Garegin Grigoryan

dblp:209/8666 · DBLP profile ↗
← Back
17ranked-venue papers
11as first author
5since 2021 · last 2026
0000-0002-3728-3249ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 11 · 6 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
6 papers
Routing and switching · 44% Software-defined and programmable networks · 39% Datacenter networks · 7%
Network and information security
1 paper
Network security · 100%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Cloud and datacenter computing · 100%

Topics — the 15 heaviest of 16, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Routing and switching
forwarding table
1.542020
PFCA: A Programmable FIB Caching Architecture · IEEE/ACM Trans. Netw. 2020
Boosting FIB Caching Performance with Aggregation · HPDC 2020
VeriTable: Fast Equivalence Verification of Multiple Large Forwarding Tables · INFOCOM 2018
Software-defined and programmable networks
programmable data plane
1.232021
Demo: Simple Deep Packet Inspection with P4 · ICNP 2021
PFCA: A Programmable FIB Caching Architecture · IEEE/ACM Trans. Netw. 2020
Toward a programmable FIB caching architecture · ICNP 2017
Software-defined and programmable networks › programmable data plane
deep packet inspection
0.512021
Demo: Simple Deep Packet Inspection with P4 · ICNP 2021
Software-defined and programmable networks › programmable data plane
p4
0.512021
Demo: Simple Deep Packet Inspection with P4 · ICNP 2021
Routing and switching › forwarding table
FIB aggregation
0.412020
Boosting FIB Caching Performance with Aggregation · HPDC 2020
Datacenter networks
RDMA
0.412019
Container Orchestration by Kubernetes for RDMA Networking · ICNP 2019
Cloud and datacenter computing
container orchestration
0.412019
Container Orchestration by Kubernetes for RDMA Networking · ICNP 2019
Network management and operations
network verification
0.312018
VeriTable: Fast Equivalence Verification of Multiple Large Forwarding Tables · INFOCOM 2018
Network performance modeling › protocol performance analysis › routing performance
routing scalability
0.312017
Toward a programmable FIB caching architecture · ICNP 2017
Routing and switching › inter-domain routing
BGP
0.112020
PFCA: A Programmable FIB Caching Architecture · IEEE/ACM Trans. Netw. 2020
Routing and switching › IP lookup
longest prefix matching
0.112020
Boosting FIB Caching Performance with Aggregation · HPDC 2020
Routing and switching
routing
0.112020
Boosting FIB Caching Performance with Aggregation · HPDC 2020
Cloud and datacenter computing
virtualization
0.112019
Container Orchestration by Kubernetes for RDMA Networking · ICNP 2019
Routing and switching › packet forwarding
IP forwarding
0.112018
VeriTable: Fast Equivalence Verification of Multiple Large Forwarding Tables · INFOCOM 2018
Routing and switching › inter-domain routing
routing table growth
0.112017
Toward a programmable FIB caching architecture · ICNP 2017

Methods — techniques the papers use, named apart from their topics

p4 · 1.0kubernetes · 0.8SR-IOV · 0.8pipeline algorithm · 0.4cache replacement · 0.4trie traversal · 0.3longest prefix matching · 0.3programmable data plane · 0.3
YearPublicationVenuePosition
2026 Securing Load Balancing Over QUIC
abstract
In-network load balancing outperforms traditional software load balancing while costing less. For instance, programmable switch ASICs can use hashing to select the backend server for the initial packet of each flow at the line rate. However, when the pool of available servers changes, ensuring that the subsequent flow packets are mapped to the same server is challenging due to the data plane's limited memory resources and performance requirements. With the emergence of the QUIC transport protocol, several works show how Connection ID fields (CIDs) can embed the server identifier for all non-initial packets. This approach requires modifications on the server side and violates the QUIC specification, which mandates that CIDs remain unlinkable. In this work, we show that stateless QUIC load balancing can be implemented inside the data plane with no changes to CIDs. Moreover, QUIC packets, except the initial client packet, can bypass the load balancer. We also investigate and mitigate attacks on QUIC in this scenario, including full load balancer bypass and 0-RTT IP spoofing.
Garegin Grigoryan, Dagim Mindaye, Shireen Maini, Minseok Kwon
HPSR1
2025 P4kube: In-Network Load Balancer for Kubernetes
abstract
Kubernetes Services such as LoadBalancer and NodePort expose applications running on pods within a Kubernetes cluster to external users. While the LoadBalancer Service requires an external load-balancing middleware, its alternative, NodePort Service, adds additional hops on the path between clients and the worker nodes. In this paper, we propose P4Kube, a framework consisting of a P4 data plane program and a Kubernetes plugin. Our solution effectively performs load balancing of requests to the worker nodes of a cluster based on the number of running replicas. In P4Kube, the data packets completely bypass the system's control plane. Unlike the previous work, to update its state, the P4Kube data plane works directly with the Kubernetes control plane without any involvement of the network control plane. Our experiments show up to 50 % improvement in the average request time to the cluster compared to conventional approaches.
Garegin Grigoryan, Kevin Penkowski, Minseok Kwon
CCNC1
2023 Towards Greener Data Centers via Programmable Data Plane
abstract
The energy demands of data centers are increasing and are expected to grow exponentially. Reducing the energy consumption of data centers decreases operational expenses, as well as their carbon footprint. We design techniques to reduce data center power consumption by leveraging Software-Defined Networking (SDN) and programmable data plane concepts. Relying solely on in-data plane registers, our proposed system P4Green consolidates traffic in the least number of network switches and shifts workloads to the servers with the available renewable energy. Unlike existing SDN-based solutions, P4Green’s operation does not depend on a centralized controller, making the system scalable and failure-resistant. Our proof-of-concept simulations show that traffic consolidation can reduce data centers’ aggregation switch usage by 36% compared to standard data center load balancing techniques, while workload control can boost renewable energy consumption for 46% of the daily traffic.
Garegin Grigoryan, Minseok Kwon
HPSR1
2023 Study on Network Importance for ML End Application Robustness
abstract
In this paper, we investigate the robustness of the ML end application performance to network Quality of Service (QoS) degradation, and the ways to improve it. We introduce a novel system approach to define the Machine Learning (ML) with Integrated Networks (MLINs) and describe how ML end performance can be employed to adjust network hyperparameters in order to prevent system Data Quality decrease. We investigate the interrelations between the network QoS degradation during the data transmission and ML image classification performance. We demonstrate how the studied interrelationships can be employed to produce recommendations on network adjustment in order to improve MLIN robustness. In particular, we propose an example of MLIN feedback system design that employs ML end performance as the major indicator to produce recommendations on network hyperparameters adjustment aimed at improving MLIN robustness.
Sergei Chuprov, Leon Reznik, Garegin Grigoryan
ICC3
2021 Demo: Simple Deep Packet Inspection with P4
abstract
The P4 language allows "protocol-independent packet parsing" in network switches, and makes many operations possible in the data plane. But P4 is not built for Deep Packet Inspection – it can only "parse" well-defined packet headers, not free-form headers as seen in HTTPS etc. Thus some very important use cases, such as application-layer firewalls, are considered impossible for P4. This demonstration shows that this limitation is not strictly true: switches, that support only standard P4, are able to independently perform tasks such as blocking specific URLs (without using non-standard "extern" components, help from the SDN controller, or rerouting to a firewall). As more Internet infrastructure becomes SDN-compatible, in future, switches may perform simple application-layer firewall tasks.
Sahil Gupta, Devashish Gosain, Garegin Grigoryan, Minseok Kwon, Hrishikesh B. Acharya
ICNP3
2020 Boosting FIB Caching Performance with Aggregation
abstract
In the era of high-performance cloud computations, networks need to ensure fast packet forwarding. This task is carried by TCAM forwarding chips that perform line-rate Longest Prefix Matches in a Forwarding Information Base (FIB). However, with the increasing number of prefixes in IPv4 and IPv6 routing tables the price of TCAM increases as well. In this work, we present a novel FIB compression technique by adding an aggregation layer into a FIB caching architecture. In Combined FIB Caching and Aggregation (CFCA), cache-hit ratio is maximized up to 99.94% with only 2.50% entries of the FIB, while the churn in TCAM is reduced by more than 40% compared to low-churn FIB aggregation techniques.
Garegin Grigoryan, Yaoqing Liu, Minseok Kwon
HPDC1
2020 VeriTable: Fast equivalence verification of multiple large forwarding tables
Yaoqing Liu, Garegin Grigoryan, Jun Li 0001, Guchuan Sun, Tony Tauber
Comput. Networks2
2020 PFCA: A Programmable FIB Caching Architecture
abstract
Ternary Content-Addressable Memory (TCAM) chips are used to store Forwarding Information Bases (FIB) in modern routers. TCAM provides next-hop lookup for IP packets at the line-rate. However, TCAM is expensive and energy-consuming; in addition, the constant FIB growth may lead to TCAM overflow problem. Yet only a small portion of FIB entries carries the most of network traffic. Thus, FIB caching, namely, installing the most popular entries in a fast memory, e.g., TCAM, may significantly minimize TCAM usage. To date, FIB caching architecture has not been widely deployed in backbone routers due to high cache-miss latency and the lack of an efficient cache replacement strategy. In this work, we leverage the concept of the programmable data plane to design a Programmable FIB Caching Architecture (PFCA) with two levels of cache. We present a pipeline-based algorithm to detect the least popular prefixes in a cache for a victim selection. We tested the prototype of PFCA using real traffic traces and an FIB with more than 599K entries, and showed that PFCA can be implemented using P4 programmable data plane language. Our results show that PFCA achieves 99.8% hit ratio for Level-1 cache with 20K entries and nearly 99.9% hit ratio for Level-2 cache with 40K entries. We also demonstrate that PFCA significantly reduces the number of BGP updates in the cache and thus makes the cache more stable.
Garegin Grigoryan, Yaoqing Liu, Minseok Kwon
IEEE/ACM Trans. Netw.1
2019 Container Orchestration by Kubernetes for RDMA Networking
abstract
With the widespread usage of containerized virtualization in data centers and clouds, it is important to enabling high-throughput and zero-copy data transfer between those containers. Remote Direct Memory Access (RDMA) allows bypassing the kernel for packet processing by offloading it to specific RDMA-enabled NICs. The existing solutions enabling RDMA with containers are either based on custom container orchestrators (e.g., FreeFlow) or lack the ability for the control plane to manage the underlying RDMA traffic (e.g., Kubernetes RDMA plug-in via SR-IOV). The work in this paper builds off of previous work in Kubernetes to make an architecture that allows control over bandwidth requirements of RDMA within a Kubernetes cluster.
Coleman Link, Jesse Sarran, Garegin Grigoryan, Minseok Kwon, M. Mustafa Rafique, Warren R. Carithers
ICNP3
2018 PFCA: a programmable FIB caching architecture
abstract
Ternary Content-Addressable Memory (TCAM) chips are used to store Forwarding Information Bases (FIB) in modern routers. TCAM provides next hop lookup for IP packets at the line-rate. However, TCAM is expensive and energy-consuming; in addition, the constant FIB growth may lead to TCAM overflow problem. Yet only a small portion of FIB entries carries the most of the network traffic. Thus, FIB caching, namely, installing the most popular entries in a fast memory, e.g., TCAM, may significantly minimize TCAM usage. In this work, we leverage the concept of the programmable data plane to design a Programmable FIB Caching Architecture (PFCA) with two levels of cache. We present a pipeline-based algorithm to detect the least popular prefixes in a cache for victim eviction. We tested the prototype of PFCA using real traffic traces and an FIB with more than 599K entries. Our results show that PFCA achieves 99.8% hit ratio for Level-1 cache with 20K entries and nearly 99.9% hit ratio for Level-2 cache with 40K entries. We also demonstrate that PFCA significantly reduces the number of BGP updates in the cache and thus makes the cache more stable.
Garegin Grigoryan, Yaoqing Liu
ANCS1
2018 LAMP: prompt layer 7 attack mitigation with programmable data planes
abstract
While there are various methods to detect application layer attacks or intrusion attempts on an individual end host, it is not efficient to provide all end hosts in the network with heavy-duty defense systems or software firewalls. In this work, we leverage a new concept of programmable data planes, to directly react on alerts raised by a victim and prevent further attacks on the whole network by blocking the attack at the network edge.
Garegin Grigoryan, Yaoqing Liu
ANCS1
2018 Toward incremental FIB aggregation with quick selections (FAQS)
abstract
FIB aggregation is the most feasible solution to mitigate FIB overflow. We present FAQS, an algorithm that uses a single tree traversal to perform faster FIB aggregation and update handling. FAQS is 2.53 and 1.75 times faster than the-state-of-the-art FIB aggregation algorithm for IPv4 and IPv6 FIBs respectively while achieving a near-optimal aggregation ratio.
Yaoqing Liu, Garegin Grigoryan
ANCS2
2018 Enabling Cooperative IoT Security via Software Defined Networks (SDN)
abstract
Internet of Things (IoT) is becoming an increasingly attractive target for cybercriminals. We observe that many attacks to IoTs are launched in a collusive way, such as brute-force hacking usernames and passwords, to target at a particular victim. However, most of the time our defending mechanisms to such kind of attacks are carried out individually and independently, which leads to ineffective and weak defense. To this end, we propose to leverage Software Defined Networks (SDN) to enable cooperative security for legacy IP-based IoT devices. SDN decouples control plane and data plane, and can help bridge the knowledge divided between the application and network layers. In this paper, we discuss the IoT security problems and challenges, and present an SDN-based architecture to enable IoT security in a cooperative manner. Furthermore, we implemented a platform that can quickly share the attacking information with peer controllers and block the attacks. We carried out our experiments in both virtual and physical SDN environments with OpenFlow switches. Our evaluation results show that both environments can scale well to handle attacks, but hardware implementation is much more efficient than a virtual one.
Garegin Grigoryan, Yaoqing Liu, Laurent Njilla, Charles A. Kamhoua, Kevin A. Kwiat
ICC1
2018 VeriTable: Fast Equivalence Verification of Multiple Large Forwarding Tables
abstract
Due to network practices such as traffic engineering and multi-homing, the number of routes-also known as IP prefixes-in the global forwarding tables has been increasing significantly in the last decade and continues growing in a super linear trend. One of the most promising solutions is to use smart Forwarding Information Base (FIB) aggregation algorithms to aggregate the prefixes and convert a large table into a small one. Doing so poses a research question, however, i.e., how can we quickly verify that the original table yields the same forwarding behaviors as the aggregated one? We answer this question in this paper, including addressing the challenges caused by the longest prefix matching (LPM) lookups. In particular, we propose the VeriTable algorithm that can employ a single tree/trie traversal to quickly check if multiple forwarding tables are forwarding equivalent, as well as if they could result in routing loops or black holes. The VeriTable algorithm significantly outperforms the state-of-the-art work for both IPv4 and IPv6 tables in every aspect, including the total running time, memory access times and memory consumption.
Garegin Grigoryan, Yaoqing Liu, Michael Leczinsky, Jun Li 0001
INFOCOM1
2018 LAMP: Prompt Layer 7 Attack Mitigation with Programmable Data Planes
abstract
While there are various methods to detect application layer attacks or intrusion attempts on an individual end host, it is not efficient to provide all end hosts in the network with heavy-duty defense systems or software firewalls. In this work, we leverage a new concept of programmable data planes, to directly react on alerts raised by a victim and prevent further attacks on the whole network by blocking the attack at the network edge. We call our design LAMP, Layer 7 Attack Mitigation with Programmable data planes. We implemented LAMP using the P4 data plane programming language and evaluated its effectiveness and efficiency in the Behavioral Model (bmv2) environment.
Garegin Grigoryan, Yaoqing Liu
NCA1
2018 Toward Incremental FIB Aggregation with Quick Selections (FAQS)
abstract
Several approaches to mitigating the Forwarding Information Base (FIB) overflow problem were developed and software solutions using FIB aggregation are of particular interest. One of the greatest concerns to deploy these algorithms to real networks is their high running time and heavy computational overhead to handle thousands of FIB updates every second. In this work, we manage to use a single tree traversal to implement faster aggregation and update handling algorithm with much lower memory footprint than other existing work. We utilize 6-year realistic IPv4 and IPv6 routing tables from 2011 to 2016 to evaluate the performance of our algorithm with various metrics. To the best of our knowledge, it is the first time that IPv6 FIB aggregation has been performed. Our new solution is 2.53 and 1.75 times as fast as the-state-of-the-art FIB aggregation algorithm for IPv4 and IPv6 FIBs, respectively, while achieving a near-optimal FIB aggregation ratio.
Yaoqing Liu, Garegin Grigoryan
NCA2
2017 Toward a programmable FIB caching architecture
abstract
The current Internet routing ecosystem is neither sustainable nor economical. More than 711K IPv4 routes and more than 41K IPv6 routes exist in current global Forwarding Information Base (FIBs) with growth rates increasing. This rapid growth has serious consequences, such as creating the need for costly FIB memory upgrades and increased potential for Internet service outages. And while FIB memories are power-hungry and prohibitively expensive, more than 70% of the routes in FIBs carry no traffic for long time periods, a wasteful use of these expensive resources. Taking advantage of the emerging concept of programmable data plane, we design a programmable FIB caching architecture to address the existing concerns. Our preliminary evaluation results show that the architecture can significantly mitigate the global routing scalability and poor FIB utilization issues.
Garegin Grigoryan, Yaoqing Liu
ICNP1