EDBT 2026 Demo / reviewers in the wild / expert
Laurent Mathy
dblp:01/3642
· DBLP profile ↗
46ranked-venue papers
5as first author
5since 2021 · last 2025
0009-0006-4418-7227ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 34 · 5 first-author · 1 since 2021Systems, architecture and hardware · 8 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Efficient Versioning for UnikernelsabstractUnikernels are specialized, single-address-space op-erating systems (OSes) tailored to specific applications. They offer strong isolation, low memory/disk footprints, and fast startup times-making them well-suited for cloud and serverless computing. However, deploying many of them at scale in cloud environments introduces new challenges. In particular, managing library updates and versioning in statically linked unikernels is difficult due to their tightly coupled structure. Unlike dynamically linked binaries, statically linked unikernels lack built-in versioning mechanisms. Consequently, even minor library changes result in entirely new memory layouts, which can significantly increase memory consumption when multiple instances run concurrently. We present Spacer-A, a framework that improves memory sharing across statically linked unikernels with different library versions. Spacer uses differential analysis and library align-ment to enable page-level sharing via memory deduplication scanners or a custom loader backed by a shared library pool. Our evaluation with Unikraft shows that Spacer reduces memory consumption and boot overhead while maintaining compatibility across versions. The framework integrates into existing unikernel build pipelines with minimal changes and is released as open source. Gaulthier Gain, Benoit Knott, Laurent Mathy |
CLOUD | 3 |
| 2025 | Memory Matters: Load-Time Deduplication for UnikernelsabstractUnikernels offer strong isolation and performance benefits over traditional virtual machines, but their specialized, statically linked design complicates memory deduplication—particularly in multi-tenant environments. Traditional approaches like Kernel Samepage Merging (KSM) struggle with convergence delays, high CPU usage, and unpredictable memory savings. Dynamic linking improves memory reuse but compromises performance, simplicity, and security. We present Spacer-SLT, a novel load time deduplication mechanism that eliminates the need for memory scanners. Spacer-SLT extracts common libraries into a shared pool and uses a custom Firecracker-based loader to enable instant, deterministic memory deduplication at launch time. Unlike KSM, it introduces no runtime overhead and maintains the benefits of static linking, including performance and reduced attack surface. Gaulthier Gain, Benoit Knott, Cyril Soldani, Laurent Mathy |
SoCC | 4 |
| 2022 | Want more unikernels?: inflate them!abstractUnikernels are on the rise in the cloud. These lightweight virtual machines (VMs) specialized to a single application offer the same level of isolation as full-blown VMs, while providing performance superior to standard Linux-based VMs or even to containers. However, their inherent specialization renders memory deduplication ineffective, causing unikernels, in practice, to consume more memory than their small memory footprint would suggest. This makes them less advantageous when thousands of SaaS and/or FaaS unikernels instances have to run on the same server. Gaulthier Gain, Cyril Soldani, Felipe Huici, Laurent Mathy |
SoCC | 4 |
| 2021 | Unikraft: fast, specialized unikernels the easy wayabstractUnikernels are famous for providing excellent performance in terms of boot times, throughput and memory consumption, to name a few metrics. However, they are infamous for making it hard and extremely time consuming to extract such performance, and for needing significant engineering effort in order to port applications to them. We introduce Unikraft, a novel micro-library OS that (1) fully modularizes OS primitives so that it is easy to customize the unikernel and include only relevant components and (2) exposes a set of composable, performance-oriented APIs in order to make it easy for developers to obtain high performance. Simon Kuenzer, Vlad-Andrei Badoiu, Hugo Lefeuvre, Sharan Santhanam, Alexander Jung 0002, Gaulthier Gain, Cyril Soldani, Costin Lupu, Stefan Teodorescu, Costi Raducanu, Cristian Banu, Laurent Mathy, Razvan Deaconescu, Costin Raiciu, Felipe Huici |
EuroSys | 12 |
| 2021 | Combined Stateful Classification and Session Splicing for High-Speed NFV Service ChainingabstractNetwork functionssuch as firewalls, NAT, DPI, content-aware optimizers, and load-balancers are increasingly realized as software to reduce costs and enable outsourcing. To meet performance requirements thesevirtualnetwork functions (VNFs) often bypass the kernel and use their own user-space networking stack. A naïve realization of a chain of VNFs will exchange raw packets, leading to many redundant operations, wasting resources. In this work, we design a system to execute a pipeline of VNFs. We provide the user facilities to define (i) a traffic class of interest for the VNF, (ii) a session to group the packets (such as the TCP 4-tuple), and (iii) the amount of space per session. The system synthesizes a classifier and builds an efficient flow table that when possible will automatically be partially offloaded and accelerated by the network interface. We utilize an abstract view of flows to support seamless inspection and modification of the content of any flow (such as TCP or HTTP). By applying only surgical modifications to the protocol headers, we avoid the need for a complex, hard-to-maintain user-space TCP stack and can chain multiple VNFswithout re-constructing the stream multiple times, allowing up to 5x improvement over standard approaches. Tom Barbette, Cyril Soldani, Laurent Mathy |
IEEE/ACM Trans. Netw. | 3 |
| 2019 | Fast privacy-preserving network function outsourcingabstractIn this paper, we present the design and implementation of SplitBox, a system for privacy-preserving processing of network functions outsourced to cloud middleboxes—i.e., without revealing the policies governing these functions. SplitBox is built to provide privacy for a generic network function that abstracts the functionality of a variety of network functions and associated policies, including firewalls, virtual LANs, network address translators (NATs), deep packet inspection , and load balancers. We present a scalable design aiming to provide high throughput and low latency, by distributing functionalities to a few virtual machines (VMs), while providing provably secure guarantees. We implement SplitBox inside FastClick, an extension of the Click modular router, using Intel’s DPDK to handle packet I/O. We evaluate our prototype experimentally to find its bottlenecks and stress-test its different components, vis-à-vis two widely used network functions, i.e., firewall and VLAN tagging. Our evaluation shows that, on commodity hardware, SplitBox can process packets close to line rate (i.e., 8.9Gbps) with up to 50 traversed policies. Hassan Jameel Asghar, Emiliano De Cristofaro, Guillaume Jourjon, Mohamed Ali Kâafar, Laurent Mathy, Luca Melis, Craig Russell, Mang Yu |
Comput. Networks | 5 |
| 2018 | Building a chain of high-speed VNFs in no time: Invited PaperabstractTo cope with the growing performance needs of appliances in datacenters or the network edge, current middle-box functionalities such as firewalls, NAT, DPI, content-aware optimizers or load-balancers are often implemented on multiple (perhaps virtual) machines. In this work, we design a system able to run a pipeline of VNFs with a high level of parallelism to handle many flows. We provide the user facilities to define the traffic class of interest for the VNF, a definition of session to group the packets such as the TCP 4-tuples, and the amount of space per sessions. The system will then synthesize the classification and build a unique, efficient flow table. We build an abstract view of flows and use it to implement support for seamless inspection and modification of the content of any flow (such as TCP or HTTP), automatically reflecting a consistent view, across layers, of flows modified on-the-fly. Our prototype gives rise to a user-space software NFV data-plane enabling easy implementation of middlebox functionalities, as well as the deployment of complex scenarios. Our prototype implementation is able to handle our testbed limit of -34 Gbps of HTTP requests (for 8-KB files) through a service chain of multiples stateful VNFs, on a single Xeon core. Tom Barbette, Cyril Soldani, Romain Gaillard, Laurent Mathy |
HPSR | 4 |
| 2018 | Efficient Action Computation for Compositional SDN PoliciesabstractSoftware-defined networking envisions the support of multiple applications collaboratively operating on the same traffic. Policies of applications therefore require composition into a rule list that represents the union of application intents. In this context, ensuring the correctness and efficiency of composition for match fields as well as the associated actions is the fundamental requirement. Prior work however focuses only on the composition of match fields and assumes simple concatenation for action composition. We show in this paper that simple concatenation can result in incorrect behavior and inefficiency of packet processing. To address this issue, we formalize the action composition problem and propose two graph-based computation models to facilitate efficient composition of action lists. Our proposed approach has been integrated into the CoVisor code base and the evaluation results show its fitness for purpose. Zhenyu Li 0001, Gaogang Xie, Peng He 0003, Hongtao Guan, Laurent Mathy |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2018 | Constant IP Lookup With FIB Explosion
Tong Yang 0003, Gaogang Xie, Alex X. Liu, Qiaobin Fu, Yanbiao Li 0001, Xiaoming Li 0001, Laurent Mathy |
IEEE/ACM Trans. Netw. | 7 |
| 2017 | FlowConvertor: Enabling portability of SDN applicationsabstractSoftware-Defined Networking (SDN) provides network administrators opportunities to control network devices more simply and easily than in traditional networking. However, heterogeneity in switch hardware, especially in forwarding pipeline architecture, renders the task of network application developers and network administrators tedious, by hampering portability across switch models. In this paper, we propose FlowConvertor, an algorithm capable of converting rules from any forwarding pipeline to any other different forwarding pipeline, as long as both pipelines offer compatible operations. More precisely, FlowConvertor is an online algorithm that operates on flow updates issued to the origin pipeline and computes the corresponding updates for the target pipeline in real time. Performance evaluation shows that the latency introduced by FlowConvertor on the path between the SDN controller and the target switch is of the order of 1ms in most cases, and is thus acceptable for practical deployment. Gaogang Xie, Zhenyu Li 0001, Peng He 0003, Laurent Mathy |
INFOCOM | 5 |
| 2015 | Fast Userspace Packet ProcessingabstractIn recent years, we have witnessed the emergence of high speed packet I/O frameworks, bringing unprecedented network performance to userspace. Using the Click modular router, we rst review and quantitatively compare several such packet I/O frameworks, showing their superiority to kernel-based forwarding. We then reconsider the issue of software packet processing, in the context of modern commodity hardware with hardware multi-queues, multi-core processors and non-uniform memory access. Through a combination of existing techniques and improvements of our own, we derive modern general principles for the design of software packet processors. Our implementation of a fast packet processor framework, integrating a faster Click with both Netmap and DPDK, ex-hibits up-to about 2.3x speed-up compared to other software implementations, when used as an IP router. Tom Barbette, Cyril Soldani, Laurent Mathy |
ANCS | 3 |
| 2014 | Meta-algorithms for Software-Based Packet ClassificationabstractWe observe that a same rule set can induce very different memory requirement, as well as varying classification performance, when using various well known decision tree based packet classification algorithms. Worse, two similar rule sets, in terms of types and number of rules, can give rise to widely differing performance behaviour for a same classification algorithms. We identify the intrinsic characteristics of rule sets that yield such performance differences, allowing us to understand and predict the performance behaviour of a rule set for various modern packet classification algorithms. Indeed, from our observations, we are able to derive a memory consumption model and an offline algorithm capable of quickly identifying which packet classification is suited to a give rule set. By splitting a large rule set in several subsets and using different packet classification algorithms for different subsets, our Smart Split algorithm is shown to be capable of configuring a multi-component packet classification system that exhibits up to 11 times less memory consumption, as well as up to about 4× faster classification speed, than the state-of-art work [20] for large rule sets. Our Auto PC framework obtains further performance gain by avoiding splitting large rule sets if the memory size of the built decision tree is shown by the memory consumption model to be small. Peng He 0003, Gaogang Xie, Kavé Salamatian, Laurent Mathy |
ICNP | 4 |
| 2014 | Guarantee IP lookup performance with FIB explosionabstractThe Forwarding Information Base (FIB) of backbone routers has been rapidly growing in size. An ideal IP lookup algorithm should achieve constant, yet small, IP lookup time and on-chip memory usage. However, no prior IP lookup algorithm achieves both requirements at the same time. In this paper, we first propose SAIL, a Splitting Approach to IP Lookup. One splitting is along the dimension of the lookup process, namely finding the prefix length and finding the next hop, and another splitting is along the dimension of prefix length, namely IP lookup on prefixes of length less than or equal to 24 and IP lookup on prefixes of length longer than 24. Second, we propose a suite of algorithms for IP lookup based on our SAIL framework. Third, we implemented our algorithms on four platforms: CPU, FPGA, GPU, and many-core. We conducted extensive experiments to evaluate our algorithms using real FIBs and real traffic from a major ISP in China. Experimental results show that our SAIL algorithms are several times or even two orders of magnitude faster than well known IP lookup algorithms. Tong Yang 0003, Gaogang Xie, Yanbiao Li 0001, Qiaobin Fu, Alex X. Liu, Qi Li 0002, Laurent Mathy |
SIGCOMM | 7 |
| 2014 | A Hybrid Hardware Architecture for High-Speed IP Lookups and Fast Route UpdatesabstractAs network link rates are being pushed beyond 40 Gb/s, IP lookup in high-speed routers is moving to hardware. The ternary content addressable memory (TCAM)-based IP lookup engine and the static random access memory (SRAM)-based IP lookup pipeline are the two most common ways to achieve high throughput. However, route updates in both engines degrade lookup performance and may lead to packet drops. Moreover, there is a growing interest in virtual IP routers where more frequent updates happen. Finding solutions that achieve both fast lookup and low update overhead becomes critical. In this paper, we propose a hybrid IP lookup architecture to address this challenge. The architecture is based on an efficient trie partitioning scheme that divides the forwarding information base (FIB) into two prefix sets: a large disjoint leaf prefix set mapped into an external TCAM-based lookup engine and a small overlapping prefix set mapped into an on-chip SRAM-based lookup pipeline. Critical optimizations are developed on both IP lookup engines to reduce the update overhead. We show how to extend the proposed hybrid architecture to support virtual routers. Our implementation shows a throughput of 250 million lookups per second (equivalent to 128 Gb/s with 64-B packets). The update overhead is significantly lower than that of previous work, the memory consumption is reasonable, and the utilization ratio of most external TCAMs is up to 100%. Layong Luo, Gaogang Xie, Yingke Xie, Laurent Mathy, Kavé Salamatian |
IEEE/ACM Trans. Netw. | 4 |
| 2013 | Scalable high-performance parallel design for Network Intrusion Detection Systems on many-core processorsabstractNetwork Intrusion Detection Systems (NIDSes) face significant challenges coming from the relentless network link speed growth and increasing complexity of threats. Both hardware accelerated and parallel software-based NIDS solutions, based on commodity multi-core and GPU processors, have been proposed to overcome these challenges. This work explores new parallel opportunities afforded by many-core processors for high performance, scalable and inexpensive NIDS. We exploit the huge many-core computational power by adopting a hybrid parallel architecture combining data and pipeline parallelism. We also design a hybrid load balancing scheme, using both ruleset and flow space partitioning. Furthermore, the proposed design leverages particular features of the processor to break the bottlenecks. We have integrated the open source NIDS Suricata into our proposed design and evaluated its performance with synthetic traffic. The prototype exhibits almost linear speedup and can handle up to 7.2 Gbps traffic with 100-bytes packets. Haiyang Jiang 0001, Guangxing Zhang, Gaogang Xie, Kavé Salamatian, Laurent Mathy |
ANCS | 5 |
| 2013 | A trie merging approach with incremental updates for virtual routersabstractVirtual routers are increasingly being studied, as an important building block to enable network virtualization. In a virtual router platform, multiple virtual router instances coexist, each having its own FIB (Forwarding Information Base). In this context, memory scalability and route updates are two major challenges. Existing approaches addressed one of these challenges but not both. In this paper, we present a trie merging approach, which compactly represents multiple FIBs by a merged trie and a table of next-hop-pointer arrays to achieve good memory scalability, while supporting fast incremental updates by avoiding the use of leaf pushing during merging. Experimental results show that storing the merged trie requires limited memory space, e.g., we only need 10MB memory space to store the merged trie for 14 full FIBs from IPv4 core routers, achieving a memory reduction by 87% when compared to the total size of the individual tries. We implement our approach in an SRAM (Static Random Access Memory)-based lookup pipeline. Using our approach, an on-chip SRAM-based lookup pipeline with 5 external stages is sufficient to store the 14 full IPv4 FIBs. Furthermore, our approach can guarantee a minimum update overhead of one write bubble per update, as well as a high lookup throughput of one lookup per clock cycle, which corresponds to a throughput of 251 million lookups per second in the implementation. Layong Luo, Gaogang Xie, Kavé Salamatian, Steve Uhlig, Laurent Mathy, Yingke Xie |
INFOCOM | 5 |
| 2013 | Toward predictable performance in decision tree based packet classification algorithmsabstractPacket classification has been studied extensively in the past decade. While many efficient algorithms have been proposed, the lack of deterministic performance has hindered the adoption and deployment of these algorithms: the expensive and power-hungry TCAM is still the de facto standard solution for packet classification. In this work, in contrast to proposing yet another new packet classification algorithm, we present the first steps to understand this unpredictability in performance for the existing algorithms. We focus on decision-tree based algorithms in this paper. In order to achieve the predictability, we firstly revisit the classical and many state-of-art packet classification algorithms. Through a detailed analysis, we conclude that two features of ruleset usually dominate the performance results: 1) the uniformity of the range distribution in different dimensions of the rules; 2) the existence and the number of “orthogonal structure” and wildcard rules in the ruleset. We conduct experiments to show the correctness of these observations, and discribe some potential applications for those results. Our work provides some insight to make the packet classification algorithms a credible alternative to the TCAM-only solutions. Peng He 0003, Hongtao Guan, Laurent Mathy, Kavé Salamatian, Gaogang Xie |
LANMAN | 3 |
| 2013 | Improved parallelism and scheduling in multi-core software routers
Norbert Egi, Gianluca Iannaccone, Maziar Manesh, Laurent Mathy, Sylvia Ratnasamy |
J. Supercomput. | 4 |
| 2012 | FlowOS: a pure flow-based vision of network trafficabstractThe original Internet architecture lacked the concept of a flow, and considered each traffic as a set of packets. In this short paper, we rethink this concept inside middlebox-based platform and handle each traffic as a whole block instead of packets. We design a whole system where each input packet matching some criteria is placed in a specific structure which is shared between all processing modules that interact in a parallel manner with this flow. Thus, this new design improves flexibility of traffic and also increases the flow processing performances. Abdul Alim, Mehdi Bezahaf, Laurent Mathy |
ANCS | 3 |
| 2012 | Towards TCAM-based scalable virtual routersabstractAs the key building block for enabling network virtualization, virtual routers have attracted much attention recently. In a virtual router platform, multiple virtual router instances coexist, each with its own FIB (Forwarding Information Base). The small amount of high-speed memory in a physical router platform severely limits the number of FIBs supported, which leads to a scalability challenge. In this paper, we present a method towards TCAM (Ternary Content Addressable Memory) based scalable virtual routers, through a merged data structure that enables the sharing of prefixes from several FIBs in TCAMs. Based on this data structure, we propose two approaches to merge multiple FIBs in TCAMs, paving the way for scalable virtual routers. Experimental results show that, by using the two approaches for storing 14 full IPv4 FIBs, the TCAM memory requirement can be reduced by about 92% and 82% respectively, compared with the conventional approach of treating FIBs as independent entities. Layong Luo, Gaogang Xie, Steve Uhlig, Laurent Mathy, Kavé Salamatian, Yingke Xie |
CoNEXT | 4 |
| 2012 | A hybrid IP lookup architecture with fast updatesabstractAs network link rates are being pushed beyond 40 Gbps, IP lookup in high-speed routers is moving to hardware. The TCAM (Ternary Content Addressable Memory)-based IP lookup engine and the SRAM (Static Random Access Memory)-based IP lookup pipeline are the two most common ways to achieve high throughput. However, route updates in both engines degrade lookup performance and may lead to packet drops. Moreover, there is a growing interest in virtual IP routers where more frequent updates happen. Finding solutions that achieve both fast lookup and low update overhead becomes critical. In this paper, we propose a hybrid IP lookup architecture to address this challenge. The architecture is based on an efficient trie partitioning scheme that divides the Forwarding Information Base (FIB) into two prefix sets: a large disjoint leaf prefix set mapped into an external TCAM-based lookup engine and a small overlapping prefix set mapped into an on-chip SRAM-based lookup pipeline. Critical optimizations are developed on both IP lookup engines to reduce the update overhead. We show how to extend the proposed hybrid architecture to support virtual routers. Our implementation shows a throughput of 250 million lookups per second (MLPS). The update overhead is significantly lower than that of previous work and the utilization ratio of most external TCAMs is up to 100%. Layong Luo, Gaogang Xie, Yingke Xie, Laurent Mathy, Kavé Salamatian |
INFOCOM | 4 |
| 2012 | Editorial for Computer Networks special issue on "Measurement-based optimization of P2P networking and applications"
Xiaoming Fu 0001, Yang Chen 0001, Guy Leduc, Laurent Mathy |
Comput. Networks | 4 |
| 2011 | Building virtual networks across multiple domainsabstractThis paper presents a platform for virtual network (VN) provisioning across multiple domains. The platform decomposes VN provisioning into multiple steps to address the implications of limited information disclosure on resource discovery and allocation. A new VN embedding algorithm with simultaneous node and link mapping allows to assign resources within each domain. For inter-domain virtual link setup, we design and realize a signaling protocol that also integrates resource reservations for providing virtual links with Quality-of-Service guarantees. Experimental results show that small VNs can be provisioned within a few seconds. Christoph Werle, Panagiotis Papadimitriou 0001, Ines Houidi, Wajdi Louati, Djamal Zeghlache, Roland Bless, Laurent Mathy |
SIGCOMM | 7 |
| 2009 | Certified Internet CoordinatesabstractWe address the issue of asserting the accuracy of coordinates advertised by nodes of Internet coordinate systems during distance estimations. Indeed, some nodes may lie deliberately about their coordinates to mount various attacks against applications and overlays. Our proposed method consists in two steps: 1) establish the correctness of a node's claimed coordinate (which leverages our previous work on securing the coordinates embedding phase using a Surveyor infrastructure); and 2) issue a time limited validity certificate for each verified coordinate. Validity periods are computed based on an analysis of coordinate inter-shift times observed on PlanetLab, and shown to follow a long-tail distribution (lognormal distribution in most cases, or Weibull distribution otherwise). The effectiveness of the coordinate certification method is validated by measuring the impact of a variety of attacks on distance estimates. Mohamed Ali Kâafar, Laurent Mathy, Chadi Barakat, Kavé Salamatian, Thierry Turletti, Walid Dabbous |
ICCCN | 2 |
| 2009 | Improved Forwarding Architecture and Resource Management for Multi-Core Software RoutersabstractRecent technological advances in commodity server architectures, with multiple multi-core CPUs, integrated memory controllers, high-speed interconnects and enhanced network interface cards, provide substantial computational capacity and thus an attractive platform for packet forwarding. However, to exploit this available capacity, we need a suitable software platform that allows effective parallel packet processing and resource management. In this paper, we at first introduce an improved forwarding architecture for software routers that enhances parallelism by exploiting hardware classification and multi-queue support, already available in recent commodity network interface cards. After evaluating the original scheduling algorithm of the widely-used Click modular router, we propose solutions for extending this scheduler for improved fairness, throughput and more precise resource management. To illustrate the potential benefits of our proposal, we implement and evaluate a few key elements of our overall design. Norbert Egi, Adam Greenhalgh, Mark Handley, Gianluca Iannaccone, Maziar Manesh, Laurent Mathy, Sylvia Ratnasamy |
NPC | 6 |
| 2009 | Characterising and exploiting workloads of highly interactive video-on-demand
Andrew Brampton, Andrew MacQuire, Michael Fry 0001, Idris A. Rai, Nicholas J. P. Race, Laurent Mathy |
Multim. Syst. | 6 |
| 2008 | Towards high performance virtual routers on commodity hardwareabstractModern commodity hardware architectures, with their multiple multi-core CPUs and high-speed system interconnects, exhibit tremendous power. In this paper, we study performance limitations when building both software routers and software virtual routers on such systems. We show that the fundamental performance bottleneck is currently the memory system, and that through careful mapping of tasks to CPU cores, we can achieve forwarding rates of 7 million minimum-sized packets per second on mid-range server-class systems, thus demonstrating the viability of software routers. We also find that current virtualisation systems, when used to provide forwarding engine virtualisation, yield aggregate performance equivalent to that of a single software router, a tenfold improvement on current virtual router platform performance. Finally, we identify principles for the construction of high-performance software router systems on commodity hardware, including full router virtualisation support. Norbert Egi, Adam Greenhalgh, Mark Handley, Mickaël Hoerdt, Felipe Huici, Laurent Mathy |
CoNEXT | 6 |
| 2008 | LISP-DHT: towards a DHT to map identifiers onto locatorsabstractRecent activities in the IRTF (Internet Research Task Force), and in particular in the Routing Research Group (RRG), focus on defining a new Internet architecture, in order to solve scalability issues related to interdomain routing. The research community has agreed that the separation of the end-systems' addressing space (the identifiers) and the routing locators' space will alleviate the routing burden of the Default Free Zone. Nevertheless, such approach, adding a new level of indirection, implies the need of storing and distributing mappings between identifiers and routing locators. In this paper we present LISP-DHT, a mapping distribution system based on Distributed Hash Tables (DHTs). LISP-DHT is designed to take full advantage of the DHT architecture in order to build an efficient and secured mapping lookup system while preserving the locality of the mapping. The paper describes the overall architecture of LISP-DHT, explaining its main points and how it works. Laurent Mathy, Luigi Iannone |
CoNEXT | 1 |
| 2008 | Towards a Two-Tier Internet Coordinate System to Mitigate the Impact of Triangle Inequality Violations
Mohamed Ali Kâafar, Bamba Gueye, François Cantin, Guy Leduc, Laurent Mathy |
Networking | 5 |
| 2008 | Authentication in stealth distributed hash tables
Andrew MacQuire, Andrew Brampton, Idris A. Rai, Nicholas J. P. Race, Laurent Mathy |
J. Syst. Archit. | 5 |
| 2007 | Evaluating Xen for Router VirtualizationabstractIn this paper, we evaluate the performance of a software IP router forwarding plane inside the Xen virtual machine monitor environment with a view to identifying (some) design issues in Virtual Routers. To this end, we evaluate and compare the forwarding performance of two identical Linux software router configurations, run either above the Xen hypervisor or within vanilla Linux. Even with minimal sized packets, we show that the Xen DomO privileged domain offers near native forwarding performance at the condition that the sollicitation to unpriviledged domains stay minimal, whereas Xen unprivileged domains offer very poor performance in every cases. This shows that an important design principle for virtual router platforms must be to handle all forwarding, for all virtual routers, onto the same forwarding engine, in order to avoid much detrimental per-packet context switching. Norbert Egi, Adam Greenhalgh, Mark Handley, Mickaël Hoerdt, Laurent Mathy, Tim Schooley |
ICCCN | 5 |
| 2007 | Performance Modelling of Peer-to-Peer RoutingabstractWe propose several models based on discrete-time Markov chains for the analysis of distributed hash tables (DHTs). Specifically, we examine the Pastry routing protocol, as well as a Stealth DHT adaptation of Pastry to compute their exact expressions for average number of lookup hops. We show that our analytical models match with the protocols' simulation results almost perfectly, making them ideal for rapid evaluation. Idris A. Rai, Andrew Brampton, Andrew MacQuire, Laurent Mathy |
IPDPS | 4 |
| 2007 | Securing internet coordinate embedding systemsabstractThis paper addresses the issue of the security of Internet Coordinate Systems,by proposing a general method for malicious behavior detection during coordinate computations. We first show that the dynamics of a node, in a coordinate system without abnormal or malicious behavior, can be modeled by a Linear State Space model and tracked by a Kalman filter. Then we show, that the obtained model can be generalized in the sense that the parameters of a filtercalibrated at a node can be used effectively to model and predict the dynamic behavior at another node, as long as the two nodes are not too far apart in the network. This leads to the proposal of a Surveyor infrastructure: Surveyor nodes are trusted, honest nodes that use each other exclusively to position themselves in the coordinate space, and are therefore immune to malicious behavior in the system.During their own coordinate embedding, other nodes can thenuse the filter parameters of a nearby Surveyor as a representation of normal, clean system behavior to detect and filter out abnormal or malicious activity. A combination of simulations and PlanetLab experiments are used to demonstrate the validity, generality, and effectiveness of the proposed approach for two representative coordinate embedding systems, namely Vivaldi and NPS. Mohamed Ali Kâafar, Laurent Mathy, Chadi Barakat, Kavé Salamatian, Thierry Turletti, Walid Dabbous |
SIGCOMM | 2 |
| 2006 | Stealth distributed hash table: a robust and flexible super-peered DHTabstractMost Distributed Hash Tables (DHTs) simply consider interconnecting homogeneous nodes on the same overlay. However, realistically nodes on a network are heterogeneous in terms of their capabilities. Because of this, traditional DHTs have been shown to exhibit poor performance in a real-world environment. Additionally, we believe that it is this approach that contributes to a limited exploitation of peer-to-peer technologies. Previous work on super-peers in DHTs was proposed to address these performance issues, however the strategy used is often based on locally clustering peers around individual super-peers. This method of super-peering, however, compromises fundamental features such as load-balancing, resilience and routing efficiency, which traditional DHTs originally promised to offer. Andrew Brampton, Andrew MacQuire, Idris A. Rai, Nicholas J. P. Race, Laurent Mathy |
CoNEXT | 5 |
| 2006 | Virtual networks under attack: disrupting internet coordinate systemsabstractInternet coordinate-based systems are poised to become an important service to support overlay construction and topology-aware applications. Indeed, through network distance embedding into an appropriate geometric space, such systems allow for accurate network distance estimations with low overhead. However, coordinate systems often rely on good cooperation between nodes for correct coordination and assume that information reported by probed nodes is correct. In this paper, we identify various attacks against coordinate embedding systems and show their effectiveness on two representative positioning systems, namely Vivaldi and NPS. Our study demonstrates that these attacks can seriously disrupt the operations of these systems and therefore the virtual networks and applications relying on them for distance measurements. Through simulations of different potential scenarios where malicious nodes provide biased coordinate information and delay measurement probes, we quantify the effects of attack strategies that aim to (i) introduce disorder in the system, (ii) fool honest nodes to move far away from their correct positions and (iii) isolate particular target nodes in the system through collusion. Our findings confirm the susceptibility of the coordinate systems to such attacks. Mohamed Ali Kâafar, Laurent Mathy, Thierry Turletti, Walid Dabbous |
CoNEXT | 2 |
| 2006 | Voice over application-level multicastabstractIn this paper, we present a thorough and realistic analysis of voice (i.e. audio conferencing) over application-level multicast (ALM). Through flexibility and ease-of-deployment, ALM is a compelling alternative group-communication technique to IP multicast-which has yet to see wide-scale deployment in the Internet. However, proposed ALM techniques suffer from inherent latency inefficiencies, which we show, through realistic simulation and exploration of perceived quality in multi-party conversation, to be greatly problematic for the realisation of truly-scalable audio-conferencing systems over ALM. By incorporating talkspurt data from a large and detailed corpus of multi-party conversation, and through using network-simulation techniques based on actual Internet latency measurements, we develop our previous work on the application-level network audio-conferencing (ALNAC) routing protocol into a thorough analysis of the problem, leading to a novel model for assessing the perceptual quality of multi-party conversation and to novel techniques for speaker prediction. We show that through adaptation to conversational patterns, the ALNAC protocol can achieve perceptual quality for large-scale audio conferencing that, with little cost to each end-system node, is comparable to IP multicast. Nick Blundell, Norbert Egi, Laurent Mathy |
IPCCC | 3 |
| 2006 | Efficient Overlay Audio Conferencing
Norbert Egi, Nick Blundell, Laurent Mathy |
Networking | 3 |
| 2006 | Overlay distribution structures and their applications
Laurent Mathy, David Hutchison 0001, Thomas Plagemann, Peter Steenkiste |
Comput. Networks | 1 |
| 2006 | From content distribution networks to content networks - issues and challenges
Thomas Plagemann, Vera Goebel, Andreas Mauthe, Laurent Mathy, Thierry Turletti, Guillaume Urvoy-Keller |
Comput. Commun. | 4 |
| 2006 | A component-based middleware framework for configurable and reconfigurable Grid computingabstractAbstract Significant progress has been made in the design and development of Grid middleware which, in its present form, is founded on Web services technologies. However, we argue that present‐day Grid middleware is severely limited in supporting projected next‐generation applications which will involve pervasive and heterogeneous networked infrastructures, and advanced services such as collaborative distributed visualization. In this paper we discuss a new Grid middleware framework that features (i) support for advanced network services based on the novel concept of pluggable overlay networks, (ii) an architectural framework for constructing bespoke Grid middleware platforms in terms of ‘middleware domains’ such as extensible interaction types and resource discovery. We believe that such features will become increasingly essential with the emergence of next‐generation e‐Science applications. Copyright © 2005 John Wiley & Sons, Ltd. Geoff Coulson, Paul Grace, Gordon S. Blair, Wei Cai 0001, Christopher S. Cooper, David A. Duce, Laurent Mathy, Wai Kit Yeung, Barry Porter, Musbah Shahop Sagar |
Concurr. Comput. Pract. Exp. | 7 |
| 2005 | Controlling the effects of anomalous ARP behaviour on ethernet networksabstractThere are a large number of large-scale Ethernet-based local and metropolitan area networks in use. A significant reason for this prolific deployment is the relatively simple manner in which they can be configured and deployed. A critical service on these networks, that epitomises the simple nature of Ethernet, is the Address Resolution Protocol (ARP). This protocol is used to determine the link-layer address of a host given its network-layer identifier, and uses the intrinsic broadcast capability of Ethernet to determine these mappings. In this paper, we present an analysis of ARP behaviour on three sizable local area networks and show that due to poorly configured or malicious software (e.g. viruses) on hosts, performance issues could arise because of ARP. We also propose a scheme that can be used to manage the effect of the problems identified in our analysis. Dadi Ármannsson, Gísli Hjálmtýsson, Paul D. Smith, Laurent Mathy |
CoNEXT | 4 |
| 2005 | Stealth distributed hash table: unleashing the real potential of peer-to-peerabstractpeer reviewed Andrew Brampton, Andrew MacQuire, Idris A. Rai, Nicholas J. P. Race, Laurent Mathy |
CoNEXT | 5 |
| 2004 | Impact of Simple Cheating in Application-Level MulticastabstractWe study the impact of cheating nodes in application-level multicast overlay trees. We focus on selfish nodes acting independently, cheating about their distance measurements during the control phase building or maintaining the tree. More precisely, we study, through simulations, the impact of simple cheating strategies in four protocols, representatives of different application-level multicast protocol "families": HBM (a protocol based on a centralized approach), TBCP (a distributed, tree first protocol), NICE (a distributed, tree first protocol based on clustering) and NARADA (a mesh first protocol). We evaluate the impact of cheats on the performance of the overlay trees as perceived by their nodes and the underlying network. Laurent Mathy, Nick Blundell, Vincent Roca, Ayman El-Sayed |
INFOCOM | 1 |
| 2004 | Network support for Grid computing
David Hutchison 0001, Laurent Mathy, Olivier Bonaventure |
Comput. Commun. | 2 |
| 2002 | Scalable Adaptive Hierarchical Clustering
Laurent Mathy, Roberto Canonico, Steven Simpson, David Hutchison 0001 |
NETWORKING | 1 |
| 2002 | A performance study of RSVP with proposed extensions
Laurent Mathy, David Hutchison 0001, Stefan Schmid 0002, Steven Simpson |
Comput. Commun. | 1 |