EDBT 2026 Demo / reviewers in the wild / expert
Lukas Kencl
dblp:14/177
· DBLP profile ↗
24ranked-venue papers
3as first author
0since 2021 · last 2018
0000-0002-3339-7118ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 3 first-authorSecurity and privacy · 2Applied, interdisciplinary, general and emerging computing · 2Graphics, computer vision, multimedia, augmented reality and games · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Cryptographic primitives and cryptanalysis · 74% Privacy and data protection · 19% Network security · 6% | |
| Computer networks
5 papers |
Cellular and mobile networks · 71% Routing and switching · 14% Internet architecture and protocols · 9% | |
| Computer architecture, parallel and distributed computing, and storage systems
2 papers |
Cloud and datacenter computing · 46% Storage systems · 46% Electronic design automation · 4% | |
| Databases, data mining, and information retrieval
1 paper |
Data mining · 100% |
Topics — the 22 heaviest of 23, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cryptographic primitives and cryptanalysis › encryption
convergent encryption |
0.3 | 1 | 2018 | Enhanced Secure Thresholded Data Deduplication Scheme for Cloud Storage · IEEE Trans. Dependable Secur. Comput. 2018 |
Cryptographic primitives and cryptanalysis
encryption |
0.3 | 1 | 2018 | Enhanced Secure Thresholded Data Deduplication Scheme for Cloud Storage · IEEE Trans. Dependable Secur. Comput. 2018 |
Cloud and datacenter computing
cloud storage |
0.3 | 1 | 2018 | Enhanced Secure Thresholded Data Deduplication Scheme for Cloud Storage · IEEE Trans. Dependable Secur. Comput. 2018 |
Storage systems › data reduction
data deduplication |
0.3 | 1 | 2018 | Enhanced Secure Thresholded Data Deduplication Scheme for Cloud Storage · IEEE Trans. Dependable Secur. Comput. 2018 |
Cellular and mobile networks
mobility management |
0.3 | 2 | 2012 | Inter-Call Mobility model: A spatio-temporal refinement of Call Data Records using a Gaussian mixture model · INFOCOM 2012 Performance study of active tracking in a cellular network using a modular signaling platform · MobiSys 2010 |
Data mining › clustering › mixture modeling
gaussian mixture model |
0.1 | 1 | 2012 | Inter-Call Mobility model: A spatio-temporal refinement of Call Data Records using a Gaussian mixture model · INFOCOM 2012 |
Data mining › spatiotemporal data mining › trajectory data mining
mobility pattern mining |
0.1 | 1 | 2012 | Inter-Call Mobility model: A spatio-temporal refinement of Call Data Records using a Gaussian mixture model · INFOCOM 2012 |
Data mining
spatiotemporal data mining |
0.1 | 1 | 2012 | Inter-Call Mobility model: A spatio-temporal refinement of Call Data Records using a Gaussian mixture model · INFOCOM 2012 |
Cellular and mobile networks
call data records |
0.1 | 1 | 2012 | Inter-Call Mobility model: A spatio-temporal refinement of Call Data Records using a Gaussian mixture model · INFOCOM 2012 |
Cellular and mobile networks › mobility management › user mobility
human mobility modeling |
0.1 | 1 | 2012 | Inter-Call Mobility model: A spatio-temporal refinement of Call Data Records using a Gaussian mixture model · INFOCOM 2012 |
Cellular and mobile networks › mobility management › location management
location tracking |
0.1 | 1 | 2010 | Performance study of active tracking in a cellular network using a modular signaling platform · MobiSys 2010 |
Privacy and data protection
encrypted data |
0.1 | 1 | 2018 | Enhanced Secure Thresholded Data Deduplication Scheme for Cloud Storage · IEEE Trans. Dependable Secur. Comput. 2018 |
Privacy and data protection
secure deduplication |
0.1 | 1 | 2018 | Enhanced Secure Thresholded Data Deduplication Scheme for Cloud Storage · IEEE Trans. Dependable Secur. Comput. 2018 |
Cryptographic primitives and cryptanalysis › public-key cryptography › public-key encryption
threshold encryption |
0.1 | 1 | 2018 | Enhanced Secure Thresholded Data Deduplication Scheme for Cloud Storage · IEEE Trans. Dependable Secur. Comput. 2018 |
Routing and switching
load sharing |
0.1 | 1 | 2008 | Adaptive load sharing for network processors · IEEE/ACM Trans. Netw. 2008 |
Internet architecture and protocols › packet processing
network processor |
0.1 | 1 | 2008 | Adaptive load sharing for network processors · IEEE/ACM Trans. Netw. 2008 |
Network security › intrusion detection and prevention
intrusion detection |
0.1 | 1 | 2006 | Approximate fingerprinting to accelerate pattern matching · Internet Measurement Conference 2006 |
Routing and switching › load sharing
dynamic load balancing |
0.0 | 1 | 2002 | Adaptive Load Sharing for Network Processors · INFOCOM 2002 |
Network measurement and analytics › mobile network measurement
cellular network measurement |
0.0 | 1 | 2010 | Performance study of active tracking in a cellular network using a modular signaling platform · MobiSys 2010 |
Distributed systems › distributed scheduling › load sharing
adaptive load sharing |
0.0 | 1 | 2008 | Adaptive load sharing for network processors · IEEE/ACM Trans. Netw. 2008 |
Electronic design automation › high-level synthesis
scheduling |
0.0 | 1 | 2008 | Adaptive load sharing for network processors · IEEE/ACM Trans. Netw. 2008 |
Routing and switching
router architecture |
0.0 | 1 | 2002 | Adaptive Load Sharing for Network Processors · INFOCOM 2002 |
Methods — techniques the papers use, named apart from their topics
symmetric external diffie-hellman assumption · 0.7security proof · 0.7random oracle model · 0.7probabilistic modeling · 0.3gaussian mixture model · 0.3simulation · 0.3bloom filter · 0.1approximate fingerprinting · 0.1SS7 signaling · 0.1robust hash routing · 0.0highest random weight · 0.0feedback control · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2018 | Optimization of Cloud Connectivity Using a Smart-Home Gateway
Ondrej Tomanek, Lukas Kencl |
ICC | 2 |
| 2018 | Enhanced Secure Thresholded Data Deduplication Scheme for Cloud StorageabstractAs more corporate and private users outsource their data to cloud storage, recent data breach incidents make end-to-end encryption increasingly desirable. Unfortunately, semantically secure encryption renders various cost-effective storage optimization techniques, such as data deduplication, ineffective. On this ground Stanek et al. [1] introduced the concept of “data popularity” arguing that data known/owned by many users do not require as strong protection as unpopular data; based on this, Stanek et al. presented an encryption scheme, where the initially semantically secure ciphertext of a file is transparently downgraded to a convergent ciphertext that allows for deduplication as soon as the file becomes popular. In this paper we propose an enhanced version of the original scheme. Focusing on practicality, we modify the original scheme to improve its efficiency and emphasize clear functionality. We analyze the efficiency based on popularity properties of real datasets and provide a detailed performance evaluation, including comparison to alternative schemes in real-like settings. Importantly, the new scheme moves the handling of sensitive decryption shares and popularity state information out of the cloud storage, allowing for improved security notion, simpler security proofs and easier adoption. We show that the new scheme is secure under the Symmetric External Diffie-Hellman assumption in the random oracle model. Jan Stanek, Lukas Kencl |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2016 | Multidimensional cloud latency monitoring and evaluation
Ondrej Tomanek, Pavol Mulinka, Lukas Kencl |
Comput. Networks | 3 |
| 2014 | Analyzing anomalies in anonymized SIP trafficabstractThe Session Initiation Protocol (SIP) is a signaling protocol widely used nowadays for controlling multimedia communication sessions. Thus, understanding and troubleshooting SIP behavior is of utmost importance to network designers and operators. However, SIP traffic traces are hard to come by due to privacy and confidentiality issues. SIP contains a lot of personal information spread within the various SIP messages — IP addresses, names, usernames and domains, e-mail addresses etc. The known IP-address anonymization methods are thus insufficient. We present SiAnTo, an extended anonymization technique that substitutes session-participant information with matching, but nondescript, labels. This allows for SIP traces to be publicly shared, while keeping interesting traffic-session properties intact. We further demonstrate its usefulness by studying the problem of SIP NAT traversal as recorded in the anonymized traces. We analyze properties of the so-called “registration storm” incident and measure the influence of the active NAT traversal techniques on SIP traffic pattern, both only possible thanks to the preservation of session relationships inside the anonymized traces. As further benefit to the research community, we set up a public data-store with both the anonymization module and the anonymized traces available and invite other parties to share further SIP data using these open tools. Jan Stanek, Lukas Kencl, Jiri Kuthan |
Networking | 2 |
| 2014 | Stateless generation of distributed virtual worlds
Jirí Danihelka, Lukas Kencl, Jirí Zára |
Comput. Graph. | 2 |
| 2013 | Mobility data anonymization by obfuscating the cellular network topology graphabstractStudies of cellular-network data, comprising analyses of user movements across the network, are becoming increasingly popular with the rise of new services based on user behavior and geographic location. Such data might contain, for example, timestamped lists of IDs of cells a user was registered to. If coupled with the cell locations, confidential to the operator, this would enable reconstruction of user trajectories across the regions covered. It is vital to preserve privacy of this data for all parts involved (users, operators) while enabling open sharing of the data to foster research and development of new findings, services and technologies based on mining of this data. Thus, we pose the problem of obfuscating entire cellular-network topologies while retaining some of the analytical value of the user data. To this end, we adopt multiple obfuscation methods based on different topology-graph distortions, and analyze their performance using simulated scenarios. Eduardo Baena Martinez, Michal Ficek, Lukas Kencl |
ICC | 3 |
| 2013 | Characteristics of Real Open SIP-Server Traffic
Jan Stanek, Lukas Kencl, Jiri Kuthan |
PAM | 2 |
| 2013 | Active tracking in mobile networks: An in-depth view
Michal Ficek, Tomás Pop, Lukas Kencl |
Comput. Networks | 3 |
| 2012 | Improving QoE of SIP-based automated voice interaction in mobile networks
Jakub Dolezal, Lukas Kencl |
CNSM | 2 |
| 2012 | SIP Protector: Defense architecture mitigating DDoS flood attacks against SIP serversabstractAs Voice-over-IP becomes a commonly used technology, the need to keep it secure and reliable has grown. Session Initiation Protocol (SIP) is most often used to deploy VoIP and therefore SIP servers, the base components of SIP, are the most obvious targets of potential attacks. It has been demonstrated, that SIP servers are highly prone to DDoS flood attacks, yet no generally accepted defense solution mitigating these attacks is available. We propose a novel defense architecture against SIP DDoS floods, based upon a redirection mechanism and a combination of source and destination traffic filtering, exploiting the combined advantage of all the three techniques. We show that the proposed solution effectively mitigates various types of SIP DDoS flood attacks, discuss its strengths and weaknesses and propose its potential usability for other protocols. We also provide results of performance evaluation of the defense solution deployed in a SIP testbed. Jan Stanek, Lukas Kencl |
ICC | 2 |
| 2012 | Cloud-Based Assistive Speech-Transcription Services
Zdenek Bumbalek, Jan Zelenka, Lukas Kencl |
ICCHP (2) | 3 |
| 2012 | Inter-Call Mobility model: A spatio-temporal refinement of Call Data Records using a Gaussian mixture modelabstractWith global mobile phone penetration nearing 100%, cellular Call Data Records (CDRs) provide a large-scale and ubiquitous, but also sparse and skewed snapshot of human mobility. It may be difficult or inappropriate to reach strong conclusions about user movement based on such data without proper understanding of user movement between call records. Based on an analysis of a real-world trace, we propose a novel, probabilistic Inter-Call Mobility (ICM) model of users' position in between calls. The ICM model combines Gaussian mixtures to build a general, comprehensive spatio-temporal refinement of CDRs.We demonstrate that ICM model's application yields strikingly different conclusions to the existing models when applied to basic CDR analyses, such as user proximity probability. Michal Ficek, Lukas Kencl |
INFOCOM | 2 |
| 2011 | A unifying architecture for easy development, deployment and management of voice-driven mobile applications
Jakub Dolezal, Lukas Kencl |
CNSM | 2 |
| 2011 | SIPp-DD: SIP DDoS Flood-Attack Simulation ToolabstractWith the growing popularity of Voice-over-IP communication and of the SIP protocol, mobile networks including, denial-of-service attacks against the signaling are an increasingly menacing threat. We present SIPp-DD, a tool for generating real-like SIP DDoS flood attacks. SIPp-DD modifies the popular SIPp call generator and offers the option to spoof source IP addresses and ports of the generated messages. For flexibility, any set of source IP addresses and ports can be input, using a text file. To create real-like attacks, we analyze some of the publicly available DDoS flood attacks, derive typical distributions of address and packet populations and employ those in attack generation. We compare the generator outputs with the real analyzed DDoS floods and demonstrate the tool applicability by performing a DDoS attack within a real SIP-server testbed. Jan Stanek, Lukas Kencl |
ICCCN | 2 |
| 2010 | E-Scribe: Ubiquitous Real-Time Speech Transcription for the Hearing-Impaired
Zdenek Bumbalek, Jan Zelenka, Lukas Kencl |
ICCHP (2) | 3 |
| 2010 | Spatial extension of the Reality Mining DatasetabstractData captured from a live cellular network with the real users during their common daily routine help to understand how the users move within the network. Unlike the simulations with limited potential or expensive experimental studies, the research in user-mobility or spatio-temporal user behavior can be conducted on publicly available datasets such as the Reality Mining Dataset. These data have been for many years a source of valuable information about social interconnection between users and user-network associations. However, an important, spatial dimension is missing in this dataset. In this paper, we present a methodology for retrieving geographical locations matching the GSM cell identifiers in the Reality Mining Dataset, an approach base on querying the Google Location API. A statistical analysis of the measure of success of locations retrieval is provided. Further, we present the LAC-clustering method for detecting and removing outliers, a heuristic extension of general agglomerative hierarchical clustering. This methodology enables further, previously impossible analysis of the Reality Mining Dataset, such as studying user mobility patterns, describing spatial trajectories and mining the spatio-temporal data. Michal Ficek, Lukas Kencl |
MASS | 2 |
| 2010 | Performance study of active tracking in a cellular network using a modular signaling platformabstractWe present the SS7Box modular signaling platform, a tool for rapid application prototyping in a cellular mobile network, and examine in detail its performance limits for the application of active network-based tracking, called SS7Tracker. This application is a highly configurable, non-intrusive and cost-effective solution for large-scale data collection on user mobility in the network, uniquely enabling tracking of both active and passive mobile clients. We present performance studies of real deployment in an existing cellular network and document the measured as well as simulated performance limits such as platform interconnection utilization. Other factors, such as impact on battery consumption of the tracked device, are studied as well. Platform modularity and variability is discussed and demonstrated by further deployed use cases. We conclude by observing promising applicability for future cellular networks. Michal Ficek, Tomás Pop, Petr Vlácil, Katerina Dufková, Lukas Kencl, Martin Tomek |
MobiSys | 5 |
| 2008 | Adaptive load sharing for network processors
Lukas Kencl, Jean-Yves Le Boudec |
IEEE/ACM Trans. Netw. | 1 |
| 2006 | Sequence-preserving adaptive load balancersabstractLoad balancing in packet-switched networks is a task of ever-growing importance. Network traffic properties, such as the Zipf-like flow length distribution and bursty transmission patterns, and requirements on packet ordering or stable flow mapping, make it a particularly difficult and complex task, needing adaptive heuristic solutions. In this paper, we present two main contributions:Firstly, we evaluate and compare two recently proposed algorithmic heuristics that attempt to adaptively balance load among the destination units. The evaluation on real life traces confirms the previously conjectured impact of the Zipf-like flow length distribution and traffic burstiness. Furthermore, we identify the distinction between the goals of preserving either the sequence order of packets, or the flow-to-destination mapping, showing different strengths of each algorithm. Secondly, we demonstrate a novel hybrid scheme that combines best of the flow-based and burst-based load balancing techniques and excels in both of the key metrics of flow remapping and packet reordering. Weiguang Shi, Lukas Kencl |
ANCS | 2 |
| 2006 | Approximate fingerprinting to accelerate pattern matchingabstractPattern matching and analysis over network data streams is increasingly becoming an essential primitive of network monitoring systems. It is a fundamental part of most intrusion detection systems, worm detecting algorithms and many other anomaly detection mechanisms. It is a processing-intensive task, usually requiring to search for a large number of patterns simultaneously.We propose the technique of "approximate fingerprinting" to reduce the memory demands and significantly accelerate the pattern matching process. The method computes fingerprints of prefixes of the patterns and matches them against the input stream. It acts as a generic preprocessor to a standard pattern matching engine by "clearing" a large fraction of the input that would not match any of the patterns. The main contribution is the "approximate" characteristic of the fingerprint, which allows to slide the fingerprinting window through the packet at a faster rate, while maintaining a small memory footprint and low number of false positives. An improvement over a Bloom filter solution, a fingerprint can indicate which patterns are the candidate matches. We validate our technique by presenting the performance gain for the popular Snort intrusion detection system with the preprocessor in place. Ramaswamy Ramaswamy, Lukas Kencl, Gianluca Iannaccone |
Internet Measurement Conference | 2 |
| 2006 | Traffic-Adaptive Packet Filtering of Denial of Service AttacksabstractTraffic-adaptive packet filtering is a mechanism to adjust packet classification methods at run-time to the particular traffic mix a network node is receiving. It has been conjectured previously that such techniques could perform positively when filtering out malicious attack traffic, due to their flow aggregation capabilities. In this work, we present two novel contributions-a first ever working implementation of a traffic adaptive firewall, based on insertion of shortcuts into a search tree, and both a simulated and a real-life performance study of adaptive packet filtering under denial-of-service attack traffic, the outcomes of which support the above conjecture. Lukas Kencl, Christian Schwarzer |
WOWMOM | 1 |
| 2005 | Efficient statistics gathering from tree-search methods in packet processing systemsabstractWe present a novel algorithm for efficiently gathering statistics about the hit frequencies on the nodes of a search tree in a packet processing system, under limiting space constraints. The expand and collapse (EaC) algorithm is a heuristic that periodically adjusts the subset of nodes of the search tree at which statistics are gathered, in order to use the limited space available to collect statistics in preference from the currently most heavily-hit nodes in the search tree. We prove convergence and good node-hit coverage of the algorithm and validate its performance on a set of simulated data. The information collected can be useful for a variety of reasons, such as inferring traffic properties, discovering failures and attacks or dynamically optimizing the search method itself for locality patterns in the oncoming traffic. Nils Kammenhuber, Lukas Kencl |
ICC | 2 |
| 2005 | Network of Shortcuts: An Adaptive Data Structure for Tree-Based Search Methods
Andrea Bergamini, Lukas Kencl |
NETWORKING | 2 |
| 2002 | Adaptive Load Sharing for Network ProcessorsabstractA novel scheme for processing packets in a router is presented, which provides for load sharing among multiple network processors distributed within the router. It is complemented by a feedback control mechanism designed to prevent processor overload. Incoming traffic is scheduled to multiple processors based on a deterministic mapping. The mapping formula is derived from the robust hash routing (also known as the highest random weight - HRW) scheme, introduced in K.W. Ross, IEEE Network, vol. 11, no. 6 (1997), and D.G. Thaler et al, IEEE Trans. Networking, vol. 6, no. 1 (1998). No state information on individual flow mapping needs to be stored, but for each packet, a mapping function is computed over an identifier vector, a predefined set of fields in the packet. An adaptive extension to the HRW scheme is provided in order to cope with biased traffic patterns. We prove that our adaptation possesses the minimal disruption property with respect to the mapping and exploit that property in order to minimize the probability of flow reordering. Simulation results indicate that the scheme achieves significant improvements in processor utilization. A higher number of router interfaces can thus be supported with the same amount of processing power. Lukas Kencl, Jean-Yves Le Boudec |
INFOCOM | 1 |