Sorber, David Kotz
USENIX ATC6
2017 LightTouch: Securely connecting wearables to ambient displays with user intent
abstract
Wearables are small and have limited user interfaces, so they often wirelessly interface with a personal smartphone/computer to relay information from the wearable for display or other interactions. In this paper, we envision a new method, LightTouch, by which a wearable can establish a secure connection to an ambient display, such as a television or a computer monitor, while ensuring the user's intention to connect to the display. LightTouch uses standard RF methods (like Bluetooth) for communicating the data to display, securely bootstrapped via the visible-light communication (the brightness channel) from the display to the low-cost, low-power, ambient light sensor of a wearable. A screen `touch' gesture is adopted by users to ensure that the modulation of screen brightness can be securely captured by the ambient light sensor with minimized noise. Wireless coordination with the processor driving the display establishes a shared secret based on the brightness channel information. We further propose novel onscreen localization and correlation algorithms to improve security and reliability. Through experiments and a preliminary user study we demonstrate that LightTouch is compatible with current display and wearable designs, is easy to use (about 6 seconds to connect), is reliable (up to 98% success connection ratio), and is secure against attacks.
Xiaohui Liang 0002, Tianlong Yun, Ronald A. Peterson, David Kotz
INFOCOM4
2017 Poster: Auracle: A Wearable Device for Detecting and Monitoring Eating Behavior
abstract
Chronic disease is one of the most pressing health challenges facing the United States (and an increasing set of other countries). The onset or progression of diseases like obesity, diabetes, and metabolic disorder are strongly related to eating behavior, and scientists are still trying to fully understand the complex mixture of diet, exercise, genetics, sociocultural context, and physical environment that lead to these diseases. Health science, however, has no effective means for automatically measuring eating behavior in free-living conditions. The Auracle aims to be a wearable earpiece that detects eating behavior, to be fielded by health-science researchers in their efforts to study eating behavior and ultimately to develop interventions useful to individuals striving to address chronic disease related to eating.
Shengjie Bi, Ellen Davenport, Jun Gong 0002, Ronald A. Peterson, Joseph Skinner, Kevin M. Storer, Kelly Caine, Ryan J. Halter, David Kotz, Kofi M. Odame, Jacob Sorber, Xing-Dong Yang
MobiSys10
2017 Poster: Memory Protection in Ultra-Low-Power Multi-Application Wearables
abstract
An increasing number of wearable devices support the execution of multiple third-party applications, increasing the functionality and flexibility of these devices. These multi-application, multi-tenant devices provide users with more options, and application developers with a standard platform. Typical ultra-low-power wearable devices, however, lack the type of hardware memory protection mechanisms~-- such as Memory Management Units (MMU)~-- needed to safely separate applications. At best, they provide a Memory Protection Unit (MPU), which allows the user to configure read/write/execute permissions for a few distinct regions of memory. At worst, no hardware memory protection is provided. MPU capabilities vary across hardware platforms, with many shortcomings: (1)~the MPU may only support a few distinct memory regions (fewer than one per application), (2)~the MPU may not protect all regions of memory, like hardware registers, and (3)~MPU protection boundary rules can be arcane, because they depend on opaque hardware implementations. Our key observation is that by supplementing a limited segment MPU with runtime checks, and using compile-time static analysis to explicitly layout applications in memory, we can guarantee application isolation (sandboxing) even on these limited MPUs, with lower overhead than software-only solutions.
Taylor Hardin, Josiah D. Hester, Patrick Proctor, Jacob Sorber, David Kotz
MobiSys5
2017 Poster: Vocal Resonance as a Passive Biometric
abstract
With continuing advances in the development of low-power electronics, including sensors and actuators, we anticipate a rapid expansion of pervasive computing. Wearable devices, in particular, require new modes for interaction -- many have no keyboard or touchscreen. In this work, we focus on user authentication on wearable devices. For an entertainment device, such as a VR headset, it can recognize the user and load the right game profile or music playlist. For a house climate-control system, it can adjust the environment to the wearer's preference. Most compellingly, for a health-monitoring device, it can label the sensor data with the correct identity so that the data can be stored in the correct health record. (A mix-up of sensor data could lead to incorrect decisions, with harm to the patient.) Because not all devices are personal devices -- my phone, your fitness sensor -- many devices will need to automatically recognize their wearer. They may have no interface for user identification (or PIN or password for authentication). Thus, we need a simple, wearable biometric technique to identify the user -- which could be embedded in one authentication device that shares the identity with a body-area network of other devices (earlier confirmed to be on the same body). This device should be trained once, for each user that might wear it, but thenceforth be completely automatic. Although a wristband could use a physiological biometric to recognize its wearer; we seek an alternative biometric, notably, one that might work for devices mounted on the head, neck, or chest.
Rui Liu 0014, Cory Cornelius, Reza Rawassizadeh, Ronald A. Peterson, David Kotz
MobiSys5
2016 Wanda: Securely introducing mobile devices
abstract
Nearly every setting is increasingly populated with wireless and mobile devices - whether appliances in a home, medical devices in a health clinic, sensors in an industrial setting, or devices in an office or school. There are three fundamental operations when bringing a new device into any of these settings: to configure the device to join the wireless local-area network, to partner the device with other nearby devices so they can work together, and (3) to configure the device so it connects to the relevant individual or organizational account in the cloud. The challenge is to accomplish all three goals simply, securely, and consistent with user intent. We present a novel approach we call Wanda - a `magic wand' that accomplishes all three of the above goals - and evaluate a prototype implementation.
Timothy J. Pierson, Xiaohui Liang 0002, Ronald A. Peterson, David Kotz
INFOCOM4
2016 Amulet: An Energy-Efficient, Multi-Application Wearable Platform
abstract
Wearable technology enables a range of exciting new applications in health, commerce, and beyond. For many important applications, wearables must have battery life measured in weeks or months, not hours and days as in most current devices. Our vision of wearable platforms aims for long battery life but with the flexibility and security to support multiple applications. To achieve long battery life with a workload comprising apps from multiple developers, these platforms must have robust mechanisms for app isolation and developer tools for optimizing resource usage.
Josiah D. Hester, Travis Peters, Tianlong Yun, Ronald A. Peterson, Joseph Skinner, Bhargav Golla, Kevin M. Storer, Steven Hearndon, Kevin Freeman, Sarah E. Lord, Ryan J. Halter, David Kotz, Jacob Sorber
SenSys12
2016 The Amulet Wearable Platform: Demo Abstract
abstract
In this demonstration we present the Amulet Platform; a hardware and software platform for developing energy- and resource-efficient applications on multi-application wearable devices. This platform, which includes the Amulet Firmware Toolchain, the Amulet Runtime, the ARP-View graphical tool, and open reference hardware, efficiently protects applications from each other without MMU support, allows developers to interactively explore how their implementation decisions impact battery life without the need for hardware modeling and additional software development, and represents a new approach to developing long-lived wearable applications. We envision the Amulet Platform enabling long-duration experiments on human subjects in a wide variety of studies.
Josiah D. Hester, Travis Peters, Tianlong Yun, Ronald A. Peterson, Joseph Skinner, Bhargav Golla, Kevin M. Storer, Steven Hearndon, Sarah E. Lord, Ryan J. Halter, David Kotz, Jacob Sorber
SenSys11
2014 A wearable system that knows who wears it
abstract
Body-area networks of pervasive wearable devices are increasingly used for health monitoring, personal assistance, entertainment, and home automation. In an ideal world, a user would simply wear their desired set of devices with no configuration necessary: the devices would discover each other, recognize that they are on the same person, construct a secure communications channel, and recognize the user to which they are attached. In this paper we address a portion of this vision by offering a wearable system that unobtrusively recognizes the person wearing it. Because it can recognize the user, our system can properly label sensor data or personalize interactions.
Cory Cornelius, Ronald A. Peterson, Joseph Skinner, Ryan J. Halter, David Kotz
MobiSys5
2014 Poster: Enabling computational jewelry for mHealth applications
abstract
No abstract available.
Andres Molina-Markham, Ronald A. Peterson, Joseph Skinner, Ryan J. Halter, Jacob Sorber, David Kotz
MobiSys6
2014 Poster: Balancing disclosure and utility of personal information
abstract
The ubiquity of smartphones and mobile and wearable devices allow people to collect information about their health, wellness and lifestyle and share with others. If it is not clear what they need to share to receive benefits, subjects (people whose information is collected) might share too much, thus disclosing unnecessary private information. On the other hand, concerned about disclosing personal information, subjects might share less than what the recipient needs and lose the opportunity to enjoy the benefits. This balance of disclosure and utility is important when the subject wants to receive some benefits, but is concerned about disclosing private information.
Aarathi Prasad, Xiaohui Liang 0002, David Kotz
MobiSys3
2014 ZEBRA: Zero-Effort Bilateral Recurring Authentication
abstract
Common authentication methods based on passwords, tokens, or fingerprints perform one-time authentication and rely on users to log out from the computer terminal when they leave. Users often do not log out, however, which is a security risk. The most common solution, inactivity timeouts, inevitably fail security (too long a timeout) or usability (too short a timeout) goals. One solution is to authenticate users continuously while they are using the terminal and automatically log them out when they leave. Several solutions are based on user proximity, but these are not sufficient: they only confirm whether the user is nearby but not whether the user is actually using the terminal. Proposed solutions based on behavioral biometric authentication (e.g., keystroke dynamics) may not be reliable, as a recent study suggests. To address this problem we propose Zero-Effort Bilateral Recurring Authentication (ZEBRA). In ZEBRA, a user wears a bracelet (with a built-in accelerometer, gyroscope, and radio) on her dominant wrist. When the user interacts with a computer terminal, the bracelet records the wrist movement, processes it, and sends it to the terminal. The terminal compares the wrist movement with the inputs it receives from the user (via keyboard and mouse), and confirms the continued presence of the user only if they correlate. Because the bracelet is on the same hand that provides inputs to the terminal, the accelerometer and gyroscope data and input events received by the terminal should correlate because their source is the same - the user's hand movement. In our experiments ZEBRA performed continuous authentication with 85% accuracy in verifying the correct user and identified all adversaries within 11s. For a different threshold that trades security for usability, ZEBRA correctly verified 90% of users and identified all adversaries within 50s.
Shrirang Mare, Andres Molina-Markham, Cory Cornelius, Ronald A. Peterson, David Kotz
IEEE Symposium on Security and Privacy5
2014 Hide-n-Sense: Preserving Privacy Efficiently in Wireless mHealth
Shrirang Mare, Jacob Sorber, Minho Shin, Cory Cornelius, David Kotz
Mob. Networks Appl.5
2014 From MAP to DIST: The Evolution of a Large-Scale WLAN Monitoring System
abstract
The edge of the Internet is increasingly becoming wireless. Therefore, monitoring the wireless edge is important to understanding the security and performance aspects of the Internet experience. We designed and implemented a large-scale WLAN monitoring system, the Dartmouth Internet security testbed (DIST), at Dartmouth College. It is equipped with distributed arrays of "sniffers" that cover 210 diverse campus locations and more than 5,000 users. In this paper, we describe our approach, designs, and solutions for addressing the technical challenges that have resulted from efficiency, scalability, security, and management perspectives. We also present extensive evaluation results on a production network, and summarize the lessons learned.
Keren Tan, Chris McDonald, Bennet Vance, Chrisil Arackaparambil, Sergey Bratus, David Kotz
IEEE Trans. Mob. Comput.6
2012 Plug-n-trust: practical trusted sensing for mhealth
abstract
Mobile computing and sensing technologies present exciting opportunities for healthcare. Prescription wireless sensors worn by patients can automatically deliver medical data to care providers, dramatically improving their ability to diagnose, monitor, and manage a range of medical conditions. Using the mobile phones that patients already carry to provide connectivity between sensors and providers is essential to keeping costs low and deployments simple. Unfortunately, software-based attacks against phones are also on the rise, and successful attacks on privacy-sensitive and safety-critical applications can have significant consequences for patients.
Jacob Sorber, Minho Shin, Ronald A. Peterson, David Kotz
MobiSys4
2012 Recognizing whether sensors are on the same body
Cory Cornelius, David Kotz
Pervasive Mob. Comput.2
2011 Privacy analysis of user association logs in a large-scale wireless LAN
abstract
User association logs play an important role in wireless network research. One concern of sharing such logs with other researchers, however, is that they pose potential privacy risks for the network users. Today, the common practice in sanitizing these logs before releasing them to the public is to anonymize users' sensitive information, such as their devices' MAC addresses and their exact association locations. In this work, we aim to study whether such sanitization measures are sufficient to protect user privacy. By simulating an adversary's role, we propose a novel type of correlation attack in which the adversary uses the anonymized association log to build signatures against each user, and when combined with auxiliary information, such signatures can help to identify users within the anonymized log. Using a user association log that contains more than four thousand users and millions of association records, we demonstrate that this attack technique, under certain circumstances, is able to pinpoint the victim's identity exactly with a probability as high as 70%, or narrow it down to a set of 20 candidates with a probability close to 100%.We further evaluate the effectiveness of standard anonymization techniques, including generalization and perturbation, in mitigating correlation attacks; our experimental results reveal only limited success of these methods, suggesting that more thorough treatment is needed when anonymizing wireless user association logs before public release.
Keren Tan, Guanhua Yan, Jihwang Yeo, David Kotz
INFOCOM4
2011 Poster: practical trusted computing for mhealth sensing
abstract
Mobile sensing technologies present exciting opportunities for healthcare. Wireless sensors can automatically provide sensor data to care providers, dramatically improving their ability to diagnose, monitor, and manage a wide range of medical conditions. Using mobile phones to provide connectivity between sensors and providers is essential to keeping costs low and deployments simple. Unfortunately, software-based attacks against phones, which can have significant consequences for patients, are also on the rise.
Jacob Sorber, Minho Shin, Ronald A. Peterson, David Kotz
MobiSys4
2011 Social network analysis plugin (SNAP) for mesh networks
abstract
In a network, bridging nodes are those nodes that from a topological perspective, are strategically located between highly connected regions of nodes. Thus, they have high values of the Bridging Centrality (BC) metric. We recently introduced the Localized Bridging Centrality (LBC) metric, which can identify such nodes via distributed computation, yet has an accuracy equal to that of the centralized BC metric. The LBC and BC metrics are based on the Social Network Analysis (SNA) metric “betweenness centrality”. We now introduce a new SNA metric that is more suitable for use in wireless mesh networks: the Localized Load-aware Bridging Centrality (LLBC) metric. The LLBC metric improves upon LBC by detecting critical bridging nodes while taking into account the actual traffic flows present in a mesh network. We only use local information from surrounding nodes to compute the LLBC metric, thus our LLBC metric is designed for scalable distributed computation and distributed network analysis. We developed the SNA Plugin (SNAP) for the Optimized Link State Routing (OLSR) protocol to study the potential use of LBC and LLBC in improving multicast communications. We present some promising initial results for SNAP from real and emulated mesh networks. SNAP is open source and free for academic use.
Soumendra Nanda, David Kotz
WCNC2
2011 Short paper: the NetSANI framework for analysis and fine-tuning of network trace sanitization
abstract
Anonymization is critical prior to sharing wireless-network traces within the research community, to protect both personal and organizational sensitive information from disclosure. One difficulty in anonymization, or more generally, sanitization, is that users lack information about the quality of a sanitization result, such as how much privacy risk a sanitized trace may expose, and how much research utility the sanitized trace may retain. We propose a framework, NetSANI, that allows users to analyze and control the privacy/utility tradeoff in network sanitization. NetSANI can accommodate most of the currently available privacy and utility metrics for network trace sanitization. This framework provides a set of APIs for analyzing the privacy/utility tradeoff by comparing the changes in privacy and utility levels of a trace for a sanitization operation. We demonstrate the framework with an quantitative evaluation on wireless-network traces.
Phil Fazio, Keren Tan, Jihwang Yeo, David Kotz
WISEC4
2011 AnonySense: A system for anonymous opportunistic sensing
Minho Shin, Cory Cornelius, Daniel Peebles, Apu Kapadia, David Kotz, Nikos Triandopoulos
Pervasive Mob. Comput.5
2010 Saluki: A high-performance Wi-Fi sniffing program
Keren Tan, David Kotz
WiOpt2
2010 On the reliability of wireless fingerprinting using clock skews
abstract
Determining whether a client station should trust an access point is a known problem in wireless security. Traditional approaches to solving this problem resort to cryptography. But cryptographic exchange protocols are complex and therefore induce potential vulnerabilities in themselves. We show that measurement of clock skews of access points in an 802.11 network can be useful in this regard, since it provides fingerprints of the devices. Such fingerprints can be used to establish the first point of trust for client stations wishing to connect to an access point. Fingerprinting can also be used in the detection of fake access points.
Chrisil Arackaparambil, Sergey Bratus, Anna Shubina, David Kotz
WISEC4
2009 Activity-aware ECG-based patient authentication for remote health monitoring
abstract
Mobile medical sensors promise to provide an efficient, accurate, and economic way to monitor patients' health outside the hospital. Patient authentication is a necessary security requirement in remote health monitoring scenarios. The monitoring system needs to make sure that the data is coming from the right person before any medical or financial decisions are made based on the data. Credential-based authentication methods (e.g., passwords, certificates) are not well-suited for remote healthcare as patients could hand over credentials to someone else. Furthermore, one-time authentication using credentials or trait-based biometrics (e.g., face, fingerprints, iris) do not cover the entire monitoring period and may lead to unauthorized post-authentication use. Recent studies have shown that the human electrocardiogram (ECG) exhibits unique patterns that can be used to discriminate individuals. However, perturbation of the ECG signal due to physical activity is a major obstacle in applying the technology in real-world situations. In this paper, we present a novel ECG and accelerometer-based system that can authenticate individuals in an ongoing manner under various activity conditions. We describe the probabilistic authentication system we have developed and present experimental results from 17 individuals.
Janani C. Sriram, Minho Shin, Tanzeem Choudhury, David Kotz
ICMI4
2009 MPCS: Mobile-phone based patient compliance system for chronic illness care
abstract
More than 100 million Americans are currently living with at least one chronic health condition and expenditures on chronic diseases account for more than 75 percent of the $2.3 trillion cost of our healthcare system. To improve chronic illness care, patients must be empowered and engaged in health
Minho Shin, David Kotz, Ethan Berke
MobiQuitous4
2009 DEAMON: Energy-efficient Sensor Monitoring
abstract
In people-centric opportunistic sensing, people offer their mobile nodes (such as smart phones) as platforms for collecting sensor data. A sensing application distributes sensing 'tasks', which specify what sensor data to collect and under what conditions to report the data back to the application. To perform a task, mobile nodes may use on-board sensors, a body-area network of personal sensors, or sensors from neighboring nodes that volunteer to contribute their sensing resources. In all three cases, continuous sensor monitoring can drain a node's battery. We propose DEAMON (Distributed Energy-Aware MONitoring), an energy-efficient distributed algorithm for long-term sensor monitoring. Our approach assumes only that mobile nodes are tasked to report sensor data under conditions specified by a Boolean expression, and that a network of nearby sensor nodes contribute to monitoring subsets of the task's sensors. Our algorithm to select sensor nodes and to monitor the sensing condition conserves energy of all nodes by limiting sensing and communication operations. We evaluate DEAMON with a stochastic analysis and with simulation results, and show that it should significantly reduce energy consumption.
Minho Shin, Patrick P. Tsang, David Kotz, Cory Cornelius
SECON3
2008 Localized Bridging Centrality for Distributed Network Analysis
abstract
Centrality is a concept often used in social network analysis to study different properties of networks that are modeled as graphs. We present a new centrality metric called localized bridging centrality (LBC). LBC is based on the bridging centrality (BC) metric that Hwang et al. recently introduced. Bridging nodes are nodes that are strategically located in between highly connected regions. LBC is capable of identifying bridging nodes with an accuracy comparable to that of the BC metric for most networks. As the name suggests, we use only local information from surrounding nodes to compute the LBC metric, whereas, global knowledge is required to calculate the BC metric. The main difference between LBC and BC is that LBC uses the egocentric definition of betweenness centrality to identify bridging nodes, while BC uses the sociocentric definition of betweenness centrality. Thus, our LBC metric is suitable for distributed or parallel computation and has the benefit of being an order of magnitude faster to calculate in computational complexity. We compare the results produced by BC and LBC in three examples. We applied our LBC metric for network analysis of a real wireless mesh network. Our results indicate that the LBC metric is as powerful as the BC metric at identifying bridging nodes. The LBC metric is thus an important tool that can help network administrators identify critical nodes that are important for the robustness of the network in a distributed manner.
Soumendra Nanda, David Kotz
ICCCN2
2008 Detecting 802.11 MAC Layer Spoofing Using Received Signal Strength
abstract
MAC addresses can be easily spoofed in 802.11 wireless LANs. An adversary can exploit this vulnerability to launch a large number of attacks. For example, an attacker may masquerade as a legitimate access point to disrupt network services or to advertise false services, tricking nearby wireless stations. On the other hand, the received signal strength (RSS) is a measurement that is hard to forge arbitrarily and it is highly correlated to the transmitter's location. Assuming the attacker and the victim are separated by a reasonable distance, RSS can be used to differentiate them to detect MAC spoofing, as recently proposed by several researchers. By analyzing the RSS pattern of typical 802.11 transmitters in a 3-floor building covered by 20 air monitors, we observed that the RSS readings followed a mixture of multiple Gaussian distributions. We discovered that this phenomenon was mainly due to antenna diversity, a widely-adopted technique to improve the stability and robustness of wireless connectivity. This observation renders existing approaches ineffective because they assume a single RSS source. We propose an approach based on Gaussian mixture models, building RSS profiles for spoofing detection. Experiments on the same testbed show that our method is robust against antenna diversity and significantly outperforms existing approaches. At a 3% false positive rate, we detect 73.4%, 89.6% and 97.8% of attacks using the three proposed algorithms, based on local statistics of a single AM, combining local results from AMs, and global multi-AM detection, respectively.
Yong Sheng, Keren Tan, David Kotz, Andrew T. Campbell
INFOCOM4
2008 Anonysense: privacy-aware people-centric sensing
abstract
Personal mobile devices are increasingly equipped with the capability to sense the physical world (through cameras, microphones, and accelerometers, for example) and the, network world (with Wi-Fi and Bluetooth interfaces). Such devices offer many new opportunities for cooperative sensing applications. For example, users' mobile phones may contribute data to community-oriented information services, from city-wide pollution monitoring to enterprise-wide detection of unauthorized Wi-Fi access points. This people-centric mobile-sensing model introduces a new security challenge in the design of mobile systems: protecting the privacy of participants while allowing their devices to reliably contribute high-quality data to these large-scale applications.
Cory Cornelius, Apu Kapadia, David Kotz, Daniel Peebles, Minho Shin, Nikos Triandopoulos
MobiSys3
2008 Refocusing in 802.11 Wireless Measurement
Udayan Deshpande, Chris McDonald, David Kotz
PAM3
2008 Streaming Estimation of Information-Theoretic Metrics for Anomaly Detection (Extended Abstract)
Sergey Bratus, Joshua Brody, David Kotz, Anna Shubina
RAID3
2008 Active behavioral fingerprinting of wireless devices
abstract
We propose a simple active method for discovering facts about the chipset, the firmware or the driver of an 802.11 wireless device by observing its responses (or lack thereof) to a series of crafted non-standard or malformed 802.11 frames. We demonstrate that such responses can differ significantly enough to distinguish between a number of popular chipsets and drivers. We expect to significantly expand the number of recognized device types through community contributions of signature data for the proposed open fingerprinting framework. Our method complements known fingerprinting approaches, and can be used to interrogate and spot devices that may be spoofing their MAC addresses in order to conceal their true architecture from other stations, such as a fake AP seeking to engage clients in complex protocol frame exchange (e.g., in order to exploit a driver vulnerability). In particular, it can be used to distinguish rogue APs from legitimate APs before association.
Sergey Bratus, Cory Cornelius, David Kotz, Daniel Peebles
WISEC3
2008 The changing usage of a mature campus-wide wireless network
Tristan Henderson, David Kotz, Ilya Abyzov
Comput. Networks2
2008 Mesh-Mon: A multi-radio mesh monitoring and management system
Soumendra Nanda, David Kotz
Comput. Commun.2
2008 Data-centric middleware for context-aware pervasive computing
Ming Li 0021, David Kotz
Pervasive Mob. Comput.3
2007 Periodic properties of user mobility and access-point popularity
Minkyong Kim, David Kotz
Pers. Ubiquitous Comput.2
2006 Extracting a Mobility Model from Real User Traces
abstract
Abstract — Understanding user mobility is critical for simula-tions of mobile devices in a wireless network, but current mobility models often do not reflect real user movements. In this paper, we provide a foundation for such work by exploring mobility characteristics in traces of mobile users. We present a method to estimate the physical location of users from a large trace of mobile devices associating with access points in a wireless network. Using this method, we extracted tracks of always-on Wi-Fi devices from a 13-month trace. We discovered that the speed and pause time each follow a log-normal distribution and that the direction of movements closely reflects the direction of roads and walkways. Based on the extracted mobility characteristics, we developed a mobility model, focusing on movements among popular regions. Our validation shows that synthetic tracks match real tracks with a median relative error of 17%. I.
Minkyong Kim, David Kotz, Songkuk Kim
INFOCOM2
2006 Predictability of WLAN Mobility and Its Effects on Bandwidth Provisioning
abstract
Wireless local area networks (WLANs) are emerging as a popular technology for access to the Internet and enterprise networks. In the long term, the success of WLANs depends on services that support mobile network clients. Although other researchers have explored mobility prediction in hypothetical scenarios, evaluating their predictors analytically or with synthetic data, few studies have been able to evaluate their predictors with real user mobility data. As a first step towards filling this fundamental gap, we work with a large data set collected from the Dartmouth College campus-wide wireless network that hosts more than 500 access points and 6,000 users. Extending our earlier work that focuses on predicting the next-visited access point (i.e., location), in this work we explore the predictability of the time of user mobility. Indeed, our contributions are two-fold. First, we evaluate a series of predictors that reflect possible dependencies across time and space while benefiting from either individual or group mobility behaviors. Second, as a case study we examine voice applications and the use of handoff prediction for advance bandwidth reservation. Using application-specific performance metrics such as call drop and call block rates, we provide a picture of the potential gains of prediction. Our results indicate that it is difficult to predict handoff time accurately, when applied to real campus WLAN data. However, the findings of our case study also suggest that application performance can be improved significantly even with predictors that are only moderately accurate. The gains depend on the applications’ ability to use predictions and tolerate inaccurate predictions. In the case study, we combine the real mobility data with synthesized traffic data. The results show that intelligent prediction can lead to significant reductions in the rate at which active calls are dropped due to handoffs with marginal increments in the rate at which new calls are blocked.
Libo Song, Udayan Deshpande, Ulas C. Kozat, David Kotz, Ravi Jain
INFOCOM4
2006 On Improving Wireless Broadcast Reliability of Sensor Networks Using Erasure Codes
Arnab Paul, Umakishore Ramachandran, David Kotz
MSN4
2006 Evaluating Next-Cell Predictors with Extensive Wi-Fi Mobility Data
abstract
Location is an important feature for many applications, and wireless networks may serve their clients better by anticipating client mobility. As a result, many location predictors have been proposed in the literature, though few have been evaluated with empirical evidence. This paper reports on the results of the first extensive empirical evaluation of location predictors using a two-year trace of the mobility patterns of more than 6,000 users on Dartmouth's campus-wide Wi-Fi wireless network. The surprising results provide critical evidence for anyone designing or using mobility predictors. We implemented and compared the prediction accuracy of several location predictors drawn from four major families of domain-independent predictors, namely, Markov-based, compression-based, PPM, and SPM predictors. We found that low-order Markov predictors performed as well or better than the more complex and more space-consuming compression-based predictors
Libo Song, David Kotz, Ravi Jain, Xiaoning He
IEEE Trans. Mob. Comput.2
2005 Policy-Driven Data Dissemination for Context-Aware Applications
abstract
Context-aware pervasive-computing applications require continuous monitoring of their physical and computational environment to make appropriate adaptation decisions in time. The data streams produced by sensors, however, may overflow the queues on the dissemination path. Traditional flow-control and congestion-control policies either drop data or force the sender to pause. When the data sender is sensing the physical environment, however, a pause is equivalent to dropping data. Instead of arbitrarily dropping data that may contain important events, we present a policy-driven data dissemination service named PACK, based on an overlay-based infrastructure for efficient multicast delivery. PACK enforces application-specified policies that define how to discard or summarize data flows wherever queues overflow on the data path, notably at the mobile hosts where applications often reside. A key contribution of our approach is to uniformly apply the data-stream "packing" abstraction to queue overflow caused by network congestion, slow receivers, and temporary disconnection. We present experimental results and a detailed application study of the PACK service.
David Kotz
PerCom2
2005 Secure Context-Sensitive Authorization
abstract
There is a recent trend toward rule-based authorization systems to achieve flexible security policies. Also, new sensing technologies in pervasive computing make it possible to define context-sensitive rules, such as "allow database access only to staff who are currently located in the main office." However, these rules, or the facts that are needed to verify authority, often involve sensitive context information. This paper presents a secure context-sensitive authorization system that protects confidential information in facts or rules. Furthermore, our system allows multiple hosts in a distributed environment to perform the evaluation of an authorization query in a collaborative way; we do not need a universally trusted central host that maintains all the context information. The core of our approach is to decompose a proof for making an authorization decision into a set of subproofs produced on multiple different hosts, while preserving the integrity and confidentiality policies of the mutually untrusted principals operating these hosts
Kazuhiro Minami, David Kotz
PerCom2
2005 Secure context-sensitive authorization
Kazuhiro Minami, David Kotz
Pervasive Mob. Comput.2
2005 Analysis of a Campus-Wide Wireless Network
David Kotz, Kobby Essien
Wirel. Networks1
2004 Evaluating location predictors with extensive Wi-Fi mobility data
abstract
Location is an important feature for many applications, and wireless networks can better serve their clients by anticipating client mobility. As a result, many location predictors have been proposed in the literature, though few have been evaluated with empirical evidence. This paper reports on the results of the first extensive empirical evaluation of location predictors, using a two-year trace of the mobility patterns of over 6,000 users on Dartmouth's campus-wide Wi-Fi wireless network. We implemented and compared the prediction accuracy of several location predictors drawn from two major families of domain-independent predictors, namely Markov-based and compression-based predictors. We found that low-order Markov predictors performed as well or better than the more complex and more space-consuming compression-based predictors. Predictors of both families fail to make a prediction when the recent context has not been previously seen. To overcome this drawback, we added a simple fallback feature to each predictor and found that it significantly enhanced its accuracy in exchange for modest effort. Thus the Order-2 Markov predictor with fallback was the best predictor we studied, obtaining a median accuracy of about 72% for users with long trace lengths. We also investigated a simplification of the Markov predictors, where the prediction is based not on the most frequently seen context in the past, but the most recent, resulting in significant space and computational savings. We found that Markov predictors with this recency semantics can rival the accuracy of standard Markov predictors in some cases. Finally, we considered several seemingly obvious enhancements, such as smarter tie-breaking and aging of context information, and discovered that they had little effect on accuracy. The paper ends with a discussion and suggestions for further work.
Libo Song, David Kotz, Ravi Jain, Xiaoning He
INFOCOM2
2004 The changing usage of a mature campus-wide wireless network
abstract
Wireless Local Area Networks (WLANs) are now commonplace on many academic and corporate campuses. As "Wi-Fi" technology becomes ubiquitous, it is increasingly important to understand trends in the usage of these networks.This paper analyzes an extensive network trace from a mature 802.11 WLAN, including more than 550 access points and 7000 users over seventeen weeks. We employ several measurement techniques, including syslogs, telephone records, SNMP polling and tcpdump packet sniffing. This is the largest WLAN study to date, and the first to look at a large, mature WLAN and consider geographic mobility. We compare this trace to a trace taken after the network's initial deployment two years ago.We found that the applications used on the WLAN changed dramatically. Initial WLAN usage was dominated by Web traffic; our new trace shows significant increases in peer-to-peer, streaming multimedia, and voice over IP (VoIP) traffic. On-campus traffic now exceeds off-campus traffic, a reversal of the situation at the WLAN's initial deployment. Our study indicates that VoIP has been used little on the wireless network thus far, and most VoIP calls are made on the wired network. Most calls last less than a minute.We saw greater heterogeneity in the types of clients used, with more embedded wireless devices such as PDAs and mobile VoIP clients. We define a new metric for mobility, the "session diameter." We use this metric to show that embedded devices have different mobility characteristics than laptops, and travel further and roam to more access points. Overall, users were surprisingly non-mobile, with half remaining close to home about 98% of the time.
Tristan Henderson, David Kotz, Ilya Abyzov
MobiCom2
2004 Design and Implementation of a Large-Scale Context Fusion Network
abstract
We motivate a context fusion network (CFN), an infrastructure model that allows context-aware applications to select distributed data sources and compose them with customized data-fusion operators into a directed acyclic information fusion graph. Such a graph represents how an application computes high-level understandings of its execution context from low-level sensory data. Multiple graphs by different applications interconnect with each other to form a global graph. A key advantage of a CFN is reusability, both at code-level and instance-level, facilitated by operator composition. We designed and implemented a distributed CFN system, Solar, which maps the logical operator graph representation onto a set of overlay hosts. In particular, Solar meets the challenges inherent to heterogeneous and volatile ubicomp environments. By abstracting most complexities into the infrastructure, Solar facilitates both the development and deployment of context-aware applications. We present the operator composition model, basic services of the Solar overlay network, and programming support for the developers. We also discuss some applications built with Solar and the lessons we learned from our experience.
Ming Li 0021, David Kotz
MobiQuitous3
2004 Outdoor experimental comparison of four ad hoc routing algorithms
abstract
Most comparisons of wireless ad hoc routing algorithms involve simulated or indoor trial runs, or outdoor runs with only a small number of nodes, potentially leading to an incorrect picture of algorithm performance. In this paper, we report on an outdoor comparison of four different routing algorithms, APRL, AODV, ODMRP, and STARA, running on top of thirty-three 802.11-enabled laptops moving randomly through an athletic field. This comparison provides insight into the behavior of ad hoc routing algorithms at larger real-world scales than have been considered so far. In addition, we compare the outdoor results with both indoor ("tabletop") and simulation results for the same algorithms, examining the differences between the indoor results and the outdoor reality. Finally, we describe the software infrastructure that allowed us to implement the ad hoc routing algorithms in a comparable way, and use the same codebase for indoor, outdoor, and simulated trial runs.
Robert S. Gray, David Kotz, Calvin C. Newport, Nikita Dubrovsky, Aaron Fiske, Jason Liu 0001, Chris Masone, Susan McGrath, Yougu Yuan
MSWiM2
2004 Experimental evaluation of wireless simulation assumptions
abstract
All analytical and simulation research on ad~hoc wireless networks must necessarily model radio propagation using simplifying assumptions. We provide a comprehensive review of six assumptions that are still part of many ad hoc network simulation studies, despite increasing awareness of the need to represent more realistic features, including hills, obstacles, link asymmetries, and unpredictable fading. We use an extensive set of measurements from a large outdoor routing experiment to demonstrate the weakness of these assumptions, and show how these assumptions cause simulation results to differ significantly from experimental results. We close with a series of recommendations for researchers, whether they develop protocols, analytic models, or simulators for ad~hoc wireless networks.
David Kotz, Calvin C. Newport, Robert S. Gray, Jason Liu 0001, Yougu Yuan, Chip Elliott
MSWiM1
2003 Context-Sensitive Resource Discovery
abstract
This paper presents the "Solar" system framework that allows resources to advertise context-sensitive names and for applications to make context-sensitive name queries. The heart of our framework is a small specification language that allows composition of "context-processing operators" to calculate the desired context. Resources use the framework to register names, and applications use the framework to look up context-sensitive name descriptions. The back-end system executes these operators and constantly updates the context values, adjusting advertised names and informing applications about changes. We report experimental results from a prototype, using a modified version of the intentional naming system (INS) as the core directory service.
David Kotz
PerCom2
2003 Computational Markets to Regulate Mobile-Agent Systems
Jonathan Bredin, David Kotz, Daniela Rus, Rajiv T. Maheswaran, Orhan Çagri Imer, Tamer Basar
Auton. Agents Multi Agent Syst.2
2002 Analysis of a campus-wide wireless network
abstract
Understanding usage patterns in wireless local-area networks (WLANs) is critical for those who develop, deploy, and manage WLAN technology, as well as those who develop systems and application software for wireless networks. This paper presents results from the largest and most comprehensive trace of network activity in a large, production wireless LAN. For eleven weeks we traced the activity of nearly two thousand users drawn from a general campus population, using a campus-wide network of 476 access points spread over 161 buildings. Our study expands on those done by Tang and Baker, with a significantly larger and broader population.We found that residential traffic dominated all other traffic, particularly in residences populated by newer students; students are increasingly choosing a wireless laptop as their primary computer. Although web protocols were the single largest component of traffic volume, network backup and file sharing contributed an unexpectedly large amount to the traffic. Although there was some roaming within a network session, we were surprised by the number of situations in which cards roamed excessively, unable to settle on one access point. Cross-subnet roams were an especial problem, because they broke IP connections, indicating the need for solutions that avoid or accommodate such roams.
David Kotz, Kobby Essien
MobiCom1
2002 Armada: a parallel I/O framework for computational grids
Ron A. Oldfield, David Kotz
Future Gener. Comput. Syst.2
2002 Performance Analysis of Mobile Agents for Filtering Data Streams on Wireless Networks
David Kotz, George Cybenko, Robert S. Gray, Guofei Jiang, Ronald A. Peterson, Martin O. Hofmann, Daria A. Chacón, Kenneth R. Whitebread, James A. Hendler
Mob. Networks Appl.1
2002 D'Agents: Applications and performance of a mobile-agent system
abstract
Abstract D'Agents is a general‐purpose mobile‐agent system that has been used in several information‐retrieval applications. In this paper, we first examine one such application, operational support for military field personnel, where D'Agents greatly simplifies the task of providing efficient, application‐specific access to remote information resources. After describing the application, we discuss the key differences between D'Agents and most other mobile‐agent systems, notably its support for strong mobility and multiple agent languages. Finally, we derive a small, simple application that is representative of many information‐retrieval tasks, including those in the example application, and use this application to compare the scalability of mobile agents and traditional client/server approaches. The results confirm and quantify the usefulness of mobile code, and perhaps more importantly, confirm that intuition about when to use mobile code is usually correct. Although significant additional experiments are required to fully characterize the complex mobile‐agent performance space, the results presented here help to answer the basic question of when mobile agents should be considered at all, particularly for information‐retrieval applications. Copyright © 2002 John Wiley & Sons, Ltd.
Robert S. Gray, George Cybenko, David Kotz, Ronald A. Peterson, Daniela Rus
Softw. Pract. Exp.3
2001 Armada: A Parallel File System for Computational Grids
abstract
High-performance distributed computing appears to be shifting away from tightly-connected supercomputers to "computational grids" composed of heterogeneous systems of networks, computers, storage devices and various other devices that collectively act as a single geographically distributed "virtual" computer. One of the great challenges for this environment is providing efficient parallel data access to remote distributed data sets. In this paper, we discuss some of the issues associated with parallel I/O and computational grids and describe the design of a flexible parallel file system that allows the application to control the behavior and functionality of virtually all aspects of the file system.
Ron A. Oldfield, David Kotz
CCGRID2
2001 Special Issue: High Performance Agent Systems
abstract
High Performance
Omer F. Rana, David Kotz
Concurr. Comput. Pract. Exp.2
2000 A Formal Semantics for SPKI
Jon Howell, David Kotz
ESORICS2
2000 Performance analysis of mobile agents for filtering data streams on wireless networks
abstract
Wireless networks are an ideal environment for mobile agents, because their mobility allows them to move across an unreliable link to reside on a wired host, next to or closer to the resources they need to use. Furthermore, client-specific data transformations can be moved across the wireless link, and run on a wired gateway server, with the goal of reducing bandwidth demands. In this paper we examine the tradeoffs faced when deciding whether to use mobile agents to support a data-filtering application, in which numerous wireless clients filter information from a large data stream arriving across the wired network. We develop an analytical model and use parameters from our own experiments to explore the model's implications.
David Kotz, Guofei Jiang, Robert S. Gray, George Cybenko, Ronald A. Peterson
MSWiM1
2000 End-to-End Authorization
Jon Howell, David Kotz
OSDI2
1997 Transportable Information Agents
Daniela Rus, Robert S. Gray, David Kotz
J. Intell. Inf. Syst.3
1997 The Galley Parallel File System
abstract
Most current multiprocessor file systems are designed to use multiple disks in parallel, using the high aggregate bandwidth to meet the growing I/O requirements of parallel scientific applications. Many multiprocessor file systems provide applications with a conventional Unix-like interface, allowing the application to access multiple disks transparently. This interface conceals the parallelism within the file system, increasing the ease of programmability, but making it difficult or impossible for sophisticated programmers and libraries to use knowledge about their I/O needs to exploit that parallelism. In addition to providing an insufficient interface, most current multiprocessor file systems are optimized for a different workload than they are being asked to support. We introduce Galley, a new parallel file system that is intended to efficiently support realistic scientific multiprocessor workloads. We discuss Galley's file structure and application interface, as well as the performance advantages offered by that interface.
Nils Nieuwejaar, David Kotz
Parallel Comput.2
1997 Disk-Directed I/O for MIMD Multiprocessors
abstract
Many scientific applications that run on today's multiprocessors, such as weather forecasting and seismic analysis, are bottlenecked by their file-I/O needs. Even if the multiprocessor is configured with sufficient I/O hardware, the file system software often fails to provide the available bandwidth to the application. Although libraries and enhanced file system interfaces can make a significant improvement, we believe that fundamental changes are needed in the file server software. We propose a new technique, disk-directed I/O, to allow the disk servers to determine the flow of data for maximum performance. Our simulations show that tremendous performance gains are possible both for simple reads and writes and for an out-of-core application. Indeed, our disk-directed I/O technique provided consistent high performance that was largely independent of data distribution and obtained up to 93% of peak disk bandwidth. It was as much as 18 times faster than either a typical parallel file system or a two-phase-I/O library.
David Kotz
ACM Trans. Comput. Syst.1
1996 The Galley Parallel File System
abstract
As the 1/0 needs of parallel scientific applications increase, file systems for multiprocessors are being designed to provide applications with parallel access to multiple disks.ManY parallel file systems present applications with a conventional Unix-like interface that allows the application to access multiple disks transparently.This interface conceals the parsllelism within the file system, which increases the ease of programmability, but makes it difficult or impossible for sophisticated programmers and libraries to use knowledge about their 1/0 needs to exploit that parallelism.Furthermore, most current parallel file systems are optimized for a different workload than they are being asked to support.We introduce Galley, a new parallel file system that is intended to efficiently support realistic parallel workloads.We discuss Galley's file structure and application interface, as well as an application that has been implemented using that interface.
Nils Nieuwejaar, David Kotz
International Conference on Supercomputing2
1996 File-Access Characteristics of Parallel Scientific Workloads
abstract
Phenomenal improvements in the computational performance of multiprocessors have not been matched by comparable gains in I/O system performance. This imbalance has resulted in I/O becoming a significant bottleneck for many scientific applications. One key to overcoming this bottleneck is improving the performance of multiprocessor file systems. The design of a high-performance multiprocessor file system requires a comprehensive understanding of the expected workload. Unfortunately, until recently, no general workload studies of multiprocessor file systems have been conducted. The goal of the CHARISMA project was to remedy this problem by characterizing the behavior of several production workloads, on different machines, at the level of individual reads and writes. The first set of results from the CHARISMA project describe the workloads observed on an Intel iPSC/860 and a Thinking Machines CM-5. This paper is intended to compare and contrast these two workloads for an understanding of their essential similarities and differences, isolating common trends and platform-dependent variances. Using this comparison, we are able to gain more insight into the general principles that should guide multiprocessor file-system design.
Nils Nieuwejaar, David Kotz, Apratim Purakayastha, Carla Schlatter Ellis, Michael L. Best
IEEE Trans. Parallel Distributed Syst.2
1995 Disk-Directed I/O for an Out-of-Core Computation
abstract
New file systems are critical to obtain good I/O performance on large multiprocessors. Several researchers have suggested the use of collective file-system operations, in which all processes in an application cooperate in each I/O request. Others have suggested that the traditional low-level interface (read, write, seek) be augmented with various higher-level requests (e.g., read matrix). Collective, high-level requests permit a technique called disk-directed I/O to significantly improve performance over traditional file systems and interfaces, at least on simple I/O benchmarks. In this paper we present the results of experiments with an "out-of-core" LU-decomposition program. Although its collective interface was awkward in some places, and forced additional synchronization, disk-directed I/O was able to obtain much better overall performance than the traditional system.
David Kotz
HPDC1
1995 A data-parallel programming library for education (DAPPLE)
abstract
In the context of our overall goal to bring the concepts of parallel computing into the undergraduate curriculum, we set out to find a parallel-programming language for student use. To make it accessible to students at all levels, and to be independent of any particular hardware platform, we chose to design our own language, based on a data-parallel model and on C++. The result, DAPPLE, is a C++ class library designed to provide the illusion of a data-parallel programming language on conventional hardware and with conventional compilers. DAPPLE defines Vectors and Matrices as basic classes, with all the usual C++ operators overloaded to provide elementwise arithmetic. In addition, DAPPLE provides typical data-parallel operations like scans, permutations, and reductions. Finally, DAPPLE provides a parallel if-then-else statement to restrict the scope of the above operations to partial vectors or matrices.
David Kotz
SIGCSE1
1994 Disk-directed I/O for MIMD Multiprocessors
David Kotz
OSDI1
1994 Dynamic file-access characteristics of a production parallel scientific workload
abstract
Multiprocessors have permitted astounding increases in computational performance, but many cannot meet the intense I/O requirements of some scientific applications. An important component of any solution to this I/O bottleneck is a parallel file system that can provide high-bandwidth access to tremendous amounts of data in parallel to hundreds or thousands of processors. Most successful systems are based on a solid understanding of the expected workload, but thus far there have been no comprehensive workload characterizations of multiprocessor file systems. This paper presents the results of a three week tracing study in which all file-related activity on a massively parallel computer was recorded. Our instrumentation differs from previous efforts in that it collects information about every I/O request and about the mix of jobs running an a production environment. We also present the results of a trace-driven caching simulation and recommendations for designers of multiprocessor file systems.>
David Kotz, Nils Nieuwejaar
SC1
1994 The Expected Lifetime of "Single-Address-Space" Operating Systems
abstract
Trends toward shared-memory programming paradigms, large (64-bit) address spaces, and memory-mapped files have led some to propose the use of a single virtual-address space, shared by all processes and processors. Typical proposals require the single address space to contain all process-private data, shared data, and stored files. To simplify management of an address space where stable pointers make it difficult to re-use addresses, some have claimed that a 64-bit address space is sufficiently large that there is no need to ever re-use addresses. Unfortunately, there has been no data to either support or refute these claims, or to aid in the design of appropriate address-space management policies. In this paper, we present the results of extensive kernel-level tracing of the workstations in our department, and discuss the implications for single-address-space operating systems. We found that single-address-space systems will not outgrow the available address space, but only if reasonable space-allocation policies are used, and only if the system can adapt as larger address space becomes available.
David Kotz, Preston Crow
SIGMETRICS1
1993 The internet programming contest: a report and philosophy
abstract
article Free Access Share on The internet programming contest: a report and philosophy Authors: Vivek Khera Duke University Duke UniversityView Profile , Owen Astrachan Duke University Duke UniversityView Profile , David Kotz Dartmouth College Dartmouth CollegeView Profile Authors Info & Claims ACM SIGCSE BulletinVolume 25Issue 1March 1993 pp 48–52https://doi.org/10.1145/169073.169105Online:01 March 1993Publication History 13citation345DownloadsMetricsTotal Citations13Total Downloads345Last 12 Months18Last 6 weeks4 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteeReaderPDF
Vivek Khera, Owen L. Astrachan, David Kotz
SIGCSE3
1993 Practical Prefetching Techniques for Multiprocessor File Systems
David Kotz, Carla Schlatter Ellis
Distributed Parallel Databases1
1993 Caching and Writeback Policies in Parallel File Systems
David Kotz, Carla Schlatter Ellis
J. Parallel Distributed Comput.1
1990 Prefetching in File Systems for MIMD Multiprocessors
abstract
The question of whether prefetching blocks on the file into the block cache can effectively reduce overall execution time of a parallel computation, even under favorable assumptions, is considered. Experiments have been conducted with an interleaved file system testbed on the Butterfly Plus multiprocessor. Results of these experiments suggest that (1) the hit ratio, the accepted measure in traditional caching studies, may not be an adequate measure of performance when the workload consists of parallel computations and parallel file access patterns, (2) caching with prefetching can significantly improve the hit ratio and the average time to perform an I/O (input/output) operation, and (3) an improvement in overall execution time has been observed in most cases. In spite of these gains, prefetching sometimes results in increased execution times (a negative result, given the optimistic nature of the study). The authors explore why it is not trivial to translate savings on individual I/O requests into consistently better overall performance and identify the key problems that need to be addressed in order to improve the potential of prefetching techniques in the environment.>
David Kotz, Carla Schlatter Ellis
IEEE Trans. Parallel Distributed Syst.1
1989 Evaluation of concurrent pools
abstract
Performance considerations affecting the design of a mechanism that preserves locality and avoids high-latency remote references called the concurrent pools data structure are explored. The effectiveness of three different implementations of concurrent pools is evaluated. Experiments performed on a BBN Butterfly multiprocessor under a variety of workloads shown that the three implementations perform similarly well for light workloads, but that with stressful workloads it appears that a simple algorithm can provide better performance than a complex algorithm, designed to keep remote accesses to a minimum. Implementations can benefit by taking into account information on the nature of the operations performed by each process to help balance the elements among processes that need them.>
David Kotz, Carla Schlatter Ellis
ICDCS1
1989 Prefetching in File Systems for MIMD Multiprocessors
Carla Schlatter Ellis, David Kotz
ICPP (1)2