Jacobus E. van der Merwe

dblp:m/JEvanderMerwe · also Kobus van der Merwe · DBLP profile ↗
← Back
72ranked-venue papers
4as first author
12since 2021 · last 2025
0000-0001-5148-8278ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 37 · 2 first-author · 8 since 2021Systems, architecture and hardware · 14 · 1 since 2021Databases, data management, data science and information retrieval · 5Security and privacy · 4 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 4Software engineering, systems software and programming languages · 2 · 2 since 2021
YearPublicationVenuePosition
2025 ADDER: Service-Specific Adaptive Data-Driven Radio Resource Control for Cellular-IoT
abstract
Energy-saving methods like Discontinuous Reception (DRX) and Power Save Mode (PSM) are commonly used in Internet of Thing (IoT) applications, allowing for sleep and awake cycle adjustments to save energy. However, understanding and configuring these parameters on devices, especially actuator-type devices, is challenging for IoT service providers. Unlike sensor types, these devices must complete their sleep cycle before responding to infrequent downlink commands, making efficient parameter selection and traffic prediction vital for energy efficiency and command reception. To address this, we present ADDER, a network-side solution leveraging a context-aware traffic predictor. This predictor forecasts downlink arrival probabilities, guiding a deep deterministic policy gradient (DDPG) policymaker that selects energy-saving parameters based on thresholds defined by the IoT service providers. ADDER, leverages contextual information like day of week, hour, weather, holidays, and events, shifting the focus from individual device histories (often erratic) to analyzing broader service traffic patterns. This data-driven strategy enables ADDER to adjust energy-saving settings for the best balance between energy efficiency and latency, customizing to the unique requirements of each service and removing the burden of configuring complex network settings. We observed that ADDER meets latency needs while achieving a $\mathbf{5 . 9 \%}$ reduction in energy consumption for services requiring rapid responses. For applications prioritizing energy conservation, such as irrigation systems and city lighting, ADDER achieves a significant $32.7 \%$ reduction in energy consumption with a slight increase $(\mathbf{9 \%}$) in messages might not meet the strictest latency requirements. To evaluate the consequences of prediction inaccuracies from our predictor, we utilized a real-world shared mobility dataset provided by Austin’s Transportation Department for a case study.
Yingjing Wu, Ahmed Elmokashfi, Foivos Michelinakis, Jacobus E. van der Merwe, Shandian Zhe
WoWMoM4
2025 SigDetect: Collaborative Endpoint-based Signal Injection Attack Detection based on Channel Frequency Response
abstract
Unencrypted broadcast data in cellular networks is vulnerable to signal injection attacks that are capable of revealing sensitive information and disrupting critical services. Existing detection methods struggle with such attacks, especially for attacks with low transmission power. This paper introduces SigDetect, a collaborative anomaly detection system that leverages complex channel frequency response (CFR) measurements and machine learning to detect signal injection attacks reliably. Extensive evaluations demonstrate that individual SigDetect detectors outperform a Received Signal Strength (RSS)-based method by 32.8% in outdoor experiments with stationary radios and 26.7% in indoor experiments where one of the radios is in motion. SigDetect also outperforms a CFR approach while eliminating the need to adjust thresholds to adapt to different wireless environments. Finally, SigDetect’s collaborative approach, in which neighboring network endpoints aid in detection, improves detection accuracy from 90.2% to 97.2% while reducing the false alarm from rate 11.2% to 0.7% and the missed detection rate from 8.3% to 4.9% in an indoor environment without mobile endpoints. These results suggest that SigDetect offers a promising solution for protecting cellular networks against low-power signal injection attacks.
Yingjing Wu, Dustin Maas, Jacobus E. van der Merwe
WoWMoM3
2023 RESCue: A State-Disaggregated NFV System with Resilience, Elasticity, and State Consistency
abstract
State-disaggregated Network Function Virtualization (NFV) architectures decouple NF states from packet processing logic to achieve elasticity and resilience in stateful NFs. However, the existing state disaggregation approaches suffer from either poor NF performance due to frequent remote state access or potential inconsistencies in state updates when multiple NF instances concurrently access shared states. Moreover, they do not properly support state rejuvenation/expiration which is required for resource scalability of stateful NF operations. This paper presents a new state-disaggregated NFV system called RESCue that addresses these problems. RESCue handles remote state access differently for shared and private states. For efficient and consistent access of shared states, it leverages a lightweight custom control message protocol between NFs and a centralized state server. For private state access, it adopts a remote-paging-based interface to avoid introducing expensive blocking remote access within the critical path of NF packet processing. Finally, it utilizes non-blocking operations for state rejuvenation/expiration handling to minimize its performance overhead. Our evaluation of a RESCue prototype shows that it can handle NF scaling and failure recovery well, while supporting consistent state updates and state rejuvenation/expiration without compromising performance.
Hyunseok Chang, Sarit Mukherjee, Jacobus E. van der Merwe
NetSoft4
2023 Adjacent Channel WiFi 5 Interference on DSRC Communication at 5.9GHz
abstract
Since their controversial decision to adjust the spectrum allocation for intelligent transportation systems in November 2020, the FCC has implemented a wide range of changes. These changes include the removal of 45 MHz from existing spectrum allocations and the transition from DSRC to CV2X, both of which need to be studied in greater detail. We aimed to explore the effects of these decisions by examining the potential impacts on commercial-grade V2X hardware in a real-world, complex radio environment. This was done by characterizing DSRC and comparing its performance in a complex radio environment with different types of interference present. The results of these experiments indicate that outdoor adjacent band WiFi networks can impact DSRC operations; however, this impact is unlikely to have a measurable effect on current ITS installations.
Jacob A. Bills, Alex Orange, Jacobus E. van der Merwe
VTC2023-Spring3
2023 MAGNet: Machine Learning Guided Application-Aware Networking for Data Centers
abstract
Modern data centers are witnessing fast-growing east-west traffic on their network infrastructure due to the highly distributed data center applications. Motivated by the heterogeneity of such application workloads, we propose in this article an extensible network management architecture calledMAGNetwhich enables application-aware intra-data center networking. The crux ofMAGNetis the smart endpoint residing within end-hosts, which is empowered by machine learning combined with lightweight workload tracing to detect workload identities and enable workload-dependent packet tagging. The centralized management plane interface ofMAGNetallows network functions to interpret packet tags and perform application-aware packet processing. We demonstrate the feasibility of the architecture via prototype implementation and extensive use case evaluation. Our experiments show that the smart endpoint can fingerprint many real-world applications with 99 percent accuracy only at 1–2 percent additional CPU, and that application-aware data plane can potentially bring substantial benefits in terms of security (e.g., via identity-based microsegmentation), CPU usage (e.g., for intrusion detection) and network latency (e.g., via TCP stack customization).
Hyunseok Chang, Murali S. Kodialam, T. V. Lakshman, Sarit Mukherjee, Jacobus E. van der Merwe, Zirak Zaheer
IEEE Trans. Cloud Comput.5
2021 Nervion: a cloud native RAN emulator for scalable and flexible mobile core evaluation
abstract
Given the wide interest on mobile core systems and their pivotal role in the operations of current and future mobile network services, we focus on the issue of their effective evaluation, considering the radio access network (RAN) emulation methodology. While there exist a number of different RAN emulators, following different paradigms, they are limited in their scalability and flexibility, and moreover there is no one commonly accepted RAN emulator. Motivated by this, we present Nervion, a scalable and flexible RAN emulator for mobile core system evaluation that takes a novel cloud-native approach. Nervion embeds innovations to enable scalability via abstractions and RAN element containerization, and additionally supports an even more scalable control-plane only mode. It also offers ample flexibility in terms of realizing arbitrary RAN emulation scenarios, mapping them to compute clusters, and evaluating diverse core system designs. We develop a prototype implementation of Nervion that supports 4G and 5G standard compliant RAN emulation and integrate it into the Powder platform to benefit the research community. Our experimental evaluations validate its correctness and demonstrate its scalability relative to representative set of existing RAN emulators. We also present multiple case studies using Nervion that highlight its flexibility to support diverse types of mobile core evaluations.
Jon Larrea, Mahesh K. Marina, Jacobus E. van der Merwe
MobiCom3
2021 Nervion: a cloud native RAN emulator for core network evaluations
abstract
With the mobile networks evolving towards a software-based architecture with 5G, the research community has proposed several alternative core designs to address the issues recognized with the 4G core network architecture. It is notable, however, that these proposals are evaluated in bespoke ways which do not allow evaluate other proposals or even standard-compliant core networks, presenting several limitations in terms of the number of devices and the network load patterns that can be generated. To this end, we present Nervion, a cloud-native RAN emulator for scalable and flexible core network evaluations. Nervion leverages a compute cluster via containerization to emulate a large number of standard-compliant UEs and eNBs/gNBs generating workloads along both the control- and data-plane with a high degree of customization. This demo highlights the features of Nervion via the evaluation of a 5G core network and serves as a guide on how to use the public profile of Nervion on the Powder platform.
Jon Larrea, Mahesh K. Marina, Jacobus E. van der Merwe
MobiCom3
2021 Open source RAN slicing on POWDER: a top-to-bottom O-RAN use case
abstract
This demonstration will showcase our efforts to develop a radio access network (RAN) slicing mechanism that is controllable via management software in an Open RAN framework. To our knowledge, our work represents the first effort that combines an open source Open RAN framework with an open source mobility stack, provides a top-to-bottom RAN application via the RAN intelligent control (RIC) provided by that framework and illustrates its functionality in a realistic wireless environment. Our software is publicly available and we provide a profile in the POWDER platform to enable others to replicate and build on our work.
David Johnson 0004, Dustin Maas, Jacobus E. van der Merwe
MobiSys3
2021 Mobile and wireless research on the POWDER platform
abstract
POWDER is a highly flexible, deeply programmable, and city-scale scientific instrument that enables cutting-edge research in wireless technologies. Researchers interact with the POWDER platform via the Internet to conduct their experiments, with zero penalty for remote access. In this two-part demonstration, the POWDER implementers show how to use the platform. First, they present the workflow that researchers follow to conduct experiments. Second, they highlight some of the hardware and software building blocks available through POWDER, including components related to over-the-air wireless and mobile networking, 5G, and massive MIMO.
Joe Breen, Jonathon Duerig, Eric Eide, Mike Hibler, David Johnson 0004, Sneha Kumar Kasera, Dustin Maas, Alex Orange, Neal Patwari, Robert Ricci, David Schurig, Leigh Stoller, Jacobus E. van der Merwe, Kirk Webb, Gary Wong
MobiSys13
2021 FestNet: A Flexible and Efficient Sliced Transport Network
abstract
Network slicing was adopted as a solution for future networks to support various applications with diverse requirements. While active research has focused on this functionality, most of the work targets RAN or packet core slicing and leaves the transport network nearly untouched. With packet core functions moving to data centers and parts of RAN functions moving to edge clouds, the transport network will gain significantly more importance. To ensure stringent service level agreements (SLAs) and facilitate slice management, it is imperative for the transport network to support live slice mobility with no disruption of current services. In this paper, we present FestNet, a Flexible and Efficient Sliced Transport Network, achieved by our virtualized Programmable Data Plane (vPDP) and two-layer design. Not only conventional protocols but also stateless and stateful network functions (NFs) can be integrated as slices in FestNet. We implemented a FestNet prototype. Our evaluation shows that FestNet supports live slice migration with no packet loss and no state loss for stateful slices and that FestNet provides many times faster slice operations than implementations in related work.
Nakjung Choi, Marina Thottan, Jacobus E. van der Merwe
NetSoft4
2021 A Compliance Monitoring System for Open SDR Platforms
abstract
Next-generation wireless experimentation benefits from new large-scale open-access software defined radio (SDR) platforms. Each SDR's transmissions must be measured and monitored to guarantee spectrum compliance. The measured spectrum is, however, corrupted by external co-channel signals. This demo presents the Bidirectional Incident/Transmit Signal Separator (BITSS), a system which estimates the linear system model, the SDR's transmit signal, and the signals from other sources incident to the antenna, all on the fly and without a signal prior or system information. We implement and run BITSS on POWDER and evaluate its performance. The demo shows that BITSS enables separation over a range of signal parameters with high accuracy and alerts users and the operator whenever a spectrum violation occurs.
Jie Wang 0144, Jacobus E. van der Merwe, Neal Patwari
SenSys2
2021 Powder: Platform for Open Wireless Data-driven Experimental Research
Joe Breen, Andrew Buffmire, Jonathon Duerig, Kevin Dutt, Eric Eide, Anneswa Ghosh, Mike Hibler, David Johnson 0004, Sneha Kumar Kasera, Earl Lewis, Dustin Maas, Caleb Martin, Alex Orange, Neal Patwari, Daniel Reading, Robert Ricci, David Schurig, Leigh Stoller, Allison Todd, Jacobus E. van der Merwe, Naren Viswanathan, Kirk Webb, Gary Wong
Comput. Networks20
2019 WASPP: Workflow Automation for Security Policy Procedures
abstract
Every day, university networks are bombarded with attempts to steal the sensitive data of the various disparate domains and organizations they serve. For this reason, universities form teams of information security specialists called a Security Operations Center (SOC) to manage the complex operations involved in monitoring and mitigating such attacks. When a suspicious event is identified, members of the SOC are tasked to understand the nature of the event in order to respond to any damage the attack might have caused. This process is defined by administrative policies which are often very high-level and rarely systematically defined. This impedes the implementation of generalized and automated event response solutions, leading to specific ad hoc solutions based primarily on human intuition and experience as well as immediate administrative priorities. These solutions are often fragile, highly specific, and more difficult to reuse in other scenarios.
Ren Quinn, Nico Holguin, Ben Poster, Corey Roach, Jacobus E. van der Merwe
CNSM5
2019 Critical Reroute: A Practical Approach to Network Flow Prioritization using Segment Routing
abstract
It is widely recognized that reliable communications are a key element of a successful response to a disaster situation. To address this need, local and regional governments in all parts of the world have deployed dedicated communications networks for first responders. These systems are often prohibitively expensive, voice-only, and are needed only on rare occasions. It would be more cost-effective to use already-existing networks or to deploy networks for shared use. However, due to the sudden increase in demand or physical failure caused by the disaster, shared networks may become overloaded. In such situations, it would be desirable to prioritize traffic flows belonging to public safety applications over others. Solutions such as priority queuing and differentiated services provide partial answers to that goal but leave other problems unsolved. This work presents a novel solution using Segment Routing and a Genetic Algorithm optimizer to minimize the impact of network overload on critical traffic flows. The results show that these methods can reroute flows using a single midpoint such that the total network overload is reduced compared to traditional shortest-path routing while avoiding unnecessarily long paths and taking priority of flows into account.
Simon Redman, David Johnson 0004, Jacobus E. van der Merwe
LANMAN3
2019 Fluorescence: Detecting Kernel-Resident Malware in Clouds
Min Du 0003, David Johnson 0004, Robert Ricci, Jacobus E. van der Merwe, Eric Eide
RAID5
2018 I Heard It through the Firewall: Exploiting Cloud Management Services as an Information Leakage Channel
abstract
Though there has been much study of information leakage channels exploiting shared hardware resources (memory, cache, and disk) in cloud environments, there has been less study of the exploitability of shared software resources. In this paper, we analyze the exploitability of cloud networking services (which are shared among cloud tenants) and introduce a practical method for building information leakage channels by monitoring workloads on the cloud networking services through the virtual firewall. We also demonstrate the practicality of this attack by implementing two different covert channels in OpenStack as well as a new class of side channels that can eavesdrop on infrastructure-level events. By utilizing a Long Short-Term Memory (LSTM) neural network model, our side channel attack could detect infrastructure level VM creation/termination events with 93.3% accuracy.
Hyun Wook Baek, Eric Eide, Robert Ricci, Jacobus E. van der Merwe
SoCC4
2018 MobileStream: a scalable, programmable and evolvable mobile core control plane platform
abstract
Control planes in future mobile core networks face two new challenges. First, they must scale to process the growing control traffic generated by an ever increasing number of mobile devices. Second, they must be flexible and evolvable to support the range of emerging service abstractions and to realize customized network slices to meet the broad range of requirements of these networks. To address these challenges, we propose MobileStream, a scalable, programmable, and evolvable mobile core control plane platform. MobileStream provides a set of refactored basic building blocks, functionally decomposed from existing monolithic control plane components. It leverages realtime streaming frameworks to assemble, execute, and scale these blocks as streaming control plane applications. Moreover, it allows users to add their own functions to customize and optimize streaming control plane applications. We present several streaming control plane applications to showcase the flexibility and generality of MobileStream. We describe our extensive functional testing, with a variety of mobile devices and base stations, to validate the MobileStream prototype, and present the results of large-scale experiments demonstrating its scalability.
Junguk Cho, Ryan Stutsman, Jacobus E. van der Merwe
CoNEXT3
2018 ECHO: A Reliable Distributed Cellular Core Network for Hyper-scale Public Clouds
abstract
Economies of scale associated with hyper-scale public cloud platforms offer flexibility and cost-effectiveness, resulting in various services and businesses moving to the cloud. One area with little progress in this direction is cellular core networks. A cellular core network manages the state of cellular clients; it is essentially a large distributed state machine with very different virtualization challenges compared to typical cloud services. In this paper we present a novel cellular core network architecture, called ECHO, particularly suited to public cloud deployments, where the availability guarantees might be an order of magnitude worse compared to existing (redundant) hardware platforms. We present the design and implementation of our approach and evaluate its functionality on a public cloud platform. Analysis shows ECHO promises higher availability than existing telco solutions.
Binh Nguyen 0003, Tian Zhang 0005, Bozidar Radunovic, Ryan Stutsman, Thomas Karagiannis, Jakub Kocur, Jacobus E. van der Merwe
MobiCom7
2017 CloudSight: A tenant-oriented transparency framework for cross-layer cloud troubleshooting
abstract
Troubleshooting in an infrastructure-as-a-Service (IaaS) cloud platform is an inherently difficult task because it is a multi-player as well as multi-layer environment where tenant and provider effectively share administrative duties. To address these concerns, we present our work on CloudSight in which cloud providers allow tenants greater system-wide visibility through a transparency-as-a-service abstraction. We present the design, implementation, and evaluation of CloudSight in the OpenStack cloud platform. We also develop two example applications that make use of the CloudSight abstraction and use the applications to explore real cloud problems.
Hyun Wook Baek, Abhinav Srivastava, Jacobus E. van der Merwe
CCGrid3
2017 Polygravity: traffic usage accountability via coarse-grained measurements in multi-tenant data centers
abstract
Network usage accountability is critical in helping operators and customers of multi-tenant data centers deal with concerns such as capacity planning, resource allocation, hotspot detection, link failure detection, and troubleshooting. However, the cost of measurements and instrumentation to achieve flow-level accountability is non-trivial. We propose Polygravity to determine tenant traffic usage via lightweight measurements in multi-tenant data centers. We adopt a tomogravity model widely used in ISP networks, and adapt it to a multi-tenant data center environment. By integrating datacenter-specific domain knowledge, sampling-based partial estimation and gravity-based internal sinks/sources estimation, Polygravity addresses two key challenges for adapting tomogravity to a data center environment: sparse traffic matrices and internal traffic sinks/sources. We conducted extensive evaluation of our approach using realistic data center workloads. Our results show that Polygravity can determine tenant IP flow usage with less than 1% average relative error for tenants with fine-grained domain knowledge. In addition, for tenants with coarse-grained domain knowledge and with partial host-based sampling, Polygravity reduces the relative error of sampling-based estimation by 1/3.
Hyun Wook Baek, Cheng Jin 0008, Guofei Jiang, Cristian Lumezanu, Jacobus E. van der Merwe, Ning Xia
SoCC5
2017 CapNet: security and least authority in a capability-enabled cloud
abstract
We present CapNet, a capability-based network architecture designed to enable least authority and secure collaboration in the cloud. CapNet allows fine-grained management of rights, recursive delegation, hierarchical policies, and least privilege. To enable secure collaboration, CapNet extends a classical capability model with support for decentralized authority. We implement CapNet in the substrate of a software-defined network, integrate it with the OpenStack cloud, and develop protocols enabling secure multi-party collaboration.
Anton Burtsev, David Johnson 0004, Josh Kunz, Eric Eide, Jacobus E. van der Merwe
SoCC5
2017 AutoFocus: Automatically scoping the impact of anomalous service events
abstract
Networks, and the services they enable, are increasingly diverse and highly utilized. From DSL and fiber-to-the-home access networks, to cellular mobile networks, to contentdelivery networks; all require extensive monitoring in order to meet the increase of user expectations of the availability and quality of those services provided to them. The complexity of these networks and services require better management on the part of providers as the data resulting from service monitoring experiences an increase in dimensionality, making it difficult to fully interpret anomalies in the data. For example, anomaly detection generally says “I found an anomaly with mobile phone A in market Z”. But it is more useful to know what other phones and what other markets are also experiencing the same anomaly.
Ren Quinn, Zihui Ge, Jacobus E. van der Merwe
CNSM4
2017 Typhoon: An SDN Enhanced Real-Time Big Data Streaming Framework
abstract
Stream processing pipelines operated by current big data streaming frameworks present two problems. First, the pipelines are not flexible, controllable, and programmable enough to accommodate dynamic streaming application needs. Second, the application-level data routing over the pipelines do not exhibit optimal performance for increasingly common one-to-many communication. To address these problems, we propose an SDN-based real-time big data streaming framework called Typhoon, that tightly integrates SDN functionality into a real-time stream framework. By partially offloading application-layer data routing and control to the network layer via SDN interfaces and protocols, Typhoon provides on-the-fly programmability of both the application and network layers, and achieve high-performance data routing. In addition, Typhoon SDN controller exposes cross-layer information, from both the application and the network, to SDN control plane applications to extend the framework's functionality. We introduce several SDN control plane applications to illustrate these benefits.
Junguk Cho, Hyunseok Chang, Sarit Mukherjee, T. V. Lakshman, Jacobus E. van der Merwe
CoNEXT5
2017 SIMECA: SDN-based IoT Mobile Edge Cloud Architecture
abstract
In future mobile networks, e.g., 5G, emerging IoT services are expected to support billions of IoT devices with unique characteristics and traffic patterns. In this paper we propose an SDN-based IoT Mobile Edge Cloud Architecture (SIMECA1) which can deploy diverse IoT services at the mobile edge by leveraging distributed, lightweight control and data planes optimized for IoT communications. We prototyped our architecture using a pre-commercial mobile networking software stack to demonstrate the feasibility and utility of our approach.
Binh Nguyen 0003, Nakjung Choi, Marina Thottan, Jacobus E. van der Merwe
IM4
2017 Poster: A New Scalable, Programmable and Evolvable Mobile Control Plane Platform
abstract
We propose a new scalable, programmable and evolvable mobile control plane platform running on realtime stream frameworks for future mobile networks. We build our prototype and show its feasibility by using Cellular Internet of Things (CIoT) as an example use case in a realistic mobile networking testbed.
Junguk Cho, Jacobus E. van der Merwe
MobiCom2
2017 Orchestrating the Data-Plane of Virtual LTE Core Networks
abstract
Growing demand for data and increasing number of devices are drastically changing the scale of operation in mobile networks. Future services and business models require efficient provisioning with enhanced traffic management. It is hard to meet these requirements on today's mobile networks that are deployed over specialized hardware. While operators are keen to adopt NFV (Network Function Virtualization) to virtualize their networks, virtualized mobile network deployments face a few technical barriers. To address these challenges, we design SCOPE that effectively applies concepts from SDN and distributed systems to realize NFV-based LTE core networks. Using centralized allocation, SCOPE effectively manages the resources across multiple telecom data-centers in a way to meet the traffic requirements. To enforce the computed al- locations, SCOPE includes flexible and efficient mechanisms to configure the data-plane. With full compliance to 3GPP- based protocols, SCOPE ensures faster and cost-effective deployments. The efficacy of SCOPE is shown using a prototype implementation and large-scale simulations.
Rajesh Mahindra, Karthikeyan Sundaresan, Sneha Kumar Kasera, Jacobus E. van der Merwe, Sampath Rangarajan
SECON5
2016 ACACIA: Context-aware Edge Computing for Continuous Interactive Applications over Mobile Networks
abstract
There is widespread agreement that future continuous interactive (CI) applications will require edge computing capabilities from mobile networks. There is also widespread expectation that the emerging 5G network architecture, with its constituent technology components, will be the context in which this will be realized. Indeed many of the components that will be part of such an environment have been studied in standalone manner. However, the question of whether an end-to-end combination of these components would satisfy application requirements, or indeed, how these components would be combined into service offerings by mobile network providers, have not been meaningfully addressed. Towards addressing these challenges, we propose ACACIA - a service abstraction framework that enables CI applications on edge clouds in mobile networks. Evaluation of our prototype implementation shows that our holistic approach provides a 70% end-to-end application level latency reduction when compared with existing cloud and mobile solutions.
Junguk Cho, Karthikeyan Sundaresan, Rajesh Mahindra, Jacobus E. van der Merwe, Sampath Rangarajan
CoNEXT4
2016 HyPer4: Using P4 to Virtualize the Programmable Data Plane
abstract
Through virtualization, single physical data planes can logically support multiple networking contexts. We propose HyPer4 as a portable virtualization solution. HyPer4 provides a general purpose program, written in the P4 dataplane programming language, that may be dynamically configured to adopt behavior that is functionally equivalent to other P4 programs. HyPer4 extends, through software, the following features to diverse P4-capable devices: the ability to logically store multiple programs and either run them in parallel (network slicing) or as hot-swappable snapshots; and virtual networking between programs (supporting program composition or multi-tenant service interaction). HyPer4 permits modifying the set of programs, as well as the virtual network connecting them, at runtime, without disrupting currently active programs. We show that realistic ASICs-based hardware would be capable of running HyPer4 today.
David Hancock, Jacobus E. van der Merwe
CoNEXT2
2016 Repeatable mobile networking research with phantomNet: demo
abstract
We will demonstrate features and capabilities of the PhantomNet testbed. PhantomNet is a mobile testbed, at the University of Utah, aimed at enabling a broad range of mobile networking related research. PhantomNet is remotely accessible and open to the mobile networking research community.
Junguk Cho, Jonathon Duerig, Eric Eide, Binh Nguyen 0003, Robert Ricci, Aisha Syed, Jacobus E. van der Merwe, Kirk Webb, Gary Wong
MobiCom7
2016 Acacia - context-aware edge computing for continuous interactive applications over mobile networks: demo
abstract
We propose Acacia- a service abstraction framework that enables continuous interactive (CI) applications on edge clouds in mobile networks. We will demonstrate the Acacia architecture and illustrate its feasibility by using an augmented reality application as an example use case.
Junguk Cho, Karthikeyan Sundaresan, Rajesh Mahindra, Jacobus E. van der Merwe, Sampath Rangarajan
MobiCom4
2016 Proteus: a network service control platform for service evolution in a mobile software defined infrastructure
abstract
We present Proteus, a mobile network service control platform to enable safe and rapid evolution of services in a mobile software defined infrastructure (SDI). Proteus allows for network service and network component functionality to be specified in templates. These templates are used by the Proteus orchestrator to realize and modify service instances based on the specifics of a service creation request and the availability of resources in the mobile SDI and allows for service specific policies to be implemented. We evaluate our Proteus prototype in a realistic mobile networking testbed illustrating its ability to support service evolution.
Aisha Syed, Jacobus E. van der Merwe
MobiCom2
2016 OpenEdge: A dynamic and secure open service edge network
abstract
High performance edge networks, such as fiber-to-the-premises (FTTP), are increasingly being deployed by municipalities and communities to support advanced services and applications. The complexity of operating these networks often means that their full potential is not being reached and they are relegated to being fast access pipes to the Internet. In this paper, we present our work on OpenEdge, a dynamic and secure open service edge network architecture. OpenEdge provides a control architecture that automates the configuration of the edge network in a cloud-like manner to simplify the introduction of new network services and applications.
Josh Kunz, Christopher Becker, Mohamed Jamshidy, Sneha Kumar Kasera, Robert Ricci, Jacobus E. van der Merwe
NOMS6
2016 KnowNet: Towards a knowledge plane for enterprise network management
abstract
Network management tasks remain tedious and error-prone, and often require complex reasoning on the part of the network administrator. With KnowNet we address the challenge of reasoning about network management by approaching it as a set of cooperating applications executing over a knowledge graph which captures data and information about the network and the applications that manage and reason over it. We apply our approach to enterprise network management by developing a suite of cooperating applications that deals with security and application performance management in an enterprise network.
Ren Quinn, Josh Kunz, Aisha Syed, Joe Breen, Sneha Kumar Kasera, Robert Ricci, Jacobus E. van der Merwe
NOMS7
2015 Potassium: penetration testing as a service
abstract
Penetration testing---the process of probing a deployed system for security vulnerabilities---involves a fundamental tension. If one tests a production system, there is a real danger of collateral damage; this is particularly true for systems hosted in the cloud due to the presence of other tenants. If one tests against a separate system brought up to model the live one, the dynamic state of the production system is not captured, and the value of the test is reduced. This paper presents Potassium, which provides penetration testing as a service (PTaaS) and resolves this tension for system owners, penetration testers, and cloud providers. Potassium uses techniques originally developed for live migration of virtual machines to clone them instead, capturing their full disk, memory, and network state. Potassium isolates the cloned system from the rest of the cloud, providing confidence that side effects of the penetration test will not harm other tenants. The penetration tester effectively owns the cloned system, allowing testing to be more thorough, efficient, and automatable. Experiments with our Potassium prototype show that PTaaS can detect real-world vulnerabilities while having minimal impact on cloud-based production systems.
Dallin Abendroth, Yuankai Guo, Hyun Wook Baek, Eric Eide, Robert Ricci, Jacobus E. van der Merwe
SoCC8
2015 Scaling the LTE control-plane for future mobile access
abstract
In addition to growth of data traffic, mobile networks are bracing for a significant rise in the control-plane signaling. While a complete re-design of the network to overcome inefficiencies may help alleviate the effects of signaling, our goal is to improve the design of the current platform to better manage the signaling. To meet our goal, we combine two key trends. Firstly, mobile operators are keen to transform their networks with the adoption of Network Function Virtualization (NFV) to ensure economies of scales. Secondly, growing popularity of cloud computing has led to advances in distributed systems. In bringing these trends together, we solve several challenges specific to the context of telecom networks. We present SCALE - A framework for effectively virtualizing the MME (Mobility Management Entity), a key control-plane element in LTE. SCALE is fully compatible with the 3GPP protocols, ensuring that it can be readily deployed in today's networks. SCALE enables (i) computational scaling with load and number of devices, and (ii) computational multiplexing across data centers, thereby reducing both, the latencies for control-plane processing, and the VM provisioning costs. Using an LTE prototype implementation and large-scale simulations, we show the efficacy of SCALE.
Rajesh Mahindra, Karthikeyan Sundaresan, Sneha Kumar Kasera, Jacobus E. van der Merwe, Sampath Rangarajan
CoNEXT5
2015 ABSENCE: Usage-based Failure Detection in Mobile Networks
abstract
We present our proposed ABSENCE system which detects service disruptions in mobile networks using aggregated customer usage data. ABSENCE monitors aggregated customer usage to detect when aggregated usage is lower than expected in a given geographic region (e.g., zip code), across a given customer device type, or for a given service. Such a drop in expected usage is interpreted as a sign of a potential service disruption being experienced in that region/device type/service. ABSENCE effectively deals with users' mobility and scales to detect failures in various mobile services (e.g., voice, data, SMS, MMS, etc). We perform a systematic evaluation of our proposed approach by introducing synthetic failures in measurements obtained from a US operator. We also compare our results with ground truth (real service disruptions) obtained from the mobile operator.
Binh Nguyen 0003, Zihui Ge, Jacobus E. van der Merwe, Jennifer Yates
MobiCom3
2015 Efficient, adaptive and scalable device activation for M2M communications
abstract
When traffic arrives from the network for an idled mobile device, the network executes device activation procedures to wake the device up. Current device activation mechanisms are ill suited to support the expected growth of machine-to-machine (M2M) devices and traffic. We propose an adaptive device activation architecture for LTE/EPC cellular networks that adapts to network conditions and M2M application requirements to realize scalable device activation without increasing the resources used for this purpose. Our evaluation shows that our adaptive approach enables the network to handle M2M applications with a large number of devices without negatively impacting existing human-to-human (H2H) and human-to-machine (H2M) traffic.
Binh Nguyen 0003, Vijay Gopalakrishnan, Sneha Kumar Kasera, Seungjoon Lee, Jacobus E. van der Merwe
SECON6
2015 CloudNet: Dynamic Pooling of Cloud Resources by Live WAN Migration of Virtual Machines
abstract
Virtualization technology and the ease with which virtual machines (VMs) can be migrated within the LAN have changed the scope of resource management from allocating resources on a single server to manipulating pools of resources within a data center. We expect WAN migration of virtual machines to likewise transform the scope of provisioning resources from a single data center to multiple data centers spread across the country or around the world. In this paper, we present the CloudNet architecture consisting of cloud computing platforms linked with a virtual private network (VPN)-based network infrastructure to provide seamless and secure connectivity between enterprise and cloud data center sites. To realize our vision of efficiently pooling geographically distributed data center resources, CloudNet provides optimized support for live WAN migration of virtual machines. Specifically, we present a set of optimizations that minimize the cost of transferring storage and virtual machine memory during migrations over low bandwidth and high-latency Internet links. We evaluate our system on an operational cloud platform distributed across the continental US. During simultaneous migrations of four VMs between data centers in Texas and Illinois, CloudNet's optimizations reduce memory migration time by 65% and lower bandwidth consumption for the storage and memory transfer by 19 GB, a 50% reduction.
Timothy Wood 0001, K. K. Ramakrishnan, Prashant J. Shenoy, Jacobus E. van der Merwe, Jinho Hwang, Guyue Liu, Lucas Chaufournier
IEEE/ACM Trans. Netw.4
2014 CloudVMI: Virtual Machine Introspection as a Cloud Service
abstract
Virtual machine introspection (VMI) is a mechanism that allows indirect inspection and manipulation of the state of virtual machines. The indirection of this approach offers attractive isolation properties that has resulted in a variety of VMI-based applications dealing with security, performance, and debugging in virtual machine environments. Because it requires privileged access to the virtual machine monitor, VMI functionality is unfortunately not available to cloud users on public cloud platforms. In this paper, we present our work on the CloudVMI architecture to address this concern. CloudVMI virtualizes the VMI interface and makes it available as-a-service in a cloud environment. Because it allows introspection of users' VMs running on arbitrary physical machines in a cloud environment, our VMI-as-a-service abstraction allows a new class of cloud-centric VMI applications to be developed. We present the design and implementation of CloudVMI in the Xen hypervisor environment. We evaluate our implementation using a number of VMI applications, including a simple application that illustrates the cross-physical machine capabilities of CloudVMI.
Hyun Wook Baek, Abhinav Srivastava, Jacobus E. van der Merwe
IC2E3
2013 DEFINED: Deterministic Execution for Interactive Control-Plane Debugging
Chia-Chi Lin, Virajith Jalaparti, Matthew Caesar 0001, Jacobus E. van der Merwe
USENIX ATC4
2012 TROPIC: Transactional Resource Orchestration Platform in the Cloud
Changbin Liu, Yun Mao, Xu Chen 0028, Mary F. Fernández, Boon Thau Loo, Jacobus E. van der Merwe
USENIX ATC6
2012 Enterprise-Ready Virtual Cloud Pools: Vision, Opportunities and Challenges
abstract
Cloud computing platforms such as Amazon EC2 provide customers with flexible, on demand resources at low cost. However, while existing offerings are useful for providing basic computation and storage resources, they have not provided the transparency, security and network controls that many enterpise customers would like. While cloud computing has a great potential to change how enterprises run and manage their IT systems, a more comprehensive control over network resources and security needs to be provided for such users. Towards this goal, we propose a Virtual Cloud Pool abstraction to logically unify cloud and enterprise data center resources, and present the vision behind CloudNet, a cloud platform architecture which utilizes virtual private networks to securely and seamlessly link cloud and enterprise sites. It also enables the pooling of resources across data centers to provide enterprises the capability to have cloud resources that are dynamic and adaptive to their needs. We describe several usage scenarios for virtual cloud pools and discuss the benefits of using this abstraction in enterprise settings.
Timothy Wood 0001, K. K. Ramakrishnan, Prashant J. Shenoy, Jacobus E. van der Merwe
Comput. J.4
2012 Practical Network-Wide Compression of IP Routing Tables
abstract
The memory Internet routers use to store paths to destinations is expensive, andmustbecontinuallyupgradedinthefaceofsteadilyincreasingrouting table size. Unfortunately, routing protocols are not designed to gracefully handle cases where memory becomes full, which arises increasingly often due to misconfigurations and routing table growth. Hence router memory must typically be heavily overprovisioned by network operators, inflating operating costs and administrative effort. The research community has primarily focused on clean-slate solutions that cannot interoperate with the deployed base of protocols. This paper presents an incrementally-deployable Memory Management System (MMS) that reduces associated router state by up to 70%. The MMS coalesces prefixes to reduce memory consumption and can be deployed locally on each router or centrally on a route server. The system can operate transparently, without requiring changes in other ASes. Our memory manager can extend router lifetimes up to seven years, given current prefix growth trends. 1.
Elliott Karpilovsky, Matthew Caesar 0001, Jennifer Rexford, Aman Shaikh, Jacobus E. van der Merwe
IEEE Trans. Netw. Serv. Manag.5
2011 Cloud Resource Orchestration: A Data-Centric Approach
Yun Mao, Changbin Liu, Jacobus E. van der Merwe, Mary F. Fernández
CIDR3
2011 PipeCloud: using causality to overcome speed-of-light delays in cloud-based disaster recovery
abstract
Disaster Recovery (DR) is a desirable feature for all enterprises, and a crucial one for many. However, adoption of DR remains limited due to the stark tradeoffs it imposes. To recover an application to the point of crash, one is limited by financial considerations, substantial application overhead, or minimal geographical separation between the primary and recovery sites. In this paper, we argue for cloud-based DR and pipelined synchronous replication as an antidote to these problems. Cloud hosting promises economies of scale and on-demand provisioning that are a perfect fit for the infrequent yet urgent needs of DR. Pipelined synchrony addresses the impact of WAN replication latency on performance, by efficiently overlapping replication with application processing for multi-tier servers. By tracking the consequences of the disk modifications that are persisted to a recovery site all the way to client-directed messages, applications realize forward progress while retaining full consistency guarantees for client-visible state in the event of a disaster. PipeCloud, our prototype, is able to sustain these guarantees for multi-node servers composed of black-box VMs, with no need of application modification, resulting in a perfect fit for the arbitrary nature of VM-based cloud hosting. We demonstrate disaster failover to the Amazon EC2 platform, and show that PipeCloud can increase throughput by an order of magnitude and reduce response times by more than half compared to synchronous replication, all while providing the same zero data loss consistency guarantees.
Timothy Wood 0001, H. Andrés Lagar-Cavilla, K. K. Ramakrishnan, Prashant J. Shenoy, Jacobus E. van der Merwe
SoCC5
2011 CloudNet: dynamic pooling of cloud resources by live WAN migration of virtual machines
abstract
Virtual machine technology and the ease with which VMs can be migrated within the LAN, has changed the scope of resource management from allocating resources on a single server to manipulating pools of resources within a data center. We expect WAN migration of virtual machines to likewise transform the scope of provisioning compute resources from a single data center to multiple data centers spread across the country or around the world. In this paper we present the CloudNet architecure as a cloud framework consisting of cloud computing platforms linked with a VPN based network infrastructure to provide seamless and secure connectivity between enterprise and cloud data center sites. To realize our vision of efficiently pooling geographically distributed data center resources, CloudNet provides optimized support for live WAN migration of virtual machines. Specifically, we present a set of optimizations that minimize the cost of transferring storage and virtual machine memory during migrations over low bandwidth and high latency Internet links. We evaluate our system on an operational cloud platform distributed across the continental US. During simultaneous migrations of four VMs between data centers in Texas and Illinois, CloudNet's optimizations reduce memory migration time by 65% and lower bandwidth consumption for the storage and memory transfer by 19GB, a 50% reduction.
Timothy Wood 0001, K. K. Ramakrishnan, Prashant J. Shenoy, Jacobus E. van der Merwe
VEE4
2011 A Practical Architecture for an Anycast CDN
abstract
IP Anycast has many attractive features for any service that involve the replication of multiple instances across the Internet. IP Anycast allows multiple instances of the same service to be “naturally” discovered, and requests for this service to be delivered to the closest instance. However, while briefly considered as an enabler for content delivery networks (CDNs) when they first emerged, IP Anycast was deemed infeasible in that environment. The main reasons for this decision were the lack of load awareness of IP Anycast and unwanted side effects of Internet routing changes on the IP Anycast mechanism. In this article we re-evaluate IP Anycast for CDNs by proposing a load-aware IP Anycast CDN architecture. Our architecture is prompted by recent developments in route control technology, as well as better understanding of the behavior of IP Anycast in operational settings. Our architecture makes use of route control mechanisms to take server and network load into account to realize load-aware Anycast. We show that the resulting redirection requirements can be formulated as a Generalized Assignment Problem and present practical algorithms that address these requirements while at the same time limiting connection disruptions that plague regular IP Anycast. We evaluate our algorithms through trace based simulation using traces obtained from a production CDN network.
Hussein A. Alzoubi, Seungjoon Lee, Michael Rabinovich, Oliver Spatscheck, Jacobus E. van der Merwe
ACM Trans. Web5
2010 Declarative configuration management for complex and dynamic networks
abstract
Network management and operations are complicated, tedious, and error-prone, requiring signifcant human involvement and domain knowledge. As the complexity involved inevitably grows due to larger scale networks and more complex protocol features, human operators are increasingly short-handed, despite the best effort from existing support systems to make it otherwise. This paper presents coolaid, a system under which the domain knowledge of device vendors and service providers is formally captured by a declarative language. Through effcient and powerful rule-based reasoning on top of a database-like abstraction over a network of devices, coolaid enables new management primitives to perform network-wide reasoning, prevent misconfguration, and automate network confguration, while requiring minimum operator effort. We describe the design and prototype implementation of coolaid, and demonstrate its effectiveness and scalability through various realistic network management tasks.
Xu Chen 0028, Yun Mao, Z. Morley Mao, Jacobus E. van der Merwe
CoNEXT4
2010 Towards a ubiquitous cloud computing infrastructure
abstract
In this extended abstract we explore the architectural components of a Cloud Control Architecture with the aid of a number of cloud computing use cases. We specifically consider cloudbursting and follow-the-sun and focus on the mechanisms and user/provider interactions that would make these scenarios real. We are particularly concerned with the coordination of cloud and networking resources and mechanisms that would be applicable to cloud providers that are also network service providers.
Jacobus E. van der Merwe, K. K. Ramakrishnan, Michael Fairchild, Ashley Flavel, Joe Houle, H. Andrés Lagar-Cavilla, John Mulligan
LANMAN1
2010 Seamless BGP Migration with Router Grafting
Eric Keller, Jennifer Rexford, Jacobus E. van der Merwe
NSDI3
2009 PACMAN: a platform for automated and controlled network operations and configuration management
abstract
The lack of automation associated with network operations in general and network configuration management in particular, is widely recognized as a significant contributing factor to user-impacting network events. In this paper we present our work on the PACMAN system, a Platform for Automated and Controlled network operations and configuration MANagement. PACMAN realizes network operations by executing active documents, which systematically capture the dynamics in network management tasks. Active documents not only enable the complete execution of low-level configuration management tasks, but also allow the construction of more sophisticated tasks, while imposing additional reasoning logic to realize network-wide management objectives. We present the design, realization and evaluation of the PACMAN framework and illustrate its utility by presenting the implementation of several sophisticated operational tasks.
Xu Chen 0028, Z. Morley Mao, Jacobus E. van der Merwe
CoNEXT3
2009 Toward Interactive Debugging for ISP Networks
Chia-Chi Lin, Matthew Caesar 0001, Jacobus E. van der Merwe
HotNets3
2009 ShadowNet: A Platform for Rapid and Safe Network Evolution
Xu Chen 0028, Z. Morley Mao, Jacobus E. van der Merwe
USENIX ATC3
2009 Anycast-aware transport for content delivery networks
abstract
Anycast-based content delivery networks (CDNs) have many properties that make them ideal for the large scale distribution of content on the Internet. However, because routing changes can result in a change of the endpoint that terminates the TCP session, TCP session disruption remains a concern for anycast CDNs, especially for large file downloads. In this paper we demonstrate that this problem does not require any complex solutions. In particular, we present the design of a simple, yet efficient, mechanism to handle session disruptions due to endpoint changes. With our mechanism, a client can continue the download of the content from the point at which it was before the endpoint change. Furthermore, CDN servers purge the TCP connection state quickly to handle frequent switching with low system overhead.
Zakaria Al-Qudah, Seungjoon Lee, Michael Rabinovich, Oliver Spatscheck, Jacobus E. van der Merwe
WWW5
2008 Virtual routers on the move: live router migration as a network-management primitive
abstract
The complexity of network management is widely recognized as one of the biggest challenges facing the Internet today. Point solutions for individual problems further increase system complexity while not addressing the underlying causes. In this paper, we argue that many network-management problems stem from the same root cause---the need to maintain consistency between the physical and logical configuration of the routers. Hence, we propose VROOM (Virtual ROuters On the Move), a new network-management primitive that avoids unnecessary changes to the logical topology by allowing (virtual) routers to freely move from one physical node to another. In addition to simplifying existing network-management tasks like planned maintenance and service deployment, VROOM can also help tackle emerging challenges such as reducing energy consumption. We present the design, implementation, and evaluation of novel migration techniques for virtual routers with either hardware or software data planes. Our evaluation shows that VROOM is transparent to routing protocols and results in no performance impact on the data traffic when a hardware-based data plane is used.
Eric Keller, Brian Biskeborn, Jacobus E. van der Merwe, Jennifer Rexford
SIGCOMM4
2008 Anycast CDNS revisited
abstract
Because it is an integral part of the Internet routing apparatus, and because it allows multiple instances of the same service to be "naturally" discovered, IP Anycast has many attractive features for any service that involve the replication of multiple instances across the Internet. While briefly considered as an enabler when content distribution networks (CDNs) first emerged, the use of IP Anycast was deemed infeasible in that environment. The main reasons for this decision were the lack of load awareness of IP Anycast and unwanted side effects of Internet routing changes on the IP Anycast mechanism. Prompted by recent developments in route control technology, as well as a better understanding of the behavior of IP Anycast in operational settings, we revisit this decision and propose a load-aware IP Anycast CDN architecture that addresses these concerns while benefiting from inherent IP Anycast features. Our architecture makes use of route control mechanisms to take server and network load into account to realize load-aware Anycast. We show that the resulting redirection requirements can be formulated as a Generalized Assignment Problem and present practical algorithms that address these requirements while at the same time limiting session disruptions that plague regular IP Anycast. We evaluate our algorithms through trace based simulation using traces obtained from an operation CDN network.
Hussein A. Alzoubi, Seungjoon Lee, Michael Rabinovich, Oliver Spatscheck, Jacobus E. van der Merwe
WWW5
2007 VROOM: Virtual ROuters On the Move
Jacobus E. van der Merwe, Jennifer Rexford
HotNets2
2007 MIDAS: An Impact Scale for DDoS attacks
abstract
We usually have well-defined classification scales to estimate the intensity and impact of natural disasters. Prominent examples are the Richter and the Fujita scales for measuring earthquakes and tornadoes respectively. In this paper, we apply similar ideas to estimate the impact of distributed denial of service (DDoS) attacks from the perspective of network operators. Devising such a classification scale improves our understanding of DDoS attacks by assessing the actual damage incurred from an ISP's perspective, and allows comparison of various mitigation strategies. We have designed MIDAS, a DDoS impact scale, based on the economic impact of a DDoS attack, calculated using economic and network data. We then present an approximation of the MIDAS scale that relies only on network measurements for ease of computation. To demonstrate the usefulness of the scale, we perform sensitivity analysis to qualitatively validate the magnitude of the scale value for diverse attacks.
Rangarajan Vasudevan, Z. Morley Mao, Oliver Spatscheck, Jacobus E. van der Merwe
LANMAN4
2007 Measurement Informed Route Selection
Nick G. Duffield, Kartik Gopalan, Michael R. Hines, Aman Shaikh, Jacobus E. van der Merwe
PAM5
2007 Wresting Control from BGP: Scalable Fine-Grained Route Control
Patrick Verkaik, Dan Pei, Tom Scholl, Aman Shaikh, Alex C. Snoeren, Jacobus E. van der Merwe
USENIX ATC6
2006 BGP convergence in virtual private networks
abstract
Multi-protocol label switching (MPLS) virtual private networks (VPNs) have had significant and growing commercial deployments. In this paper we present the first systematic study of BGP convergence in MPLS VPNs using data collected from a large tier-1 ISP. We combine several data sources to produce a methodology to accurately estimate routing convergence delays. We discovered an iBGP version of BGP path exploration, and show that the route invisibility problem occurs frequently and is one of the most significant contributing factors to BGP convergence delay in the VPNs we studied. We therefore propose and evaluate several configuration changes that can be employed to greatly improve the routing convergence time and minimize the connectivity disruption in the face of network changes.
Dan Pei, Jacobus E. van der Merwe
Internet Measurement Conference2
2006 Enterprise Security: A Community of Interest Based Approach
Patrick D. McDaniel, Subhabrata Sen, Oliver Spatscheck, Jacobus E. van der Merwe, William Aiello, Charles R. Kalmanek
NDSS4
2006 LADS: Large-scale Automated DDoS Detection System
Vyas Sekar, Nick G. Duffield, Oliver Spatscheck, Jacobus E. van der Merwe, Hui Zhang 0001
USENIX ATC, General Track4
2006 Reval: A Tool for Real-time Evaluation of DDoS Mitigation Strategies
Rangarajan Vasudevan, Z. Morley Mao, Oliver Spatscheck, Jacobus E. van der Merwe
USENIX ATC, General Track4
2005 Design and Implementation of a Routing Control Platform
Matthew Caesar 0001, Donald F. Caldwell, Nick Feamster, Jennifer Rexford, Aman Shaikh, Jacobus E. van der Merwe
NSDI6
2003 Design and implementation of a distributed content management system
abstract
The convergence of advances in storage, encoding, and networking technologies has brought us to an environment where huge amounts of continuous media content is routinely stored and exchanged between network enabled devices. Keeping track of (or managing) such content remains challenging due to the sheer volume of data. Storing "live" continuous media (such as TV or radio content) adds to the complexity in that this content has no well defined start or end and is therefore cumbersome to deal with. Networked storage allows content that is logically viewed as part of the same collection to in fact be distributed across a network, making the task of content management all but impossible to deal with without a content management system. In this paper we present the design and implementation of the Spectrum content management system, which deals with rich media content effectively in this environment.Spectrum has a modular architecture that allows its application to both stand- alone and various networked scenarios. A unique aspect of Spectrum is that it requires one (or more) retention policies to apply to every piece of content that is stored in the system. This means that there are no eviction policies. Content that no longer has a retention policy applied to it is simply removed from the system. Different retention policies can easily be applied to the same content thus naturally facilitating sharing without duplication. This approach also allows Spectrum to easily apply time based policies which are basic building blocks required to deal with the storage of live continuous media, to content. We not only describe the details of the Spectrum architecture but also give typical use cases.
Chuck Cranor, R. Ethington, Amit Sehgal, David H. Shur, Cormac J. Sreenan, Jacobus E. van der Merwe
NOSSDAV6
2003 Efficient and robust streaming provisioning in VPNs
abstract
Today, most large companies maintain virtual private networks (VPNs) to connect their remote locations into a single secure network. VPNs can be quite large covering more than 1000 locations and in most cases use standard Internet protocols and services. Such VPNs are implemented using a diverse set of technologies such as Frame Relay, MPLS, or IPSEC to achieve the goal of privacy and performance isolation from the public Internet.Using VPNs to distribute live content has recently received tremendous interest. For example, a VPN could be used to broadcast a CEO-employee town hall meeting. To distribute this type of content economically without overloading the network, the deployment of streaming caches or splitters is most likely required.In this paper, we address the problem of optimally placing such streaming splitters or caches to broadcast to a given set of VPN endpoints under the constraints typically found within a VPN. In particular, we introduce an efficient algorithm with complexity O(V), V being the number of routers in the VPN. This guarantees the optimal cache placement if interception is used for redirection. We prove that the general problem is NP-hard and introduce multiple heuristics for efficient and robust cache placement suitable under different constraints. At the expense of increased implementation complexity, each heuristic solution provides additional saving in the number of caches required. We evaluate proposed solutions using extensive simulations. In particular, we show our flow-based solution is very close to the optimal.
Z. Morley Mao, David Johnson 0004, Oliver Spatscheck, Jacobus E. van der Merwe, Jia Wang 0001
WWW4
2002 Resource management with hoses: point-to-cloud services for virtual private networks
abstract
As IP technologies providing both tremendous capacity and the ability to establish dynamic security associations between endpoints emerge, virtual private networks (VPNs) are going through dramatic growth. The number of endpoints per VPN is growing and the communication pattern between endpoints is becoming increasingly hard to predict. Consequently, users are demanding dependable, dynamic connectivity between endpoints, with the network expected to accommodate any traffic matrix, as long as the traffic to the endpoints does not overwhelm the capacity of the respective ingress and egress links. We propose a new service interface, termed a hose, to provide the appropriate performance abstraction. A hose is characterized by the aggregate traffic to and from one endpoint in the VPN to a set of other endpoints in the VPN, and by an associated performance guarantee. Hoses provide important advantages to a VPN customer: (1) flexibility to send traffic to a set of endpoints without having to specify the detailed traffic matrix, and (2) reduction in the size of access links through multiplexing gains obtained from the natural aggregation of the flows between endpoints. As compared with the conventional point-to-point (or customer pipe) model for managing quality of service (QoS), hoses provide reduction in the state information a customer must maintain. On the other hand, hoses would appear to increase the complexity of the already difficult problem of resource management to support QoS. To manage network resources in the face of this increased uncertainty, we consider both conventional statistical multiplexing techniques, and a new resizing technique based on online measurements. To study these performance issues, we run trace-driven simulations, using traffic derived from AT&T's voice network and from a large corporate data network. From the customer's perspective, we find that aggregation of traffic at the hose level provides significant multiplexing gains. From the provider's perspective, we find that the statistical multiplexing and resizing techniques deal effectively with uncertainties about the traffic, providing significant gains over the conventional alternative of a mesh of statically sized customer pipes between endpoints.
Nick G. Duffield, Pawan Goyal 0001, Albert G. Greenberg, Partho Pratim Mishra, K. K. Ramakrishnan, Jacobus E. van der Merwe
IEEE/ACM Trans. Netw.6
1999 A Flexible Model for Resource Management in Virtual Private Networks
abstract
As IP technologies providing both tremendous capacity and the ability to establish dynamic secure associations between endpoints emerge, Virtual Private Networks (VPNs) are going through dramatic growth. The number of endpoints per VPN is growing and the communication pattern between endpoints is becoming increasingly hard to forecast. Consequently, users are demanding dependable, dynamic connectivity between endpoints, with the network expected to accommodate any traffic matrix, as long as the traffic to the endpoints does not overwhelm the rates of the respective ingress and egress links. We propose a new service interface, termed a hose, to provide the appropriate performance abstraction. A hose is characterized by the aggregate traffic to and from one endpoint in the VPN to the set of other endpoints in the VPN, and by an associated performance guarantee.Hoses provide important advantages to a VPN customer: (i) flexibility to send traffic to a set of endpoints without having to specify the detailed traffic matrix, and (ii) reduction in the size of access links through multiplexing gains obtained from the natural aggregation of the flows between endpoints. As compared with the conventional point to point (or customer-pipe) model for managing QoS, hoses provide reduction in the state information a customer must maintain. On the other hand, hoses would appear to increase the complexity of the already difficult problem of resource management to support QoS. To manage network resources in the face of this increased uncertainty, we consider both conventional statistical multiplexing techniques, and a new resizing technique based on online measurements.To study these performance issues, we run trace driven simulations, using traffic derived from AT&T's voice network, and from a large corporate data network. From the customer's perspective, we find that aggregation of traffic at the hose level provides significant multiplexing gains. From the provider's perspective, we find that the statistical multiplexing and resizing techniques deal effectively with uncertainties about the traffic, providing significant gains over the conventional alternative of a mesh of statically sized customer-pipes between endpoints.
Nick G. Duffield, Pawan Goyal 0001, Albert G. Greenberg, Partho Pratim Mishra, K. K. Ramakrishnan, Jacobus E. van der Merwe
SIGCOMM6
1998 Service-specific control architectures for ATM
abstract
The concept of a service-specific control architecture (SSCA) in an ATM environment is presented. Here, a control architecture denotes the out-of-band control and management mechanisms operational in a network or virtual network (or part thereof). An SSCA can use knowledge about the applications it serves to make better use of network resources, and thus provide a more efficient service. Such a control architecture can be designed to provide only the subset of control functions required by the applications it serves, thereby greatly reducing its complexity. The switchlet mechanism, which allows more than one control architecture to be operational simultaneously within the same network, enables the use of service-specific control architectures. Implementation work is presented to illustrate the use of switchlets and SSCAs. This includes both an environment which uses switchlets to dynamically create virtual networks, and an SSCA used to provide video- and audioconferencing facilities in an ATM environment.
Jacobus E. van der Merwe, Ian M. Leslie
IEEE J. Sel. Areas Commun.1
1997 Electronic commerce with secure intelligent trade agent
Jacobus E. van der Merwe, Sebastiaan H. von Solms
ICICS1
1997 Switchlets and Dynamic Virtual ATM Networks
Jacobus E. van der Merwe, Ian M. Leslie
Integrated Network Management1